
- Kod: Zaznacz wszystko
---------------------------
"D:\WINDOWS\eksplorasi.pif"
---------------------------
System Windows nie może odnaleźć pliku „"D:\WINDOWS\eksplorasi.pif"”. Upewnij się, że wpisana nazwa jest poprawna i spróbuj ponownie. Aby wyszukać plik, kliknij przycisk Start, a następnie kliknij polecenie Wyszukaj.
---------------------------
OK
---------------------------
GMER
- Kod: Zaznacz wszystko
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-04 17:16:19
Windows 5.1.2600 Dodatek Service Pack 3
Running: cn45j64z.exe; Driver: D:\DOCUME~1\Herzyk\USTAWI~1\Temp\uxkoqkod.sys
---- System - GMER 1.0.15 ----
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xB812887E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xB8128BFE]
---- Kernel code sections - GMER 1.0.15 ----
.text D:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6878380, 0x5414D5, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text D:\Program Files\ESET\ESET Smart Security\ekrn.exe[1372] kernel32.dll!SetUnhandledExceptionFilter 7C844935 4 Bytes [C2, 04, 00, 00]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x75 0x54 0x4D 0x15 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x75 0x54 0x4D 0x15 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{23a2ccea-582b-46ee-af0d-299c6b04c7c0}@Model 110
Reg HKLM\SOFTWARE\Classes\CLSID\{23a2ccea-582b-46ee-af0d-299c6b04c7c0}@Therad 8
Reg HKLM\SOFTWARE\Classes\CLSID\{23a2ccea-582b-46ee-af0d-299c6b04c7c0}@MData 0x73 0xD5 0xCF 0xB8 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}@scansk 0x93 0xAF 0xC6 0xAB ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}@scansk 0xCF 0xC3 0x30 0x4F ...
Reg HKLM\SOFTWARE\Classes\CLSID\{9c656f87-85ff-4a7c-b94b-8744a96d30af}@Model 46
Reg HKLM\SOFTWARE\Classes\CLSID\{9c656f87-85ff-4a7c-b94b-8744a96d30af}@Therad 31
Reg HKLM\SOFTWARE\Classes\CLSID\{9c656f87-85ff-4a7c-b94b-8744a96d30af}@MData 0x2B 0x8F 0x78 0x29 ...
---- EOF - GMER 1.0.15 ----
OTL
- Kod: Zaznacz wszystko
OTL logfile created on: 2010-05-04 17:32:36 - Run 2
OTL by OldTimer - Version 3.2.4.0 Folder = D:\Documents and Settings\Herzyk\Moje dokumenty\Pobieranie
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 83,00% Memory free
5,00 Gb Paging File | 5,00 Gb Available in Paging File | 93,00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 127,99 Gb Total Space | 8,48 Gb Free Space | 6,63% Space Free | Partition Type: NTFS
Drive D: | 250,00 Gb Total Space | 44,48 Gb Free Space | 17,79% Space Free | Partition Type: NTFS
Drive E: | 218,18 Gb Total Space | 97,06 Gb Free Space | 44,49% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HERZYK-6A3EBC1C
Current User Name: Herzyk
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2010-05-03 01:09:49 | 000,570,880 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Herzyk\Moje dokumenty\Pobieranie\OTL(2).exe
PRC - [2010-04-02 23:27:45 | 000,908,248 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010-03-10 16:14:30 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- D:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010-01-25 13:45:54 | 003,179,952 | ---- | M] (Tonec Inc.) -- D:\Program Files\Internet Download Manager\IDMan.exe
PRC - [2010-01-18 15:27:37 | 000,386,872 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\Java\jre6\bin\jucheck.exe
PRC - [2009-12-21 07:45:56 | 000,039,424 | ---- | M] (Nullsoft) -- D:\Program Files\Winamp\winampa.exe
PRC - [2009-10-15 11:51:51 | 000,263,600 | ---- | M] (Tonec Inc.) -- D:\Program Files\Internet Download Manager\IEMonitor.exe
PRC - [2009-09-10 15:45:00 | 001,035,264 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
PRC - [2009-02-06 15:23:36 | 000,727,720 | ---- | M] (ESET) -- D:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2009-02-06 15:23:12 | 002,021,400 | ---- | M] (ESET) -- D:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2009-01-08 15:44:06 | 000,070,936 | ---- | M] (Octoshape ApS) -- D:\Documents and Settings\Herzyk\Dane aplikacji\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
PRC - [2008-10-31 21:04:40 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- D:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2008-10-08 00:41:36 | 000,023,552 | ---- | M] (Creative Technology Ltd) -- D:\WINDOWS\system32\Ctxfihlp.exe
PRC - [2008-10-08 00:37:38 | 001,212,928 | ---- | M] (Creative Technology Ltd) -- D:\WINDOWS\system32\CTxfispi.exe
PRC - [2008-04-04 11:38:00 | 000,088,584 | ---- | M] (Logitech Inc.) -- D:\Program Files\Logitech\Gaming Software\LWEMon.exe
