Przeciążony procesor. Log hijackthis

Witam. Coś mi przeciąża procesor. Wydaje mi się, że to jest to plik ‘explore.exe’, ale nie wiem czy on ma tak wysysać procka, czy nie. Poza tym jakiś tydzień temu ściągnąłem mp3 i od tamtego czasu odpala mi się czasem stronka z reklamami w IE. Log

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 18:18:23, on 2009-10-12

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\WINDOWS\system32\ICO.EXE

C:\WINDOWS\system32\atiptaxx.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\WINDOWS\System32\regsvr32.exe

C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Gadu-Gadu\gg.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

C:\PROGRA~1\MI3AA1~1\rapimgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\WZCBDL Service\WZCBDLS.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.mini20.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = w3cache.sgh.waw.pl:8080

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)

O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: chargeyourprofit browser enhancer - {E85E8F2C-B4CD-1AFC-C1DE-1169347A8C1D} - C:\WINDOWS\system32\dwzsnprabn.dll

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (file missing)

O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe

O4 - HKLM\..\Run: [Realtime Audio Engine] mmrtkrnl.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [D-Link AirXpert Utility] C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [rlgrmpxeufljw] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\dwzsnprabn.dll"

O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: 288ABA.lnk = C:\WINDOWS\system32\E8135C\288ABA.EXE

O4 - Startup: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Pobierz wszystkie VIdeo za pomocą BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Pobierz za pomocą BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm

O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra 'Tools' menuitem: Utwórz Ulubione dla urządzenia przenośnego... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199975890363

O17 - HKLM\System\CCS\Services\Tcpip\..\{FCBBECC3-475D-4A83-B3A9-159AE3412790}: NameServer = 153.19.1.254,153.19.250.100

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL

O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe


--

End of file - 10194 bytes

Daj log z OTL albo log z ComboFix

jessi

OTL log

OTL logfile created on: 2009-10-12 17:23:13 - Run 1

OTL by OldTimer - Version 3.0.20.0 Folder = C:\Documents and Settings\T\Pulpit

Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.2180)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd


510,98 Mb Total Physical Memory | 105,49 Mb Available Physical Memory | 20,64% Memory free

1,22 Gb Paging File | 0,79 Gb Available in Paging File | 64,74% Paging File free

Paging file location(s): C:\pagefile.sys 768 1536 [binary data]


%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 37,30 Gb Total Space | 6,68 Gb Free Space | 17,91% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded


Computer Name: TOMEK

Current User Name: T

Logged in as Administrator.


Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard


[color=#E56717]========== Processes (SafeList) ==========[/color]


PRC - [2009-10-12 17:23:01 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\T\Pulpit\OTL.exe

PRC - [2009-09-10 19:39:07 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe

PRC - [2009-08-17 18:07:23 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe

PRC - [2009-08-17 18:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe

PRC - [2009-08-17 18:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

PRC - [2009-08-17 18:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

PRC - [2009-08-17 17:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

PRC - [2009-07-25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe

PRC - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe

PRC - [2008-07-15 20:03:02 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

PRC - [2008-03-20 12:04:46 | 02,127,296 | ---- | M] (Gadu-Gadu S.A.) -- C:\Program Files\Gadu-Gadu\gg.exe

PRC - [2007-06-13 15:23:49 | 01,034,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE

PRC - [2007-01-15 16:14:54 | 00,147,456 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

PRC - [2007-01-15 16:13:50 | 01,208,320 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

PRC - [2007-01-15 16:01:56 | 00,266,240 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

PRC - [2006-11-13 15:57:16 | 01,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe

PRC - [2006-11-13 15:57:06 | 00,199,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe

PRC - [2006-10-27 01:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

PRC - [2005-01-28 02:36:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe

PRC - [2004-08-04 00:44:30 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe

PRC - [2004-08-04 00:44:28 | 00,012,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\regsvr32.exe

PRC - [2004-08-04 00:44:22 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe

PRC - [2003-08-18 15:06:36 | 02,695,168 | ---- | M] (D-Link) -- C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe

PRC - [2003-08-01 17:57:06 | 00,110,592 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

PRC - [2003-08-01 17:55:56 | 00,618,496 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

PRC - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

PRC - [2002-03-19 13:15:46 | 00,036,864 | ---- | M] (D-Link) -- C:\Program Files\WZCBDL Service\WZCBDLS.exe

PRC - [2001-09-13 01:16:58 | 00,245,760 | ---- | M] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\atiptaxx.exe

PRC - [2001-08-20 20:50:50 | 00,045,056 | ---- | M] (Primax Electronics Ltd.) -- C:\WINDOWS\System32\ICO.EXE

PRC - [2001-08-20 11:25:48 | 00,086,016 | ---- | M] () -- C:\WINDOWS\System32\Ati2evxx.exe


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]


SRV - File not found -- -- (ACDaemon [On_Demand | Stopped])

SRV - [2009-08-17 18:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])

SRV - [2009-08-17 18:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])

SRV - [2009-08-17 18:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])

SRV - [2009-08-17 17:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])

SRV - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])

SRV - [2009-05-16 09:25:44 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])

SRV - [2007-01-15 17:14:38 | 00,774,144 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService [On_Demand | Stopped])

SRV - [2007-01-15 16:01:56 | 00,266,240 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Running])

SRV - [2006-10-27 01:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])

SRV - [2006-10-26 20:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])

SRV - [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])

SRV - [2006-06-05 14:59:18 | 00,174,080 | ---- | M] (Nokia.) -- C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe -- (ServiceLayer [On_Demand | Stopped])

SRV - [2005-09-23 07:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])

SRV - [2005-09-23 07:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])

SRV - [2005-01-28 02:36:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])

SRV - [2004-08-04 00:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])

SRV - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])

SRV - [2002-03-19 13:15:46 | 00,036,864 | ---- | M] (D-Link) -- C:\Program Files\WZCBDL Service\WZCBDLS.exe -- (WZCBDLService [Auto | Running])

SRV - [2001-08-20 11:25:48 | 00,086,016 | ---- | M] () -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])


[color=#E56717]========== Driver Services (SafeList) ==========[/color]


DRV - [2009-08-17 18:06:43 | 00,094,160 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])

DRV - [2009-08-17 18:05:52 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])

DRV - [2009-08-17 18:05:37 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])

DRV - [2009-08-17 18:04:40 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])

DRV - [2009-08-17 18:04:29 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])

DRV - [2009-08-17 18:03:21 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])

DRV - [2009-03-19 14:48:18 | 00,136,704 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdnsu.sys -- (nmwcdnsu [On_Demand | Stopped])

DRV - [2009-03-19 14:48:12 | 00,008,320 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc [On_Demand | Stopped])

DRV - [2009-02-09 08:37:56 | 00,007,808 | ---- | M] (Nokia) -- C:\WINDOWS\System32\DRIVERS\usbser_lowerfltj.sys -- (UsbserFilt [On_Demand | Stopped])

DRV - [2009-02-09 08:37:48 | 00,007,808 | ---- | M] (Nokia) -- C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys -- (upperdev [On_Demand | Stopped])

DRV - [2009-02-09 08:37:46 | 00,022,016 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmbo.sys -- (nmwcdc [On_Demand | Stopped])

DRV - [2009-02-09 08:37:46 | 00,017,664 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmb.sys -- (nmwcd [On_Demand | Stopped])

DRV - [2008-01-20 09:07:58 | 00,033,292 | ---- | M] (PowerISO Computing, Inc.) -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu [System | Running])

DRV - [2008-01-09 13:18:08 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])

DRV - [2007-11-13 12:25:55 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])

DRV - [2005-11-03 21:39:02 | 00,245,504 | ---- | M] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\DRIVERS\Dr71WU.sys -- (RT73 [On_Demand | Stopped])

DRV - [2005-03-22 11:03:04 | 00,032,910 | ---- | M] (USB Com port.) -- C:\WINDOWS\System32\DRIVERS\SER120.sys -- (SER120 [On_Demand | Stopped])

