Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112
Nmdfgds0.dll jak usunąć? • programosy.pl

  • Ogłoszenie:

Nmdfgds0.dll jak usunąć?

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Nmdfgds0.dll jak usunąć?

Postprzez myszkomputerowa3 03 Cze 2009, 23:24

reklama
Hej. Zarejestrowałam się na forum, bo pilnie potrzebuje pomocy. Avast wykrył mi wirusa nmdfgds0.dll, nie mogę go usunąć, pewnie przyniosłam go na pendrivie. Wiem, że był jut temat podobny, ale nie wiem czy w kazdym przypadku dziala to tak samo i nie mam pojecia co robic bo temat dla mnie zupelnie zielony i boje sie zeby czegos nie zepsuc, nizej wklejam loga. Help! :)
Ostatnio edytowany przez myszkomputerowa3, 04 Cze 2009, 17:22, edytowano w sumie 1 raz
myszkomputerowa3
~user
 
Posty: 3
Dołączenie: 03 Cze 2009, 23:14



Nmdfgds0.dll jak usunąć?

Postprzez wojtas 03 Cze 2009, 23:27

Pobierz OTListIt2 i daj z niego loga ale w tagach code.. (zaznacz myszka caly log i nacisnij code)
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Re: nmdfgds0.dll jak usunąć?

Postprzez myszkomputerowa3 03 Cze 2009, 23:41

Kod: Zaznacz wszystko
OTListIt logfile created on: 2009-06-03 23:39:58 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8     Folder = C:\Documents and Settings\User\Pulpit
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1023,48 Mb Total Physical Memory | 662,86 Mb Available Physical Memory | 64,77% Memory free
2,40 Gb Paging File | 2,09 Gb Available in Paging File | 87,06% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 3,70 Gb Free Space | 12,62% Space Free | Partition Type: NTFS
Drive D: | 101,79 Gb Total Space | 8,59 Gb Free Space | 8,44% Space Free | Partition Type: NTFS
Drive E: | 101,80 Gb Total Space | 75,41 Gb Free Space | 74,07% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KOMPUTER
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

[color=orange]========== Processes (SafeList) ==========[/color]

PRC - [2005-07-08 16:24:46 | 00,871,424 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2007-10-29 13:27:04 | 00,587,096 | ---- | M] (Lavasoft AB) -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
PRC - [2009-02-05 22:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009-02-05 22:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2007-05-10 21:55:33 | 01,423,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2004-08-04 02:44:26 | 00,420,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntvdm.exe
PRC - [2004-08-31 07:33:22 | 00,061,440 | ---- | M] (A4Tech Co.,Ltd.) -- C:\Program Files\A4Tech\Keyboard\Ikeymain.exe
PRC - [2004-09-01 04:28:04 | 00,192,512 | ---- | M] (A4Tech Co., Ltd.) -- C:\Program Files\A4Tech\Mouse\Amoumain.exe
PRC - [2006-05-27 04:47:26 | 16,208,384 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2009-02-05 22:08:45 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2008-05-04 18:14:20 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008-05-02 06:15:46 | 00,015,872 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2006-10-27 01:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2007-10-18 21:10:42 | 00,479,232 | ---- | M] (Nikon Corporation) -- C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
PRC - [2008-05-04 18:14:20 | 00,147,456 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2006-10-19 13:52:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2007-03-01 07:36:37 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2009-06-03 23:36:36 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe

[color=orange]========== Win32 Services (SafeList) ==========[/color]

SRV - [2007-10-29 13:27:04 | 00,587,096 | ---- | M] (Lavasoft AB) -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe -- (aawservice [Auto | Running])
SRV - [2009-02-05 22:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2009-02-05 22:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009-02-05 22:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Stopped])
SRV - [2009-02-05 22:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Stopped])
SRV - [2008-04-26 16:51:58 | 00,138,168 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2005-04-04 01:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2005-07-08 16:24:46 | 00,871,424 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv [Auto | Running])
SRV - [2008-05-04 18:14:20 | 00,147,456 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2006-10-19 13:52:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2006-10-27 01:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2007-03-01 07:36:37 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2006-10-26 20:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2008-04-26 14:46:43 | 00,306,432 | ---- | M] (TuneUp Software GmbH) -- C:\WINDOWS\System32\TuneUpDefragService.exe -- (TuneUp.Defrag [On_Demand | Stopped])
SRV - [2007-12-20 10:41:56 | 00,029,440 | ---- | M] (TuneUp Software GmbH) -- C:\WINDOWS\System32\uxtuneup.dll -- (UxTuneUp [Auto | Running])
SRV - [2006-12-01 10:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

