main.txt: Deckard’s System Scanner v20071014.68 Run by Komputer on 2007-12-12 08:51:39 Computer is in Safe Mode with Networking. -------------------------------------------------------------------------------- – System Restore -------------------------------------------------------------- Failed to create restore point; computer is in safe mode. – Last 5 Restore Point(s) – 70: 2007-12-10 21:30:55 UTC - RP282 - Software Distribution Service 3.0 69: 2007-12-10 21:10:53 UTC - RP281 - Punkt kontrolny systemu 68: 2007-12-09 10:24:01 UTC - RP280 - Punkt kontrolny systemu 67: 2007-12-07 21:55:25 UTC - RP279 - Punkt kontrolny systemu 66: 2007-12-05 19:22:45 UTC - RP278 - Punkt kontrolny systemu – First Restore Point – 1: 2007-10-23 16:58:44 UTC - RP213 - Punkt kontrolny systemu Backed up registry hives. Performed disk cleanup. – HijackThis (run as Komputer.exe) -------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 08:52:21, on 2007-12-12 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\Komputer\Pulpit\dss.exe C:\DOCUME~1\Komputer\Pulpit\CZYSZC~1\Komputer.exe C:\WINDOWS\system32\NOTEPAD.EXE R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O4 - HKLM…\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM…\Run: [skyTel] SkyTel.EXE O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” O4 - HKLM…\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM…\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU…\Run: [Gadu-Gadu] “C:\Program Files\Gadu-Gadu\gg.exe” /tray O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk = ? O17 - HKLM\System\CCS\Services\Tcpip…{09C5EDCC-DA17-47F2-8313-E7A7D1D64908}: NameServer = 194.204.152.34,194.204.159.1 O17 - HKLM\System\CS1\Services\Tcpip…{09C5EDCC-DA17-47F2-8313-E7A7D1D64908}: NameServer = 194.204.152.34,194.204.159.1 O17 - HKLM\System\CS2\Services\Tcpip…{09C5EDCC-DA17-47F2-8313-E7A7D1D64908}: NameServer = 194.204.152.34,194.204.159.1 O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe – HijackThis Fixed Entries (C:\DOCUME~1\Komputer\Pulpit\CZYSZC~1\backups) ---- backup-20070713-010937-813 O4 - HKLM…\Run: [Alcmtr] ALCMTR.EXE backup-20070715-013456-193 O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) backup-20070715-013456-205 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) backup-20070715-013456-480 O11 - Options group: [iNTERNATIONAL] International* backup-20070730-125011-779 O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) backup-20070730-125011-957 O4 - HKCU…\Run: [bitTorrent] “C:\Program Files\BitTorrent\bittorrent.exe” --force_start_minimized backup-20070730-125011-999 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) backup-20070730-131248-759 O4 - HKLM…\Run: [nwiz] nwiz.exe /install backup-20070730-131308-529 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll backup-20070822-014903-611 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ backup-20070831-223246-882 O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe backup-20070906-190316-242 O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup backup-20070906-190316-272 O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe backup-20070906-190316-405 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe backup-20070906-190316-737 O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL backup-20070906-190316-877 O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit backup-20070906-190316-909 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll backup-20070906-190317-679 O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe backup-20070906-190317-984 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll backup-20070909-111337-591 O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 backup-20070909-111337-676 O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) backup-20070909-111337-812 O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe backup-20070909-111337-987 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) backup-20070921-190505-275 O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup backup-20070927-140557-717 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s … wflash.cab backup-20070927-140557-937 O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup backup-20070927-141100-147 O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup backup-20070927-141939-131 O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup backup-20070927-141940-199 O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe backup-20070927-141940-242 O17 - HKLM\System\CCS\Services\Tcpip…{FFEE40FF-2459-4A48-A7C7-408FD0C0C0AE}: NameServer = 194.204.159.1 217.98.63.164 backup-20070927-141940-253 O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe backup-20070927-141940-331 O17 - HKLM\System\CS1\Services\Tcpip…{09C5EDCC-DA17-47F2-8313-E7A7D1D64908}: NameServer = 194.204.152.34,194.204.159.1 backup-20070927-141940-427 O17 - HKLM\System\CCS\Services\Tcpip…{09C5EDCC-DA17-47F2-8313-E7A7D1D64908}: NameServer = 194.204.152.34,194.204.159.1 backup-20070927-141940-530 O17 - HKLM\System\CS2\Services\Tcpip…{09C5EDCC-DA17-47F2-8313-E7A7D1D64908}: NameServer = 