x-kom hosting

wirus think point zamieszczam OTL i RSIT

aneczqa22
utworzono
utworzono (edytowane)

Witam,
Właśnie jestem w pracy i moj komputer dopadł think point na innym komputerze sama wyszukałam co to jest za wirus ale nie mam pojecia co z nim zrobić, a mój szef niestety jest tym mało zainteresowany :( proszę o pomoc.. jestem laikiem jeśli chodzi o wirusy więc zamieszczam tutaj OTL i RSIT (jeśli źle zamieszcze przepraszam ale jestem z tego zielona) w razie czego proszę o pomoc na gg 24385952 to jedyne mi dziala przez tego cholernego wirusa :(

OTL [log]OTL logfile created on: 2010-11-17 10:04:07 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Eldorado\Pulpit
Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 58,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 86,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39,06 Gb Total Space | 22,48 Gb Free Space | 57,55% Space Free | Partition Type: NTFS
Drive D: | 35,46 Gb Total Space | 35,39 Gb Free Space | 99,79% Space Free | Partition Type: NTFS

Computer Name: ELDORADO1 | User Name: Eldorado | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

[color="#e56717"]========== Processes (SafeList) ==========[/color]

PRC - [2010-11-17 09:59:21 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe
PRC - [2010-11-17 07:55:34 | 000,586,240 | ---- | M] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe
PRC - [2010-07-13 15:52:25 | 000,074,752 | -HS- | M] (Jznof) -- C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe
PRC - [2010-07-12 17:32:48 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe
PRC - [2010-06-15 13:35:22 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Google\Update\1.2.183.29\GoogleCrashHandler.exe
PRC - [2010-02-02 22:45:50 | 014,252,952 | ---- | M] (Redefine Sp z o.o.) -- C:\Program Files\ipla\ipla.exe
PRC - [2010-01-20 13:05:04 | 012,067,432 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe
PRC - [2010-01-15 13:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009-12-01 13:01:25 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008-04-14 18:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006-12-27 06:23:34 | 000,104,960 | ---- | M] () -- C:\WINDOWS\hporclnr.exe
PRC - [2006-12-27 06:23:32 | 000,098,304 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
PRC - [2006-02-10 06:56:12 | 000,479,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
PRC - [2005-10-04 13:12:52 | 000,090,112 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe


[color="#e56717"]========== Modules (SafeList) ==========[/color]

MOD - [2010-11-17 09:59:21 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe


[color="#e56717"]========== Win32 Services (SafeList) ==========[/color]

SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010-01-15 13:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)


[color="#e56717"]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
DRV - [2009-07-09 14:43:00 | 000,030,720 | ---- | M] (ZTEIC Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ztpppoe.sys -- (ZTPPPOE) WAN Miniport (PPP over Ethernet Protocol)
DRV - [2008-04-13 19:56:49 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (usb_rndis)
DRV - [2008-04-13 19:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2005-10-17 03:31:00 | 003,530,880 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2005-10-04 16:39:58 | 003,797,632 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005-08-12 07:31:12 | 000,098,432 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005-07-29 10:11:04 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005-07-29 10:11:02 | 000,034,048 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005-03-09 14:53:00 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2004-08-04 13:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2004-08-04 13:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)


[color="#e56717"]========== Standard Registry (SafeList) ==========[/color]


[color="#e56717"]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = [url="http://www.google.com/ie"]http://www.google.com/ie[/url]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = [url="http://www.google.com/ie"]http://www.google.com/ie[/url]


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-606747145-152049171-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = [url="http://www.google.com"]http://www.google.com[/url]
IE - HKU\S-1-5-21-606747145-152049171-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-606747145-152049171-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [url="https://poczta.xksi.kei.pl/?mod=wb&obj=wbmain&act="]https://poczta.xksi....obj=wbmain&act=[/url]
IE - HKU\S-1-5-21-606747145-152049171-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = [url="http://www.google.com/ie"]http://www.google.com/ie[/url]
IE - HKU\S-1-5-21-606747145-152049171-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color="#e56717"]========== FireFox ==========[/color]

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {9CE11043-9A15-4207-A565-0C94C42D590D}:2.0
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-04-02 14:02:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-10-15 08:42:52 | 000,000,000 | ---D | M]

[2010-04-01 09:16:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Extensions
[2010-08-05 08:42:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\extensions
[2010-09-24 11:26:56 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010-08-05 08:42:37 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010-10-18 16:57:14 | 000,001,196 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\searchplugins\winamp-search.xml
[2010-08-05 08:42:48 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010-07-13 15:52:27 | 000,000,000 | ---D | M] (Firefox security) -- C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}
[2010-07-12 17:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2010-03-16 20:50:20 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2010-03-16 20:50:20 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2010-03-16 20:50:20 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2010-03-16 20:50:20 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2010-03-16 20:50:20 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2010-03-16 20:50:20 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2010-08-03 08:07:39 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 NtKrnlpa.info
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKU\S-1-5-21-606747145-152049171-725345543-1004\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-606747145-152049171-725345543-1004\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [HP OrderReminder Cleaner] C:\WINDOWS\hporclnr.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe (Hewlett-Packard)
O4 - HKLM..\Run: [PrzyspieszKomputer] C:\Program Files\Przyspiesz Komputer\PrzyspieszKomputer.exe File not found
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-21-606747145-152049171-725345543-1004..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.)
O4 - HKU\S-1-5-21-606747145-152049171-725345543-1004..\Run: [IPLA!] C:\Program Files\ipla\ipla.exe (Redefine Sp z o.o.)
O4 - HKU\S-1-5-21-606747145-152049171-725345543-1004..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Photosmart Premier - Szybkie uruchomienie.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: RTHDBPL = C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe (Jznof)
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-606747145-152049171-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Funkcja Google Sidewiki - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: se-2011-download.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: se-2011-payment.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-606747145-152049171-725345543-1004\..Trusted Domains: se-2011-download.com ([]http in Zaufane witryny)
O15 - HKU\S-1-5-21-606747145-152049171-725345543-1004\..Trusted Domains: se-2011-payment.com ([]http in Zaufane witryny)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} [url="http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab"]http://download.macr...director/sw.cab[/url] (Shockwave ActiveX Control)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} [url="http://www.mks.com.pl/skaner/SkanerOnline.cab"]http://www.mks.com.p...kanerOnline.cab[/url] (MksSkanerOnline Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} [url="https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab"]https://h20436.www2....re/HPDEXAXO.cab[/url] (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [url="http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab"]http://java.sun.com/...indows-i586.cab[/url] (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [url="http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab"]http://java.sun.com/...indows-i586.cab[/url] (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [url="http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab"]http://java.sun.com/...indows-i586.cab[/url] (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} [url="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab"]http://download.macr...ash/swflash.cab[/url] (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} [url="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"]http://platformdl.ad...Plus/1.6/gp.cab[/url] (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-606747145-152049171-725345543-1004 Winlogon: Shell - (C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe) - C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe (Monkey Software)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-09-24 19:52:33 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{09be80d0-db2b-11de-9a22-0016e658ee63}\Shell - "" = AutoRun
O33 - MountPoints2\{09be80d0-db2b-11de-9a22-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{09be80d1-db2b-11de-9a22-0016e658ee63}\Shell - "" = AutoRun
O33 - MountPoints2\{09be80d1-db2b-11de-9a22-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{12ff8e88-4c72-11df-9a48-0016e658ee63}\Shell\AutoRun\command - "" = NADFOLDER\autorun.exe
O33 - MountPoints2\{12ff8e88-4c72-11df-9a48-0016e658ee63}\Shell\open\command - "" = NADFOLDER\autorun.exe
O33 - MountPoints2\{221c96dc-ba6c-11df-9ac2-0016e658ee63}\Shell\Open(&0)\command - "" = F:\Recycled\ctfmon.exe -- File not found
O33 - MountPoints2\{2d155864-ae63-11de-99fa-0016e658ee63}\Shell - "" = AutoRun
O33 - MountPoints2\{2d155864-ae63-11de-99fa-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{2d155865-ae63-11de-99fa-0016e658ee63}\Shell - "" = AutoRun
O33 - MountPoints2\{2d155865-ae63-11de-99fa-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{b68fa3aa-c229-11df-9acb-0016e658ee63}\Shell - "" = AutoRun
O33 - MountPoints2\{b68fa3aa-c229-11df-9acb-0016e658ee63}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{e5ab78ae-8ffb-11df-9a89-002512c80555}\Shell\AutoRun\command - "" = F:\Launcher.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found


SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - Reg Error: Value error.
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

[color="#e56717"]========== Files/Folders - Created Within 30 Days ==========[/color]

[2010-11-17 09:59:19 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe
[2010-11-17 09:16:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2010-11-17 08:55:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\pl
[2010-11-17 08:55:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2010-11-17 08:55:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2010-11-17 08:48:34 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2010-11-17 08:48:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\EHome
[2010-11-17 07:55:34 | 000,586,240 | ---- | C] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe
[2010-11-03 08:42:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Security Essentials 2011
[2010-11-02 12:55:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eldorado\Pulpit\hiszpański
[2010-10-21 13:41:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\McAfee
[2010-10-18 15:26:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eldorado\Pulpit\mieszkanko
[13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color="#e56717"]========== Files - Modified Within 30 Days ==========[/color]

[2010-11-17 09:59:21 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe
[2010-11-17 09:48:18 | 000,001,507 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Notatnik.lnk
[2010-11-17 09:40:01 | 000,001,144 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004UA.job
[2010-11-17 09:24:26 | 000,499,958 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2010-11-17 09:24:26 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010-11-17 09:24:26 | 000,088,618 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2010-11-17 09:24:26 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010-11-17 09:23:22 | 000,039,472 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010-11-17 09:23:11 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2010-11-17 09:21:10 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\completescan
[2010-11-17 09:19:38 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010-11-17 09:19:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-11-17 09:17:11 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job
[2010-11-17 09:16:21 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-11-17 09:15:50 | 000,161,136 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-11-17 08:52:16 | 000,251,152 | RHS- | M] () -- C:\ntldr
[2010-11-17 08:16:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010-11-17 08:08:54 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\start
[2010-11-17 07:57:18 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\install
[2010-11-17 07:55:34 | 000,586,240 | ---- | M] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe
[2010-11-16 14:40:00 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004Core.job
[2010-11-16 14:31:42 | 000,000,480 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Eldorado.job
[2010-11-16 14:03:39 | 000,002,327 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Google Chrome.lnk
[2010-11-10 12:15:34 | 000,002,513 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Microsoft Office Word 2007.lnk
[2010-11-10 09:01:55 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2010-11-09 08:48:44 | 001,422,994 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\TIA Aqua Park plan.jpg
[2010-11-08 12:47:31 | 000,025,573 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\linki do hoteli.docx
[2010-11-08 12:16:15 | 000,533,708 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Egipt w przekroju Ostatni termin listopad Wrocław.pdf
[2010-11-08 10:50:10 | 000,000,035 | ---- | M] () -- C:\WINDOWS\Printout.012.INI
[2010-11-06 13:30:44 | 000,324,612 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\OFERTA HISZPANIA - TRAVEL SENIOR.pdf
[2010-11-04 16:26:38 | 000,435,111 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael LISTOPAD.pdf
[2010-11-04 16:22:44 | 000,064,512 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.doc
[2010-11-04 16:22:32 | 000,321,682 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.pdf
[2010-11-04 16:08:48 | 000,440,677 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael Rejs po Nilu LISTOPAD.pdf
[2010-11-04 14:10:50 | 000,000,271 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Avaro Bluzki sklep internetowy, Eleganckie bluzki damskie, Koszulki damskie.url
[2010-11-04 13:10:33 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe (2).url
[2010-11-04 13:01:48 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe.url
[2010-11-03 08:42:36 | 000,000,837 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Security Essentials 2011.lnk
[2010-11-02 17:15:50 | 000,469,572 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\dokumenty.study VIVA CLUB Polska.pdf
[2010-10-28 16:35:52 | 000,049,152 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\tunezja Jinene Beach.doc
[2010-10-27 10:23:57 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1wydrukuj.doc
[2010-10-27 10:22:52 | 000,068,608 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\dialogi1 do druku.doc
[2010-10-27 10:21:10 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1do druku.doc
[2010-10-26 15:32:40 | 000,000,377 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Hotele z aquaparkiem, ze zjeżdżalniami. Aquapark, park wodny, zjeżdżalnie poleca Traveliada.pl.url
[2010-10-25 13:57:12 | 000,318,598 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\Golden Five!Egipt!LastMinute!Eldorado Travel.pdf
[2010-10-21 13:41:27 | 000,001,619 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\McAfee Security Scan Plus.lnk
[2010-10-21 13:41:27 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk
[2010-10-19 12:07:12 | 000,163,328 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\wniosek na doposazenie.doc
[2010-10-18 15:40:04 | 000,000,214 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\MERLIN REZERWACJE.url
[13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color="#e56717"]========== Files Created - No Company Name ==========[/color]

[2010-11-17 08:08:32 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\start
[2010-11-17 08:00:26 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\completescan
[2010-11-17 07:57:18 | 000,000,010 | ---- | C] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\install
[2010-11-09 08:48:39 | 001,422,994 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\TIA Aqua Park plan.jpg
[2010-11-08 12:16:14 | 000,533,708 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Egipt w przekroju Ostatni termin listopad Wrocław.pdf
[2010-11-06 13:30:43 | 000,324,612 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\OFERTA HISZPANIA - TRAVEL SENIOR.pdf
[2010-11-04 16:26:37 | 000,435,111 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael LISTOPAD.pdf
[2010-11-04 16:22:44 | 000,064,512 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.doc
[2010-11-04 16:22:32 | 000,321,682 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.pdf
[2010-11-04 16:08:47 | 000,440,677 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael Rejs po Nilu LISTOPAD.pdf
[2010-11-04 13:10:33 | 000,000,344 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe (2).url
[2010-11-04 13:01:48 | 000,000,344 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe.url
[2010-11-03 08:42:36 | 000,000,837 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Security Essentials 2011.lnk
[2010-11-02 17:16:36 | 000,000,271 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\Avaro Bluzki sklep internetowy, Eleganckie bluzki damskie, Koszulki damskie.url
[2010-11-02 17:15:47 | 000,469,572 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\dokumenty.study VIVA CLUB Polska.pdf
[2010-10-27 10:23:57 | 000,123,392 | ---- | C] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1wydrukuj.doc
[2010-10-27 10:22:52 | 000,068,608 | ---- | C] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\dialogi1 do druku.doc
[2010-10-27 10:21:10 | 000,123,392 | ---- | C] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1do druku.doc
[2010-10-25 14:29:10 | 000,049,152 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\tunezja Jinene Beach.doc
[2010-10-25 13:57:12 | 000,318,598 | ---- | C] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\Golden Five!Egipt!LastMinute!Eldorado Travel.pdf
[2010-10-19 12:07:12 | 000,163,328 | ---- | C] () -- C:\Documents and Settings\Eldorado\Pulpit\wniosek na doposazenie.doc
[2010-09-02 16:38:31 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2010-08-11 15:11:53 | 000,000,231 | ---- | C] () -- C:\WINDOWS\pdf2word.INI
[2010-08-04 13:31:49 | 000,002,272 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat
[2010-07-15 15:06:25 | 000,000,035 | ---- | C] () -- C:\WINDOWS\Printout.012.INI
[2010-06-28 13:47:51 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\HPMLVS.dll
[2010-06-09 08:20:30 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\fusioncache.dat
[2010-06-08 09:09:30 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2010-06-08 09:06:52 | 000,003,876 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log
[2010-03-04 12:49:53 | 000,000,000 | ---- | C] () -- C:\WINDOWS\S4.INI
[2009-09-24 20:54:02 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009-09-24 20:05:17 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2009-09-24 20:05:14 | 000,157,184 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2005-10-17 03:31:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2005-10-17 03:31:00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2005-10-17 03:31:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2005-10-17 03:31:00 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2005-10-17 03:31:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2005-10-17 03:31:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2005-10-17 03:31:00 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2001-07-07 02:00:02 | 000,003,234 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI

[color="#e56717"]========== LOP Check ==========[/color]

[2010-03-05 09:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10
[2010-03-05 09:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla
[2010-07-13 15:55:59 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\.#
[2009-10-01 17:15:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Gadu-Gadu
[2010-10-04 16:44:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Gadu-Gadu 10
[2009-11-14 12:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\GHISLER
[2010-07-19 10:22:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Image Zone Express
[2010-11-17 09:23:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\ipla
[2010-11-03 08:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Security Essentials 2011
[2010-07-13 15:52:31 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc
[2010-11-17 09:17:11 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job

[color="#e56717"]========== Purity Check ==========[/color]



[color="#e56717"]========== Custom Scans ==========[/color]


[color="#a23bec"]< %systemdrive%\*.* >[/color]
[2009-09-24 19:52:33 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009-09-24 19:44:03 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2004-08-04 13:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2009-09-24 19:52:33 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009-09-24 19:52:33 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010-04-06 16:49:26 | 000,015,040 | ---- | M] () -- C:\mksbasel.cpp.log
[2010-06-28 12:23:42 | 000,109,190 | ---- | M] () -- C:\mombi.log
[2009-09-24 19:52:33 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004-08-04 13:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010-11-17 08:52:16 | 000,251,152 | RHS- | M] () -- C:\ntldr
[2010-11-17 09:19:33 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys


[color="#a23bec"]< MD5 for: AGP440.SYS >[/color]
[2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:agp440.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:agp440.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:agp440.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:agp440.sys
[2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\agp440.sys
[2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\System32\drivers\agp440.sys

[color="#a23bec"]< MD5 for: ATAPI.SYS >[/color]
[2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:atapi.sys
[2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\atapi.sys
[2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\System32\drivers\atapi.sys
[2004-08-04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004-08-04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\System32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys

[color="#a23bec"]< MD5 for: BEEP.SYS >[/color]
[2004-08-04 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\System32\dllcache\beep.sys
[2004-08-04 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\System32\drivers\beep.sys

[color="#a23bec"]< MD5 for: CDROM.SYS >[/color]
[2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:cdrom.sys
[2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\cdrom.sys
[2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\System32\drivers\cdrom.sys
[2009-12-22 19:39:20 | 000,062,592 | ---- | M] (Microsoft Corporation) MD5=7B53584D94E9D8716B2DE91D5F1CB42D -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
[2004-08-04 13:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtUninstallKB952011$\cdrom.sys

[color="#a23bec"]< MD5 for: EVENTLOG.DLL >[/color]
[2004-08-04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=05684DE2DA55A04C8AAAB5911AFE7643 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\eventlog.dll
[2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\system32\eventlog.dll

[color="#a23bec"]< MD5 for: NDIS.SYS >[/color]
[2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ndis.sys
[2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\System32\drivers\ndis.sys
[2004-08-04 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

[color="#a23bec"]< MD5 for: WINLOGON.EXE >[/color]
[2004-08-04 13:00:00 | 000,504,832 | ---- | M] (Microsoft Corporation) MD5=0344407089B08548D4FEBA62BB0F32D0 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\winlogon.exe
[2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\System32\winlogon.exe

