lifous utworzono 21 sierpnia 2011 utworzono 21 sierpnia 2011 Witam, przed formatem wgrałem foldery ze zdjęciami, notatniki z hasłami itp.. Zawsze przed formatem te same pliki kopiowalem.. Teraz po formacie wchodze na pendrive patrzee a tu: http://imageshack.us/photo/my-images/197/28493684.jpg/ 1. Jest to pendrive a na nim te foldery wgrane, chociaż one się inaczej nazywały.. 2. To są opcje po kliknięciu PPM na pliku byle jakim.. Da się jakoś to odzyskać ?
okejokej komentarz 21 sierpnia 2011 komentarz 21 sierpnia 2011 (edytowane) Jesteś pewny że przekopiowałeś dane, bo ja tu widzę same skróty
lifous komentarz 22 sierpnia 2011 Autor komentarz 22 sierpnia 2011 No właśnie dobrze, i teraz nawet w te skróty wejść nie moge i w ten notatnik Password.. ;( A miałem braciaka małego zdjęcia z roczku, chrzcin ;p : (
kuba134 komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 musiałeś się pomylić i zamiast skopiować dane, skopiowałeś sktóry do tych danych. Jeśli komp jest już po formacie to nic z tym niestety już nie zrobisz.
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 [b]liofus[/b] masz infekcje na dysku ([b]podstawia skróty w miejsce prawdziwych plików[/b]) Pobierz USBfix[b] [url="http://www.teamxscript.changelog.fr/too/UsbFix.exe"]KLIK[/url][/b] i daj log z opcji[b] listing[/b]. Pendraiw ma być podłaczony
lifous komentarz 22 sierpnia 2011 Autor komentarz 22 sierpnia 2011 [code] ############################## | UsbFix 7.057 | [Listing] User: lifous (Administrator) # LIFOUS-PC [MICRO-STAR INTERNATIONAL CO.,LTD MS-7507] Updated 21/08/2011 by El Desaparecido Started at 15:02:34 | 22/08/2011 Website: http://www.teamxscript.org Submit your sample: http://www.teamxscript.org/Upload.php Contact: TeamXscript.ElDesaparecido@gmail.com CPU: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz CPU 2: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz Microsoft® Windows Vista™ Home Basic (6.0.6000 32-Bit) # Internet Explorer 7.0.6000.16982 Windows Firewall: Enabled RAM -> 3071 Mb C:\ (%systemdrive%) -> Fixed drive # 195 Gb (163 Mb free - 83%) [] # NTFS D:\ -> Fixed drive # 270 Gb (260 Mb free - 96%) [] # NTFS E:\ -> CD-ROM F:\ -> CD-ROM G:\ -> Removable drive # 7 Gb (7 Mb free - 100%) [CRUZER] # FAT32 ################## | Listing | [20/08/2011 - 13:10:24 | SHD ] C:\$Recycle.Bin [18/09/2006 - 23:43:36 | A | 24] C:\autoexec.bat [20/08/2011 - 12:54:58 | SHD ] C:\Boot [02/11/2006 - 11:53:57 | RASH | 438840] C:\bootmgr [20/08/2011 - 12:54:58 | RAS | 8192] C:\BOOTSECT.BAK [18/09/2006 - 23:43:37 | A | 10] C:\config.sys [02/11/2006 - 14:59:44 | SHD ] C:\Documents and Settings [22/08/2011 - 09:59:20 | ASH | 3220430848] C:\hiberfil.sys [20/08/2011 - 13:30:10 | D ] C:\Intel [22/08/2011 - 09:59:19 | ASH | 3534356480] C:\pagefile.sys [22/08/2011 - 10:21:42 | RD ] C:\Program Files [22/08/2011 - 10:20:33 | HD ] C:\ProgramData [22/08/2011 - 10:26:00 | SHD ] C:\System Volume Information [22/08/2011 - 15:02:24 | D ] C:\UsbFix [22/08/2011 - 15:02:24 | A | 1585] C:\UsbFix.txt [20/08/2011 - 13:44:08 | RD ] C:\Users [22/08/2011 - 10:21:58 | D ] C:\Windows [20/08/2011 - 13:32:05 | SHD ] D:\$RECYCLE.BIN [22/08/2011 - 15:00:03 | D ] D:\DOWNLOAD [22/08/2011 - 10:26:23 | D ] D:\Program files [20/08/2011 - 13:52:39 | SHD ] D:\System Volume Information [14/08/2007 - 02:30:58 | R | 402696] F:\AutoRun.exe [02/09/2007 - 06:55:55 | D ] F:\Autorun [02/09/2007 - 06:55:09 | D ] F:\CommonEASO [02/09/2007 - 06:55:53 | D ] F:\DirectX [14/08/2007 - 02:30:58 | R | 386312] F:\EASetup.exe [02/09/2007 - 06:53:35 | R | 11183368] F:\FIFA08.exe [25/09/2007 - 05:34:40 | D ] F:\Fairlight [02/09/2007 - 05:44:06 | R | 910670944] F:\Group1.cab [02/09/2007 - 05:40:42 | R | 12820728] F:\Group10.cab [02/09/2007 - 05:38:51 | R | 620340903] F:\Group2.cab [02/09/2007 - 05:37:25 | R | 486893877] F:\Group3.cab [02/09/2007 - 05:40:16 | R | 215235894] F:\Group4.cab [02/09/2007 - 06:54:13 | D ] F:\Player [02/09/2007 - 06:55:53 | D ] F:\Support [02/09/2007 - 06:55:57 | D ] F:\alocale [02/09/2007 - 06:56:15 | R | 2984960] F:\autorun.dat [02/09/2007 - 06:50:18 | R | 136] F:\autorun.inf [02/09/2007 - 05:20:21 | R | 26238] F:\config.dat [02/09/2007 - 06:54:13 | D ] F:\data [14/07/2007 - 05:28:52 | R | 25622] F:\fifapc.ico [16/07/2007 - 22:00:39 | R | 6168] F:\gameinterface.tlb [12/08/2011 - 23:37:56 | RSH | 172543] G:\cxim.pif [20/08/2011 - 11:39:36 | RSH | 136] G:\autorun.inf [20/08/2011 - 11:39:36 | RSH | 49152] G:\gaegaen.exe [27/07/2011 - 16:24:48 | RSH | 49152] G:\gaegaen.scr [22/08/2011 - 15:01:14 | A | 382] G:\New Folder.lnk [22/08/2011 - 15:01:14 | A | 382] G:\Passwords.lnk [22/08/2011 - 15:01:14 | A | 382] G:\Documents.lnk [22/08/2011 - 15:01:14 | A | 382] G:\Pictures.lnk [22/08/2011 - 15:01:14 | A | 382] G:\Music.lnk [22/08/2011 - 15:01:14 | A | 382] G:\Video.lnk ################## | E.O.F | [/code]
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 [b]1.[/b] Pobierz OTL [b][url="http://oldtimer.geekstogo.com/OTL.exe"]KLIK[/url][/b] Uruchom i w sekcji [b]Własne opcja skanowania / skrypt[/b] wklej: [php]:Files G:\*.lnk G:\cxim.pif G:\autorun.inf G:\gaegaen.exe G:\gaegaen.scr attrib /d /s -s -h G:\* /C[/php] Klik w [b]Wykonaj skrypt[/b]. Z tej operacji powstanie log. Na urządzeniu powinno się już wszystko odkryć [b]2.[/b] Do oceny wystarczy log z punktu 1 oraz nowy USBFix z opcji Listing.
