x-kom hosting

Internet jakby cały czas coś pobierał.

Hellu
utworzono
utworzono

Proszę o to logi z OTL :

[log]OTL logfile created on: 2011-08-06 09:30:52 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Jarhead\Moje dokumenty\Downloads
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1 023,00 Mb Total Physical Memory | 395,00 Mb Available Physical Memory | 39,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 81,00% Paging File free
Paging file location(s): C:\pagefile.sys 1534 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 2,70 Gb Free Space | 3,62% Space Free | Partition Type: NTFS

Computer Name: JARHEAD-ACD1642 | User Name: Jarhead | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2011-07-27 10:03:22 | 001,017,912 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
PRC - [2011-07-04 13:43:54 | 003,493,720 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011-07-04 13:43:51 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2011-02-14 17:49:11 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jarhead\Moje dokumenty\Downloads\OTL_3.2.20.6(dobreprogramy.pl).exe
PRC - [2010-12-16 07:19:28 | 012,984,928 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe
PRC - [2008-04-14 23:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007-04-16 16:28:22 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe


[color=#E56717]========== Modules (SafeList) ==========[/color]

MOD - [2011-07-04 13:43:51 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2011-02-14 17:49:11 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jarhead\Moje dokumenty\Downloads\OTL_3.2.20.6(dobreprogramy.pl).exe
MOD - [2010-08-23 18:12:53 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2011-07-04 13:43:51 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011-05-25 09:25:59 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2010-03-18 17:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -- (aspnet_state)
SRV - [2010-03-18 14:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010-03-18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010-03-18 14:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2011-07-04 13:36:43 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011-07-04 13:36:32 | 000,309,848 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011-07-04 13:35:23 | 000,043,608 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011-07-04 13:35:12 | 000,102,616 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011-07-04 13:32:32 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011-07-04 13:32:13 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011-07-04 13:32:12 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011-06-25 14:29:40 | 000,017,962 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\GVTDrv.sys -- (GVTDrv)
DRV - [2011-05-25 09:25:56 | 012,753,664 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2010-02-11 14:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2008-09-24 11:40:22 | 004,122,368 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2008-04-14 01:26:08 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008-04-14 01:23:10 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008-04-14 01:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2004-08-04 00:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Sterownik NT karty Realtek RTL8139(A/B/C)
DRV - [2002-09-29 00:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2002-09-29 00:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultthis.engineName: "ClixSense.com Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2192277&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: wrc@avast.com:20110101
FF - prefs.js..extensions.enabledItems: affiliates.firefox@addons.filesonic.com:1.0.9
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2192277&SearchSource=2&q="
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-07-23 21:39:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-06-23 22:51:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-06-07 19:09:53 | 000,000,000 | ---D | M]

[2011-03-14 21:07:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jarhead\Dane aplikacji\Mozilla\Extensions
[2011-07-22 21:04:45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jarhead\Dane aplikacji\Mozilla\Firefox\Profiles\5he1vqvl.default\extensions
[2011-04-14 20:59:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Jarhead\Dane aplikacji\Mozilla\Firefox\Profiles\5he1vqvl.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011-07-01 17:29:24 | 000,000,000 | ---D | M] (ClixSense.com Community Toolbar) -- C:\Documents and Settings\Jarhead\Dane aplikacji\Mozilla\Firefox\Profiles\5he1vqvl.default\extensions\{70df8d13-bdd3-448e-944c-efde21b77161}
[2011-07-09 20:16:18 | 000,000,000 | ---D | M] (WOT) -- C:\Documents and Settings\Jarhead\Dane aplikacji\Mozilla\Firefox\Profiles\5he1vqvl.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011-04-16 08:09:15 | 000,000,000 | ---D | M] (FileSonic Affiliate Plugin) -- C:\Documents and Settings\Jarhead\Dane aplikacji\Mozilla\Firefox\Profiles\5he1vqvl.default\extensions\affiliates.firefox@addons.filesonic.com
[2011-06-20 14:41:52 | 000,000,929 | ---- | M] () -- C:\Documents and Settings\Jarhead\Dane aplikacji\Mozilla\Firefox\Profiles\5he1vqvl.default\searchplugins\conduit.xml
[2011-07-14 20:31:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011-06-07 19:10:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011-07-13 16:47:03 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2
File not found (No name found) --
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JARHEAD\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\5HE1VQVL.DEFAULT\EXTENSIONS\TABSCOPE@XULDEV.ORG.XPI
[2011-07-23 21:39:39 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2011-02-06 15:21:53 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011-06-23 22:51:16 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011-05-04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010-01-01 10:00:00 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2010-01-01 10:00:00 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2010-01-01 10:00:00 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2010-01-01 10:00:00 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2010-01-01 10:00:00 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2010-01-01 10:00:00 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2011-04-21 09:39:22 | 000,000,739 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Companion BHO) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll (Yahoo! Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 78.31.159.225 78.31.159.227
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-09-30 15:43:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: WmdmPmSp - File not found

MsConfig - StartUpReg: [b]a-squared[/b] - hkey= - key= - File not found
MsConfig - StartUpReg: [b]Gadu-Gadu 10[/b] - hkey= - key= - C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.)
MsConfig - StartUpReg: [b]IPLA![/b] - hkey= - key= - C:\Program Files\ipla\ipla.exe (Redefine Sp z o.o.)
MsConfig - StartUpReg: [b]iTunesHelper[/b] - hkey= - key= - File not found
MsConfig - StartUpReg: [b]Pando Media Booster[/b] - hkey= - key= - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
MsConfig - StartUpReg: [b]Steam[/b] - hkey= - key= - C:\Program Files\Steam\steam.exe (Valve Corporation)
MsConfig - StartUpReg: [b]WinampAgent[/b] - hkey= - key= - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2

SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: nm - C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
SafeBootNet: nm.sys - C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

[color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color]