PRC - [2007-09-07 15:54:54 | 000,159,744 | ---- | M] () -- D:\Program Files\Razer\DeathAdder\razerhid.exe
PRC - [2007-05-07 15:35:14 | 000,163,840 | ---- | M] (Razer Inc.) -- D:\Program Files\Razer\DeathAdder\razerofa.exe
PRC - [2006-11-24 15:24:16 | 000,143,360 | ---- | M] () -- D:\Program Files\Razer\DeathAdder\razertra.exe
PRC - [2004-08-28 20:27:04 | 000,295,424 | ---- | M] (http://autoconnect.prv.pl) -- D:\Program Files\AutoConnect\AutoConnect.exe
PRC - [2004-01-26 13:38:38 | 000,866,816 | ---- | M] (THOMSON Telecom Belgium) -- D:\Program Files\Thomson\SpeedTouch USB\dragdiag.exe
[color=#E56717]========== Modules (SafeList) ==========[/color]
MOD - [2010-05-03 01:09:49 | 000,570,880 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Herzyk\Moje dokumenty\Pobieranie\OTL(2).exe
MOD - [2009-09-10 15:45:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\msscript.ocx
MOD - [2009-03-26 17:35:39 | 000,034,224 | ---- | M] (Tonec Inc.) -- D:\Program Files\Internet Download Manager\idmmkb.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - File not found [Auto | Stopped] -- -- (AntiVirUpgradeService)
SRV - File not found [Auto | Stopped] -- -- (.EsetTrialReset)
SRV - [2010-04-17 23:31:29 | 001,265,264 | ---- | M] (Lavasoft) [On_Demand | Stopped] -- D:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010-01-30 19:27:32 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- D:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2010-01-27 20:46:35 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009-02-06 15:27:06 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- D:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009-02-06 15:23:36 | 000,727,720 | ---- | M] (ESET) [Auto | Running] -- D:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2008-10-31 21:04:40 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- D:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2010-05-03 23:59:47 | 000,138,592 | ---- | M] () [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK)
DRV - [2010-04-17 23:32:45 | 000,095,024 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\SBREDrv.sys -- (SBRE)
DRV - [2010-03-30 23:38:26 | 000,020,968 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | Auto | Running] -- D:\WINDOWS\system32\drivers\cpuz133_x32.sys -- (cpuz133)
DRV - [2010-02-04 17:53:02 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- D:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009-11-21 04:34:54 | 010,235,968 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2009-09-10 15:45:00 | 000,215,856 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- D:\WINDOWS\system32\drivers\Si3132r5.sys -- (Si3132r5)
DRV - [2009-09-10 15:45:00 | 000,212,520 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- D:\WINDOWS\system32\drivers\Si3531.sys -- (Si3531)
DRV - [2009-09-10 15:45:00 | 000,195,072 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Stopped] -- D:\WINDOWS\system32\drivers\Si3114r5.sys -- (Si3114r5)
DRV - [2009-09-10 15:45:00 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2009-09-10 15:45:00 | 000,074,672 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- D:\WINDOWS\system32\drivers\si3132.sys -- (Si3132)
DRV - [2009-09-10 15:45:00 | 000,069,248 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- D:\WINDOWS\system32\drivers\si3124.sys -- (Si3124)
DRV - [2009-09-10 15:45:00 | 000,062,336 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- D:\WINDOWS\system32\drivers\si3112.sys -- (Si3112)
DRV - [2009-07-10 05:03:04 | 001,381,632 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009-02-10 18:23:02 | 000,082,320 | ---- | M] (EZB Systems, Inc.) [File_System | System | Running] -- D:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive)
DRV - [2009-02-06 15:24:22 | 000,056,280 | ---- | M] (ESET) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi)
DRV - [2009-02-06 15:24:22 | 000,033,096 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2009-02-06 15:24:18 | 000,130,952 | ---- | M] (ESET) [Kernel | Auto | Running] -- D:\WINDOWS\system32\drivers\epfw.sys -- (epfw)
DRV - [2009-02-06 15:23:18 | 000,106,208 | ---- | M] (ESET) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009-02-06 15:19:52 | 000,113,448 | ---- | M] (ESET) [File_System | Auto | Running] -- D:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2008-10-08 02:22:04 | 001,177,624 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ha20x2k.sys -- (ha20x2k)