DRV - [2005-01-11 17:05:30 | 00,092,672 | ---- | M] (ALCATech) -- C:\WINDOWS\system32\drivers\mmrtkrnl.sys -- (MMRTKRNL [Boot | Running])

DRV - [2004-08-23 13:55:54 | 00,029,440 | ---- | M] (Siemens AG) -- C:\WINDOWS\System32\drivers\actser.sys -- (actser [On_Demand | Stopped])

DRV - [2004-08-22 16:31:48 | 00,005,248 | ---- | M] ( ) -- C:\WINDOWS\System32\Drivers\d347prt.sys -- (d347prt [Boot | Running])

DRV - [2004-08-22 16:31:10 | 00,155,136 | ---- | M] ( ) -- C:\WINDOWS\system32\DRIVERS\d347bus.sys -- (d347bus [Boot | Running])

DRV - [2004-08-03 23:08:44 | 00,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbser.sys -- (usbser [On_Demand | Stopped])

DRV - [2003-08-01 17:35:08 | 00,270,480 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\System32\DRIVERS\SynTP.sys -- (SynTP [On_Demand | Running])

DRV - [2003-07-23 10:44:36 | 00,322,976 | R--- | M] (D-Link Corporation) -- C:\WINDOWS\System32\DRIVERS\A3AB.sys -- (A3AB [On_Demand | Stopped])

DRV - [2003-06-06 12:19:56 | 00,330,784 | ---- | M] (D-Link) -- C:\WINDOWS\System32\DRIVERS\ar5211.sys -- (AR5211 [On_Demand | Stopped])

DRV - [2003-05-07 12:07:58 | 00,041,472 | R--- | M] (Prolific Technology Inc.) -- C:\WINDOWS\System32\DRIVERS\ser2pl.sys -- (Ser2pl [On_Demand | Stopped])

DRV - [2002-09-27 19:21:26 | 00,022,912 | ---- | M] (D-Link Corporation) -- C:\WINDOWS\System32\NIOC.SYS -- (NIOC [Auto | Running])

DRV - [2001-10-26 18:50:42 | 00,117,760 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys -- (E100B [On_Demand | Running])

DRV - [2001-09-13 01:03:02 | 00,337,344 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])

DRV - [2001-08-17 22:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])

DRV - [2001-08-17 22:51:22 | 00,037,040 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SonyPI.sys -- (SPI [On_Demand | Running])

DRV - [2001-08-17 22:51:20 | 00,020,752 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SonyNC.sys -- (SNC [On_Demand | Running])

DRV - [2001-08-17 22:20:04 | 00,096,256 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\drivers\ac97intc.sys -- (ac97intc [On_Demand | Stopped])

DRV - [2001-08-17 21:53:32 | 00,003,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\qv2kux.sys -- (QV2KUX [On_Demand | Stopped])

DRV - [2001-08-17 21:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])

DRV - [2001-07-25 15:40:30 | 00,438,200 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\System32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])

DRV - [2001-07-24 11:34:34 | 00,007,520 | ---- | M] (Primax Electronics Ltd.) -- C:\WINDOWS\System32\DRIVERS\pelusblf.sys -- (pelusblf [On_Demand | Running])

DRV - [2001-01-09 17:49:28 | 00,027,088 | ---- | M] (Primax Electronics Ltd.) -- C:\WINDOWS\System32\DRIVERS\pelmouse.sys -- (pelmouse [On_Demand | Running])

DRV - [1997-12-23 02:00:00 | 00,023,936 | ---- | M] (Adaptec) -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (ASPI32 [Auto | Running])


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]



[color=#E56717]========== Internet Explorer ==========[/color]


IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll File not found


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.mini20.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll File not found

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = w3cache.sgh.waw.pl:8080


[color=#E56717]========== FireFox ==========[/color]


FF - prefs.js..browser.startup.homepage: "http://www.onet.pl/"

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1

FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.07

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..extensions.enabledItems: {eaf8a4ef-d221-45ca-9deb-d0934b45fa34}:1.3.0.3

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14

FF - prefs.js..network.proxy.backup.ftp: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.backup.ftp_port: 8080

FF - prefs.js..network.proxy.backup.gopher: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.backup.gopher_port: 8080

FF - prefs.js..network.proxy.backup.socks: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.backup.socks_port: 8080

FF - prefs.js..network.proxy.backup.ssl: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.backup.ssl_port: 8080

FF - prefs.js..network.proxy.ftp: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.ftp_port: 8080

FF - prefs.js..network.proxy.gopher: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.gopher_port: 8080

FF - prefs.js..network.proxy.http: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.http_port: 8080

FF - prefs.js..network.proxy.share_proxy_settings: true

FF - prefs.js..network.proxy.socks: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.socks_port: 8080

FF - prefs.js..network.proxy.ssl: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.ssl_port: 8080


FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-01-17 21:08:25 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-09-11 20:27:39 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-10 19:39:15 | 00,000,000 | ---D | M]


[2009-02-06 11:46:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Extensions

[2008-09-08 20:46:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2009-02-06 11:46:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Extensions\mozswing@mozswing.org

[2006-06-06 18:14:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\pq6bcmpb.default\extensions

[2006-06-06 18:14:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\pq6bcmpb.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009-10-11 21:03:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\xa2l30op.default\extensions

[2009-03-17 16:42:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\xa2l30op.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}

[2009-09-11 19:47:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\xa2l30op.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}

[2009-01-26 18:56:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\xa2l30op.default\extensions\{eaf8a4ef-d221-45ca-9deb-d0934b45fa34}

[2008-06-04 09:18:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\xa2l30op.default\extensions\temp

[2008-07-07 18:15:15 | 00,001,196 | ---- | M] () -- C:\Documents and Settings\T\Dane aplikacji\Mozilla\FireFox\Profiles\xa2l30op.default\searchplugins\winamp-search.xml

[2009-10-11 21:03:59 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions

[2009-09-10 19:39:15 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009-01-17 21:08:54 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

[2009-05-28 17:17:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

[2009-08-26 09:16:18 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

[2009-09-10 19:39:06 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll

[2009-09-10 19:39:07 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll

[2004-07-02 15:51:00 | 00,327,904 | ---- | M] (Macromedia, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32asw.dll

[2008-08-06 16:22:02 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll

[2008-11-11 09:38:54 | 00,663,552 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll

[2009-07-25 05:23:01 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll

[2006-06-02 00:08:19 | 00,527,872 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll

[2006-06-02 00:07:33 | 00,086,016 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll

[2008-06-27 17:03:12 | 01,446,440 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll

[2004-01-14 13:07:00 | 01,925,120 | ---- | M] (Cycore AB) -- C:\Program Files\mozilla firefox\plugins\NPMCult3DP.dll

[2005-10-02 12:28:00 | 00,110,592 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npmozax.dll

[2008-09-06 01:35:30 | 00,024,576 | ---- | M] (My Global Search) -- C:\Program Files\mozilla firefox\plugins\NPMyGlSh.dll

[2009-09-10 19:39:10 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll

[2003-07-15 06:56:52 | 00,013,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL

[2007-12-11 11:07:28 | 00,307,200 | ---- | M] (ESKA) -- C:\Program Files\mozilla firefox\plugins\npOggX.dll

[2008-10-14 22:33:30 | 00,095,600 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll

[2009-08-01 15:48:39 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml

[2008-09-08 20:45:48 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml

[2008-09-08 20:45:48 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml

[2008-09-08 20:45:48 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml

[2008-09-08 20:45:48 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml

[2008-09-08 20:45:48 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml

[2008-09-08 20:45:48 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml


O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll File not found

O2 - BHO: (My Global Search Bar BHO) - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL (My Global Search)

O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll (BitComet)

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)

O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

O2 - BHO: (chargeyourprofit browser enhancer) - {E85E8F2C-B4CD-1AFC-C1DE-1169347A8C1D} - C:\WINDOWS\System32\dwzsnprabn.dll ()

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (My Global Search Bar) - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL (My Global Search)

O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll File not found

O3 - HKCU\..\Toolbar\ShellBrowser: (My Global Search Bar) - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL (My Global Search)

O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKCU\..\Toolbar\WebBrowser: (BitComet Toolbar) - {2E608F70-C430-4BC5-96F6-608E02EBA5B2} - C:\Program Files\BitComet Toolbar\v2.0.0.5\BitComet_Toolbar.dll File not found

O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll File not found

O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)

O4 - HKLM..\Run: [AtiPTA] C:\WINDOWS\System32\atiptaxx.exe (ATI Technologies, Inc.)