[2011-08-03 19:28:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Temporary Projects
[2011-08-01 22:20:16 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Jarhead\Recent
[2011-07-31 22:56:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\riotsGamesLogs
[2011-07-30 21:05:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Dane aplikacji\LolClient
[2011-07-30 20:24:29 | 000,000,000 | ---D | C] -- C:\Riot Games
[2011-07-30 20:24:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Riot Games
[2011-07-30 19:34:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\PMB Files
[2011-07-30 19:34:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\PMB Files
[2011-07-30 19:34:02 | 000,000,000 | ---D | C] -- C:\Program Files\Pando Networks
[2011-07-23 21:39:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\avast! Free Antivirus
[2011-07-23 21:39:54 | 000,309,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011-07-23 21:39:54 | 000,019,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011-07-23 21:39:52 | 000,025,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011-07-23 21:39:51 | 000,441,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011-07-23 21:39:51 | 000,102,616 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011-07-23 21:39:51 | 000,096,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011-07-23 21:39:51 | 000,043,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011-07-23 21:39:50 | 000,030,808 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011-07-23 21:39:36 | 000,040,112 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011-07-23 21:39:35 | 000,199,304 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011-07-23 21:39:25 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011-07-23 21:39:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\AVAST Software
[2011-07-23 20:22:57 | 000,000,000 | ---D | C] -- C:\8354f671bc50f4e0ab3108c9
[2011-07-22 15:05:00 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011-07-22 15:01:17 | 000,000,000 | ---D | C] -- C:\2f00e3efcddf74f6ce801267e97db7cb
[2011-07-20 16:45:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\PCHealth
[2011-07-20 15:47:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Microsoft Silverlight
[2011-07-17 18:07:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Deployment
[2011-07-17 18:05:27 | 000,000,000 | ---D | C] -- C:\Program Files\MetaTrader - FXOpen
[2011-07-02 00:08:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
[2011-06-29 15:46:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Publish Providers
[2011-06-29 15:46:00 | 000,000,000 | ---D | C] -- C:\Program Files\VSTplugins
[2011-06-29 15:45:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Sony
[2011-06-29 15:45:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Sony
[2011-06-29 15:45:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Moje dokumenty\My Videos
[2011-06-29 15:41:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Toolbar4
[2011-06-29 15:33:52 | 000,000,000 | ---D | C] -- C:\Fraps
[2011-06-29 15:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\Sony Setup
[2011-06-28 23:43:36 | 000,000,000 | ---D | C] -- C:\Program Files\TibiaReplay
[2011-06-26 21:10:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2011-06-26 21:10:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Norton
[2011-06-26 21:10:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\NortonInstaller
[2011-06-26 19:09:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2011-06-25 14:35:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Moje dokumenty\temp
[2011-06-25 14:34:40 | 000,000,000 | ---D | C] -- C:\Program Files\GIGABYTE
[2011-06-25 14:25:13 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2011-06-24 21:24:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Cobra Mobile
[2011-06-19 20:34:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Banner Maker Pro 8
[2011-06-19 20:34:01 | 000,000,000 | ---D | C] -- C:\Program Files\Banner Maker Pro 8
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 60 Days ==========[/color]

[2011-08-06 09:21:24 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011-08-06 09:04:43 | 000,001,034 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011-08-06 09:04:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-08-06 00:04:01 | 000,001,038 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011-08-06 00:03:00 | 000,001,140 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1123561945-682003330-1003UA.job
[2011-08-05 23:31:12 | 000,000,751 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\World of Warcraft.lnk
[2011-08-03 23:09:18 | 000,000,638 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\Tibia.lnk
[2011-08-03 20:03:01 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1123561945-682003330-1003Core.job
[2011-08-02 17:06:57 | 000,002,318 | ---- | M] () -- C:\Documents and Settings\Jarhead\Pulpit\Google Chrome.lnk
[2011-07-31 23:11:15 | 000,008,908 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2011-07-30 20:33:29 | 000,001,616 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\League of Legends.lnk
[2011-07-30 11:51:41 | 000,273,424 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011-07-30 11:51:41 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011-07-30 11:51:40 | 000,273,424 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011-07-24 12:53:32 | 000,001,663 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\FileZilla Client.lnk
[2011-07-24 12:53:19 | 004,521,014 | ---- | M] () -- C:\Documents and Settings\Jarhead\Moje dokumenty\FileZilla_3.5.0_win32-setup.exe
[2011-07-24 11:29:16 | 000,555,118 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2011-07-24 11:29:16 | 000,493,054 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-07-24 11:29:16 | 000,104,274 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2011-07-24 11:29:16 | 000,083,598 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-07-23 21:39:55 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\avast! Free Antivirus.lnk
[2011-07-23 21:39:51 | 000,002,644 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011-07-22 11:01:18 | 000,098,256 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011-07-18 15:56:37 | 000,007,168 | ---- | M] () -- C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-07-13 16:50:27 | 000,017,408 | ---- | M] () -- C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\WebpageIcons.db
[2011-07-04 13:43:53 | 000,040,112 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011-07-04 13:43:51 | 000,199,304 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011-07-04 13:36:43 | 000,441,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011-07-04 13:36:32 | 000,309,848 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011-07-04 13:35:23 | 000,043,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011-07-04 13:35:12 | 000,102,616 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011-07-04 13:35:09 | 000,096,344 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011-07-04 13:32:32 | 000,025,432 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011-07-04 13:32:13 | 000,030,808 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011-07-04 13:32:12 | 000,019,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011-07-01 19:29:34 | 000,000,214 | ---- | M] () -- C:\Documents and Settings\Jarhead\Pulpit\Killing Floor.url
[2011-06-29 15:43:34 | 009,690,216 | ---- | M] () -- C:\Documents and Settings\Jarhead\Moje dokumenty\clip0001.avi
[2011-06-26 15:09:41 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-06-25 14:29:40 | 000,017,962 | ---- | M] () -- C:\WINDOWS\System32\drivers\GVTDrv.sys
[2011-06-25 14:29:40 | 000,000,004 | ---- | M] () -- C:\WINDOWS\System32\GVTunner.ref
[2011-06-24 21:23:58 | 000,444,952 | ---- | M] (Creative Labs) -- C:\WINDOWS\System32\wrap_oal.dll
[2011-06-11 17:46:06 | 000,000,837 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\TeamSpeak 3 Client.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2011-07-31 23:11:15 | 000,008,908 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011-07-30 20:33:29 | 000,001,616 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\League of Legends.lnk
[2011-07-24 12:53:12 | 004,521,014 | ---- | C] () -- C:\Documents and Settings\Jarhead\Moje dokumenty\FileZilla_3.5.0_win32-setup.exe
[2011-07-23 21:39:55 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\avast! Free Antivirus.lnk
[2011-07-13 16:50:20 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\WebpageIcons.db
[2011-07-01 19:29:33 | 000,000,214 | ---- | C] () -- C:\Documents and Settings\Jarhead\Pulpit\Killing Floor.url
[2011-06-29 15:43:24 | 009,690,216 | ---- | C] () -- C:\Documents and Settings\Jarhead\Moje dokumenty\clip0001.avi
[2011-06-25 14:26:01 | 000,017,962 | ---- | C] () -- C:\WINDOWS\System32\drivers\GVTDrv.sys
[2011-06-25 14:26:01 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\GVTunner.ref
[2011-04-19 14:51:15 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2011-03-29 16:42:57 | 000,004,904 | ---- | C] () -- C:\Program Files\index.html
[2011-03-24 19:00:13 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-02-11 15:18:01 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011-02-03 16:02:21 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011-02-03 15:55:14 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2010-10-01 18:48:38 | 000,002,596 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Config.nt.bak
[2010-10-01 18:48:38 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Autoexec.nt.bak
[2010-10-01 18:48:38 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\hosts.bak
[2007-07-23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007-07-23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007-07-23 09:03:32 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007-07-23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007-07-23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007-07-23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007-07-23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007-07-23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007-07-23 09:03:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2006-08-11 15:45:20 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006-08-11 15:43:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll

[color=#E56717]========== LOP Check ==========[/color]

[2011-06-24 21:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Cobra Mobile
[2011-07-26 16:51:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\FileZilla
[2011-02-03 21:08:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Gadu-Gadu 10
[2011-07-02 23:12:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\ipla
[2011-07-30 21:05:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\LolClient
[2011-03-25 18:45:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Mumble
[2011-02-06 22:13:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Notepad++
[2011-02-03 17:22:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\OpenFM
[2011-05-06 13:23:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Opera
[2011-06-29 15:46:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Publish Providers
[2011-02-03 17:20:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\RDRM
[2011-06-29 15:45:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Sony
[2011-04-13 11:08:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Tibia
[2011-02-04 22:44:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Tibiacast
[2011-07-20 10:38:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Toolbar4
[2011-07-27 20:18:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\TS3Client
[2011-06-05 15:54:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jarhead\Dane aplikacji\Worldwinner
[2011-02-03 16:13:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Alwil Software
[2011-07-23 21:39:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\AVAST Software
[2011-02-03 17:18:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Gadu-Gadu 10
[2011-05-14 16:11:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ipla
[2011-02-06 16:43:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\OpenFM
[2011-08-05 10:18:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\PMB Files
[2011-05-14 15:56:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\RDRM
[2011-07-23 13:29:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP
[2011-06-05 15:54:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\WorldWinner
[2011-05-17 17:15:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Custom Scans ==========[/color]


[color=#A23BEC]< %systemdrive%\*.* >[/color]
[2010-09-30 15:43:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2011-08-06 09:21:24 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2002-09-29 00:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2010-09-30 15:43:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2007-11-07 09:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007-11-07 09:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007-11-07 09:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007-11-07 09:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007-11-07 09:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007-11-07 09:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007-11-07 09:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007-11-07 09:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007-11-07 09:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007-11-07 09:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2010-12-21 14:16:18 | 000,006,298 | ---- | M] () -- C:\graph.log
[2011-02-03 14:45:37 | 804,839,424 | -HS- | M] () -- C:\hiberfil.sys
[2007-11-07 09:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
[2007-11-07 09:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2007-11-07 09:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007-11-07 09:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007-11-07 09:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007-11-07 09:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007-11-07 09:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007-11-07 09:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007-11-07 09:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007-11-07 09:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007-11-07 09:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2010-09-30 15:43:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010-09-30 15:43:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004-08-03 22:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010-12-20 15:54:27 | 000,251,152 | RHS- | M] () -- C:\ntldr
[2011-08-06 09:04:05 | 1608,515,584 | -HS- | M] () -- C:\pagefile.sys
[2007-11-07 09:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007-11-07 09:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007-11-07 09:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI


[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2004-08-04 00:54:52 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:agp440.sys
[2008-04-15 00:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:agp440.sys
[2008-04-15 00:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:agp440.sys
[2008-04-14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008-04-13 20:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\agp440.sys
[2008-04-14 01:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\System32\drivers\agp440.sys

[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2004-08-04 00:54:52 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008-04-15 00:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008-04-15 00:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008-04-14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008-04-13 20:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\atapi.sys
[2008-04-14 01:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\System32\drivers\atapi.sys
[2004-08-03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

[color=#A23BEC]< MD5 for: BEEP.SYS >[/color]
[2002-09-29 00:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\System32\dllcache\beep.sys
[2002-09-29 00:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\System32\drivers\beep.sys

[color=#A23BEC]< MD5 for: CDROM.SYS >[/color]
[2004-08-04 00:54:52 | 018,789,127 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008-04-15 00:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2008-04-15 00:09:56 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008-04-14 01:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008-04-13 20:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\cdrom.sys
[2008-04-14 01:10:48 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\System32\drivers\cdrom.sys
[2004-08-03 22:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys

[color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color]
[2004-08-04 00:43:58 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=05684DE2DA55A04C8AAAB5911AFE7643 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008-04-14 23:50:32 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008-04-14 19:20:31 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\eventlog.dll
[2008-04-14 23:50:32 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\System32\eventlog.dll

[color=#A23BEC]< MD5 for: NDIS.SYS >[/color]
[2008-04-14 01:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008-04-13 21:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\ndis.sys
[2008-04-14 01:50:38 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\System32\drivers\ndis.sys
[2004-08-03 23:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys

[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2004-08-04 00:44:30 | 000,504,832 | ---- | M] (Microsoft Corporation) MD5=0344407089B08548D4FEBA62BB0F32D0 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008-04-14 23:51:50 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008-04-14 19:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\SoftwareDistribution\Download\51fc2b55c6deef38fc801319336cdbc7\winlogon.exe
[2008-04-14 23:51:50 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\System32\winlogon.exe

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 48 bytes -> C:\Documents and Settings\All Users.WINDOWS\DRM:مايكروسوفت
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP:08948D52

< End of report >[/log]

[log]OTL Extras logfile created on: 2011-08-06 09:30:52 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Jarhead\Moje dokumenty\Downloads
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1 023,00 Mb Total Physical Memory | 395,00 Mb Available Physical Memory | 39,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 81,00% Paging File free
Paging file location(s): C:\pagefile.sys 1534 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 2,70 Gb Free Space | 3,62% Space Free | Partition Type: NTFS