DRV - [2008-10-08 02:22:02 | 000,095,768 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia)
DRV - [2008-10-08 02:22:00 | 000,158,744 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2008-10-08 02:21:58 | 000,014,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV - [2008-10-08 02:21:56 | 000,130,072 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2008-10-08 02:21:54 | 000,347,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ctdvda2k.sys -- (ctdvda2k)
DRV - [2008-10-08 02:21:50 | 000,526,232 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)
DRV - [2008-10-08 02:21:46 | 000,511,000 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k)
DRV - [2008-10-08 02:21:44 | 001,324,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- D:\WINDOWS\System32\drivers\CTEXFIFX.SYS -- (CTEXFIFX.SYS)
DRV - [2008-10-08 02:21:44 | 001,324,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\CTEXFIFX.sys -- (CTEXFIFX)
DRV - [2008-10-08 02:21:40 | 000,072,728 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- D:\WINDOWS\System32\drivers\CTHWIUT.SYS -- (CTHWIUT.SYS)
DRV - [2008-10-08 02:21:40 | 000,072,728 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\CTHWIUT.sys -- (CTHWIUT)
DRV - [2008-10-08 02:21:38 | 000,171,032 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- D:\WINDOWS\System32\drivers\CT20XUT.SYS -- (CT20XUT.SYS)
DRV - [2008-10-08 02:21:38 | 000,171,032 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\CT20XUT.sys -- (CT20XUT)
DRV - [2008-08-14 08:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- D:\WINDOWS\system32\drivers\adfs.sys -- (adfs)
DRV - [2008-01-24 15:09:34 | 000,048,904 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2008-01-24 15:09:24 | 000,014,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2008-01-24 15:09:14 | 000,029,192 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\WmHidLo.sys -- (WmHidLo)
DRV - [2008-01-24 15:09:04 | 000,028,168 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2008-01-24 15:08:54 | 000,019,336 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2007-12-17 11:14:06 | 000,012,400 | R--- | M] () [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO)
DRV - [2007-09-21 04:11:02 | 000,028,432 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2007-09-21 04:10:54 | 000,078,992 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2007-09-21 04:10:46 | 000,036,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2007-09-21 04:10:40 | 000,035,088 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007-09-21 04:10:26 | 000,063,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2007-09-21 04:10:20 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2007-08-02 17:32:26 | 000,022,784 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\dadder.sys -- (DAdderFltr)
DRV - [2006-11-08 22:19:18 | 000,004,544 | ---- | M] (SweetLow) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\hidusbf.sys -- (hidusbf)
DRV - [2005-08-18 01:00:00 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- D:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt -- (EverestDriver)
DRV - [2004-08-13 04:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2003-12-08 13:53:48 | 000,053,600 | ---- | M] (THOMSON) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\alcan5wn.sys -- (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN)
DRV - [2003-12-08 13:53:46 | 000,070,688 | ---- | M] (THOMSON) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\alcaudsl.sys -- (alcaudsl)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1060284298-1390067357-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
IE - HKU\S-1-5-21-1060284298-1390067357-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "www.google.pl"
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.1.0014
FF - prefs.js..extensions.enabledItems: mozilla_cc@internetdownloadmanager.com:6.7
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010-04-02 23:27:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010-04-02 23:27:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.1\extensions\\Components: D:\Program Files\Mozilla Thunderbird\components [2010-03-10 16:14:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: D:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010-03-09 19:56:52 | 000,000,000 | ---D | M]
[2010-02-02 22:50:03 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Mozilla\Extensions
