x-kom hosting

WmiPrvSE.exe spowalnia komputer

Gregor1
utworzono
utworzono

Witam serdecznie

Problem polega na tym ze, w/w proces co chwilę używa 60-80% procesora.

OTL:
[log]OTL logfile created on: 2010-11-21 19:22:31 - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Grzegorz\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 59,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 78,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99,61 Gb Total Space | 67,42 Gb Free Space | 67,68% Space Free | Partition Type: NTFS
Drive D: | 198,38 Gb Total Space | 82,32 Gb Free Space | 41,50% Space Free | Partition Type: NTFS
Drive F: | 982,03 Mb Total Space | 751,41 Mb Free Space | 76,52% Space Free | Partition Type: FAT

Computer Name: GRZEGORZ-3810T | User Name: Grzegorz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Processes (All) ==========[/color]

PRC - [2010-11-21 16:28:30 | 015,900,672 | ---- | M] (Adobe Systems, Incorporated) -- C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe
PRC - [2010-11-20 20:25:37 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Grzegorz\Desktop\OTL.exe
PRC - [2010-11-19 09:21:00 | 007,965,696 | ---- | M] (Creative Team S.A.) -- C:\Program Files\WapSter\WapSter AQQ\AQQ.exe
PRC - [2010-11-01 22:36:03 | 000,974,904 | ---- | M] (Google Inc.) -- C:\Users\Grzegorz\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2010-10-09 18:57:36 | 000,328,056 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2010-09-07 16:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010-09-07 16:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010-08-21 06:32:37 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spoolsv.exe
PRC - [2010-07-04 18:07:40 | 000,238,952 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe
PRC - [2010-04-15 22:38:33 | 000,049,792 | ---- | M] (TMRG, Inc.) -- C:\Program Files\RelevantKnowledge\rlservice.exe
PRC - [2010-04-15 22:38:31 | 001,860,736 | ---- | M] (TMRG, Inc.) -- C:\Program Files\RelevantKnowledge\rlvknlg.exe
PRC - [2009-10-31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009-10-28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winlogon.exe
PRC - [2009-10-02 14:29:38 | 000,694,816 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
PRC - [2009-10-02 14:29:16 | 000,690,720 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
PRC - [2009-10-02 14:28:30 | 000,469,536 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe
PRC - [2009-09-07 17:44:14 | 004,057,600 | ---- | M] () -- C:\Program Files\OSCARK3G5\OscarEditor.exe
PRC - [2009-09-02 18:18:44 | 000,135,168 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxtray.exe
PRC - [2009-09-02 18:18:32 | 000,167,424 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hkcmd.exe
PRC - [2009-09-02 18:18:22 | 000,144,384 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpers.exe
PRC - [2009-09-02 18:18:12 | 000,246,272 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.exe
PRC - [2009-07-17 15:30:48 | 000,582,944 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
PRC - [2009-07-14 02:14:50 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WUDFHost.exe
PRC - [2009-07-14 02:14:47 | 000,254,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\WmiPrvSE.exe
PRC - [2009-07-14 02:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wininit.exe
PRC - [2009-07-14 02:14:43 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
PRC - [2009-07-14 02:14:42 | 000,227,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskmgr.exe
PRC - [2009-07-14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\svchost.exe [comLaunch]
PRC - [2009-07-14 02:14:39 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\smss.exe
PRC - [2009-07-14 02:14:38 | 001,173,504 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2009-07-14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\services.exe
PRC - [2009-07-14 02:14:35 | 000,428,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SearchIndexer.exe
PRC - [2009-07-14 02:14:23 | 000,261,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lsm.exe
PRC - [2009-07-14 02:14:23 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lsass.exe
PRC - [2009-07-14 02:14:19 | 000,092,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwm.exe
PRC - [2009-07-14 02:14:16 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\csrss.exe
PRC - [2006-10-27 14:23:04 | 000,347,432 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\WINWORD.EXE


[color=#E56717]========== Modules (All) ==========[/color]

MOD - [2010-11-20 20:25:37 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Grzegorz\Desktop\OTL.exe
MOD - [2010-08-21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2010-07-27 15:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shell32.dll
MOD - [2010-06-29 06:02:02 | 001,413,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ole32.dll
MOD - [2010-03-24 07:37:04 | 001,286,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntdll.dll
MOD - [2009-12-08 12:33:31 | 000,857,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\kernel32.dll
MOD - [2009-12-08 12:32:02 | 000,292,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\apphelp.dll
MOD - [2009-10-02 14:35:22 | 000,215,584 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer PowerSmart Manager\SysHook.dll
MOD - [2009-07-14 02:16:19 | 000,268,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Wldap32.dll
MOD - [2009-07-14 02:16:17 | 001,123,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vssapi.dll
MOD - [2009-07-14 02:16:17 | 000,811,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\user32.dll
MOD - [2009-07-14 02:16:17 | 000,627,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\usp10.dll
MOD - [2009-07-14 02:16:17 | 000,249,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\uxtheme.dll
MOD - [2009-07-14 02:16:17 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vsstrace.dll
MOD - [2009-07-14 02:16:17 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\version.dll
MOD - [2009-07-14 02:16:15 | 000,171,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spp.dll
MOD - [2009-07-14 02:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll
MOD - [2009-07-14 02:16:15 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\srclient.dll
MOD - [2009-07-14 02:16:14 | 001,668,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\setupapi.dll
MOD - [2009-07-14 02:16:14 | 000,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shlwapi.dll
MOD - [2009-07-14 02:16:14 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\shdocvw.dll
MOD - [2009-07-14 02:16:13 | 000,652,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rpcrt4.dll
MOD - [2009-07-14 02:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll
MOD - [2009-07-14 02:16:13 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samlib.dll
MOD - [2009-07-14 02:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll
MOD - [2009-07-14 02:16:13 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\secur32.dll
MOD - [2009-07-14 02:16:12 | 000,988,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\propsys.dll
MOD - [2009-07-14 02:16:12 | 000,571,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\oleaut32.dll
MOD - [2009-07-14 02:16:12 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\olepro32.dll
MOD - [2009-07-14 02:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll
MOD - [2009-07-14 02:16:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\psapi.dll
MOD - [2009-07-14 02:16:11 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntmarta.dll
MOD - [2009-07-14 02:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll
MOD - [2009-07-14 02:15:50 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msvcrt.dll
MOD - [2009-07-14 02:15:43 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msctf.dll
MOD - [2009-07-14 02:15:36 | 000,026,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lpk.dll
MOD - [2009-07-14 02:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll
MOD - [2009-07-14 02:15:32 | 000,118,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imm32.dll
MOD - [2009-07-14 02:15:22 | 000,304,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gdi32.dll
MOD - [2009-07-14 02:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
MOD - [2009-07-14 02:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll
MOD - [2009-07-14 02:15:07 | 000,486,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\comdlg32.dll
MOD - [2009-07-14 02:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll
MOD - [2009-07-14 02:15:03 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\clbcatq.dll
MOD - [2009-07-14 02:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
MOD - [2009-07-14 02:14:57 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\atl.dll
MOD - [2009-07-14 02:14:53 | 000,640,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\advapi32.dll
MOD - [2009-07-14 02:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
MOD - [2009-07-14 02:14:08 | 000,319,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\winspool.drv