Computer Name: JARHEAD-ACD1642 | User Name: Jarhead | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] -- Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

[color=#E56717]========== Shell Spawning ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Opera\Opera.exe" "%1"
https [open] -- "C:\Program Files\Opera\Opera.exe" "%1"
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[color=#E56717]========== System Restore Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"57452:TCP" = 57452:TCP:*:Enabled:Pando Media Booster
"57452:UDP" = 57452:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"57452:TCP" = 57452:TCP:*:Enabled:Pando Media Booster
"57452:UDP" = 57452:UDP:*:Enabled:Pando Media Booster

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Gadu-Gadu 10\gg.exe" = C:\Program Files\Gadu-Gadu 10\gg.exe:*:Enabled:Gadu-Gadu 10 -- (GG Network S.A.)
"C:\Program Files\Tibiacast\Tibiacast Client.exe" = C:\Program Files\Tibiacast\Tibiacast Client.exe:*:Enabled:Tibiacast Client -- (Silver Squirrel Software HB)
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe -- (Flagship Industries, Inc.)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)
"C:\Program Files\Firefly Studios\Twierdza Krzyzowiec Extreme\Stronghold Crusader.exe" = C:\Program Files\Firefly Studios\Twierdza Krzyzowiec Extreme\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth
"C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- (Blizzard Entertainment)
"C:\Program Files\Metin2\metin2.bin" = C:\Program Files\Metin2\metin2.bin:*:Enabled:metin2
"C:\Program Files\Metin2\metin2client.bin" = C:\Program Files\Metin2\metin2client.bin:*:Enabled:metin2client
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\Launcher.patch.exe" = C:\Program Files\World of Warcraft\Launcher.patch.exe:*:Enabled:Blizzard Launcher
"C:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe" = C:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\Repair.exe" = C:\Program Files\World of Warcraft\Repair.exe:*:Enabled:Blizzard Repair Utility -- ()
"C:\Program Files\Microsoft Games\Rise Of Legends\legends.exe" = C:\Program Files\Microsoft Games\Rise Of Legends\legends.exe:*:Enabled:Rise Of Legends
"C:\Program Files\GameSpy Arcade\Aphex.exe" = C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade 1.4
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser
"C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe" = C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe:*:Enabled:AGEIA PhysX System Tray Icon -- ()
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe" = C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:BackgroundDownloader.exe -- (Blizzard Entertainment)
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe -- (NVIDIA Corporation)
"C:\Program Files\VentSrv\ventrilo_srv.exe" = C:\Program Files\VentSrv\ventrilo_srv.exe:*:Disabled:ventrilo_srv -- ()
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Disabled:Xfire
"C:\Program Files\Steam\steamapps\helluczolg\counter-strike\hl.exe" = C:\Program Files\Steam\steamapps\helluczolg\counter-strike\hl.exe:*:Enabled:Counter-Strike -- (Valve)
"C:\Program Files\GIGABYTE\VGA Utility Manager\G-VGA.exe" = C:\Program Files\GIGABYTE\VGA Utility Manager\G-VGA.exe:*:Enabled:Menu
"C:\Program Files\Tibia\Tibia.exe" = C:\Program Files\Tibia\Tibia.exe:*:Enabled:Tibia Player -- (CipSoft GmbH)
"C:\Program Files\Steam\steamapps\common\killingfloor\System\KillingFloor.exe" = C:\Program Files\Steam\steamapps\common\killingfloor\System\KillingFloor.exe:*:Enabled:Killing Floor -- ()
"C:\Program Files\DreamCatcher\PainkillerMultiplayerDemo\Bin\painkillerdemo.exe" = C:\Program Files\DreamCatcher\PainkillerMultiplayerDemo\Bin\painkillerdemo.exe:*:Disabled:Painkiller
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()


[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{1D46A3A0-B37D-423A-91C2-101A49E2FF80}" = Ventrilo Server
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java(TM) 6 Update 26
"{2A2F3AE8-246A-4252-BB26-1BEB45627074}" = Microsoft SQL Server System CLR Types
"{2A82EBFC-89AB-41EA-80E8-A07C73C752A0}" = WorldWinner Games
"{2AFF2951-86B1-3C53-B34D-B440F11E7D0A}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PLK
"{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{45235788-142C-44BE-8A4D-DDE9A84492E5}" = AGEIA PhysX v7.09.13
"{46F8CF66-AB83-38A7-99B2-A5BE507EE472}" = Microsoft Visual C++ 2010 Express - ENU
"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E968D9C-21A7-4915-B698-F7AEB913541D}" = Microsoft SQL Server 2008 R2 Management Objects
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A0DDC27-88E5-3CAD-BC3D-28FFD05CA6B9}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PLK
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{64858B76-F829-4591-A6E5-FA6387B55FAD}" = Tibiacast
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel sterowania NVIDIA 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Sterownik graficzny 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.85
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Aktualizacje NVIDIA 1.3.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D61C8B8D-F2B0-42F1-ABA5-CB63D7AD43E1}_is1" = AusLogics BoostSpeed
"{ED784556-66AA-3F17-9B58-7246ACB5C7E4}" = Microsoft Visual Basic 2010 Express - ENU
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"avast" = avast! Free Antivirus
"Banner Maker Pro 8_is1" = Banner Maker Pro Version 8
"CCleaner" = CCleaner
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"FileZilla Client" = FileZilla Client 3.5.0
"Gadu-Gadu 10" = Gadu-Gadu 10
"ie8" = Windows Internet Explorer 8
"ipla" = ipla 2.3.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft Visual Basic 2010 Express - ENU" = Microsoft Visual Basic 2010 Express - ENU
"Microsoft Visual C++ 2010 Express - ENU" = Microsoft Visual C++ 2010 Express - ENU
"Mozilla Firefox 5.0 (x86 pl)" = Mozilla Firefox 5.0 (x86 pl)
"Notepad++" = Notepad++
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"Steam App 1250" = Killing Floor
"SystemRequirementsLab" = System Requirements Lab
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Tibia_is1" = Tibia
"Warcraft III" = Warcraft III
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = Archiwizator WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"Yahoo! Companion" = Yahoo! Companion

[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

[color=#E56717]========== Last 10 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2011-07-23 14:28:40 | Computer Name = JARHEAD-ACD1642 | Source = MsiInstaller | ID = 11704
Description =