O4 - HKLM..\Run: [AutoEJCD_0ACE20FF] File not found

O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)

O4 - HKLM..\Run: [D-Link AirXpert Utility] C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe (D-Link)

O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\WINDOWS\System32\ICO.EXE (Primax Electronics Ltd.)

O4 - HKLM..\Run: [Realtime Audio Engine] C:\WINDOWS\System32\mmrtkrnl.exe (ALCATech)

O4 - HKLM..\Run: [rlgrmpxeufljw] C:\WINDOWS\System32\dwzsnprabn.dll ()

O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)

O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)

O4 - HKLM..\Run: [Wireless Adapter Manager] File not found

O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)

O4 - HKCU..\Run: [Gadu-Gadu] C:\Program Files\Gadu-Gadu\gg.exe (Gadu-Gadu S.A.)

O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)

O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - Startup: C:\Documents and Settings\T\Menu Start\Programy\Autostart\288ABA.lnk = C:\WINDOWS\System32\E8135C\288ABA.EXE File not found

O4 - Startup: C:\Documents and Settings\T\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = 

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = 

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE File not found

O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: Pobierz wszystkie VIdeo za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)

O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)

O8 - Extra context menu item: Pobierz za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)

O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Utwórz Ulubione dla urządzenia przenośnego... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll (BitComet)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKCU\..Trusted Domains: onet.pl ([www] https in Zaufane witryny)

O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199975890363 (WUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.76.33.232 212.76.33.233

O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)

O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2006-03-30 21:21:39 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [NTFS]

O32 - AutoRun File - [2008-02-10 16:20:49 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [NTFS]

O33 - MountPoints2\{f75cba12-4091-11de-8deb-080046434e13}\Shell\AutoRun\command - "" = E:\DRIVE\file.exe -- File not found

O33 - MountPoints2\{f75cba12-4091-11de-8deb-080046434e13}\Shell\open\command - "" = E:\DRIVE\file.exe -- File not found

O34 - HKLM BootExecute: (autocheck) - File not found

O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)

O34 - HKLM BootExecute: (*) - File not found

O35 - comfile [open] -- "%1" %* File not found

O35 - exefile [open] -- "%1" %* File not found


[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]


[2009-10-05 17:37:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations

[2009-10-05 17:47:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Nokia

[2009-10-05 17:38:28 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0

[2009-10-12 17:22:55 | 00,521,216 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\T\Pulpit\OTL.exe

[2009-10-05 17:51:01 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbser.sys

[2009-10-05 17:51:01 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbser.sys

[2009-10-05 17:50:17 | 00,014,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsgXP_2k3.dll

[2009-10-05 17:44:26 | 00,008,320 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdnsuc.sys

[2009-10-05 17:44:25 | 00,136,704 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdnsu.sys

[2009-10-05 17:44:24 | 00,007,808 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\usbser_lowerfltj.sys

[2009-10-05 17:44:23 | 00,007,808 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\usbser_lowerflt.sys

[2009-10-05 17:44:20 | 00,022,016 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmbo.sys

[2009-10-05 17:44:19 | 00,659,968 | ---- | C] (Nokia) -- C:\WINDOWS\System32\nmwcdcocls.dll

[2009-10-05 17:44:19 | 00,017,664 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmb.sys

[2009-10-05 17:44:18 | 01,112,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfcoinstaller01007.dll

[2009-10-02 20:22:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\T\Pulpit\Rodzina Soprano S1

[2008-01-01 19:02:20 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnp325.dll

[2008-01-01 19:02:20 | 00,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp325.dll

[2006-03-31 15:02:17 | 00,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys

[2006-03-31 15:02:17 | 00,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys


[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]


[1 C:\WINDOWS\System32\*.tmp files]

[3 C:\WINDOWS\*.tmp files]

[2009-10-12 17:23:01 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\T\Pulpit\OTL.exe

[2009-10-12 17:13:51 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009-10-12 17:13:35 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009-10-12 12:25:26 | 00,110,592 | ---- | M] () -- C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009-10-12 12:25:26 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2009-10-12 11:31:12 | 07,490,206 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\ogolna_9_10_09.pdf

[2009-10-12 11:01:01 | 00,032,768 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\kursinform.doc

[2009-10-11 20:40:11 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009-10-08 21:30:31 | 02,370,127 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\real tone2-dorfmeister_vs._mdla_-_boogie_no_more_(reverso_68_remix).mp3

[2009-10-08 21:25:34 | 02,370,127 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\real tone1-dorfmeister_vs._mdla_-_boogie_no_more_(reverso_68_remix).mp3

[2009-10-07 09:57:31 | 02,732,432 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\spec2007.rtf

[2009-10-06 18:01:00 | 00,028,672 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\Deklaracja(2).xls

[2009-10-06 15:43:08 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2009-10-05 17:50:46 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01007.Wdf

[2009-10-05 17:50:44 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf

[2009-10-05 17:39:43 | 00,001,855 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Nokia Software Updater.lnk

[2009-10-05 17:35:29 | 24,671,032 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\NokiaSoftwareUpdaterSetup_pl.exe

[2009-10-05 17:27:37 | 00,000,680 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\NSS.lnk

[2009-10-04 16:08:22 | 02,713,088 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\BOD.doc

[2009-10-04 11:34:30 | 00,187,540 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\hiszpanska.pdf

[2009-10-04 11:21:45 | 00,018,944 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\stacjonarne.xls

[2009-10-03 22:37:19 | 02,109,058 | -H-- | M] () -- C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\IconCache.db

[2009-09-17 20:52:04 | 00,048,281 | ---- | M] () -- C:\WINDOWS\System32\qdjmohxyxhdk.exe

[2009-09-14 13:56:48 | 00,442,368 | ---- | M] () -- C:\WINDOWS\System32\dwzsnprabn.dll


[color=#E56717]========== Files - No Company Name ==========[/color]

[2009-10-12 11:31:10 | 07,490,206 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\ogolna_9_10_09.pdf

[2009-10-12 11:00:59 | 00,032,768 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\kursinform.doc

[2009-10-08 21:30:31 | 02,370,127 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\real tone2-dorfmeister_vs._mdla_-_boogie_no_more_(reverso_68_remix).mp3

[2009-10-08 21:25:33 | 02,370,127 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\real tone1-dorfmeister_vs._mdla_-_boogie_no_more_(reverso_68_remix).mp3

[2009-10-08 21:15:06 | 02,370,127 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\real tone-dorfmeister_vs._mdla_-_boogie_no_more_(reverso_68_remix).mp3

[2009-10-07 09:57:25 | 02,732,432 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\spec2007.rtf

[2009-10-06 18:00:48 | 00,028,672 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\Deklaracja(2).xls

[2009-10-05 17:50:46 | 00,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01007.Wdf

[2009-10-05 17:50:44 | 00,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf

[2009-10-05 17:39:43 | 00,001,855 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Nokia Software Updater.lnk

[2009-10-05 17:34:47 | 24,671,032 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\NokiaSoftwareUpdaterSetup_pl.exe

[2009-10-05 17:27:37 | 00,000,680 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\NSS.lnk

[2009-10-04 11:34:30 | 00,187,540 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\hiszpanska.pdf