lifous komentarz 22 sierpnia 2011 Autor komentarz 22 sierpnia 2011 Kurde miałem pena niepodłączonego. Teraz to jest po podłączeniu usb, nie wiem czy coś się zmieniło [code] ############################## | UsbFix 7.057 | [Listing] User: lifous (Administrator) # LIFOUS-PC [MICRO-STAR INTERNATIONAL CO.,LTD MS-7507] Updated 21/08/2011 by El Desaparecido Started at 15:31:47 | 22/08/2011 Website: http://www.teamxscript.org Submit your sample: http://www.teamxscript.org/Upload.php Contact: TeamXscript.ElDesaparecido@gmail.com CPU: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz CPU 2: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz Microsoft® Windows Vista™ Home Basic (6.0.6000 32-Bit) # Internet Explorer 7.0.6000.16982 Windows Firewall: Enabled RAM -> 3071 Mb C:\ (%systemdrive%) -> Fixed drive # 195 Gb (163 Mb free - 83%) [] # NTFS D:\ -> Fixed drive # 270 Gb (261 Mb free - 96%) [] # NTFS E:\ -> CD-ROM F:\ -> CD-ROM G:\ -> Removable drive # 7 Gb (7 Mb free - 100%) [CRUZER] # FAT32 ################## | Listing | [20/08/2011 - 13:10:24 | SHD ] C:\$Recycle.Bin [18/09/2006 - 23:43:36 | A | 24] C:\autoexec.bat [20/08/2011 - 12:54:58 | SHD ] C:\Boot [02/11/2006 - 11:53:57 | RASH | 438840] C:\bootmgr [20/08/2011 - 12:54:58 | RAS | 8192] C:\BOOTSECT.BAK [18/09/2006 - 23:43:37 | A | 10] C:\config.sys [02/11/2006 - 14:59:44 | SHD ] C:\Documents and Settings [22/08/2011 - 15:29:48 | ASH | 3220430848] C:\hiberfil.sys [20/08/2011 - 13:30:10 | D ] C:\Intel [22/08/2011 - 15:29:34 | ASH | 3534356480] C:\pagefile.sys [22/08/2011 - 10:21:42 | RD ] C:\Program Files [22/08/2011 - 10:20:33 | HD ] C:\ProgramData [22/08/2011 - 10:26:00 | SHD ] C:\System Volume Information [22/08/2011 - 15:02:24 | D ] C:\UsbFix [22/08/2011 - 15:31:46 | A | 1585] C:\UsbFix.txt [20/08/2011 - 13:44:08 | RD ] C:\Users [22/08/2011 - 15:29:24 | D ] C:\Windows [20/08/2011 - 13:32:05 | SHD ] D:\$RECYCLE.BIN [22/08/2011 - 15:28:24 | D ] D:\DOWNLOAD [22/08/2011 - 10:26:23 | D ] D:\Program files [20/08/2011 - 13:52:39 | SHD ] D:\System Volume Information [22/08/2011 - 15:27:51 | D ] D:\_OTL [14/08/2007 - 02:30:58 | R | 402696] F:\AutoRun.exe [02/09/2007 - 06:55:55 | D ] F:\Autorun [02/09/2007 - 06:55:09 | D ] F:\CommonEASO [02/09/2007 - 06:55:53 | D ] F:\DirectX [14/08/2007 - 02:30:58 | R | 386312] F:\EASetup.exe [02/09/2007 - 06:53:35 | R | 11183368] F:\FIFA08.exe [25/09/2007 - 05:34:40 | D ] F:\Fairlight [02/09/2007 - 05:44:06 | R | 910670944] F:\Group1.cab [02/09/2007 - 05:40:42 | R | 12820728] F:\Group10.cab [02/09/2007 - 05:38:51 | R | 620340903] F:\Group2.cab [02/09/2007 - 05:37:25 | R | 486893877] F:\Group3.cab [02/09/2007 - 05:40:16 | R | 215235894] F:\Group4.cab [02/09/2007 - 06:54:13 | D ] F:\Player [02/09/2007 - 06:55:53 | D ] F:\Support [02/09/2007 - 06:55:57 | D ] F:\alocale [02/09/2007 - 06:56:15 | R | 2984960] F:\autorun.dat [02/09/2007 - 06:50:18 | R | 136] F:\autorun.inf [02/09/2007 - 05:20:21 | R | 26238] F:\config.dat [02/09/2007 - 06:54:13 | D ] F:\data [14/07/2007 - 05:28:52 | R | 25622] F:\fifapc.ico [16/07/2007 - 22:00:39 | R | 6168] F:\gameinterface.tlb [22/08/2011 - 15:30:32 | RSH | 135] G:\autorun.inf [22/08/2011 - 15:30:36 | RSH | 49152] G:\cuebud.exe [21/08/2011 - 19:46:10 | RSH | 49152] G:\cuebud.scr [22/08/2011 - 15:30:38 | A | 377] G:\New Folder.lnk [22/08/2011 - 15:30:38 | A | 377] G:\Passwords.lnk [22/08/2011 - 15:30:38 | A | 377] G:\Documents.lnk [22/08/2011 - 15:30:38 | A | 377] G:\Pictures.lnk [22/08/2011 - 15:30:38 | A | 377] G:\Music.lnk [22/08/2011 - 15:30:38 | A | 377] G:\Video.lnk ################## | E.O.F | [/code]Jesli to jest to samo, to zrobilem teraz co mi kazales wkleic.. Zrobilem to, notatnik się stworzył.. Ale dupa.. są skróty.. Tylko że 2. pkt nie zrobiłem Bo nie kumam.
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 (edytowane) [quote]Kurde miałem pena niepodłączonego [/quote] Troche rozwagi przecież usuwamy z dysku przenośnego i musi być podłaczony. [quote]Jesli to jest to samo, to zrobilem teraz co mi kazales wkleic.. [/quote] Nie jest to samo. Jak nie dałem innych poleceń - nie działaj na własną rękę. Powtarzaj, nowy skrypt [php]:Files G:\*.lnk G:\autorun.inf G:\cuebud.exe G:\cuebud.scr attrib /d /s -s -h G:\* /C[/php] z usuwania bedzie nowy log z [b]OTL[/b] masz go dać i jeszcze raz wykonać log z [b]USBfix[/b]
lifous komentarz 22 sierpnia 2011 Autor komentarz 22 sierpnia 2011 Wkleilem ten skrypt, teraz musze uruchomic go ponownie, ale czekam na twoje dalsze wskazówki
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 [quote]Wkleilem ten skrypt, [/quote] Edytowałem posta. W skrypcie był błąd było Files: a powinno :Files który skrypt wkleiłeś?