[2010-02-02 22:50:03 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Herzyk\Dane aplikacji\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010-05-04 14:44:15 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Mozilla\Firefox\Profiles\uc046z20.default\extensions
[2010-01-21 15:32:09 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Mozilla\Firefox\Profiles\uc046z20.default\extensions\DTToolbar@toolbarnet.com
[2010-01-21 15:31:59 | 000,002,055 | ---- | M] () -- D:\Documents and Settings\Herzyk\Dane aplikacji\Mozilla\Firefox\Profiles\uc046z20.default\searchplugins\daemon-search.xml
[2010-05-04 14:44:15 | 000,000,000 | ---D | M] -- D:\Program Files\Mozilla Firefox\extensions
[2009-12-21 07:47:02 | 000,063,488 | ---- | M] (Nullsoft) -- D:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2010-04-02 23:27:49 | 000,002,767 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2010-04-02 23:27:49 | 000,001,406 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2010-04-02 23:27:49 | 000,000,917 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2010-04-02 23:27:49 | 000,000,858 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2010-04-02 23:27:49 | 000,001,183 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2010-04-02 23:27:49 | 000,001,683 | ---- | M] () -- D:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml
O1 HOSTS File: ([2010-04-14 23:29:27 | 000,012,527 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
O1 - Hosts: <html lang='en'>
O1 - Hosts: <head>
O1 - Hosts: <meta name="description" content="Yahoo! GeoCities offers you a free web site and all the tools you need to build a dynamic site. Features include easy-to-use site building tools, online help, web site statistics, secure and reliable hosting, and an intuitive control panel.">
O1 - Hosts: <title>Yahoo! GeoCities: Get a web site with easy-to-use site building tools.</title>
O1 - Hosts: <link rel="stylesheet" type="text/css" media="all" href="http://l.yimg.com/a/combo?yui/2.5.2/build/reset-fonts-grids/reset-fonts-grids.css&smbiz/css/headfoot_6.css&smbiz/css/ysbs_glossary_1.css">
O1 - Hosts: <link rel="stylesheet" type="text/css" media="all" href="http://us.i1.yimg.com/us.yimg.com/lib/smbiz/css/geocities_84954.css">
O1 - Hosts: <style>
O1 - Hosts: h1 { line-height:30px;height:30px; padding-left:15px; font-weight:bold;font-size:1.6em;color:#1f296a;}
O1 - Hosts: .services li { margin-left:1.0em; padding-left:0.5em; background:url("http://l.yimg.com/a/lib/smbiz/i/geo_bullet_3x3_1.gif") no-repeat 0 0.5em; margin-bottom:0.5em;margin-left:1.5em;margin-right:0.5em;width:6em}
O1 - Hosts: .services li {float:left; width:17em; font-size:116%;margin-top:0.8em}
O1 - Hosts: .services { font-size:116%; padding-bottom:20px }
O1 - Hosts: .learnmore a {color:#2882DE;font-size:16px}
O1 - Hosts: .image_web {float:right; margin:15px 0 0 15px}
O1 - Hosts: p {margin:20px;font-size:1em;}
O1 - Hosts: h2 {margin:20px 0 0 20px;color:#1F296;font-weight:bold;font-size:1.25em;color:#1f296a;}
O1 - Hosts: h3 {margin:20px;color:#1F296;font-weight:bold;font-size:1.15em;color:#1f296a;}
O1 - Hosts: li.rule {border-top:solid 1px #DBE1E6;}
O1 - Hosts: </style>
O1 - Hosts: </head>
O1 - Hosts: <body>
O1 - Hosts: <!-- following code added by server. PLEASE REMOVE -->
O1 - Hosts: <!-- preceding code added by server. PLEASE REMOVE -->
O1 - Hosts: <div class="ez-mw" style ="height:900px;width:905px">
O1 - Hosts: <div class="ez-wri ez-oh" style="width:900px">
O1 - Hosts: 91 more lines...
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-1060284298-1390067357-1801674531-1003\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [CTxfiHlp] D:\WINDOWS\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DeathAdder] D:\Program Files\Razer\DeathAdder\razerhid.exe ()
O4 - HKLM..\Run: [egui] D:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] D:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] D:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [SpeedTouch USB Diagnostics] D:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe (THOMSON Telecom Belgium)
O4 - HKLM..\Run: [Start WingMan Profiler] D:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [TkBellExe] D:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe (Nullsoft)
O4 - HKU\S-1-5-21-1060284298-1390067357-1801674531-1003..\Run: [AutoConnect] D:\Program Files\AutoConnect\AutoConnect.exe (http://autoconnect.prv.pl)
O4 - HKU\S-1-5-21-1060284298-1390067357-1801674531-1003..\Run: [Desktop Security 2010] D:\Documents and Settings\Herzyk\Dane aplikacji\Desktop Security 2010\Desktop Security 2010.exe File not found
