aneczqa22 utworzono 17 listopada 2010 utworzono 17 listopada 2010 (edytowane) Witam, Właśnie jestem w pracy i moj komputer dopadł think point na innym komputerze sama wyszukałam co to jest za wirus ale nie mam pojecia co z nim zrobić, a mój szef niestety jest tym mało zainteresowany proszę o pomoc.. jestem laikiem jeśli chodzi o wirusy więc zamieszczam tutaj OTL i RSIT (jeśli źle zamieszcze przepraszam ale jestem z tego zielona) w razie czego proszę o pomoc na gg 24385952 to jedyne mi dziala przez tego cholernego wirusa OTL [log]OTL logfile created on: 2010-11-17 10:04:07 - Run 1 OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Eldorado\Pulpit Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 58,00% Memory free 3,00 Gb Paging File | 3,00 Gb Available in Paging File | 86,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 39,06 Gb Total Space | 22,48 Gb Free Space | 57,55% Space Free | Partition Type: NTFS Drive D: | 35,46 Gb Total Space | 35,39 Gb Free Space | 99,79% Space Free | Partition Type: NTFS Computer Name: ELDORADO1 | User Name: Eldorado | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color="#e56717"]========== Processes (SafeList) ==========[/color] PRC - [2010-11-17 09:59:21 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe PRC - [2010-11-17 07:55:34 | 000,586,240 | ---- | M] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe PRC - [2010-07-13 15:52:25 | 000,074,752 | -HS- | M] (Jznof) -- C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe PRC - [2010-07-12 17:32:48 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe PRC - [2010-06-15 13:35:22 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Google\Update\1.2.183.29\GoogleCrashHandler.exe PRC - [2010-02-02 22:45:50 | 014,252,952 | ---- | M] (Redefine Sp z o.o.) -- C:\Program Files\ipla\ipla.exe PRC - [2010-01-20 13:05:04 | 012,067,432 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe PRC - [2010-01-15 13:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe PRC - [2009-12-01 13:01:25 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe PRC - [2008-04-14 18:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2006-12-27 06:23:34 | 000,104,960 | ---- | M] () -- C:\WINDOWS\hporclnr.exe PRC - [2006-12-27 06:23:32 | 000,098,304 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe PRC - [2006-02-10 06:56:12 | 000,479,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe PRC - [2005-10-04 13:12:52 | 000,090,112 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe [color="#e56717"]========== Modules (SafeList) ==========[/color] MOD - [2010-11-17 09:59:21 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe [color="#e56717"]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt) SRV - [2010-01-15 13:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService) [color="#e56717"]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys -- (hwdatacard) DRV - [2009-07-09 14:43:00 | 000,030,720 | ---- | M] (ZTEIC Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ztpppoe.sys -- (ZTPPPOE) WAN Miniport (PPP over Ethernet Protocol) DRV - [2008-04-13 19:56:49 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (usb_rndis) DRV - [2008-04-13 19:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx) DRV - [2005-10-17 03:31:00 | 003,530,880 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv) DRV - [2005-10-04 16:39:58 | 003,797,632 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM) DRV - [2005-08-12 07:31:12 | 000,098,432 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata) DRV - [2005-07-29 10:11:04 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2005-07-29 10:11:02 | 000,034,048 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2005-03-09 14:53:00 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8) DRV - [2004-08-04 13:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb) DRV - [2004-08-04 13:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx) [color="#e56717"]========== Standard Registry (SafeList) ==========[/color] [color="#e56717"]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = [url="http://www.google.com/ie"]http://www.google.com/ie[/url] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = [url="http://www.google.com/ie"]http://www.google.com/ie[/url] IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-606747145-152049171-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = [url="http://www.google.com"]http://www.google.com[/url] IE - HKU\S-1-5-21-606747145-152049171-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes] IE - HKU\S-1-5-21-606747145-152049171-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [url="https://poczta.xksi.kei.pl/?mod=wb&obj=wbmain&act="]https://poczta.xksi....obj=wbmain&act=[/url] IE - HKU\S-1-5-21-606747145-152049171-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = [url="http://www.google.com/ie"]http://www.google.com/ie[/url] IE - HKU\S-1-5-21-606747145-152049171-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color="#e56717"]========== FireFox ==========[/color] FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.google.pl/" FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {9CE11043-9A15-4207-A565-0C94C42D590D}:2.0 FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1 FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-04-02 14:02:44 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-10-15 08:42:52 | 000,000,000 | ---D | M] [2010-04-01 09:16:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Extensions [2010-08-05 08:42:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\extensions [2010-09-24 11:26:56 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2010-08-05 08:42:37 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-10-18 16:57:14 | 000,001,196 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\searchplugins\winamp-search.xml [2010-08-05 08:42:48 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2010-07-13 15:52:27 | 000,000,000 | ---D | M] (Firefox security) -- C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D} [2010-07-12 17:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll [2010-03-16 20:50:20 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml [2010-03-16 20:50:20 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml [2010-03-16 20:50:20 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml [2010-03-16 20:50:20 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml [2010-03-16 20:50:20 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml [2010-03-16 20:50:20 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2010-08-03 08:07:39 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 NtKrnlpa.info O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKU\S-1-5-21-606747145-152049171-725345543-1004\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKU\S-1-5-21-606747145-152049171-725345543-1004\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [HP OrderReminder Cleaner] C:\WINDOWS\hporclnr.exe () O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard) O4 - HKLM..\Run: [PrzyspieszKomputer] C:\Program Files\Przyspiesz Komputer\PrzyspieszKomputer.exe File not found O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.) O4 - HKU\S-1-5-21-606747145-152049171-725345543-1004..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-21-606747145-152049171-725345543-1004..\Run: [IPLA!] C:\Program Files\ipla\ipla.exe (Redefine Sp z o.o.) O4 - HKU\S-1-5-21-606747145-152049171-725345543-1004..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Photosmart Premier - Szybkie uruchomienie.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: RTHDBPL = C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe (Jznof) O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-606747145-152049171-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html () O8 - Extra context menu item: Funkcja Google Sidewiki - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.) O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: se-2011-download.com ([]http in Trusted sites) O15 - HKLM\..Trusted Domains: se-2011-payment.com ([]http in Trusted sites) O15 - HKU\S-1-5-21-606747145-152049171-725345543-1004\..Trusted Domains: se-2011-download.com ([]http in Zaufane witryny) O15 - HKU\S-1-5-21-606747145-152049171-725345543-1004\..Trusted Domains: se-2011-payment.com ([]http in Zaufane witryny) O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} [url="http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab"]http://download.macr...director/sw.cab[/url] (Shockwave ActiveX Control) O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} [url="http://www.mks.com.pl/skaner/SkanerOnline.cab"]http://www.mks.com.p...kanerOnline.cab[/url] (MksSkanerOnline Class) O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} [url="https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab"]https://h20436.www2....re/HPDEXAXO.cab[/url] (HP Download Manager) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [url="http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab"]http://java.sun.com/...indows-i586.cab[/url] (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [url="http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab"]http://java.sun.com/...indows-i586.cab[/url] (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [url="http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab"]http://java.sun.com/...indows-i586.cab[/url] (Java Plug-in 1.6.0_17) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} [url="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab"]http://download.macr...ash/swflash.cab[/url] (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} [url="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"]http://platformdl.ad...Plus/1.6/gp.cab[/url] (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKU\S-1-5-21-606747145-152049171-725345543-1004 Winlogon: Shell - (C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe) - C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe (Monkey Software) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-09-24 19:52:33 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{09be80d0-db2b-11de-9a22-0016e658ee63}\Shell - "" = AutoRun O33 - MountPoints2\{09be80d0-db2b-11de-9a22-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O33 - MountPoints2\{09be80d1-db2b-11de-9a22-0016e658ee63}\Shell - "" = AutoRun O33 - MountPoints2\{09be80d1-db2b-11de-9a22-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O33 - MountPoints2\{12ff8e88-4c72-11df-9a48-0016e658ee63}\Shell\AutoRun\command - "" = NADFOLDER\autorun.exe O33 - MountPoints2\{12ff8e88-4c72-11df-9a48-0016e658ee63}\Shell\open\command - "" = NADFOLDER\autorun.exe O33 - MountPoints2\{221c96dc-ba6c-11df-9ac2-0016e658ee63}\Shell\Open(&0)\command - "" = F:\Recycled\ctfmon.exe -- File not found O33 - MountPoints2\{2d155864-ae63-11de-99fa-0016e658ee63}\Shell - "" = AutoRun O33 - MountPoints2\{2d155864-ae63-11de-99fa-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O33 - MountPoints2\{2d155865-ae63-11de-99fa-0016e658ee63}\Shell - "" = AutoRun O33 - MountPoints2\{2d155865-ae63-11de-99fa-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O33 - MountPoints2\{b68fa3aa-c229-11df-9acb-0016e658ee63}\Shell - "" = AutoRun O33 - MountPoints2\{b68fa3aa-c229-11df-9acb-0016e658ee63}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found O33 - MountPoints2\{e5ab78ae-8ffb-11df-9a89-002512c80555}\Shell\AutoRun\command - "" = F:\Launcher.