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 jesteś pewien ze ten edytowany? bo jeśli wkleiłeś z błedem może sie windows wysypać. chodzi mi o pierwszą linijke skryptu - powinna tak wygląać [code]:Files [/code]
lifous komentarz 22 sierpnia 2011 Autor komentarz 22 sierpnia 2011 hmm, właśnie właśnie, tam było coś, ale to ten stary wklejałem.. To reset kompa zrobiłem, to potem jak się włączał, to napisy wyskoczyły, i coś o dysku czy cos ze jakąś płyte włożyć czy coś;p Tak wkleiłem ten edytowany.
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 [quote]Tak wkleiłem ten edytowany. [/quote] To wykonaj restart. I daj mi logi do oceny zarówno z USBfix jak i z OTL. Przy czym z Otl wykonaj skanowanie na poniższych ustawieniach Po uruchomieniu OTL pojawi sie okienko główne i w nim masz zaznaczyć następujące opcje: [b]Wszystkie sekcje ustawione na Użyj filtrowania (Use SafeList). Należy zaznaczyć Wszyscy użytkownicy (Scan All Users) Dodatkowo postawić ptaszki przy pozycjach Infekcja LOP (LOP Check) + Infekcja Purity (Purity Check)[/b] Potem klikasz Skanuj. Jak program skończy powstaną dwa logi [b]OTL i Extras[/b], obydwa wstaw na wklej org.
lifous komentarz 22 sierpnia 2011 Autor komentarz 22 sierpnia 2011 (edytowane) USBFIX [code]############################## | UsbFix 7.057 | [Listing] User: lifous (Administrator) # LIFOUS-PC [MICRO-STAR INTERNATIONAL CO.,LTD MS-7507] Updated 21/08/2011 by El Desaparecido Started at 16:25:17 | 22/08/2011 Website: http://www.teamxscript.org Submit your sample: http://www.teamxscript.org/Upload.php Contact: TeamXscript.ElDesaparecido@gmail.com CPU: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz CPU 2: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz Microsoft® Windows Vista™ Home Basic (6.0.6000 32-Bit) # Internet Explorer 7.0.6000.16982 Windows Firewall: Enabled RAM -> 3071 Mb C:\ (%systemdrive%) -> Fixed drive # 195 Gb (163 Mb free - 83%) [] # NTFS D:\ -> Fixed drive # 270 Gb (261 Mb free - 96%) [] # NTFS E:\ -> CD-ROM F:\ -> CD-ROM G:\ -> Removable drive # 7 Gb (7 Mb free - 100%) [CRUZER] # FAT32 ################## | Listing | [20/08/2011 - 13:10:24 | SHD ] C:\$Recycle.Bin [18/09/2006 - 23:43:36 | A | 24] C:\autoexec.bat [20/08/2011 - 12:54:58 | SHD ] C:\Boot [02/11/2006 - 11:53:57 | RASH | 438840] C:\bootmgr [20/08/2011 - 12:54:58 | RAS | 8192] C:\BOOTSECT.BAK [18/09/2006 - 23:43:37 | A | 10] C:\config.sys [02/11/2006 - 14:59:44 | SHD ] C:\Documents and Settings [22/08/2011 - 16:23:10 | ASH | 3220430848] C:\hiberfil.sys [20/08/2011 - 13:30:10 | D ] C:\Intel [22/08/2011 - 16:23:08 | ASH | 3534356480] C:\pagefile.sys [22/08/2011 - 10:21:42 | RD ] C:\Program Files [22/08/2011 - 10:20:33 | HD ] C:\ProgramData [22/08/2011 - 10:26:00 | SHD ] C:\System Volume Information [22/08/2011 - 15:02:24 | D ] C:\UsbFix [22/08/2011 - 16:25:15 | A | 1585] C:\UsbFix.txt [20/08/2011 - 13:44:08 | RD ] C:\Users [22/08/2011 - 15:43:09 | D ] C:\Windows [20/08/2011 - 13:32:05 | SHD ] D:\$RECYCLE.BIN [22/08/2011 - 16:08:20 | D ] D:\DOWNLOAD [22/08/2011 - 10:26:23 | D ] D:\Program files [20/08/2011 - 13:52:39 | SHD ] D:\System Volume Information [22/08/2011 - 15:27:51 | D ] D:\_OTL [14/08/2007 - 02:30:58 | R | 402696] F:\AutoRun.exe [02/09/2007 - 06:55:55 | D ] F:\Autorun [02/09/2007 - 06:55:09 | D ] F:\CommonEASO [02/09/2007 - 06:55:53 | D ] F:\DirectX [14/08/2007 - 02:30:58 | R | 386312] F:\EASetup.exe [02/09/2007 - 06:53:35 | R | 11183368] F:\FIFA08.exe [25/09/2007 - 05:34:40 | D ] F:\Fairlight [02/09/2007 - 05:44:06 | R | 910670944] F:\Group1.cab [02/09/2007 - 05:40:42 | R | 12820728] F:\Group10.cab [02/09/2007 - 05:38:51 | R | 620340903] F:\Group2.cab [02/09/2007 - 05:37:25 | R | 486893877] F:\Group3.cab [02/09/2007 - 05:40:16 | R | 215235894] F:\Group4.cab [02/09/2007 - 06:54:13 | D ] F:\Player [02/09/2007 - 06:55:53 | D ] F:\Support [02/09/2007 - 06:55:57 | D ] F:\alocale [02/09/2007 - 06:56:15 | R | 2984960] F:\autorun.dat [02/09/2007 - 06:50:18 | R | 136] F:\autorun.inf [02/09/2007 - 05:20:21 | R | 26238] F:\config.dat [02/09/2007 - 06:54:13 | D ] F:\data [14/07/2007 - 05:28:52 | R | 25622] F:\fifapc.ico [16/07/2007 - 22:00:39 | R | 6168] F:\gameinterface.tlb [22/08/2011 - 16:23:40 | RSH | 135] G:\autorun.inf [22/08/2011 - 16:23:44 | RSH | 49152] G:\cuebud.exe [21/08/2011 - 19:46:10 | RSH | 49152] G:\cuebud.scr [22/08/2011 - 16:23:44 | A | 377] G:\New Folder.lnk [22/08/2011 - 16:23:44 | A | 377] G:\Passwords.lnk [22/08/2011 - 16:23:44 | A | 377] G:\Documents.lnk [22/08/2011 - 16:23:44 | A | 377] G:\Pictures.lnk [22/08/2011 - 16:23:44 | A | 377] G:\Music.lnk [22/08/2011 - 16:23:44 | A | 377] G:\Video.lnk ################## | E.O.F | [/code] OTL [code] ========== FILES ========== G:\New Folder.lnk moved successfully. G:\Passwords.lnk moved successfully. G:\Documents.lnk moved successfully. G:\Pictures.lnk moved successfully. G:\Music.lnk moved successfully. G:\Video.lnk moved successfully. File move failed. G:\autorun.inf scheduled to be moved on reboot. G:\cuebud.exe moved successfully. File move failed. G:\cuebud.scr scheduled to be moved on reboot. [color=#A23BEC]< attrib /d /s -s -h G:\* /C >[/color] D:\DOWNLOAD\cmd.bat deleted successfully. D:\DOWNLOAD\cmd.txt deleted successfully. OTL by OldTimer - Version 3.2.26.5 log created on 08222011_160810 Files\Folders moved on Reboot... G:\autorun.inf moved successfully. G:\cuebud.scr moved successfully. Registry entries deleted on Reboot... [/code] i zaraz zaczne zaznaczac tamto A to wyskoczyło po skanowaniu. [code] OTL logfile created on: 2011-08-22 16:25:45 - Run 1 OTL by OldTimer - Version 3.2.26.5 Folder = D:\DOWNLOAD Windows Vista Home Basic Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16982) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 1,98 Gb Available Physical Memory | 66,09% Memory free 6,18 Gb Paging File | 5,19 Gb Available in Paging File | 83,97% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 195,31 Gb Total Space | 162,82 Gb Free Space | 83,36% Space Free | Partition Type: NTFS Drive D: | 270,45 Gb Total Space | 260,69 Gb Free Space | 96,39% Space Free | Partition Type: NTFS Drive F: | 2,67 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Drive G: | 7,46 Gb Total Space | 7,46 Gb Free Space | 100,00% Space Free | Partition Type: FAT32 Computer Name: LIFOUS-PC | User Name: lifous | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011-08-22 15:27:01 | 000,580,096 | ---- | M] (OldTimer Tools) -- D:\DOWNLOAD\OTL.exe PRC - [2011-08-22 03:57:28 | 001,006,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe PRC - [2011-08-22 03:38:19 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2011-08-21 19:46:09 | 000,049,152 | RHS- | M] () -- C:\Users\lifous\cuebud.exe PRC - [2011-08-20 14:17:44 | 000,411,432 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe PRC - [2011-08-20 14:15:20 | 001,242,448 | ---- | M] (Valve Corporation) -- D:\Program files\Steam\Steam.exe PRC - [2011-08-04 00:58:44 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2011-08-02 09:33:30 | 004,910,912 