x-kom hosting

Logi do sprawdzenia - OTL+RSIT

simivar
utworzono
utworzono (edytowane)

[log]OTL logfile created on: 2009-12-02 22:09:04 - Run 1
OTL by OldTimer - Version 3.1.11.4 Folder = C:\Documents and Settings\M4g\Pulpit
Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 1,11 Gb Available Physical Memory | 55,75% Memory free
3,85 Gb Paging File | 2,98 Gb Available in Paging File | 77,51% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232,42 Gb Total Space | 179,21 Gb Free Space | 77,10% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PRO-25831CBED72
Current User Name: M4g
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (All) ==========[/color]

PRC - [2009-12-02 22:08:14 | 00,535,552 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\M4g\Pulpit\OTL.exe
PRC - [2009-11-23 11:56:06 | 11,797,096 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe
PRC - [2009-11-23 10:39:56 | 00,077,824 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\spellchecker_gg.exe
PRC - [2009-11-19 21:28:18 | 00,470,273 | ---- | M] (Avira GmbH) -- c:\Program Files\Avira\AntiVir Desktop\avcenter.exe
PRC - [2009-11-19 21:28:18 | 00,466,689 | ---- | M] (Avira GmbH) -- c:\Program Files\Avira\AntiVir Desktop\avscan.exe
PRC - [2009-11-07 20:09:03 | 00,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-11-01 19:23:14 | 01,217,808 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2009-10-20 18:15:22 | 00,528,384 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\open-fm.exe
PRC - [2009-10-11 04:17:36 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009-10-11 04:17:35 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009-08-19 09:53:18 | 07,418,368 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2009-08-19 09:52:16 | 07,424,000 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009-07-21 13:34:33 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009-05-21 18:57:00 | 00,362,496 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
PRC - [2009-05-13 15:48:22 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009-03-02 12:08:47 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2009-02-15 23:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2009-02-15 23:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2009-02-09 12:25:57 | 00,111,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\services.exe
PRC - [2008-12-08 15:50:04 | 00,054,576 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\HP Software Update\hpwuschd2.exe
PRC - [2008-10-16 20:11:26 | 00,569,344 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
PRC - [2008-10-16 20:11:26 | 00,184,320 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
PRC - [2008-10-16 19:23:30 | 00,214,360 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2008-10-16 17:22:20 | 00,464,264 | ---- | M] () -- C:\Program Files\AskBarDis\bar\bin\AskService.exe
PRC - [2008-04-14 18:21:48 | 00,510,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winlogon.exe
PRC - [2008-04-14 18:21:43 | 00,057,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spoolsv.exe
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [RPCSS]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETWORKSERVICE]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETSVCS]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [mi]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [LOCALSERVICE]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [LOCALSERVICE]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [IMGSVC]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [HTTPFILTER]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [HPZ12]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [HPZ12]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [HPDEVMGMT]
PRC - [2008-04-14 18:21:43 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [DCOMLAUNCH]
PRC - [2008-04-14 18:21:42 | 00,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\smss.exe
PRC - [2008-04-14 18:21:38 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
PRC - [2008-04-14 18:21:30 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2008-04-14 18:21:22 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\lsass.exe
PRC - [2008-04-14 18:21:16 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-04-14 18:21:10 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ctfmon.exe
PRC - [2008-04-14 18:21:10 | 00,006,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\csrss.exe
PRC - [2008-04-14 18:21:02 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\alg.exe
PRC - [2008-01-09 08:23:00 | 00,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2007-08-10 08:21:56 | 16,384,000 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2007-06-15 15:55:00 | 00,300,544 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe


[color=#E56717]========== Modules (All) ==========[/color]

MOD - [2009-12-02 22:08:14 | 00,535,552 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\M4g\Pulpit\OTL.exe
MOD - [2009-06-25 09:27:54 | 00,056,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\secur32.dll
MOD - [2009-04-15 15:54:38 | 00,585,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rpcrt4.dll
MOD - [2009-03-21 15:08:59 | 01,018,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\kernel32.dll
MOD - [2009-02-27 05:58:02 | 00,177,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msctfime.ime
MOD - [2009-02-09 11:53:44 | 00,686,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\advapi32.dll
MOD - [2009-02-09 11:53:43 | 00,722,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntdll.dll
MOD - [2008-10-23 13:42:41 | 00,286,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\gdi32.dll
MOD - [2008-06-17 20:03:15 | 08,489,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shell32.dll
MOD - [2008-04-14 21:50:48 | 00,997,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\setupapi.dll
MOD - [2008-04-14 18:21:56 | 00,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winspool.drv
MOD - [2008-04-14 18:20:57 | 00,178,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winmm.dll
MOD - [2008-04-14 18:20:57 | 00,172,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wldap32.dll
MOD - [2008-04-14 18:20:57 | 00,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\version.dll
MOD - [2008-04-14 18:20:56 | 00,580,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\user32.dll
MOD - [2008-04-14 18:20:56 | 00,219,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\uxtheme.dll
MOD - [2008-04-14 18:20:56 | 00,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\srclient.dll
MOD - [2008-04-14 18:20:47 | 00,474,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shlwapi.dll
MOD - [2008-04-14 18:20:45 | 00,064,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\samlib.dll
MOD - [2008-04-14 18:20:44 | 01,287,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ole32.dll
MOD - [2008-04-14 18:20:44 | 00,551,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oleaut32.dll
MOD - [2008-04-14 18:20:44 | 00,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\olepro32.dll
MOD - [2008-04-14 18:20:44 | 00,023,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\psapi.dll
MOD - [2008-04-14 18:20:41 | 00,119,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntmarta.dll
MOD - [2008-04-14 18:20:39 | 00,343,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcrt.dll
MOD - [2008-04-14 18:20:38 | 00,004,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msimg32.dll
MOD - [2008-04-14 18:20:36 | 00,297,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msctf.dll
MOD - [2008-04-14 18:20:32 | 00,110,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\imm32.dll
MOD - [2008-04-14 18:20:31 | 00,185,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll
MOD - [2008-04-14 17:59:08 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2009-10-11 04:17:35 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009-09-23 15:37:30 | 00,051,168 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2009-07-21 13:34:33 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009-05-21 20:21:18 | 00,248,832 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08)
SRV - [2009-05-13 15:48:22 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009-02-15 23:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
SRV - [2008-10-16 19:24:24 | 00,135,168 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc)
SRV - [2008-10-16 17:22:20 | 00,464,264 | ---- | M] () -- C:\Program Files\AskBarDis\bar\bin\AskService.exe -- (ASKService)
SRV - [2008-07-18 13:13:20 | 00,053,760 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\HPZipm12.dll -- (Pml Driver HPZ12)
SRV - [2008-07-18 13:13:20 | 00,044,032 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\HPZinw12.dll -- (Net Driver HPZ12)
SRV - [2008-01-09 08:23:00 | 00,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - [2007-06-15 15:55:00 | 00,300,544 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2009-11-02 17:34:10 | 00,691,696 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009-07-28 15:33:56 | 00,055,656 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009-05-11 09:12:24 | 00,028,520 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009-03-30 09:33:07 | 00,096,104 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2009-02-15 23:10:26 | 00,353,672 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2009-02-13 11:35:05 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008-11-17 01:24:00 | 00,051,688 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\srescan.sys -- (srescan)
DRV - [2008-10-30 07:12:04 | 00,021,568 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZius12.sys -- (HPZius12)
DRV - [2008-10-30 07:12:03 | 00,049,920 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZid412.sys -- (HPZid412)
DRV - [2008-10-30 07:12:03 | 00,016,496 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZipr12.sys -- (HPZipr12)
DRV - [2008-04-13 17:39:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2008-04-13 17:36:05 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008-01-09 08:23:00 | 07,434,336 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2007-08-10 06:52:44 | 04,603,904 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007-07-29 03:51:10 | 00,048,896 | R--- | M] (JMicron Technology Corp.) -- C:\WINDOWS\system32\DRIVERS\jraid.sys -- (JRAID)
DRV - [2007-07-12 04:49:16 | 00,096,384 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2007-02-22 10:15:56 | 00,137,216 | ---- | M] (Nokia) -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (nmwcd)
DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (nmwcdcm)
DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (nmwcdcj)
DRV - [2007-02-22 10:15:14 | 00,008,320 | ---- | M] (Nokia) -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (nmwcdc)
DRV - [2006-03-02 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]



IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-583907252-115176313-725345543-1004\S-1-5-21-583907252-115176313-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 48
FF - prefs.js..extensions.enabledItems: cfxHelper@Triton:0.9.9.5
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.0.8.0552
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.2
FF - prefs.js..extensions.enabledItems: {5529a434-d9f6-11db-8314-0800200c9a66}:1.1.0
FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.2.5

FF - HKLM\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009-11-02 22:34:53 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-11-07 20:09:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-11-07 20:09:08 | 00,000,000 | ---D | M]

[2009-09-14 21:04:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Mozilla\Extensions
[2009-12-02 19:36:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions
[2009-10-20 16:56:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\{5529a434-d9f6-11db-8314-0800200c9a66}
[2009-10-12 19:29:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2009-10-20 16:56:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2009-11-19 18:28:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\cfxe@Triton
[2009-11-19 18:28:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\cfxHelper@Triton
[2009-10-28 22:19:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\DTToolbar@toolbarnet.com
[2009-10-23 19:19:30 | 00,001,832 | ---- | M] () -- C:\Documents and Settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\searchplugins\translaticapl---angielsko-polski.xml
[2009-10-23 19:19:24 | 00,001,827 | ---- | M] () -- C:\Documents and Settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\searchplugins\translaticapl---polsko-angielski.xml
[2009-12-02 19:36:43 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009-08-24 20:19:13 | 00,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2009-08-24 20:19:13 | 00,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2009-08-24 20:19:13 | 00,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2009-08-24 20:19:13 | 00,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2009-08-24 20:19:13 | 00,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2009-08-24 20:19:13 | 00,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: (742 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\M4g\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll (GG Network S.A.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-583907252-115176313-725345543-1004\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-583907252-115176313-725345543-1004\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe (Nokia)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKU\.DEFAULT..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - HKU\S-1-5-18..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - HKU\S-1-5-21-583907252-115176313-725345543-1004..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-583907252-115176313-725345543-1004..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.)
O4 - HKU\S-1-5-21-583907252-115176313-725345543-1004..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - HKU\S-1-5-21-583907252-115176313-725345543-1004..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\M4g\Menu Start\Programy\Autostart\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-583907252-115176313-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Zaznaczanie HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.63 62.179.1.62
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-09-14 20:23:40 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009-09-14 21:59:21 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2009-12-02 22:08:13 | 00,535,552 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\M4g\Pulpit\OTL.exe
[2009-12-01 20:48:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Dane aplikacji\Gadu-Gadu 10
[2009-12-01 20:48:53 | 00,000,000 | ---D | C] -- C:\Program Files\Gadu-Gadu 10
[2009-11-27 17:33:38 | 00,000,000 | ---D | C] -- C:\Program Files\Tibia
[2009-11-25 15:21:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\HP Product Assistant
[2009-11-24 21:35:05 | 00,000,000 | ---D | C] -- C:\Program Files\Graffiti Studio 2.0
[2009-11-24 11:36:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\.gstreamer-0.10
[2009-11-24 11:36:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2009-11-24 11:36:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Dane aplikacji\OpenFM
[2009-11-23 20:58:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Pulpit\design
[2009-11-23 19:51:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Pulpit\[NBF][vB3.6.x-3.7.x-3.8.x]MGC Chatbox evo 2.4.2 - tłumaczenie boards-assistant.net
[2009-11-23 15:56:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Pulpit\Skladanka
[2009-11-15 22:00:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Pulpit\n9hwph9gkc_1107
[2009-11-15 19:18:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Pulpit\1107
[2009-11-14 14:14:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Dane aplikacji\Remere's Map Editor
[2009-11-14 14:12:40 | 00,000,000 | ---D | C] -- C:\Program Files\Remere's Map Editor
[2009-11-14 13:13:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Dane aplikacji\Ashampoo
[2009-11-14 13:13:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Ustawienia lokalne\Dane aplikacji\ashampoo
[2009-11-14 13:13:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\ashampoo
[2009-11-14 13:13:12 | 00,000,000 | ---D | C] -- C:\Program Files\Ashampoo
[2009-11-13 22:41:05 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2009-11-11 23:41:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\.thinupload
[2009-11-11 12:08:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Pulpit\Przerobki
[2009-11-09 16:55:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Ustawienia lokalne\Dane aplikacji\BlackPencil
[2009-11-09 16:55:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\BlackPencil
[2009-11-08 14:46:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Pulpit\Public+TS+1.0
[2009-11-07 20:07:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\PopCap Games
[2009-11-07 20:07:03 | 00,000,000 | ---D | C] -- C:\Program Files\PopCap Games
[2009-11-06 22:27:53 | 00,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
[2009-11-04 14:10:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Dane aplikacji\HpUpdate
[2009-11-04 14:10:46 | 00,000,000 | ---D | C] -- C:\WINDOWS\Hewlett-Packard
[2009-11-03 22:06:13 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2009-11-03 20:49:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Moje dokumenty\Moje skanowanie
[2009-11-03 18:24:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Dane aplikacji\OpenOffice.org
[2009-11-03 18:22:45 | 00,000,000 | ---D | C] -- C:\Program Files\OpenOffice.org 3
[2009-11-02 22:48:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Ustawienia lokalne\Dane aplikacji\HP
[2009-11-02 22:35:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\M4g\Dane aplikacji\HP
[2009-11-02 22:35:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\WEBREG
[2009-11-02 22:32:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\HP
[2009-11-02 22:29:12 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\HP
[2009-11-02 22:29:11 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Hewlett-Packard
[2009-11-02 22:29:10 | 00,000,000 | ---D | C] -- C:\Program Files\Hewlett-Packard
[2009-11-02 22:28:44 | 00,000,000 | ---D | C] -- C:\Program Files\HP
[2009-11-02 22:28:18 | 00,000,000 | -H-D | C] -- C:\Config.Msi
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2009-12-02 22:09:31 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\M4g\Pulpit\RSIT.exe
[2009-12-02 22:09:18 | 06,553,600 | -H-- | M] () -- C:\Documents and Settings\M4g\NTUSER.DAT
[2009-12-02 22:08:14 | 00,535,552 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\M4g\Pulpit\OTL.exe
[2009-12-02 19:02:26 | 00,350,192 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2009-12-02 19:01:39 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-12-02 19:01:36 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-12-02 17:20:17 | 00,000,188 | -HS- | M] () -- C:\Documents and Settings\M4g\ntuser.ini