194.204.152.34,194.204.159.1 backup-20071129-232048-467 O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup backup-20071129-232048-516 O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll backup-20071129-232048-653 O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe backup-20071129-232048-685 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll backup-20071129-232048-862 O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html backup-20071201-145427-729 O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe backup-20071201-151303-737 O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe backup-20071204-233132-243 O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll backup-20071204-233132-332 O4 - HKLM…\Run: [TkBellExe] “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot backup-20071204-233132-366 O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll backup-20071204-233132-428 O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll backup-20071204-233132-531 O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe backup-20071204-233132-784 O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll backup-20071212-083859-585 O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe backup-20071212-083859-790 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ – File Associations ----------------------------------------------------------- .cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL “%1”,%* .cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser “%1”,%* – Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R3 RTLE8023xp (Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver) - c:\windows\system32\drivers\rtenicxp.sys S3 CnxEtP (ZTE ZXDSL852 Adapter Filter Driver) - c:\windows\system32\drivers\cnxetp.sys (file missing) S3 CnxEtU (ZTE ZXDSL852 Interface Device Driver) - c:\windows\system32\drivers\cnxetu.sys (file missing) S3 CnxTgNW (ZTE ZXDSL852 WAN PPPoA Adapter Driver) - c:\windows\system32\drivers\cnxtgnw.sys (file missing) S3 GMSIPCI - e:\install\gmsipci.sys (file missing) S3 NTACCESS - e:\ntaccess.sys (file missing) S3 PCANDIS5 (PCANDIS5 Protocol Driver) - c:\windows\system32\pcandis5.sys (file missing) S3 SetupNTGLM7X - e:\ntglm7x.sys (file missing) S3 ZDCndis5 (ZDCndis5 Protocol Driver) - c:\windows\system32\zdcndis5.sys (file missing) S3 ZDPSp50 (ZDPSp50 NDIS Protocol Driver) - c:\windows\system32\drivers\zdpsp50.sys – Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- S2 StarWindServiceAE (StarWind AE Service) - c:\program files\alcohol soft\alcohol 120\starwind\starwindserviceae.exe S3 AresChatServer (Ares Chatroom server) - c:\program files\ares\chatserver.exe S4 FLEXnet Licensing Service - “c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe” – Device Manager: Disabled ---------------------------------------------------- No disabled devices found. – Files created between 2007-11-12 and 2007-12-12 ----------------------------- 2007-12-12 08:43:17 90112 --a------ C:\WINDOWS\system32\RegDACL.exe 2007-12-12 08:43:17 4096 --a------ C:\WINDOWS\system32\reboot.exe 2007-12-12 08:43:17 53248 --a------ C:\WINDOWS\system32\process.exe http://www.beyondlogic.org; Command Line Process Utility> 2007-12-12 08:43:17 136704 --a------ C:\WINDOWS\system32\catchme.exe 2007-12-12 08:43:17 347 --a------ C:\run2.reg 2007-12-12 08:43:17 8925 --a------ C:\clean.bat 2007-12-11 20:25:30 0 d-------- C:\Program Files\Hamachi 2007-12-09 09:07:48 0 d–hs---- C:\WINDOWS\CSC 2007-12-08 18:12:54 0 d-------- C:\WINDOWS\NV36922880.TMP 2007-12-08 18:10:08 0 d-------- C:\NVIDIA 2007-12-08 17:50:29 0 d-------- C:\Program Files\SystemRequirementsLab 2007-12-02 20:47:28 0 d-------- C:\Program Files\Medal of Honor Respev Edition 2007-12-02 11:49:32 0 d-------- C:\Program Files\Common Files\xing shared 2007-12-02 11:48:51 0 d-------- C:\Program Files\Common Files\Real 2007-12-02 11:48:45 0 d-------- C:\Program Files\Real 2007-12-02 11:47:19 0 d-------- C:\Program Files\QuickTime Alternative 2007-12-02 11:30:28 60273 --a------ C:\WINDOWS\system32\pthreadGC2.dll 2007-11-15 23:00:17 0 d-------- C:\Program Files\EA GAMES 2007-11-15 22:51:15 0 d-------- C:\Program Files\GameSpy Arcade 2007-11-14 21:40:04 0 d-------- C:\Program Files\Winamp Toolbar 2007-11-14 21:39:54 0 d-------- C:\Program Files\Winamp Remote 2007-11-14 21:35:19 0 d-------- C:\Program Files\Winamp 2007-11-13 09:44:01 0 d–h----- C:\WINDOWS\PIF – Find3M Report --------------------------------------------------------------- 2007-12-11 22:54:50 0 d-------- C:\Documents and Settings\Komputer\Dane aplikacji\Hamachi 2007-12-11 19:14:27 0 d-------- C:\Documents and Settings\Komputer\Dane aplikacji\DivX 2007-12-09 16:21:19 0 d-------- C:\Documents and Settings\Komputer\Dane aplikacji\Gadu-Gadu 2007-12-09 15:34:29 0 d-------- C:\Documents and Settings\Komputer\Dane aplikacji\SopCast 2007-12-09 10:01:35 0 d-------- C:\Program Files\IrfanView 2007-12-09 09:18:55 0 d-------- C:\Documents and Settings\Komputer\Dane aplikacji\Talkback 2007-12-09 09:11:59 0 d-------- C:\Documents and Settings\Komputer\Dane aplikacji\Identities 2007-12-07 21:19:57 0 