Skocz do zawartości
dzl

Dziwne zachowanie windowsa XP

Rekomendowane odpowiedzi

Od dwuch ni mój system na starym kompie dziwnie się zachowuję, a wygląda to następująco: po kilku godzinach następuje chwilowe przycinanie kursora myszy po czym uruchomienie jakiejkolwiek aplikacj w tym menadżera użądzeń jest niemożliwe. Czasami także ikony stają się przezroczyste, lub też w me nu start obok ikon nie ma podpisów. Skanowałem system programem Malwarebtes Ant-Malware, a tekże Avast, oba nic nie wykryły. Memtest nie wykazał błędów.

Athlon XP 2600+

1,5 GB ram pc3200 ddr400

Zotac nvidia 7300gt ddr2

Udostępnij tę odpowiedź


Odnośnik do odpowiedzi
Udostępnij na innych stronach

Okazało się, że problem jednak był natury sprzętowej. Wiatraczek na karcie się ułamał i karta graficzna się piekielnie grzała(70C w idle 85 w stresie). Znalazłem dwa wypukłe kondensatory, które od razu wymieniłem. Pozostaje problem chłodzenia karty. Czy na tąDołączona grafika grafikę da się wmontować wentylator 80mm, lub proszę o polecenie chłodzenia do 30zł.

Udostępnij tę odpowiedź


Odnośnik do odpowiedzi
Udostępnij na innych stronach

Ok, przyczepiłem wentylator 80mm i jak dotąd jest dobrze. Temperatura w idle ok 60C( bo w domu jest gorącą) w stresie do 68 przy max obciążenu(specjalnie sprawdzałem w crysisie). Temat można zamknąć. Tak czy inaczej dzięki za chęci. :)

 

EDIT: Jednak problem powrócił zaraz zapodam log z OTL.

Edytowane przez dzl

Udostępnij tę odpowiedź


Odnośnik do odpowiedzi
Udostępnij na innych stronach

Log z OTL

 

OTL logfile created on: 2012-07-02 16:54:23 - Run 1

OTL by OldTimer - Version 3.2.53.0 Folder = C:Documents and SettingsMateuszPulpitProgramy

Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

 

1.50 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 73.50% Memory free

5.48 Gb Paging File | 5.13 Gb Available in Paging File | 93.57% Paging File free

Paging file location(s): C:pagefile.sys 4096 4096 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files

Drive C: | 64.45 Gb Total Space | 47.50 Gb Free Space | 73.70% Space Free | Partition Type: NTFS

Drive D: | 300.00 Gb Total Space | 242.41 Gb Free Space | 80.80% Space Free | Partition Type: NTFS

Drive E: | 250.10 Gb Total Space | 101.58 Gb Free Space | 40.62% Space Free | Partition Type: NTFS

Drive F: | 316.96 Gb Total Space | 139.18 Gb Free Space | 43.91% Space Free | Partition Type: NTFS

 

Computer Name: WELCOMETOHELL66 | User Name: Mateusz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2012-07-01 15:03:06 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:Documents and SettingsMateuszPulpitProgramyOTL.exe

PRC - [2012-06-28 14:51:53 | 000,044,808 | ---- | M] (AVAST Software) -- C:Program FilesAVAST SoftwareAvastAvastSvc.exe

PRC - [2012-06-28 14:51:51 | 004,273,976 | ---- | M] (AVAST Software) -- C:Program FilesAVAST SoftwareAvastAvastUI.exe

PRC - [2012-03-11 23:13:21 | 001,983,232 | ---- | M] (COMODO) -- C:Program FilesCOMODOCOMODO Internet Securitycmdagent.exe

PRC - [2012-03-11 23:13:00 | 006,749,512 | ---- | M] (COMODO) -- C:Program FilesCOMODOCOMODO Internet Securitycfp.exe

PRC - [2010-07-22 14:18:32 | 002,636,800 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditorOscarEditor.exe

PRC - [2009-06-27 17:16:26 | 004,063,232 | ---- | M] (Microsoft Corporation) -- C:WINDOWSexplorer.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2012-07-02 12:53:08 | 001,779,712 | ---- | M] () -- C:Program FilesAVAST SoftwareAvastdefs12070201algo.dll

MOD - [2010-07-22 14:18:32 | 002,636,800 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditorOscarEditor.exe

MOD - [2010-06-01 11:41:38 | 000,098,816 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_MouseDeviceManager.dll

MOD - [2010-05-07 23:05:57 | 000,042,496 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditorDataX7HFormsOSD_TextOSD_Text.dll

MOD - [2010-04-03 11:37:14 | 000,127,488 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_Wheel4D.dll

MOD - [2010-04-03 11:37:09 | 000,094,208 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_ZoomControl.dll

MOD - [2010-04-03 11:37:07 | 000,062,976 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_ScrollbarControl.dll

MOD - [2010-04-03 11:37:02 | 000,069,632 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_AnalyzeGesturesInRight.dll

MOD - [2010-04-03 11:36:58 | 000,069,632 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_AnalyzeGesturesInOne.dll

 

 

========== Win32 Services (SafeList) ==========

 

SRV - File not found [Auto | Stopped] -- C:WINDOWSsystem32wuauserv.dll -- (wuauserv)

SRV - File not found [Auto | Stopped] -- %SYSTEMROOT%system32wscsvc.dll -- (wscsvc)

SRV - File not found [On_Demand | Stopped] -- C:WINDOWSsystem32spoolsv.exe -- (Spooler)

SRV - File not found [Disabled | Stopped] -- C:Program FilesGoogleUpdateGoogleUpdate.exe /medsvc -- (gupdatem) Usługa Google Update (gupdatem)

SRV - File not found [Disabled | Stopped] -- C:Program FilesGoogleUpdateGoogleUpdate.exe /svc -- (gupdate) Usługa Google Update (gupdate)

SRV - File not found [Disabled | Stopped] -- C:Program FilesFuturemarkFuturemark SystemInfoFMSISvc.exe -- (Futuremark SystemInfo Service)

SRV - File not found [Auto | Stopped] -- %SystemRoot%System32ersvc.dll -- (ERSvc)

SRV - File not found [Disabled | Stopped] -- C:WINDOWSMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - File not found [Disabled | Stopped] -- c:WINDOWSMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - File not found [On_Demand | Stopped] -- C:WINDOWSsystem32cisvc.exe -- (CiSvc)

SRV - File not found [Disabled | Stopped] -- C:WINDOWSSystem32alg.exe -- (ALG)

SRV - [2012-07-02 09:31:15 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:WINDOWSsystem32MacromedFlashFlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2012-07-01 18:04:32 | 000,661,600 | ---- | M] (Wellbia.com Co., Ltd.) [On_Demand | Stopped] -- C:WINDOWSsystem32xsherlock.xem -- (xsherlock)

SRV - [2012-06-28 14:51:53 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:Program FilesAVAST SoftwareAvastAvastSvc.exe -- (avast! Antivirus)

SRV - [2012-06-15 00:17:46 | 000,113,120 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:Program FilesMozilla Maintenance Servicemaintenanceservice.exe -- (MozillaMaintenance)

SRV - [2012-05-15 12:40:09 | 000,161,736 | ---- | M] (Oracle Corporation) [Disabled | Stopped] -- C:Program FilesJavajre7binjqs.exe -- (JavaQuickStarterService)

SRV - [2012-04-21 15:17:58 | 000,131,912 | ---- | M] (Desura Pty Ltd) [Disabled | Stopped] -- C:Program FilesCommon FilesDesuradesura_service.exe -- (Desura Install Service)

SRV - [2012-03-11 23:13:21 | 001,983,232 | ---- | M] (COMODO) [Auto | Running] -- C:Program FilesCOMODOCOMODO Internet Securitycmdagent.exe -- (cmdAgent)

SRV - [2011-10-30 19:38:45 | 000,604,488 | ---- | M] (TuneUp Software) [Disabled | Stopped] -- C:WINDOWSsystem32TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)

SRV - [2011-10-30 19:38:34 | 000,361,288 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:WINDOWSsystem32TuneUpDefragService.exe -- (TuneUp.Defrag)

SRV - [2011-05-03 13:18:00 | 004,137,464 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:WINDOWSsystem32GameMon.des -- (npggsvc)

SRV - [2011-03-16 11:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:Program FilesCommon FilesSteamSteamService.exe -- (Steam Client Service)

SRV - [2009-07-15 12:48:20 | 000,029,000 | ---- | M] (TuneUp Software) [Auto | Running] -- C:WINDOWSsystem32uxtuneup.dll -- (UxTuneUp)

SRV - [2007-05-28 18:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Disabled | Stopped] -- C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindServiceAE.exe -- (StarWindServiceAE)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Kernel | On_Demand | Stopped] -- C:WINDOWSxhunter1.sys -- (xhunter1)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:WINDOWSvtany.sys -- (vtany)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgusbmodem.sys -- (USBModem)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgusbdiag.sys -- (UsbDiag)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgusbbus.sys -- (usbbus)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)

DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSpccsmcfd.sys -- (pccsmcfd)

DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)

DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSGenericMount.sys -- (GenericMount)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversEagleXNt.sys -- (EagleXNt)

DRV - File not found [Kernel | System | Stopped] -- -- (Changer)

DRV - File not found [Kernel | On_Demand | Unknown] -- -- (ayoe9igo)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgandmodem.sys -- (ANDModem)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgandgps.sys -- (AndGps)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlganddiag.sys -- (AndDiag)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgandbus.sys -- (Andbus)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSAmdLLD.sys -- (AmdLLD)