< End of report >
[2010-11-17 10:07:57 | 000,028,672 | -H-- | M] () -- C:\Documents and Settings\Eldorado\ntuser.dat
[2010-11-17 10:07:39 | 000,000,000 | R--D | M] -- C:\Documents and Settings\Eldorado\Moje dokumenty
[2010-11-17 10:07:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Pulpit
[2010-11-17 10:07:32 | 000,339,991 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\RSIT.exe
[2010-11-17 10:07:24 | 000,000,000 | ---D | M] -- C:\Program Files\Gadu-Gadu 10
[2010-11-17 09:59:21 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe
[2010-11-17 09:58:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Skype
[2010-11-17 09:48:18 | 000,001,507 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Notatnik.lnk
[2010-11-17 09:47:52 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files\Symantec Shared
[2010-11-17 09:40:01 | 000,001,144 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004UA.job
[2010-11-17 09:24:53 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Eldorado\Ustawienia lokalne
[2010-11-17 09:24:26 | 001,115,590 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010-11-17 09:24:26 | 000,499,958 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2010-11-17 09:24:26 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010-11-17 09:24:26 | 000,088,618 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2010-11-17 09:24:26 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010-11-17 09:23:53 | 000,032,968 | ---- | M] () -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2010-11-17 09:23:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\ipla
[2010-11-17 09:23:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\ApplicationHistory
[2010-11-17 09:23:22 | 000,039,472 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010-11-17 09:23:11 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2010-11-17 09:21:10 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\completescan
[2010-11-17 09:19:38 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010-11-17 09:19:37 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010-11-17 09:19:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-11-17 09:17:11 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job
[2010-11-17 09:16:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft
[2010-11-17 09:16:21 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-11-17 09:15:50 | 000,161,136 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-11-17 09:09:07 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010-11-17 09:08:00 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010-11-17 09:00:38 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2010-11-17 08:56:59 | 000,000,000 | R--D | M] -- C:\Documents and Settings\All Users\Menu Start
[2010-11-17 08:56:03 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2010-11-17 08:55:45 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2010-11-17 08:54:07 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2010-11-17 08:54:04 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2010-11-17 08:54:01 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files\System
[2010-11-17 08:16:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010-11-17 08:09:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\skypePM
[2010-11-17 08:08:54 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\start
[2010-11-17 08:08:32 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji
[2010-11-17 07:57:39 | 003,407,872 | ---- | M] () -- C:\Documents and Settings\Eldorado\ntuser.dat
[2010-11-17 07:57:39 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\Eldorado\ntuser.ini
[2010-11-17 07:57:18 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\install
[2010-11-17 07:55:34 | 000,586,240 | ---- | M] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe
[2010-11-16 17:58:18 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Eldorado\Cookies
[2010-11-16 16:40:48 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Eldorado\NetHood
[2010-11-16 14:40:00 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004Core.job
[2010-11-16 14:31:42 | 000,000,480 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Eldorado.job
[2010-11-16 14:03:39 | 000,002,327 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Google Chrome.lnk
[2010-11-16 14:03:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Temp
[2010-11-16 13:11:59 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Eldorado\Recent
[2010-11-10 12:15:34 | 000,002,513 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Microsoft Office Word 2007.lnk
[2010-11-10 09:01:55 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2010-11-09 08:48:44 | 001,422,994 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\TIA Aqua Park plan.jpg
[2010-11-08 12:47:31 | 000,025,573 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\linki do hoteli.docx
[2010-11-08 12:16:15 | 000,533,708 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Egipt w przekroju Ostatni termin listopad Wrocław.pdf
[2010-11-08 10:50:10 | 000,000,035 | ---- | M] () -- C:\WINDOWS\Printout.012.INI
[2010-11-06 13:30:44 | 000,324,612 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\OFERTA HISZPANIA - TRAVEL SENIOR.pdf
[2010-11-04 16:26:38 | 000,435,111 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael LISTOPAD.pdf
[2010-11-04 16:22:44 | 000,064,512 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.doc
[2010-11-04 16:22:32 | 000,321,682 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.pdf
[2010-11-04 16:08:48 | 000,440,677 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael Rejs po Nilu LISTOPAD.pdf
[2010-11-04 14:10:50 | 000,000,271 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Avaro Bluzki sklep internetowy, Eleganckie bluzki damskie, Koszulki damskie.url
[2010-11-04 13:10:33 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe (2).url
[2010-11-04 13:01:48 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe.url
[2010-11-03 08:42:36 | 000,000,837 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Security Essentials 2011.lnk
[2010-11-03 08:42:36 | 000,000,000 | R--D | M] -- C:\Documents and Settings\Eldorado\Menu Start
[2010-11-03 08:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Security Essentials 2011
[2010-11-02 17:15:50 | 000,469,572 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\dokumenty.study VIVA CLUB Polska.pdf
[2010-10-28 16:35:52 | 000,049,152 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\tunezja Jinene Beach.doc
[2010-10-27 10:23:57 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1wydrukuj.doc
[2010-10-27 10:22:52 | 000,068,608 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\dialogi1 do druku.doc
[2010-10-27 10:21:10 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1do druku.doc
[2010-10-27 07:55:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Google
[2010-10-26 15:32:40 | 000,000,377 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Hotele z aquaparkiem, ze zjeżdżalniami. Aquapark, park wodny, zjeżdżalnie poleca Traveliada.pl.url
[2010-10-25 13:57:12 | 000,318,598 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\Golden Five!Egipt!LastMinute!Eldorado Travel.pdf
[2010-10-21 13:41:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\McAfee
[2010-10-21 13:41:27 | 000,001,619 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\McAfee Security Scan Plus.lnk
[2010-10-21 13:41:27 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk
[2010-10-21 13:41:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Pulpit
[2010-10-21 13:41:25 | 000,000,000 | ---D | M] -- C:\Program Files\McAfee Security Scan
[2010-10-19 12:07:12 | 000,163,328 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\wniosek na doposazenie.doc
[2010-10-18 16:57:03 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2010-10-18 15:40:04 | 000,000,214 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\MERLIN REZERWACJE.url
[2010-08-04 13:31:49 | 000,002,272 | ---- | M] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat
[2010-06-09 08:20:30 | 000,000,133 | ---- | M] () -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\fusioncache.dat
[2010-06-08 09:46:26 | 000,003,876 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log
[2010-03-04 18:03:34 | 005,358,404 | -H-- | M] () -- C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-09-24 20:53:28 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\desktop.ini
[2009-09-24 20:53:28 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
[13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[color="#e56717"]========== Files - Modified Within 30 Days ==========[/color]

[2010-11-17 10:07:32 | 000,339,991 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\RSIT.exe
[2010-11-17 09:59:21 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eldorado\Pulpit\OTL.exe
[2010-11-17 09:48:18 | 000,001,507 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Notatnik.lnk
[2010-11-17 09:40:01 | 000,001,144 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004UA.job
[2010-11-17 09:24:26 | 000,499,958 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2010-11-17 09:24:26 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010-11-17 09:24:26 | 000,088,618 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2010-11-17 09:24:26 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010-11-17 09:23:22 | 000,039,472 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010-11-17 09:23:11 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2010-11-17 09:21:10 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\completescan
[2010-11-17 09:19:38 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010-11-17 09:19:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-11-17 09:17:11 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job
[2010-11-17 09:16:21 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-11-17 09:15:50 | 000,161,136 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-11-17 08:52:16 | 000,251,152 | RHS- | M] () -- C:\ntldr
[2010-11-17 08:16:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010-11-17 08:08:54 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\start
[2010-11-17 07:57:18 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\install
[2010-11-17 07:55:34 | 000,586,240 | ---- | M] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe
[2010-11-16 14:40:00 | 000,001,092 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004Core.job
[2010-11-16 14:31:42 | 000,000,480 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Eldorado.job
[2010-11-16 14:03:39 | 000,002,327 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Google Chrome.lnk
[2010-11-10 12:15:34 | 000,002,513 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Microsoft Office Word 2007.lnk
[2010-11-10 09:01:55 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2010-11-09 08:48:44 | 001,422,994 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\TIA Aqua Park plan.jpg
[2010-11-08 12:47:31 | 000,025,573 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\linki do hoteli.docx
[2010-11-08 12:16:15 | 000,533,708 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Egipt w przekroju Ostatni termin listopad Wrocław.pdf
[2010-11-08 10:50:10 | 000,000,035 | ---- | M] () -- C:\WINDOWS\Printout.012.INI
[2010-11-06 13:30:44 | 000,324,612 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\OFERTA HISZPANIA - TRAVEL SENIOR.pdf
[2010-11-04 16:26:38 | 000,435,111 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael LISTOPAD.pdf
[2010-11-04 16:22:44 | 000,064,512 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.doc
[2010-11-04 16:22:32 | 000,321,682 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\IZRAEL LISTOPAD.pdf
[2010-11-04 16:08:48 | 000,440,677 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Jordania + Izrael Rejs po Nilu LISTOPAD.pdf
[2010-11-04 14:10:50 | 000,000,271 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Avaro Bluzki sklep internetowy, Eleganckie bluzki damskie, Koszulki damskie.url
[2010-11-04 13:10:33 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe (2).url
[2010-11-04 13:01:48 | 000,000,344 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Strojekapielowe.com - oferujemy stroje i kostiumy kąpielowe.url
[2010-11-03 08:42:36 | 000,000,837 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Security Essentials 2011.lnk
[2010-11-02 17:15:50 | 000,469,572 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\dokumenty.study VIVA CLUB Polska.pdf
[2010-10-28 16:35:52 | 000,049,152 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\tunezja Jinene Beach.doc
[2010-10-27 10:23:57 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1wydrukuj.doc
[2010-10-27 10:22:52 | 000,068,608 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\dialogi1 do druku.doc
[2010-10-27 10:21:10 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\slowka1do druku.doc
[2010-10-26 15:32:40 | 000,000,377 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\Hotele z aquaparkiem, ze zjeżdżalniami. Aquapark, park wodny, zjeżdżalnie poleca Traveliada.pl.url
[2010-10-25 13:57:12 | 000,318,598 | ---- | M] () -- C:\Documents and Settings\Eldorado\Moje dokumenty\Golden Five!Egipt!LastMinute!Eldorado Travel.pdf
[2010-10-21 13:41:27 | 000,001,619 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\McAfee Security Scan Plus.lnk
[2010-10-21 13:41:27 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk
[2010-10-19 12:07:12 | 000,163,328 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\wniosek na doposazenie.doc
[2010-10-18 15:40:04 | 000,000,214 | ---- | M] () -- C:\Documents and Settings\Eldorado\Pulpit\MERLIN REZERWACJE.url
[13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color="#e56717"]========== LOP Check ==========[/color]