[color=orange]========== Driver Services (SafeList) ==========[/color]

DRV - [2009-02-05 22:05:11 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
DRV - [2005-03-09 15:53:00 | 00,043,008 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running])
DRV - [2005-09-21 10:26:36 | 00,006,656 | R--- | M] (A4Tech Co.,Ltd.) -- C:\WINDOWS\system32\DRIVERS\Amfilter.sys -- (Amfilter [System | Running])
DRV - [2004-08-25 11:09:46 | 00,007,424 | ---- | M] (A4Tech Co.,Ltd.) -- C:\WINDOWS\system32\DRIVERS\Amusbdev.sys -- (Amusbdev [On_Demand | Running])
DRV - [2005-09-21 10:25:40 | 00,012,800 | R--- | M] (A4Tech Co.,Ltd.) -- C:\WINDOWS\system32\DRIVERS\Amusbprt.sys -- (Amusbprt [On_Demand | Running])
DRV - [2009-02-05 22:07:12 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009-02-05 22:08:10 | 00,094,032 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
DRV - [2009-02-05 22:06:10 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
DRV - [2009-02-05 22:07:23 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009-02-05 22:06:20 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2002-07-27 18:01:06 | 00,005,306 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\system32\drivers\TBPANEL.SYS -- (Cardex [On_Demand | Stopped])
DRV - [2005-01-07 17:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2005-07-08 16:17:54 | 00,099,584 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs [Disabled | Running])
DRV - [2005-07-08 16:17:36 | 00,029,696 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\DRIVERS\InCDPass.sys -- (InCDPass [System | Running])
DRV - [2006-11-02 08:55:17 | 00,028,672 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm [System | Running])
DRV - [2006-05-26 07:20:58 | 04,279,296 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2007-03-01 07:36:37 | 03,994,688 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2006-04-24 17:52:28 | 00,100,736 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata [Boot | Running])
DRV - [2006-03-22 08:24:00 | 00,052,736 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
DRV - [2006-03-22 08:24:02 | 00,018,944 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
DRV - [2008-04-26 15:03:40 | 00,009,856 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc [On_Demand | Running])
DRV - [2001-08-18 01:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008-11-20 21:19:06 | 00,043,872 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2008-08-29 14:58:12 | 00,028,624 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2002-07-27 18:01:06 | 00,005,306 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\System32\drivers\TBPanel.sys -- (TBPanel [Auto | Running])

[color=orange]========== Standard Registry (SafeList) ==========[/color]


[color=orange]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wyborcza.pl/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=orange]========== FireFox ==========[/color]

FF - prefs.js..browser.search.selectedEngine: "GooglePL"
FF - prefs.js..browser.startup.homepage: "http://www.wp.pl/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "http://www.googlc.pl/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="

FF - user.js..browser.search.selectedEngine: "GooglePL"
FF - user.js..keyword.URL: "http://www.googlc.pl/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008-05-04 18:14:21 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\COMPONENTS [2009-05-06 07:17:13 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\PLUGINS [2009-04-30 07:28:19 | 00,000,000 | ---D | M]

[2008-05-16 18:00:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\mozilla\Extensions
[2008-05-16 18:00:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-06-03 19:35:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\mozilla\Firefox\Profiles\ja67q5q1.default\extensions
[2009-05-13 06:51:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\mozilla\Firefox\Profiles\ja67q5q1.default\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}
[2009-05-13 06:41:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\mozilla\Firefox\Profiles\ja67q5q1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}

O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe (A4Tech Co.,Ltd.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SkyTel] SkyTel.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" ()
O4 - HKLM..\Run: [WheelMouse] C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe (A4Tech Co., Ltd.)
O4 - HKCU..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe ()
O4 - HKCU..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe" (GG Network S.A.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - Startup: C:\Documents and Settings\User\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
F3 - HKCU WinNT: Load - (C:\YDPDict\watch.exe) - C:\YDPDict\watch.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInstrumentation = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMFUprogramsList = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 (Google Inc.)
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_10.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter:  - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Bieżąca strona główna) - About:Home
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-04-26 13:45:55 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009-06-03 07:07:04 | 00,000,051 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-03 07:07:07 | 00,000,051 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-03 07:07:10 | 00,000,051 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{66c11fcc-14ee-11dd-bd94-000fea65f207}\Shell\AutoRun\command - "" = u.cmd
O33 - MountPoints2\{66c11fcc-14ee-11dd-bd94-000fea65f207}\Shell\explore\Command - "" = u.cmd
O33 - MountPoints2\{66c11fcc-14ee-11dd-bd94-000fea65f207}\Shell\open\Command - "" = u.cmd
O33 - MountPoints2\{74513838-4626-11de-845d-000fea65f207}\Shell - "" = AutoRun
O33 - MountPoints2\{74513838-4626-11de-845d-000fea65f207}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) -  File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009-06-03 23:36:35 | 00,000,000 | ---D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]