DRV - [2012-06-28 14:52:42 | 000,353,688 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:WINDOWSSystem32driversaswSP.sys -- (aswSP)

DRV - [2012-06-28 14:52:42 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:WINDOWSSystem32driversaswTdi.sys -- (aswTdi)

DRV - [2012-06-28 14:52:37 | 000,721,000 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:WINDOWSSystem32driversaswSnx.sys -- (aswSnx)

DRV - [2012-06-28 14:52:37 | 000,097,352 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:WINDOWSSystem32driversaswmon2.sys -- (aswMon2)

DRV - [2012-06-28 14:52:37 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:WINDOWSSystem32driversaswRdr.sys -- (AswRdr)

DRV - [2012-06-28 14:52:36 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:WINDOWSSystem32driversaavmker4.sys -- (Aavmker4)

DRV - [2012-06-28 14:52:36 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:WINDOWSSystem32driversaswFsBlk.sys -- (aswFsBlk)

DRV - [2012-03-11 23:13:46 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversinspect.sys -- (Inspect)

DRV - [2012-03-11 23:13:45 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- C:WINDOWSsystem32driverscmdhlp.sys -- (cmdHlp)

DRV - [2012-03-11 23:13:44 | 000,494,968 | ---- | M] (COMODO) [File_System | System | Running] -- C:WINDOWSsystem32driverscmdGuard.sys -- (cmdGuard)

DRV - [2012-01-23 17:52:28 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:WINDOWSsystem32driverssptd.sys -- (sptd)

DRV - [2011-12-02 17:14:37 | 000,083,872 | ---- | M] () [Kernel | Auto | Running] -- C:WINDOWSsystem32driversatksgt.sys -- (atksgt)

DRV - [2011-12-02 17:14:37 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:WINDOWSsystem32driverslirsgt.sys -- (lirsgt)

DRV - [2011-10-30 20:21:43 | 000,169,472 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:WINDOWSsystem32driverssnapman.sys -- (snapman)

DRV - [2011-10-13 14:06:14 | 000,441,608 | ---- | M] (Paragon) [Kernel | System | Stopped] -- C:WINDOWSsystem32driversUim_IM.sys -- (Uim_IM)

DRV - [2011-10-13 14:06:14 | 000,277,576 | ---- | M] (Paragon) [Kernel | System | Stopped] -- C:WINDOWSsystem32driversUim_Vim.sys -- (Uim_Vim)

DRV - [2011-10-13 14:06:14 | 000,045,240 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | System | Stopped] -- C:WINDOWSsystem32driversUimBus.sys -- (UimBus)

DRV - [2009-12-30 19:56:46 | 000,088,960 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32drivershmumdm.sys -- (MobileAdapter)

DRV - [2009-09-29 08:11:22 | 000,012,160 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driverslgbtport.sys -- (LgBttPort)

DRV - [2009-09-29 08:11:20 | 000,012,928 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driverslgvmodem.sys -- (LGVMODEM)

DRV - [2009-09-29 08:11:20 | 000,010,496 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driverslgbtbus.sys -- (lgbusenum)

DRV - [2009-08-22 20:25:00 | 000,009,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:Program FilesRivaTuner v2.24 MSI Master Overclocking Arena 2009 editionRivaTuner32.sys -- (RivaTuner32)

DRV - [2009-07-05 02:19:05 | 000,062,208 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:WINDOWSSystem32driverssi3112.sys -- (Si3112)

DRV - [2009-07-04 23:08:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversRTL8139.sys -- (rtl8139) Sterownik NT karty Realtek RTL8139(A/B/C)

DRV - [2009-07-04 23:08:24 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driversgameenum.sys -- (gameenum)

DRV - [2008-07-24 00:29:16 | 000,047,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversvserial.sys -- (vserial)

DRV - [2008-07-24 00:29:16 | 000,015,264 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversvsb.sys -- (vsbus)

DRV - [2006-06-16 20:56:38 | 000,083,968 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driversRtnicxp.sys -- (RTL8023xp)

DRV - [2004-08-09 13:33:26 | 000,114,016 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversprohlp02.sys -- (prohlp02)

DRV - [2004-08-09 13:29:28 | 000,053,920 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:WINDOWSsystem32driversprodrv06.sys -- (prodrv06)

DRV - [2004-07-19 16:49:54 | 000,007,040 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversprosync1.sys -- (prosync1)

DRV - [2004-06-03 10:40:46 | 000,079,360 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversnvatabus.sys -- (nvatabus)

DRV - [2004-04-02 15:40:00 | 000,021,760 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversnv_agp.SYS -- (nv_agp)

DRV - [2003-12-01 17:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:WINDOWSsystem32driverssfhlp01.sys -- (sfhlp01)

DRV - [2001-11-28 03:58:18 | 000,001,950 | ---- | M] () [Kernel | System | Unknown] -- C:WINDOWSsystem32driversREGISTER.SYS -- (project)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://pl.v9.com/?utm_source=b&utm_medium=ism

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://pl.v9.com/?utm_source=b&utm_medium=ism

IE - HKLM..SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

 

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://pl.v9.com/?utm_source=b&utm_medium=ism

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://sunonline.webzen.com/Default.aspx

IE - HKCU..SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKCU..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC

IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"

FF - prefs.js..network.proxy.backup.ftp: "212.191.7.144"

FF - prefs.js..network.proxy.backup.ftp_port: 8080

FF - prefs.js..network.proxy.backup.socks: "212.191.7.144"

FF - prefs.js..network.proxy.backup.socks_port: 8080

FF - prefs.js..network.proxy.backup.ssl: "212.191.7.144"

FF - prefs.js..network.proxy.backup.ssl_port: 8080

FF - prefs.js..network.proxy.ftp: "217.98.20.195"

FF - prefs.js..network.proxy.ftp_port: 8080

FF - prefs.js..network.proxy.http: "217.98.20.195"

FF - prefs.js..network.proxy.http_port: 8080

FF - prefs.js..network.proxy.share_proxy_settings: true

FF - prefs.js..network.proxy.socks: "217.98.20.195"

FF - prefs.js..network.proxy.socks_port: 8080

FF - prefs.js..network.proxy.ssl: "217.98.20.195"

FF - prefs.js..network.proxy.ssl_port: 8080

FF - prefs.js..network.proxy.type: 0

 

FF - user.js..browser.search.openintab: false

 

FF - HKLMSoftwareMozillaPlugins@adobe.com/FlashPlayer: C:WINDOWSsystem32MacromedFlashNPSWF32_11_3_300_262.dll ()

FF - HKLMSoftwareMozillaPlugins@adobe.com/ShockwavePlayer: C:WINDOWSsystem32AdobeDirectornp32dsw.dll (Adobe Systems, Inc.)

FF - HKLMSoftwareMozillaPlugins@java.com/DTPlugin,version=10.4.0: C:WINDOWSsystem32npDeployJava1.dll (Oracle Corporation)

FF - HKLMSoftwareMozillaPlugins@java.com/JavaPlugin,version=10.4.0: C:Program FilesJavajre7binplugin2npjp2.dll (Oracle Corporation)

FF - HKLMSoftwareMozillaPlugins@Microsoft.com/NpCtrl,version=1.0: C:Program FilesMicrosoft Silverlight4.0.60831.0npctrl.dll ( Microsoft Corporation)

FF - HKLMSoftwareMozillaPlugins@microsoft.com/OfficeAuthz,version=14.0: C:PROGRA~1Microsoft OfficeOffice14NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLMSoftwareMozillaPlugins@microsoft.com/SharePoint,version=14.0: C:PROGRA~1Microsoft OfficeOffice14NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLMSoftwareMozillaPlugins@real.com/nppl3260;version=6.0.12.69: C:Program FilesReal Alternativebrowserpluginsnppl3260.dll (RealNetworks, Inc.)

FF - HKLMSoftwareMozillaPlugins@real.com/nprpjplug;version=6.0.12.69: C:Program FilesReal Alternativebrowserpluginsnprpjplug.dll (RealNetworks, Inc.)

FF - HKLMSoftwareMozillaPlugins@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKLMSoftwareMozillaPlugins@tools.google.com/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.99npGoogleUpdate3.dll File not found

FF - HKLMSoftwareMozillaPlugins@tools.google.com/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.99npGoogleUpdate3.dll File not found

FF - HKLMSoftwareMozillaPlugins@Webzen.com/NPBrowserExt: C:Program FilesWEBZENBrowserExtensionNPWZCmnCtrl.dll (WEBZEN)

FF - HKCUSoftwareMozillaPlugins@eximion.com/KalydoPlayer: C:Documents and SettingsMateuszDane aplikacjiKalydoKalydoPlayerbin1npkalydo.dll File not found

 

FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxextensionswrc@avast.com: C:Program FilesAVAST SoftwareAvastWebRepFF [2012-06-29 20:17:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 13.0.1extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2012-06-30 13:37:22 | 000,000,000 | ---D | M]

 

[2012-07-01 10:40:36 | 000,000,000 | ---D | M] (No name found) -- C:Documents and SettingsMateuszDane aplikacjiMozillaExtensions

[2012-07-01 12:17:29 | 000,000,000 | ---D | M] (No name found) -- C:Documents and SettingsMateuszDane aplikacjiMozillaFirefoxProfilesmaft7plq.defaultextensions

[2012-07-01 10:41:02 | 000,000,000 | ---D | M] (FT DeepDark) -- C:Documents and SettingsMateuszDane aplikacjiMozillaFirefoxProfilesmaft7plq.defaultextensions{77d2ed30-4cd2-11e0-b8af-0800200c9a66}