[2009-10-04 11:14:24 | 00,018,944 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\stacjonarne.xls

[2009-10-03 11:12:13 | 02,713,088 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\BOD.doc

[2009-09-17 20:52:04 | 00,048,281 | ---- | C] () -- C:\WINDOWS\System32\qdjmohxyxhdk.exe

[2009-09-14 13:56:48 | 00,442,368 | ---- | C] () -- C:\WINDOWS\System32\dwzsnprabn.dll

[2009-07-31 11:28:14 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll

[2009-03-08 15:22:06 | 00,000,380 | ---- | C] () -- C:\WINDOWS\pdf2word.INI

[2009-02-14 13:24:26 | 00,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll

[2009-01-03 19:01:51 | 00,217,088 | ---- | C] () -- C:\WINDOWS\System32\libmySQL.dll

[2009-01-03 19:01:51 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\TrackerNET.dll

[2009-01-01 22:00:45 | 00,000,452 | ---- | C] () -- C:\WINDOWS\SIERRA.INI

[2008-12-30 18:16:12 | 00,147,456 | R--- | C] () -- C:\WINDOWS\System32\ssleay32.dll

[2008-12-30 18:16:11 | 00,651,264 | R--- | C] () -- C:\WINDOWS\System32\libeay32.dll

[2008-10-04 11:58:23 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll

[2008-06-22 09:04:55 | 00,016,031 | ---- | C] () -- C:\Documents and Settings\T\Dane aplikacji\ggconsole.log

[2008-04-18 20:49:28 | 02,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll

[2008-03-01 19:08:26 | 00,000,008 | ---- | C] () -- C:\Documents and Settings\T\Dane aplikacji\NMM-MetaData.db

[2008-02-07 17:07:41 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2008-01-09 13:18:12 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll

[2008-01-09 13:16:10 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest

[2008-01-09 13:16:10 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest

[2007-12-11 21:43:44 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll

[2007-08-30 15:50:52 | 00,114,688 | ---- | C] () -- C:\WINDOWS\System32\WLANUTL.dll

[2007-05-18 22:42:11 | 00,002,528 | ---- | C] () -- C:\Documents and Settings\T\Dane aplikacji\$_hpcst$.hpc

[2007-05-01 13:55:35 | 00,000,083 | ---- | C] () -- C:\WINDOWS\wa.INI

[2007-04-07 21:28:33 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2006-12-28 22:50:24 | 00,000,024 | ---- | C] () -- C:\WINDOWS\ChessGen.ini

[2006-11-29 23:13:44 | 00,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll

[2006-10-27 21:45:25 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI

[2006-08-24 14:59:59 | 00,000,053 | ---- | C] () -- C:\WINDOWS\wininit.ini

[2006-07-27 22:52:56 | 00,000,156 | ---- | C] () -- C:\WINDOWS\PRESTO.INI

[2006-07-27 16:19:59 | 00,000,173 | ---- | C] () -- C:\WINDOWS\ae.INI

[2006-07-27 16:06:42 | 00,001,562 | ---- | C] () -- C:\WINDOWS\psmplay.ini

[2006-06-24 17:54:54 | 00,000,070 | ---- | C] () -- C:\WINDOWS\mmpoly.ini

[2006-06-23 21:59:41 | 00,000,019 | ---- | C] () -- C:\WINDOWS\SoundConverter.INI

[2006-06-21 18:18:05 | 00,001,186 | ---- | C] () -- C:\WINDOWS\cdplayer.ini

[2006-06-09 15:35:43 | 02,109,058 | -H-- | C] () -- C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\IconCache.db

[2006-04-30 14:27:25 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll

[2006-04-30 14:27:25 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll

[2006-04-30 14:27:25 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll

[2006-04-25 09:02:22 | 00,000,149 | ---- | C] () -- C:\WINDOWS\disney.ini

[2006-04-24 20:40:11 | 00,000,052 | ---- | C] () -- C:\WINDOWS\mafosav.INI

[2006-04-06 10:53:19 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2006-03-30 23:50:12 | 00,001,324 | ---- | C] () -- C:\WINDOWS\naglos.INI

[2006-03-30 23:24:57 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll

[2006-03-30 23:01:22 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini

[2006-03-30 22:42:09 | 00,110,592 | ---- | C] () -- C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2006-03-30 21:58:01 | 00,065,104 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinrvxx.sys

[2006-03-30 21:58:01 | 00,060,464 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinbtxx.sys

[2006-03-30 21:58:01 | 00,032,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinraxx.sys

[2006-03-30 21:58:01 | 00,032,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinxsxx.sys

[2006-03-30 21:58:01 | 00,032,320 | ---- | C] () -- C:\WINDOWS\System32\drivers\atintuxx.sys

[2006-03-30 21:58:01 | 00,020,960 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinttxx.sys

[2006-03-30 21:58:01 | 00,011,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinpdxx.sys

[2006-03-30 21:58:01 | 00,011,280 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinmdxx.sys

[2006-03-30 21:56:11 | 00,000,556 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2006-03-30 21:30:59 | 00,071,552 | ---- | C] () -- C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT

[2006-03-30 21:29:32 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\T\Dane aplikacji\desktop.ini

[2005-12-07 13:31:00 | 00,202,752 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll

[2004-08-22 17:04:56 | 00,069,120 | ---- | C] () -- C:\WINDOWS\daemon.dll

[2004-08-04 00:44:00 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll

[2002-06-09 14:07:30 | 00,053,315 | ---- | C] () -- C:\WINDOWS\System32\DevCtrl.dll

[2001-07-21 22:16:20 | 00,001,039 | ---- | C] () -- C:\WINDOWS\win.ini

[2001-07-21 22:15:52 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

[1997-06-14 02:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll


[color=#E56717]========== Alternate Data Streams ==========[/color]


@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:0CE7F3C9

< End of report >

Uruchom OTL i w oknie Custom Scans/Fixes wklej to:

Kliknij w Run Fix. Zatwierdź restart komputera.

Następnie uruchom OTL ponownie, tym razem wywołaj opcję Run Scan.

Pokaż nowy log OTL.txt oraz log z czyszczenia.

jessi

OTL logfile created on: 2009-10-12 19:40:14 - Run 2

OTL by OldTimer - Version 3.0.20.0 Folder = C:\Documents and Settings\T\Pulpit

Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.2180)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd


510,98 Mb Total Physical Memory | 165,88 Mb Available Physical Memory | 32,46% Memory free

1,22 Gb Paging File | 0,85 Gb Available in Paging File | 69,91% Paging File free

Paging file location(s): C:\pagefile.sys 768 1536 [binary data]


%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 37,30 Gb Total Space | 7,53 Gb Free Space | 20,18% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded


Computer Name: TOMEK

Current User Name: T

Logged in as Administrator.


Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard


[color=#E56717]========== Processes (SafeList) ==========[/color]


PRC - [2009-10-12 17:23:01 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\T\Pulpit\OTL.exe

PRC - [2009-09-10 19:39:07 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe

PRC - [2009-08-17 18:07:23 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe

PRC - [2009-08-17 18:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe

PRC - [2009-08-17 18:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

PRC - [2009-08-17 18:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

PRC - [2009-08-17 17:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

PRC - [2009-07-25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe

PRC - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe

PRC - [2008-07-15 20:03:02 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

PRC - [2008-03-20 12:04:46 | 02,127,296 | ---- | M] (Gadu-Gadu S.A.) -- C:\Program Files\Gadu-Gadu\gg.exe

PRC - [2007-06-13 15:23:49 | 01,034,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE

PRC - [2007-01-15 16:14:54 | 00,147,456 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

PRC - [2007-01-15 16:13:50 | 01,208,320 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

PRC - [2007-01-15 16:01:56 | 00,266,240 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

PRC - [2006-11-13 15:57:16 | 01,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe

PRC - [2006-11-13 15:57:06 | 00,199,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe

PRC - [2006-10-27 01:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

PRC - [2005-01-28 02:36:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe

PRC - [2004-08-04 00:44:30 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe

PRC - [2004-08-04 00:44:26 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe

PRC - [2003-08-18 15:06:36 | 02,695,168 | ---- | M] (D-Link) -- C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe

PRC - [2003-08-01 17:57:06 | 00,110,592 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

PRC - [2003-08-01 17:55:56 | 00,618,496 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

PRC - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

PRC - [2002-03-19 13:15:46 | 00,036,864 | ---- | M] (D-Link) -- C:\Program Files\WZCBDL Service\WZCBDLS.exe

PRC - [2001-09-13 01:16:58 | 00,245,760 | ---- | M] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\atiptaxx.exe

PRC - [2001-08-20 20:50:50 | 00,045,056 | ---- | M] (Primax Electronics Ltd.) -- C:\WINDOWS\System32\ICO.EXE

PRC - [2001-08-20 11:25:48 | 00,086,016 | ---- | M] () -- C:\WINDOWS\System32\Ati2evxx.exe


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]


SRV - File not found -- -- (ACDaemon [On_Demand | Stopped])

SRV - [2009-08-17 18:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])

SRV - [2009-08-17 18:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])

SRV - [2009-08-17 18:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])

SRV - [2009-08-17 17:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])

SRV - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])

SRV - [2009-05-16 09:25:44 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])

SRV - [2007-01-15 17:14:38 | 00,774,144 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService [On_Demand | Stopped])

SRV - [2007-01-15 16:01:56 | 00,266,240 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Running])

SRV - [2006-10-27 01:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])

SRV - [2006-10-26 20:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])

SRV - [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])

SRV - [2006-06-05 14:59:18 | 00,174,080 | ---- | M] (Nokia.) -- C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe -- (ServiceLayer [On_Demand | Stopped])

SRV - [2005-09-23 07:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])

SRV - [2005-09-23 07:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])

SRV - [2005-01-28 02:36:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])

SRV - [2004-08-04 00:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])

SRV - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])

SRV - [2002-03-19 13:15:46 | 00,036,864 | ---- | M] (D-Link) -- C:\Program Files\WZCBDL Service\WZCBDLS.exe -- (WZCBDLService [Auto | Running])

SRV - [2001-08-20 11:25:48 | 00,086,016 | ---- | M] () -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])


[color=#E56717]========== Driver Services (SafeList) ==========[/color]


DRV - [2009-08-17 18:06:43 | 00,094,160 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])

DRV - [2009-08-17 18:05:52 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])

DRV - [2009-08-17 18:05:37 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])

DRV - [2009-08-17 18:04:40 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])

DRV - [2009-08-17 18:04:29 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])

DRV - [2009-08-17 18:03:21 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])

DRV - [2009-03-19 14:48:18 | 00,136,704 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdnsu.sys -- (nmwcdnsu [On_Demand | Stopped])

DRV - [2009-03-19 14:48:12 | 00,008,320 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc [On_Demand | Stopped])

DRV - [2009-02-09 08:37:56 | 00,007,808 | ---- | M] (Nokia) -- C:\WINDOWS\System32\DRIVERS\usbser_lowerfltj.sys -- (UsbserFilt [On_Demand | Stopped])

DRV - [2009-02-09 08:37:48 | 00,007,808 | ---- | M] (Nokia) -- C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys -- (upperdev [On_Demand | Stopped])

DRV - [2009-02-09 08:37:46 | 00,022,016 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmbo.sys -- (nmwcdc [On_Demand | Stopped])

DRV - [2009-02-09 08:37:46 | 00,017,664 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmb.sys -- (nmwcd [On_Demand | Stopped])

DRV - [2008-01-20 09:07:58 | 00,033,292 | ---- | M] (PowerISO Computing, Inc.) -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu [System | Running])

DRV - [2008-01-09 13:18:08 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])

DRV - [2007-11-13 12:25:55 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])

DRV - [2005-11-03 21:39:02 | 00,245,504 | ---- | M] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\DRIVERS\Dr71WU.sys -- (RT73 [On_Demand | Stopped])

DRV - [2005-03-22 11:03:04 | 00,032,910 | ---- | M] (USB Com port.) -- C:\WINDOWS\System32\DRIVERS\SER120.sys -- (SER120 [On_Demand | Stopped])

DRV - [2005-01-11 17:05:30 | 00,092,672 | ---- | M] (ALCATech) -- C:\WINDOWS\system32\drivers\mmrtkrnl.sys -- (MMRTKRNL [Boot | Running])

DRV - [2004-08-23 13:55:54 | 00,029,440 | ---- | M] (Siemens AG) -- C:\WINDOWS\System32\drivers\actser.sys -- (actser [On_Demand | Stopped])

DRV - [2004-08-22 16:31:48 | 00,005,248 | ---- | M] ( ) -- C:\WINDOWS\System32\Drivers\d347prt.sys -- (d347prt [Boot | Running])

DRV - [2004-08-22 16:31:10 | 00,155,136 | ---- | M] ( ) -- C:\WINDOWS\system32\DRIVERS\d347bus.sys -- (d347bus [Boot | Running])

DRV - [2004-08-03 23:08:44 | 00,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbser.sys -- (usbser [On_Demand | Stopped])

DRV - [2003-08-01 17:35:08 | 00,270,480 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\System32\DRIVERS\SynTP.sys -- (SynTP [On_Demand | Running])

DRV - [2003-07-23 10:44:36 | 00,322,976 | R--- | M] (D-Link Corporation) -- C:\WINDOWS\System32\DRIVERS\A3AB.sys -- (A3AB [On_Demand | Stopped])

DRV - [2003-06-06 12:19:56 | 00,330,784 | ---- | M] (D-Link) -- C:\WINDOWS\System32\DRIVERS\ar5211.sys -- (AR5211 [On_Demand | Stopped])

DRV - [2003-05-07 12:07:58 | 00,041,472 | R--- | M] (Prolific Technology Inc.) -- C:\WINDOWS\System32\DRIVERS\ser2pl.sys -- (Ser2pl [On_Demand | Stopped])

DRV - [2002-09-27 19:21:26 | 00,022,912 | ---- | M] (D-Link Corporation) -- C:\WINDOWS\System32\NIOC.SYS -- (NIOC [Auto | Running])

DRV - [2001-10-26 18:50:42 | 00,117,760 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys -- (E100B [On_Demand | Running])

DRV - [2001-09-13 01:03:02 | 00,337,344 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])

DRV - [2001-08-17 22:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])

DRV - [2001-08-17 22:51:22 | 00,037,040 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SonyPI.sys -- (SPI [On_Demand | Running])

DRV - [2001-08-17 22:51:20 | 00,020,752 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SonyNC.sys -- (SNC [On_Demand | Running])

DRV - [2001-08-17 22:20:04 | 00,096,256 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\drivers\ac97intc.sys -- (ac97intc [On_Demand | Stopped])

DRV - [2001-08-17 21:53:32 | 00,003,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\qv2kux.sys -- (QV2KUX [On_Demand | Stopped])

DRV - [2001-08-17 21:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])

DRV - [2001-07-25 15:40:30 | 00,438,200 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\System32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])

DRV - [2001-07-24 11:34:34 | 00,007,520 | ---- | M] (Primax Electronics Ltd.) -- C:\WINDOWS\System32\DRIVERS\pelusblf.sys -- (pelusblf [On_Demand | Running])

DRV - [2001-01-09 17:49:28 | 00,027,088 | ---- | M] (Primax Electronics Ltd.) -- C:\WINDOWS\System32\DRIVERS\pelmouse.sys -- (pelmouse [On_Demand | Running])

DRV - [1997-12-23 02:00:00 | 00,023,936 | ---- | M] (Adaptec) -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (ASPI32 [Auto | Running])


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]



[color=#E56717]========== Internet Explorer ==========[/color]


IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.mini20.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = w3cache.sgh.waw.pl:8080


[color=#E56717]========== FireFox ==========[/color]


FF - prefs.js..browser.startup.homepage: "http://www.onet.pl/"

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1

FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.07

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..extensions.enabledItems: {eaf8a4ef-d221-45ca-9deb-d0934b45fa34}:1.3.0.3

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14

FF - prefs.js..network.proxy.backup.ftp: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.backup.ftp_port: 8080

FF - prefs.js..network.proxy.backup.gopher: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.backup.gopher_port: 8080

FF - prefs.js..network.proxy.backup.socks: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.backup.socks_port: 8080

FF - prefs.js..network.proxy.backup.ssl: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.backup.ssl_port: 8080

FF - prefs.js..network.proxy.ftp: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.ftp_port: 8080

FF - prefs.js..network.proxy.gopher: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.gopher_port: 8080

FF - prefs.js..network.proxy.http: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.http_port: 8080

FF - prefs.js..network.proxy.share_proxy_settings: true

FF - prefs.js..network.proxy.socks: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.socks_port: 8080

FF - prefs.js..network.proxy.ssl: "w3cache.sgh.waw.pl"

FF - prefs.js..network.proxy.ssl_port: 8080


FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-01-17 21:08:25 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-09-11 20:27:39 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-10 19:39:15 | 00,000,000 | ---D | M]


[2009-02-06 11:46:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Extensions

[2008-09-08 20:46:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2009-02-06 11:46:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Extensions\mozswing@mozswing.org

[2006-06-06 18:14:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\pq6bcmpb.default\extensions

[2006-06-06 18:14:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\pq6bcmpb.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009-10-11 21:03:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\xa2l30op.default\extensions

[2009-03-17 16:42:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\xa2l30op.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}

[2009-09-11 19:47:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\xa2l30op.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}

[2009-01-26 18:56:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\xa2l30op.default\extensions\{eaf8a4ef-d221-45ca-9deb-d0934b45fa34}

[2008-06-04 09:18:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\T\Dane aplikacji\mozilla\Firefox\Profiles\xa2l30op.default\extensions\temp

[2008-07-07 18:15:15 | 00,001,196 | ---- | M] () -- C:\Documents and Settings\T\Dane aplikacji\Mozilla\FireFox\Profiles\xa2l30op.default\searchplugins\winamp-search.xml

[2009-10-11 21:03:59 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions

[2009-09-10 19:39:15 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009-01-17 21:08:54 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

[2009-05-28 17:17:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

[2009-08-26 09:16:18 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

[2009-09-10 19:39:06 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll

[2009-09-10 19:39:07 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll

[2004-07-02 15:51:00 | 00,327,904 | ---- | M] (Macromedia, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32asw.dll

[2008-08-06 16:22:02 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll

[2008-11-11 09:38:54 | 00,663,552 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll

[2009-07-25 05:23:01 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll

[2006-06-02 00:08:19 | 00,527,872 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll

[2006-06-02 00:07:33 | 00,086,016 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll

[2008-06-27 17:03:12 | 01,446,440 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll

[2004-01-14 13:07:00 | 01,925,120 | ---- | M] (Cycore AB) -- C:\Program Files\mozilla firefox\plugins\NPMCult3DP.dll

[2005-10-02 12:28:00 | 00,110,592 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npmozax.dll

[2009-09-10 19:39:10 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll

[2003-07-15 06:56:52 | 00,013,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL

[2007-12-11 11:07:28 | 00,307,200 | ---- | M] (ESKA) -- C:\Program Files\mozilla firefox\plugins\npOggX.dll

[2008-10-14 22:33:30 | 00,095,600 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll

[2009-08-01 15:48:39 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml

[2008-09-08 20:45:48 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml

[2008-09-08 20:45:48 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml

[2008-09-08 20:45:48 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml

[2008-09-08 20:45:48 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml

[2008-09-08 20:45:48 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml

[2008-09-08 20:45:48 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml


O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll (BitComet)

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)

O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKCU\..\Toolbar\WebBrowser: (BitComet Toolbar) - {2E608F70-C430-4BC5-96F6-608E02EBA5B2} - C:\Program Files\BitComet Toolbar\v2.0.0.5\BitComet_Toolbar.dll File not found

O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)

O4 - HKLM..\Run: [AtiPTA] C:\WINDOWS\System32\atiptaxx.exe (ATI Technologies, Inc.)

O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)

O4 - HKLM..\Run: [D-Link AirXpert Utility] C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe (D-Link)

O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\WINDOWS\System32\ICO.EXE (Primax Electronics Ltd.)

O4 - HKLM..\Run: [Realtime Audio Engine] C:\WINDOWS\System32\mmrtkrnl.exe (ALCATech)

O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)

O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)

O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)

O4 - HKCU..\Run: [Gadu-Gadu] C:\Program Files\Gadu-Gadu\gg.exe (Gadu-Gadu S.A.)

O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)

O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - Startup: C:\Documents and Settings\T\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = 

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = 

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE File not found

O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: Pobierz wszystkie VIdeo za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)

O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)

O8 - Extra context menu item: Pobierz za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)

O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Utwórz Ulubione dla urządzenia przenośnego... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll (BitComet)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKCU\..Trusted Domains: onet.pl ([www] https in Zaufane witryny)

O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199975890363 (WUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.76.33.232 212.76.33.233

O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)

O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2006-03-30 21:21:39 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [NTFS]

O32 - AutoRun File - [2008-02-10 16:20:49 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [NTFS]

O33 - MountPoints2\{f75cba12-4091-11de-8deb-080046434e13}\Shell\AutoRun\command - "" = E:\DRIVE\file.exe -- File not found

O33 - MountPoints2\{f75cba12-4091-11de-8deb-080046434e13}\Shell\open\command - "" = E:\DRIVE\file.exe -- File not found

O34 - HKLM BootExecute: (autocheck) - File not found

O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)

O34 - HKLM BootExecute: (*) - File not found

O35 - comfile [open] -- "%1" %* File not found

O35 - exefile [open] -- "%1" %* File not found


[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]


[2009-10-05 17:37:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations

[2009-10-05 17:47:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Nokia

[2009-10-05 17:38:28 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0

[2009-10-12 19:28:32 | 00,000,000 | ---D | C] -- C:\_OTL

[2009-10-12 18:17:47 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\T\Pulpit\HJTInstall.exe

[2009-10-12 17:22:55 | 00,521,216 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\T\Pulpit\OTL.exe

[2009-10-05 17:51:01 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbser.sys

[2009-10-05 17:51:01 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbser.sys

[2009-10-05 17:50:17 | 00,014,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsgXP_2k3.dll

[2009-10-05 17:44:26 | 00,008,320 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdnsuc.sys

[2009-10-05 17:44:25 | 00,136,704 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdnsu.sys

[2009-10-05 17:44:24 | 00,007,808 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\usbser_lowerfltj.sys

[2009-10-05 17:44:23 | 00,007,808 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\usbser_lowerflt.sys

[2009-10-05 17:44:20 | 00,022,016 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmbo.sys

[2009-10-05 17:44:19 | 00,659,968 | ---- | C] (Nokia) -- C:\WINDOWS\System32\nmwcdcocls.dll

[2009-10-05 17:44:19 | 00,017,664 | ---- | C] (Nokia) -- C:\WINDOWS\System32\drivers\ccdcmb.sys

[2009-10-05 17:44:18 | 01,112,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfcoinstaller01007.dll

[2009-10-02 20:22:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\T\Pulpit\Rodzina Soprano S1

[2008-01-01 19:02:20 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnp325.dll

[2008-01-01 19:02:20 | 00,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp325.dll

[2006-03-31 15:02:17 | 00,155,136 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347bus.sys

[2006-03-31 15:02:17 | 00,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\d347prt.sys


[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]


[2009-10-12 19:35:13 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009-10-12 19:35:05 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009-10-12 18:51:48 | 00,000,653 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\Gadu-Gadu.lnk