[2010-03-05 09:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10
[2010-03-05 09:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla
[2010-07-13 15:55:59 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\.#
[2009-10-01 17:15:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Gadu-Gadu
[2010-10-04 16:44:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Gadu-Gadu 10
[2009-11-14 12:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\GHISLER
[2010-07-19 10:22:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Image Zone Express
[2010-11-17 09:23:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\ipla
[2010-11-03 08:42:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\Security Essentials 2011
[2010-07-13 15:52:31 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc
[2010-11-17 09:17:11 | 000,000,468 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job

[color="#e56717"]========== Purity Check ==========[/color]



[color="#e56717"]========== Custom Scans ==========[/color]


[color="#a23bec"]< %systemdrive%\*.* >[/color]
[2009-09-24 19:52:33 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009-09-24 19:44:03 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2004-08-04 13:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2009-09-24 19:52:33 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009-09-24 19:52:33 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010-04-06 16:49:26 | 000,015,040 | ---- | M] () -- C:\mksbasel.cpp.log
[2010-06-28 12:23:42 | 000,109,190 | ---- | M] () -- C:\mombi.log
[2009-09-24 19:52:33 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004-08-04 13:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010-11-17 08:52:16 | 000,251,152 | RHS- | M] () -- C:\ntldr
[2010-11-17 09:19:33 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys


[color="#a23bec"]< MD5 for: AGP440.SYS >[/color]
[2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:agp440.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:agp440.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:agp440.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:agp440.sys
[2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\agp440.sys
[2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\System32\drivers\agp440.sys

[color="#a23bec"]< MD5 for: ATAPI.SYS >[/color]
[2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:atapi.sys
[2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\atapi.sys
[2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\System32\drivers\atapi.sys
[2004-08-04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004-08-04 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\System32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys

[color="#a23bec"]< MD5 for: BEEP.SYS >[/color]
[2004-08-04 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\System32\dllcache\beep.sys
[2004-08-04 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\System32\drivers\beep.sys

[color="#a23bec"]< MD5 for: CDROM.SYS >[/color]
[2004-08-04 13:00:00 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2010-11-17 08:48:32 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\sp3.cab:cdrom.sys
[2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\cdrom.sys
[2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\System32\drivers\cdrom.sys
[2009-12-22 19:39:20 | 000,062,592 | ---- | M] (Microsoft Corporation) MD5=7B53584D94E9D8716B2DE91D5F1CB42D -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
[2004-08-04 13:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtUninstallKB952011$\cdrom.sys

[color="#a23bec"]< MD5 for: EVENTLOG.DLL >[/color]
[2004-08-04 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=05684DE2DA55A04C8AAAB5911AFE7643 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\eventlog.dll
[2008-04-14 18:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\system32\eventlog.dll

[color="#a23bec"]< MD5 for: NDIS.SYS >[/color]
[2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ndis.sys
[2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\System32\drivers\ndis.sys
[2004-08-04 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

[color="#a23bec"]< MD5 for: WINLOGON.EXE >[/color]
[2004-08-04 13:00:00 | 000,504,832 | ---- | M] (Microsoft Corporation) MD5=0344407089B08548D4FEBA62BB0F32D0 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\winlogon.exe
[2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\System32\winlogon.exe

< End of report >
[/log]



[log]Logfile of random's system information tool 1.08 (written by random/random)
Run by Eldorado at 2010-11-17 10:17:29
Microsoft Windows XP Home Edition Dodatek Service Pack 3
System drive C: has 23 GB (58%) free of 40 GB
Total RAM: 1471 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:17:32, on 2010-11-17
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\WINDOWS\hporclnr.exe
C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ipla\ipla.exe
C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Gadu-Gadu 10\gg.exe
C:\Documents and Settings\Eldorado\Pulpit\RSIT.exe
C:\Program Files\trend micro\Eldorado.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url="https://poczta.xksi.kei.pl/?mod=wb&obj=wbmain&act="]https://poczta.xksi....obj=wbmain&act=[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft....k/?LinkId=69157[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft....k/?LinkId=54896[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft....k/?LinkId=54896[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft....k/?LinkId=69157[/url]
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [HP OrderReminder Cleaner] C:\WINDOWS\hporclnr.exe
O4 - HKLM\..\Run: [PrzyspieszKomputer] "C:\Program Files\Przyspiesz Komputer\PrzyspieszKomputer.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Gadu-Gadu 10] "C:\Program Files\Gadu-Gadu 10\gg.exe"
O4 - HKCU\..\Run: [IPLA!] C:\Program Files\ipla\ipla.exe /autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKLM\..\Policies\Explorer\Run: [RTHDBPL] C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier - Szybkie uruchomienie.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Funkcja Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: [url="http://*.se-2011-download.com"]http://*.se-2011-download.com[/url]
O15 - Trusted Zone: [url="http://*.se-2011-payment.com"]http://*.se-2011-payment.com[/url]
O15 - Trusted Zone: [url="http://*.se-2011-download.com"]http://*.se-2011-download.com[/url] (HKLM)
O15 - Trusted Zone: [url="http://*.se-2011-payment.com"]http://*.se-2011-payment.com[/url] (HKLM)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - [url="http://www.mks.com.pl/skaner/SkanerOnline.cab"]http://www.mks.com.p...kanerOnline.cab[/url]
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - [url="https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab"]https://h20436.www2....re/HPDEXAXO.cab[/url]
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - [url="http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab"]http://platformdl.ad...Plus/1.6/gp.cab[/url]
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Moduł wstępnego ładowania interfejsu Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Demon buforu kategorii składników - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Usługa Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 9651 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004UA.job
C:\WINDOWS\tasks\Norton Security Scan for Eldorado.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{3E309B20-F328-4D4B-B7A6-AA22B489B285}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2010-07-28 1267024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-10-26 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-10-26 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-01 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-01 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2010-07-28 1267024]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-10-26 297648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-10-17 7307264]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2005-10-17 86016]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-10-04 90112]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-12-01 149280]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]
"OrderReminder"=C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [2006-12-27 98304]
"HP OrderReminder Cleaner"=C:\WINDOWS\hporclnr.exe [2006-12-27 104960]
""= []
"PrzyspieszKomputer"=C:\Program Files\Przyspiesz Komputer\PrzyspieszKomputer.exe []
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2010-07-12 74752]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"RTHDBPL"=C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe [2010-07-13 74752]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\Eldorado\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2009-11-14 135664]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-12-01 39408]
"Gadu-Gadu 10"=C:\Program Files\Gadu-Gadu 10\gg.exe [2010-01-20 12067432]
"IPLA!"=C:\Program Files\ipla\ipla.exe [2010-02-02 14252952]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2010-09-02 13351304]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
HP Photosmart Premier - Szybkie uruchomienie.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Documents and Settings\Eldorado\Menu Start\Programy\Autostart
Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Gadu-Gadu\gg.exe"="C:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program główny"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\Program Files\Gadu-Gadu 10\gg.exe"="C:\Program Files\Gadu-Gadu 10\gg.exe:*:Disabled:Gadu-Gadu 10"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1005MC.EXE"="C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1005MC.EXE:*:Enabled:SMLMProxy Module - HP1005MC.EXE"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-11-17 10:14:12 ----D---- C:\rsit
2010-11-17 10:14:12 ----D---- C:\Program Files\trend micro
2010-11-17 09:16:09 ----D---- C:\WINDOWS\Prefetch
2010-11-17 09:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-11-17 09:09:56 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-11-17 09:09:44 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-11-17 09:09:37 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-11-17 09:09:29 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-11-17 09:09:23 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-11-17 09:09:17 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-11-17 09:09:11 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-11-17 09:09:05 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-11-17 09:08:58 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-11-17 09:08:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-11-17 09:08:42 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-11-17 09:08:36 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-11-17 09:08:24 ----HDC---- C:\WINDOWS\$NtUninstallKB977165-v2$
2010-11-17 09:08:10 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-11-17 09:08:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-11-17 09:07:58 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-11-17 09:07:50 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-11-17 09:07:44 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-11-17 09:07:38 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-11-17 09:07:32 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-11-17 09:07:23 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-11-17 09:07:13 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-11-17 09:07:08 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-11-17 09:07:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-11-17 09:06:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-11-17 09:06:47 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-11-17 09:06:36 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-11-17 09:06:29 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-11-17 09:06:20 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-11-17 09:06:07 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-11-17 09:06:00 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-11-17 09:05:53 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2010-11-17 09:05:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2010-11-17 09:05:40 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-11-17 09:05:29 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-11-17 09:05:22 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-11-17 09:05:14 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-11-17 09:05:05 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-11-17 09:04:55 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-11-17 09:04:47 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2010-11-17 09:04:37 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-11-17 09:04:24 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-11-17 09:04:17 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-11-17 09:04:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
2010-11-17 09:03:46 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-11-17 09:03:38 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-11-17 09:03:30 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-11-17 09:03:21 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-11-17 09:03:13 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-11-17 09:03:07 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2010-11-17 09:03:00 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-11-17 09:02:52 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2010-11-17 09:02:43 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-11-17 09:02:36 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-11-17 09:02:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-11-17 09:02:15 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-11-17 09:02:04 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-11-17 09:01:54 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2010-11-17 09:01:47 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-11-17 09:01:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_1$
2010-11-17 09:01:33 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2010-11-17 09:01:27 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-11-17 09:01:21 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-11-17 09:01:14 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-11-17 09:01:06 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-11-17 09:01:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-11-17 09:00:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-11-17 09:00:47 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-11-17 09:00:42 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-11-17 09:00:36 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-11-17 09:00:31 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2010-11-17 09:00:22 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-11-17 09:00:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-11-17 08:55:44 ----D---- C:\WINDOWS\system32\pl
2010-11-17 08:55:44 ----D---- C:\WINDOWS\system32\bits
2010-11-17 08:55:44 ----D---- C:\WINDOWS\l2schemas
2010-11-17 08:48:34 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-11-17 08:48:33 ----D---- C:\WINDOWS\EHome
2010-11-17 07:55:34 ----A---- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe
2010-11-03 08:42:36 ----D---- C:\Documents and Settings\Eldorado\Dane aplikacji\Security Essentials 2011