[2012-07-01 10:41:02 | 000,000,000 | ---D | M] (DownloadHelper) -- C:Documents and SettingsMateuszDane aplikacjiMozillaFirefoxProfilesmaft7plq.defaultextensions{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

[2012-06-30 13:37:22 | 000,000,000 | ---D | M] (No name found) -- C:Program FilesMozilla Firefoxextensions

[2012-06-08 15:09:36 | 000,052,174 | ---- | M] () (No name found) -- C:DOCUMENTS AND SETTINGSMATEUSZDANE APLIKACJIMOZILLAFIREFOXPROFILESMAFT7PLQ.DEFAULTEXTENSIONSFABTAB@CAPTAINCAVEMAN.NL.XPI

[2012-06-15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:Program Filesmozilla firefoxcomponentsbrowsercomps.dll

[2012-06-15 01:13:23 | 000,002,767 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginsallegro-pl.xml

[2012-06-15 01:13:23 | 000,001,406 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginsfbc-pl.xml

[2012-06-15 01:13:23 | 000,000,917 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginsmerlin-pl.xml

[2012-06-15 01:13:23 | 000,000,858 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginspwn-pl.xml

[2012-06-15 01:13:23 | 000,001,183 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginswikipedia-pl.xml

[2012-06-15 01:13:23 | 000,001,683 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginswp-pl.xml

 

O1 HOSTS File: ([2012-06-26 11:30:12 | 000,000,933 | ---- | M]) - C:WINDOWSsystem32driversetchosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com

O1 - Hosts: 127.0.0.1 www.alcohol-soft.com

O1 - Hosts: 127.0.0.1 images.alcohol-soft.com

O1 - Hosts: 127.0.0.1 trial.alcohol-soft.com

O1 - Hosts: 127.0.0.1 alcohol-soft.com

O1 - Hosts: 0.0.0.0 crl.verisign.com

O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre7binssv.dll (Oracle Corporation)

O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)

O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Program FilesMicrosoft OfficeOffice14URLREDIR.DLL (Microsoft Corporation)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre7binjp2ssv.dll (Oracle Corporation)

O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.

O3 - HKLM..Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)

O4 - HKLM..Run: [avast] C:Program FilesAVAST SoftwareAvastavastUI.exe (AVAST Software)

O4 - HKLM..Run: [COMODO Internet Security] C:Program FilesCOMODOCOMODO Internet Securitycfp.exe (COMODO)

O4 - HKLM..Run: [NvCplDaemon] C:WINDOWSSystem32NvCpl.dll (NVIDIA Corporation)

O4 - HKLM..Run: [RivaTunerStartupDaemon] C:Program FilesRivaTuner v2.24 MSI Master Overclocking Arena 2009 editionRivaTuner.exe ()

O4 - HKCU..Run: [OscarEditor] C:Program FilesAnti-Vibrate Oscar EditorOscarEditor.exe ()

O4 - Startup: C:Documents and SettingsMateuszMenu StartProgramyAutostartETERNA.lnk = File not found

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDesktopCleanupWizard = 1

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: HonorAutoRunSetting = 1

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: NoInternetOpenWith = 1

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: DisableStatusMessages = 1

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: VerboseStatus = 0

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoSMMyPictures = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoSMConfigurePrograms = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoSMHelp = 0

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoLowDiskSpaceChecks = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoResolveTrack = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: LinkResolveIgnoreLinkInfo = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoResolveSearch = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863

O8 - Extra context menu item: Se&nd to OneNote - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)

O13 - gopher Prefix: missing

O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{B2C8C128-573B-4A6F-B54E-7B85E4C706DE}: NameServer = 194.204.159.1 194.204.152.34

O20 - AppInit_DLLs: (C:WINDOWSsystem32wbsys.dll) - C:WINDOWSsystem32wbsys.dll (Stardock.Net, Inc)

O20 - AppInit_DLLs: (C:WINDOWSsystem32guard32.dll) - C:WINDOWSsystem32guard32.dll (COMODO)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:WINDOWSexplorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:WINDOWSsystem32userinit.exe) - C:WINDOWSsystem32userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UIHost - (C:Documents and SettingsAll UsersDane aplikacjiTuneUp SoftwareTuneUp UtilitiesWinStylertu_logonui.exe) - C:Documents and SettingsAll UsersDane aplikacjiTuneUp SoftwareTuneUp UtilitiesWinStylertu_logonui.exe (Microsoft Corporation)

O20 - WinlogonNotifyAtiExtEvent: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found

O20 - WinlogonNotifyWBSrv: DllName - (C:Program FilesStardockObject DesktopWindowBlindswbsrv.dll) - File not found

O22 - SharedTaskScheduler: {1984D045-52CF-49cd-DB77-08F378FEA4DB} - ObjectDockShellExt - No CLSID value found.

O24 - Desktop Components:0 (Bieżąca strona główna) - About:Home

O24 - Desktop WallPaper: C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp

O24 - Desktop BackupWallPaper: C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2011-10-30 18:37:54 | 000,000,000 | ---- | M] () - C:AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2{ef1c13d8-0c8c-11e1-93c4-00138fdb5109}ShellAutoRuncommand - "" = G:InstallTomTomHOME.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM..comfile [open] -- "%1" %*

O35 - HKLM..exefile [open] -- "%1" %*

O37 - HKLM...com [@ = comfile] -- "%1" %*

O37 - HKLM...exe [@ = exefile] -- "%1" %*

O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2012-07-02 16:50:22 | 000,000,000 | -HSD | C] -- C:Documents and SettingsMateuszRecent

[2012-07-02 15:28:59 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersMenu StartProgramyGOM Player

[2012-07-01 18:04:32 | 000,661,600 | ---- | C] (Wellbia.com Co., Ltd.) -- C:WINDOWSSystem32xsherlock.xem

[2012-07-01 16:55:09 | 000,230,920 | ---- | C] (WEBZEN, INC.) -- C:WINDOWSSystem32EPWZCmnCtrl.dll

[2012-07-01 16:55:08 | 000,000,000 | ---D | C] -- C:Program FilesWEBZEN

[2012-07-01 16:54:58 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersDane aplikacjiWEBZEN

[2012-07-01 15:08:02 | 000,518,144 | ---- | C] (SteelWerX) -- C:WINDOWSSWREG.exe

[2012-07-01 15:08:02 | 000,406,528 | ---- | C] (SteelWerX) -- C:WINDOWSSWSC.exe

[2012-07-01 15:08:02 | 000,212,480 | ---- | C] (SteelWerX) -- C:WINDOWSSWXCACLS.exe

[2012-07-01 15:07:19 | 000,000,000 | ---D | C] -- C:WINDOWSerdnt

[2012-07-01 13:53:40 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyKONAMI

[2012-07-01 11:10:51 | 000,000,000 | ---D | C] -- C:WINDOWSSystem32AGEIA

[2012-07-01 11:10:50 | 000,000,000 | ---D | C] -- C:Program FilesAGEIA Technologies

[2012-07-01 10:40:33 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjiMozilla

[2012-06-30 20:55:19 | 000,000,000 | ---D | C] -- C:Program FilesUbisoft

[2012-06-30 20:20:30 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyNBA LIVE 08

[2012-06-30 19:55:43 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyChillstream

[2012-06-30 19:11:19 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersDane aplikacjiWindows Genuine Advantage

[2012-06-30 18:39:56 | 001,112,288 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32WdfCoInstaller01007.dll

[2012-06-30 18:39:55 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersMenu StartProgramyMicrosoft Xbox 360 Accessories

[2012-06-30 18:39:54 | 000,000,000 | ---D | C] -- C:Program FilesMicrosoft Xbox 360 Accessories

[2012-06-30 13:37:24 | 000,000,000 | ---D | C] -- C:Program FilesMozilla Maintenance Service

[2012-06-30 13:37:19 | 000,000,000 | ---D | C] -- C:Program FilesMozilla Firefox

[2012-06-30 11:45:03 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyMount&Blade Warband Savegames

[2012-06-30 11:43:57 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjiMount&Blade Warband

[2012-06-30 11:43:49 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyMount&Blade Warband

[2012-06-30 11:29:53 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyMount&Blade With Fire and Sword

[2012-06-30 11:29:53 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjiMount&Blade With Fire and Sword

[2012-06-29 22:53:35 | 004,137,464 | ---- | C] (INCA Internet Co., Ltd.) -- C:WINDOWSSystem32GameMon.des

[2012-06-29 22:49:11 | 000,004,682 | ---- | C] (INCA Internet Co., Ltd.) -- C:WINDOWSSystem32npptNT2.sys

[2012-06-29 22:48:18 | 000,000,000 | ---D | C] -- C:Program FilesCommon FilesINCA Shared

[2012-06-29 19:18:49 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyTom Clancy's H.A.W.X

[2012-06-29 16:29:00 | 003,563,520 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32physxcore.dll

[2012-06-29 16:29:00 | 000,057,856 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32physxloader.dll

[2012-06-29 16:28:52 | 000,387,072 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32physxcooking.dll

[2012-06-28 17:44:38 | 000,000,000 | ---D | C] -- C:WINDOWSPerformance

[2012-06-28 17:44:29 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiMicrosoft Corporation

[2012-06-28 14:45:10 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjiRovio

[2012-06-28 13:41:56 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiDeployment

[2012-06-28 10:13:07 | 000,013,824 | ---- | C] (Loghain) -- C:Documents and SettingsMateuszMoje dokumentygiveme2entitlements_v2.exe