d-------- C:\Documents and Settings\Komputer\Dane aplikacji\uTorrent 2007-12-02 11:49:44 0 d-------- C:\Documents and Settings\Komputer\Dane aplikacji\Real 2007-12-02 11:49:32 0 d-------- C:\Program Files\Common Files 2007-11-28 19:25:00 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-11-23 09:55:55 0 d-------- C:\Documents and Settings\Komputer\Dane aplikacji\Adobe 2007-11-15 23:14:45 0 d–h----- C:\Program Files\InstallShield Installation Information 2007-11-14 21:55:31 0 d-------- C:\Documents and Settings\Komputer\Dane aplikacji\Winamp 2007-11-13 09:45:49 25 --a------ C:\WINDOWS\Ya.com 2007-11-13 09:45:44 5610176 -r-hs---- C:\WINDOWS\himem.exe 2007-11-12 06:51:00 1626112 --a------ C:\WINDOWS\system32\nwiz.exe 2007-11-12 06:51:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll 2007-11-12 06:51:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll 2007-11-12 06:51:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll 2007-11-12 06:51:00 286720 --a------ C:\WINDOWS\system32\nvnt4cpl.dll 2007-11-12 06:51:00 1474560 --a------ C:\WINDOWS\system32\nview.dll 2007-11-12 06:51:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe 2007-11-12 06:51:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe 2007-11-12 06:51:00 425984 --a------ C:\WINDOWS\system32\keystone.exe 2007-11-01 18:27:37 0 d–h----- C:\Program Files\Zero G Registry 2007-11-01 18:23:35 0 d-------- C:\Program Files\DaemonTools_WhenUSave_Installer 2007-11-01 18:23:22 0 d-------- C:\Program Files\DAEMON Tools 2007-11-01 18:16:57 0 d-------- C:\Program Files\SlySoft 2007-11-01 18:16:08 229057 --a------ C:\WINDOWS\Alcohol_Toolbar_Uninstaller_3703.exe 2007-11-01 18:16:08 0 d-------- C:\Program Files\Alcohol Toolbar 2007-11-01 18:16:02 0 d-------- C:\Program Files\Alcohol Soft 2007-11-01 13:29:06 0 d-------- C:\Program Files\SAGEM WiFi manager 2007-11-01 13:28:37 0 d-------- C:\Program Files\SAGEM 2007-10-28 08:48:31 494652 --a------ C:\WINDOWS\system32\perfh015.dat 2007-10-28 08:48:31 87188 --a------ C:\WINDOWS\system32\perfc015.dat 2007-10-27 14:25:56 0 d-------- C:\Program Files\Java 2007-10-23 13:38:37 0 d-------- C:\Program Files\WinAVI Video Converter 2007-10-23 12:47:10 0 d-------- C:\Program Files\XviD 2007-10-23 12:45:00 0 d-------- C:\Program Files\AviSynth 2.5 2007-10-23 12:30:47 0 d-------- C:\Program Files\Rm To AVI VCD SVCD DVD MPEG Converter 2007-10-22 20:32:20 0 d-------- C:\Program Files\uTorrent 2007-10-20 19:40:22 0 d-------- C:\Program Files\Common Files\Adobe 2007-10-20 19:38:00 0 d-------- C:\Program Files\Common Files\Macrovision Shared 2007-10-19 16:59:26 0 d-------- C:\Program Files\Neat Image – Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}] 2007-10-04 21:06 1135968 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “RTHDCPL”=“RTHDCPL.EXE” [2006-07-21 09:56 C:\WINDOWS\RTHDCPL.exe] “SkyTel”=“SkyTel.EXE” [2006-05-16 11:04 C:\WINDOWS\SkyTel.exe] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 00:11] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 14:00] “MSConfig”=“C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe” [2005-09-28 19:13] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-07-22 20:23] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-03 23:44] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk - C:\Program Files\SAGEM WiFi manager\WLANUTL.exe [2007-11-01 13:29:05] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] “Authentication Packages”= msv1_0 nwprovau [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Komputer^Menu Start^Programy^Autostart^hamachi.lnk] path=C:\Documents and Settings\Komputer\Menu Start\Programy\Autostart\hamachi.lnk backup=C:\WINDOWS\pss\hamachi.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^user^Menu Start^Programy^Autostart^hamachi.lnk] path=C:\Documents and Settings\user\Menu Start\Programy\Autostart\hamachi.lnk backup=C:\WINDOWS\pss\hamachi.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares] “C:\Program Files\Ares\Ares.exe” -h [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] “C:\Program Files\BitTorrent\bittorrent.exe” --force_start_minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] “C:\Program Files\DAEMON Tools\daemon.exe” -lang 1033 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu] “C:\Program Files\Gadu-Gadu\gg.exe” /tray [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\himem] “c:\windows\himem.exe” 3fff 8ffff [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] nwiz.exe /install [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb] “C:\Program Files\Winamp Remote\bin\OrbTray.exe” /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] “C:\Program Files\Winamp\winampa.exe” *Newly Created Service* - CATCHME – End of Deckard’s System Scanner: finished at 2007-12-12 08:52:48 ------------ ComboScan extra.txt: Deckard’s System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- – System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 2.0 Architecture: X86; Language: Polish CPU 0: Genuine Intel® CPU 2140 @ 1.60GHz CPU 1: Genuine Intel® CPU 2140 @ 1.60GHz Percentage of Memory in Use: 26% Physical Memory (total/avail): 1023.48 MiB / 752.71 MiB Pagefile Memory (total/avail): 2463.93 MiB / 2327.29 MiB Virtual Memory (total/avail): 2047.88 MiB / 1928.21 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 76.08 GiB total, 30.75 GiB free. D: is Fixed (NTFS) - 72.97 GiB total, 14.94 GiB free. E: is CDROM (No Media) F: is CDROM (No Media) \.