Error - 2011-07-23 15:34:02 | Computer Name = JARHEAD-ACD1642 | Source = MsiInstaller | ID = 11704
Description =

Error - 2011-07-24 05:43:31 | Computer Name = JARHEAD-ACD1642 | Source = .NET Runtime Optimization Service | ID = 1103
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Tried to start a service that wasn't the latest version of CLR Optimization service.
Will shutdown

Error - 2011-07-24 08:47:18 | Computer Name = JARHEAD-ACD1642 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)
- 1>Failed to compile: Accessibility, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
. Error code = 0x80131f06

Error - 2011-07-24 08:47:18 | Computer Name = JARHEAD-ACD1642 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)
- 1>Failed to compile: Accessibility, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
. Error code = 0x80131f06

Error - 2011-07-24 08:47:41 | Computer Name = JARHEAD-ACD1642 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)
- 1>Failed to compile: System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
. Error code = 0x80131f06

Error - 2011-07-24 08:47:41 | Computer Name = JARHEAD-ACD1642 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)
- 1>Failed to compile: System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
. Error code = 0x80131f06

Error - 2011-07-24 08:47:41 | Computer Name = JARHEAD-ACD1642 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)
- 1>Failed to compile: AspNetMMCExt, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
. Error code = 0x80131f06

Error - 2011-07-24 08:47:42 | Computer Name = JARHEAD-ACD1642 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)
- 1>Failed to compile: AspNetMMCExt, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
. Error code = 0x80131f06

Error - 2011-07-24 08:48:02 | Computer Name = JARHEAD-ACD1642 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)
- 1>Failed to compile: mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
. Error code = 0x8007007e

[ System Events ]
Error - 2011-07-22 08:59:55 | Computer Name = JARHEAD-ACD1642 | Source = DCOM | ID = 10010
Description = Serwer {000C101C-0000-0000-C000-000000000046} nie zarejestrował się
w modelu DCOM w wymaganym czasie.

Error - 2011-07-22 09:00:44 | Computer Name = JARHEAD-ACD1642 | Source = Windows Update Agent | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80070643: Aktualizacja zabezpieczeń
dla programu Microsoft Visual Studio 2010 (KB2542054).

Error - 2011-07-29 10:10:55 | Computer Name = JARHEAD-ACD1642 | Source = Service Control Manager | ID = 7011
Description = Limit czasu (30000 milisekund) podczas oczekiwania na odpowiedź transakcji
z usługi NVSvc.

Error - 2011-07-30 15:24:57 | Computer Name = JARHEAD-ACD1642 | Source = Service Control Manager | ID = 7011
Description = Limit czasu (30000 milisekund) podczas oczekiwania na odpowiedź transakcji
z usługi NVSvc.

Error - 2011-07-30 16:41:31 | Computer Name = JARHEAD-ACD1642 | Source = Windows Update Agent | ID = 20
Description = Instalacja nie powiodła się: system Windows nie mógł zainstalować
następującej aktualizacji, ponieważ wystąpił błąd 0x80246007: Aktualizacja zabezpieczeń
dla Edytora XML w programie Microsoft Visual Studio 2010 (KB2251489).

Error - 2011-07-31 03:22:48 | Computer Name = JARHEAD-ACD1642 | Source = Service Control Manager | ID = 7011
Description = Limit czasu (30000 milisekund) podczas oczekiwania na odpowiedź transakcji
z usługi NVSvc.

Error - 2011-08-01 15:35:00 | Computer Name = JARHEAD-ACD1642 | Source = Service Control Manager | ID = 7011
Description = Limit czasu (30000 milisekund) podczas oczekiwania na odpowiedź transakcji
z usługi NVSvc.

Error - 2011-08-04 09:26:00 | Computer Name = JARHEAD-ACD1642 | Source = Service Control Manager | ID = 7011
Description = Limit czasu (30000 milisekund) podczas oczekiwania na odpowiedź transakcji
z usługi NVSvc.

Error - 2011-08-05 04:16:07 | Computer Name = JARHEAD-ACD1642 | Source = Service Control Manager | ID = 7011
Description = Limit czasu (30000 milisekund) podczas oczekiwania na odpowiedź transakcji
z usługi NVSvc.

Error - 2011-08-05 15:28:52 | Computer Name = JARHEAD-ACD1642 | Source = Service Control Manager | ID = 7011
Description = Limit czasu (30000 milisekund) podczas oczekiwania na odpowiedź transakcji
z usługi NVSvc.


< End of report >
[/log]

[size="3"][b]z RSIT[/b][/size]

[log]Logfile of random's system information tool 1.08 (written by random/random)
Run by Jarhead at 2011-08-06 09:49:52
Microsoft Windows XP Professional Dodatek Service Pack 3
System drive C: has 3 GB (4%) free of 76 GB
Total RAM: 1023 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 09:49:57, on 2011-08-06
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Jarhead\Moje dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Jarhead.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-21-1390067357-1123561945-682003330-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} (WorldWinner ActiveX Launcher Control) - http://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab
O22 - SharedTaskScheduler: Moduł wstępnego ładowania interfejsu Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Demon buforu kategorii składników - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Usługa Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Usługa Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