[2012-06-27 18:09:06 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyOpenLieroX

[2012-06-27 16:04:36 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32msconfig.exe

[2012-06-26 16:58:01 | 000,000,000 | ---D | C] -- C:WINDOWSSxsCaPendDel

[2012-06-26 09:03:02 | 000,000,000 | ---D | C] -- C:WINDOWSusgwmt

[2012-06-22 14:42:50 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyDragon age save editor

[2012-06-22 10:11:27 | 000,000,000 | ---D | C] -- C:Program FilesOrigin Games

[2012-06-22 10:11:25 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiOrigin

[2012-06-22 10:03:11 | 000,000,000 | ---D | C] -- C:Program FilesOrigin

[2012-06-21 14:34:16 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMenu StartProgramyRevo Uninstaller

[2012-06-19 10:50:19 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjicom.bwsf.DragonAgeLegends

[2012-06-19 10:14:31 | 000,000,000 | ---D | C] -- C:Program FilesCommon FilesAdobe AIR

[2012-06-18 17:14:44 | 000,000,000 | ---D | C] -- C:Program FilesNVIDIA Corporation

[2012-06-18 17:09:37 | 014,757,888 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvoglnt.dll

[2012-06-18 17:09:37 | 002,646,632 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvcuvenc.dll

[2012-06-18 17:09:37 | 000,061,440 | ---- | C] (Khronos Group) -- C:WINDOWSSystem32OpenCL.dll

[2012-06-18 17:09:35 | 011,647,592 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvcompiler.dll

[2012-06-18 17:09:35 | 006,432,128 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nv4_disp.dll

[2012-06-18 17:09:35 | 001,097,728 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvapi.dll

[2012-06-18 17:09:35 | 000,227,944 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvcodins.dll

[2012-06-18 17:09:35 | 000,227,944 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvcod.dll

[2012-06-18 14:30:37 | 000,000,000 | ---D | C] -- C:Program FilesSystemRequirementsLab

[2012-06-17 12:54:04 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll Usersdocuments

[2012-06-14 13:08:55 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersDokumentystalker-stcs

[2012-06-14 13:00:18 | 000,000,000 | ---D | C] -- C:Program FilesAnti-Vibrate Oscar Editor

[2012-06-13 15:32:24 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentySquare Enix

[2012-06-13 15:32:11 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacji119615131254924532

[2012-06-13 15:32:01 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacji119611918619387124

[2012-06-13 11:08:14 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMenu StartProgramyMultimedia Keyboard Driver

[2012-06-13 11:08:00 | 000,000,000 | ---D | C] -- C:Program FilesMultimedia Keyboard Driver

[2012-06-13 08:31:02 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjiTropico 3

[2012-06-09 15:11:50 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyWBGames

[2012-06-09 13:18:30 | 000,000,000 | ---D | C] -- C:Program FilesLG Electronics

[2012-06-09 10:02:56 | 000,000,000 | ---D | C] -- C:Program FilesblueMSX

[2012-06-07 18:22:14 | 000,000,000 | ---D | C] -- C:Program FilesparticleIllusion_3

[2012-06-07 11:45:50 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjistorage

[2012-06-05 19:42:53 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersPulpit

[8 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]

[5 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]

[2 C:Program Files*.tmp files -> C:Program Files*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2012-07-02 16:51:23 | 000,280,403 | ---- | M] () -- C:WINDOWSSystem32NvApps.xml

[2012-07-02 16:51:18 | 000,002,048 | --S- | M] () -- C:WINDOWSbootstat.dat

[2012-07-02 16:38:00 | 000,000,930 | ---- | M] () -- C:WINDOWStasksAdobe Flash Player Updater.job

[2012-07-02 12:46:29 | 000,000,664 | ---- | M] () -- C:WINDOWSSystem32d3d9caps.dat

[2012-07-02 09:31:15 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:WINDOWSSystem32FlashPlayerApp.exe

[2012-07-02 09:31:15 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:WINDOWSSystem32FlashPlayerCPLApp.cpl

[2012-07-02 09:12:43 | 000,000,552 | ---- | M] () -- C:WINDOWSSystem32d3d8caps.dat

[2012-07-01 18:04:32 | 000,661,600 | ---- | M] (Wellbia.com Co., Ltd.) -- C:WINDOWSSystem32xsherlock.xem

[2012-07-01 15:42:05 | 000,000,223 | RHS- | M] () -- C:boot.ini

[2012-07-01 13:14:02 | 000,015,412 | ---- | M] () -- C:WINDOWSSystem32BReWErS.dll

[2012-07-01 13:14:00 | 000,003,386 | ---- | M] () -- C:WINDOWSSystem32NOTEPAD.ini

[2012-07-01 10:40:21 | 000,000,448 | ---- | M] () -- C:Documents and SettingsMateuszMoje dokumentyremember password.URL

[2012-06-30 19:11:23 | 000,002,206 | ---- | M] () -- C:WINDOWSSystem32wpa.dbl

[2012-06-30 18:40:40 | 000,000,000 | -H-- | M] () -- C:WINDOWSSystem32driversMsft_Kernel_xusb21_01007.Wdf

[2012-06-29 20:25:58 | 000,216,856 | ---- | M] () -- C:WINDOWSSystem32FNTCACHE.DAT

[2012-06-29 20:17:51 | 000,002,657 | ---- | M] () -- C:WINDOWSSystem32CONFIG.NT

[2012-06-28 15:02:25 | 000,002,601 | ---- | M] () -- C:Documents and SettingsAll UsersDokumentyGlobal.sw2

[2012-06-28 14:52:42 | 000,353,688 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswSP.sys

[2012-06-28 14:52:42 | 000,054,232 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswTdi.sys

[2012-06-28 14:52:37 | 000,721,000 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswSnx.sys

[2012-06-28 14:52:37 | 000,097,352 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswmon2.sys

[2012-06-28 14:52:37 | 000,089,624 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswmon.sys

[2012-06-28 14:52:37 | 000,035,928 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswRdr.sys

[2012-06-28 14:52:36 | 000,025,256 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaavmker4.sys

[2012-06-28 14:52:36 | 000,021,256 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswFsBlk.sys

[2012-06-28 14:52:20 | 000,041,224 | ---- | M] (AVAST Software) -- C:WINDOWSavastSS.scr

[2012-06-28 14:51:49 | 000,227,648 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32aswBoot.exe

[2012-06-26 16:13:57 | 000,053,044 | ---- | M] () -- C:Documents and SettingsMateusz.recently-used.xbel

[2012-06-26 15:38:00 | 000,000,023 | ---- | M] () -- C:WINDOWSBlendSettings.ini

[2012-06-23 17:15:51 | 000,000,438 | ---- | M] () -- C:WINDOWStasksKonserwacja 1 kliknięciem.job

[2012-06-22 10:03:18 | 000,000,661 | ---- | M] () -- C:Documents and SettingsAll UsersPulpitOrigin.lnk

[2012-06-21 14:49:13 | 022,954,388 | ---- | M] () -- C:Documents and SettingsMateuszMoje dokumentyFirefox 13.0.1 (pl) - 2012-06-21.pcv

[2012-06-18 16:35:59 | 140,259,328 | ---- | M] () -- C:WINDOWSMEMORY.DMP

[2012-06-18 15:19:36 | 000,563,636 | ---- | M] () -- C:WINDOWSSystem32perfh015.dat

[2012-06-18 15:19:36 | 000,501,072 | ---- | M] () -- C:WINDOWSSystem32perfh009.dat

[2012-06-18 15:19:36 | 000,109,070 | ---- | M] () -- C:WINDOWSSystem32perfc015.dat

[2012-06-18 15:19:36 | 000,087,420 | ---- | M] () -- C:WINDOWSSystem32perfc009.dat

[2012-06-18 08:31:33 | 000,000,202 | ---- | M] () -- C:WINDOWSNeroDigital.ini

[2012-06-14 11:04:15 | 000,003,083 | ---- | M] () -- C:Documents and SettingsMateuszMoje dokumentyresetdma.vbs

[2012-06-09 14:22:09 | 000,002,413 | ---- | M] () -- C:WINDOWSSystem32lgAxconfig.ini

[2012-06-07 18:25:22 | 021,145,805 | ---- | M] () -- C:Documents and SettingsMateuszMoje dokumentyFirefox 13.0 (pl) - 2012-06-07.pcv

[8 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]

[5 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]

[2 C:Program Files*.tmp files -> C:Program Files*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2012-07-02 09:12:43 | 000,000,552 | ---- | C] () -- C:WINDOWSSystem32d3d8caps.dat

[2012-07-01 15:08:03 | 000,208,896 | ---- | C] () -- C:WINDOWSMBR.exe

[2012-07-01 15:08:02 | 000,256,000 | ---- | C] () -- C:WINDOWSPEV.exe

[2012-07-01 15:08:02 | 000,098,816 | ---- | C] () -- C:WINDOWSsed.exe

[2012-07-01 15:08:02 | 000,080,412 | ---- | C] () -- C:WINDOWSgrep.exe

[2012-07-01 15:08:02 | 000,068,096 | ---- | C] () -- C:WINDOWSzip.exe

[2012-07-01 10:40:21 | 000,000,448 | ---- | C] () -- C:Documents and SettingsMateuszMoje dokumentyremember password.URL

[2012-06-30 18:40:40 | 000,000,000 | -H-- | C] () -- C:WINDOWSSystem32driversMsft_Kernel_xusb21_01007.Wdf