[2009-10-12 18:17:59 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\HijackThis.lnk

[2009-10-12 18:17:48 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\T\Pulpit\HJTInstall.exe

[2009-10-12 17:23:01 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\T\Pulpit\OTL.exe

[2009-10-12 12:25:26 | 00,110,592 | ---- | M] () -- C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009-10-12 12:25:26 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2009-10-12 11:31:12 | 07,490,206 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\ogolna_9_10_09.pdf

[2009-10-12 11:01:01 | 00,032,768 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\kursinform.doc

[2009-10-11 20:40:11 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009-10-08 21:30:31 | 02,370,127 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\real tone2-dorfmeister_vs._mdla_-_boogie_no_more_(reverso_68_remix).mp3

[2009-10-08 21:25:34 | 02,370,127 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\real tone1-dorfmeister_vs._mdla_-_boogie_no_more_(reverso_68_remix).mp3

[2009-10-07 09:57:31 | 02,732,432 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\spec2007.rtf

[2009-10-06 18:01:00 | 00,028,672 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\Deklaracja(2).xls

[2009-10-06 15:43:08 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2009-10-05 17:50:46 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01007.Wdf

[2009-10-05 17:50:44 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf

[2009-10-05 17:39:43 | 00,001,855 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Nokia Software Updater.lnk

[2009-10-05 17:35:29 | 24,671,032 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\NokiaSoftwareUpdaterSetup_pl.exe

[2009-10-05 17:27:37 | 00,000,680 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\NSS.lnk

[2009-10-04 16:08:22 | 02,713,088 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\BOD.doc

[2009-10-04 11:34:30 | 00,187,540 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\hiszpanska.pdf

[2009-10-04 11:21:45 | 00,018,944 | ---- | M] () -- C:\Documents and Settings\T\Pulpit\stacjonarne.xls

[2009-10-03 22:37:19 | 02,109,058 | -H-- | M] () -- C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\IconCache.db


[color=#E56717]========== Files - No Company Name ==========[/color]

[2009-10-12 18:17:59 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\HijackThis.lnk

[2009-10-12 11:31:10 | 07,490,206 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\ogolna_9_10_09.pdf

[2009-10-12 11:00:59 | 00,032,768 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\kursinform.doc

[2009-10-08 21:30:31 | 02,370,127 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\real tone2-dorfmeister_vs._mdla_-_boogie_no_more_(reverso_68_remix).mp3

[2009-10-08 21:25:33 | 02,370,127 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\real tone1-dorfmeister_vs._mdla_-_boogie_no_more_(reverso_68_remix).mp3

[2009-10-08 21:15:06 | 02,370,127 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\real tone-dorfmeister_vs._mdla_-_boogie_no_more_(reverso_68_remix).mp3

[2009-10-07 09:57:25 | 02,732,432 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\spec2007.rtf

[2009-10-06 18:00:48 | 00,028,672 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\Deklaracja(2).xls

[2009-10-05 17:50:46 | 00,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01007.Wdf

[2009-10-05 17:50:44 | 00,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf

[2009-10-05 17:39:43 | 00,001,855 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Nokia Software Updater.lnk

[2009-10-05 17:34:47 | 24,671,032 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\NokiaSoftwareUpdaterSetup_pl.exe

[2009-10-05 17:27:37 | 00,000,680 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\NSS.lnk

[2009-10-04 11:34:30 | 00,187,540 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\hiszpanska.pdf

[2009-10-04 11:14:24 | 00,018,944 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\stacjonarne.xls

[2009-10-03 11:12:13 | 02,713,088 | ---- | C] () -- C:\Documents and Settings\T\Pulpit\BOD.doc

[2009-07-31 11:28:14 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll

[2009-03-08 15:22:06 | 00,000,380 | ---- | C] () -- C:\WINDOWS\pdf2word.INI

[2009-02-14 13:24:26 | 00,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll

[2009-01-03 19:01:51 | 00,217,088 | ---- | C] () -- C:\WINDOWS\System32\libmySQL.dll

[2009-01-03 19:01:51 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\TrackerNET.dll

[2009-01-01 22:00:45 | 00,000,452 | ---- | C] () -- C:\WINDOWS\SIERRA.INI

[2008-12-30 18:16:12 | 00,147,456 | R--- | C] () -- C:\WINDOWS\System32\ssleay32.dll

[2008-12-30 18:16:11 | 00,651,264 | R--- | C] () -- C:\WINDOWS\System32\libeay32.dll

[2008-10-04 11:58:23 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll

[2008-06-22 09:04:55 | 00,016,031 | ---- | C] () -- C:\Documents and Settings\T\Dane aplikacji\ggconsole.log

[2008-04-18 20:49:28 | 02,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll

[2008-03-01 19:08:26 | 00,000,008 | ---- | C] () -- C:\Documents and Settings\T\Dane aplikacji\NMM-MetaData.db

[2008-02-07 17:07:41 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2008-01-09 13:18:12 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll

[2008-01-09 13:16:10 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest

[2008-01-09 13:16:10 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest

[2007-12-11 21:43:44 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll

[2007-08-30 15:50:52 | 00,114,688 | ---- | C] () -- C:\WINDOWS\System32\WLANUTL.dll

[2007-05-18 22:42:11 | 00,002,528 | ---- | C] () -- C:\Documents and Settings\T\Dane aplikacji\$_hpcst$.hpc

[2007-05-01 13:55:35 | 00,000,083 | ---- | C] () -- C:\WINDOWS\wa.INI

[2007-04-07 21:28:33 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2006-12-28 22:50:24 | 00,000,024 | ---- | C] () -- C:\WINDOWS\ChessGen.ini

[2006-11-29 23:13:44 | 00,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll

[2006-10-27 21:45:25 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI

[2006-08-24 14:59:59 | 00,000,053 | ---- | C] () -- C:\WINDOWS\wininit.ini

[2006-07-27 22:52:56 | 00,000,156 | ---- | C] () -- C:\WINDOWS\PRESTO.INI

[2006-07-27 16:19:59 | 00,000,173 | ---- | C] () -- C:\WINDOWS\ae.INI

[2006-07-27 16:06:42 | 00,001,562 | ---- | C] () -- C:\WINDOWS\psmplay.ini

[2006-06-24 17:54:54 | 00,000,070 | ---- | C] () -- C:\WINDOWS\mmpoly.ini

[2006-06-23 21:59:41 | 00,000,019 | ---- | C] () -- C:\WINDOWS\SoundConverter.INI

[2006-06-21 18:18:05 | 00,001,186 | ---- | C] () -- C:\WINDOWS\cdplayer.ini

[2006-06-09 15:35:43 | 02,109,058 | -H-- | C] () -- C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\IconCache.db

[2006-04-30 14:27:25 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll

[2006-04-30 14:27:25 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll

[2006-04-30 14:27:25 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll

[2006-04-25 09:02:22 | 00,000,149 | ---- | C] () -- C:\WINDOWS\disney.ini

[2006-04-24 20:40:11 | 00,000,052 | ---- | C] () -- C:\WINDOWS\mafosav.INI

[2006-04-06 10:53:19 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2006-03-30 23:50:12 | 00,001,324 | ---- | C] () -- C:\WINDOWS\naglos.INI

[2006-03-30 23:24:57 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll

[2006-03-30 23:01:22 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini

[2006-03-30 22:42:09 | 00,110,592 | ---- | C] () -- C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2006-03-30 21:58:01 | 00,065,104 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinrvxx.sys

[2006-03-30 21:58:01 | 00,060,464 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinbtxx.sys

[2006-03-30 21:58:01 | 00,032,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinraxx.sys

[2006-03-30 21:58:01 | 00,032,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinxsxx.sys

[2006-03-30 21:58:01 | 00,032,320 | ---- | C] () -- C:\WINDOWS\System32\drivers\atintuxx.sys