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: SCSI Class - Driver Group SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vds - Service SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: SCSI Class - Driver Group SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vga.sys - Driver SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error. SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices [color="#e56717"]========== Files/Folders - Created Within 30 Days ==========[/color] [2010-11-17 09:59:19 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe [2010-11-17 09:16:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch [2010-11-17 08:55:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\pl [2010-11-17 08:55:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas [2010-11-17 08:55:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits [2010-11-17 08:48:34 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$ [2010-11-17 08:48:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\EHome [2010-11-17 07:55:34 | 000,586,240 | ---- | C] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe [2010-11-03 08:42:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Security Essentials 2011 [2010-11-02 12:55:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eldorado\Pulpit\hiszpański [2010-10-21 13:41:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\McAfee [2010-10-18 15:26:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eldorado\Pulpit\mieszkanko [13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color="#e56717"]========== Files - Modified Within 30 Days ==========[/color] [2010-11-17 09:59:21 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe [2010-11-17 09:48:18 | 000,001,507 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Notatnik.lnk [2010-11-17 09:40:01 | 000,001,144 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004UA.job [2010-11-17 09:24:26 | 000,499,958 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2010-11-17 09:24:26 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010-11-17 09:24:26 | 000,088,618 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2010-11-17 09:24:26 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010-11-17 09:23:22 | 000,039,472 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2010-11-17 09:23:11 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx [2010-11-17 09:21:10 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\completescan [2010-11-17 09:19:38 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2010-11-17 09:19:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010-11-17 09:17:11 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job [2010-11-17 09:16:21 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010-11-17 09:15:50 | 000,161,136 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010-11-17 08:52:16 | 000,251,152 | RHS- | M] () -- C:\ntldr [2010-11-17 08:16:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010-11-17 08:08:54 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\start [2010-11-17 07:57:18 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\install [2010-11-17 07:55:34 | 000,586,240 | ---- | M] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe [2010-11-16 14:40:00 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004Core.job [2010-11-16 14:31:42 | 000,000,480 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Eldorado.job [2010-11-16 14:03:39 | 000,002,327 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Google Chrome.lnk [2010-11-10 12:15:34 | 000,002,513 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Microsoft Office Word 2007.lnk [2010-11-10 09:01:55 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk [2010-11-09 08:48:44 | 001,422,994 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\TIA Aqua Park plan.jpg [2010-11-08 12:47:31 | 000,025,573 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\linki do hoteli.docx [2010-11-08 12:16:15 | 000,533,708 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Egipt w przekroju Ostatni termin listopad Wrocław.pdf [2010-11-08 10:50:10 | 000,000,035 | ---- | M] () -- C:\WINDOWS\Printout.012.INI [2010-11-06 13:30:44 | 000,324,612 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\OFERTA HISZPANIA - TRAVEL SENIOR.pdf [2010-11-04 16:26:38 | 000,435,111 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael LISTOPAD.pdf [2010-11-04 16:22:44 | 000,064,512 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.doc [2010-11-04 16:22:32 | 000,321,682 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.pdf [2010-11-04 16:08:48 | 000,440,677 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael Rejs po Nilu LISTOPAD.pdf [2010-11-04 14:10:50 | 000,000,271 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Avaro Bluzki sklep internetowy, Eleganckie bluzki damskie, Koszulki damskie.url [2010-11-04 13:10:33 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe (2).url [2010-11-04 13:01:48 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe.url [2010-11-03 08:42:36 | 000,000,837 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Security Essentials 2011.lnk [2010-11-02 17:15:50 | 000,469,572 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\dokumenty.study VIVA CLUB Polska.pdf [2010-10-28 16:35:52 | 000,049,152 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\tunezja Jinene Beach.doc [2010-10-27 10:23:57 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1wydrukuj.doc [2010-10-27 10:22:52 | 000,068,608 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\dialogi1 do druku.doc [2010-10-27 10:21:10 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1do druku.doc [2010-10-26 15:32:40 | 000,000,377 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Hotele z aquaparkiem, ze zjeżdżalniami. Aquapark, park wodny, zjeżdżalnie poleca Traveliada.pl.url [2010-10-25 13:57:12 | 000,318,598 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\Golden Five!Egipt!LastMinute!Eldorado Travel.pdf [2010-10-21 13:41:27 | 000,001,619 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\McAfee Security Scan Plus.lnk [2010-10-21 13:41:27 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk [2010-10-19 12:07:12 | 000,163,328 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\wniosek na doposazenie.doc [2010-10-18 15:40:04 | 000,000,214 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\MERLIN REZERWACJE.url [13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color="#e56717"]========== Files Created - No Company Name ==========[/color] [2010-11-17 08:08:32 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\start [2010-11-17 08:00:26 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\completescan [2010-11-17 07:57:18 | 000,000,010 | ---- | C] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\install [2010-11-09 08:48:39 | 001,422,994 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\TIA Aqua Park plan.jpg [2010-11-08 12:16:14 | 000,533,708 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Egipt w przekroju Ostatni termin listopad Wrocław.pdf [2010-11-06 13:30:43 | 000,324,612 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\OFERTA HISZPANIA - TRAVEL SENIOR.pdf [2010-11-04 16:26:37 | 000,435,111 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael LISTOPAD.pdf [2010-11-04 16:22:44 | 000,064,512 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.doc [2010-11-04 16:22:32 | 000,321,682 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.pdf [2010-11-04 16:08:47 | 000,440,677 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael Rejs po Nilu LISTOPAD.pdf [2010-11-04 13:10:33 | 000,000,344 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe (2).url [2010-11-04 13:01:48 | 000,000,344 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe.url [2010-11-03 08:42:36 | 000,000,837 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Security Essentials 2011.lnk [2010-11-02 17:16:36 | 000,000,271 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Avaro Bluzki sklep internetowy, Eleganckie bluzki damskie, Koszulki damskie.url [2010-11-02 17:15:47 | 000,469,572 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\dokumenty.study VIVA CLUB Polska.pdf [2010-10-27 10:23:57 | 000,123,392 | ---- | C] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1wydrukuj.doc [2010-10-27 10:22:52 | 000,068,608 | ---- | C] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\dialogi1 do druku.doc [2010-10-27 10:21:10 | 000,123,392 | ---- | C] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1do druku.doc [2010-10-25 14:29:10 | 000,049,152 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\tunezja Jinene Beach.doc [2010-10-25 13:57:12 | 000,318,598 | ---- | C] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\Golden Five!Egipt!LastMinute!Eldorado Travel.pdf [2010-10-19 12:07:12 | 000,163,328 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\wniosek na doposazenie.doc [2010-09-02 16:38:31 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini [2010-08-11 15:11:53 | 000,000,231 | ---- | C] () -- C:\WINDOWS\pdf2word.INI [2010-08-04 13:31:49 | 000,002,272 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2010-07-15 15:06:25 | 000,000,035 | ---- | C] () -- C:\WINDOWS\Printout.012.INI [2010-06-28 13:47:51 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\HPMLVS.dll [2010-06-09 08:20:30 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2010-06-08 09:09:30 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll [2010-06-08 09:06:52 | 000,003,876 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log [2010-03-04 12:49:53 | 000,000,000 | ---- | C] () -- C:\WINDOWS\S4.INI [2009-09-24 20:54:02 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2009-09-24 20:05:17 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini [2009-09-24 20:05:14 | 000,157,184 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2005-10-17 03:31:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2005-10-17 03:31:00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2005-10-17 03:31:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2005-10-17 03:31:00 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll [2005-10-17 03:31:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll [2005-10-17 03:31:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll [2005-10-17 03:31:00 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll [2001-07-07 02:00:02 | 000,003,234 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI [color="#e56717"]========== LOP Check ==========[/color] [2010-03-05 09:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2010-03-05 09:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla [2010-07-13 15:55:59 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\.# [2009-10-01 17:15:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Gadu-Gadu [2010-10-04 16:44:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Gadu-Gadu 10 [2009-11-14 12:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\GHISLER [2010-07-19 10:22:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Image Zone Express [2010-11-17 09:23:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\ipla [2010-11-03 08:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Security Essentials 2011 [2010-07-13 15:52:31 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc [2010-11-17 09:17:11 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job [color="#e56717"]========== Purity Check ==========[/color] [color="#e56717"]========== Custom Scans ==========[/color] [color="#a23bec"]< %systemdrive%\*.* >[/color] [2009-09-24 19:52:33 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2009-09-24 19:44:03 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2004-08-04 13:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin [2009-09-24 19:52:33 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2009-09-24 19:52:33 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2010-04-06 16:49:26 | 000,015,040 | ---- | M] () -- C:\mksbasel.cpp.log [2010-06-28 12:23:42 | 000,109,190 | ---- | M] () -- C:\mombi.log [2009-09-24 19:52:33 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2004-08-04 13:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2010-11-17 08:52:16 | 000,251,152 | RHS- | M] () -- C:\ntldr [2010-11-17 09:19:33 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys [color="#a23bec"]< MD5 for: AGP440.SYS >[/color] [2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:agp440.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:agp440.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:agp440.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:agp440.sys [2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys [2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\agp440.sys [2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\System32\drivers\agp440.sys [color="#a23bec"]< MD5 for: ATAPI.SYS >[/color] [2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:atapi.sys [2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys [2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\atapi.sys [2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\System32\drivers\atapi.sys [2004-08-04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys [2004-08-04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\System32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys [color="#a23bec"]< MD5 for: BEEP.SYS >[/color] [2004-08-04 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\System32\dllcache\beep.sys [2004-08-04 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\System32\drivers\beep.sys [color="#a23bec"]< MD5 for: CDROM.SYS >[/color] [2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:cdrom.sys [2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys [2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\cdrom.sys [2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\System32\drivers\cdrom.sys [2009-12-22 19:39:20 | 000,062,592 | ---- | M] (Microsoft Corporation) MD5=7B53584D94E9D8716B2DE91D5F1CB42D -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys [2004-08-04 13:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtUninstallKB952011$\cdrom.sys [color="#a23bec"]< MD5 for: EVENTLOG.DLL >[/color] [2004-08-04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=05684DE2DA55A04C8AAAB5911AFE7643 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll [2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll [2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\eventlog.dll [2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\system32\eventlog.dll [color="#a23bec"]< MD5 for: NDIS.SYS >[/color] [2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys [2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ndis.sys [2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\System32\drivers\ndis.sys [2004-08-04 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys [color="#a23bec"]< MD5 for: WINLOGON.EXE >[/color] [2004-08-04 13:00:00 | 000,504,832 | ---- | M] (Microsoft Corporation) MD5=0344407089B08548D4FEBA62BB0F32D0 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe [2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe [2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\winlogon.exe [2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\System32\winlogon.exe < End of report > [2010-11-17 10:07:57 | 000,028,672 | -H-- | M] () -- C:\Documents and Settings\Eldorado\ntuser.dat [2010-11-17 10:07:39 | 000,000,000 | R--D | M] -- C:\Documents and Settings\Eldorado\Moje dokumenty [2010-11-17 10:07:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Pulpit [2010-11-17 10:07:32 | 000,339,991 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\RSIT.exe [2010-11-17 10:07:24 | 000,000,000 | ---D | M] -- C:\Program Files\Gadu-Gadu 10 [2010-11-17 09:59:21 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe [2010-11-17 09:58:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Skype [2010-11-17 09:48:18 | 000,001,507 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Notatnik.lnk [2010-11-17 09:47:52 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files\Symantec Shared [2010-11-17 09:40:01 | 000,001,144 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004UA.job [2010-11-17 09:24:53 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Eldorado\Ustawienia lokalne [2010-11-17 09:24:26 | 001,115,590 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2010-11-17 09:24:26 | 000,499,958 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2010-11-17 09:24:26 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010-11-17 09:24:26 | 000,088,618 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2010-11-17 09:24:26 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010-11-17 09:23:53 | 000,032,968 | ---- | M] () -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT [2010-11-17 09:23:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\ipla [2010-11-17 09:23:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\ApplicationHistory [2010-11-17 09:23:22 | 000,039,472 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2010-11-17 09:23:11 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx [2010-11-17 09:21:10 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\completescan [2010-11-17 09:19:38 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2010-11-17 09:19:37 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010-11-17 09:19:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010-11-17 09:17:11 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job [2010-11-17 09:16:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft [2010-11-17 09:16:21 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010-11-17 09:15:50 | 000,161,136 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010-11-17 09:09:07 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express [2010-11-17 09:08:00 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker [2010-11-17 09:00:38 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger [2010-11-17 08:56:59 | 000,000,000 | R--D | M] -- C:\Documents and Settings\All Users\Menu Start [2010-11-17 08:56:03 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player [2010-11-17 08:55:45 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer [2010-11-17 08:54:07 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting [2010-11-17 08:54:04 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT [2010-11-17 08:54:01 