[2012-06-30 13:37:24 | 000,000,743 | ---- | C] () -- C:Documents and SettingsAll UsersMenu StartProgramyMozilla Firefox.lnk

[2012-06-29 22:49:11 | 000,005,174 | ---- | C] () -- C:WINDOWSSystem32nppt9x.vxd

[2012-06-26 16:13:57 | 000,053,044 | ---- | C] () -- C:Documents and SettingsMateusz.recently-used.xbel

[2012-06-22 10:03:18 | 000,000,661 | ---- | C] () -- C:Documents and SettingsAll UsersPulpitOrigin.lnk

[2012-06-21 14:48:47 | 022,954,388 | ---- | C] () -- C:Documents and SettingsMateuszMoje dokumentyFirefox 13.0.1 (pl) - 2012-06-21.pcv

[2012-06-18 17:09:35 | 002,183,470 | ---- | C] () -- C:WINDOWSSystem32nvdata.bin

[2012-06-17 16:56:16 | 000,112,688 | ---- | C] () -- C:WINDOWSSystem32SH31W32.DLL

[2012-06-16 18:00:47 | 000,009,046 | ---- | C] () -- C:WINDOWSSystem32nvinfo.pb

[2012-06-16 17:18:59 | 000,001,950 | ---- | C] () -- C:WINDOWSSystem32driversREGISTER.SYS

[2012-06-14 11:04:14 | 000,003,083 | ---- | C] () -- C:Documents and SettingsMateuszMoje dokumentyresetdma.vbs

[2012-06-07 18:24:59 | 021,145,805 | ---- | C] () -- C:Documents and SettingsMateuszMoje dokumentyFirefox 13.0 (pl) - 2012-06-07.pcv

[2012-05-20 20:07:34 | 000,034,678 | ---- | C] () -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjirecently-used.xbel

[2012-05-13 16:15:37 | 000,233,472 | ---- | C] () -- C:WINDOWSSystem32cmirmdrv.exe

[2012-05-13 16:15:36 | 000,028,672 | ---- | C] () -- C:WINDOWSSystem32cmirmdrv.dll

[2012-05-13 16:15:35 | 000,136,302 | ---- | C] () -- C:WINDOWSCmuda.ini

[2012-05-13 16:15:34 | 000,225,280 | ---- | C] () -- C:WINDOWSCmiRmRedundDir.exe

[2012-05-12 21:53:12 | 000,000,736 | ---- | C] () -- C:WINDOWSsetup.ini

[2012-05-01 10:36:45 | 000,000,025 | ---- | C] () -- C:WINDOWSpopcinfot.dat

[2012-04-26 19:17:13 | 000,000,016 | ---- | C] () -- C:WINDOWSSystem32msvcsv60.dll

[2012-04-26 19:17:13 | 000,000,016 | ---- | C] () -- C:WINDOWSmsocreg32.dat

[2012-04-24 18:38:03 | 000,000,857 | ---- | C] () -- C:WINDOWSclient.config.ini

[2012-04-17 12:58:55 | 000,043,520 | ---- | C] () -- C:WINDOWSSystem32CmdLineExt03.dll

[2012-04-17 11:32:28 | 000,000,077 | ---- | C] () -- C:Documents and SettingsMateuszDane aplikacjimainhst.zgh

[2012-04-02 18:33:14 | 000,064,918 | ---- | C] () -- C:Documents and SettingsMateuszKLR320 Bloody Justice.png

[2012-02-17 16:31:46 | 000,000,414 | RHS- | C] () -- C:Documents and SettingsAll Usersntuser.pol

[2012-02-16 13:06:14 | 000,138,904 | ---- | C] () -- C:Documents and SettingsMateuszDane aplikacjiPnkBstrK.sys

[2012-02-08 11:17:17 | 000,000,537 | ---- | C] () -- C:WINDOWSFICEDULA.INI

[2012-02-05 17:56:50 | 000,000,128 | R--- | C] () -- C:Documents and SettingsMateuszValid.Ext

[2012-01-28 19:15:37 | 000,074,752 | ---- | C] () -- C:WINDOWSSystem32ff_vfw.dll

[2012-01-27 17:35:31 | 000,053,248 | ---- | C] () -- C:WINDOWSSystem32CommonDL.dll

[2012-01-27 17:35:31 | 000,002,413 | ---- | C] () -- C:WINDOWSSystem32lgAxconfig.ini

[2012-01-19 20:45:06 | 000,000,041 | ---- | C] () -- C:WINDOWSlz_tcm.ini

[2012-01-11 17:16:05 | 000,000,057 | ---- | C] () -- C:WINDOWSnfsc_patch.ini

[2012-01-01 19:39:44 | 000,516,096 | ---- | C] () -- C:WINDOWSSystem32VTFLib.dll

[2011-12-27 12:35:35 | 000,000,202 | ---- | C] () -- C:WINDOWSNeroDigital.ini

[2011-12-26 20:28:00 | 000,122,880 | ---- | C] () -- C:WINDOWSUnGins.exe

[2011-12-19 19:28:55 | 000,000,000 | ---- | C] () -- C:WINDOWSWB.ini

[2011-12-07 15:36:39 | 000,015,412 | ---- | C] () -- C:WINDOWSSystem32BReWErS.dll

[2011-12-05 12:14:08 | 000,000,001 | ---- | C] () -- C:Documents and SettingsMateuszSI.bin

[2011-12-01 19:56:42 | 000,083,872 | ---- | C] () -- C:WINDOWSSystem32driversatksgt.sys

[2011-12-01 19:56:42 | 000,025,888 | ---- | C] () -- C:WINDOWSSystem32driverslirsgt.sys

[2011-11-25 21:30:10 | 000,004,096 | ---- | C] () -- C:WINDOWSd3dx.dat

[2011-11-18 13:39:21 | 000,000,001 | ---- | C] () -- C:Documents and SettingsAll UsersDane aplikacjiflagposition.out

[2011-11-17 11:04:21 | 000,354,816 | ---- | C] () -- C:WINDOWSSystem32psisdecd.dll

[2011-11-14 13:49:39 | 000,000,155 | ---- | C] () -- C:WINDOWSwinamp.ini

[2011-11-14 10:45:16 | 000,000,056 | RHS- | C] () -- C:WINDOWSSystem320D4F86FFD5.sys

[2011-11-14 10:43:20 | 000,001,890 | -HS- | C] () -- C:WINDOWSSystem32KGyGaAvL.sys

[2011-11-09 21:17:49 | 000,175,616 | ---- | C] () -- C:WINDOWSSystem32unrar.dll

[2011-11-08 11:49:22 | 000,000,001 | ---- | C] () -- C:WINDOWSSystem32SI.bin

[2011-11-07 11:24:27 | 000,075,264 | ---- | C] () -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011-11-06 17:56:48 | 000,000,000 | ---- | C] () -- C:WINDOWSPowerReg.dat

[2011-11-05 12:00:13 | 000,000,132 | ---- | C] () -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjifusioncache.dat

[2011-11-02 13:35:27 | 000,000,088 | ---- | C] () -- C:WINDOWSStyleBuilder.INI

[2011-10-30 21:03:32 | 000,000,023 | ---- | C] () -- C:WINDOWSBlendSettings.ini

[2011-10-30 19:34:21 | 000,000,092 | ---- | C] () -- C:WINDOWSCMISETUP.INI

[2011-10-30 19:34:19 | 000,000,026 | ---- | C] () -- C:WINDOWSCMCDPLAY.INI

[2011-10-30 19:34:18 | 000,000,010 | ---- | C] () -- C:WINDOWSWininit.ini

[2011-10-30 19:34:17 | 000,266,240 | ---- | C] () -- C:WINDOWSCMIUninstall.exe

[2011-10-30 19:34:17 | 000,028,672 | ---- | C] () -- C:WINDOWSCMIRmDriver.dll

[2011-10-30 19:30:33 | 000,003,386 | ---- | C] () -- C:WINDOWSSystem32NOTEPAD.ini

[2011-10-30 19:27:13 | 000,004,293 | ---- | C] () -- C:WINDOWSODBCINST.INI

[2011-10-30 19:26:52 | 000,283,648 | ---- | C] () -- C:WINDOWSNOTEPAD.EXE

[2011-10-30 19:25:50 | 000,216,856 | ---- | C] () -- C:WINDOWSSystem32FNTCACHE.DAT

[2011-10-30 19:24:57 | 000,244,224 | ---- | C] () -- C:WINDOWSSystem32NvRaidMan.exe

[2011-10-30 19:10:00 | 000,000,664 | ---- | C] () -- C:WINDOWSSystem32d3d9caps.dat

[2011-10-30 18:51:46 | 000,002,048 | --S- | C] () -- C:WINDOWSbootstat.dat

[2011-10-30 18:40:06 | 000,000,047 | ---- | C] () -- C:WINDOWSTransBar.ini

[2011-10-30 18:37:59 | 000,652,287 | ---- | C] () -- C:WINDOWSNowe_konto.exe

[2011-10-30 18:34:32 | 000,021,856 | ---- | C] () -- C:WINDOWSSystem32emptyregdb.dat

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 5120 bytes -> C:Documents and SettingsAll UsersDane aplikacjidesktop.ini:gs5sys

@Alternate Data Stream - 48 bytes -> C:Documents and SettingsAll UsersDRM:احتضان

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszSzablony:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszPulpit:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszMoje dokumenty:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszDane aplikacjidesktop.ini:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszCookies:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsAll UsersSzablony:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsAll UsersDokumentydesktop.ini:gs5sys

@Alternate Data Stream - 129 bytes -> C:Documents and SettingsAll UsersDane aplikacjiTEMP:05EE1EEF

@Alternate Data Stream - 123 bytes -> C:Documents and SettingsAll UsersDane aplikacjiTEMP:8CE646EE

@Alternate Data Stream - 121 bytes -> C:Documents and SettingsAll UsersDane aplikacjiTEMP:C31F31E6

@Alternate Data Stream - 118 bytes -> C:Documents and SettingsAll UsersDane aplikacjiTEMP:D06A4C76

 

< End of report >

 

 

 

 

Log z HIJACKTHIS

 

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 17:05:46, on 2012-07-02

Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)

MSIE: Unable to get Internet Explorer version!