--
End of file - 6348 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1123561945-682003330-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1123561945-682003330-1003UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
Yahoo! Companion BHO - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll [2005-04-22 328275]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-05-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - &Yahoo! Companion - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll [2005-04-22 328275]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-05-25 13895272]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2011-05-05 1632360]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [2008-04-14 171520]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Google Update"=C:\Documents and Settings\Jarhead\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2011-02-03 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a-squared]
C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2guard.exe /d=60 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu 10]
C:\Program Files\Gadu-Gadu 10\gg.exe [2010-12-16 12984928]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPLA!]
C:\Program Files\ipla\ipla.exe [2011-05-09 19759104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
C:\Program Files\Pando Networks\Media Booster\PMB.exe [2011-07-30 3077528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\steam.exe [2011-02-11 1242448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2010-07-12 74752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Gadu-Gadu 10\gg.exe"="C:\Program Files\Gadu-Gadu 10\gg.exe:*:Enabled:Gadu-Gadu 10"
"C:\Program Files\Tibiacast\Tibiacast Client.exe"="C:\Program Files\Tibiacast\Tibiacast Client.exe:*:Enabled:Tibiacast Client"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\Firefly Studios\Twierdza Krzyzowiec Extreme\Stronghold Crusader.exe"="C:\Program Files\Firefly Studios\Twierdza Krzyzowiec Extreme\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\Warcraft III\Warcraft III.exe"="C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\Metin2\metin2.bin"="C:\Program Files\Metin2\metin2.bin:*:Enabled:metin2"
"C:\Program Files\Metin2\metin2client.bin"="C:\Program Files\Metin2\metin2client.bin:*:Enabled:metin2client"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\Program Files\World of Warcraft\Launcher.patch.exe"="C:\Program Files\World of Warcraft\Launcher.patch.exe:*:Enabled:Blizzard Launcher"
"C:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe"="C:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-EU-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\Repair.exe"="C:\Program Files\World of Warcraft\Repair.exe:*:Enabled:Blizzard Repair Utility"
"C:\Program Files\Microsoft Games\Rise Of Legends\legends.exe"="C:\Program Files\Microsoft Games\Rise Of Legends\legends.exe:*:Enabled:Rise Of Legends"
"C:\Program Files\GameSpy Arcade\Aphex.exe"="C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade 1.4"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe"="C:\Program Files\AGEIA Technologies\bin\TrayIcon.exe:*:Enabled:AGEIA PhysX System Tray Icon"
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe"="C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:BackgroundDownloader.exe"
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\Program Files\VentSrv\ventrilo_srv.exe"="C:\Program Files\VentSrv\ventrilo_srv.exe:*:Disabled:ventrilo_srv"
"C:\Program Files\Xfire\Xfire.exe"="C:\Program Files\Xfire\Xfire.exe:*:Disabled:Xfire"
"C:\Program Files\Steam\steamapps\helluczolg\counter-strike\hl.exe"="C:\Program Files\Steam\steamapps\helluczolg\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"C:\Program Files\GIGABYTE\VGA Utility Manager\G-VGA.exe"="C:\Program Files\GIGABYTE\VGA Utility Manager\G-VGA.exe:*:Enabled:Menu"
"C:\Program Files\Tibia\Tibia.exe"="C:\Program Files\Tibia\Tibia.exe:*:Enabled:Tibia Player"
"C:\Program Files\Steam\steamapps\common\killingfloor\System\KillingFloor.exe"="C:\Program Files\Steam\steamapps\common\killingfloor\System\KillingFloor.exe:*:Enabled:Killing Floor"
"C:\Program Files\DreamCatcher\PainkillerMultiplayerDemo\Bin\painkillerdemo.exe"="C:\Program Files\DreamCatcher\PainkillerMultiplayerDemo\Bin\painkillerdemo.exe:*:Disabled:Painkiller"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

======List of files/folders created in the last 3 months======

2011-07-30 21:05:55 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\LolClient
2011-07-30 20:33:22 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2011-07-30 20:33:22 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2011-07-30 20:33:17 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2011-07-30 20:33:17 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2011-07-30 20:33:10 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2011-07-30 20:24:29 ----D---- C:\Riot Games
2011-07-30 19:34:29 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\PMB Files
2011-07-30 19:34:02 ----D---- C:\Program Files\Pando Networks
2011-07-24 11:25:43 ----HDC---- C:\WINDOWS\$NtUninstallKB2507938$
2011-07-23 21:39:54 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-07-23 21:39:54 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-07-23 21:39:52 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-07-23 21:39:51 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-07-23 21:39:51 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-07-23 21:39:51 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-07-23 21:39:51 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-07-23 21:39:50 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-07-23 21:39:35 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-07-23 21:39:25 ----D---- C:\Program Files\AVAST Software
2011-07-23 21:39:25 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\AVAST Software
2011-07-23 20:22:57 ----D---- C:\8354f671bc50f4e0ab3108c9
2011-07-22 15:05:00 ----D---- C:\Config.Msi
2011-07-22 15:01:17 ----D---- C:\2f00e3efcddf74f6ce801267e97db7cb
2011-07-22 09:42:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2555917$
2011-07-20 15:46:00 ----HDC---- C:\WINDOWS\$NtUninstallKB2476490$
2011-07-20 15:45:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2503665$
2011-07-20 15:43:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2535512$
2011-07-20 15:39:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276$
2011-07-17 18:05:27 ----D---- C:\Program Files\MetaTrader - FXOpen
2011-07-02 00:09:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2544893$
2011-07-02 00:08:32 ----D---- C:\WINDOWS\SxsCaPendDel
2011-07-02 00:07:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2541763$
2011-06-29 15:46:01 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\Publish Providers
2011-06-29 15:46:00 ----D---- C:\Program Files\VSTplugins
2011-06-29 15:45:36 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\Sony
2011-06-29 15:41:50 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\Toolbar4
2011-06-29 15:33:52 ----D---- C:\Fraps
2011-06-29 15:31:38 ----D---- C:\Program Files\Sony Setup
2011-06-28 23:43:36 ----D---- C:\Program Files\TibiaReplay
2011-06-26 21:10:37 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-06-26 21:10:23 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Norton
2011-06-26 21:10:19 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\NortonInstaller
2011-06-26 19:09:53 ----D---- C:\WINDOWS\system32\Adobe
2011-06-25 14:34:40 ----D---- C:\Program Files\GIGABYTE
2011-06-25 14:26:01 ----A---- C:\WINDOWS\system32\drivers\GVTDrv.sys
2011-06-25 14:25:13 ----D---- C:\Program Files\Yahoo!
2011-06-24 21:24:02 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\Cobra Mobile
2011-06-19 20:34:01 ----D---- C:\Program Files\Banner Maker Pro 8
2011-06-07 19:09:53 ----A---- C:\WINDOWS\system32\javaws.exe
2011-06-07 19:09:53 ----A---- C:\WINDOWS\system32\javaw.exe
2011-06-07 19:09:53 ----A---- C:\WINDOWS\system32\java.exe
2011-06-05 15:54:28 ----D---- C:\Program Files\WorldWinner.com, Inc
2011-06-05 15:54:28 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\Worldwinner
2011-06-03 08:28:36 ----A---- C:\WINDOWS\system32\nvgenco322090.dll
2011-06-03 08:28:35 ----A---- C:\WINDOWS\system32\nvdispco3220150.dll
2011-05-29 16:13:00 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP
2011-05-28 14:56:24 ----A---- C:\WINDOWS\system32\frapsvid.dll
2011-05-28 00:18:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\NVIDIA
2011-05-28 00:14:19 ----A---- C:\WINDOWS\system32\nvgenco322060.dll
2011-05-28 00:14:18 ----A---- C:\WINDOWS\system32\nvdispco3220140.dll
2011-05-28 00:09:20 ----D---- C:\Program Files\SystemRequirementsLab
2011-05-17 17:14:32 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-05-15 08:37:31 ----A---- C:\WINDOWS\system32\muweb.dll
2011-05-15 08:37:31 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2011-05-15 08:37:31 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-05-14 22:09:45 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\Apple Computer
2011-05-14 16:11:40 ----D---- C:\Program Files\PlayReady
2011-05-14 15:56:53 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\RDRM