\PHYSICALDRIVE0 - WDC WD1600AAJS-98PSA0 - 149.05 GiB - 2 partitions \PARTITION0 (bootable) - Instalowalny system plików - 76.08 GiB - C: \PARTITION1 - Rozszerzona z rozszerzonym przerwaniem 13 - 72.97 GiB - D: – Security Center ------------------------------------------------------------- AUOptions is scheduled to auto-install. – Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Komputer\Dane aplikacji CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=USER-E3A55F7BE4 ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Komputer LOGONSERVER=\USER-E3A55F7BE4 NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 2, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0f02 ProgramFiles=C:\Program Files PROMPT=$P$G SAFEBOOT_OPTION=NETWORK SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\Komputer\USTAWI~1\Temp TMP=C:\DOCUME~1\Komputer\USTAWI~1\Temp USERDOMAIN=USER-E3A55F7BE4 USERNAME=Komputer USERPROFILE=C:\Documents and Settings\Komputer windir=C:\WINDOWS – User Profiles --------------------------------------------------------------- user (admin) Komputer (admin) Administrator (new local, admin) – Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{4E7DC12A-3597-4A94-9429-F6C6987361B1}\setup.exe” -l0x9 -removeonly --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{7DADB304-AF20-48C3-A780-4B4133A08817}\setup.exe” -l0x9 -removeonly --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}\setup.exe” -l0x9 -removeonly --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{ADEF1025-6D3B-485C-9AC9-1A2D81665B7F}\setup.exe” -l0x9 -removeonly --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}\setup.exe” -l0x9 -removeonly --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf @BIOS B06.0721.01 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}\Setup.exe” -l0x9 -removeonly Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95} Adobe Asset Services CS3 --> MsiExec.exe /I{6D12B99F-EAAA-49D8-8E2F-74FA7459CCB2} Adobe Bridge CS3 --> MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394} Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D} Adobe Photoshop CS3 --> C:\Program Files\Common Files\Adobe\Installers\678cd98c8365a5647f9a2e539d120a8\Setup.exe Adobe Reader 7.0.5 - Polish --> MsiExec.exe /I{AC76BA86-7AD7-1045-7B44-A70500000002} Adobe Setup --> MsiExec.exe /I{CBF4DADD-974D-49C8-BC83-C6F31554001E} Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log Adobe Update Manager CS3 --> MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8} Airline Tycoon Evolution PL --> D:\MICHA~1\Gry\AIRLIN~1\UNWISE.EXE D:\MICHA~1\Gry\AIRLIN~1\INSTALL.LOG Airline Tycoon First Class PL --> D:\Ewa\Airline Tycoon\Odinstaluj.exe Aktualizacja dla systemu Windows XP (KB894391) --> “C:\WINDOWS$NtUninstallKB894391$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB896256) --> “C:\WINDOWS$NtUninstallKB896256$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB897663) --> “C:\WINDOWS$NtUninstallKB897663$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB898461) --> “C:\WINDOWS$NtUninstallKB898461$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB900485) --> “C:\WINDOWS$NtUninstallKB900485$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB904942) --> “C:\WINDOWS$NtUninstallKB904942$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB908521) --> “C:\WINDOWS$NtUninstallKB908521$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB908531) --> “C:\WINDOWS$NtUninstallKB908531$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB910437) --> “C:\WINDOWS$NtUninstallKB910437$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB911280) --> “C:\WINDOWS$NtUninstallKB911280$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB916595) --> “C:\WINDOWS$NtUninstallKB916595$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB916846) --> “C:\WINDOWS$NtUninstallKB916846$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB920342) --> “C:\WINDOWS$NtUninstallKB920342$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB920872) --> “C:\WINDOWS$NtUninstallKB920872$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB922120) --> “C:\WINDOWS$NtUninstallKB922120$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB922582) --> “C:\WINDOWS$NtUninstallKB922582$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB925720) --> “C:\WINDOWS$NtUninstallKB925720$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB925876) --> “C:\WINDOWS$NtUninstallKB925876$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB927891) --> “C:\WINDOWS$NtUninstallKB927891$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB930916) --> “C:\WINDOWS$NtUninstallKB930916$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB931836) --> “C:\WINDOWS$NtUninstallKB931836$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB933360) --> “C:\WINDOWS$NtUninstallKB933360$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB936357) --> “C:\WINDOWS$NtUninstallKB936357$\spuninst\spuninst.exe” Aktualizacja