======List of files/folders modified in the last 1 months======

2010-11-17 10:14:12 ----RD---- C:\Program Files
2010-11-17 10:13:58 ----D---- C:\Documents and Settings\Eldorado\Dane aplikacji\Skype
2010-11-17 10:13:05 ----D---- C:\Documents and Settings\Eldorado\Dane aplikacji\ipla
2010-11-17 10:13:04 ----D---- C:\WINDOWS
2010-11-17 10:12:38 ----D---- C:\WINDOWS\Temp
2010-11-17 10:07:24 ----D---- C:\Program Files\Gadu-Gadu 10
2010-11-17 09:47:52 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-11-17 09:24:26 ----D---- C:\WINDOWS\system32
2010-11-17 09:24:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-11-17 09:23:16 ----A---- C:\WINDOWS\OEWABLog.txt
2010-11-17 09:23:15 ----D---- C:\WINDOWS\system32\CatRoot2
2010-11-17 09:17:11 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-11-17 09:16:14 ----A---- C:\WINDOWS\setuplog.txt
2010-11-17 09:15:48 ----D---- C:\WINDOWS\AppPatch
2010-11-17 09:15:47 ----D---- C:\WINDOWS\system32\wbem
2010-11-17 09:15:47 ----D---- C:\WINDOWS\system32\Setup
2010-11-17 09:15:46 ----RD---- C:\WINDOWS\Fonts
2010-11-17 09:15:40 ----D---- C:\WINDOWS\system32\drivers
2010-11-17 09:10:05 ----HD---- C:\WINDOWS\inf
2010-11-17 09:10:04 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-11-17 09:10:04 ----D---- C:\WINDOWS\system32\CatRoot
2010-11-17 09:09:07 ----D---- C:\Program Files\Outlook Express
2010-11-17 09:08:00 ----D---- C:\Program Files\Movie Maker
2010-11-17 09:00:38 ----D---- C:\Program Files\Messenger
2010-11-17 09:00:32 ----D---- C:\WINDOWS\WinSxS
2010-11-17 08:59:51 ----D---- C:\WINDOWS\security
2010-11-17 08:56:03 ----D---- C:\Program Files\Windows Media Player
2010-11-17 08:56:02 ----D---- C:\WINDOWS\Help
2010-11-17 08:55:56 ----D---- C:\WINDOWS\network diagnostic
2010-11-17 08:55:55 ----D---- C:\WINDOWS\ime
2010-11-17 08:55:45 ----D---- C:\WINDOWS\system32\usmt
2010-11-17 08:55:45 ----D---- C:\WINDOWS\system32\pl-PL
2010-11-17 08:55:45 ----D---- C:\Program Files\Internet Explorer
2010-11-17 08:55:44 ----SHD---- C:\WINDOWS\Installer
2010-11-17 08:55:44 ----D---- C:\WINDOWS\PeerNet
2010-11-17 08:54:13 ----D---- C:\WINDOWS\ServicePackFiles
2010-11-17 08:54:10 ----D---- C:\WINDOWS\system32\Restore
2010-11-17 08:54:10 ----D---- C:\WINDOWS\system32\npp
2010-11-17 08:54:09 ----D---- C:\WINDOWS\msagent
2010-11-17 08:54:08 ----D---- C:\WINDOWS\srchasst
2010-11-17 08:54:07 ----D---- C:\Program Files\NetMeeting
2010-11-17 08:54:06 ----D---- C:\WINDOWS\system32\Com
2010-11-17 08:54:04 ----D---- C:\Program Files\Windows NT
2010-11-17 08:54:01 ----D---- C:\Program Files\Common Files\System
2010-11-17 08:53:44 ----D---- C:\WINDOWS\system32\oobe
2010-11-17 08:53:43 ----D---- C:\WINDOWS\system
2010-11-17 08:09:18 ----D---- C:\Documents and Settings\Eldorado\Dane aplikacji\skypePM
2010-11-10 07:44:52 ----HD---- C:\Config.Msi
2010-11-08 10:50:10 ----A---- C:\WINDOWS\Printout.012.INI
2010-11-08 10:47:01 ----D---- C:\ET
2010-11-02 16:47:16 ----A---- C:\WINDOWS\system32\MRT.exe
2010-10-21 13:41:25 ----D---- C:\Program Files\McAfee Security Scan
2010-10-18 16:57:03 ----D---- C:\Program Files\Mozilla Firefox