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2010-09-16 21:48:39 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010-09-07 16:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010-09-07 16:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010-09-07 16:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010-07-04 18:07:40 | 000,238,952 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010-04-15 22:38:33 | 000,049,792 | ---- | M] (TMRG, Inc.) [Auto | Running] -- C:\Program Files\RelevantKnowledge\rlservice.exe -- (RelevantKnowledge)
SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-10-02 14:29:16 | 000,690,720 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe -- (ePowerSvc)
SRV - [2009-07-17 15:30:48 | 000,582,944 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2009-07-14 02:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc)
SRV - [2009-07-14 02:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc)
SRV - [2009-07-14 02:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power)
SRV - [2009-07-14 02:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2009-07-14 02:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sppuinotify.dll -- (sppuinotify)
SRV - [2009-07-14 02:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper)
SRV - [2009-07-14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009-07-14 02:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc)
SRV - [2009-07-14 02:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc)
SRV - [2009-07-14 02:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider)
SRV - [2009-07-14 02:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg)
SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009-07-14 02:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener)
SRV - [2009-07-14 02:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009-07-14 02:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2009-07-14 02:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc)
SRV - [2009-07-14 02:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC)
SRV - [2009-07-14 02:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) Instalator formantów ActiveX (AxInstSV)
SRV - [2009-07-14 02:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc)
SRV - [2009-07-14 02:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\sppsvc.exe -- (sppsvc)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2010-09-16 20:52:48 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010-09-07 15:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010-09-07 15:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010-09-07 15:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010-09-07 15:47:30 | 000,050,768 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2010-09-07 15:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010-06-14 08:32:54 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009-12-11 08:44:02 | 000,133,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg)
DRV - [2009-09-15 19:40:18 | 006,114,816 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5s32.sys -- (NETw5s32) Sterownik karty Intel(R)
DRV - [2009-09-02 18:48:08 | 005,946,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\igdkmd32.sys -- (igfx)
DRV - [2009-09-02 08:59:42 | 000,174,592 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009-07-14 02:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\cmdide.sys -- (cmdide)
DRV - [2009-07-14 02:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpahci.sys -- (adpahci)
DRV - [2009-07-14 02:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adp94xx.sys -- (adp94xx)
DRV - [2009-07-14 02:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs)
DRV - [2009-07-14 02:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpu320.sys -- (adpu320)
DRV - [2009-07-14 02:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arcsas.sys -- (arcsas)
DRV - [2009-07-14 02:26:15 | 000,079,952 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsata.sys -- (amdsata)
DRV - [2009-07-14 02:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arc.sys -- (arc)
DRV - [2009-07-14 02:26:15 | 000,023,616 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\amdxata.sys -- (amdxata)
DRV - [2009-07-14 02:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\aliide.sys -- (aliide)
DRV - [2009-07-14 02:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvstor.sys -- (nvstor)
DRV - [2009-07-14 02:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvraid.sys -- (nvraid)
DRV - [2009-07-14 02:20:44 | 000,044,624 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nfrd960.sys -- (nfrd960)
DRV - [2009-07-14 02:20:37 | 000,089,168 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas.sys -- (LSI_SAS)
DRV - [2009-07-14 02:20:36 | 000,332,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iaStorV.sys -- (iaStorV)
DRV - [2009-07-14 02:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MegaSR.sys -- (MegaSR)
DRV - [2009-07-14 02:20:36 | 000,096,848 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2009-07-14 02:20:36 | 000,095,824 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_fc.sys -- (LSI_FC)
DRV - [2009-07-14 02:20:36 | 000,054,864 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2)
DRV - [2009-07-14 02:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iirsp.sys -- (iirsp)
DRV - [2009-07-14 02:20:36 | 000,030,800 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\megasas.sys -- (megasas)
DRV - [2009-07-14 02:20:36 | 000,013,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hwpolicy.sys -- (hwpolicy)
DRV - [2009-07-14 02:20:28 | 000,453,712 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\elxstor.sys -- (elxstor)
DRV - [2009-07-14 02:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\djsvs.sys -- (aic78xx)
DRV - [2009-07-14 02:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HpSAMD.sys -- (HpSAMD)
DRV - [2009-07-14 02:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fsdepends.sys -- (FsDepends)
DRV - [2009-07-14 02:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vsmraid.sys -- (vsmraid)
DRV - [2009-07-14 02:19:10 | 000,159,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vhdmp.sys -- (vhdmp)
DRV - [2009-07-14 02:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vdrvroot.sys -- (vdrvroot)
DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\wimmount.sys -- (WIMMount)
DRV - [2009-07-14 02:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\viaide.sys -- (viaide)
DRV - [2009-07-14 02:19:04 | 001,383,488 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql2300.sys -- (ql2300)
DRV - [2009-07-14 02:19:04 | 000,173,648 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rdyboost.sys -- (rdyboost)
DRV - [2009-07-14 02:19:04 | 000,106,064 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql40xx.sys -- (ql40xx)
DRV - [2009-07-14 02:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\sisraid4.sys -- (SiSRaid4)
DRV - [2009-07-14 02:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pcw.sys -- (pcw)
DRV - [2009-07-14 02:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\SiSRaid2.sys -- (SiSRaid2)
DRV - [2009-07-14 02:19:04 | 000,021,072 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor)
DRV - [2009-07-14 02:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\cng.sys -- (CNG)
DRV - [2009-07-14 01:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\Brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2009-07-14 01:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\rdpbus.sys -- (rdpbus)
DRV - [2009-07-14 01:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV - [2009-07-14 00:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