[2009-12-02 17:20:09 | 05,332,440 | -H-- | M] () -- C:\Documents and Settings\M4g\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-12-01 23:28:59 | 00,020,122 | ---- | M] () -- C:\Documents and Settings\M4g\Pulpit\rozprawka.odt
[2009-12-01 20:49:11 | 00,000,703 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\OpenFM.lnk
[2009-12-01 20:49:11 | 00,000,674 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Gadu-Gadu 10.lnk
[2009-12-01 20:48:17 | 22,547,792 | ---- | M] () -- C:\Documents and Settings\M4g\Pulpit\gg10.exe
[2009-12-01 19:25:42 | 00,005,696 | ---- | M] () -- C:\Documents and Settings\M4g\Moje dokumenty\cos.otbm
[2009-12-01 19:25:42 | 00,000,049 | ---- | M] () -- C:\Documents and Settings\M4g\Moje dokumenty\cos-spawn.xml
[2009-12-01 19:25:42 | 00,000,049 | ---- | M] () -- C:\Documents and Settings\M4g\Moje dokumenty\cos-house.xml
[2009-11-30 19:13:33 | 00,052,600 | ---- | M] () -- C:\Documents and Settings\M4g\Moje dokumenty\7894882[1].jpg
[2009-11-30 19:13:05 | 00,044,199 | ---- | M] () -- C:\Documents and Settings\M4g\Moje dokumenty\7894885[1].jpg
[2009-11-30 19:12:20 | 00,049,061 | ---- | M] () -- C:\Documents and Settings\M4g\Moje dokumenty\7894878[1].jpg
[2009-11-30 15:59:05 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-11-28 22:23:10 | 00,033,619 | ---- | M] () -- C:\Documents and Settings\M4g\.recently-used.xbel
[2009-11-28 18:55:09 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\M4g\Moje dokumenty\backup_1259427504_5dbac8f354e2ec27.sql.gz
[2009-11-27 17:33:40 | 00,000,638 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Tibia.lnk
[2009-11-26 21:55:41 | 00,021,216 | ---- | M] () -- C:\Documents and Settings\M4g\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2009-11-25 17:23:53 | 00,804,830 | ---- | M] () -- C:\Documents and Settings\M4g\Pulpit\[NBF][vB3.6.x-3.7.x-3.8.x]MGC Chatbox evo 2.4.2 - tłumaczenie boards-assistant.net.zip
[2009-11-25 16:32:25 | 00,077,440 | ---- | M] () -- C:\WINDOWS\hpqins05.dat
[2009-11-25 16:31:42 | 00,130,888 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-11-25 16:30:33 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-11-25 15:21:07 | 00,001,020 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Centrum obsługi HP.lnk
[2009-11-24 21:35:12 | 00,000,024 | ---- | M] () -- C:\WINDOWS\AM_D8.PRF
[2009-11-19 22:45:24 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[2009-11-17 20:29:20 | 00,008,932 | ---- | M] () -- C:\Documents and Settings\M4g\Pulpit\logo.xcf
[2009-11-17 14:58:41 | 00,001,663 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\FileZilla Client.lnk
[2009-11-15 22:38:51 | 00,011,214 | ---- | M] () -- C:\Documents and Settings\M4g\Pulpit\belka.jpg
[2009-11-15 19:18:47 | 01,103,550 | ---- | M] () -- C:\Documents and Settings\M4g\Pulpit\n9hwph9gkc_1107.zip
[2009-11-15 17:02:36 | 02,163,371 | ---- | M] () -- C:\Documents and Settings\M4g\Pulpit\Bez nazwy.xcf
[2009-11-14 14:14:49 | 00,002,279 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Remere's Map Editor.lnk
[2009-11-14 13:13:35 | 00,000,836 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Ashampoo Burning Studio 9.lnk
[2009-11-12 20:55:08 | 00,000,573 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-11-11 00:05:12 | 00,000,145 | ---- | M] () -- C:\WINDOWS\Eudcedit.ini
[2009-11-03 18:24:50 | 00,000,864 | ---- | M] () -- C:\Documents and Settings\M4g\Menu Start\Programy\Autostart\OpenOffice.org 3.1.lnk
[2009-11-03 18:23:25 | 00,000,967 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\OpenOffice.org 3.1.lnk
[2009-11-02 22:35:34 | 00,157,033 | ---- | M] () -- C:\WINDOWS\hpoins34.dat
[2009-11-02 22:33:49 | 00,001,808 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2009-12-02 22:09:30 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\M4g\Pulpit\RSIT.exe
[2009-12-01 22:27:31 | 00,020,122 | ---- | C] () -- C:\Documents and Settings\M4g\Pulpit\rozprawka.odt
[2009-12-01 20:49:11 | 00,000,703 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\OpenFM.lnk
[2009-12-01 20:49:11 | 00,000,674 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Gadu-Gadu 10.lnk
[2009-12-01 20:47:58 | 22,547,792 | ---- | C] () -- C:\Documents and Settings\M4g\Pulpit\gg10.exe
[2009-12-01 19:25:42 | 00,005,696 | ---- | C] () -- C:\Documents and Settings\M4g\Moje dokumenty\cos.otbm
[2009-12-01 19:25:42 | 00,000,049 | ---- | C] () -- C:\Documents and Settings\M4g\Moje dokumenty\cos-spawn.xml
[2009-12-01 19:25:42 | 00,000,049 | ---- | C] () -- C:\Documents and Settings\M4g\Moje dokumenty\cos-house.xml
[2009-11-30 19:13:18 | 00,052,600 | ---- | C] () -- C:\Documents and Settings\M4g\Moje dokumenty\7894882[1].jpg
[2009-11-30 19:12:50 | 00,044,199 | ---- | C] () -- C:\Documents and Settings\M4g\Moje dokumenty\7894885[1].jpg
[2009-11-30 19:12:05 | 00,049,061 | ---- | C] () -- C:\Documents and Settings\M4g\Moje dokumenty\7894878[1].jpg
[2009-11-28 22:23:10 | 00,033,619 | ---- | C] () -- C:\Documents and Settings\M4g\.recently-used.xbel
[2009-11-28 18:55:09 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\M4g\Moje dokumenty\backup_1259427504_5dbac8f354e2ec27.sql.gz
[2009-11-27 17:33:40 | 00,000,638 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Tibia.lnk
[2009-11-25 15:21:06 | 00,001,020 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Centrum obsługi HP.lnk
[2009-11-25 15:20:22 | 00,077,440 | ---- | C] () -- C:\WINDOWS\hpqins05.dat
[2009-11-24 21:35:12 | 00,000,024 | ---- | C] () -- C:\WINDOWS\AM_D8.PRF
[2009-11-23 19:45:04 | 00,804,830 | ---- | C] () -- C:\Documents and Settings\M4g\Pulpit\[NBF][vB3.6.x-3.7.x-3.8.x]MGC Chatbox evo 2.4.2 - tłumaczenie boards-assistant.net.zip
[2009-11-17 20:29:20 | 00,008,932 | ---- | C] () -- C:\Documents and Settings\M4g\Pulpit\logo.xcf
[2009-11-15 22:19:43 | 00,011,214 | ---- | C] () -- C:\Documents and Settings\M4g\Pulpit\belka.jpg
[2009-11-15 19:18:47 | 01,103,550 | ---- | C] () -- C:\Documents and Settings\M4g\Pulpit\n9hwph9gkc_1107.zip
[2009-11-15 17:05:06 | 02,163,371 | ---- | C] () -- C:\Documents and Settings\M4g\Pulpit\Bez nazwy.xcf
[2009-11-14 14:12:41 | 00,002,279 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Remere's Map Editor.lnk
[2009-11-14 13:13:35 | 00,000,836 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Ashampoo Burning Studio 9.lnk
[2009-11-11 00:05:12 | 00,000,145 | ---- | C] () -- C:\WINDOWS\Eudcedit.ini
[2009-11-03 18:24:50 | 00,000,864 | ---- | C] () -- C:\Documents and Settings\M4g\Menu Start\Programy\Autostart\OpenOffice.org 3.1.lnk
[2009-11-03 18:23:25 | 00,000,967 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\OpenOffice.org 3.1.lnk
[2009-11-02 22:33:49 | 00,001,808 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk
[2009-11-02 22:24:15 | 00,157,033 | ---- | C] () -- C:\WINDOWS\hpoins34.dat
[2009-11-02 22:24:15 | 00,001,391 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log
[2009-11-02 22:24:15 | 00,000,404 | ---- | C] () -- C:\WINDOWS\hpomdl34.dat
[2009-10-28 21:46:40 | 00,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009-10-06 12:07:42 | 00,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009-09-28 12:32:32 | 00,003,584 | ---- | C] () -- C:\Documents and Settings\M4g\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-06-19 20:06:22 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2009-06-19 20:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009-06-19 20:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009-06-19 20:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009-06-19 20:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009-06-19 20:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009-06-19 20:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2009-06-19 20:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009-06-19 20:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2009-06-19 20:06:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008-01-09 08:23:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008-01-09 08:23:00 | 01,482,752 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008-01-09 08:23:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008-01-09 08:23:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008-01-09 08:23:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007-03-29 22:00:40 | 00,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll

[color=#E56717]========== LOP Check ==========[/color]

[2009-11-14 13:13:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ashampoo
[2009-11-09 17:17:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\BlackPencil
[2009-11-02 17:33:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite
[2009-09-20 17:16:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations
[2009-10-23 16:47:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla
[2009-12-02 22:10:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2009-09-20 17:18:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite
[2009-11-07 20:07:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PopCap Games
[2009-11-14 13:13:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Ashampoo
[2009-10-28 22:22:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\DAEMON Tools Lite
[2009-11-30 21:09:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\FileZilla
[2009-12-01 20:49:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Gadu-Gadu 10
[2009-11-23 21:06:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\gtk-2.0
[2009-11-09 16:00:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\ipla
[2009-09-20 17:20:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Nokia
[2009-09-15 19:10:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Notepad++
[2009-10-29 17:42:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Nowe Gadu-Gadu
[2009-11-24 11:36:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\OpenFM
[2009-11-03 18:24:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\OpenOffice.org
[2009-09-20 18:21:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\PC Suite
[2009-11-14 14:14:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Remere's Map Editor
[2009-10-11 19:57:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Teeworlds
[2009-11-08 15:31:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\M4g\Dane aplikacji\Tibia

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Custom Scans ==========[/color]


[color=#A23BEC]< %systemdrive%\*.* >[/color]
[2009-10-29 16:05:43 | 00,407,480 | ---- | M] () -- C:\AnalysisLog.sr0
[2009-09-14 20:23:40 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009-09-14 20:18:51 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2006-03-02 13:00:00 | 00,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2009-09-14 20:23:40 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2007-11-07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007-11-07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007-11-07 08:00:40 | 00,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007-11-07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007-11-07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007-11-07 08:00:40 | 00,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007-11-07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007-11-07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007-11-07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007-11-07 08:00:40 | 00,001,110 | ---- | M] () -- C:\globdata.ini
[2007-11-07 08:03:18 | 00,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
[2007-11-07 08:00:40 | 00,000,843 | ---- | M] () -- C:\install.ini
[2007-11-07 08:03:18 | 00,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007-11-07 08:03:18 | 00,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007-11-07 08:03:18 | 00,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007-11-07 08:03:18 | 00,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007-11-07 08:03:18 | 00,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007-11-07 08:03:18 | 00,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007-11-07 08:03:18 | 00,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007-11-07 08:03:18 | 00,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007-11-07 08:03:18 | 00,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2009-09-14 20:23:40 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2009-09-14 20:23:40 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2006-03-02 13:00:00 | 00,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009-09-17 09:46:37 | 00,251,152 | RHS- | M] () -- C:\ntldr
[2009-12-02 19:01:34 | 21,453,86496 | -HS- | M] () -- C:\pagefile.sys
[2007-11-07 08:00:40 | 00,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007-11-07 08:09:22 | 01,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007-11-07 08:12:28 | 00,232,960 | ---- | M] () -- C:\VC_RED.MSI
< End of report >
[/log]
[log]Logfile of random's system information tool 1.06 (written by random/random)
Run by M4g at 2009-12-02 22:12:48
Microsoft Windows XP Home Edition Dodatek Service Pack 3
System drive C: has 184 GB (77%) free of 238 GB
Total RAM: 2047 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:13:04, on 2009-12-02
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Gadu-Gadu 10\gg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Gadu-Gadu 10\spellchecker_gg.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Gadu-Gadu 10\open-fm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\program files\avira\antivir desktop\avcenter.exe
c:\program files\avira\antivir desktop\avscan.exe
C:\Documents and Settings\M4g\Pulpit\RSIT.exe
C:\Program Files\trend micro\M4g.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Pomocnik rejestracji usługi Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\M4g\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Gadu-Gadu 10] "C:\Program Files\Gadu-Gadu 10\gg.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Zaznaczanie HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7767 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2008-10-16 322864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-10-16 333192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocnik rejestracji usługi Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}]
IEPluginBHO Class - C:\Documents and Settings\M4g\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll [2009-11-23 37376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2008-10-16 505136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - ZoneAlarm Spy Blocker Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-10-16 333192]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-08-10 16384000]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-01-09 8523776]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-01-09 81920]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-02-15 981384]
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe [2007-06-18 271360]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
""= []
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Steam"=C:\Program Files\Steam\Steam.exe [2009-11-01 1217808]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-09-02 25623336]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Gadu-Gadu 10"=C:\Program Files\Gadu-Gadu 10\gg.exe [2009-11-23 11797096]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Documents and Settings\M4g\Menu Start\Programy\Autostart
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Nowe Gadu-Gadu\gg.exe"="C:\Program Files\Nowe Gadu-Gadu\gg.exe:*:Disabled:Nowe Gadu-Gadu"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"