dla systemu Windows XP (KB938828) --> “C:\WINDOWS$NtUninstallKB938828$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB893756) --> “C:\WINDOWS$NtUninstallKB893756$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB896358) --> “C:\WINDOWS$NtUninstallKB896358$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB896423) --> “C:\WINDOWS$NtUninstallKB896423$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB896424) --> “C:\WINDOWS$NtUninstallKB896424$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB896428) --> “C:\WINDOWS$NtUninstallKB896428$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB899587) --> “C:\WINDOWS$NtUninstallKB899587$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB899589) --> “C:\WINDOWS$NtUninstallKB899589$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB899591) --> “C:\WINDOWS$NtUninstallKB899591$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB900725) --> “C:\WINDOWS$NtUninstallKB900725$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB901017) --> “C:\WINDOWS$NtUninstallKB901017$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB901190) --> “C:\WINDOWS$NtUninstallKB901190$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB901214) --> “C:\WINDOWS$NtUninstallKB901214$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB902400) --> “C:\WINDOWS$NtUninstallKB902400$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB904706) --> “C:\WINDOWS$NtUninstallKB904706$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB905414) --> “C:\WINDOWS$NtUninstallKB905414$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB905749) --> “C:\WINDOWS$NtUninstallKB905749$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB908519) --> “C:\WINDOWS$NtUninstallKB908519$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB911562) --> “C:\WINDOWS$NtUninstallKB911562$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB911927) --> “C:\WINDOWS$NtUninstallKB911927$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB912919) --> “C:\WINDOWS$NtUninstallKB912919$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB913580) --> “C:\WINDOWS$NtUninstallKB913580$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB914388) --> “C:\WINDOWS$NtUninstallKB914388$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB914389) --> “C:\WINDOWS$NtUninstallKB914389$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB917422) --> “C:\WINDOWS$NtUninstallKB917422$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB917537) --> “C:\WINDOWS$NtUninstallKB917537$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB917953) --> “C:\WINDOWS$NtUninstallKB917953$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB918118) --> “C:\WINDOWS$NtUninstallKB918118$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB918439) --> “C:\WINDOWS$NtUninstallKB918439$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB919007) --> “C:\WINDOWS$NtUninstallKB919007$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB920213) --> “C:\WINDOWS$NtUninstallKB920213$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB920670) --> “C:\WINDOWS$NtUninstallKB920670$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB920683) --> “C:\WINDOWS$NtUninstallKB920683$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB920685) --> “C:\WINDOWS$NtUninstallKB920685$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB921503) --> “C:\WINDOWS$NtUninstallKB921503$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB922819) --> “C:\WINDOWS$NtUninstallKB922819$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB923191) --> “C:\WINDOWS$NtUninstallKB923191$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB923414) --> “C:\WINDOWS$NtUninstallKB923414$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB923694) --> “C:\WINDOWS$NtUninstallKB923694$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB923789) --> C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf Aktualizacja zabezpieczeń dla systemu Windows XP (KB923980) --> “C:\WINDOWS$NtUninstallKB923980$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB924191) --> “C:\WINDOWS$NtUninstallKB924191$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB924270) --> “C:\WINDOWS$NtUninstallKB924270$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB924667) --> “C:\WINDOWS$NtUninstallKB924667$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB925902) --> “C:\WINDOWS$NtUninstallKB925902$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB926255) --> “C:\WINDOWS$NtUninstallKB926255$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB926436) --> “C:\WINDOWS$NtUninstallKB926436$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB927779) --> “C:\WINDOWS$NtUninstallKB927779$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB927802) --> “C:\WINDOWS$NtUninstallKB927802$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB928090) --> “C:\WINDOWS$NtUninstallKB928090$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB928255) --> “C:\WINDOWS$NtUninstallKB928255$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB928843) --> “C:\WINDOWS$NtUninstallKB928843$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB929123) --> “C:\WINDOWS$NtUninstallKB929123$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB930178) --> “C:\WINDOWS$NtUninstallKB930178$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB931261) --> “C:\WINDOWS$NtUninstallKB931261$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB931784) --> “C:\WINDOWS$NtUninstallKB931784$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB932168) --> “C:\WINDOWS$NtUninstallKB932168$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB933729) --> “C:\WINDOWS$NtUninstallKB933729$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB935839) --> “C:\WINDOWS$NtUninstallKB935839$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB935840) --> “C:\WINDOWS$NtUninstallKB935840$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB936021) --> “C:\WINDOWS$NtUninstallKB936021$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB938829) --> “C:\WINDOWS$NtUninstallKB938829$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB941202) --> “C:\WINDOWS$NtUninstallKB941202$\spuninst\spuninst.exe” Aktualizacja zabezpieczeń dla systemu Windows XP (KB943460) --> “C:\WINDOWS$NtUninstallKB943460$\spuninst\spuninst.exe” Alcohol Toolbar --> “C:\WINDOWS\Alcohol_Toolbar_Uninstaller_3703.exe” _?=C:\Program Files\Alcohol Toolbar ALLPlayer V2.3.0 --> “C:\Program Files\MarBit\ALLPlayer\unins000.exe” Archiwizator WinRAR --> C:\Program Files\WinRAR\uninstall.exe Ares 2.0.9 --> “C:\Program Files\Ares\uninstall.exe” avast! Antivirus --> rundll32 C:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll,RunSetup AviSynth 2.5 --> “C:\Program Files\AviSynth 2.5\Uninstall.exe” BitTorrent 5.0.7 --> “C:\Program Files\BitTorrent\uninstall.exe” Biznes filmowy --> D:\Michał\Gry\Biznes Filmowy\uninstall.exe Dodatek SP2 na potrzeby zgodności z poprzednimi wersjami Klienta programu Zarządzanie prawami Windows --> MsiExec.exe /X{EC905264-BCFE-423B-9C42-C3A106266790} EA SPORTS online 2008 --> C:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exe eMusic - 50 Free MP3 offer --> “C:\Program Files\Winamp\eMusic\Uninst-eMusic-promotion.exe” ffdshow [rev 1650] [2007-11-28] --> “C:\Program Files\K-Lite Codec Pack\ffdshow\unins000.exe” FIFA 07 --> D:\Michał\Gry\Fifa 2007\EAUninstall.exe FIFA 08 --> MsiExec.exe /X{0A2A5039-B37F-489D-B1DC-A5258DF9E697} FM Modifier 2.12 --> MsiExec.exe /I{C609012F-FB56-4AA0-8FEC-5A8E5715702C} Football Manager 2007 --> D:\Michał\Gry\Football Manager 2007\uninstall\Uninstall FM 2007.exe Football Manager 2008 --> “D:\Michał\Gry\FM 2008\Uninstall_Football Manager 2008\Uninstall Football Manager 2008.exe” FSone 2006 1.3 --> “D:\Michał\Gry\rFactor\unins000.exe” FSONE v1.52 --> “D:\Michał\Gry\rFactor\rFactor\unins000.exe” Gadu-Gadu 7.7 --> C:\Program Files\Gadu-Gadu\Setup.exe GameSpy Arcade --> C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG Google Earth --> MsiExec.exe /I{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B} GTA San Andreas --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe” -l0x9 -removeonly Hamachi 1.0.2.4 --> C:\Program Files\Hamachi\uninstall.exe HaxFix 4.59 --> “C:\Program Files\HaxFix\unins000.exe” High Definition Audio Driver Package - KB888111 --> “C:\WINDOWS$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe” HijackThis 1.99.1 --> C:\Documents and Settings\user\Pulpit\czyszczenie kompa\HijackThis.exe /uninstall Hotfix for Windows Media Format 11 SDK (KB929399) --> “C:\WINDOWS$NtUninstallKB929399$\spuninst\spuninst.exe” Image Data Converter SR --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{0F429FF7-8C47-40D7-AF6F-D8B090233D04}\setup.exe” -l0x9 -removeonly IrfanView (remove only) --> C:\Program Files\IrfanView\iv_uninstall.exe Java 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020} Java 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030} Java SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010} K-Lite Codec Pack 3.2.5 Full --> “C:\Program Files\K-Lite Codec Pack\unins000.exe” Klient programu Zarządzanie prawami Windows z dodatkiem Service Pack 2 --> MsiExec.exe /X{09A9504A-6DA0-40FC-A519-90BE04132685} livebox tp --> C:\Program Files\InstallShield Installation Information{FC7DDAAE-7F2B-4270-9BFD-5A130B667E9E}\Setup.exe -runfromtemp -l0x0015 -removeonly Medal of Honor Respev Edition --> “C:\Program Files\Medal of Honor Respev Edition\unins000.exe” Microsoft AutoRoute Express Europe 2000 --> C:\Program Files\Common Files\Microsoft Shared\Geography\Setup\acmsetup.exe /T SEU70809.stf Microsoft Compression Client Pack 1.0 for Windows XP --> “C:\WINDOWS$NtUninstallMSCompPackV1$\spuninst\spuninst.exe” Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110415-6000-11D3-8CFE-0150048383C9} Microsoft User-Mode Driver Framework Feature Pack 1.0 --> “C:\WINDOWS$NtUninstallWudf01000$\spuninst\spuninst.exe” Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7} mIRC --> “C:\Program Files\mIRC\mirc.exe” -uninstall Mozilla Firefox (2.0.0.11) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E} Neat Image v5 Demo (with plug-in) --> “C:\Program Files\Neat Image\unins000.exe” Nero OEM --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL NVIDIA Drivers --> C:\WINDOWS\system32\nvuninst.exe UninstallGUI Pakiet podstawowego dostawcy usług kryptograficznych kart inteligentnych Microsoft --> “C:\WINDOWS$NtUninstallbasecsp$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB889527) --> “C:\WINDOWS$NtUninstallKB889527$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB897338) --> “C:\WINDOWS$NtUninstallKB897338$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB898900) --> “C:\WINDOWS$NtUninstallKB898900$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB903234) --> “C:\WINDOWS$NtUninstallKB903234$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB904412) --> “C:\WINDOWS$NtUninstallKB904412$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB906569) --> “C:\WINDOWS$NtUninstallKB906569$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB907865) --> “C:\WINDOWS$NtUninstallKB907865$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB913538) --> “C:\WINDOWS$NtUninstallKB913538$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB914440) --> “C:\WINDOWS$NtUninstallKB914440$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB917021) --> “C:\WINDOWS$NtUninstallKB917021$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB918005) --> “C:\WINDOWS$NtUninstallKB918005$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB918093) --> “C:\WINDOWS$NtUninstallKB918093$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB918997) --> “C:\WINDOWS$NtUninstallKB918997$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB924867) --> “C:\WINDOWS$NtUninstallKB924867$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB924941) --> “C:\WINDOWS$NtUninstallKB924941$\spuninst\spuninst.exe” Poprawka dla systemu Windows XP (KB935448) --> “C:\WINDOWS$NtUninstallKB935448$\spuninst\spuninst.exe” Poprawka systemu Windows XP - KB319740 --> “C:\WINDOWS$NtUninstallKB319740$\spuninst\spuninst.exe” Poprawka systemu Windows XP - KB873339 --> C:\WINDOWS$NtUninstallKB873339$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB884020 --> C:\WINDOWS$NtUninstallKB884020$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB884883 --> “C:\WINDOWS$NtUninstallKB884883$\spuninst\spuninst.exe” Poprawka systemu Windows XP - KB885222 --> “C:\WINDOWS$NtUninstallKB885222$\spuninst\spuninst.exe” Poprawka systemu Windows XP - KB885626 --> C:\WINDOWS$NtUninstallKB885626$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB885836 --> C:\WINDOWS$NtUninstallKB885836$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB886185 --> C:\WINDOWS$NtUninstallKB886185$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB886677 --> C:\WINDOWS$NtUninstallKB886677$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB886716 --> “C:\WINDOWS$NtUninstallKB886716$\spuninst\spuninst.exe” Poprawka systemu Windows XP - KB887472 --> C:\WINDOWS$NtUninstallKB887472$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB887742 --> C:\WINDOWS$NtUninstallKB887742$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB888302 --> C:\WINDOWS$NtUninstallKB888302$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB889673 --> C:\WINDOWS$NtUninstallKB889673$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB890831 --> C:\WINDOWS$NtUninstallKB890831$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB890859 --> “C:\WINDOWS$NtUninstallKB890859$\spuninst\spuninst.exe” Poprawka systemu Windows XP - KB891781 --> C:\WINDOWS$NtUninstallKB891781$\spuninst\spuninst.exe Poprawka systemu Windows XP - KB896626 --> “C:\WINDOWS$NtUninstallKB896626$\spuninst\spuninst.exe” QuickTime Alternative 2.1.1 --> “C:\Program Files\QuickTime Alternative\unins000.exe” Real Alternative 1.50 --> “C:\Program Files\Real Alternative\unins000.exe” RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 REALTEK GbE & FE Ethernet PCI-E NIC Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{C9BED750-1211-4480-B1A5-718A3BE15525}\SETUP.EXE” -l0x15 -removeonly Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.EXE” -l0x15 -removeonly rFactor (remove only) --> “D:\Michał\Gry\rFactor\Uninstall.exe” Rhapsody Player Engine --> MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} Rm To AVI VCD SVCD DVD MPEG Converter 5.9 --> “C:\Program Files\Rm To AVI VCD SVCD DVD MPEG Converter\unins000.exe” Rozszerzenie HighMAT do Kreatora zapisywania dysku CD w systemie Microsoft Windows XP --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F} Sagem Wi-Fi 11g USB adapter (driver) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{2ED60C17-4568-4CD5-830A-03C4688B09A1}\setup.exe” -l0x15 Sagem Wi-Fi 11g USB adapter (utility) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{AAFD22B6-A6C7-4134-AF4E-080BCBCD3493}\Setup.exe” -l0x15 Sony Picture Utility --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe” -l0x9 /removeonly uninstall -removeonly Sony USB Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup “C:\Program Files\InstallShield