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files\System [2010-11-17 08:16:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010-11-17 08:09:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\skypePM [2010-11-17 08:08:54 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\start [2010-11-17 08:08:32 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji [2010-11-17 07:57:39 | 003,407,872 | ---- | M] () -- C:\Documents and Settings\Eldorado\ntuser.dat [2010-11-17 07:57:39 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\Eldorado\ntuser.ini [2010-11-17 07:57:18 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\install [2010-11-17 07:55:34 | 000,586,240 | ---- | M] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe [2010-11-16 17:58:18 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Eldorado\Cookies [2010-11-16 16:40:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Eldorado\NetHood [2010-11-16 14:40:00 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004Core.job [2010-11-16 14:31:42 | 000,000,480 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Eldorado.job [2010-11-16 14:03:39 | 000,002,327 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Google Chrome.lnk [2010-11-16 14:03:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Temp [2010-11-16 13:11:59 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Eldorado\Recent [2010-11-10 12:15:34 | 000,002,513 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Microsoft Office Word 2007.lnk [2010-11-10 09:01:55 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk [2010-11-09 08:48:44 | 001,422,994 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\TIA Aqua Park plan.jpg [2010-11-08 12:47:31 | 000,025,573 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\linki do hoteli.docx [2010-11-08 12:16:15 | 000,533,708 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Egipt w przekroju Ostatni termin listopad Wrocław.pdf [2010-11-08 10:50:10 | 000,000,035 | ---- | M] () -- C:\WINDOWS\Printout.012.INI [2010-11-06 13:30:44 | 000,324,612 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\OFERTA HISZPANIA - TRAVEL SENIOR.pdf [2010-11-04 16:26:38 | 000,435,111 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael LISTOPAD.pdf [2010-11-04 16:22:44 | 000,064,512 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.doc [2010-11-04 16:22:32 | 000,321,682 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.pdf [2010-11-04 16:08:48 | 000,440,677 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael Rejs po Nilu LISTOPAD.pdf [2010-11-04 14:10:50 | 000,000,271 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Avaro Bluzki sklep internetowy, Eleganckie bluzki damskie, Koszulki damskie.url [2010-11-04 13:10:33 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe (2).url [2010-11-04 13:01:48 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe.url [2010-11-03 08:42:36 | 000,000,837 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Security Essentials 2011.lnk [2010-11-03 08:42:36 | 000,000,000 | R--D | M] -- C:\Documents and Settings\Eldorado\Menu Start [2010-11-03 08:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Security Essentials 2011 [2010-11-02 17:15:50 | 000,469,572 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\dokumenty.study VIVA CLUB Polska.pdf [2010-10-28 16:35:52 | 000,049,152 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\tunezja Jinene Beach.doc [2010-10-27 10:23:57 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1wydrukuj.doc [2010-10-27 10:22:52 | 000,068,608 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\dialogi1 do druku.doc [2010-10-27 10:21:10 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1do druku.doc [2010-10-27 07:55:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Google [2010-10-26 15:32:40 | 000,000,377 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Hotele z aquaparkiem, ze zjeżdżalniami. Aquapark, park wodny, zjeżdżalnie poleca Traveliada.pl.url [2010-10-25 13:57:12 | 000,318,598 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\Golden Five!Egipt!LastMinute!Eldorado Travel.pdf [2010-10-21 13:41:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\McAfee [2010-10-21 13:41:27 | 000,001,619 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\McAfee Security Scan Plus.lnk [2010-10-21 13:41:27 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk [2010-10-21 13:41:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Pulpit [2010-10-21 13:41:25 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee Security Scan [2010-10-19 12:07:12 | 000,163,328 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\wniosek na doposazenie.doc [2010-10-18 16:57:03 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox [2010-10-18 15:40:04 | 000,000,214 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\MERLIN REZERWACJE.url [2010-08-04 13:31:49 | 000,002,272 | ---- | M] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2010-06-09 08:20:30 | 000,000,133 | ---- | M] () -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2010-06-08 09:46:26 | 000,003,876 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log [2010-03-04 18:03:34 | 005,358,404 | -H-- | M] () -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\IconCache.db [2009-09-24 20:53:28 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\desktop.ini [2009-09-24 20:53:28 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini [13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color="#e56717"]========== Files - Modified Within 30 Days ==========[/color] [2010-11-17 10:07:32 | 000,339,991 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\RSIT.exe [2010-11-17 09:59:21 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe [2010-11-17 09:48:18 | 000,001,507 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Notatnik.lnk [2010-11-17 09:40:01 | 000,001,144 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004UA.job [2010-11-17 09:24:26 | 000,499,958 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2010-11-17 09:24:26 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010-11-17 09:24:26 | 000,088,618 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2010-11-17 09:24:26 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010-11-17 09:23:22 | 000,039,472 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2010-11-17 09:23:11 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx [2010-11-17 09:21:10 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\completescan [2010-11-17 09:19:38 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2010-11-17 09:19:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010-11-17 09:17:11 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job [2010-11-17 09:16:21 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010-11-17 09:15:50 | 000,161,136 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010-11-17 08:52:16 | 000,251,152 | RHS- | M] () -- C:\ntldr [2010-11-17 08:16:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010-11-17 08:08:54 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\start [2010-11-17 07:57:18 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\install [2010-11-17 07:55:34 | 000,586,240 | ---- | M] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe [2010-11-16 14:40:00 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004Core.job [2010-11-16 14:31:42 | 000,000,480 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Eldorado.job [2010-11-16 14:03:39 | 000,002,327 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Google Chrome.lnk [2010-11-10 12:15:34 | 000,002,513 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Microsoft Office Word 2007.lnk [2010-11-10 09:01:55 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk [2010-11-09 08:48:44 | 001,422,994 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\TIA Aqua Park plan.jpg [2010-11-08 12:47:31 | 000,025,573 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\linki do hoteli.docx [2010-11-08 12:16:15 | 000,533,708 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Egipt w przekroju Ostatni termin listopad Wrocław.pdf [2010-11-08 10:50:10 | 000,000,035 | ---- | M] () -- C:\WINDOWS\Printout.012.INI [2010-11-06 13:30:44 | 000,324,612 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\OFERTA HISZPANIA - TRAVEL SENIOR.pdf [2010-11-04 16:26:38 | 000,435,111 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael LISTOPAD.pdf [2010-11-04 16:22:44 | 000,064,512 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.doc [2010-11-04 16:22:32 | 000,321,682 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.pdf [2010-11-04 16:08:48 | 000,440,677 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael Rejs po Nilu LISTOPAD.pdf [2010-11-04 14:10:50 | 000,000,271 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Avaro Bluzki sklep internetowy, Eleganckie bluzki damskie, Koszulki damskie.url [2010-11-04 13:10:33 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe (2).url [2010-11-04 13:01:48 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe.url [2010-11-03 08:42:36 | 000,000,837 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Security Essentials 2011.lnk [2010-11-02 17:15:50 | 000,469,572 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\dokumenty.study VIVA CLUB Polska.pdf [2010-10-28 16:35:52 | 000,049,152 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\tunezja Jinene Beach.doc [2010-10-27 10:23:57 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1wydrukuj.doc [2010-10-27 10:22:52 | 000,068,608 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\dialogi1 do druku.doc [2010-10-27 10:21:10 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1do druku.doc [2010-10-26 15:32:40 | 000,000,377 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Hotele z aquaparkiem, ze zjeżdżalniami. Aquapark, park wodny, zjeżdżalnie poleca Traveliada.pl.url [2010-10-25 13:57:12 | 000,318,598 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\Golden Five!Egipt!LastMinute!Eldorado Travel.pdf [2010-10-21 13:41:27 | 000,001,619 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\McAfee Security Scan Plus.lnk [2010-10-21 13:41:27 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk [2010-10-19 12:07:12 | 000,163,328 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\wniosek na doposazenie.doc [2010-10-18 15:40:04 | 000,000,214 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\MERLIN REZERWACJE.url [13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color="#e56717"]========== LOP Check ==========[/color] [2010-03-05 09:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2010-03-05 09:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla [2010-07-13 15:55:59 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\.