======List of files/folders created in the last 1 months======

2009-12-02 22:12:52 ----D---- C:\Program Files\trend micro
2009-12-02 22:12:48 ----D---- C:\rsit
2009-12-01 20:48:57 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\Gadu-Gadu 10
2009-12-01 20:48:53 ----D---- C:\Program Files\Gadu-Gadu 10
2009-11-28 19:36:44 ----A---- C:\WINDOWS\system32\javaws.exe
2009-11-28 19:36:44 ----A---- C:\WINDOWS\system32\javaw.exe
2009-11-28 19:36:44 ----A---- C:\WINDOWS\system32\java.exe
2009-11-27 17:33:38 ----D---- C:\Program Files\Tibia
2009-11-25 16:30:34 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2009-11-25 16:30:29 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2009-11-25 15:21:35 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\HP Product Assistant
2009-11-24 21:35:05 ----D---- C:\Program Files\Graffiti Studio 2.0
2009-11-24 11:36:18 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
2009-11-24 11:36:17 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\OpenFM
2009-11-14 14:14:56 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\Remere's Map Editor
2009-11-14 14:12:40 ----D---- C:\Program Files\Remere's Map Editor
2009-11-14 13:13:50 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\Ashampoo
2009-11-14 13:13:36 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\ashampoo
2009-11-14 13:13:12 ----D---- C:\Program Files\Ashampoo
2009-11-13 22:41:05 ----D---- C:\Program Files\Microsoft Silverlight
2009-11-11 23:56:41 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2009-11-11 00:05:12 ----A---- C:\WINDOWS\Eudcedit.ini
2009-11-09 16:55:01 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\BlackPencil
2009-11-07 20:07:16 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\PopCap Games
2009-11-07 20:07:03 ----D---- C:\Program Files\PopCap Games
2009-11-06 22:28:33 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2009-11-06 22:28:33 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2009-11-06 22:28:33 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2009-11-06 22:28:32 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2009-11-06 22:28:32 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2009-11-06 22:28:32 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2009-11-06 22:28:32 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2009-11-06 22:27:53 ----HD---- C:\WINDOWS\msdownld.tmp
2009-11-04 14:10:48 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\HpUpdate
2009-11-04 14:10:46 ----D---- C:\WINDOWS\Hewlett-Packard
2009-11-03 22:06:13 ----D---- C:\Program Files\MSXML 4.0
2009-11-03 18:24:18 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\OpenOffice.org
2009-11-03 18:22:45 ----D---- C:\Program Files\OpenOffice.org 3

======List of files/folders modified in the last 1 months======

2009-12-02 22:13:04 ----D---- C:\WINDOWS\Prefetch
2009-12-02 22:12:52 ----RD---- C:\Program Files
2009-12-02 22:10:12 ----D---- C:\WINDOWS\Internet Logs
2009-12-02 21:22:02 ----D---- C:\Program Files\Steam
2009-12-02 19:26:43 ----D---- C:\Program Files\Mozilla Firefox
2009-12-02 19:16:46 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\Skype
2009-12-02 19:02:40 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\skypePM
2009-12-02 19:02:20 ----D---- C:\WINDOWS\Temp
2009-12-02 19:01:40 ----D---- C:\WINDOWS\system32\CatRoot2
2009-12-02 17:20:19 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-12-01 20:49:11 ----SHD---- C:\WINDOWS\Installer
2009-12-01 20:49:03 ----HD---- C:\Config.Msi
2009-11-30 21:09:04 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\FileZilla
2009-11-30 19:13:14 ----D---- C:\Program Files\Nowe Gadu-Gadu
2009-11-28 19:36:45 ----D---- C:\WINDOWS\system32
2009-11-28 19:36:39 ----D---- C:\Program Files\Java
2009-11-25 16:33:10 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\HP
2009-11-25 16:32:18 ----D---- C:\WINDOWS
2009-11-25 16:30:36 ----HD---- C:\WINDOWS\inf
2009-11-25 16:30:33 ----A---- C:\WINDOWS\imsins.BAK
2009-11-25 16:30:31 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-25 16:30:14 ----HD---- C:\WINDOWS\$hf_mig$
2009-11-25 16:30:11 ----D---- C:\WINDOWS\WinSxS
2009-11-25 15:22:01 ----RSD---- C:\WINDOWS\Fonts
2009-11-23 21:06:12 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\gtk-2.0
2009-11-19 22:45:25 ----SD---- C:\Documents and Settings\All Users\Dane aplikacji\Microsoft
2009-11-17 14:58:40 ----D---- C:\Program Files\FileZilla FTP Client
2009-11-12 20:55:08 ----A---- C:\WINDOWS\win.ini
2009-11-09 16:00:50 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\ipla
2009-11-08 15:31:26 ----D---- C:\Documents and Settings\M4g\Dane aplikacji\Tibia
2009-11-06 22:28:34 ----D---- C:\WINDOWS\system32\DirectX
2009-11-05 18:36:21 ----A---- C:\WINDOWS\system32\MRT.exe
2009-11-04 22:41:23 ----D---- C:\WINDOWS\ie8updates
2009-11-04 14:11:13 ----D---- C:\Program Files\HP
2009-11-03 18:23:28 ----RSD---- C:\WINDOWS\assembly
2009-11-03 14:49:10 ----D---- C:\Program Files\DAEMON Tools Lite

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Sterownik procesora Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448]
R1 kbdhid;Sterownik klawiatury HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2009-02-15 353672]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-07-28 55656]
R3 HDAudBus;Sterownik magistrali Microsoft UAA dla High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-08-10 4603904]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-01-09 7434336]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2007-07-12 96384]
R3 usbccgp;Rodzajowy sterownik nadrzędny USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Koncentrator z obsługą USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Sterownik Miniport uniwersalnego kontrolera hosta USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 augixml9;augixml9; C:\WINDOWS\system32\drivers\augixml9.sys []
S3 FXDrv32;FXDrv32; \??\E:\FXDrv32.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2008-10-30 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2008-10-30 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2008-10-30 21568]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2007-02-22 137216]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2007-02-22 8320]
S3 nmwcdcj;Nokia USB Port; C:\WINDOWS\system32\drivers\nmwcdcj.sys [2007-02-22 12288]
S3 nmwcdcm;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2007-02-22 12288]
S3 RT73;RT73 USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt73.sys []
S3 usbprint;Klasa PRINTER USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Sterownik skanera USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbstor;Sterownik magazynu masowego USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 ASKService;ASKService; C:\Program Files\AskBarDis\bar\bin\AskService.exe [2008-10-16 464264]
R2 hpqddsvc;Usługa HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-01-09 155716]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2009-02-15 2402184]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-06-15 300544]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 getPlusHelper;getPlus(R) Helper; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WMPNetworkSvc;Usługa udostępniania w sieci programu Windows Media Player; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-12-01 918016]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
[/log]
[log]info.txt logfile of random's system information tool 1.06 2009-12-02 22:13:05