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2005-08-12 98432]
R0 ohci1394;Kontroler hosta IEEE 1394 VIA zgodny z OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R1 AmdK8;Sterownik procesora AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 43008]
R2 NwlnkIpx;Protokół transportowy zgodny z NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;System NetBIOS NWLink; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-04 63232]
R2 NwlnkSpx;Protokół NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-04 55936]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-10-04 3797632]
R3 Arp1394;Protokół klienta 1394 ARP; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 NIC1394;Sterownik sieci 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-10-17 3530880]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-07-29 34048]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-07-29 12928]
R3 ZTPPPOE;WAN Miniport (PPP over Ethernet Protocol); C:\WINDOWS\system32\DRIVERS\ztpppoe.sys [2009-07-09 30720]
S1 kbdhid;Sterownik klawiatury HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
S3 HidUsb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-03-20 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-03-20 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-03-20 21568]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys []
S3 usb_rndis;ZTE USB Remote NDIS Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
S3 usbccgp;Rodzajowy sterownik nadrzędny USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Klasa PRINTER USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Sterownik skanera USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Sterownik magazynu masowego USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-01 153376]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-10-17 131139]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 gupdate;Usługa Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-01 135664]
S3 aspnet_state;Usuga stanu ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-01 182768]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Usługa udostępniania portów Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
[/log]

[log]info.txt logfile of random's system information tool 1.08 2010-11-17 10:14:26

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
AbiWord 2.8.4-->C:\Program Files\AbiWord\UninstallAbiWord2.exe
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_ActiveX.exe -maintain activex
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.1.3 - Polish-->MsiExec.exe /I{AC76BA86-7AD7-1045-7B44-A91000000001}
Adobe Shockwave Player 11.5-->"C:\WINDOWS\system32\Adobe\Shockwave 11\uninstaller.exe"
Aktualizacja dla systemu Windows Internet Explorer 8 (KB976662)-->"C:\WINDOWS\ie8updates\KB976662-IE8\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows Internet Explorer 8 (KB980182)-->"C:\WINDOWS\ie8updates\KB980182-IE8\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows Internet Explorer 8 (KB980302)-->"C:\WINDOWS\ie8updates\KB980302-IE8\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB976749)-->"C:\WINDOWS\$NtUninstallKB976749$\spuninst\spuninst.exe"
Aktualizacja dla systemu Windows XP (KB978207)-->"C:\WINDOWS\$NtUninstallKB978207$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB978695)-->"C:\WINDOWS\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla programu Windows Media Player (KB979402)-->"C:\WINDOWS\$NtUninstallKB979402_WM9L$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 8 (KB981332)-->"C:\WINDOWS\ie8updates\KB981332-IE8\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows Internet Explorer 8 (KB982381)-->"C:\WINDOWS\ie8updates\KB982381-IE8\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB2229593)-->"C:\WINDOWS\$NtUninstallKB2229593$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB961371-v2)-->"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB972260)-->"C:\WINDOWS\$NtUninstallKB972260$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB974455)-->"C:\WINDOWS\$NtUninstallKB974455$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB975561)-->"C:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB975562)-->"C:\WINDOWS\$NtUninstallKB975562$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB976325)-->"C:\WINDOWS\$NtUninstallKB976325$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB977165-v2)-->"C:\WINDOWS\$NtUninstallKB977165-v2$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB977816)-->"C:\WINDOWS\$NtUninstallKB977816$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB978338)-->"C:\WINDOWS\$NtUninstallKB978338$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB978542)-->"C:\WINDOWS\$NtUninstallKB978542$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB978601)-->"C:\WINDOWS\$NtUninstallKB978601$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB978706)-->"C:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB979309)-->"C:\WINDOWS\$NtUninstallKB979309$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB979482)-->"C:\WINDOWS\$NtUninstallKB979482$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB979559)-->"C:\WINDOWS\$NtUninstallKB979559$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB979683)-->"C:\WINDOWS\$NtUninstallKB979683$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB980195)-->"C:\WINDOWS\$NtUninstallKB980195$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB980218)-->"C:\WINDOWS\$NtUninstallKB980218$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla systemu Windows XP (KB980232)-->"C:\WINDOWS\$NtUninstallKB980232$\spuninst\spuninst.exe"
Aktualizacja zabezpieczeń dla Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Athlon 64 Processor Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x15
Dodatek Zapisywanie jako PDF lub XPS firmy Microsoft dla programów pakietu Microsoft Office 2007-->MsiExec.exe /X{90120000-00B2-0415-0000-0000000FF1CE}
Easy Burning (remove only)-->C:\Program Files\EasyBurning\Uninst Easy_Burning.exe
EasyDialer-->"C:\Program Files\ZTE\EasyDialer\unins000.exe"
euro TICKET on-line Sprzedaż-->"C:\ET\unins000.exe"
Free PDF to Word Doc Converter v1.1-->"C:\Program Files\Free PDF to Word Doc Converter\unins000.exe"
Gadu-Gadu 10-->C:\Program Files\Gadu-Gadu 10\Uninstall.exe
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_AC0049E063DE2AEA.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Customer Participation Program 7.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Document Viewer 7.0-->C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
HP Imaging Device Functions 7.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP LaserJet M1005-->C:\Program Files\Agilent-HP\{a324bee9-c355-4984-9bde-0e85f4a1d7ec}\uninstall.exe SYSTEM "C:\Program Files\Agilent-HP\{a324bee9-c355-4984-9bde-0e85f4a1d7ec}"
HP Officejet Pro All-In-One Series-->C:\Program Files\HP\Digital Imaging\{7729A02E-D1AD-4830-8FC5-11853500D90D}\setup\hpzscr01.exe -datfile hpwscr05.dat
HP OrderReminder-->"C:\Program Files\Hewlett-Packard\OrderReminder\uninstall\hpuninstaller.exe" hp_LaserJet_1018
HP Photosmart Essential-->MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F}
HP Photosmart Premier Software 6.5-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Software Update-->MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
HP Solution Center 7.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
ipla 2.1.2-->C:\Program Files\ipla\uninst.exe
Java™ 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
KSI SWPB 2-->MsiExec.exe /X{AE95CDDA-A29E-43CB-9EEA-4B418F30DEA4}
McAfee Security Scan Plus-->"C:\Program Files\McAfee Security Scan\uninstall.exe"
Microsoft .NET Framework 1.1 Polish Language Pack-->MsiExec.exe /X{64CB2553-C109-4132-AA51-1F421B515FD1}
Microsoft .NET Framework 1.1 Security Update (KB979906)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PLK-->MsiExec.exe /I{2AFF2951-86B1-3C53-B34D-B440F11E7D0A}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PLK-->MsiExec.exe /I{5A0DDC27-88E5-3CAD-BC3D-28FFD05CA6B9}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 Language Pack SP1 - plk-->MsiExec.exe /I{9EFDFBA8-9174-3C61-8645-28376C5CA994}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Excel MUI (Polish) 2007-->MsiExec.exe /X{90120000-0016-0415-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Polish) 2007-->MsiExec.exe /X{90120000-00A1-0415-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Polish) 2007-->MsiExec.exe /X{90120000-0018-0415-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Polish) 2007-->MsiExec.exe /X{90120000-001F-0415-0000-0000000FF1CE}
Microsoft Office Proofing (Polish) 2007-->MsiExec.exe /X{90120000-002C-0415-0000-0000000FF1CE}
Microsoft Office Shared MUI (Polish) 2007-->MsiExec.exe /X{90120000-006E-0415-0000-0000000FF1CE}
Microsoft Office Word MUI (Polish) 2007-->MsiExec.exe /X{90120000-001B-0415-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Mozilla Firefox (3.6.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MPM-->MsiExec.exe /X{D48AD533-BAD5-469B-A9AA-272C6D80E70B}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 6 Service Pack 2 (KB973686)-->MsiExec.exe /I{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
Nauka Jazdy-->"C:\Program Files\Grupa33\TPJ2010\Uninstall.exe"
Nero 6 Enterprise Edition-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Norton Security Scan-->C:\Program Files\Norton Security Scan\Engine\2.7.3.34\InstWrap.exe
NVIDIA Drivers-->C:\WINDOWS\system32\nvuide.exe UninstallGUI
OCR Software by I.R.I.S 7.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - plk\setup.exe
Poprawka dla systemu Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Poprawka dla systemu Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Poprawka dla systemu Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
Poprawka dla systemu Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
Poprawka dla systemu Windows XP (KB979306)-->"C:\WINDOWS\$NtUninstallKB979306$\spuninst\spuninst.exe"
Poprawka dla systemu Windows XP (KB981793)-->"C:\WINDOWS\$NtUninstallKB981793$\spuninst\spuninst.exe"
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x15 -removeonly
Scan To-->MsiExec.exe /I{9356940C-B360-4EF4-BE6C-BD488350AB17}
Skaner on-line mks_vir-->C:\WINDOWS\system32\SkanerOnlineUninstall.exe
Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
VeryPDF PDF2Word v3.0-->"C:\Program Files\VeryPDF PDF2Word v3.0\unins000.exe"
Winamp Toolbar-->"C:\Program Files\Winamp Toolbar\uninstall.exe"
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
ZTE Remote NDIS Device-->"C:\Program Files\ADSL Router\unins000.exe"