Boot mode: Normal

 

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesCOMODOCOMODO Internet Securitycmdagent.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesAVAST SoftwareAvastAvastSvc.exe

C:WINDOWSExplorer.EXE

C:Program FilesCOMODOCOMODO Internet Securitycfp.exe

C:Program FilesAVAST SoftwareAvastavastUI.exe

C:Program FilesMicrosoft Xbox 360 AccessoriesXboxStat.exe

C:Program FilesAnti-Vibrate Oscar EditorOscarEditor.exe

C:WINDOWSnotepad.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:WINDOWSsystem32msiexec.exe

C:Program FilesTrend MicroHiJackThisHiJackThis.exe

 

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://pl.v9.com/?utm_source=b&utm_medium=ism

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://sunonline.webzen.com/Default.aspx

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://pl.v9.com/?utm_source=b&utm_medium=ism

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://pl.v9.com/?utm_source=b&utm_medium=ism

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre7binssv.dll

O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:PROGRA~1Microsoft OfficeOffice14URLREDIR.DLL

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre7binjp2ssv.dll

O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - (no file)

O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll

O4 - HKLM..Run: [COMODO Internet Security] "C:Program FilesCOMODOCOMODO Internet Securitycfp.exe" -h

O4 - HKLM..Run: [avast] "C:Program FilesAVAST SoftwareAvastavastUI.exe" /nogui

O4 - HKLM..Run: [RivaTunerStartupDaemon] "C:Program FilesRivaTuner v2.24 MSI Master Overclocking Arena 2009 editionRivaTuner.exe" /S

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [XboxStat] "C:Program FilesMicrosoft Xbox 360 AccessoriesXboxStat.exe" silentrun

O4 - HKCU..Run: [OscarEditor] "C:Program FilesAnti-Vibrate Oscar EditorOscarEditor.exe" Minimum

O4 - HKUSS-1-5-18..Run: [TransBar] C:WINDOWSTransBar.exe /s (User 'SYSTEM')

O4 - HKUSS-1-5-18..RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

O4 - HKUS.DEFAULT..Run: [TransBar] C:WINDOWSTransBar.exe /s (User 'Default user')

O4 - HKUS.DEFAULT..RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O4 - S-1-5-18 Startup: ETERNA.lnk = ? (User 'SYSTEM')

O4 - .DEFAULT Startup: ETERNA.lnk = ? (User 'Default user')

O4 - Startup: ETERNA.lnk = ?

O8 - Extra context menu item: Se&nd to OneNote - res://C:PROGRA~1Microsoft OfficeOffice14ONBttnIE.dll/105

O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll

O9 - Extra button: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe

O17 - HKLMSystemCCSServicesTcpip..{B2C8C128-573B-4A6F-B54E-7B85E4C706DE}: NameServer = 194.204.159.1 194.204.152.34

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:Program FilesCommon FilesMicrosoft SharedOFFICE14MSOXMLMF.DLL

O20 - AppInit_DLLs: C:WINDOWSsystem32wbsys.dll C:WINDOWSsystem32guard32.dll

O22 - SharedTaskScheduler: Moduł wstępnego ładowania interfejsu Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:WINDOWSsystem32browseui.dll

O22 - SharedTaskScheduler: Demon buforu kategorii składników - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:WINDOWSsystem32browseui.dll

O22 - SharedTaskScheduler: ObjectDockShellExt - {1984D045-52CF-49cd-DB77-08F378FEA4DB} - (no file)

O23 - Service: avast! Antivirus - AVAST Software - C:Program FilesAVAST SoftwareAvastAvastSvc.exe

O23 - Service: CiSvc - Unknown owner - C:WINDOWSsystem32cisvc.exe (file missing)

O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:Program FilesCOMODOCOMODO Internet Securitycmdagent.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:WINDOWSsystem32GameMon.des.exe (file missing)

O23 - Service: Bufor wydruku (Spooler) - Unknown owner - C:WINDOWSsystem32spoolsv.exe (file missing)

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:WINDOWSSystem32TuneUpDefragService.exe

O23 - Service: xsherlock - Wellbia.com Co., Ltd. - C:WINDOWSsystem32xsherlock.xem

 

--

End of file - 6527 bytes

 

 

 

Udostępnij tę odpowiedź


Odnośnik do odpowiedzi
Udostępnij na innych stronach

Daj extras.txt z OTL zamiast bezuzytecznego hjt.

 

Sam popsules te wszystkie uslugi czy moze masz jakis modyfikowany system?

 

Wykonaj skrypt w OTL:

 

:OTL

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://pl.v9.com/?ut...&utm_medium=ism

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://pl.v9.com/?ut...&utm_medium=ism

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://pl.v9.com/?ut...&utm_medium=ism

O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.

O4 - Startup: C:Documents and SettingsMateuszMenu StartProgramyAutostartETERNA.lnk = File not found

O20 - WinlogonNotifyAtiExtEvent: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found

@Alternate Data Stream - 5120 bytes -> C:Documents and SettingsAll UsersDane aplikacjidesktop.ini:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszSzablony:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszPulpit:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszMoje dokumenty:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszDane aplikacjidesktop.ini:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszCookies:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsAll UsersSzablony:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsAll UsersDokumentydesktop.ini:gs5sys

 

:Commands

[emptytemp]

 

Zrob skan przy pomocy mbam oraz cureit.

 

Jezeli nic sie nie zmieni to odinstaluj:

AVAST Software

COMODO

WinStyler

Stardock Object Desktop (WindowBlinds)

 

Po jednym, nastepnie sprawdzaj czy cos sie zmienia.

Edytowane przez Kolobos

Udostępnij tę odpowiedź


Odnośnik do odpowiedzi
Udostępnij na innych stronach

Świeże logi

OTL

 

OTL logfile created on: 2012-07-03 11:48:35 - Run 1

OTL by OldTimer - Version 3.2.53.1 Folder = C:Documents and SettingsMateuszPulpitProgramy

Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

 

1.50 Gb Total Physical Memory | 0.82 Gb Available Physical Memory | 54.37% Memory free

5.48 Gb Paging File | 4.82 Gb Available in Paging File | 87.92% Paging File free

Paging file location(s): C:pagefile.sys 4096 4096 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files

Drive C: | 64.45 Gb Total Space | 47.25 Gb Free Space | 73.30% Space Free | Partition Type: NTFS

Drive D: | 300.00 Gb Total Space | 237.98 Gb Free Space | 79.33% Space Free | Partition Type: NTFS

Drive E: | 250.10 Gb Total Space | 99.56 Gb Free Space | 39.81% Space Free | Partition Type: NTFS

Drive F: | 316.96 Gb Total Space | 191.65 Gb Free Space | 60.47% Space Free | Partition Type: NTFS

 

Computer Name: WELCOMETOHELL66 | User Name: Mateusz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2012-07-03 09:31:16 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:Documents and SettingsMateuszPulpitProgramyOTL.exe

PRC - [2012-06-28 14:51:53 | 000,044,808 | ---- | M] (AVAST Software) -- C:Program FilesAVAST SoftwareAvastAvastSvc.exe

PRC - [2012-06-28 14:51:51 | 004,273,976 | ---- | M] (AVAST Software) -- C:Program FilesAVAST SoftwareAvastAvastUI.exe

PRC - [2012-06-15 00:17:36 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:Program FilesMozilla Firefoxfirefox.exe

PRC - [2012-03-11 23:13:21 | 001,983,232 | ---- | M] (COMODO) -- C:Program FilesCOMODOCOMODO Internet Securitycmdagent.exe

PRC - [2012-03-11 23:13:00 | 006,749,512 | ---- | M] (COMODO) -- C:Program FilesCOMODOCOMODO Internet Securitycfp.exe

PRC - [2010-07-22 14:18:32 | 002,636,800 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditorOscarEditor.exe

PRC - [2009-06-27 17:16:26 | 004,063,232 | ---- | M] (Microsoft Corporation) -- C:WINDOWSexplorer.exe

PRC - [2009-03-13 03:18:48 | 000,602,624 | ---- | M] () -- C:Program FilesEverythingEverything.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2012-07-03 09:22:15 | 001,780,224 | ---- | M] () -- C:Program FilesAVAST SoftwareAvastdefs12070300algo.dll

MOD - [2012-06-15 00:17:55 | 002,042,848 | ---- | M] () -- C:Program FilesMozilla Firefoxmozjs.dll

MOD - [2012-02-17 20:55:35 | 000,166,912 | ---- | M] () -- C:Program FilesWinRARRarExt.dll

MOD - [2010-07-22 14:18:32 | 002,636,800 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditorOscarEditor.exe

MOD - [2010-06-01 11:41:38 | 000,098,816 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_MouseDeviceManager.dll

MOD - [2010-05-07 23:05:57 | 000,042,496 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditorDataX7HFormsOSD_TextOSD_Text.dll

MOD - [2010-04-03 11:37:14 | 000,127,488 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_Wheel4D.dll