[1 C:\WINDOWS\*.tmp files]
[2009-06-03 23:33:37 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
[2009-06-03 23:20:35 | 00,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\User\Pulpit\User.exe
[2009-06-03 23:20:35 | 00,000,000 | ---D | C] -- C:\rsit
[2009-06-03 23:11:38 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\RSIT.exe
[2009-06-03 22:27:58 | 03,129,961 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\ComboFix.exe
[2009-06-03 18:27:02 | 01,370,996 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\PZU.jpg
[2009-06-03 07:59:00 | 00,473,188 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\ISO1_DVD.nri
[2009-06-02 14:24:09 | 00,039,936 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\Irena Opis i analiza przypadku rozpoznania i rozwizania problemu wychowawczego uczennicy z problemami szkolnymi.doc
[2009-06-02 14:12:11 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\launch.exe
[2009-06-02 13:39:28 | 00,013,967 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\wirus.JPG
[2009-06-02 13:22:58 | 00,402,176 | ---- | C] (Panda Security) -- C:\Documents and Settings\User\Pulpit\USBVaccine.exe
[2009-06-02 13:19:27 | 00,001,548 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\CCleaner.lnk
[2009-06-02 13:19:27 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009-06-02 13:11:10 | 03,247,736 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\User\Pulpit\ccsetup220(2).exe
[2009-06-02 13:10:45 | 00,388,974 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\USBVaccine.zip
[2009-06-02 12:26:50 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009-06-02 08:11:45 | 00,096,768 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\JdaAKR4k.doc.part
[2009-06-02 05:15:20 | 00,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\User\Pulpit\HijackThis.exe
[2009-06-01 07:44:45 | 00,000,051 | RHS- | C] () -- C:\autorun.inf
[2009-06-01 07:44:18 | 00,105,555 | RHS- | C] () -- C:\WINDOWS\System32\olhrwef.exe
[2009-05-30 18:32:12 | 00,035,328 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\ANKIETA dobra.doc
[2009-05-11 13:51:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Dane aplikacji\U3
[2009-01-24 11:08:44 | 00,000,036 | -H-- | C] () -- C:\WINDOWS\System32\swk.ini
[2008-12-19 13:13:10 | 00,003,350 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2008-12-19 13:13:10 | 00,000,088 | RHS- | C] () -- C:\WINDOWS\System32\CD2CCFDA61.sys
[2008-08-16 21:28:42 | 00,000,795 | ---- | C] () -- C:\WINDOWS\VPlayer.INI
[2008-05-04 18:05:20 | 00,002,271 | ---- | C] () -- C:\WINDOWS\bestplayer.ini
[2008-05-04 17:52:09 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-05-04 13:20:42 | 00,000,419 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008-04-26 15:11:00 | 00,000,911 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008-04-26 15:10:43 | 00,000,789 | ---- | C] () -- C:\WINDOWS\YDPDICT.INI
[2008-04-26 14:35:09 | 00,000,669 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-04-26 14:15:13 | 00,000,259 | ---- | C] () -- C:\WINDOWS\lgfwup.ini
[2008-04-26 14:01:08 | 00,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008-04-26 13:54:27 | 00,000,558 | ---- | C] () -- C:\WINDOWS\DFC.INI
[2008-02-11 11:11:06 | 00,002,045 | -H-- | C] () -- C:\WINDOWS\System32\whlb32g.dll
[2007-03-01 07:36:37 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007-03-01 07:36:37 | 01,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007-03-01 07:36:37 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007-03-01 07:36:37 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2007-03-01 07:36:37 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007-03-01 07:36:37 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007-03-01 07:36:37 | 00,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006-05-22 13:47:24 | 00,008,704 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006-05-21 23:56:42 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2004-08-30 05:28:44 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2004-08-30 05:26:54 | 00,638,976 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2004-07-17 13:36:38 | 00,028,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2003-03-07 12:13:10 | 01,032,266 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2002-11-15 14:11:28 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\MMSwitch.dll
[2002-10-06 20:42:58 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2002-10-05 01:04:26 | 00,921,600 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2002-10-05 01:04:26 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\VORBIS.DLL
[2002-10-05 01:04:18 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\OGG.DLL
[2001-07-22 02:16:20 | 00,000,661 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 02:15:52 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[1997-06-14 02:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll

[color=orange]========== Files - Modified Within 30 Days ==========[/color]

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009-06-03 23:40:00 | 00,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{16F4BEE2-7120-4C78-9AF3-28BCFB14059B}.job
[2009-06-03 23:36:36 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
[2009-06-03 23:12:14 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\RSIT.exe
[2009-06-03 22:31:17 | 03,129,961 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\ComboFix.exe
[2009-06-03 22:05:55 | 00,089,134 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009-06-03 22:05:54 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-06-03 22:05:49 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\desktop.ini
[2009-06-03 22:05:48 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-06-03 18:28:01 | 01,370,996 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\PZU.jpg
[2009-06-03 15:09:22 | 00,003,213 | ---- | M] () -- C:\WINDOWS\bestplayer.bbt
[2009-06-03 15:09:22 | 00,002,271 | ---- | M] () -- C:\WINDOWS\bestplayer.ini
[2009-06-03 15:09:22 | 00,000,038 | ---- | M] () -- C:\WINDOWS\bestplayer.bpp
[2009-06-03 07:59:08 | 00,473,188 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\ISO1_DVD.nri
[2009-06-03 07:07:04 | 00,000,051 | RHS- | M] () -- C:\autorun.inf
[2009-06-02 14:24:10 | 00,039,936 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\Irena Opis i analiza przypadku rozpoznania i rozwizania problemu wychowawczego uczennicy z problemami szkolnymi.doc
[2009-06-02 14:12:11 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\launch.exe
[2009-06-02 13:58:05 | 00,000,789 | ---- | M] () -- C:\WINDOWS\YDPDICT.INI
[2009-06-02 13:39:28 | 00,013,967 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\wirus.JPG
[2009-06-02 13:33:35 | 00,002,645 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009-06-02 13:19:27 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\CCleaner.lnk
[2009-06-02 13:11:10 | 03,247,736 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\User\Pulpit\ccsetup220(2).exe
[2009-06-02 13:10:59 | 00,388,974 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\USBVaccine.zip
[2009-06-02 08:11:46 | 00,096,768 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\JdaAKR4k.doc.part
[2009-05-31 21:19:22 | 00,105,555 | RHS- | M] () -- C:\WINDOWS\System32\olhrwef.exe
[2009-05-30 20:08:32 | 00,012,288 | -H-- | M] () -- C:\Documents and Settings\User\Pulpit\photothumb.db
[2009-05-30 19:39:39 | 00,035,328 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\ANKIETA dobra.doc
[2009-05-22 17:15:55 | 00,000,374 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2009-05-19 16:41:41 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-05-11 13:17:37 | 00,003,072 | -H-- | M] () -- C:\Documents and Settings\User\Moje dokumenty\photothumb.db
< End of report >

Kod: Zaznacz wszystko
Ostatnio edytowany przez wojtas, 03 Cze 2009, 23:43, edytowano w sumie 1 raz
Powód: brak tagów code ... http://forum.programosy.pl/hijackthis-silent-runners-regulamin-tego-dzialu-vt9452.html
myszkomputerowa3
~user
 
Posty: 3
Dołączenie: 03 Cze 2009, 23:14



Nmdfgds0.dll jak usunąć?

Postprzez wojtas 03 Cze 2009, 23:47

Uruchom OTListIt2 i w oknie Custom Scans/Fixes wklej :

:OTLI
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O4 - HKCU..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe ()
O32 - AutoRun File - [2009-06-03 07:07:04 | 00,000,051 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-03 07:07:07 | 00,000,051 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-06-03 07:07:10 | 00,000,051 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{66c11fcc-14ee-11dd-bd94-000fea65f207}\Shell\AutoRun\command - "" = u.cmd
O33 - MountPoints2\{66c11fcc-14ee-11dd-bd94-000fea65f207}\Shell\explore\Command - "" = u.cmd
O33 - MountPoints2\{66c11fcc-14ee-11dd-bd94-000fea65f207}\Shell\open\Command - "" = u.cmd
O33 - MountPoints2\{74513838-4626-11de-845d-000fea65f207}\Shell - "" = AutoRun

:Files
C:\autorun.inf
D:\autorun.inf
E:\autorun.inf
C:\WINDOWS\System32\olhrwef.exe
C:\WINDOWS\SYSTEM32\nmdfgds0.dll

:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""

:Commands
[emptytemp]
[start explorer]
[Reboot]

Kliknij w Run Fix. I potwierdz reset kompa .

Następnie uruchamiasz OTListIt2 z opcją Run Scan. Pokazujesz nowy log OTListIt.txt oraz raport z czyszczenia kompa
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Nmdfgds0.dll jak usunąć?