DRV - [2009-07-14 00:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\wfplwf.sys -- (WfpLwf)
DRV - [2009-07-14 00:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ndiscap.sys -- (NdisCap)
DRV - [2009-07-14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009-07-14 00:52:04 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vwififlt.sys -- (VWiFiFlt)
DRV - [2009-07-14 00:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifibus.sys -- (vwifibus)
DRV - [2009-07-14 00:52:00 | 000,163,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\1394ohci.sys -- (1394ohci)
DRV - [2009-07-14 00:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\umpass.sys -- (UmPass)
DRV - [2009-07-14 00:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV - [2009-07-14 00:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MTConfig.sys -- (MTConfig)
DRV - [2009-07-14 00:45:26 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CompositeBus.sys -- (CompositeBus)
DRV - [2009-07-14 00:36:52 | 000,050,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\appid.sys -- (AppID)
DRV - [2009-07-14 00:33:50 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\scfilter.sys -- (scfilter)
DRV - [2009-07-14 00:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\discache.sys -- (discache)
DRV - [2009-07-14 00:16:36 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\acpipmi.sys -- (AcpiPmi)
DRV - [2009-07-14 00:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdppm.sys -- (AmdPPM)
DRV - [2009-07-13 23:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009-07-13 23:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbMdm.sys -- (BrUsbMdm)
DRV - [2009-07-13 23:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbSer.sys -- (BrUsbSer)
DRV - [2009-07-13 23:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrSerWdm.sys -- (BrSerWdm)
DRV - [2009-07-13 23:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltLo.sys -- (BrFiltLo)
DRV - [2009-07-13 23:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltUp.sys -- (BrFiltUp)
DRV - [2009-07-13 23:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2009-07-13 23:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\evbdx.sys -- (ebdrv)
DRV - [2009-07-13 23:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\bxvbdx.sys -- (b06bdrv)
DRV - [2009-07-13 23:02:47 | 000,050,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20)
DRV - [2009-07-02 02:46:14 | 000,086,056 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btwaudio.sys -- (btwaudio)
DRV - [2009-07-02 02:46:12 | 000,108,072 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btwavdt.sys -- (btwavdt)
DRV - [2009-07-02 02:46:04 | 000,018,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btwrchid.sys -- (btwrchid)
DRV - [2009-06-04 14:43:16 | 000,330,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2009-05-26 03:12:36 | 000,122,368 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel(R)
DRV - [2009-05-14 07:40:38 | 004,231,680 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw5v32.sys -- (netw5v32) Intel(R)
DRV - [2009-05-06 17:15:38 | 001,759,744 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2009-04-08 05:32:50 | 000,029,472 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btwl2cap.sys -- (btwl2cap)
DRV - [2008-02-19 14:39:44 | 000,191,424 | ---- | M] (Jungo) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\windrvr6.sys -- (WinDriver6)
DRV - [2008-02-02 13:58:26 | 000,053,760 | ---- | M] (Microchip Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mchpusb.sys -- (MCHPUSB)
DRV - [2007-09-28 01:54:10 | 000,003,584 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\DLPORTIO.sys -- (DLPortIO)
DRV - [2007-07-31 18:45:50 | 000,076,800 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2005-06-22 17:17:02 | 000,033,792 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\libusb0.sys -- (libusb0)
DRV - [1998-11-27 18:57:18 | 000,006,144 | ---- | M] (Erik Salaj) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\IOPORT.SYS -- (IOPort)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2396130858-3024342048-3616289110-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010-11-07 09:52:10 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\mozilla\Extensions
[2010-10-04 07:17:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Grzegorz\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010-11-07 09:52:10 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\mozilla\Firefox\Profiles\fpasb2fn.default\extensions
[2010-11-07 09:51:59 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010-10-27 06:37:26 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2010-10-27 06:37:26 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2010-10-27 06:37:26 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2010-10-27 06:37:26 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2010-10-27 06:37:26 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2010-10-27 06:37:26 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2009-06-10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Acer Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKU\S-1-5-21-2396130858-3024342048-3616289110-1000..\Run: [DriverMax] File not found
O4 - HKU\S-1-5-21-2396130858-3024342048-3616289110-1000..\Run: [DriverMax_RESTART] File not found
O4 - HKU\S-1-5-21-2396130858-3024342048-3616289110-1000..\Run: [OscarEditor] C:\Program Files\OSCARK3G5\OscarEditor.exe ()
O4 - HKU\S-1-5-21-2396130858-3024342048-3616289110-1000..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: Wyślij obraz do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Wyślij stronę do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{d92297bb-c271-11df-8486-00a0d1af75ea}\Shell - "" = AutoRun
O33 - MountPoints2\{d92297bb-c271-11df-8486-00a0d1af75ea}\Shell\AutoRun\command - "" = E:\setup.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe - (Broadcom Corporation.)
MsConfig - StartUpFolder: C:^Users^Grzegorz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE - (Microsoft Corporation)
MsConfig - StartUpReg: [b]Adobe ARM[/b] - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe File not found
MsConfig - StartUpReg: [b]Adobe Reader Speed Launcher[/b] - hkey= - key= - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe File not found
MsConfig - StartUpReg: [b]AutoStartNPSAgent[/b] - hkey= - key= - C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
MsConfig - StartUpReg: [b]BIH[/b] - hkey= - key= - File not found
MsConfig - StartUpReg: [b]DAEMON Tools Lite[/b] - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
MsConfig - StartUpReg: [b]Google Update[/b] - hkey= - key= - C:\Users\Grzegorz\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
MsConfig - StartUpReg: [b]GrooveMonitor[/b] - hkey= - key= - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
MsConfig - StartUpReg: [b]HotKeysCmds[/b] - hkey= - key= - File not found
MsConfig - StartUpReg: [b]OscarEditor[/b] - hkey= - key= - C:\Program Files\OSCARK3G5\OscarEditor.exe ()
MsConfig - StartUpReg: [b]Persistence[/b] - hkey= - key= - File not found
MsConfig - StartUpReg: [b]PLFSetI[/b] - hkey= - key= - C:\Windows\PLFSetI.exe ()
MsConfig - StartUpReg: [b]PLFSetL[/b] - hkey= - key= - C:\Windows\PLFSetL.exe (sonix)
MsConfig - StartUpReg: [b]Sidebar[/b] - hkey= - key= - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
MsConfig - StartUpReg: [b]snp2uvc[/b] - hkey= - key= - C:\Windows\vsnp2uvc.exe File not found
MsConfig - StartUpReg: [b]SunJavaUpdateSched[/b] - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
MsConfig - StartUpReg: [b]uTorrent[/b] - hkey= - key= - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
MsConfig - State: "startup" - 2

SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Power - C:\Windows\System32\umpo.dll (Microsoft Corporation)
SafeBootMin: Primary disk - Driver Group
SafeBootMin: RpcEptMapper - C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: Dhcp - C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: ndiscap - C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Power - C:\Windows\System32\umpo.dll (Microsoft Corporation)
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: RpcEptMapper - C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

[color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color]

[2010-11-21 18:54:54 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010-11-21 16:27:53 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010-11-21 16:23:38 | 000,000,000 | ---D | C] -- C:\temp_ps
[2010-11-21 16:12:35 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Desktop\Banlieue.13.Ultimatum.2009.DvDRip-FxM
[2010-11-21 09:37:40 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Desktop\ee541
[2010-11-21 09:31:01 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010-11-20 20:25:37 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Grzegorz\Desktop\OTL.exe
[2010-11-20 15:17:52 | 000,000,000 | ---D | C] -- C:\Program Files\OSCARK3G5
[2010-11-20 15:15:25 | 000,000,000 | ---D | C] -- C:\Program Files\OscarG7
[2010-11-20 09:43:49 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Roaming\MathWorks
[2010-11-20 09:43:23 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Documents\MATLAB
[2010-11-20 09:22:50 | 000,000,000 | ---D | C] -- C:\Program Files\RelevantKnowledge
[2010-11-20 09:21:53 | 000,000,000 | ---D | C] -- C:\Program Files\Mp3 Knife
[2010-11-20 09:20:03 | 000,000,000 | ---D | C] -- C:\Program Files\MATLAB
[2010-11-17 19:35:02 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2010-11-17 12:52:34 | 000,000,000 | ---D | C] -- C:\Program Files\Codemasters
[2010-11-17 12:46:38 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Local\GHISLER
[2010-11-15 21:29:35 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Roaming\PDF Writer
[2010-11-15 21:29:35 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Local\PDF Writer
[2010-11-15 21:29:35 | 000,000,000 | ---D | C] -- C:\ProgramData\PDF Writer
[2010-11-15 21:02:59 | 000,227,840 | ---- | C] (Bullzip) -- C:\Windows\System32\bzFlRdr.dll
[2010-11-15 21:02:59 | 000,135,168 | ---- | C] (Bullzip) -- C:\Windows\System32\bzpdfc.dll
[2010-11-15 21:02:59 | 000,103,424 | ---- | C] (Bullzip) -- C:\Windows\System32\bzDCT.dll
[2010-11-15 21:02:59 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Bullzip
[2010-11-15 21:02:56 | 000,196,096 | ---- | C] (Bullzip) -- C:\Windows\System32\bzpdf.dll
[2010-11-15 21:02:52 | 000,000,000 | ---D | C] -- C:\Program Files\Bullzip
[2010-11-11 22:48:00 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Local\MigWiz
[2010-11-11 18:43:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Novell Shared
[2010-11-07 09:52:05 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Local\Mozilla
[2010-11-07 09:51:58 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010-11-06 10:06:44 | 000,000,000 | ---D | C] -- C:\Warcraft III
[2010-11-06 10:06:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment
[2010-11-03 10:10:02 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Roaming\Termite
[2010-11-03 10:09:49 | 000,000,000 | ---D | C] -- C:\Program Files\Termite
[2010-11-02 18:39:11 | 000,000,000 | ---D | C] -- C:\Program Files\Prolific
[2010-11-02 18:38:56 | 000,076,800 | ---- | C] (Prolific Technology Inc.) -- C:\Windows\System32\drivers\ser2pl.sys
[2010-11-02 18:24:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2010-10-30 18:13:53 | 000,053,760 | ---- | C] (Microchip Technology, Inc.) -- C:\Windows\System32\drivers\mchpusb.sys
[2010-10-29 14:15:57 | 000,000,000 | ---D | C] -- C:\Program Files\BatteryMon
[2010-10-29 14:12:39 | 000,208,896 | ---- | C] (Thomas Michel eMail: support.batteryinfo@arcor.de Web: http://www.batteryinfo.de.vu or http://home.arcor.de/batteryinfo) -- C:\Windows\System32\bih.dll
[2010-10-29 14:12:39 | 000,000,000 | ---D | C] -- C:\Program Files\BatteryInfo
[2010-10-27 07:46:46 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Desktop\PIC
[2010-10-23 21:21:12 | 000,833,536 | ---- | C] (Trace Systems, Inc.) -- C:\Windows\System32\HIDagentXControl1.ocx
[2010-10-23 21:21:08 | 000,000,000 | ---D | C] -- C:\Program Files\melabs Programmer Beta
[2010-10-22 20:12:11 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Documents\Notesy programu OneNote
[2010-10-18 14:38:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\sda
[2010-10-18 14:28:17 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Documents\NPS
[2010-10-18 14:28:05 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Documents\My Art
[2010-10-18 14:17:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
[2010-10-18 14:17:16 | 000,238,952 | ---- | C] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe
[2010-10-18 14:17:09 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Roaming\Samsung
[2010-10-18 14:17:09 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Documents\My NPS Files
[2010-10-18 14:17:00 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Documents\Samsung
[2010-10-18 14:17:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2010-10-18 14:16:36 | 000,000,000 | ---D | C] -- C:\Program Files\MarkAny
[2010-10-18 14:16:17 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
[2010-10-18 14:15:22 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Local\Downloaded Installations
[2010-10-17 18:38:16 | 000,000,000 | ---D | C] -- C:\Program Files\AIMP2 Tools
[2010-10-11 07:39:16 | 000,165,584 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2010-10-11 07:39:16 | 000,046,672 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2010-10-11 07:39:16 | 000,023,376 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2010-10-11 07:39:16 | 000,017,744 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2010-10-11 07:39:15 | 000,050,768 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2010-10-11 07:39:05 | 000,167,592 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2010-10-11 07:39:05 | 000,038,848 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2010-10-09 13:00:10 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Documents\My Drivers
[2010-10-09 13:00:10 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Local\Innovative Solutions
[2010-10-09 13:00:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Innovative Solutions
[2010-10-09 13:00:00 | 000,000,000 | ---D | C] -- C:\Program Files\Innovative Solutions
[2010-10-06 15:50:42 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\Documents\test
[2010-10-06 15:45:12 | 000,000,000 | ---D | C] -- C:\WinAVR-20080610
[2010-10-06 15:31:14 | 000,102,400 | ---- | C] (Jungo) -- C:\Windows\System32\wdapi811.dll
[2010-10-06 15:31:13 | 003,858,432 | ---- | C] (BCGSoft Ltd) -- C:\Windows\System32\BCGCBPRO95580.dll
[2010-10-06 15:31:13 | 000,191,424 | ---- | C] (Jungo) -- C:\Windows\System32\drivers\windrvr6.sys
[2010-10-06 15:31:13 | 000,143,360 | ---- | C] (Jungo) -- C:\Windows\System32\wdapi920.dll
[2010-10-06 15:31:13 | 000,073,728 | ---- | C] (Rogue Wave Software Inc) -- C:\Windows\System32\RWUXThemeS.dll
[2010-10-06 15:31:06 | 000,000,000 | ---D | C] -- C:\Program Files\Atmel
[2010-10-06 12:48:13 | 000,171,520 | ---- | C] (Europress Software) -- C:\Windows\System32\cncs32.dll
[2010-10-06 12:48:13 | 000,000,000 | ---D | C] -- C:\Windows\Tablice
[2010-10-04 17:12:50 | 000,006,144 | ---- | C] (Erik Salaj) -- C:\Windows\System32\drivers\IOPORT.SYS
[2010-10-04 17:12:28 | 000,000,000 | ---D | C] -- C:\Program Files\MCS Electronics
[2010-10-04 15:24:02 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Local\Adobe
[2010-10-04 15:23:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2010-10-04 15:23:35 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010-10-04 07:17:56 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Roaming\Mozilla
[2010-10-04 07:17:54 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Roaming\Thunderbird
[2010-10-04 07:17:54 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Local\Thunderbird
[2010-09-30 20:05:21 | 000,000,000 | ---D | C] -- C:\BE2WorksDemo
[2010-09-29 18:52:13 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Local\ElevatedDiagnostics
[2010-09-27 18:56:04 | 000,000,000 | ---D | C] -- C:\Users\Grzegorz\AppData\Local\Labcenter Electronics
[2010-09-27 18:56:04 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Downloaded Data Sheets
[2010-09-25 12:39:01 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2010-09-16 18:37:02 | 000,225,280 | ---- | C] ( ) -- C:\Windows\System32\rsnp2uvc.dll