======Uninstall list======

-->MsiExec /X{5DB65884-C963-4454-AABA-4CA3089281FA}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
32 Bit HP CIO Components Installer-->MsiExec.exe /I{47ECCB1F-2811-49C0-B6A7-26778639ABA0}
7-Zip 4.65-->"C:\Program Files\7-Zip\Uninstall.exe"
Adobe Download Manager-->"C:\WINDOWS\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
Aktualizacja dla systemu Windows Internet Explorer 8 (KB973874)-->"C:\WINDOWS\ie8updates\KB973874-IE8\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Aktualizacja zabezpieczeń dla systemu Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB961371-v2)-->"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB972260)-->"C:\WINDOWS\$NtUninstallKB972260$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Ashampoo Burning Studio 9.20-->"C:\Program Files\Ashampoo\Ashampoo Burning Studio 9\unins000.exe"
Asystent rejestracji usługi Windows Live-->MsiExec.exe /I{51958BA7-21E4-4A8B-9098-CD8375BD17B2}
Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
Condition Zero Deleted Scenes-->"C:\Program Files\Steam\steam.exe" steam://uninstall/100
Condition Zero-->"C:\Program Files\Steam\steam.exe" steam://uninstall/80
Counter-Strike: Source-->"C:\Program Files\Steam\steam.exe" steam://uninstall/240
Counter-Strike-->"C:\Program Files\Steam\steam.exe" steam://uninstall/10
DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
FileZilla Client 3.3.0.1-->C:\Program Files\FileZilla FTP Client\uninstall.exe
Gadu-Gadu 10-->C:\Program Files\Gadu-Gadu 10\Uninstall.exe
GIMP 2.6.7-->"C:\Program Files\GIMP-2.0\setup\unins000.exe"
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Customer Participation Program 12.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat -forcereboot
HP Deskjet F735 All-in-one Driver Software 12.0 Rel .4-->C:\Program Files\HP\Digital Imaging\{7BE02706-B038-4844-8FE0-E7A7C0597023}\setup\hpzscr01.exe -datfile hposcr34.dat -onestop -forcereboot
HP Imaging Device Functions 12.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Smart Web Printing-->C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
HP Solution Center 13.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat -forcereboot
HP Update-->MsiExec.exe /X{818ABC3C-635C-4651-8183-D0E9640B7DD1}
Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
Mozilla Firefox (3.5.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Narzędzie do przekazywania usługi Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Need for Speed™ SHIFT-->MsiExec.exe /X{BBF0A67B-5DBA-452F-9D2E-6F168BC226E4}
Nokia Connectivity Cable Driver-->MsiExec.exe /X{11964613-805F-432D-A12B-169554B793E7}
Nokia PC Suite-->C:\Documents and Settings\All Users\Dane aplikacji\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Nokia_PC_Suite_6_84_10_3_EA.exe
Nokia PC Suite-->MsiExec.exe /I{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}
Notepad++-->C:\Program Files\Notepad++\uninstall.exe
Nowe Gadu-Gadu-->C:\Program Files\Nowe Gadu-Gadu\Uninstall.exe
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
NVIDIA PhysX-->MsiExec.exe /X{5DB65884-C963-4454-AABA-4CA3089281FA}
OpenOffice.org 3.1-->MsiExec.exe /I{9E35B051-C7EE-47CB-BA43-9A7FFD4E61DE}
Pakiet sterowników systemu Windows - Nokia (WUDFRd) WPD (06/01/2007 6.84.33.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccswpddri_044C8712DB44F83D9DE6C376991EE9254E0A69E4\pccswpddriver.inf
Pakiet sterowników systemu Windows - Nokia Modem (02/15/2007 3.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccs_bluet_8B37DC72918CCD58A6EC20373AF6242B037A293B\pccs_bluetooth.inf
Pakiet sterowników systemu Windows - Nokia Modem (02/15/2007 3.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccs_bluet_F12A08B6F776984A95553486F64C541356F86E38\pccs_bluetooth.inf
Pakiet sterowników systemu Windows - Nokia Modem (05/24/2007 6.84.0.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_5E1541AFF1E1EA3554CE566743CCAD323ED1C108\nokbtmdm.inf
PC Connectivity Solution-->MsiExec.exe /I{99A40651-0BC2-4095-8F9A-A40FAB224FEF}
Podstawowe programy Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Podstawowe programy Windows Live-->MsiExec.exe /I{9862473C-E063-4C68-A161-2CDE0E8048A5}
Poprawka dla programu Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Poprawka dla systemu Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Poprawka dla systemu Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Poprawka dla systemu Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
Poprawka dla systemu Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
REALTEK GbE & FE Ethernet PCI NIC Driver-->C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\Setup.exe -runfromtemp -l0x0015 -removeonly
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Remere's Map Editor-->MsiExec.exe /I{11F6F2C9-4215-4CDF-8763-4BBDDDEAD601}
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
Skype web features-->MsiExec.exe /I{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}
Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Tibia-->"C:\Program Files\Tibia\unins000.exe"
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
VC 9.0 Runtime-->MsiExec.exe /I{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}
Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Messenger-->MsiExec.exe /X{D1803CD4-0CE7-4484-98E3-88D7A2D629A4}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
World of Warcraft-->C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft (2)\Uninstall.exe
ZoneAlarm Spy Blocker Toolbar-->"C:\Program Files\AskBarDis\unins000.exe"
ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

======System event log======

Computer Name: PRO-25831CBED72
Event Code: 7036
Message: Usługa Karta wydajności WMI weszła w stan zatrzymania.

Record Number: 3337
Source Name: Service Control Manager
Time Written: 20091104140508.000000+060
Event Type: informacje
User:

Computer Name: PRO-25831CBED72
Event Code: 7036
Message: Usługa Usługa odnajdywania SSDP weszła w stan uruchomienia.

Record Number: 3336
Source Name: Service Control Manager
Time Written: 20091104140507.000000+060
Event Type: informacje
User:

Computer Name: PRO-25831CBED72
Event Code: 7036
Message: Usługa Karta wydajności WMI weszła w stan uruchomienia.

Record Number: 3335
Source Name: Service Control Manager
Time Written: 20091104140507.000000+060
Event Type: informacje
User:

Computer Name: PRO-25831CBED72
Event Code: 7035
Message: Do usługi Karta wydajności WMI został pomyślnie wysłany kod sterowania uruchom.

Record Number: 3334
Source Name: Service Control Manager
Time Written: 20091104140507.000000+060
Event Type: informacje
User: ZARZĄDZANIE NT\SYSTEM

Computer Name: PRO-25831CBED72
Event Code: 7036
Message: Usługa hpqcxs08 weszła w stan uruchomienia.

Record Number: 3333
Source Name: Service Control Manager
Time Written: 20091104140507.000000+060
Event Type: informacje
User:

=====Application event log=====

Computer Name: PRO-25831CBED72
Event Code: 1000
Message: Liczniki wydajności dla usługi ContentIndex (ContentIndex) zostały pomyślnie załadowane.
Dane rekordu zawierają nowe wartości indeksu przypisane
do tej usługi.

Record Number: 5
Source Name: LoadPerf
Time Written: 20090914212041.000000+120
Event Type: informacje
User:

Computer Name: PRO-25831CBED72
Event Code: 1000
Message: Liczniki wydajności dla usługi TermService (Usługi terminalowe) zostały pomyślnie załadowane.
Dane rekordu zawierają nowe wartości indeksu przypisane
do tej usługi.

Record Number: 4
Source Name: LoadPerf
Time Written: 20090914212040.000000+120
Event Type: informacje
User:

Computer Name: PRO-25831CBED72
Event Code: 1000
Message: Liczniki wydajności dla usługi RemoteAccess (Routing i dostęp zdalny) zostały pomyślnie załadowane.
Dane rekordu zawierają nowe wartości indeksu przypisane
do tej usługi.

Record Number: 3
Source Name: LoadPerf
Time Written: 20090914211942.000000+120
Event Type: informacje
User:

Computer Name: PRO-25831CBED72
Event Code: 1000
Message: Liczniki wydajności dla usługi PSched (PSched) zostały pomyślnie załadowane.
Dane rekordu zawierają nowe wartości indeksu przypisane
do tej usługi.

Record Number: 2
Source Name: LoadPerf
Time Written: 20090914211909.000000+120
Event Type: informacje
User:

Computer Name: PRO-25831CBED72
Event Code: 1000
Message: Liczniki wydajności dla usługi RSVP (QoS RSVP) zostały pomyślnie załadowane.
Dane rekordu zawierają nowe wartości indeksu przypisane
do tej usługi.

Record Number: 1
Source Name: LoadPerf
Time Written: 20090914211908.000000+120
Event Type: informacje
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=1706
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"tvdumpflags"=8

-----------------EOF-----------------
[/log]
Proszę o sprawdzenie ze względu na to, iż kilka osób korzystało z mojego komputera i ściągało jakieś pliki, boję się o bezpieczeństwo swojego konta bankowego.