======Hosts File======

127.0.0.1 NtKrnlpa.info

======System event log======

Computer Name: ELDORADO1
Event Code: 7035
Message: Do usługi Google Software Updater został pomyślnie wysłany kod sterowania uruchom.

Record Number: 8646
Source Name: Service Control Manager
Time Written: 20100915083243.000000+120
Event Type: informacje
User: ZARZĄDZANIE NT\SYSTEM

Computer Name: ELDORADO1
Event Code: 7036
Message: Usługa Usługa Google Update (gupdate) weszła w stan zatrzymania.

Record Number: 8645
Source Name: Service Control Manager
Time Written: 20100915083122.000000+120
Event Type: informacje
User:

Computer Name: ELDORADO1
Event Code: 7036
Message: Usługa HTTP SSL weszła w stan uruchomienia.

Record Number: 8644
Source Name: Service Control Manager
Time Written: 20100915083106.000000+120
Event Type: informacje
User:

Computer Name: ELDORADO1
Event Code: 7035
Message: Do usługi HTTP SSL został pomyślnie wysłany kod sterowania uruchom.

Record Number: 8643
Source Name: Service Control Manager
Time Written: 20100915083106.000000+120
Event Type: informacje
User: ZARZĄDZANIE NT\USŁUGA LOKALNA

Computer Name: ELDORADO1
Event Code: 7036
Message: Usługa Karta wydajności WMI weszła w stan zatrzymania.

Record Number: 8642
Source Name: Service Control Manager
Time Written: 20100915083106.000000+120
Event Type: informacje
User:

=====Application event log=====

Computer Name: ELDORADO-9CA899
Event Code: 0
Message:
Record Number: 765
Source Name: gupdate
Time Written: 20100517085430.000000+120
Event Type: informacje
User:

Computer Name: ELDORADO-9CA899
Event Code: 0
Message:
Record Number: 764
Source Name: gusvc
Time Written: 20100517085405.000000+120
Event Type: informacje
User:

Computer Name: ELDORADO-9CA899
Event Code: 1800
Message: Usługa Centrum zabezpieczeń systemu Windows została uruchomiona.

Record Number: 763
Source Name: SecurityCenter
Time Written: 20100517085355.000000+120
Event Type: informacje
User:

Computer Name: ELDORADO-9CA899
Event Code: 0
Message:
Record Number: 762
Source Name: gupdate
Time Written: 20100517085354.000000+120
Event Type: informacje
User:

Computer Name: ELDORADO-9CA899
Event Code: 1517
Message: System Windows zapisał rejestr użytkownika ELDORADO-9CA899\Eldorado, kiedy aplikacja lub usługa nadal użytkowała rejestr podczas wylogowania. Pamięć używana przez rejestr użytkownika nie została zwolniona. Rejestr zostanie zwolniony, kiedy nie będzie używany.


Najczęstszą tego przyczyną są usługi uruchamiane z konta użytkownika. Próbuj skonfigurować te usługi, aby były uruchamiane z konta LocalService lub NetworkService.

Record Number: 761
Source Name: Userenv
Time Written: 20100515125149.000000+120
Event Type: ostrzeżenie
User: ZARZĄDZANIE NT\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 44 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=2c02
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------
[/log]

bardzo proszę o pomoc :(
[color="#ff0000"]
//przenoszę do Bezpieczeństwa
//dan[/color]

Tomek01
komentarz
komentarz

Odinstaluj Winamp Toolbar jeśli nie używasz.

W OTL, w oknie Custom scan/fixes wklej:
[code]:Processes
Explorer.exe

:OTL
PRC - [2010-11-17 07:55:34 | 000,586,240 | ---- | M] (Monkey Software) -- C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe
PRC - [2010-07-13 15:52:25 | 000,074,752 | -HS- | M] (Jznof) -- C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe
[2010-09-24 11:26:56 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010-10-18 16:57:14 | 000,001,196 | ---- | M] () -- C:\Documents and Settings\Eldorado\Dane aplikacji\Mozilla\Firefox\Profiles\wfabp8ve.default\searchplugins\winamp-search.xml
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKU\S-1-5-21-606747145-152049171-725345543-1004\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O20 - HKU\S-1-5-21-606747145-152049171-725345543-1004 Winlogon: Shell - (C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe) - C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe (Monkey Software)
O33 - MountPoints2\{09be80d0-db2b-11de-9a22-0016e658ee63}\Shell - "" = AutoRun
O33 - MountPoints2\{09be80d0-db2b-11de-9a22-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{09be80d1-db2b-11de-9a22-0016e658ee63}\Shell - "" = AutoRun
O33 - MountPoints2\{09be80d1-db2b-11de-9a22-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{12ff8e88-4c72-11df-9a48-0016e658ee63}\Shell\AutoRun\command - "" = NADFOLDER\autorun.exe
O33 - MountPoints2\{12ff8e88-4c72-11df-9a48-0016e658ee63}\Shell\open\command - "" = NADFOLDER\autorun.exe
O33 - MountPoints2\{2d155864-ae63-11de-99fa-0016e658ee63}\Shell - "" = AutoRun
O33 - MountPoints2\{2d155864-ae63-11de-99fa-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{2d155865-ae63-11de-99fa-0016e658ee63}\Shell - "" = AutoRun
O33 - MountPoints2\{2d155865-ae63-11de-99fa-0016e658ee63}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found

:Files
C:\Documents and Settings\Eldorado\Dane aplikacji\hotfix.exe
C:\Documents and Settings\Eldorado\Dane aplikacji\start
C:\Documents and Settings\Eldorado\Dane aplikacji\install
C:\Documents and Settings\Eldorado\Dane aplikacji\completescan
C:\Documents and Settings\Eldorado\Dane aplikacji\.#
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-152049171-725345543-1004UA.job
C:\Documents and Settings\Eldorado\Dane aplikacji\SystemProc\lsass.exe

:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"RTHDBPL"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""

:Services
Jznof

:Commands
[emptytemp]
[start explorer]
[Reboot][/code]

Klikasz run fix, komputer uruchamia się ponownie.
Wrzuć log z usuwania oraz nowe logi: OTL i RSIT.

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.