[color=#E56717]========== Files - Modified Within 60 Days ==========[/color]

[2010-11-21 19:08:05 | 000,001,070 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2396130858-3024342048-3616289110-1000UA.job
[2010-11-21 18:54:55 | 000,002,979 | ---- | M] () -- C:\Users\Grzegorz\Desktop\HiJackThis.lnk
[2010-11-21 18:49:00 | 000,001,040 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010-11-21 18:26:33 | 000,471,689 | ---- | M] () -- C:\Users\Grzegorz\Desktop\EE541.docx
[2010-11-21 17:35:41 | 000,697,912 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2010-11-21 17:35:41 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010-11-21 17:35:41 | 000,134,990 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2010-11-21 17:35:41 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010-11-21 16:44:12 | 000,000,162 | -H-- | M] () -- C:\Users\Grzegorz\Desktop\~$EE541.docx
[2010-11-21 16:39:48 | 000,014,800 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010-11-21 16:39:48 | 000,014,800 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010-11-21 16:32:46 | 000,001,036 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010-11-21 16:32:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010-11-21 16:32:17 | 2339,512,320 | -HS- | M] () -- C:\hiberfil.sys
[2010-11-21 16:28:34 | 000,001,323 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2010-11-21 15:08:00 | 000,001,018 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2396130858-3024342048-3616289110-1000Core.job
[2010-11-21 09:52:13 | 000,414,792 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010-11-21 00:02:29 | 000,000,860 | ---- | M] () -- C:\Users\Grzegorz\Desktop\AQQ.lnk
[2010-11-20 23:41:02 | 000,016,031 | ---- | M] () -- C:\Users\Grzegorz\Desktop\Projekty.xlsx
[2010-11-20 20:25:37 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Grzegorz\Desktop\OTL.exe
[2010-11-20 18:40:16 | 000,003,288 | ---- | M] () -- C:\bootsqm.dat
[2010-11-20 18:15:43 | 000,010,328 | ---- | M] () -- C:\Users\Grzegorz\Desktop\Kontakty_1439238.xml
[2010-11-20 09:42:07 | 000,001,178 | ---- | M] () -- C:\Users\Public\Desktop\MATLAB R2010a.lnk
[2010-11-20 09:21:57 | 000,000,927 | ---- | M] () -- C:\Users\Grzegorz\Desktop\Mp3 Knife.lnk
[2010-11-17 12:59:02 | 000,002,078 | ---- | M] () -- C:\Users\Public\Desktop\Colin McRae Rally 2.lnk
[2010-11-15 21:39:20 | 000,038,891 | ---- | M] () -- C:\Users\Grzegorz\Desktop\INSTRUKCJA.pdf
[2010-11-14 20:55:50 | 000,000,553 | ---- | M] () -- C:\Users\Grzegorz\Desktop\Terminal — skrót.lnk
[2010-11-13 21:48:26 | 000,001,001 | ---- | M] () -- C:\Users\Grzegorz\Desktop\Warcraft III.lnk
[2010-11-10 18:52:13 | 000,224,247 | ---- | M] () -- C:\Users\Grzegorz\Desktop\DS18B20.pdf
[2010-11-10 18:34:02 | 000,001,821 | ---- | M] () -- C:\Users\Grzegorz\AppData\Roaming\bascom-avr.xml
[2010-11-05 06:41:11 | 003,764,247 | ---- | M] () -- C:\Users\Grzegorz\Desktop\ATTiny2313.PDF
[2010-11-01 14:15:48 | 000,001,387 | ---- | M] () -- C:\Users\Grzegorz\Desktop\USBurn.lnk
[2010-10-29 14:12:39 | 000,208,896 | ---- | M] (Thomas Michel eMail: support.batteryinfo@arcor.de Web: http://www.batteryinfo.de.vu or http://home.arcor.de/batteryinfo) -- C:\Windows\System32\bih.dll
[2010-10-16 08:23:43 | 007,156,174 | ---- | M] () -- C:\Users\Grzegorz\Desktop\18F2550.pdf
[2010-10-11 07:39:15 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2010-10-07 19:28:40 | 000,002,059 | ---- | M] () -- C:\Users\Grzegorz\Desktop\BASCOM-AVR.lnk
[2010-10-06 15:31:07 | 000,000,928 | ---- | M] () -- C:\Users\Grzegorz\Desktop\AVR Studio 4.lnk
[2010-10-06 12:48:13 | 000,171,520 | ---- | M] (Europress Software) -- C:\Windows\System32\cncs32.dll
[2010-10-06 12:48:13 | 000,000,018 | ---- | M] () -- C:\Windows\gfact.ini
[2010-10-04 13:26:37 | 000,002,092 | ---- | M] () -- C:\Users\Grzegorz\Desktop\ISIS 7 Professional.lnk
[2010-09-28 19:31:27 | 003,175,964 | ---- | M] () -- C:\Users\Grzegorz\Desktop\PIC16F688.pdf
[2010-09-27 17:36:05 | 000,023,339 | ---- | M] () -- C:\Users\Grzegorz\Desktop\WIEiK 2010.docx
[2010-09-27 15:28:06 | 000,196,096 | ---- | M] (Bullzip) -- C:\Windows\System32\bzpdf.dll
[2010-09-27 15:27:58 | 000,135,168 | ---- | M] (Bullzip) -- C:\Windows\System32\bzpdfc.dll