Postprzez myszkomputerowa3 04 Cze 2009, 00:27

Kod: Zaznacz wszystko
OTListIt logfile created on: 2009-06-04 00:21:45 - Run 2
OTListIt2 by OldTimer - Version 2.0.15.8     Folder = C:\Documents and Settings\User\Pulpit
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1023,48 Mb Total Physical Memory | 698,86 Mb Available Physical Memory | 68,28% Memory free
2,40 Gb Paging File | 2,09 Gb Available in Paging File | 86,82% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 4,76 Gb Free Space | 16,26% Space Free | Partition Type: NTFS
Drive D: | 101,79 Gb Total Space | 8,59 Gb Free Space | 8,44% Space Free | Partition Type: NTFS
Drive E: | 101,80 Gb Total Space | 75,41 Gb Free Space | 74,07% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KOMPUTER
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

[color=orange]========== Processes (SafeList) ==========[/color]

PRC - [2005-07-08 16:24:46 | 00,871,424 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2007-10-29 13:27:04 | 00,587,096 | ---- | M] (Lavasoft AB) -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
PRC - [2009-02-05 22:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009-02-05 22:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2007-05-10 21:55:33 | 01,423,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2004-08-04 02:44:26 | 00,420,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntvdm.exe
PRC - [2004-08-31 07:33:22 | 00,061,440 | ---- | M] (A4Tech Co.,Ltd.) -- C:\Program Files\A4Tech\Keyboard\Ikeymain.exe
PRC - [2004-09-01 04:28:04 | 00,192,512 | ---- | M] (A4Tech Co., Ltd.) -- C:\Program Files\A4Tech\Mouse\Amoumain.exe
PRC - [2006-05-27 04:47:26 | 16,208,384 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2009-02-05 22:08:45 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2008-05-04 18:14:20 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008-05-02 06:15:46 | 00,015,872 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2006-10-27 01:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2007-10-18 21:10:42 | 00,479,232 | ---- | M] (Nikon Corporation) -- C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
PRC - [2008-05-04 18:14:20 | 00,147,456 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2006-10-19 13:52:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2007-03-01 07:36:37 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2009-02-05 22:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009-02-05 22:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2004-08-04 02:44:30 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2009-06-04 00:20:49 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
PRC - [2009-06-04 00:20:49 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe

[color=orange]========== Win32 Services (SafeList) ==========[/color]

SRV - [2007-10-29 13:27:04 | 00,587,096 | ---- | M] (Lavasoft AB) -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe -- (aawservice [Auto | Running])
SRV - [2009-02-05 22:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2009-02-05 22:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009-02-05 22:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009-02-05 22:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2008-04-26 16:51:58 | 00,138,168 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2005-04-04 01:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2005-07-08 16:24:46 | 00,871,424 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv [Auto | Running])
SRV - [2008-05-04 18:14:20 | 00,147,456 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2006-10-19 13:52:24 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2006-10-27 01:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2007-03-01 07:36:37 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2006-10-26 20:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2008-04-26 14:46:43 | 00,306,432 | ---- | M] (TuneUp Software GmbH) -- C:\WINDOWS\System32\TuneUpDefragService.exe -- (TuneUp.Defrag [On_Demand | Stopped])
SRV - [2007-12-20 10:41:56 | 00,029,440 | ---- | M] (TuneUp Software GmbH) -- C:\WINDOWS\System32\uxtuneup.dll -- (UxTuneUp [Auto | Running])
SRV - [2006-12-01 10:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

[color=orange]========== Driver Services (SafeList) ==========[/color]