Gość
komentarz
komentarz

Tutaj jest niby OK.

Na wszelki wypadek daj log z ComboFixa: http://www.forumpc.pl/index.php?showtopic=120614&st=0&p=837303&fromsearch=1&#entry837303

simivar
komentarz
komentarz

[log]ComboFix 09-12-02.08 - M4g 2009-12-03 17:37.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.2047.1522 [GMT 1:00]
Uruchomiony z: c:\documents and settings\M4g\Pulpit\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.exe

.
((((((((((((((((((((((((( Pliki utworzone od 2009-11-03 do 2009-12-03 )))))))))))))))))))))))))))))))
.

2009-12-02 21:12 . 2009-12-02 21:13 -------- d-----w- c:\program files\trend micro
2009-12-02 21:12 . 2009-12-02 21:13 -------- d-----w- C:\rsit
2009-12-01 19:48 . 2009-12-01 19:49 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\Gadu-Gadu 10
2009-12-01 19:48 . 2009-12-03 15:54 -------- d-----w- c:\program files\Gadu-Gadu 10
2009-11-28 18:36 . 2009-11-28 18:36 152576 ----a-w- c:\documents and settings\M4g\Dane aplikacji\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-28 18:36 . 2009-11-28 18:36 79488 ----a-w- c:\documents and settings\M4g\Dane aplikacji\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-27 16:33 . 2009-11-27 16:33 -------- d-----w- c:\program files\Tibia
2009-11-25 14:21 . 2009-11-25 14:21 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\HP Product Assistant
2009-11-25 14:20 . 2009-11-25 15:32 77440 ----a-w- c:\windows\hpqins05.dat
2009-11-24 20:35 . 2009-11-29 17:46 -------- d-----w- c:\program files\Graffiti Studio 2.0
2009-11-24 10:36 . 2009-12-02 18:24 -------- d-----w- c:\documents and settings\M4g\.gstreamer-0.10
2009-11-24 10:36 . 2009-12-02 21:39 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\OpenFM
2009-11-24 10:36 . 2009-11-24 10:36 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\OpenFM
2009-11-23 10:53 . 2009-11-23 10:53 37376 ----a-w- c:\documents and settings\M4g\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll
2009-11-23 10:53 . 2009-11-23 10:53 11776 ----a-w- c:\documents and settings\M4g\Dane aplikacji\Gadu-Gadu 10\_userdata\npgg.2.dll
2009-11-14 13:14 . 2009-11-14 13:14 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\Remere's Map Editor
2009-11-14 13:12 . 2009-11-14 13:12 -------- d-----w- c:\program files\Remere's Map Editor
2009-11-14 12:13 . 2009-11-14 12:13 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\Ashampoo
2009-11-14 12:13 . 2009-11-14 12:13 -------- d-----w- c:\documents and settings\M4g\Ustawienia lokalne\Dane aplikacji\ashampoo
2009-11-14 12:13 . 2009-11-14 12:13 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\ashampoo
2009-11-14 12:13 . 2009-11-14 12:13 -------- d-----w- c:\program files\Ashampoo
2009-11-13 21:41 . 2009-11-13 21:41 -------- d-----w- c:\program files\Microsoft Silverlight
2009-11-11 22:41 . 2009-11-11 22:41 -------- d-----w- c:\documents and settings\M4g\.thinupload
2009-11-09 20:27 . 2009-11-09 20:27 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-11-09 15:55 . 2009-11-09 16:17 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\BlackPencil
2009-11-09 15:55 . 2009-11-09 15:55 -------- d-----w- c:\documents and settings\M4g\Ustawienia lokalne\Dane aplikacji\BlackPencil
2009-11-07 19:07 . 2009-11-07 19:07 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\PopCap Games
2009-11-07 19:07 . 2009-11-07 19:07 -------- d-----w- c:\program files\PopCap Games
2009-11-06 21:28 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-11-06 21:28 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-11-06 21:28 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-11-06 21:28 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-11-06 21:28 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-11-06 21:28 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-11-06 21:28 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-11-06 21:27 . 2009-11-06 21:28 -------- d--h--w- c:\windows\msdownld.tmp
2009-11-04 13:10 . 2009-12-02 15:02 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\HpUpdate
2009-11-04 13:10 . 2009-11-04 13:10 -------- d-----w- c:\windows\Hewlett-Packard
2009-11-03 21:06 . 2009-11-03 21:06 -------- d-----w- c:\program files\MSXML 4.0
2009-11-03 17:24 . 2009-12-01 20:34 1 ----a-w- c:\documents and settings\M4g\Dane aplikacji\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-03 17:24 . 2009-11-03 17:24 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\OpenOffice.org
2009-11-03 17:22 . 2009-11-03 17:22 -------- d-----w- c:\program files\OpenOffice.org 3