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2010-11-21 18:54:55 | 000,002,979 | ---- | C] () -- C:\Users\Grzegorz\Desktop\HiJackThis.lnk
[2010-11-21 16:44:12 | 000,000,162 | -H-- | C] () -- C:\Users\Grzegorz\Desktop\~$EE541.docx
[2010-11-21 16:28:34 | 000,001,323 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2010-11-21 00:02:29 | 000,000,860 | ---- | C] () -- C:\Users\Grzegorz\Desktop\AQQ.lnk
[2010-11-20 18:40:16 | 000,003,288 | ---- | C] () -- C:\bootsqm.dat
[2010-11-20 18:15:43 | 000,010,328 | ---- | C] () -- C:\Users\Grzegorz\Desktop\Kontakty_1439238.xml
[2010-11-20 09:42:07 | 000,001,178 | ---- | C] () -- C:\Users\Public\Desktop\MATLAB R2010a.lnk
[2010-11-20 09:41:45 | 000,002,362 | ---- | C] () -- C:\Windows\System32\mscomct2.dep
[2010-11-20 09:41:33 | 000,645,120 | ---- | C] () -- C:\Windows\System32\config.gms
[2010-11-20 09:21:57 | 000,000,927 | ---- | C] () -- C:\Users\Grzegorz\Desktop\Mp3 Knife.lnk
[2010-11-17 16:30:20 | 000,471,689 | ---- | C] () -- C:\Users\Grzegorz\Desktop\EE541.docx
[2010-11-17 12:59:02 | 000,002,078 | ---- | C] () -- C:\Users\Public\Desktop\Colin McRae Rally 2.lnk
[2010-11-15 21:29:52 | 000,038,891 | ---- | C] () -- C:\Users\Grzegorz\Desktop\INSTRUKCJA.pdf
[2010-11-14 20:55:52 | 000,000,553 | ---- | C] () -- C:\Users\Grzegorz\Desktop\Terminal — skrót.lnk
[2010-11-13 21:48:26 | 000,001,001 | ---- | C] () -- C:\Users\Grzegorz\Desktop\Warcraft III.lnk
[2010-11-10 18:52:11 | 000,224,247 | ---- | C] () -- C:\Users\Grzegorz\Desktop\DS18B20.pdf
[2010-11-08 08:56:09 | 000,016,031 | ---- | C] () -- C:\Users\Grzegorz\Desktop\Projekty.xlsx
[2010-11-05 06:40:38 | 003,764,247 | ---- | C] () -- C:\Users\Grzegorz\Desktop\ATTiny2313.PDF
[2010-10-30 18:14:26 | 000,001,387 | ---- | C] () -- C:\Users\Grzegorz\Desktop\USBurn.lnk
[2010-10-18 14:17:16 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2010-10-18 14:17:16 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2010-10-16 08:23:10 | 007,156,174 | ---- | C] () -- C:\Users\Grzegorz\Desktop\18F2550.pdf
[2010-10-06 15:31:13 | 000,290,904 | ---- | C] () -- C:\Windows\System32\vc6-re200l.dll
[2010-10-06 15:31:07 | 000,000,928 | ---- | C] () -- C:\Users\Grzegorz\Desktop\AVR Studio 4.lnk
[2010-10-06 12:48:13 | 000,000,018 | ---- | C] () -- C:\Windows\gfact.ini
[2010-10-04 17:14:44 | 000,002,059 | ---- | C] () -- C:\Users\Grzegorz\Desktop\BASCOM-AVR.lnk
[2010-10-04 17:14:23 | 000,001,821 | ---- | C] () -- C:\Users\Grzegorz\AppData\Roaming\bascom-avr.xml
[2010-10-04 13:26:37 | 000,002,092 | ---- | C] () -- C:\Users\Grzegorz\Desktop\ISIS 7 Professional.lnk
[2010-09-28 19:31:12 | 003,175,964 | ---- | C] () -- C:\Users\Grzegorz\Desktop\PIC16F688.pdf
[2010-09-27 17:36:04 | 000,023,339 | ---- | C] () -- C:\Users\Grzegorz\Desktop\WIEiK 2010.docx
[2010-09-25 12:39:05 | 000,001,040 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010-09-25 12:39:05 | 000,001,036 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010-09-22 18:04:27 | 000,000,017 | ---- | C] () -- C:\Users\Grzegorz\AppData\Local\resmon.resmoncfg
[2010-09-18 11:33:27 | 000,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll
[2010-09-18 11:25:50 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2010-09-18 05:34:15 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2010-09-16 20:52:48 | 000,691,696 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2010-09-16 20:16:58 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010-09-16 20:16:57 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2010-09-16 20:16:50 | 000,790,528 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010-09-16 20:16:50 | 000,134,144 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010-09-16 20:16:49 | 000,108,032 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010-09-16 19:50:07 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010-09-16 18:37:02 | 001,759,744 | ---- | C] () -- C:\Windows\System32\drivers\snp2uvc.sys
[2010-09-16 18:37:02 | 000,028,544 | ---- | C] () -- C:\Windows\System32\drivers\sncduvc.sys
[2010-09-16 18:37:02 | 000,000,323 | ---- | C] () -- C:\Windows\PidList.ini
[2010-08-06 13:58:34 | 000,081,920 | ---- | C] () -- C:\Windows\System32\MPMapTrace.dll
[2010-08-06 13:21:24 | 000,364,544 | ---- | C] () -- C:\Windows\System32\mpPathan.dll
[2009-10-25 18:27:18 | 000,033,792 | ---- | C] () -- C:\Windows\System32\drivers\libusb0.sys
[2009-07-14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009-07-14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2007-10-25 16:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2007-09-28 01:54:10 | 000,003,584 | ---- | C] () -- C:\Windows\System32\drivers\DLPORTIO.sys
[2006-12-13 15:03:14 | 000,074,240 | ---- | C] () -- C:\Windows\System32\zlibwapi.dll

[color=#E56717]========== LOP Check ==========[/color]

[2010-11-21 09:50:03 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\AIMP
[2010-10-27 12:32:41 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\BESTplayer
[2010-11-11 22:22:49 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\CadSoft
[2010-09-18 11:58:07 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\DAEMON Tools Lite
[2010-09-18 14:54:09 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\EurekaLog
[2010-09-16 20:32:08 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\Foxit
[2010-09-16 20:32:08 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\Foxit Software
[2010-11-11 22:22:49 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\GHISLER
[2010-11-11 22:22:49 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\IrfanView
[2010-11-15 21:52:52 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\Microchip
[2010-11-15 21:29:35 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\PDF Writer
[2010-10-18 14:17:09 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\Samsung
[2010-11-03 10:10:02 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\Termite
[2010-10-04 07:17:55 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\Thunderbird
[2010-11-21 19:26:24 | 000,000,000 | ---D | M] -- C:\Users\Grzegorz\AppData\Roaming\uTorrent
[2010-11-20 19:14:52 | 000,032,590 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Custom Scans ==========[/color]