MOD - [2010-04-03 11:37:09 | 000,094,208 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_ZoomControl.dll

MOD - [2010-04-03 11:37:07 | 000,062,976 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_ScrollbarControl.dll

MOD - [2010-04-03 11:37:02 | 000,069,632 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_AnalyzeGesturesInRight.dll

MOD - [2010-04-03 11:36:58 | 000,069,632 | ---- | M] () -- C:Program FilesAnti-Vibrate Oscar EditordllDLL_AnalyzeGesturesInOne.dll

MOD - [2010-03-31 23:30:12 | 000,473,704 | ---- | M] () -- C:Program FilesNVIDIA CorporationnViewnvShell.dll

MOD - [2009-03-13 03:18:48 | 000,602,624 | ---- | M] () -- C:Program FilesEverythingEverything.exe

MOD - [2008-03-23 01:01:34 | 000,039,424 | ---- | M] () -- C:Program FilesAlky for Applicationsvshellext.dll

MOD - [2007-04-04 21:27:06 | 000,007,680 | ---- | M] () -- C:Program FilesAlcohol SoftAlcohol 120PluginsImagesbw5mount.dll

MOD - [2007-03-10 10:36:02 | 000,516,096 | ---- | M] () -- C:WINDOWSsystem32VTFLib.dll

 

 

========== Win32 Services (SafeList) ==========

 

SRV - File not found [Auto | Stopped] -- C:WINDOWSsystem32wuauserv.dll -- (wuauserv)

SRV - File not found [Auto | Stopped] -- %SYSTEMROOT%system32wscsvc.dll -- (wscsvc)

SRV - File not found [On_Demand | Stopped] -- C:WINDOWSsystem32spoolsv.exe -- (Spooler)

SRV - File not found [Disabled | Stopped] -- C:Program FilesGoogleUpdateGoogleUpdate.exe /medsvc -- (gupdatem) Usługa Google Update (gupdatem)

SRV - File not found [Disabled | Stopped] -- C:Program FilesGoogleUpdateGoogleUpdate.exe /svc -- (gupdate) Usługa Google Update (gupdate)

SRV - File not found [Disabled | Stopped] -- C:Program FilesFuturemarkFuturemark SystemInfoFMSISvc.exe -- (Futuremark SystemInfo Service)

SRV - File not found [Auto | Stopped] -- %SystemRoot%System32ersvc.dll -- (ERSvc)

SRV - File not found [Disabled | Stopped] -- C:WINDOWSMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - File not found [Disabled | Stopped] -- c:WINDOWSMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - File not found [On_Demand | Stopped] -- C:WINDOWSsystem32cisvc.exe -- (CiSvc)

SRV - File not found [Disabled | Stopped] -- C:WINDOWSSystem32alg.exe -- (ALG)

SRV - [2012-07-03 11:33:07 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:WINDOWSsystem32MacromedFlashFlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2012-07-01 18:04:32 | 000,661,600 | ---- | M] (Wellbia.com Co., Ltd.) [On_Demand | Stopped] -- C:WINDOWSsystem32xsherlock.xem -- (xsherlock)

SRV - [2012-06-28 14:51:53 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:Program FilesAVAST SoftwareAvastAvastSvc.exe -- (avast! Antivirus)

SRV - [2012-06-15 00:17:46 | 000,113,120 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:Program FilesMozilla Maintenance Servicemaintenanceservice.exe -- (MozillaMaintenance)

SRV - [2012-05-15 12:40:09 | 000,161,736 | ---- | M] (Oracle Corporation) [Disabled | Stopped] -- C:Program FilesJavajre7binjqs.exe -- (JavaQuickStarterService)

SRV - [2012-04-21 15:17:58 | 000,131,912 | ---- | M] (Desura Pty Ltd) [Disabled | Stopped] -- C:Program FilesCommon FilesDesuradesura_service.exe -- (Desura Install Service)

SRV - [2012-03-11 23:13:21 | 001,983,232 | ---- | M] (COMODO) [Auto | Running] -- C:Program FilesCOMODOCOMODO Internet Securitycmdagent.exe -- (cmdAgent)

SRV - [2011-10-30 19:38:45 | 000,604,488 | ---- | M] (TuneUp Software) [Disabled | Stopped] -- C:WINDOWSsystem32TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)

SRV - [2011-10-30 19:38:34 | 000,361,288 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:WINDOWSsystem32TuneUpDefragService.exe -- (TuneUp.Defrag)

SRV - [2011-05-03 13:18:00 | 004,137,464 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:WINDOWSsystem32GameMon.des -- (npggsvc)

SRV - [2011-03-16 11:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:Program FilesCommon FilesSteamSteamService.exe -- (Steam Client Service)

SRV - [2009-07-15 12:48:20 | 000,029,000 | ---- | M] (TuneUp Software) [Auto | Running] -- C:WINDOWSsystem32uxtuneup.dll -- (UxTuneUp)

SRV - [2007-05-28 18:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Disabled | Stopped] -- C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindServiceAE.exe -- (StarWindServiceAE)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Kernel | On_Demand | Stopped] -- C:WINDOWSxhunter1.sys -- (xhunter1)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:WINDOWSvtany.sys -- (vtany)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgusbmodem.sys -- (USBModem)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgusbdiag.sys -- (UsbDiag)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgusbbus.sys -- (usbbus)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)

DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSpccsmcfd.sys -- (pccsmcfd)

DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)

DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSGenericMount.sys -- (GenericMount)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversEagleXNt.sys -- (EagleXNt)

DRV - File not found [Kernel | System | Stopped] -- -- (Changer)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgandmodem.sys -- (ANDModem)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgandgps.sys -- (AndGps)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlganddiag.sys -- (AndDiag)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSlgandbus.sys -- (Andbus)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32DRIVERSAmdLLD.sys -- (AmdLLD)

DRV - File not found [Kernel | On_Demand | Unknown] -- -- (aa52iwoz)

DRV - [2012-06-28 14:52:42 | 000,353,688 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:WINDOWSSystem32driversaswSP.sys -- (aswSP)

DRV - [2012-06-28 14:52:42 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:WINDOWSSystem32driversaswTdi.sys -- (aswTdi)

DRV - [2012-06-28 14:52:37 | 000,721,000 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:WINDOWSSystem32driversaswSnx.sys -- (aswSnx)

DRV - [2012-06-28 14:52:37 | 000,097,352 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:WINDOWSSystem32driversaswmon2.sys -- (aswMon2)

DRV - [2012-06-28 14:52:37 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:WINDOWSSystem32driversaswRdr.sys -- (AswRdr)

DRV - [2012-06-28 14:52:36 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:WINDOWSSystem32driversaavmker4.sys -- (Aavmker4)

DRV - [2012-06-28 14:52:36 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:WINDOWSSystem32driversaswFsBlk.sys -- (aswFsBlk)

DRV - [2012-03-11 23:13:46 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversinspect.sys -- (Inspect)

DRV - [2012-03-11 23:13:45 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- C:WINDOWSsystem32driverscmdhlp.sys -- (cmdHlp)

DRV - [2012-03-11 23:13:44 | 000,494,968 | ---- | M] (COMODO) [File_System | System | Running] -- C:WINDOWSsystem32driverscmdGuard.sys -- (cmdGuard)

DRV - [2012-01-23 17:52:28 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:WINDOWSsystem32driverssptd.sys -- (sptd)

DRV - [2011-12-02 17:14:37 | 000,083,872 | ---- | M] () [Kernel | Auto | Running] -- C:WINDOWSsystem32driversatksgt.sys -- (atksgt)

DRV - [2011-12-02 17:14:37 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:WINDOWSsystem32driverslirsgt.sys -- (lirsgt)

DRV - [2011-10-30 20:21:43 | 000,169,472 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:WINDOWSsystem32driverssnapman.sys -- (snapman)

DRV - [2011-10-13 14:06:14 | 000,441,608 | ---- | M] (Paragon) [Kernel | System | Stopped] -- C:WINDOWSsystem32driversUim_IM.sys -- (Uim_IM)

DRV - [2011-10-13 14:06:14 | 000,277,576 | ---- | M] (Paragon) [Kernel | System | Stopped] -- C:WINDOWSsystem32driversUim_Vim.sys -- (Uim_Vim)

DRV - [2011-10-13 14:06:14 | 000,045,240 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | System | Stopped] -- C:WINDOWSsystem32driversUimBus.sys -- (UimBus)

DRV - [2009-12-30 19:56:46 | 000,088,960 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32drivershmumdm.sys -- (MobileAdapter)

DRV - [2009-09-29 08:11:22 | 000,012,160 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driverslgbtport.sys -- (LgBttPort)

DRV - [2009-09-29 08:11:20 | 000,012,928 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driverslgvmodem.sys -- (LGVMODEM)

DRV - [2009-09-29 08:11:20 | 000,010,496 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driverslgbtbus.sys -- (lgbusenum)

DRV - [2009-08-22 20:25:00 | 000,009,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:Program FilesRivaTuner v2.24 MSI Master Overclocking Arena 2009 editionRivaTuner32.sys -- (RivaTuner32)

DRV - [2009-07-05 02:19:05 | 000,062,208 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:WINDOWSSystem32driverssi3112.sys -- (Si3112)

DRV - [2009-07-04 23:08:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversRTL8139.sys -- (rtl8139) Sterownik NT karty Realtek RTL8139(A/B/C)

DRV - [2009-07-04 23:08:24 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driversgameenum.sys -- (gameenum)

DRV - [2008-07-24 00:29:16 | 000,047,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversvserial.sys -- (vserial)