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe PRC - [2011-08-02 09:33:22 | 002,998,592 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe PRC - [2011-07-04 19:45:30 | 013,374,048 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe PRC - [2010-07-22 14:18:08 | 002,636,800 | ---- | M] () -- C:\Program Files\OSCAR Editor X7\OscarEditor.exe PRC - [2009-12-06 17:13:14 | 000,397,312 | R--- | M] () -- C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe PRC - [2009-11-02 03:33:26 | 000,651,264 | R--- | M] (AVerMedia TECHNOLOGIES, Inc.) -- C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe PRC - [2009-10-30 10:48:42 | 000,348,160 | R--- | M] (AVerMedia) -- C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe PRC - [2009-07-31 13:06:24 | 000,155,648 | R--- | M] () -- C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe PRC - [2008-02-13 07:52:10 | 004,915,200 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2007-11-26 14:54:22 | 001,629,480 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe PRC - [2007-11-26 14:54:12 | 001,554,728 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe PRC - [2007-11-26 14:54:02 | 001,057,064 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\InCD\InCD.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2011-08-21 19:46:09 | 000,049,152 | RHS- | M] () -- C:\Users\lifous\cuebud.exe MOD - [2011-08-20 14:17:44 | 014,401,832 | ---- | M] () -- D:\Program files\Steam\bin\libcef.dll MOD - [2011-08-20 14:17:43 | 000,914,216 | ---- | M] () -- D:\Program files\Steam\bin\avcodec-52.dll MOD - [2011-08-20 14:17:43 | 000,190,248 | ---- | M] () -- D:\Program files\Steam\bin\chromehtml.dll MOD - [2011-08-20 14:17:43 | 000,155,432 | ---- | M] () -- D:\Program files\Steam\bin\avformat-52.dll MOD - [2011-08-20 14:17:43 | 000,091,432 | ---- | M] () -- D:\Program files\Steam\bin\avutil-50.dll MOD - [2011-08-20 13:55:00 | 006,277,280 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll MOD - [2011-08-04 00:58:45 | 001,000,920 | ---- | M] () -- C:\Program Files\Mozilla Firefox\js3250.dll MOD - [2011-07-04 19:46:20 | 000,217,696 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\gglog.dll MOD - [2011-07-04 19:46:18 | 000,123,488 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggipcradioproxy.dll MOD - [2011-07-04 19:46:16 | 000,017,504 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggipc.dll MOD - [2011-07-04 19:46:12 | 000,027,744 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggcrypto.dll MOD - [2011-07-04 19:46:10 | 000,356,960 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggcommon.dll MOD - [2011-04-16 05:04:30 | 014,749,696 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtWebKit4.dll MOD - [2011-02-17 11:00:28 | 001,781,760 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtScript4.dll MOD - [2011-02-17 11:00:28 | 000,393,216 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtXml4.dll MOD - [2011-02-17 11:00:28 | 000,327,680 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtSvg4.dll MOD - [2011-02-17 11:00:26 | 001,044,480 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtNetwork4.dll MOD - [2011-02-17 11:00:24 | 009,097,216 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtGui4.dll MOD - [2011-02-17 11:00:24 | 002,560,000 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtCore4.dll MOD - [2011-02-17 10:59:40 | 000,311,296 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qtiff4.dll MOD - [2011-02-17 10:59:40 | 000,274,432 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qmng4.dll MOD - [2011-02-17 10:59:40 | 000,143,360 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qjpeg4.dll MOD - [2011-02-17 10:59:40 | 000,027,648 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qgif4.dll MOD - [2011-02-17 10:59:40 | 000,018,944 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qsvg4.dll MOD - [2011-02-17 10:59:32 | 000,059,904 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\zlib1.dll MOD - [2010-07-22 14:18:08 | 002,636,800 | ---- | M] () -- C:\Program Files\OSCAR Editor X7\OscarEditor.exe MOD - [2010-06-01 11:41:38 | 000,098,816 | ---- | M] () -- C:\Program Files\OSCAR Editor X7\dll\DLL_MouseDeviceManager.dll MOD - [2010-05-07 23:05:57 | 000,042,496 | ---- | M] () -- C:\Program Files\OSCAR Editor X7\Data\X7\Forms\OSD_Text\OSD_Text.dll MOD - [2010-04-03 11:37:14 | 000,127,488 | ---- | M] () -- C:\Program Files\OSCAR Editor X7\dll\DLL_Wheel4D.dll MOD - [2010-04-03 11:37:09 | 000,094,208 | ---- | M] () -- C:\Program Files\OSCAR Editor X7\dll\DLL_ZoomControl.dll MOD - [2010-04-03 11:37:07 | 000,062,976 | ---- | M] () -- C:\Program Files\OSCAR Editor X7\dll\DLL_ScrollbarControl.dll MOD - [2010-04-03 11:37:02 | 000,069,632 | ---- | M] () -- C:\Program Files\OSCAR Editor X7\dll\DLL_AnalyzeGesturesInRight.dll MOD - [2010-04-03 11:36:58 | 000,069,632 | ---- | M] () -- C:\Program Files\OSCAR Editor X7\dll\DLL_AnalyzeGesturesInOne.dll MOD - [2009-07-31 13:06:24 | 000,155,648 | R--- | M] () -- C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2011-08-22 03:57:27 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2011-08-20 14:17:44 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2009-12-06 17:13:14 | 000,397,312 | R--- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe -- (AVerScheduleService) SRV - [2009-10-30 10:48:42 | 000,348,160 | R--- | M] (AVerMedia) [Auto | Running] -- C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe -- (AVerRemote) SRV - [2007-11-26 14:54:12 | 001,554,728 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe -- (InCDsrv) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2011-08-22 10:21:47 | 000,232,512 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2009-11-18 06:50:12 | 001,171,328 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVerA706.sys -- (AVerA706) DRV - [2008-08-02 12:20:00 | 007,314,528 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2008-02-14 08:56:02 | 000,118,784 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2007-11-26 14:54:12 | 000,038,440 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\InCDRm.sys -- (incdrm) DRV - [2007-11-26 14:54:12 | 000,036,776 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\InCDPass.sys -- (InCDPass) DRV - [2007-11-26 14:54:02 | 000,118,952 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\Windows\System32\drivers\InCDfs.sys -- (InCDfs) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.) IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.pl/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultthis.engineName: " " FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.selectedEngine: " " FF - prefs.js..browser.startup.homepage: "http://google.pl/" FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.5.0.12 FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=" FF - prefs.js..network.proxy.type: 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-08-20 13:40:22 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-08-22 10:26:22 | 000,000,000 | ---D | M] [2011-08-20 13:41:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lifous\AppData\Roaming\mozilla\Extensions [2011-08-22 15:08:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lifous\AppData\Roaming\mozilla\Firefox\Profiles\9yx61z1i.default\extensions [2011-08-21 23:27:23 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\lifous\AppData\Roaming\mozilla\Firefox\Profiles\9yx61z1i.