[color=#A23BEC]< %systemdrive%\*.* >[/color]
[2009-06-10 22:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2010-11-20 18:40:16 | 000,003,288 | ---- | M] () -- C:\bootsqm.dat
[2009-06-10 22:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010-11-17 13:19:41 | 000,000,157 | ---- | M] () -- C:\error.txt
[2010-11-21 16:32:17 | 2339,512,320 | -HS- | M] () -- C:\hiberfil.sys
[2010-09-18 06:05:15 | 000,000,317 | ---- | M] () -- C:\MPUsbSIn.log
[2010-11-21 16:32:20 | 3119,353,856 | -HS- | M] () -- C:\pagefile.sys


[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2009-07-14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009-07-14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009-07-14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys

[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2009-07-14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009-07-14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009-07-14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys

[color=#A23BEC]< MD5 for: BEEP.SYS >[/color]
[2009-07-14 00:45:01 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=505506526A9D467307B3C393DEDAF858 -- C:\Windows\System32\drivers\beep.sys
[2009-07-14 00:45:01 | 000,006,144 | ---- | M] (Microsoft Corporation) MD5=505506526A9D467307B3C393DEDAF858 -- C:\Windows\winsxs\x86_microsoft-windows-beepsys_31bf3856ad364e35_6.1.7600.16385_none_c3f6f77668f0ddcc\beep.sys

[color=#A23BEC]< MD5 for: CDROM.SYS >[/color]
[2009-07-14 00:11:26 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\Windows\System32\drivers\cdrom.sys
[2009-07-14 00:11:26 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_neutral_db87d184bc84f910\cdrom.sys
[2009-07-14 00:11:26 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BA6E70AA0E6091BC39DE29477D866A77 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_5f7fb206051affbb\cdrom.sys

[color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color]
[2007-01-23 16:22:16 | 000,032,890 | ---- | M] () MD5=4FA5D1120762802A741F374F8B391E69 -- C:\Program Files\MATLAB\R2010a\sys\perl\win32\lib\auto\Win32\EventLog\EventLog.dll

[color=#A23BEC]< MD5 for: NDIS.SYS >[/color]
[2009-07-14 02:20:44 | 000,710,720 | ---- | M] (Microsoft Corporation) MD5=23759D175A0A9BAAF04D05047BC135A8 -- C:\Windows\System32\drivers\ndis.sys
[2009-07-14 02:20:44 | 000,710,720 | ---- | M] (Microsoft Corporation) MD5=23759D175A0A9BAAF04D05047BC135A8 -- C:\Windows\winsxs\x86_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_a79d81ea7d62a289\ndis.sys

[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2009-10-28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009-10-28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009-10-28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009-07-14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:0E08FC17

< End of report >
[/log]


Extras:
[log]

OTL Extras logfile created on: 2010-11-21 19:22:32 - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Grzegorz\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 59,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 78,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99,61 Gb Total Space | 67,42 Gb Free Space | 67,68% Space Free | Partition Type: NTFS
Drive D: | 198,38 Gb Total Space | 82,32 Gb Free Space | 41,50% Space Free | Partition Type: NTFS
Drive F: | 982,03 Mb Total Space | 751,41 Mb Free Space | 76,52% Space Free | Partition Type: FAT

Computer Name: GRZEGORZ-3810T | User Name: Grzegorz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2396130858-3024342048-3616289110-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- C:\Users\Grzegorz\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)

[color=#E56717]========== Shell Spawning ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[color=#E56717]========== Authorized Applications List ==========[/color]


[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{13C4E8F0-B747-4C7C-9090-884832F9F90A}" = Proteus 7 Professional
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{19B72AA9-985A-11D4-9C8A-00D0B75D1498}" = Colin McRae Rally 2
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Narzędzie do przekazywania usługi Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23D6630B-7538-483B-8B27-6452AE3BA628}" = ExtremeCopy
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java(TM) 6 Update 21
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{321320E1-0E5A-36CB-9E52-F3B201B8C4D4}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = WebCam
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer PowerSmart Manager
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51958BA7-21E4-4A8B-9098-CD8375BD17B2}" = Asystent rejestracji usługi Windows Live
"{7760D94E-B1B5-40A0-9AA0-ABF942108755}" = Acer Crystal Eye Webcam
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007
"{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007
"{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007
"{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007
"{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007
"{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007
"{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2007
"{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007
"{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007
"{90120000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2007
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{C35FE07E-24B5-410F-85B7-122087A0C7DD}" = Poczta usługi Windows Live
"{C5096D00-8B9C-41DB-8472-9D721E982DF0}" = Podstawowe programy Windows Live
"{CDB4B708-B3A5-42E5-AA46-68678D1313FF}" = 8-in-Right
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{d08d9f98-1c78-4704-87e6-368b0023d831}" = RelevantKnowledge
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D5D88F8F-FDA4-4CF4-9F3E-3F40118C2120}" = AVRStudio4
"{DDC0FC3C-70D7-41F3-803A-C92484EE53AC}" = AVRStudio4
"{E2AC8456-E8E8-41CD-9344-D505FBF1F68F}" = MPLAB Tools v8.56
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EEC010D0-1252-4E1D-BAD9-F1B8F414535C}" = PL-2303 Vista Driver Installer
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"AIMP2" = AIMP2
"AIMP2at" = AIMP2: Audio Tools
"AQQ" = WapSter AQQ
"avast5" = avast! Free Antivirus
"BASCOM-AVR DEMO Setup" = BASCOM-AVR DEMO Setup
"BatteryInfo" = Notebook BatteryInfo
"BatteryMon_is1" = BatteryMon V2.1
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 7.1.0.1218
"DMX5_is1" = DriverMax 5
"EAGLE 5.6.0" = EAGLE 5.6.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"Foxit Reader" = Foxit Reader
"GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.70
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"InstallShield_{CDB4B708-B3A5-42E5-AA46-68678D1313FF}" = 8-in-Right
"InstallShield_{E2AC8456-E8E8-41CD-9344-D505FBF1F68F}" = MPLAB Tools v8.56
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"IrfanView" = IrfanView (remove only)
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 6.4.0
"MatlabR2010a" = MATLAB R2010a
"melabs Programmer Beta_is1" = melabs Programmer 4.32 Beta
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile
"Mp3 Knife_is1" = Mp3 Knife 3.2
"NapiProjekt_is1" = NapiProjekt 1.0.6.9
"PICC 9.80" = HI-TECH C Compiler for the PIC10/12/16 MCUs V9.80PL0
"Totalcmd" = Total Commander (Remove or Repair)
"TVWiz" = Intel(R) TV Wizard
"uTorrent" = µTorrent
"WinAVR" = WinAVR 20080610 (remove only)
"WinAVR-20080610" = WinAVR 20080610 (remove only)
"WinLiveSuite_Wave3" = Podstawowe programy Windows Live
"WinRAR archiver" = Archiwizator WinRAR

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-2396130858-3024342048-3616289110-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

[color=#E56717]========== Last 10 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2010-11-14 18:47:38 | Computer Name = Grzegorz-3810t | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\innovative
solutions\drivermax\DPInst\amd64\dpinst.exe". Nie można odnaleźć zestawu zależnego
Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.