DRV - [2009-02-05 22:05:11 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
DRV - [2005-03-09 15:53:00 | 00,043,008 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running])
DRV - [2005-09-21 10:26:36 | 00,006,656 | R--- | M] (A4Tech Co.,Ltd.) -- C:\WINDOWS\system32\DRIVERS\Amfilter.sys -- (Amfilter [System | Running])
DRV - [2004-08-25 11:09:46 | 00,007,424 | ---- | M] (A4Tech Co.,Ltd.) -- C:\WINDOWS\system32\DRIVERS\Amusbdev.sys -- (Amusbdev [On_Demand | Running])
DRV - [2005-09-21 10:25:40 | 00,012,800 | R--- | M] (A4Tech Co.,Ltd.) -- C:\WINDOWS\system32\DRIVERS\Amusbprt.sys -- (Amusbprt [On_Demand | Running])
DRV - [2009-02-05 22:07:12 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009-02-05 22:08:10 | 00,094,032 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
DRV - [2009-02-05 22:06:10 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
DRV - [2009-02-05 22:07:23 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009-02-05 22:06:20 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2002-07-27 18:01:06 | 00,005,306 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\system32\drivers\TBPANEL.SYS -- (Cardex [On_Demand | Stopped])
DRV - [2005-01-07 17:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2005-07-08 16:17:54 | 00,099,584 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs [Disabled | Running])
DRV - [2005-07-08 16:17:36 | 00,029,696 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\DRIVERS\InCDPass.sys -- (InCDPass [System | Running])
DRV - [2006-11-02 08:55:17 | 00,028,672 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm [System | Running])
DRV - [2006-05-26 07:20:58 | 04,279,296 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2007-03-01 07:36:37 | 03,994,688 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2006-04-24 17:52:28 | 00,100,736 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata [Boot | Running])
DRV - [2006-03-22 08:24:00 | 00,052,736 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
DRV - [2006-03-22 08:24:02 | 00,018,944 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
DRV - [2008-04-26 15:03:40 | 00,009,856 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc [On_Demand | Running])
DRV - [2001-08-18 01:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008-11-20 21:19:06 | 00,043,872 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2008-08-29 14:58:12 | 00,028,624 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2002-07-27 18:01:06 | 00,005,306 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\System32\drivers\TBPanel.sys -- (TBPanel [Auto | Running])

[color=orange]========== Standard Registry (SafeList) ==========[/color]


[color=orange]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wyborcza.pl/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=orange]========== FireFox ==========[/color]

FF - prefs.js..browser.search.selectedEngine: "GooglePL"
FF - prefs.js..browser.startup.homepage: "http://www.wp.pl/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "http://www.googlc.pl/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="

FF - user.js..browser.search.selectedEngine: "GooglePL"
FF - user.js..keyword.URL: "http://www.googlc.pl/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008-05-04 18:14:21 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\COMPONENTS [2009-05-06 07:17:13 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\PLUGINS [2009-04-30 07:28:19 | 00,000,000 | ---D | M]

[2008-05-16 18:00:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\mozilla\Extensions
[2008-05-16 18:00:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-06-03 19:35:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\mozilla\Firefox\Profiles\ja67q5q1.default\extensions
[2009-05-13 06:51:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\mozilla\Firefox\Profiles\ja67q5q1.default\extensions\{c33c5b47-69c8-45a4-a5e0-af85bbe628dd}
[2009-05-13 06:41:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\mozilla\Firefox\Profiles\ja67q5q1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}

O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe (A4Tech Co.,Ltd.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SkyTel] SkyTel.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" ()
O4 - HKLM..\Run: [WheelMouse] C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe (A4Tech Co., Ltd.)
O4 - HKCU..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe" (GG Network S.A.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - Startup: C:\Documents and Settings\User\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
F3 - HKCU WinNT: Load - (C:\YDPDict\watch.exe) - C:\YDPDict\watch.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInstrumentation = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMFUprogramsList = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 (Google Inc.)
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_10.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter:  - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Bieżąca strona główna) - About:Home
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-04-26 13:45:55 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) -  File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009-06-04 00:20:48 | 00,000,000 | ---D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]