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} [2011-08-21 23:27:23 | 000,000,863 | ---- | M] () -- C:\Users\lifous\AppData\Roaming\Mozilla\Firefox\Profiles\9yx61z1i.default\searchplugins\conduit.xml [2011-08-20 13:40:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011-08-04 00:14:15 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2011-08-04 00:14:15 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2011-08-04 00:14:15 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2011-08-04 00:14:15 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2011-08-04 00:14:15 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2011-08-04 00:14:15 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2006-09-18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.) O4 - HKLM..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [cuebud] C:\Users\lifous\cuebud.exe () O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKCU..\Run: [OscarEditor] C:\Program Files\OSCAR Editor X7\OscarEditor.exe () O4 - HKCU..\Run: [Steam] D:\Program files\Steam\steam.exe (Valve Corporation) O4 - HKLM..\RunOnce: [] File not found O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.199.225.14 82.160.1.1 O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\lifous\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O24 - Desktop BackupWallPaper: C:\Users\lifous\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2007-08-14 02:30:58 | 000,402,696 | R--- | M] (Electronic Arts) - F:\AutoRun.exe -- [ CDFS ] O32 - AutoRun File - [2007-09-02 06:55:55 | 000,000,000 | ---D | M] - F:\Autorun -- [ CDFS ] O32 - AutoRun File - [2007-09-02 06:56:15 | 002,984,960 | R--- | M] () - F:\autorun.dat -- [ CDFS ] O32 - AutoRun File - [2007-09-02 06:50:18 | 000,000,136 | R--- | M] () - F:\autorun.inf -- [ CDFS ] O32 - Unable to obtain root file information for disk G:\ O33 - MountPoints2\{9635a045-cc94-11e0-b2c3-001d92fbe5ed}\Shell - "" = AutoRun O33 - MountPoints2\{9635a045-cc94-11e0-b2c3-001d92fbe5ed}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2007-08-14 02:30:58 | 000,402,696 | R--- | M] (Electronic Arts) O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011-08-22 15:02:24 | 000,000,000 | ---D | C] -- C:\UsbFix [2011-08-22 10:29:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Sports [2011-08-22 10:21:47 | 000,232,512 | ---- | C] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys [2011-08-22 10:21:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite [2011-08-22 10:21:42 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite [2011-08-22 10:21:27 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\DAEMON Tools Lite [2011-08-22 10:20:33 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite [2011-08-21 23:27:23 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Local\Google [2011-08-21 23:27:22 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit [2011-08-21 23:27:21 | 000,000,000 | ---D | C] -- C:\Program Files\ConduitEngine [2011-08-21 23:27:20 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrentBar [2011-08-21 23:27:20 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Local\Conduit [2011-08-21 23:27:01 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent [2011-08-21 23:26:36 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\uTorrent [2011-08-21 23:26:36 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Local\uTorrent [2011-08-21 18:43:59 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\DivX [2011-08-21 18:29:35 | 000,000,000 | ---D | C] -- C:\Users\lifous\Desktop\Lubelski 4FUN [2011-08-21 13:37:01 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\Tibia [2011-08-21 13:26:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Asprate [2011-08-21 13:25:41 | 000,000,000 | ---D | C] -- C:\Windows\System32\custom matrices [2011-08-21 13:25:40 | 000,000,000 | ---D | C] -- C:\Windows\System32\QuickTime [2011-08-21 13:25:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cole2k Media - Codec Pack [2011-08-21 13:25:40 | 000,000,000 | ---D | C] -- C:\Windows\System32\C2MP [2011-08-21 13:24:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tibia 8.60 [2011-08-20 18:10:33 | 000,000,000 | ---D | C] -- C:\Users\lifous\Documents\AVerTV [2011-08-20 17:32:00 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\SFBot [2011-08-20 17:28:22 | 000,000,000 | ---D | C] -- C:\Users\lifous\Desktop\sf [2011-08-20 15:21:52 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\WinRAR [2011-08-20 15:21:52 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [2011-08-20 15:21:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [2011-08-20 15:21:50 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR [2011-08-20 14:21:13 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam [2011-08-20 14:14:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam [2011-08-20 14:14:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam [2011-08-20 13:59:10 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\Gadu-Gadu 10 [2011-08-20 13:57:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Gadu-Gadu 10 [2011-08-20 13:57:03 | 000,000,000 | ---D | C] -- C:\Program Files\Gadu-Gadu 10 [2011-08-20 13:53:00 | 000,000,000 | ---D | C] -- C:\ProgramData\SnugTV [2011-08-20 13:52:57 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA [2011-08-20 13:48:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A4TECH Software [2011-08-20 13:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\OSCAR Editor X7 [2011-08-20 13:48:03 | 000,000,000 | ---D | C] -- C:\Program Files\OscarX7 [2011-08-20 13:46:31 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Local\Adobe [2011-08-20 13:46:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe [2011-08-20 13:46:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2011-08-20 13:46:14 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2011-08-20 13:45:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SnugTV [2011-08-20 13:45:28 | 000,000,000 | ---D | C] -- C:\Program Files\SnugTV [2011-08-20 13:45:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SnugTV [2011-08-20 13:45:16 | 000,000,000 | ---D | C] -- C:\ProgramData\AVerTV [2011-08-20 13:45:10 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Local\AVerMedia [2011-08-20 13:45:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVerMedia [2011-08-20 13:44:46 | 000,102,400 | R--- | C] (AVerMedia Technologies, Inc.) -- C:\Windows\System32\CardID.dll [2011-08-20 13:44:41 | 000,045,056 | R--- | C] (Open Source Software community project) -- C:\Windows\System32\pthreadVC.dll [2011-08-20 13:44:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVerMedia [2011-08-20 