O4 - HKU\S-1-5-21-1060284298-1390067357-1801674531-1003..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKU\S-1-5-21-1060284298-1390067357-1801674531-1003..\Run: [Octoshape Streaming Services] D:\Documents and Settings\Herzyk\Dane aplikacji\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKU\S-1-5-21-1060284298-1390067357-1801674531-1003..\Run: [SecurityCenter] D:\Documents and Settings\Herzyk\Dane aplikacji\Desktop Security 2010\securitycenter.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1060284298-1390067357-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1060284298-1390067357-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 48
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - D:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Ściągnij przez IDM - D:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Ściągnij wszystkie linki przez IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Ściągnij zawartość wideo FLV przez IDM - D:\Program Files\Internet Download Manager\IEGetVL.htm ()
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - D:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - D:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - ("D:\WINDOWS\eksplorasi.pif") - D:\WINDOWS\eksplorasi.pif File not found
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: D:\Documents and Settings\Herzyk\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\Herzyk\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-03-08 16:46:58 | 000,000,007 | -HS- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010-03-09 22:33:19 | 000,000,051 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-03-09 22:33:19 | 000,000,051 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010-03-09 22:33:19 | 000,000,051 | RHS- | M] () - E:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{4204ec5d-25ec-11df-bd19-000e507efed3}\Shell\AutoRun\command - "" = J:\k1d.exe -- File not found
O33 - MountPoints2\{4204ec5d-25ec-11df-bd19-000e507efed3}\Shell\open\Command - "" = J:\k1d.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - D:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2010-05-04 02:26:37 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Herzyk\Application Data
[2010-05-02 21:45:44 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Desktop Security 2010
[2010-04-29 14:16:00 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data
[2010-04-29 01:20:28 | 000,069,632 | ---- | C] (HP) -- D:\WINDOWS\System32\HPZipm12.exe
[2010-04-29 01:20:28 | 000,065,536 | ---- | C] (HP) -- D:\WINDOWS\System32\HPZinw12.exe
[2010-04-29 01:20:25 | 000,306,688 | ---- | C] (InstallShield Software Corporation) -- D:\WINDOWS\IsUninst.exe
[2010-04-29 01:16:52 | 000,098,304 | ---- | C] (Hewlett Packard Company) -- D:\WINDOWS\System32\hpzjsn01.dll
[2010-04-25 17:27:31 | 000,000,000 | ---D | C] -- D:\Program Files\Defraggler
[2010-04-25 17:25:54 | 000,000,000 | ---D | C] -- D:\Program Files\Audacity
[2010-04-25 16:08:44 | 000,000,000 | ---D | C] -- D:\Program Files\MP3Gain
[2010-04-24 15:33:35 | 000,000,000 | ---D | C] -- D:\Program Files\GoldWave
[2010-04-20 15:25:48 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Herzyk\Ustawienia lokalne\Dane aplikacji\Ubisoft
[2010-04-19 21:23:07 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\Ubisoft
[2010-04-17 23:32:48 | 000,095,024 | ---- | C] (Sunbelt Software) -- D:\WINDOWS\System32\drivers\SBREDrv.sys
[2010-04-17 23:20:14 | 000,000,000 | -H-D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010-04-17 23:20:04 | 000,000,000 | ---D | C] -- D:\Program Files\Lavasoft
[2010-04-15 19:51:39 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Herzyk\Moje dokumenty\Hitman Blood Money
[2010-04-15 19:37:14 | 000,000,000 | ---D | C] -- D:\Program Files\Hitman - Krwawa Forsa
[2010-04-15 15:09:22 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\JonIon Games
[2010-04-14 23:28:49 | 000,000,000 | ---D | C] -- D:\Program Files\Trend Micro
[2010-04-14 20:20:22 | 000,000,000 | -HSD | C] -- D:\Documents and Settings\Herzyk\IECompatCache
[2010-04-11 11:35:22 | 000,000,000 | -HSD | C] -- D:\WINDOWS\CSC
[2010-04-09 18:18:38 | 000,000,000 | ---D | C] -- D:\Program Files\DIFX
[2010-04-09 18:18:28 | 000,022,784 | ---- | C] (Razer (Asia-Pacific) Pte Ltd) -- D:\WINDOWS\System32\drivers\dadder.sys
[2010-04-09 18:18:27 | 000,031,104 | ---- | C] (Cypress Semiconductor) -- D:\WINDOWS\System32\drivers\CYUSB.sys