Error - 2010-11-14 18:47:38 | Computer Name = Grzegorz-3810t | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\innovative
solutions\drivermax\DPInst\ia64\dpinst.exe". Nie można odnaleźć zestawu zależnego
Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.

Error - 2010-11-14 20:35:41 | Computer Name = Grzegorz-3810t | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: MPLAB.exe, wersja: 8.56.0.0, sygnatura
czasowa: 0x4c5c81f3 Nazwa modułu powodującego błąd: MPEditor4.dll_unloaded, wersja:
0.0.0.0, sygnatura czasowa: 0x4c5c82f0 Kod wyjątku: 0xc0000005 Przesunięcie błędu:
0x042119f3 Identyfikator procesu powodującego błąd: 0xdb8 Godzina uruchomienia aplikacji
powodującej błąd: 0x01cb844fcbb8582c Ścieżka aplikacji powodującej błąd: C:\Program
Files\Microchip\MPLAB IDE\Core\MPLAB.exe Ścieżka modułu powodującego błąd: MPEditor4.dll
Identyfikator
raportu: 45e7128b-f050-11df-a601-00a0d1af75ea

Error - 2010-11-17 07:52:19 | Computer Name = Grzegorz-3810t | Source = VSS | ID = 8194
Description =

Error - 2010-11-18 11:29:10 | Computer Name = Grzegorz-3810t | Source = SideBySide | ID = 16842815
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\WapSter\wapster
aqq\System\DelZip179.dll". Błąd w pliku manifestu lub w pliku zasad "c:\program
files\WapSter\wapster aqq\System\DelZip179.dll" w wierszu 8. Wartość "*" atrybutu
"language" elementu "assemblyIdentity" jest nieprawidłowa.

Error - 2010-11-18 11:29:18 | Computer Name = Grzegorz-3810t | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\innovative
solutions\drivermax\DPInst\amd64\dpinst.exe". Nie można odnaleźć zestawu zależnego
Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.

Error - 2010-11-18 11:29:18 | Computer Name = Grzegorz-3810t | Source = SideBySide | ID = 16842785
Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files\innovative
solutions\drivermax\DPInst\ia64\dpinst.exe". Nie można odnaleźć zestawu zależnego
Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
Użyj
narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.

Error - 2010-11-20 10:15:50 | Computer Name = Grzegorz-3810t | Source = VSS | ID = 8194
Description =

Error - 2010-11-20 14:51:21 | Computer Name = Grzegorz-3810t | Source = Application Error | ID = 1000
Description = Nazwa aplikacji powodującej błąd: OscarEditor.exe, wersja: 0.0.0.0,
sygnatura czasowa: 0x00000000 Nazwa modułu powodującego błąd: Win32Share.dll_unloaded,
wersja: 0.0.0.0, sygnatura czasowa: 0x4a5e9a40 Kod wyjątku: 0xc0000005 Przesunięcie
błędu: 0x742c6920 Identyfikator procesu powodującego błąd: 0x4e8 Godzina uruchomienia
aplikacji powodującej błąd: 0x01cb88e3a0488dff Ścieżka aplikacji powodującej błąd:
C:\Program Files\OSCARK3G5\OscarEditor.exe Ścieżka modułu powodującego błąd: Win32Share.dll
Identyfikator
raportu: 29eb1fed-f4d7-11df-bc7e-00a0d1af75ea

Error - 2010-11-20 15:01:05 | Computer Name = Grzegorz-3810t | Source = VSS | ID = 8194
Description =

[ System Events ]
Error - 2010-11-20 14:42:43 | Computer Name = Grzegorz-3810t | Source = Service Control Manager | ID = 7001
Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji
w sieci, której nie można uruchomić z powodu następującego błędu: %%1068

Error - 2010-11-20 14:42:43 | Computer Name = Grzegorz-3810t | Source = Service Control Manager | ID = 7001
Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji
w sieci, której nie można uruchomić z powodu następującego błędu: %%1068

Error - 2010-11-20 14:42:44 | Computer Name = Grzegorz-3810t | Source = Service Control Manager | ID = 7001
Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji
w sieci, której nie można uruchomić z powodu następującego błędu: %%1068

Error - 2010-11-20 14:42:44 | Computer Name = Grzegorz-3810t | Source = Service Control Manager | ID = 7001
Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji
w sieci, której nie można uruchomić z powodu następującego błędu: %%1068

Error - 2010-11-20 14:42:44 | Computer Name = Grzegorz-3810t | Source = Service Control Manager | ID = 7001
Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji
w sieci, której nie można uruchomić z powodu następującego błędu: %%1068

Error - 2010-11-20 14:42:44 | Computer Name = Grzegorz-3810t | Source = Service Control Manager | ID = 7001
Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji
w sieci, której nie można uruchomić z powodu następującego błędu: %%1068

Error - 2010-11-20 14:42:44 | Computer Name = Grzegorz-3810t | Source = Service Control Manager | ID = 7001
Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji
w sieci, której nie można uruchomić z powodu następującego błędu: %%1068

Error - 2010-11-20 14:42:44 | Computer Name = Grzegorz-3810t | Source = Service Control Manager | ID = 7001
Description = Usługa Usługa listy sieci zależy od usługi Rozpoznawanie lokalizacji
w sieci, której nie można uruchomić z powodu następującego błędu: %%1068

Error - 2010-11-20 14:50:17 | Computer Name = Grzegorz-3810t | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 2010-11-21 04:50:32 | Computer Name = Grzegorz-3810t | Source = DCOM | ID = 10010
Description =


< End of report >
[/log]

Z góry dziękuję za pomoc
Pozdrawiam

Tomek01
komentarz
komentarz

Nic specjalnego nie widać.

Wykonaj pełny skan [url=http://www.instalki.pl/programy/download_c/14/155.html][color=#0000CD][b]DrWebCureIt[/b][/color][/url] oraz [url=http://www.instalki.pl/programy/download_c/13/96.html][color=#0000CD][b]Malwarebytes Anti-Malware[/b][/color][/url] i wyniki pokaż na forum.

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.