13:43:54 | 000,000,000 | ---D | C] -- C:\Windows\Driver Cache [2011-08-20 13:43:53 | 000,000,000 | ---D | C] -- C:\Program Files\AVerMedia [2011-08-20 13:40:44 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Local\Mozilla [2011-08-20 13:40:43 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\Mozilla [2011-08-20 13:40:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox [2011-08-20 13:40:20 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2011-08-20 13:39:53 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Local\Ahead [2011-08-20 13:39:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Essentials [2011-08-20 13:38:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Ahead [2011-08-20 13:36:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Nero [2011-08-20 13:36:37 | 000,000,000 | ---D | C] -- C:\Program Files\Nero [2011-08-20 13:36:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Ahead [2011-08-20 13:36:05 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\Macromedia [2011-08-20 13:35:11 | 000,000,000 | -HSD | C] -- C:\Windows\Installer [2011-08-20 13:33:59 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\Adobe [2011-08-20 13:33:47 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed [2011-08-20 13:30:15 | 000,000,000 | ---D | C] -- C:\Program Files\Intel [2011-08-20 13:30:10 | 000,000,000 | ---D | C] -- C:\Intel [2011-08-20 13:29:42 | 000,118,784 | ---- | C] (Realtek Corporation ) -- C:\Windows\System32\drivers\Rtlh86.sys [2011-08-20 13:29:28 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\InstallShield [2011-08-20 13:29:10 | 000,098,304 | ---- | C] (Realtek Semiconductor) -- C:\Windows\RTKAUDIOSERVICE.EXE [2011-08-20 13:29:04 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM [2011-08-20 13:28:49 | 000,339,968 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll [2011-08-20 13:28:49 | 000,185,776 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll [2011-08-20 13:28:49 | 000,167,936 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll [2011-08-20 13:28:49 | 000,135,168 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll [2011-08-20 13:28:46 | 004,915,200 | ---- | C] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe [2011-08-20 13:28:45 | 000,126,976 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\maxxaudioapo.dll [2011-08-20 13:28:45 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek [2011-08-20 13:28:44 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information [2011-08-20 13:28:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield [2011-08-20 13:11:23 | 000,000,000 | R--D | C] -- C:\Users\lifous\Desktop\Documents [2011-08-20 13:10:22 | 000,000,000 | R--D | C] -- C:\Users\lifous\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup [2011-08-20 13:10:22 | 000,000,000 | R--D | C] -- C:\Users\lifous\Searches [2011-08-20 13:10:22 | 000,000,000 | R--D | C] -- C:\Users\lifous\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools [2011-08-20 13:10:14 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Roaming\Identities [2011-08-20 13:10:13 | 000,000,000 | R--D | C] -- C:\Users\lifous\Contacts [2011-08-20 13:10:13 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Local\VirtualStore [2011-08-20 13:10:10 | 000,000,000 | --SD | C] -- C:\Users\lifous\AppData\Roaming\Microsoft [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\Videos [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\Saved Games [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\Pictures [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\Music [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\Links [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\Favorites [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\Downloads [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\Documents [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\Desktop [2011-08-20 13:10:10 | 000,000,000 | R--D | C] -- C:\Users\lifous\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\Ustawienia lokalne [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\AppData\Local\Temporary Internet Files [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\Szablony [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\SendTo [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\Recent [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\PrintHood [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\NetHood [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\Documents\Moje wideo [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\Documents\Moje obrazy [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\Moje dokumenty [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\Documents\Moja muzyka [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\Menu Start [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\AppData\Local\Historia [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\Dane aplikacji [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\AppData\Local\Dane aplikacji [2011-08-20 13:10:10 | 000,000,000 | -HSD | C] -- C:\Users\lifous\Cookies [2011-08-20 13:10:10 | 000,000,000 | -H-D | C] -- C:\Users\lifous\AppData [2011-08-20 13:10:10 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Local\Temp [2011-08-20 13:10:10 | 000,000,000 | ---D | C] -- C:\Users\lifous\AppData\Local\Microsoft [2011-08-20 13:08:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Ulubione [2011-08-20 13:08:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Szablony [2011-08-20 13:08:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Pulpit [2011-08-20 13:08:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje wideo [2011-08-20 13:08:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moje obrazy [2011-08-20 13:08:37 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Moja muzyka [2011-08-20 13:08:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Start [2011-08-20 13:08:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenty [2011-08-20 13:08:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dane aplikacji [2011-08-20 12:55:11 | 000,000,000 | ---D | C] -- C:\Windows\Panther [2011-08-20 12:54:57 | 000,000,000 | -HSD | C] -- C:\Boot [2011-08-20 12:03:18 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution [2011-08-20 12:02:15 | 000,000,000 | ---D | C] -- C:\Windows\System32\catroot2 [2011-08-20 12:02:05 | 000,000,000 | ---D | C] -- C:\Windows\Debug [2011-08-20 12:00:59 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch [2011-08-20 12:00:50 | 000,000,000 | -HSD | C] -- C:\System Volume Information [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011-08-22 16:23:19 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011-08-22 16:23:19 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011-08-22 16:23:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011-08-22 16:23:10 | 3220,430,848 | -HS- | M] () -- C:\hiberfil.sys [2011-08-22 15:48:52 | 000,609,944 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011-08-22 