[2010-04-09 18:18:17 | 000,073,728 | ---- | C] (Razer Inc.) -- D:\WINDOWS\System32\DeathAdder.cpl
[2010-04-09 18:18:15 | 000,000,000 | ---D | C] -- D:\Program Files\Razer
[2010-04-09 18:17:57 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Herzyk\Dane aplikacji\InstallShield
[2010-04-08 01:56:54 | 000,000,000 | ---D | C] -- D:\Program Files\K-Lite Codec Pack
[2010-04-08 01:56:45 | 000,000,000 | ---D | C] -- D:\Program Files\MP4 Player 3.5
[2010-04-06 11:00:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Herzyk\Moje dokumenty\Settlers7
[2010-04-05 19:35:18 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Herzyk\Ustawienia lokalne\Dane aplikacji\Logitech
[2010-04-05 19:28:54 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Logitech
[2008-10-08 00:42:42 | 000,060,928 | ---- | C] ( ) -- D:\WINDOWS\System32\a3d.dll
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2010-05-04 17:19:37 | 000,273,035 | ---- | M] () -- D:\WINDOWS\System32\NvApps.xml
[2010-05-04 17:19:36 | 000,000,280 | ---- | M] () -- D:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1390067357-1801674531-1003.job
[2010-05-04 17:19:30 | 000,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2010-05-04 17:19:29 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2010-05-04 03:24:01 | 005,767,168 | -H-- | M] () -- D:\Documents and Settings\Herzyk\NTUSER.DAT
[2010-05-04 03:24:00 | 000,055,440 | ---- | M] () -- D:\WINDOWS\System32\BMXStateBkp-{00000006-00000000-00000002-00001102-00000005-002C1102}.rfx
[2010-05-04 03:24:00 | 000,055,440 | ---- | M] () -- D:\WINDOWS\System32\BMXState-{00000006-00000000-00000002-00001102-00000005-002C1102}.rfx
[2010-05-04 03:24:00 | 000,000,788 | ---- | M] () -- D:\WINDOWS\System32\DVCState-{00000006-00000000-00000002-00001102-00000005-002C1102}.rfx
[2010-05-03 23:59:47 | 000,138,592 | ---- | M] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010-05-03 23:59:27 | 000,219,128 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrB.xtr
[2010-05-03 23:58:07 | 000,288,761 | ---- | M] () -- D:\Documents and Settings\Herzyk\Pulpit\gvfejk.JPG
[2010-05-02 21:03:00 | 000,000,288 | ---- | M] () -- D:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1390067357-1801674531-1003.job
[2010-05-01 13:39:10 | 000,041,472 | ---- | M] () -- D:\Documents and Settings\Herzyk\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-04-30 18:36:16 | 000,000,827 | ---- | M] () -- D:\Documents and Settings\Herzyk\Pulpit\Splinter Cell Double Agent.lnk
[2010-04-29 17:16:31 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2010-04-29 16:31:55 | 000,000,188 | -HS- | M] () -- D:\Documents and Settings\Herzyk\ntuser.ini
[2010-04-29 14:14:54 | 000,000,632 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Splinter Cell - Double Agent.lnk
[2010-04-29 01:40:50 | 000,113,025 | ---- | M] () -- D:\WINDOWS\hpoins11.dat
[2010-04-29 01:22:57 | 000,113,025 | ---- | M] () -- D:\WINDOWS\hpoins11.dat.temp
[2010-04-27 17:34:56 | 000,038,113 | ---- | M] () -- D:\Documents and Settings\Herzyk\Pulpit\tede.JPG
[2010-04-27 10:45:26 | 000,000,514 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Steam.lnk
[2010-04-27 03:15:29 | 000,002,064 | ---- | M] () -- D:\WINDOWS\System32\settingsbkup.sfm
[2010-04-27 03:15:29 | 000,002,064 | ---- | M] () -- D:\WINDOWS\System32\settings.sfm
[2010-04-25 17:27:32 | 000,001,580 | ---- | M] () -- D:\Documents and Settings\Herzyk\Pulpit\Defraggler.lnk
[2010-04-25 17:25:57 | 000,000,630 | ---- | M] () -- D:\Documents and Settings\Herzyk\Pulpit\Audacity.lnk
[2010-04-24 15:36:48 | 010,539,958 | ---- | M] () -- D:\Documents and Settings\Herzyk\Pulpit\asasasas.wav
[2010-04-24 15:33:38 | 000,000,471 | ---- | M] () -- D:\Documents and Settings\Herzyk\Pulpit\GoldWave.lnk
[2010-04-22 14:00:09 | 000,000,412 | ---- | M] () -- D:\Documents and Settings\Herzyk\Moje dokumenty\spider.sav
[2010-04-19 21:23:10 | 000,000,769 | ---- | M] () -- D:\Documents and Settings\Herzyk\Pulpit\Tom Clancy's Splinter Cell Chaos Theory.lnk
[2010-04-17 23:32:45 | 000,095,024 | ---- | M] (Sunbelt Software) -- D:\WINDOWS\System32\drivers\SBREDrv.sys
[2010-04-17 23:32:34 | 000,015,880 | ---- | M] () -- D:\WINDOWS\System32\lsdelete.exe
[2010-04-17 23:20:13 | 000,000,867 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Ad-Aware.lnk
[2010-04-16 22:26:30 | 000,041,872 | ---- | M] () -- D:\WINDOWS\System32\xfcodec.dll
[2010-04-15 19:42:12 | 000,001,543 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Hitman - Krwawa Forsa.lnk