# [2009-10-01 17:15:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Gadu-Gadu [2010-10-04 16:44:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Gadu-Gadu 10 [2009-11-14 12:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\GHISLER [2010-07-19 10:22:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Image Zone Express [2010-11-17 09:23:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\ipla [2010-11-03 08:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Security Essentials 2011 [2010-07-13 15:52:31 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc [2010-11-17 09:17:11 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job [color="#e56717"]========== Purity Check ==========[/color] [color="#e56717"]========== Custom Scans ==========[/color] [color="#a23bec"]< %systemdrive%\*.* >[/color] [2009-09-24 19:52:33 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2009-09-24 19:44:03 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2004-08-04 13:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin [2009-09-24 19:52:33 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2009-09-24 19:52:33 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2010-04-06 16:49:26 | 000,015,040 | ---- | M] () -- C:\mksbasel.cpp.log [2010-06-28 12:23:42 | 000,109,190 | ---- | M] () -- C:\mombi.log [2009-09-24 19:52:33 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2004-08-04 13:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2010-11-17 08:52:16 | 000,251,152 | RHS- | M] () -- C:\ntldr [2010-11-17 09:19:33 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys [color="#a23bec"]< MD5 for: AGP440.SYS >[/color] [2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:agp440.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:agp440.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:agp440.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:agp440.sys [2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys [2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\agp440.sys [2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\System32\drivers\agp440.sys [color="#a23bec"]< MD5 for: ATAPI.SYS >[/color] [2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:atapi.sys [2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys [2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\atapi.sys [2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\System32\drivers\atapi.sys [2004-08-04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys [2004-08-04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\System32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys [color="#a23bec"]< MD5 for: BEEP.SYS >[/color] [2004-08-04 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\System32\dllcache\beep.sys [2004-08-04 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\System32\drivers\beep.sys [color="#a23bec"]< MD5 for: CDROM.SYS >[/color] [2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys [2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:cdrom.sys [2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys [2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\cdrom.sys [2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\System32\drivers\cdrom.sys [2009-12-22 19:39:20 | 000,062,592 | ---- | M] (Microsoft Corporation) MD5=7B53584D94E9D8716B2DE91D5F1CB42D -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys [2004-08-04 13:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtUninstallKB952011$\cdrom.sys [color="#a23bec"]< MD5 for: EVENTLOG.DLL >[/color] [2004-08-04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=05684DE2DA55A04C8AAAB5911AFE7643 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll [2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll [2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\eventlog.dll [2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\system32\eventlog.dll [color="#a23bec"]< MD5 for: NDIS.SYS >[/color] [2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys [2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ndis.sys [2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\System32\drivers\ndis.sys [2004-08-04 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys [color="#a23bec"]< MD5 for: WINLOGON.EXE >[/color] [2004-08-04 13:00:00 | 000,504,832 | ---- | M] (Microsoft Corporation) MD5=0344407089B08548D4FEBA62BB0F32D0 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe [2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe [2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\winlogon.exe [2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\System32\winlogon.exe < End of report > [/log] [log]Logfile of random's system information tool 1.08 (written by random/random) Run by Eldorado at 2010-11-17 10:17:29 Microsoft Windows XP Home Edition Dodatek Service Pack 3 System drive C: has 23 GB (58%) free of 40 GB Total RAM: 1471 MB (62% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 10:17:32, on 2010-11-17 Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe C:\WINDOWS\hporclnr.exe C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe C:\Program Files\Winamp\winampa.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\ipla\ipla.exe C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Google\Update\1.2.183.29\GoogleCrashHandler.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Gadu-Gadu 10\gg.exe C:\Documents and Settings\Eldorado\Pulpit\RSIT.exe C:\Program Files\trend micro\Eldorado.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url="https://poczta.xksi.kei.pl/?mod=wb&obj=wbmain&act="]https://poczta.xksi....obj=wbmain&act=[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft....k/?LinkId=69157[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft....k/?LinkId=54896[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft....k/?LinkId=54896[/url] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft....k/?LinkId=69157[/url] R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe O4 - HKLM\..\Run: [HP OrderReminder Cleaner] C:\WINDOWS\hporclnr.exe O4 - HKLM\..\Run: [PrzyspieszKomputer] "C:\Program Files\Przyspiesz Komputer\PrzyspieszKomputer.exe" O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [Gadu-Gadu 10] "C:\Program Files\Gadu-Gadu 10\gg.exe" O4 - HKCU\..\Run: [IPLA!] C:\Program Files\ipla\ipla.exe /autorun O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized O4 - HKLM\..\Policies\Explorer\Run: [RTHDBPL] C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP Photosmart Premier - Szybkie uruchomienie.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: McAfee Security Scan Plus.lnk = ? O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Funkcja Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O15 - Trusted Zone: [url="http://*.se-2011-download.com"]http://*.se-2011-download.com[/url] O15 - Trusted Zone: [url="http://*.se-2011-payment.com"]http://*.se-2011-payment.com[/url] O15 - Trusted Zone: [url="http://*.se-2011-download.com"]http://*.se-2011-download.com[/url] (HKLM) O15 - Trusted Zone: [url="http://*.se-2011-payment.com"]http://*.se-2011-payment.com[/url] (HKLM) O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - [url="http://www.mks.com.pl/skaner/SkanerOnline.cab"]http://www.mks.com.p...kanerOnline.cab[/url] O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - [url="https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab"]https://h20436.www2....re/HPDEXAXO.cab[/url] O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - [url="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"]http://platformdl.ad...Plus/1.6/gp.cab[/url] O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O22 - SharedTaskScheduler: Moduł wstępnego ładowania interfejsu Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Demon buforu kategorii składników - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Usługa Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 9651 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004Core.job C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004UA.job C:\WINDOWS\tasks\Norton Security Scan for Eldorado.job C:\WINDOWS\tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}] Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2010-07-28 1267024] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-10-26 297648] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-10-26 843832] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-01 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-01 73728] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2010-07-28 1267024] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-10-26 297648] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-10-17 7307264] "nwiz"=nwiz.exe /install [] "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2005-10-17 86016] "SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-10-04 90112] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696] "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-12-01 149280] "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152] "OrderReminder"=C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [2006-12-27 98304] "HP OrderReminder Cleaner"=C:\WINDOWS\hporclnr.exe [2006-12-27 104960] ""= [] "PrzyspieszKomputer"=C:\Program Files\Przyspiesz Komputer\PrzyspieszKomputer.exe [] "WinampAgent"=C:\Program Files\Winamp\winampa.exe [2010-07-12 74752] "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "RTHDBPL"=C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe [2010-07-13 74752] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360] "Google Update"=C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2009-11-14 135664] "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-12-01 39408] "Gadu-Gadu 10"=C:\Program Files\Gadu-Gadu 10\gg.exe [2010-01-20 12067432] "IPLA!"