15:48:52 | 000,535,330 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2011-08-22 15:48:52 | 000,086,210 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2011-08-22 15:48:51 | 000,103,726 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011-08-22 10:29:24 | 000,001,663 | ---- | M] () -- C:\Users\Public\Desktop\FIFA 08.lnk [2011-08-22 10:21:47 | 000,232,512 | ---- | M] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys [2011-08-22 10:21:44 | 000,001,735 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk [2011-08-22 09:59:50 | 000,231,984 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011-08-22 04:07:41 | 000,001,820 | ---- | M] () -- C:\Windows\System32\rasctrnm.h [2011-08-22 04:02:41 | 001,657,350 | ---- | M] () -- C:\Windows\System32\wlan.tmf [2011-08-22 03:23:14 | 021,299,200 | ---- | M] () -- C:\Windows\ocsetup_install_NetFx3.etl [2011-08-22 03:23:14 | 000,196,608 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_NetFx3.perf [2011-08-22 03:23:14 | 000,065,536 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_NetFx3.dpx [2011-08-21 23:27:01 | 000,000,752 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk [2011-08-21 19:46:09 | 000,049,152 | RHS- | M] () -- C:\Users\lifous\cuebud.exe [2011-08-21 19:23:28 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\UMDF\Msft_User_WpdFs_01_00_00.Wdf [2011-08-21 13:26:00 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\Tibia MULTI-IP Changer.lnk [2011-08-21 13:24:47 | 000,000,627 | ---- | M] () -- C:\Users\Public\Desktop\Tibia.lnk [2011-08-20 15:16:11 | 000,000,213 | ---- | M] () -- C:\Users\lifous\Desktop\Counter-Strike Source.url [2011-08-20 14:21:13 | 000,000,212 | ---- | M] () -- C:\Users\lifous\Desktop\Counter-Strike.url [2011-08-20 14:14:42 | 000,000,624 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk [2011-08-20 13:45:29 | 000,001,960 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SnugTV Quick Start.lnk [2011-08-20 13:45:06 | 000,002,081 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVer HID Receiver.lnk [2011-08-20 13:45:06 | 000,002,039 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVerQuick.lnk [2011-08-20 13:45:06 | 000,001,788 | ---- | M] () -- C:\Users\Public\Desktop\AVerTV 6.lnk [2011-08-20 13:11:08 | 000,000,680 | ---- | M] () -- C:\Users\lifous\AppData\Local\d3d9caps.dat [2011-08-20 12:54:58 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK [2011-08-20 12:04:09 | 000,065,369 | ---- | M] () -- C:\Windows\System32\license.rtf [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011-08-22 10:29:24 | 000,001,663 | ---- | C] () -- C:\Users\Public\Desktop\FIFA 08.lnk [2011-08-22 10:21:44 | 000,001,735 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk [2011-08-22 04:07:41 | 000,001,820 | ---- | C] () -- C:\Windows\System32\rasctrnm.h [2011-08-22 04:02:41 | 001,657,350 | ---- | C] () -- C:\Windows\System32\wlan.tmf [2011-08-22 03:18:56 | 000,196,608 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_NetFx3.perf [2011-08-22 03:18:56 | 000,065,536 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_NetFx3.dpx [2011-08-22 03:18:55 | 021,299,200 | ---- | C] () -- C:\Windows\ocsetup_install_NetFx3.etl [2011-08-21 23:27:01 | 000,000,752 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk [2011-08-21 19:46:09 | 000,049,152 | RHS- | C] () -- C:\Users\lifous\cuebud.exe [2011-08-21 13:26:00 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\Tibia MULTI-IP Changer.lnk [2011-08-21 13:24:47 | 000,000,627 | ---- | C] () -- C:\Users\Public\Desktop\Tibia.lnk [2011-08-20 15:16:11 | 000,000,213 | ---- | C] () -- C:\Users\lifous\Desktop\Counter-Strike Source.url [2011-08-20 14:21:13 | 000,000,212 | ---- | C] () -- C:\Users\lifous\Desktop\Counter-Strike.url [2011-08-20 14:14:42 | 000,000,624 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk [2011-08-20 13:57:03 | 000,000,808 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gadu-Gadu 10.lnk [2011-08-20 13:46:22 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 8.lnk [2011-08-20 13:45:29 | 000,001,960 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SnugTV Quick Start.lnk [2011-08-20 13:45:06 | 000,002,081 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVer HID Receiver.lnk [2011-08-20 13:45:06 | 000,002,039 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVerQuick.lnk [2011-08-20 13:45:06 | 000,001,788 | ---- | C] () -- C:\Users\Public\Desktop\AVerTV 6.lnk [2011-08-20 13:44:46 | 000,049,152 | R--- | C] () -- C:\Windows\System32\AVerIO.dll [2011-08-20 13:44:46 | 000,003,456 | R--- | C] () -- C:\Windows\System32\AVerIO.sys [2011-08-20 13:44:41 | 000,598,016 | R--- | C] () -- C:\Windows\System32\sptlib21.dll [2011-08-20 13:44:41 | 000,311,296 | R--- | C] () -- C:\Windows\System32\sptlib01.dll [2011-08-20 13:44:41 | 000,294,912 | R--- | C] () -- C:\Windows\System32\sptlib11.dll [2011-08-20 13:44:41 | 000,290,816 | R--- | C] () -- C:\Windows\System32\sptlib22.dll [2011-08-20 13:44:41 | 000,249,856 | R--- | C] () -- C:\Windows\System32\sptlib03.dll [2011-08-20 13:44:41 | 000,225,280 | R--- | C] () -- C:\Windows\System32\sptlib02.dll [2011-08-20 13:44:41 | 000,135,168 | R--- | C] () -- C:\Windows\System32\sptlib12.dll [2011-08-20 13:29:22 | 000,000,553 | R--- | C] () -- C:\Windows\USetup.iss [2011-08-20 13:14:05 | 000,008,664 | ---- | C] () -- C:\Windows\System32\nvdisp.nvu [2011-08-20 13:10:23 | 000,000,949 | ---- | C] () -- C:\Users\lifous\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [2011-08-20 13:10:22 | 000,000,944 | ---- | C] () -- C:\Users\lifous\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk [2011-08-20 13:10:13 | 000,000,915 | ---- | C] () -- C:\Users\lifous\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk [2011-08-20 13:10:11 | 000,000,680 | ---- | C] () -- C:\Users\lifous\AppData\Local\d3d9caps.dat [2011-08-20 13:07:08 | 3220,430,848 | -HS- | C] () -- C:\hiberfil.sys [2011-08-20 12:54:58 | 000,008,192 | R-S- | C] () -- C:\BOOTSECT.BAK [2011-08-20 12:54:57 | 000,438,840 | RHS- | C] () -- C:\bootmgr [2011-08-20 12:04:03 | 000,000,604 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live.lnk [2011-03-03 13:40:08 | 000,150,528 | ---- | C] () -- C:\Windows\System32\mkx.dll [2011-03-03 13:39:56 | 000,109,568 | ---- | C] () -- C:\Windows\System32\avi.dll [2011-03-03 13:39:46 | 000,141,824 | ---- | C] () -- C:\Windows\System32\mp4.dll [2011-03-03 13:39:34 | 000,123,392 | ---- | C] () -- C:\Windows\System32\ogm.dll [2011-03-03 13:39:02 | 000,113,152 | ---- | C] () -- C:\Windows\System32\dsmux.exe [2011-03-03 13:38:54 | 000,154,112 | ---- | C] () -- C:\Windows\System32\ts.dll [2011-03-03 13:38:40 | 000,249,856 | ---- | C] () -- C:\Windows\System32\dxr.dll [2011-03-03 13:38:10 | 000,097,792 | ---- | C] () -- C:\Windows\System32\avs.dll [2011-03-03 13:38:04 | 000,137,728 | ---- | C] () -- C:\Windows\System32\mkv2vfr.exe [2011-03-03 13:37:50 | 000,093,184 | ---- | C] () -- C:\Windows\System32\avss.dll [2011-03-03 13:37:40 | 000,358,400 | ---- | C] () -- C:\Windows\System32\gdsmux.exe [2011-03-03 