[2010-04-14 23:29:27 | 000,012,527 | ---- | M] () -- D:\WINDOWS\System32\drivers\etc\hosts
[2010-04-14 23:28:49 | 000,001,734 | ---- | M] () -- D:\Documents and Settings\Herzyk\Pulpit\HijackThis.lnk
[2010-04-12 20:41:57 | 003,349,784 | ---- | M] () -- D:\Documents and Settings\Herzyk\Moje dokumenty\Grudzień 2009-Wigilia II C 211.jpg
[2010-04-11 11:29:41 | 000,054,472 | ---- | M] () -- D:\WINDOWS\System32\BMXStateBkp-{00000007-00000000-00000002-00001102-00000005-002C1102}.rfx
[2010-04-11 11:29:41 | 000,054,472 | ---- | M] () -- D:\WINDOWS\System32\BMXState-{00000007-00000000-00000002-00001102-00000005-002C1102}.rfx
[2010-04-11 11:29:41 | 000,000,788 | ---- | M] () -- D:\WINDOWS\System32\DVCState-{00000007-00000000-00000002-00001102-00000005-002C1102}.rfx
[2010-04-10 11:43:16 | 001,736,507 | ---- | M] () -- D:\Documents and Settings\Herzyk\Moje dokumenty\Zdjęcie666.jpg
[2010-04-10 11:42:29 | 001,713,010 | ---- | M] () -- D:\Documents and Settings\Herzyk\Moje dokumenty\Zdjęcie665.jpg
[2010-04-10 10:48:38 | 000,548,910 | ---- | M] () -- D:\Documents and Settings\Herzyk\Pulpit\ddd.bmp
[2010-04-09 18:09:48 | 000,000,760 | ---- | M] () -- D:\Documents and Settings\Herzyk\Dane aplikacji\setup_ldm.iss
[2010-04-08 01:53:29 | 029,079,165 | ---- | M] () -- D:\PLcom.mp4
[2010-04-07 03:10:16 | 007,433,894 | -H-- | M] () -- D:\Documents and Settings\Herzyk\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2010-04-06 10:58:12 | 000,000,792 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\The Settlers 7 - Droga do królestwa.lnk
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2010-05-03 23:58:07 | 000,288,761 | ---- | C] () -- D:\Documents and Settings\Herzyk\Pulpit\gvfejk.JPG
[2010-04-30 18:36:16 | 000,000,827 | ---- | C] () -- D:\Documents and Settings\Herzyk\Pulpit\Splinter Cell Double Agent.lnk
[2010-04-29 14:14:54 | 000,000,632 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\Splinter Cell - Double Agent.lnk
[2010-04-29 01:32:12 | 000,113,025 | ---- | C] () -- D:\WINDOWS\hpoins11.dat
[2010-04-29 01:31:56 | 000,006,947 | ---- | C] () -- D:\WINDOWS\hpomdl11.dat
[2010-04-29 01:28:46 | 000,113,025 | ---- | C] () -- D:\WINDOWS\hpoins11.dat.temp
[2010-04-29 01:28:46 | 000,006,947 | ---- | C] () -- D:\WINDOWS\hpomdl11.dat.temp
[2010-04-27 17:34:56 | 000,038,113 | ---- | C] () -- D:\Documents and Settings\Herzyk\Pulpit\tede.JPG
[2010-04-25 17:27:32 | 000,001,580 | ---- | C] () -- D:\Documents and Settings\Herzyk\Pulpit\Defraggler.lnk
[2010-04-25 17:25:57 | 000,000,630 | ---- | C] () -- D:\Documents and Settings\Herzyk\Pulpit\Audacity.lnk
[2010-04-24 15:36:48 | 010,539,958 | ---- | C] () -- D:\Documents and Settings\Herzyk\Pulpit\asasasas.wav
[2010-04-24 15:33:38 | 000,000,471 | ---- | C] () -- D:\Documents and Settings\Herzyk\Pulpit\GoldWave.lnk
[2010-04-22 14:00:09 | 000,000,412 | ---- | C] () -- D:\Documents and Settings\Herzyk\Moje dokumenty\spider.sav
[2010-04-19 21:23:10 | 000,000,769 | ---- | C] () -- D:\Documents and Settings\Herzyk\Pulpit\Tom Clancy's Splinter Cell Chaos Theory.lnk
[2010-04-17 23:20:13 | 000,000,867 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\Ad-Aware.lnk
[2010-04-16 22:26:30 | 000,041,872 | ---- | C] () -- D:\WINDOWS\System32\xfcodec.dll
[2010-04-15 19:42:12 | 000,001,543 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\Hitman - Krwawa Forsa.lnk
[2010-04-14 23:28:49 | 000,001,734 | ---- | C] () -- D:\Documents and Settings\Herzyk\Pulpit\HijackThis.lnk
[2010-04-12 20:40:15 | 003,349,784 | ---- | C] () -- D:\Documents and Settings\Herzyk\Moje dokumenty\Grudzień 2009-Wigilia II C 211.jpg
[2010-04-10 11:42:14 | 001,736,507 | ---- | C] () -- D:\Documents and Settings\Herzyk\Moje dokumenty\Zdjęcie666.jpg
[2010-04-10 11:41:32 | 001,713,010 | ---- | C] () -- D:\Documents and Settings\Herzyk\Moje dokumenty\Zdjęcie665.jpg
[2010-04-10 10:48:37 | 000,548,910 | ---- | C] () -- D:\Documents and Settings\Herzyk\Pulpit\ddd.bmp
[2010-04-08 01:58:11 | 029,079,165 | ---- | C] () -- D:\PLcom.mp4
[2010-04-08 01:56:57 | 000,168,448 | ---- | C] () -- D:\WINDOWS\System32\unrar.dll
[2010-04-06 10:58:12 | 000,000,792 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\The Settlers 7 - Droga do królestwa.lnk
[2010-03-09 22:17:21 | 000,000,319 | ---- | C] () -- D:\WINDOWS\game.ini
[2010-01-30 20:51:04 | 000,024,576 | R--- | C] () -- D:\WINDOWS\System32\AsIO.dll
[2010-01-30 20:51:04 | 000,012,400 | R--- | C] () -- D:\WINDOWS\System32\drivers\AsIO.sys