[1 C:\WINDOWS\*.tmp files]
[2009-06-04 00:20:48 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
[2009-06-04 00:17:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009-06-03 23:50:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\backups
[2009-06-03 23:20:35 | 00,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\User\Pulpit\User.exe
[2009-06-03 18:27:02 | 01,370,996 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\PZU.jpg
[2009-06-03 07:59:00 | 00,473,188 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\ISO1_DVD.nri
[2009-06-02 14:24:09 | 00,039,936 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\Irena Opis i analiza przypadku rozpoznania i rozwizania problemu wychowawczego uczennicy z problemami szkolnymi.doc
[2009-06-02 14:12:11 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\launch.exe
[2009-06-02 13:39:28 | 00,013,967 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\wirus.JPG
[2009-06-02 13:22:58 | 00,402,176 | ---- | C] (Panda Security) -- C:\Documents and Settings\User\Pulpit\USBVaccine.exe
[2009-06-02 13:19:27 | 00,001,548 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\CCleaner.lnk
[2009-06-02 13:19:27 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009-06-02 13:11:10 | 03,247,736 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\User\Pulpit\ccsetup220(2).exe
[2009-06-02 13:10:45 | 00,388,974 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\USBVaccine.zip
[2009-06-02 12:26:50 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009-06-02 08:11:45 | 00,096,768 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\JdaAKR4k.doc.part
[2009-06-02 05:15:20 | 00,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\User\Pulpit\HijackThis.exe
[2009-05-30 18:32:12 | 00,035,328 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\ANKIETA dobra.doc
[2009-05-11 13:51:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\User\Dane aplikacji\U3
[2009-01-24 11:08:44 | 00,000,036 | -H-- | C] () -- C:\WINDOWS\System32\swk.ini
[2008-12-19 13:13:10 | 00,003,350 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2008-12-19 13:13:10 | 00,000,088 | RHS- | C] () -- C:\WINDOWS\System32\CD2CCFDA61.sys
[2008-08-16 21:28:42 | 00,000,795 | ---- | C] () -- C:\WINDOWS\VPlayer.INI
[2008-05-04 18:05:20 | 00,002,271 | ---- | C] () -- C:\WINDOWS\bestplayer.ini
[2008-05-04 17:52:09 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-05-04 13:20:42 | 00,000,419 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008-04-26 15:11:00 | 00,000,911 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008-04-26 15:10:43 | 00,000,789 | ---- | C] () -- C:\WINDOWS\YDPDICT.INI
[2008-04-26 14:35:09 | 00,000,669 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-04-26 14:15:13 | 00,000,259 | ---- | C] () -- C:\WINDOWS\lgfwup.ini
[2008-04-26 14:01:08 | 00,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2008-04-26 13:54:27 | 00,000,558 | ---- | C] () -- C:\WINDOWS\DFC.INI
[2008-02-11 11:11:06 | 00,002,045 | -H-- | C] () -- C:\WINDOWS\System32\whlb32g.dll
[2007-03-01 07:36:37 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007-03-01 07:36:37 | 01,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007-03-01 07:36:37 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007-03-01 07:36:37 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2007-03-01 07:36:37 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007-03-01 07:36:37 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007-03-01 07:36:37 | 00,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006-05-22 13:47:24 | 00,008,704 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006-05-21 23:56:42 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2004-08-30 05:28:44 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2004-08-30 05:26:54 | 00,638,976 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2004-07-17 13:36:38 | 00,028,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2003-03-07 12:13:10 | 01,032,266 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2002-11-15 14:11:28 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\MMSwitch.dll
[2002-10-06 20:42:58 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2002-10-05 01:04:26 | 00,921,600 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2002-10-05 01:04:26 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\VORBIS.DLL
[2002-10-05 01:04:18 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\OGG.DLL
[2001-07-22 02:16:20 | 00,000,661 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 02:15:52 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[1997-06-14 02:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll

[color=orange]========== Files - Modified Within 30 Days ==========[/color]

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009-06-04 00:20:49 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Pulpit\OTListIt2.exe
[2009-06-04 00:20:00 | 00,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{16F4BEE2-7120-4C78-9AF3-28BCFB14059B}.job
[2009-06-04 00:13:12 | 00,089,134 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009-06-04 00:13:08 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-06-04 00:13:06 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\desktop.ini
[2009-06-04 00:13:05 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-06-03 18:28:01 | 01,370,996 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\PZU.jpg
[2009-06-03 15:09:22 | 00,003,213 | ---- | M] () -- C:\WINDOWS\bestplayer.bbt
[2009-06-03 15:09:22 | 00,002,271 | ---- | M] () -- C:\WINDOWS\bestplayer.ini
[2009-06-03 15:09:22 | 00,000,038 | ---- | M] () -- C:\WINDOWS\bestplayer.bpp
[2009-06-03 07:59:08 | 00,473,188 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\ISO1_DVD.nri
[2009-06-02 14:24:10 | 00,039,936 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\Irena Opis i analiza przypadku rozpoznania i rozwizania problemu wychowawczego uczennicy z problemami szkolnymi.doc
[2009-06-02 14:12:11 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\launch.exe
[2009-06-02 13:58:05 | 00,000,789 | ---- | M] () -- C:\WINDOWS\YDPDICT.INI
[2009-06-02 13:39:28 | 00,013,967 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\wirus.JPG
[2009-06-02 13:33:35 | 00,002,645 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009-06-02 13:19:27 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\CCleaner.lnk
[2009-06-02 13:11:10 | 03,247,736 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\User\Pulpit\ccsetup220(2).exe
[2009-06-02 13:10:59 | 00,388,974 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\USBVaccine.zip
[2009-06-02 08:11:46 | 00,096,768 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\JdaAKR4k.doc.part
[2009-05-30 20:08:32 | 00,012,288 | -H-- | M] () -- C:\Documents and Settings\User\Pulpit\photothumb.db
[2009-05-30 19:39:39 | 00,035,328 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\ANKIETA dobra.doc
[2009-05-22 17:15:55 | 00,000,374 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2009-05-19 16:41:41 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-05-11 13:17:37 | 00,003,072 | -H-- | M] () -- C:\Documents and Settings\User\Moje dokumenty\photothumb.db
< End of report >