13:35:32 | 000,080,384 | ---- | C] () -- C:\Windows\System32\mkzlib.dll [2011-03-03 13:35:26 | 000,024,576 | ---- | C] () -- C:\Windows\System32\mkunicode.dll [2011-02-22 21:39:04 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2011-02-07 20:00:08 | 001,529,856 | ---- | C] () -- C:\Windows\System32\ff_samplerate.dll [2011-02-07 20:00:08 | 000,925,667 | ---- | C] () -- C:\Windows\System32\ffmpegmt.dll [2011-02-07 20:00:08 | 000,721,798 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2011-02-07 20:00:08 | 000,336,384 | ---- | C] () -- C:\Windows\System32\ff_libfaad2.dll [2011-02-07 20:00:08 | 000,324,096 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll [2011-02-07 20:00:08 | 000,216,576 | ---- | C] () -- C:\Windows\System32\ff_libdts.dll [2011-02-07 20:00:08 | 000,151,552 | ---- | C] () -- C:\Windows\System32\ff_libmad.dll [2011-02-07 20:00:08 | 000,145,408 | ---- | C] () -- C:\Windows\System32\libmpeg2_ff.dll [2011-02-07 20:00:08 | 000,140,800 | ---- | C] () -- C:\Windows\System32\ff_unrar.dll [2011-02-07 20:00:08 | 000,121,856 | ---- | C] () -- C:\Windows\System32\ff_liba52.dll [2011-02-07 20:00:08 | 000,100,864 | ---- | C] () -- C:\Windows\System32\ff_wmv9.dll [2011-02-07 20:00:08 | 000,065,024 | ---- | C] () -- C:\Windows\System32\FLT_ffdshow.dll [2011-02-07 19:45:52 | 000,080,896 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2011-02-07 19:39:02 | 004,166,551 | ---- | C] () -- C:\Windows\System32\ffmpeg.dll [2010-08-18 21:56:38 | 000,000,151 | ---- | C] () -- C:\Windows\System32\Registration.ini [2009-08-11 23:21:26 | 000,087,552 | ---- | C] () -- C:\Windows\System32\ac3config.exe [2009-08-11 23:21:20 | 001,021,440 | ---- | C] () -- C:\Windows\System32\ac3filter_intl.dll [2008-11-06 17:37:32 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll [2007-04-02 05:44:44 | 000,003,072 | ---- | C] () -- C:\Windows\System32\34CoInstaller.dll [2006-12-05 07:19:18 | 000,535,330 | ---- | C] () -- C:\Windows\System32\perfh015.dat [2006-12-05 07:19:18 | 000,332,832 | ---- | C] () -- C:\Windows\System32\perfi015.dat [2006-12-05 07:19:18 | 000,086,210 | ---- | C] () -- C:\Windows\System32\perfc015.dat [2006-12-05 07:19:18 | 000,037,468 | ---- | C] () -- C:\Windows\System32\perfd015.dat [2006-11-02 14:53:49 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006-11-02 14:44:53 | 000,231,984 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006-11-02 12:33:01 | 000,609,944 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006-11-02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006-11-02 12:33:01 | 000,103,726 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006-11-02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006-11-02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006-11-02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006-11-02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006-11-02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006-11-02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2006-11-02 09:22:43 | 000,099,999 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2006-11-02 09:22:43 | 000,018,271 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2006-03-04 06:52:00 | 000,088,576 | ---- | C] () -- C:\Windows\System32\OptimFROG.dll [color=#E56717]========== LOP Check ==========[/color] [2011-08-22 10:23:26 | 000,000,000 | ---D | M] -- C:\Users\lifous\AppData\Roaming\DAEMON Tools Lite [2011-08-20 15:25:46 | 000,000,000 | ---D | M] -- C:\Users\lifous\AppData\Roaming\Gadu-Gadu 10 [2011-08-20 17:32:00 | 000,000,000 | ---D | M] -- C:\Users\lifous\AppData\Roaming\SFBot [2011-08-21 13:41:32 | 000,000,000 | ---D | M] -- C:\Users\lifous\AppData\Roaming\Tibia [2011-08-22 15:31:34 | 000,000,000 | ---D | M] -- C:\Users\lifous\AppData\Roaming\uTorrent [2011-08-22 16:22:16 | 000,003,918 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [color=#E56717]========== Purity Check ==========[/color] < End of report > [/code]
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 [quote]i zaraz zaczne zaznaczac tamto [/quote] no czekam, czekam tylko wstaw logi na wklej.org albo wklejto. żeby bałaganu nie było
lifous komentarz 22 sierpnia 2011 Autor komentarz 22 sierpnia 2011 Extras.txt http://wklejto.pl/103512 OTL.Txt http://wklejto.pl/103513
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 W OTL wklej skrypt: [code]:Files PRC - [2011-08-21 19:46:09 | 000,049,152 | RHS- | M] () -- C:\Users\lifous\cuebud.exe O4 - HKCU..\Run: [cuebud] C:\Users\lifous\cuebud.exe () O4 - HKLM..\RunOnce: [] File not found :Commands [emptyflash] [emptytemp][/code] Klikasz wykonaj skrypt. Powstanie z tego nowy log. Dajesz go do posta. Do odinstalowania z panelu Dodaj Usuń nastepujące śmieci: [b]1.ConduitEngine 2.uTorrentBar Toolbar [/b]jak to wykonasz wstawiasz nowe logi - tylko nie do posta a na[b] wklejto. [/b]Potem przejdziemy do czynności końcowych[b] [/b]
lifous komentarz 22 sierpnia 2011 Autor komentarz 22 sierpnia 2011 (edytowane) http://wklejto.pl/103522 - log po wgraniu tego skryptu. ps: jakie nowe logi.? ps: usunelem te 2 pliiki z dodaj usuń.
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 [quote]ps: jakie nowe logi.? [/quote] Daj mi log z skanowania OTL wg. ustawień które podałem. Czy foldery są juz widoczne normalnie na dysku przenośnym?
lifous komentarz 22 sierpnia 2011 Autor komentarz 22 sierpnia 2011 (edytowane) Nadal nie działają.. Już skanuje, dam edit jak coś. http://wklejto.pl/103526
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 Powtórz skrypt w OTL [code]:OTL MOD - [2011-08-21 19:46:09 | 000,049,152 | RHS- | M] () -- C:\Users\lifous\cuebud.exe O4 - HKCU..\Run: [cuebud] C:\Users\lifous\cuebud.exe () :Commands [emptyflash] [emptytemp][/code] Po wykonaniu powinien powstać log. Daj go do posta. Wykonaj potem jeszcze skanowanie USBfix i wstaw log
lifous komentarz 22 sierpnia 2011 Autor komentarz 22 sierpnia 2011 Log po wgraniu skryptu: [code] All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\cuebud deleted successfully. C:\Users\lifous\cuebud.exe moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User: Default User User: lifous ->Flash cache emptied: 765 bytes User: Public User: user Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: lifous ->Temp folder emptied: 8672704 bytes ->Temporary Internet Files folder emptied: 174932 bytes ->FireFox cache emptied: 59540683 bytes ->Flash cache emptied: 0 bytes User: Public User: user %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 15372 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 65,00 mb OTL by OldTimer - Version 3.2.26.5 log created on 08222011_174322 Files\Folders moved on Reboot... Registry entries deleted on Reboot... [/code] a gdzie jest skanowanie w usbfix?
Gość komentarz 22 sierpnia 2011 komentarz 22 sierpnia 2011 [quote]a gdzie jest skanowanie w usbfix? [/quote] opcja listing, to co juz robiłeś widze że teraz dziadostwo się usunęlo. Potrzebny mi log z[b] USBfix[/b] żeby powtórzyć ewentualne czyszczenie pendraka
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.