[2006-03-30 21:58:01 | 00,020,960 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinttxx.sys

[2006-03-30 21:58:01 | 00,011,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinpdxx.sys

[2006-03-30 21:58:01 | 00,011,280 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinmdxx.sys

[2006-03-30 21:56:11 | 00,000,556 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2006-03-30 21:30:59 | 00,071,552 | ---- | C] () -- C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT

[2006-03-30 21:29:32 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\T\Dane aplikacji\desktop.ini

[2005-12-07 13:31:00 | 00,202,752 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll

[2004-08-22 17:04:56 | 00,069,120 | ---- | C] () -- C:\WINDOWS\daemon.dll

[2004-08-04 00:44:00 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll

[2002-06-09 14:07:30 | 00,053,315 | ---- | C] () -- C:\WINDOWS\System32\DevCtrl.dll

[2001-07-21 22:16:20 | 00,001,039 | ---- | C] () -- C:\WINDOWS\win.ini

[2001-07-21 22:15:52 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

[1997-06-14 02:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll


[color=#E56717]========== Alternate Data Streams ==========[/color]


@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:0CE7F3C9

< End of report >

All processes killed

========== OTL ==========

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E85E8F2C-B4CD-1AFC-C1DE-1169347A8C1D}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E85E8F2C-B4CD-1AFC-C1DE-1169347A8C1D}\ deleted successfully.

C:\WINDOWS\System32\dwzsnprabn.dll unregistered successfully.

C:\WINDOWS\System32\dwzsnprabn.dll moved successfully.

C:\Documents and Settings\T\Menu Start\Programy\Autostart\288ABA.lnk moved successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Wireless Adapter Manager deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\rlgrmpxeufljw not found.

File C:\WINDOWS\System32\dwzsnprabn.dll not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\AutoEJCD_0ACE20FF deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{37B85A29-692B-4205-9CAD-2626E4993404} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\ deleted successfully.

C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL unregistered successfully.

C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL moved successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}\ deleted successfully.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{37B85A29-692B-4205-9CAD-2626E4993404} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\ not found.

File C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL not found.

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37B85A21-692B-4205-9CAD-2626E4993404}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}\ not found.

File C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL not found.

DllUnregisterServer procedure not found in C:\Program Files\mozilla firefox\plugins\NPMyGlSh.dll

C:\Program Files\mozilla firefox\plugins\NPMyGlSh.dll NOT unregistered.

C:\Program Files\mozilla firefox\plugins\NPMyGlSh.dll moved successfully.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}\ deleted successfully.

Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}\ not found.

========== FILES ==========

C:\WINDOWS\System32\qdjmohxyxhdk.exe moved successfully.

File\Folder C:\WINDOWS\System32\dwzsnprabn.dll not found.

========== COMMANDS ==========


[EMPTYTEMP]


User: Administrator

->Temp folder emptied: 2250756 bytes

->Temporary Internet Files folder emptied: 453908 bytes


User: All Users


User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes


User: Gość

->Temp folder emptied: 77132 bytes

->Temporary Internet Files folder emptied: 273040 bytes

->Java cache emptied: 1744489 bytes

->FireFox cache emptied: 76623374 bytes


User: LocalService

File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temp\Historia\History.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temp\Cookies\index.dat scheduled to be deleted on reboot.

->Temp folder emptied: 65716 bytes

File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

->Temporary Internet Files folder emptied: 10075796 bytes


User: NetworkService

->Temp folder emptied: 0 bytes

File delete failed. C:\Documents and Settings\NetworkService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

->Temporary Internet Files folder emptied: 103834027 bytes


User: T

File delete failed. C:\Documents and Settings\T\Ustawienia lokalne\Temp\etilqs_Hbl022S8hT3THyGJYSxX scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\T\Ustawienia lokalne\Temp\WCESLog.log scheduled to be deleted on reboot.

->Temp folder emptied: 252984170 bytes

File delete failed. C:\Documents and Settings\T\Ustawienia lokalne\Temporary Internet Files\Content.IE5\3HKCGJJV\getmainbanner[1].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\T\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

->Temporary Internet Files folder emptied: 322549486 bytes

->Java cache emptied: 61158449 bytes

File delete failed. C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\urlclassifier3.sqlite scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\XUL.mfl scheduled to be deleted on reboot.

->FireFox cache emptied: 154502224 bytes


%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 2114584 bytes

%systemroot%\System32 .tmp files removed: 2596 bytes

File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.

File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5a8.dat scheduled to be deleted on reboot.

File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_640.dat scheduled to be deleted on reboot.

Windows Temp folder emptied: 3886714 bytes

RecycleBin emptied: 0 bytes


Total Files Cleaned = 946,61 mb



OTL by OldTimer - Version 3.0.20.0 log created on 10122009_192832


Files\Folders moved on Reboot...

File\Folder C:\Documents and Settings\T\Ustawienia lokalne\Temp\etilqs_Hbl022S8hT3THyGJYSxX not found!

C:\Documents and Settings\T\Ustawienia lokalne\Temp\WCESLog.log moved successfully.

C:\Documents and Settings\T\Ustawienia lokalne\Temporary Internet Files\Content.IE5\3HKCGJJV\getmainbanner[1].htm moved successfully.

C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\Cache\_CACHE_001_ moved successfully.

C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\Cache\_CACHE_002_ moved successfully.

C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\Cache\_CACHE_003_ moved successfully.

C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\Cache\_CACHE_MAP_ moved successfully.

C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\urlclassifier3.sqlite moved successfully.

C:\Documents and Settings\T\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\xa2l30op.default\XUL.mfl moved successfully.

File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.

C:\WINDOWS\temp\Perflib_Perfdata_5a8.dat moved successfully.

File\Folder C:\WINDOWS\temp\Perflib_Perfdata_640.dat not found!


Registry entries deleted on Reboot...

Do Notatnika wklej:

Windows Registry Editor Version 5.00


[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]

"SuperHidden"=dword:00000001


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]

"Hidden"=dword:00000001


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]

"ShowSuperHidden"=dword:00000001


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]

"CheckedValue"=dword:00000001


[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]

@=""


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\shellBrowser]

"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"=-


[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{2E608F70-C430-4BC5-96F6-608E02EBA5B2}"=-

Z Menu Notatnika >> Plik >> Zapisz jako >> Ustaw rozszerzenie na Wszystkie pliki >> Zapisz jako > FIX.REG >>

plik uruchom (dwuklik i OK).

Zrestartuj komputer.

Potem:

W OTL kliknij na przycisk “CleanUp”.

Usuń kopie szkodników z folderu “System Volume Information” poprzez chwilowe wyłączenie “Przywracania Systemu”:

jessi

Postąpiłem zgodnie z Twoim wskazówkami. Oto log z hijackthis

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:37:00, on 2009-10-12

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\WINDOWS\system32\ICO.EXE

C:\WINDOWS\system32\atiptaxx.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Gadu-Gadu\gg.exe

C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

C:\PROGRA~1\MI3AA1~1\rapimgr.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\WZCBDL Service\WZCBDLS.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.mini20.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = w3cache.sgh.waw.pl:8080

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe

O4 - HKLM\..\Run: [Realtime Audio Engine] mmrtkrnl.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [D-Link AirXpert Utility] C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Pobierz wszystkie VIdeo za pomocą BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Pobierz za pomocą BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm

O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra 'Tools' menuitem: Utwórz Ulubione dla urządzenia przenośnego... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199975890363

O17 - HKLM\System\CCS\Services\Tcpip\..\{FCBBECC3-475D-4A83-B3A9-159AE3412790}: NameServer = 153.19.1.254,153.19.250.100

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL

O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe


--

End of file - 9137 bytes

Log już nie był potrzebny - to, co zaleciłam poprzednio, to były czynności kończące całej sprawy.

jessi

Yhym. Dziękuje bardzo w takim razie za pomoc. Masz u mnie kawę :wink: hehehe, pozdro