Installation Information{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}\Setup.exe” UNINSTALL SopCast 1.1.2 --> C:\Program Files\SopCast\uninst.exe Spotter Plugin 1.11 --> “D:\Michał\Gry\rFactor\SpotterUnistall\unins000.exe” SubEdit-Player --> “C:\Program Files\SubEdit-Player\unins000.exe” System Requirements Lab --> C:\Program Files\SystemRequirementsLab\Uninstall.exe Tlen.pl --> “C:\Program Files\Tlen.pl\uninstall.exe” Tv Style Beta 0.9 --> “D:\Michał\Gry\rFactor\TvStyleUnistall\unins000.exe” TVAnts 1.0 --> C:\PROGRA~1\TVAnts\UNWISE.EXE C:\PROGRA~1\TVAnts\INSTALL.LOG TVUPlayer 2.3.2.47 --> C:\Program Files\TVUPlayer\uninst.exe Western Australian Time Zone Update --> MsiExec.exe /X{C098DAEC-29EF-4A59-B18E-0E950169CA3C} Winamp --> “C:\Program Files\Winamp\UninstWA.exe” Winamp Remote --> “C:\Program Files\Winamp Remote\uninstall.exe” Winamp Toolbar --> “C:\Program Files\Winamp Toolbar\uninstall.exe” WinAVI Video Converter --> “C:\Program Files\WinAVI Video Converter\unins000.exe” Windows Communication Foundation --> MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333} Windows Imaging Component --> “C:\WINDOWS$NtUninstallWIC$\spuninst\spuninst.exe” Windows Media Format 11 runtime --> “C:\WINDOWS$NtUninstallWMFDist11$\spuninst\spuninst.exe” Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840} Windows Workflow Foundation --> MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD} XML Paper Specification Shared Components Pack 1.0 --> XviD 1.2.-127 +SMP Alpha uninstall --> “C:\Program Files\XviD\unins000.exe” Zune Desktop Theme --> MsiExec.exe /X{7E20EFE6-E604-48C6-8B39-BA4742F2CDB4} – Application Event Log ------------------------------------------------------- Event Record #/Type2309 / Error Event Submitted/Written: 12/10/2007 10:38:51 PM Event ID/Source: 1002 / Application Hang Event Description: Aplikacja zawieszająca firefox.exe, wersja 1.8.20071.12718, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Event Record #/Type2308 / Error Event Submitted/Written: 12/10/2007 09:37:37 PM Event ID/Source: 1000 / Application Error Event Description: Aplikacja powodująca błąd firefox.exe, wersja 1.8.20071.12718, moduł powodujący błąd unknown, wersja 0.0.0.0, adres błędu 0x03f37541. Przetwarzanie zdarzenia określonego nośnika dla [firefox.exe!ws!] Event Record #/Type2306 / Warning Event Submitted/Written: 12/10/2007 07:01:48 PM Event ID/Source: 1004 / MsiInstaller Event Description: Wykrycie produktu „{90110415-6000-11D3-8CFE-0150048383C9}”, funkcja „WordUserData”, składnik „{8ADD2C93-C8B7-11D1-9C67-0000F81F1B38}” nie powiodło się. Zasób „HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\UserData” nie istnieje. Event Record #/Type2304 / Warning Event Submitted/Written: 12/10/2007 07:01:43 PM Event ID/Source: 1004 / MsiInstaller Event Description: Wykrycie produktu „{90110415-6000-11D3-8CFE-0150048383C9}”, funkcja „WordUserData”, składnik „{8ADD2C93-C8B7-11D1-9C67-0000F81F1B38}” nie powiodło się. Zasób „HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\UserData” nie istnieje. Event Record #/Type2303 / Warning Event Submitted/Written: 12/10/2007 07:01:40 PM Event ID/Source: 1004 / MsiInstaller Event Description: Wykrycie produktu „{90110415-6000-11D3-8CFE-0150048383C9}”, funkcja „OfficeUserData”, składnik „{4A31E933-6F67-11D2-AAA2-00A0C90F57B0}” nie powiodło się. Zasób „HKEY_CURRENT_USER\Software\ODBC\ODBC.INI\MS Access Database\” nie istnieje. – Security Event Log ---------------------------------------------------------- No Errors/Warnings found. – System Event Log ------------------------------------------------------------ Event Record #/Type31601 / Error Event Submitted/Written: 12/12/2007 08:43:49 AM Event ID/Source: 7026 / Service Control Manager Event Description: Nie można załadować następujących sterowników startu rozruchowego lub systemowego: Aavmker4 Fips intelppm Event Record #/Type31600 / Error Event Submitted/Written: 12/12/2007 08:42:40 AM Event ID/Source: 10005 / DCOM Event Description: Model DCOM odebrał błąd „%%1084” podczas próby uruchomienia usługi EventSystem z argumentami „” w celu uruchomienia serwera: {1BE1F766-5536-11D1-B726-00C04FB926AF} Event Record #/Type31599 / Error Event Submitted/Written: 12/12/2007 08:42:34 AM Event ID/Source: 10005 / DCOM Event Description: Model DCOM odebrał błąd „%%1084” podczas próby uruchomienia usługi upnphost z argumentami „” w celu uruchomienia serwera: {204810B9-73B2-11D4-BF42-00B0D0118B56} Event Record #/Type31590 / Error Event Submitted/Written: 12/12/2007 08:39:03 AM Event ID/Source: 10005 / DCOM Event Description: Model DCOM odebrał błąd „%%1084” podczas próby uruchomienia usługi EventSystem z argumentami „” w celu uruchomienia serwera: {1BE1F766-5536-11D1-B726-00C04FB926AF} Event Record #/Type31589 / Error Event Submitted/Written: 12/12/2007 08:38:00 AM Event ID/Source: 10005 / DCOM Event Description: Model DCOM odebrał błąd „%%1084” podczas próby uruchomienia usługi EventSystem z argumentami „” w celu uruchomienia serwera: {1BE1F766-5536-11D1-B726-00C04FB926AF} – End of Deckard’s System Scanner: finished at 2007-12-12 08:52:48 ------------