.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-03 16:35 . 2009-09-14 21:03 -------- d-----w- c:\program files\Steam
2009-12-03 16:32 . 2009-10-10 19:38 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\Skype
2009-12-03 16:32 . 2009-10-10 19:40 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\skypePM
2009-11-30 20:09 . 2009-09-14 20:38 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\FileZilla
2009-11-28 18:36 . 2009-10-09 15:43 -------- d-----w- c:\program files\Java
2009-11-26 20:55 . 2009-09-14 20:36 21216 ----a-w- c:\documents and settings\M4g\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-11-25 15:33 . 2009-11-02 21:32 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\HP
2009-11-23 20:06 . 2009-09-30 12:06 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\gtk-2.0
2009-11-17 13:58 . 2009-09-14 20:38 -------- d-----w- c:\program files\FileZilla FTP Client
2009-11-09 15:00 . 2009-10-23 15:47 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\ipla
2009-11-08 14:31 . 2009-10-23 22:25 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\Tibia
2009-11-04 13:11 . 2009-11-02 21:28 -------- d-----w- c:\program files\HP
2009-11-03 13:49 . 2009-11-02 16:34 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-11-02 22:46 . 2009-11-02 21:35 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\HP
2009-11-02 21:35 . 2009-11-02 21:35 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\WEBREG
2009-11-02 21:35 . 2009-11-02 21:24 157033 ----a-w- c:\windows\hpoins34.dat
2009-11-02 21:29 . 2009-11-02 21:29 -------- d-----w- c:\program files\Common Files\HP
2009-11-02 21:29 . 2009-11-02 21:29 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-11-02 21:29 . 2009-11-02 21:29 -------- d-----w- c:\program files\Hewlett-Packard
2009-11-02 16:34 . 2009-10-28 21:19 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-11-02 16:34 . 2009-10-28 20:46 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-02 16:33 . 2009-10-28 21:19 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\DAEMON Tools Lite
2009-10-29 16:42 . 2009-09-14 20:08 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\Nowe Gadu-Gadu
2009-10-28 21:24 . 2009-10-28 21:24 -------- d-----w- c:\program files\Electronic Arts
2009-10-28 21:22 . 2009-10-28 21:22 -------- d-----w- c:\program files\AGEIA Technologies
2009-10-28 21:22 . 2009-10-28 20:46 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\DAEMON Tools Lite
2009-10-25 08:30 . 2006-03-02 12:00 83660 ----a-w- c:\windows\system32\perfc015.dat
2009-10-25 08:30 . 2006-03-02 12:00 490284 ----a-w- c:\windows\system32\perfh015.dat
2009-10-24 12:49 . 2009-10-19 21:43 -------- d-----w- c:\program files\Visual Discomix DJ Basic
2009-10-23 15:47 . 2009-10-23 15:47 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\ipla
2009-10-23 15:46 . 2009-10-23 15:46 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2009-10-19 21:42 . 2009-10-19 21:43 720896 ----a-w- c:\windows\iun6002.exe
2009-10-19 18:52 . 2009-09-14 20:08 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-19 18:52 . 2009-09-14 19:48 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-14 15:25 . 2009-09-27 18:21 -------- d-----w- c:\program files\WoW
2009-10-14 15:21 . 2009-10-14 15:22 1608704 ----a-w- c:\windows\Internet Logs\xDB1.tmp
2009-10-13 13:56 . 2009-10-13 13:56 726077 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-10-12 18:29 . 2009-10-12 18:29 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\NOS
2009-10-12 18:29 . 2009-10-12 18:29 -------- d-----w- c:\program files\NOS
2009-10-11 19:56 . 2009-10-06 11:07 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\Ventrilo
2009-10-11 18:57 . 2009-10-11 18:56 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\Teeworlds
2009-10-11 14:53 . 2009-10-11 14:53 -------- d-----w- c:\program files\Audacity
2009-10-11 03:17 . 2009-10-09 15:42 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-10 19:40 . 2009-10-10 19:40 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-10-10 19:38 . 2009-10-10 19:38 -------- d-----r- c:\program files\Skype
2009-10-10 19:38 . 2009-10-10 19:38 -------- d-----w- c:\program files\Common Files\Skype
2009-10-10 19:37 . 2009-10-10 19:37 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Skype
2009-10-09 15:43 . 2009-10-09 15:42 152576 ----a-w- c:\documents and settings\M4g\Dane aplikacji\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-07 15:20 . 2009-10-07 15:07 -------- d-----w- c:\documents and settings\M4g\Dane aplikacji\mIRC
2009-10-06 11:07 . 2009-10-06 11:07 -------- d-----w- c:\program files\Ventrilo
2009-10-06 11:07 . 2009-10-06 11:07 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-02 19:59 . 2009-10-02 19:59 131072 ----a-w- c:\windows\system32\SpoonUninstall.exe
2009-09-23 14:37 . 2009-10-12 18:29 34112 ----a-w- c:\documents and settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-09-23 14:37 . 2009-10-12 18:29 32448 ----a-w- c:\documents and settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-09-23 14:37 . 2009-10-12 18:29 22352 ----a-w- c:\documents and settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-09-20 16:16 . 2009-09-20 16:16 8192 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstCCD.exe
2009-09-20 16:16 . 2009-09-20 16:16 61440 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstPCSFEMsi.exe
2009-09-20 16:16 . 2009-09-20 16:16 10240 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Installations\CommonCustomActions\UninstPCS.exe
2009-09-20 16:02 . 2009-09-20 16:02 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-09-18 14:57 . 2009-09-18 14:57 19142294 ----a-w- c:\windows\Internet Logs\vsmon_on_demand_thread_2009_09_18_16_43_24_full.dmp.zip
2009-09-18 13:57 . 2009-09-18 13:57 19133332 ----a-w- c:\windows\Internet Logs\vsmon_on_demand_thread_2009_09_18_15_05_49_full.dmp.zip
2009-09-18 13:03 . 2009-09-18 13:03 19132298 ----a-w- c:\windows\Internet Logs\vsmon_on_demand_thread_2009_09_18_09_07_40_full.dmp.zip
2009-09-17 08:59 . 2009-09-17 08:59 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-09-17 08:50 . 2009-09-14 19:23 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-09-14 20:04 . 2009-09-14 20:04 0 ----a-w- c:\windows\nsreg.dat
2009-09-14 19:21 . 2009-09-14 19:21 21856 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-11 14:19 . 2006-03-02 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:05 . 2006-03-02 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 16:44 . 2009-10-28 21:24 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
.

((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-10-16 16:22 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-16 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-16 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2009-11-01 1217808]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-09-02 25623336]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"Gadu-Gadu 10"="c:\program files\Gadu-Gadu 10\gg.exe" [2009-12-02 11833960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-09 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-09 81920]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-08-10 16384000]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-01-09 1626112]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]

c:\documents and settings\M4g\Menu Start\Programy\Autostart\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]

c:\documents and settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-09-15 108289]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [2009-09-17 464264]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-10-28 691696]
S3 FXDrv32;FXDrv32;\??\e:\fxdrv32.sys --> e:\FXDrv32.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Skan uzupełniający -------
.
FF - ProfilePath - c:\documents and settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\
FF - component: c:\documents and settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\{5529a434-d9f6-11db-8314-0800200c9a66}\platform\WINNT_x86-msvc\components\imgwbmp.dll
FF - component: c:\documents and settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\documents and settings\M4g\Dane aplikacji\Gadu-Gadu 10\_userdata\npgg.2.dll
FF - plugin: c:\documents and settings\M4g\Dane aplikacji\Mozilla\Firefox\Profiles\45f2tq8j.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - USUNIĘTO PUSTE WPISY - - - -

AddRemove-NVIDIA Drivers - c:\windows\system32\nvuninst.exe UninstallGUI
AddRemove-Steam App 10 - c:\program files\Steam\steam.exe steam://uninstall/10
AddRemove-Steam App 100 - c:\program files\Steam\steam.exe steam://uninstall/100
AddRemove-Steam App 240 - c:\program files\Steam\steam.exe steam://uninstall/240
AddRemove-Steam App 80 - c:\program files\Steam\steam.exe steam://uninstall/80



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-03 17:40
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ...

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ...

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************
.
Czas ukończenia: 2009-12-03 17:40
ComboFix-quarantined-files.txt 2009-12-03 16:40

Przed: 201 272 991 744 bajtów wolnych
Po: 201 563 873 280 bajtów wolnych

WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - DA90AA3539C28E7DB77BCE8090196C1A
[/log]

Gość
komentarz
komentarz

Ten log jest też czysty.

Użyj programu: http://www.forumpc.pl/index.php?showtopic=107753&st=0&p=752434&fromsearch=1&#entry752434
i wklej raport po PEŁNYM SKANOWANIU.

simivar
komentarz
komentarz (edytowane)

[log]Malwarebytes' Anti-Malware 1.42
Wersja bazy definicji: 3292
Windows 5.1.2600 Dodatek Service Pack 3
Internet Explorer 8.0.6001.18702

2009-12-04 16:04:17
mbam-log-2009-12-04 (16-04-17).txt

Typ skanowania: Pełne skanowanie (C:\|D:\|)
Przeskanowane obiekty: 168022
Upłynęło: 30 minute(s), 11 second(s)

Zainfekowane procesy w pamięci: 0
Zainfekowane moduły pamięci: 0
Zainfekowane klucze rejestru: 0
Zainfekowane wartości rejestru: 0
Zainfekowane pliki rejestru: 0
Zainfekowane foldery: 0
Zainfekowane pliki: 0

Zainfekowane procesy w pamięci:
(Nie wykryto groźnych plików)

Zainfekowane moduły pamięci:
(Nie wykryto groźnych plików)

Zainfekowane klucze rejestru:
(Nie wykryto groźnych plików)

Zainfekowane wartości rejestru:
(Nie wykryto groźnych plików)

Zainfekowane pliki rejestru:
(Nie wykryto groźnych plików)

Zainfekowane foldery:
(Nie wykryto groźnych plików)

Zainfekowane pliki:
(Nie wykryto groźnych plików)
[/log]

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.