======List of files/folders modified in the last 3 months======

2011-08-06 09:49:56 ----D---- C:\Program Files\trend micro
2011-08-06 09:21:24 ----SH---- C:\boot.ini
2011-08-06 09:21:24 ----A---- C:\WINDOWS\win.ini
2011-08-06 09:21:24 ----A---- C:\WINDOWS\system.ini
2011-08-06 09:19:42 ----D---- C:\WINDOWS\Temp
2011-08-06 09:18:17 ----D---- C:\WINDOWS\system32\CatRoot2
2011-08-06 00:24:54 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-08-05 23:31:12 ----D---- C:\Program Files\World of Warcraft
2011-08-05 15:28:16 ----D---- C:\Program Files\Warcraft III
2011-08-04 16:14:43 ----D---- C:\WINDOWS
2011-08-03 23:09:18 ----D---- C:\Program Files\Tibia
2011-08-03 23:09:16 ----D---- C:\WINDOWS\Prefetch
2011-08-01 09:34:09 ----D---- C:\WINDOWS\Microsoft.NET
2011-07-31 23:11:15 ----D---- C:\WINDOWS\system32
2011-07-31 09:30:14 ----SHD---- C:\WINDOWS\Installer
2011-07-30 20:33:29 ----D---- C:\WINDOWS\system32\DirectX
2011-07-30 20:33:22 ----HD---- C:\WINDOWS\inf
2011-07-30 20:33:05 ----D---- C:\WINDOWS\Logs
2011-07-30 20:24:26 ----HD---- C:\Program Files\InstallShield Installation Information
2011-07-30 19:34:02 ----RD---- C:\Program Files
2011-07-29 11:08:57 ----RSD---- C:\WINDOWS\assembly
2011-07-27 20:18:58 ----D---- C:\Program Files\Steam
2011-07-27 20:18:57 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\TS3Client
2011-07-27 20:18:50 ----D---- C:\WINDOWS\Debug
2011-07-26 19:58:25 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2011-07-26 19:57:58 ----D---- C:\WINDOWS\WinSxS
2011-07-26 19:57:34 ----D---- C:\Program Files\Microsoft SQL Server
2011-07-26 19:56:36 ----SD---- C:\Documents and Settings\Jarhead\Dane aplikacji\Microsoft
2011-07-26 19:56:36 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Microsoft
2011-07-26 16:51:21 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\FileZilla
2011-07-24 12:53:32 ----D---- C:\Program Files\FileZilla FTP Client
2011-07-24 11:29:16 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-07-24 11:25:46 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-07-23 21:39:54 ----D---- C:\WINDOWS\system32\drivers
2011-07-20 16:54:10 ----HD---- C:\WINDOWS\$hf_mig$
2011-07-20 16:48:13 ----D---- C:\WINDOWS\system32\CatRoot
2011-07-20 16:40:47 ----D---- C:\Program Files\Microsoft Silverlight
2011-07-20 15:43:35 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2011-07-20 15:39:40 ----D---- C:\Program Files\Internet Explorer
2011-07-20 15:39:08 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2011-07-20 15:19:34 ----D---- C:\WINDOWS\Minidump
2011-07-20 15:17:42 ----SD---- C:\WINDOWS\Tasks
2011-07-20 15:06:48 ----D---- C:\WINDOWS\network diagnostic
2011-07-13 16:49:39 ----SHD---- C:\System Volume Information
2011-07-09 12:10:48 ----D---- C:\Program Files\Firefly Studios
2011-07-02 23:12:47 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\ipla
2011-07-02 21:49:37 ----D---- C:\Logs
2011-07-02 00:06:41 ----D---- C:\WINDOWS\ie8updates
2011-07-01 09:54:42 ----A---- C:\WINDOWS\system32\MRT.exe
2011-06-26 21:10:37 ----D---- C:\Program Files\Common Files
2011-06-26 19:10:57 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\Adobe
2011-06-24 21:23:58 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2011-06-24 21:23:58 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2011-06-23 22:51:39 ----D---- C:\Program Files\Mozilla Firefox
2011-06-18 15:00:43 ----D---- C:\Program Files\Emsisoft Anti-Malware
2011-06-16 11:43:24 ----D---- C:\Program Files\Tibiacast
2011-06-11 17:45:52 ----D---- C:\Program Files\TeamSpeak 3 Client
2011-06-08 19:18:00 ----RSD---- C:\WINDOWS\Fonts
2011-06-08 19:08:25 ----D---- C:\Program Files\WarRock
2011-06-08 19:06:17 ----D---- C:\Program Files\Mumble
2011-06-07 19:09:48 ----D---- C:\Program Files\Java
2011-06-07 19:04:28 ----D---- C:\Program Files\QuickTime
2011-06-05 22:20:28 ----D---- C:\Program Files\Microsoft Games
2011-06-05 15:54:35 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\WorldWinner
2011-06-03 08:34:43 ----D---- C:\WINDOWS\Help
2011-06-03 08:31:08 ----D---- C:\Program Files\NVIDIA Corporation
2011-06-03 08:30:39 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-05-31 00:12:42 ----A---- C:\WINDOWS\system32\mshtml.dll
2011-05-28 00:18:10 ----D---- C:\Documents and Settings
2011-05-25 09:26:15 ----A---- C:\WINDOWS\system32\nvwddi.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrszht.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrszhc.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrstr.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrsth.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrssv.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrssl.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrssk.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrsru.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrsptb.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrspt.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrspl.dll
2011-05-25 09:26:14 ----A---- C:\WINDOWS\system32\nvrsno.dll
2011-05-25 09:26:13 ----A---- C:\WINDOWS\system32\nvrsnl.dll
2011-05-25 09:26:13 ----A---- C:\WINDOWS\system32\nvrsko.dll
2011-05-25 09:26:13 ----A---- C:\WINDOWS\system32\nvrsja.dll
2011-05-25 09:26:13 ----A---- C:\WINDOWS\system32\nvrsit.dll
2011-05-25 09:26:13 ----A---- C:\WINDOWS\system32\nvrshu.dll
2011-05-25 09:26:12 ----A---- C:\WINDOWS\system32\nvrshe.dll
2011-05-25 09:26:12 ----A---- C:\WINDOWS\system32\nvrsfr.dll
2011-05-25 09:26:12 ----A---- C:\WINDOWS\system32\nvrsfi.dll
2011-05-25 09:26:11 ----A---- C:\WINDOWS\system32\nvrsesm.dll
2011-05-25 09:26:11 ----A---- C:\WINDOWS\system32\nvrses.dll
2011-05-25 09:26:11 ----A---- C:\WINDOWS\system32\nvrseng.dll
2011-05-25 09:26:11 ----A---- C:\WINDOWS\system32\nvrsel.dll
2011-05-25 09:26:11 ----A---- C:\WINDOWS\system32\nvrsde.dll
2011-05-25 09:26:10 ----A---- C:\WINDOWS\system32\nvrsda.dll
2011-05-25 09:26:10 ----A---- C:\WINDOWS\system32\nvrscs.dll
2011-05-25 09:26:10 ----A---- C:\WINDOWS\system32\nvrsar.dll
2011-05-25 09:26:09 ----A---- C:\WINDOWS\system32\nvmctray.dll
2011-05-25 09:26:03 ----A---- C:\WINDOWS\system32\nvcpl.dll
2011-05-25 09:26:01 ----A---- C:\WINDOWS\system32\nvcolor.exe
2011-05-25 09:26:00 ----A---- C:\WINDOWS\system32\easyupdatusapiu.dll
2011-05-25 09:25:58 ----A---- C:\WINDOWS\system32\OpenCL.dll
2011-05-25 09:25:58 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2011-05-25 09:25:57 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2011-05-25 09:25:57 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2011-05-25 09:25:57 ----A---- C:\WINDOWS\system32\nvcuda.dll
2011-05-25 09:25:57 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2011-05-25 09:25:56 ----A---- C:\WINDOWS\system32\nvapi.dll
2011-05-25 09:25:56 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2011-05-21 16:23:17 ----D---- C:\Program Files\Common Files\Apple
2011-05-21 16:22:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2011-05-17 17:14:32 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Apple Computer
2011-05-15 17:45:43 ----D---- C:\Program Files\Opera
2011-05-15 11:23:29 ----D---- C:\Program Files\VentSrv
2011-05-15 11:23:29 ----D---- C:\Documents and Settings\Jarhead\Dane aplikacji\Ventrilo
2011-05-15 11:18:31 ----D---- C:\Program Files\CCleaner
2011-05-14 16:11:53 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ipla
2011-05-14 15:56:37 ----D---- C:\Program Files\ipla
2011-05-09 13:31:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 gagp30kx;Filtr rodzajowy AGPv3.0 firmy Microsoft dla platform procesora K8; C:\WINDOWS\system32\DRIVERS\gagp30kx.sys [2008-04-14 46464]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-07-04 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-07-04 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-07-04 441176]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-07-04 309848]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-07-04 43608]
R1 Tcpip6;Sterownik protokołu IPv6 Microsoft; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-07-04 19544]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-07-04 102616]
R2 NwlnkIpx;Protokół transportowy zgodny z NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;System NetBIOS NWLink; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2002-09-29 63232]
R2 NwlnkSpx;Protokół NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2002-09-29 55936]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
R3 hidusb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Sterownik myszy HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2002-09-29 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-05-25 12753664]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2008-04-14 163584]
R3 rtl8139;Sterownik NT karty Realtek RTL8139(A/B/C)-based PCI Fast Ethernet; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 tunmp;Sterownik karty Microsoft Tun Miniport; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R3 usbuhci;Sterownik Miniport uniwersalnego kontrolera hosta USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 kbdhid;Sterownik klawiatury HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys []
S3 GVTDrv;GVTDrv; \??\C:\WINDOWS\system32\Drivers\GVTDrv.sys []
S3 nm;Sterownik monitora sieci; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 usbccgp;Rodzajowy sterownik nadrzędny USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 USBSTOR;Sterownik magazynu masowego USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Usługa Pomocnik IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-05-04 153376]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2011-05-25 154728]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-25 2214504]
R2 NWCWorkstation;Usługa klienta dla systemu NetWare; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 NwSapAgent;Agent SAP; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Usługa Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-28 136176]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Usługa Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-28 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------
[/log]