=C:\Program Files\ipla\ipla.exe [2010-02-02 14252952] "Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2010-09-02 13351304] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe HP Photosmart Premier - Szybkie uruchomienie.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Documents and Settings\Eldorado\Menu Start\Programy\Autostart Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "HonorAutoRunSetting"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote" "C:\Program Files\Gadu-Gadu\gg.exe"="C:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program główny" "C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit" "C:\Program Files\Gadu-Gadu 10\gg.exe"="C:\Program Files\Gadu-Gadu 10\gg.exe:*:Disabled:Gadu-Gadu 10" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe" "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe" "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe" "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe" "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe" "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe" "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe" "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe" "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe" "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe" "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe" "C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1005MC.EXE"="C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1005MC.EXE:*:Enabled:SMLMProxy Module - HP1005MC.EXE" "C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager" "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" ======List of files/folders created in the last 1 months====== 2010-11-17 10:14:12 ----D---- C:\rsit 2010-11-17 10:14:12 ----D---- C:\Program Files\trend micro 2010-11-17 09:16:09 ----D---- C:\WINDOWS\Prefetch 2010-11-17 09:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$ 2010-11-17 09:09:56 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$ 2010-11-17 09:09:44 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$ 2010-11-17 09:09:37 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$ 2010-11-17 09:09:29 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$ 2010-11-17 09:09:23 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$ 2010-11-17 09:09:17 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$ 2010-11-17 09:09:11 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$ 2010-11-17 09:09:05 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$ 2010-11-17 09:08:58 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$ 2010-11-17 09:08:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$ 2010-11-17 09:08:42 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$ 2010-11-17 09:08:36 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$ 2010-11-17 09:08:24 ----HDC---- C:\WINDOWS\$NtUninstallKB977165-v2$ 2010-11-17 09:08:10 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$ 2010-11-17 09:08:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$ 2010-11-17 09:07:58 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$ 2010-11-17 09:07:50 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$ 2010-11-17 09:07:44 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$ 2010-11-17 09:07:38 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$ 2010-11-17 09:07:32 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$ 2010-11-17 09:07:23 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$ 2010-11-17 09:07:13 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$ 2010-11-17 09:07:08 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$ 2010-11-17 09:07:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$ 2010-11-17 09:06:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$ 2010-11-17 09:06:47 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$ 2010-11-17 09:06:36 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$ 2010-11-17 09:06:29 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$ 2010-11-17 09:06:20 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$ 2010-11-17 09:06:07 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$ 2010-11-17 09:06:00 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$ 2010-11-17 09:05:53 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$ 2010-11-17 09:05:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$ 2010-11-17 09:05:40 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$ 2010-11-17 09:05:29 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$ 2010-11-17 09:05:22 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$ 2010-11-17 09:05:14 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$ 2010-11-17 09:05:05 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$ 2010-11-17 09:04:55 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$ 2010-11-17 09:04:47 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$ 2010-11-17 09:04:37 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$ 2010-11-17 09:04:24 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$ 2010-11-17 09:04:17 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$ 2010-11-17 09:04:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$ 2010-11-17 09:03:46 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$ 2010-11-17 09:03:38 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$ 2010-11-17 09:03:30 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$ 2010-11-17 09:03:21 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$ 2010-11-17 09:03:13 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$ 2010-11-17 09:03:07 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$ 2010-11-17 09:03:00 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$ 2010-11-17 09:02:52 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$ 2010-11-17 09:02:43 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$ 2010-11-17 09:02:36 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$ 2010-11-17 09:02:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$ 2010-11-17 09:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$ 2010-11-17 09:02:04 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$ 2010-11-17 09:01:54 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$ 2010-11-17 09:01:47 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$ 2010-11-17 09:01:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_1$ 2010-11-17 09:01:33 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$ 2010-11-17 09:01:27 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$ 2010-11-17 09:01:21 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$ 2010-11-17 09:01:14 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$ 2010-11-17 09:01:06 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$ 2010-11-17 09:01:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$ 2010-11-17 09:00:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$ 2010-11-17 09:00:47 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$ 2010-11-17 09:00:42 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$ 2010-11-17 09:00:36 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$ 2010-11-17 09:00:31 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$ 2010-11-17 09:00:22 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$ 2010-11-17 09:00:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$ 2010-11-17 08:55:44 ----D---- C:\WINDOWS\system32\pl 2010-11-17 08:55:44 ----D---- C:\WINDOWS\system32\bits 2010-11-17 08:55:44 ----D---- C:\WINDOWS\l2schemas 2010-11-17 08:48:34 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$ 2010-11-17 08:48:33 ----D---- C:\WINDOWS\EHome 2010-11-17 07:55:34 ----A---- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe 2010-11-03 08:42:36 ----D---- C:\Documents and Settings\Eldorado\Dane aplikacji\Security Essentials 2011 ======List of files/folders modified in the last 1 months====== 2010-11-17 10:14:12 ----RD---- C:\Program Files 2010-11-17 10:13:58 ----D---- C:\Documents and Settings\Eldorado\Dane aplikacji\Skype 2010-11-17 10:13:05 ----D---- C:\Documents and Settings\Eldorado\Dane aplikacji\ipla 2010-11-17 10:13:04 ----D---- C:\WINDOWS 2010-11-17 10:12:38 ----D---- C:\WINDOWS\Temp 2010-11-17 10:07:24 ----D---- C:\Program Files\Gadu-Gadu 10 2010-11-17 09:47:52 ----D---- C:\Program Files\Common Files\Symantec Shared 2010-11-17 09:24:26 ----D---- C:\WINDOWS\system32 2010-11-17 09:24:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2010-11-17 09:23:16 ----A---- C:\WINDOWS\OEWABLog.txt 2010-11-17 09:23:15 ----D---- C:\WINDOWS\system32\CatRoot2 2010-11-17 09:17:11 ----A---- C:\WINDOWS\SchedLgU.Txt 2010-11-17 09:16:14 ----A---- C:\WINDOWS\setuplog.txt 2010-11-17 09:15:48 ----D---- C:\WINDOWS\AppPatch 2010-11-17 09:15:47 ----D---- C:\WINDOWS\system32\wbem 2010-11-17 09:15:47 ----D---- C:\WINDOWS\system32\Setup 2010-11-17 09:15:46 ----RD---- C:\WINDOWS\Fonts 2010-11-17 09:15:40 ----D---- C:\WINDOWS\system32\drivers 2010-11-17 09:10:05 ----HD---- C:\WINDOWS\inf 2010-11-17 09:10:04 ----RSHDC---- C:\WINDOWS\system32\dllcache 2010-11-17 09:10:04 ----D---- C:\WINDOWS\system32\CatRoot 2010-11-17 09:09:07 ----D---- C:\Program Files\Outlook Express 2010-11-17 09:08:00 ----D---- C:\Program Files\Movie Maker 2010-11-17 09:00:38 ----D---- C:\Program Files\Messenger 2010-11-17 09:00:32 ----D---- C:\WINDOWS\WinSxS 2010-11-17 08:59:51 ----D---- C:\WINDOWS\security 2010-11-17 08:56:03 ----D---- C:\Program Files\Windows Media Player 2010-11-17 08:56:02 ----D---- C:\WINDOWS\Help 2010-11-17 08:55:56 ----D---- C:\WINDOWS\network diagnostic 2010-11-17 08:55:55 ----D---- C:\WINDOWS\ime 2010-11-17 08:55:45 ----D---- C:\WINDOWS\system32\usmt 2010-11-17 08:55:45 ----D---- C:\WINDOWS\system32\pl-PL 2010-11-17 08:55:45 ----D---- C:\Program Files\Internet Explorer 2010-11-17 08:55:44 ----SHD---- C:\WINDOWS\Installer 2010-11-17 08:55:44 ----D---- C:\WINDOWS\PeerNet 2010-11-17 08:54:13 ----D---- C:\WINDOWS\ServicePackFiles 2010-11-17 08:54:10 ----D---- C:\WINDOWS\system32\Restore 2010-11-17 08:54:10 ----D---- C:\WINDOWS\system32\npp 2010-11-17 08:54:09 ----D---- C:\WINDOWS\msagent 2010-11-17 08:54:08 ----D---- C:\WINDOWS\srchasst 2010-11-17 08:54:07 ----D---- C:\Program Files\NetMeeting 2010-11-17 08:54:06 ----D---- C:\WINDOWS\system32\Com 2010-11-17 08:54:04 ----D---- C:\Program Files\Windows NT 2010-11-17 08:54:01 ----D---- C:\Program Files\Common Files\System 2010-11-17 08:53:44 ----D---- C:\WINDOWS\system32\oobe 2010-11-17 08:53:43 ----D---- C:\WINDOWS\system 2010-11-17 08:09:18 ----D---- C:\Documents and Settings\Eldorado\Dane aplikacji\skypePM 2010-11-10 07:44:52 ----HD---- C:\Config.Msi 2010-11-08 10:50:10 ----A---- C:\WINDOWS\Printout.012.INI 2010-11-08 10:47:01 ----D---- C:\ET 2010-11-02 16:47:16 ----A---- C:\WINDOWS\system32\MRT.exe 2010-10-21 13:41:25 ----D---- C:\Program Files\McAfee Security Scan 2010-10-18 16:57:03 ----D---- C:\Program Files\Mozilla Firefox ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2005-08-12 98432] R0 ohci1394;Kontroler hosta IEEE 1394 VIA zgodny z OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696] R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944] R1 AmdK8;Sterownik procesora AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 43008] R2 NwlnkIpx;Protokół transportowy zgodny z NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320] R2 NwlnkNb;System NetBIOS NWLink; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-04 63232] R2 NwlnkSpx;Protokół NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-04 55936] R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-10-04 3797632] R3 Arp1394;Protokół klienta 1394 ARP; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800] R3 NIC1394;Sterownik sieci 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-10-17 3530880] R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-07-29 34048] R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-07-29 12928] R3 ZTPPPOE;WAN Miniport (PPP over Ethernet Protocol); C:\WINDOWS\system32\DRIVERS\ztpppoe.sys [2009-07-09 30720] S1 kbdhid;Sterownik klawiatury HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720] S3 HidUsb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368] S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-03-20 49920] S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-03-20 16496] S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-03-20 21568] S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [] S3 usb_rndis;ZTE USB Remote NDIS Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800] S3 usbccgp;Rodzajowy sterownik nadrzędny USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128] S3 usbprint;Klasa PRINTER USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856] S3 usbscan;Sterownik skanera USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104] S3 USBSTOR;Sterownik magazynu masowego USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-01 153376] R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336] R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-10-17 131139] R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336] R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912] S2 gupdate;Usługa Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-01 135664] S3 aspnet_state;Usuga stanu ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104] S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-01 182768] S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664] S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S4 NetTcpPortSharing;Usługa udostępniania portów Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096] -----------------EOF----------------- [/log] [log]info.txt logfile of random's system information tool 1.08 2010-11-17 10:14:26 ======Uninstall list====== -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf AbiWord 2.8.4-->C:\Program Files\AbiWord\UninstallAbiWord2.exe Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_ActiveX.exe -maintain activex Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe Adobe Reader 9.1.3 - Polish-->MsiExec.exe /I{AC76BA86-7AD7-1045-7B44-A91000000001} Adobe Shockwave Player 11.5-->"C:\WINDOWS\system32\Adobe\Shockwave 11\uninstaller.exe" Aktualizacja dla systemu Windows Internet Explorer 8 (KB976662)-->"C:\WINDOWS\ie8updates\KB976662-IE8\spuninst\spuninst.exe" Aktualizacja dla systemu Windows Internet Explorer 8 (KB980182)-->"C:\WINDOWS\ie8updates\KB980182-IE8\spuninst\spuninst.exe" Aktualizacja dla systemu Windows Internet Explorer 8 (KB980302)-->"C:\WINDOWS\ie8updates\KB980302-IE8\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB976749)-->"C:\WINDOWS\$NtUninstallKB976749$\spuninst\spuninst.exe" Aktualizacja dla systemu Windows XP (KB978207)-->"C:\WINDOWS\$NtUninstallKB978207$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla programu Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla programu Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla programu Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla programu Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla programu Windows Media Player (KB978695)-->"C:\WINDOWS\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla programu Windows Media Player (KB979402)-->"C:\WINDOWS\$NtUninstallKB979402_WM9L$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 8 (KB981332)-->"C:\WINDOWS\ie8updates\KB981332-IE8\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 8 (KB982381)-->"C:\WINDOWS\ie8updates\KB982381-IE8\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB2229593)-->"C:\WINDOWS\$NtUninstallKB2229593$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB961371-v2)-->"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB972260)-->"C:\WINDOWS\$NtUninstallKB972260$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB974455)-->"C:\WINDOWS\$NtUninstallKB974455$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975561)-->"C:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975562)-->"C:\WINDOWS\$NtUninstallKB975562$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB976325)-->"C:\WINDOWS\$NtUninstallKB976325$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB977165-v2)-->"C:\WINDOWS\$NtUninstallKB977165-v2$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB977816)-->"C:\WINDOWS\$NtUninstallKB977816$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978338)-->"C:\WINDOWS\$NtUninstallKB978338$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978542)-->"C:\WINDOWS\$NtUninstallKB978542$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978601)-->"C:\WINDOWS\$NtUninstallKB978601$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB979309)-->"C:\WINDOWS\$NtUninstallKB979309$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB979482)-->"C:\WINDOWS\$NtUninstallKB979482$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB979559)-->"C:\WINDOWS\$NtUninstallKB979559$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB979683)-->"C:\WINDOWS\$NtUninstallKB979683$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB980195)-->"C:\WINDOWS\$NtUninstallKB980195$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB980218)-->"C:\WINDOWS\$NtUninstallKB980218$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla systemu Windows XP (KB980232)-->"C:\WINDOWS\$NtUninstallKB980232$\spuninst\spuninst.exe" Aktualizacja zabezpieczeń dla Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe" Athlon 64 Processor Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x15 Dodatek Zapisywanie jako PDF lub XPS firmy Microsoft dla programów pakietu Microsoft Office 2007-->MsiExec.exe /X{90120000-00B2-0415-0000-0000000FF1CE} Easy Burning (remove only)-->C:\Program Files\EasyBurning\Uninst Easy_Burning.exe EasyDialer-->"C:\Program Files\ZTE\EasyDialer\unins000.exe" euro TICKET on-line Sprzedaż-->"C:\ET\unins000.exe" Free PDF to Word Doc Converter v1.1-->"C:\Program Files\Free PDF to Word Doc Converter\unins000.exe" Gadu-Gadu 10-->C:\Program Files\Gadu-Gadu 10\Uninstall.exe Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_AC0049E063DE2AEA.exe" /uninstall Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C} Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT="" Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT="" HP Customer Participation Program 7.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat HP Document Viewer 7.0-->C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat HP Imaging Device Functions 7.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat HP LaserJet M1005-->C:\Program Files\Agilent-HP\{a324bee9-c355-4984-9bde-0e85f4a1d7ec}\uninstall.exe SYSTEM "C:\Program Files\Agilent-HP\{a324bee9-c355-4984-9bde-0e85f4a1d7ec}" HP Officejet Pro All-In-One Series-->C:\Program Files\HP\Digital Imaging\{7729A02E-D1AD-4830-8FC5-11853500D90D}\setup\hpzscr01.exe -datfile hpwscr05.dat HP OrderReminder-->"C:\Program Files\Hewlett-Packard\OrderReminder\uninstall\hpuninstaller.exe" hp_LaserJet_1018 HP Photosmart Essential-->MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F} HP Photosmart Premier Software 6.5-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat HP Software Update-->MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E} HP Solution Center 7.