Dodano Dzisiaj, 00:55:
Kod: Zaznacz wszystko
CZYSZCZENIE ZAKOŃCZONE - (0.845 sek)
------------------------------------------------------------------------------------------
23,0MB usunięto.
------------------------------------------------------------------------------------------

Szczegóły usuniętych plików
------------------------------------------------------------------------------------------
Tymczasowe pliki internetowe IE (10 pliki) 69,74KB
C:\Documents and Settings\User\Cookies\user@hit.gemius[1].txt 221 bajt(ów)
Opróżniono kosz (4 plików) 1,55MB
C:\WINDOWS\system32\wbem\Logs\wbemess.log 41,62KB
C:\WINDOWS\system32\wbem\Logs\wmiprov.log 4,66KB
C:\WINDOWS\system32\wbem\Logs\wbemess.lo_ 64,04KB
C:\WINDOWS\0.log 0 bajt(ów)
C:\WINDOWS\setupapi.log 6,00KB
C:\WINDOWS\Moje Gimnazjum Profil Humanistyczny Uninstall Log.txt 46,42KB
C:\WINDOWS\Debug\UserMode\userenv.log 13,77KB
Usunięto Cookie: http://www.wp.pl
Usunięto Cookie: wp.pl
Usunięto Cookie: openx.xenium.pl
Usunięto Cookie: hit.gemius.pl
Usunięto Cookie: dobreprogramy.pl
Usunięto Cookie: ad.adocean.pl
Usunięto Cookie: google.com
Usunięto Cookie: doubleclick.net
Usunięto Cookie: gde.adocean.pl
Usunięto Cookie: hit.stat.pl
Usunięto Cookie: recaptcha.net
Usunięto Cookie: ads.o2.pl
Usunięto Cookie: o2.pl
Usunięto Cookie: http://www.winiary.pl
Usunięto Cookie: my.adocean.pl
Usunięto Cookie: tradedoubler.com
Usunięto Cookie: xn--wylijto-epb.pl
Usunięto Cookie: http://www.xn--wylijto-epb.pl
Usunięto Cookie: advicepl.adocean.pl
Usunięto Cookie: lotechgde.adocean.pl
Usunięto Cookie: revsci.net
Usunięto Cookie: wyslijto.pl
Usunięto Cookie: wklejto.pl
Usunięto Cookie: google.pl
Usunięto Cookie: hub.com.pl
Usunięto Cookie: nuggad.net
Usunięto Cookie: forum.programosy.pl
Usunięto Cookie: drupal.org.pl
Usunięto Cookie: sms.ikp.pl
Usunięto Cookie: http://www.sms.ikp.pl
Usunięto Cookie: go.pol.bbelements.com
C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\ja67q5q1.default\downloads.sqlite 2,00KB
Firefox/Mozilla Temporary Internet Cache (255 pliki) 21,1MB
C:\Program Files\Ahead\Nero\NeroHistory.log 26,15KB
C:\Documents and Settings\User\Dane aplikacji\Macromedia\Flash Player\#SharedObjects\CD7A23CQ\s.ytimg.com\soundData.sol 58 bajt(ów)
C:\Documents and Settings\User\Dane aplikacji\Macromedia\Flash Player\#SharedObjects\CD7A23CQ\s.ytimg.com\videostats.sol 161 bajt(ów)
C:\Documents and Settings\User\Dane aplikacji\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#s.ytimg.com\settings.sol 81 bajt(ów)
------------------------------------------------------------------------------------------

Kod: Zaznacz wszystko
Ostatnio edytowany przez myszkomputerowa3, 04 Cze 2009, 17:28, edytowano w sumie 1 raz
myszkomputerowa3
~user
 
Posty: 3
Dołączenie: 03 Cze 2009, 23:14



Nmdfgds0.dll jak usunąć?

Postprzez Okocza 04 Cze 2009, 14:40

myszkomputerowa3, popraw tagi...
eMachines E730G - Core i5-430M, 2GiB RAM, ATI Mobility Radeon HD5470, WD 320GiB; Cort Z-44,DR 0.09-0.42, Peavey Backstage
Mac OS X 10.7.4 Lion // Windows 7 Professional x64 // NIE POMAGAM NA PW/GG/E-MAIL
Image
"Moje Ego i Anima spotykają się i wymieniają przepisami na ciasteczka" - Maynard James Keenan
Awatar użytkownika
Okocza
~user
 
Posty: 8001
Dołączenie: 19 Mar 2006, 11:53
Pochwały: 406




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 24 gości