bump

wirusolog
komentarz
komentarz (edytowane)

Ja nie widzę w logach niczego podejrzanego.

Kosmetyka:
[hr]

[b]1.[/b] Uruchom OTL i w oknie [b]Własne opcje skanowania/Skrypt[/b] wklej następujący tekst:

[code]:OTL
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2192277&SearchSource=2&q="
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2192277&SearchSource=3&q={searchTerms}"
MsConfig - StartUpReg: a-squared - hkey= - key= - File not found
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - File not found
@Alternate Data Stream - 48 bytes -> C:\Documents and Settings\All Users.WINDOWS\DRM:مايكروسوفت
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP:08948D52

:Files
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Config.nt.bak
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Autoexec.nt.bak
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\hosts.bak
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1123561945-682003330-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1123561945-682003330-1003UA.job

:Commands
[emptyflash]
[emptytemp][/code]
Kliknij w [b]Wykonaj skrypt[/b]. Zatwierdź restart komputera. Po restarcie pokaż raport z usuwania.

  • Dobra wypowiedź 1
maxsp2
komentarz
komentarz (edytowane)

A jak obserwujesz to w ilu % ci obciąża łącze.

Dla pewności możesz użyć [url="http://www.pobierztu.pl/program/subcategory/1"]antyszpiegowskie[/url] oprogramowanie. A dokładnie mam na myśli Malwarebytes' Anti-Malware.

Tylko po instalacji dajesz odrzuć i jest darmowy bo jest okienko z taką opcja.

I po aktualizacji jego bazy skanować.

Polecam ze wglądu na skuteczność.

  • Dobra wypowiedź 1

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.