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat ipla 2.1.2-->C:\Program Files\ipla\uninst.exe Java™ 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF} KSI SWPB 2-->MsiExec.exe /X{AE95CDDA-A29E-43CB-9EEA-4B418F30DEA4} McAfee Security Scan Plus-->"C:\Program Files\McAfee Security Scan\uninstall.exe" Microsoft .NET Framework 1.1 Polish Language Pack-->MsiExec.exe /X{64CB2553-C109-4132-AA51-1F421B515FD1} Microsoft .NET Framework 1.1 Security Update (KB979906)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp" Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PLK-->MsiExec.exe /I{2AFF2951-86B1-3C53-B34D-B440F11E7D0A} Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PLK-->MsiExec.exe /I{5A0DDC27-88E5-3CAD-BC3D-28FFD05CA6B9} Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7} Microsoft .NET Framework 3.5 Language Pack SP1 - plk-->MsiExec.exe /I{9EFDFBA8-9174-3C61-8645-28376C5CA994} Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe" Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe" Microsoft Office Excel MUI (Polish) 2007-->MsiExec.exe /X{90120000-0016-0415-0000-0000000FF1CE} Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE} Microsoft Office OneNote MUI (Polish) 2007-->MsiExec.exe /X{90120000-00A1-0415-0000-0000000FF1CE} Microsoft Office PowerPoint MUI (Polish) 2007-->MsiExec.exe /X{90120000-0018-0415-0000-0000000FF1CE} Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE} Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE} Microsoft Office Proof (Polish) 2007-->MsiExec.exe /X{90120000-001F-0415-0000-0000000FF1CE} Microsoft Office Proofing (Polish) 2007-->MsiExec.exe /X{90120000-002C-0415-0000-0000000FF1CE} Microsoft Office Shared MUI (Polish) 2007-->MsiExec.exe /X{90120000-006E-0415-0000-0000000FF1CE} Microsoft Office Word MUI (Polish) 2007-->MsiExec.exe /X{90120000-001B-0415-0000-0000000FF1CE} Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c} Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7} Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4} Mozilla Firefox (3.6.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe MPM-->MsiExec.exe /X{D48AD533-BAD5-469B-A9AA-272C6D80E70B} MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC} MSXML 6 Service Pack 2 (KB973686)-->MsiExec.exe /I{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA} Nauka Jazdy-->"C:\Program Files\Grupa33\TPJ2010\Uninstall.exe" Nero 6 Enterprise Edition-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL Norton Security Scan-->C:\Program Files\Norton Security Scan\Engine\2.7.3.34\InstWrap.exe NVIDIA Drivers-->C:\WINDOWS\system32\nvuide.exe UninstallGUI OCR Software by I.R.I.S 7.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - plk\setup.exe Poprawka dla systemu Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe" Poprawka dla systemu Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe" Poprawka dla systemu Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe" Poprawka dla systemu Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe" Poprawka dla systemu Windows XP (KB979306)-->"C:\WINDOWS\$NtUninstallKB979306$\spuninst\spuninst.exe" Poprawka dla systemu Windows XP (KB981793)-->"C:\WINDOWS\$NtUninstallKB981793$\spuninst\spuninst.exe" Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x15 -removeonly Scan To-->MsiExec.exe /I{9356940C-B360-4EF4-BE6C-BD488350AB17} Skaner on-line mks_vir-->C:\WINDOWS\system32\SkanerOnlineUninstall.exe Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A} Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36} Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT="" VeryPDF PDF2Word v3.0-->"C:\Program Files\VeryPDF PDF2Word v3.0\unins000.exe" Winamp Toolbar-->"C:\Program Files\Winamp Toolbar\uninstall.exe" Winamp-->"C:\Program Files\Winamp\UninstWA.exe" Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe" Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe" XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe" ZTE Remote NDIS Device-->"C:\Program Files\ADSL Router\unins000.exe" ======Hosts File====== 127.0.0.1 NtKrnlpa.info ======System event log====== Computer Name: ELDORADO1 Event Code: 7035 Message: Do usługi Google Software Updater został pomyślnie wysłany kod sterowania uruchom. Record Number: 8646 Source Name: Service Control Manager Time Written: 20100915083243.000000+120 Event Type: informacje User: ZARZĄDZANIE NT\SYSTEM Computer Name: ELDORADO1 Event Code: 7036 Message: Usługa Usługa Google Update (gupdate) weszła w stan zatrzymania. Record Number: 8645 Source Name: Service Control Manager Time Written: 20100915083122.000000+120 Event Type: informacje User: Computer Name: ELDORADO1 Event Code: 7036 Message: Usługa HTTP SSL weszła w stan uruchomienia. Record Number: 8644 Source Name: Service Control Manager Time Written: 20100915083106.000000+120 Event Type: informacje User: Computer Name: ELDORADO1 Event Code: 7035 Message: Do usługi HTTP SSL został pomyślnie wysłany kod sterowania uruchom. Record Number: 8643 Source Name: Service Control Manager Time Written: 20100915083106.000000+120 Event Type: informacje User: ZARZĄDZANIE NT\USŁUGA LOKALNA Computer Name: ELDORADO1 Event Code: 7036 Message: Usługa Karta wydajności WMI weszła w stan zatrzymania. Record Number: 8642 Source Name: Service Control Manager Time Written: 20100915083106.000000+120 Event Type: informacje User: =====Application event log===== Computer Name: ELDORADO-9CA899 Event Code: 0 Message: Record Number: 765 Source Name: gupdate Time Written: 20100517085430.000000+120 Event Type: informacje User: Computer Name: ELDORADO-9CA899 Event Code: 0 Message: Record Number: 764 Source Name: gusvc Time Written: 20100517085405.000000+120 Event Type: informacje User: Computer Name: ELDORADO-9CA899 Event Code: 1800 Message: Usługa Centrum zabezpieczeń systemu Windows została uruchomiona. Record Number: 763 Source Name: SecurityCenter Time Written: 20100517085355.000000+120 Event Type: informacje User: Computer Name: ELDORADO-9CA899 Event Code: 0 Message: Record Number: 762 Source Name: gupdate Time Written: 20100517085354.000000+120 Event Type: informacje User: Computer Name: ELDORADO-9CA899 Event Code: 1517 Message: System Windows zapisał rejestr użytkownika ELDORADO-9CA899\Eldorado, kiedy aplikacja lub usługa nadal użytkowała rejestr podczas wylogowania. Pamięć używana przez rejestr użytkownika nie została zwolniona. Rejestr zostanie zwolniony, kiedy nie będzie używany. Najczęstszą tego przyczyną są usługi uruchamiane z konta użytkownika. Próbuj skonfigurować te usługi, aby były uruchamiane z konta LocalService lub NetworkService. Record Number: 761 Source Name: Userenv Time Written: 20100515125149.000000+120 Event Type: ostrzeżenie User: ZARZĄDZANIE NT\SYSTEM ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem "windir"=%SystemRoot% "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 44 Stepping 2, AuthenticAMD "PROCESSOR_REVISION"=2c02 "NUMBER_OF_PROCESSORS"=1 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP -----------------EOF----------------- [/log] bardzo proszę o pomoc [color="#ff0000"] //przenoszę do Bezpieczeństwa //dan[/color]
Tomek01 komentarz 18 listopada 2010 komentarz 18 listopada 2010 Odinstaluj Winamp Toolbar jeśli nie używasz. W OTL, w oknie Custom scan/fixes wklej: [code]:Processes Explorer.exe :OTL PRC - [2010-11-17 07:55:34 | 000,586,240 | ---- | M] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe PRC - [2010-07-13 15:52:25 | 000,074,752 | -HS- | M] (Jznof) -- C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe [2010-09-24 11:26:56 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2010-10-18 16:57:14 | 000,001,196 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\searchplugins\winamp-search.xml O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKU\S-1-5-21-606747145-152049171-725345543-1004\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O20 - HKU\S-1-5-21-606747145-152049171-725345543-1004 Winlogon: Shell - (C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe) - C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe (Monkey Software) O33 - MountPoints2\{09be80d0-db2b-11de-9a22-0016e658ee63}\Shell - "" = AutoRun O33 - MountPoints2\{09be80d0-db2b-11de-9a22-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O33 - MountPoints2\{09be80d1-db2b-11de-9a22-0016e658ee63}\Shell - "" = AutoRun O33 - MountPoints2\{09be80d1-db2b-11de-9a22-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O33 - MountPoints2\{12ff8e88-4c72-11df-9a48-0016e658ee63}\Shell\AutoRun\command - "" = NADFOLDER\autorun.exe O33 - MountPoints2\{12ff8e88-4c72-11df-9a48-0016e658ee63}\Shell\open\command - "" = NADFOLDER\autorun.exe O33 - MountPoints2\{2d155864-ae63-11de-99fa-0016e658ee63}\Shell - "" = AutoRun O33 - MountPoints2\{2d155864-ae63-11de-99fa-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O33 - MountPoints2\{2d155865-ae63-11de-99fa-0016e658ee63}\Shell - "" = AutoRun O33 - MountPoints2\{2d155865-ae63-11de-99fa-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found :Files C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe C:\Documents and Settings\Eldorado\Dane aplikacji\start C:\Documents and Settings\Eldorado\Dane aplikacji\install C:\Documents and Settings\Eldorado\Dane aplikacji\completescan C:\Documents and Settings\Eldorado\Dane aplikacji\.# C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004Core.job C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004UA.job C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe :Reg [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}=- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "RTHDBPL"=- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "SuperHidden"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "Hidden"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "ShowSuperHidden"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] "CheckedValue"=dword:00000001 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden] @="" :Services Jznof :Commands [emptytemp] [start explorer] [Reboot][/code] Klikasz run fix, komputer uruchamia się ponownie. Wrzuć log z usuwania oraz nowe logi: OTL i RSIT.
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.