[2010-01-30 20:51:02 | 000,011,832 | ---- | C] () -- D:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2010-01-30 20:51:02 | 000,010,216 | ---- | C] () -- D:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2010-01-30 18:44:12 | 000,005,810 | R--- | C] () -- D:\WINDOWS\System32\drivers\ASACPI.sys
[2010-01-30 18:44:03 | 000,001,769 | ---- | C] () -- D:\WINDOWS\Language_trs.ini
[2010-01-30 18:43:57 | 000,024,318 | ---- | C] () -- D:\WINDOWS\Ascd_tmp.ini
[2010-01-30 18:43:54 | 000,010,296 | ---- | C] () -- D:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010-01-19 02:13:57 | 000,881,664 | ---- | C] () -- D:\WINDOWS\System32\xvidcore.dll
[2010-01-19 02:06:47 | 000,000,547 | ---- | C] () -- D:\WINDOWS\System32\ff_vfw.dll.manifest
[2010-01-19 02:06:46 | 000,085,504 | ---- | C] () -- D:\WINDOWS\System32\ff_vfw.dll
[2010-01-17 00:30:25 | 000,138,592 | ---- | C] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009-12-31 03:00:34 | 000,005,606 | ---- | C] () -- D:\WINDOWS\System32\stci.dll
[2009-08-03 01:21:54 | 000,197,912 | ---- | C] () -- D:\WINDOWS\System32\physxcudart_20.dll
[2009-08-03 01:21:54 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009-08-03 01:21:54 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSwedish.dll
[2009-08-03 01:21:54 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSpanish.dll
[2009-08-03 01:21:54 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009-08-03 01:21:54 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelPortugese.dll
[2009-08-03 01:21:54 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelKorean.dll
[2009-08-03 01:21:54 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelJapanese.dll
[2009-08-03 01:21:52 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelGerman.dll
[2009-08-03 01:21:52 | 000,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelFrench.dll
[2008-10-08 01:08:38 | 000,020,936 | ---- | C] () -- D:\WINDOWS\System32\instwdm.ini
[2008-10-08 00:41:40 | 000,002,560 | ---- | C] () -- D:\WINDOWS\System32\CtxfiRes.dll
[2008-10-08 00:41:40 | 000,002,560 | ---- | C] () -- D:\WINDOWS\CTXFIRES.DLL
[2008-09-12 22:22:40 | 000,000,054 | ---- | C] () -- D:\WINDOWS\System32\ctzapxx.ini
[2008-08-19 19:39:18 | 000,000,321 | ---- | C] () -- D:\WINDOWS\System32\kill.ini
[color=#E56717]========== LOP Check ==========[/color]
[2010-01-21 15:31:35 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite
[2010-03-09 19:56:50 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\ESET
[2010-02-25 15:09:57 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10
[2010-04-15 15:09:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\JonIon Games
[2010-01-17 01:25:07 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\Last.fm
[2010-03-11 05:05:29 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\Mistrz Klawiatury II Data
[2010-01-30 19:02:01 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\PC Drivers HeadQuarters
[2010-04-19 21:23:07 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\Ubisoft
[2010-04-17 23:20:15 | 000,000,000 | -H-D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010-01-21 15:39:08 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\DAEMON Tools Lite
[2010-05-03 01:06:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Desktop Security 2010
[2010-05-04 17:19:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\DMCache
[2010-03-09 19:59:14 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\ESET
[2010-04-04 10:42:24 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Facebook
[2010-02-25 15:09:54 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Gadu-Gadu 10
[2010-03-28 23:21:39 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\GHISLER
[2010-04-24 22:13:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\HLSW
[2010-02-22 20:30:28 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\IDM
[2010-01-29 22:32:46 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Leadertech
[2010-05-03 10:44:55 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Nowe Gadu-Gadu
[2010-01-24 16:19:32 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Octoshape
[2010-02-06 05:31:54 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\The Creative Assembly
[2010-02-02 22:49:56 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\Thunderbird
[2010-01-27 21:03:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Herzyk\Dane aplikacji\TS3Client
[color=#E56717]========== Purity Check ==========[/color]
< End of report >
OTL EXTRAS http://www.wklej.org/id/328043/