DRV - [2008-07-24 00:29:16 | 000,015,264 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:WINDOWSsystem32driversvsb.sys -- (vsbus)

DRV - [2006-06-16 20:56:38 | 000,083,968 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:WINDOWSsystem32driversRtnicxp.sys -- (RTL8023xp)

DRV - [2004-08-09 13:33:26 | 000,114,016 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversprohlp02.sys -- (prohlp02)

DRV - [2004-08-09 13:29:28 | 000,053,920 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:WINDOWSsystem32driversprodrv06.sys -- (prodrv06)

DRV - [2004-07-19 16:49:54 | 000,007,040 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversprosync1.sys -- (prosync1)

DRV - [2004-06-03 10:40:46 | 000,079,360 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversnvatabus.sys -- (nvatabus)

DRV - [2004-04-02 15:40:00 | 000,021,760 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:WINDOWSsystem32driversnv_agp.SYS -- (nv_agp)

DRV - [2003-12-01 17:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:WINDOWSsystem32driverssfhlp01.sys -- (sfhlp01)

DRV - [2001-11-28 03:58:18 | 000,001,950 | ---- | M] () [Kernel | System | Unknown] -- C:WINDOWSsystem32driversREGISTER.SYS -- (project)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.msn.com/

IE - HKLM..SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}

 

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://sunonline.web...om/Default.aspx

IE - HKCU..SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKCU..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC

IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"

FF - prefs.js..network.proxy.backup.ftp: "212.191.7.144"

FF - prefs.js..network.proxy.backup.ftp_port: 8080

FF - prefs.js..network.proxy.backup.socks: "212.191.7.144"

FF - prefs.js..network.proxy.backup.socks_port: 8080

FF - prefs.js..network.proxy.backup.ssl: "212.191.7.144"

FF - prefs.js..network.proxy.backup.ssl_port: 8080

FF - prefs.js..network.proxy.ftp: "217.98.20.195"

FF - prefs.js..network.proxy.ftp_port: 8080

FF - prefs.js..network.proxy.http: "217.98.20.195"

FF - prefs.js..network.proxy.http_port: 8080

FF - prefs.js..network.proxy.share_proxy_settings: true

FF - prefs.js..network.proxy.socks: "217.98.20.195"

FF - prefs.js..network.proxy.socks_port: 8080

FF - prefs.js..network.proxy.ssl: "217.98.20.195"

FF - prefs.js..network.proxy.ssl_port: 8080

FF - prefs.js..network.proxy.type: 0

 

FF - user.js..browser.search.openintab: false

 

FF - HKLMSoftwareMozillaPlugins@adobe.com/FlashPlayer: C:WINDOWSsystem32MacromedFlashNPSWF32_11_3_300_262.dll ()

FF - HKLMSoftwareMozillaPlugins@adobe.com/ShockwavePlayer: C:WINDOWSsystem32AdobeDirectornp32dsw.dll (Adobe Systems, Inc.)

FF - HKLMSoftwareMozillaPlugins@java.com/DTPlugin,version=10.4.0: C:WINDOWSsystem32npDeployJava1.dll (Oracle Corporation)

FF - HKLMSoftwareMozillaPlugins@java.com/JavaPlugin,version=10.4.0: C:Program FilesJavajre7binplugin2npjp2.dll (Oracle Corporation)

FF - HKLMSoftwareMozillaPlugins@Microsoft.com/NpCtrl,version=1.0: C:Program FilesMicrosoft Silverlight4.0.60831.0npctrl.dll ( Microsoft Corporation)

FF - HKLMSoftwareMozillaPlugins@microsoft.com/OfficeAuthz,version=14.0: C:PROGRA~1Microsoft OfficeOffice14NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLMSoftwareMozillaPlugins@microsoft.com/SharePoint,version=14.0: C:PROGRA~1Microsoft OfficeOffice14NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLMSoftwareMozillaPlugins@real.com/nppl3260;version=6.0.12.69: C:Program FilesReal Alternativebrowserpluginsnppl3260.dll (RealNetworks, Inc.)

FF - HKLMSoftwareMozillaPlugins@real.com/nprpjplug;version=6.0.12.69: C:Program FilesReal Alternativebrowserpluginsnprpjplug.dll (RealNetworks, Inc.)

FF - HKLMSoftwareMozillaPlugins@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKLMSoftwareMozillaPlugins@tools.google.com/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.99npGoogleUpdate3.dll File not found

FF - HKLMSoftwareMozillaPlugins@tools.google.com/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.99npGoogleUpdate3.dll File not found

FF - HKLMSoftwareMozillaPlugins@Webzen.com/NPBrowserExt: C:Program FilesWEBZENBrowserExtensionNPWZCmnCtrl.dll (WEBZEN)

FF - HKCUSoftwareMozillaPlugins@eximion.com/KalydoPlayer: C:Documents and SettingsMateuszDane aplikacjiKalydoKalydoPlayerbin1npkalydo.dll File not found

 

FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxextensionswrc@avast.com: C:Program FilesAVAST SoftwareAvastWebRepFF [2012-06-29 20:17:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 13.0.1extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2012-06-30 13:37:22 | 000,000,000 | ---D | M]

 

[2012-07-01 10:40:36 | 000,000,000 | ---D | M] (No name found) -- C:Documents and SettingsMateuszDane aplikacjiMozillaExtensions

[2012-07-01 12:17:29 | 000,000,000 | ---D | M] (No name found) -- C:Documents and SettingsMateuszDane aplikacjiMozillaFirefoxProfilesmaft7plq.defaultextensions

[2012-07-01 10:41:02 | 000,000,000 | ---D | M] (FT DeepDark) -- C:Documents and SettingsMateuszDane aplikacjiMozillaFirefoxProfilesmaft7plq.defaultextensions{77d2ed30-4cd2-11e0-b8af-0800200c9a66}

[2012-07-01 10:41:02 | 000,000,000 | ---D | M] (DownloadHelper) -- C:Documents and SettingsMateuszDane aplikacjiMozillaFirefoxProfilesmaft7plq.defaultextensions{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

[2012-06-30 13:37:22 | 000,000,000 | ---D | M] (No name found) -- C:Program FilesMozilla Firefoxextensions

[2012-06-08 15:09:36 | 000,052,174 | ---- | M] () (No name found) -- C:DOCUMENTS AND SETTINGSMATEUSZDANE APLIKACJIMOZILLAFIREFOXPROFILESMAFT7PLQ.DEFAULTEXTENSIONSFABTAB@CAPTAINCAVEMAN.NL.XPI

[2012-06-15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:Program Filesmozilla firefoxcomponentsbrowsercomps.dll

[2012-06-15 01:13:23 | 000,002,767 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginsallegro-pl.xml

[2012-06-15 01:13:23 | 000,001,406 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginsfbc-pl.xml

[2012-06-15 01:13:23 | 000,000,917 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginsmerlin-pl.xml

[2012-06-15 01:13:23 | 000,000,858 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginspwn-pl.xml

[2012-06-15 01:13:23 | 000,001,183 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginswikipedia-pl.xml

[2012-06-15 01:13:23 | 000,001,683 | ---- | M] () -- C:Program Filesmozilla firefoxsearchpluginswp-pl.xml

 

O1 HOSTS File: ([2012-06-26 11:30:12 | 000,000,933 | ---- | M]) - C:WINDOWSsystem32driversetchosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com

O1 - Hosts: 127.0.0.1 www.alcohol-soft.com

O1 - Hosts: 127.0.0.1 images.alcohol-soft.com

O1 - Hosts: 127.0.0.1 trial.alcohol-soft.com

O1 - Hosts: 127.0.0.1 alcohol-soft.com

O1 - Hosts: 0.0.0.0 crl.verisign.com

O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre7binssv.dll (Oracle Corporation)

O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)

O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre7binjp2ssv.dll (Oracle Corporation)

O3 - HKLM..Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)

O4 - HKLM..Run: [avast] C:Program FilesAVAST SoftwareAvastavastUI.exe (AVAST Software)

O4 - HKLM..Run: [COMODO Internet Security] C:Program FilesCOMODOCOMODO Internet Securitycfp.exe (COMODO)

O4 - HKLM..Run: [NvCplDaemon] C:WINDOWSSystem32NvCpl.dll (NVIDIA Corporation)

O4 - HKLM..Run: [RivaTunerStartupDaemon] C:Program FilesRivaTuner v2.24 MSI Master Overclocking Arena 2009 editionRivaTuner.exe ()

O4 - HKCU..Run: [OscarEditor] C:Program FilesAnti-Vibrate Oscar EditorOscarEditor.exe ()

O4 - Startup: C:Documents and SettingsMateuszMenu StartProgramyAutostartETERNA.lnk = File not found

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDesktopCleanupWizard = 1

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: HonorAutoRunSetting = 1

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: NoInternetOpenWith = 1

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: DisableStatusMessages = 1

O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: VerboseStatus = 0

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 323

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoSMMyPictures = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoSMConfigurePrograms = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoSMHelp = 0

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoLowDiskSpaceChecks = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoResolveTrack = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: LinkResolveIgnoreLinkInfo = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoResolveSearch = 1

O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveAutoRun = 67108863

O8 - Extra context menu item: Se&nd to OneNote - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)

O13 - gopher Prefix: missing

O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{B2C8C128-573B-4A6F-B54E-7B85E4C706DE}: NameServer = 194.204.159.1 194.204.152.34

O20 - AppInit_DLLs: (C:WINDOWSsystem32wbsys.dll) - C:WINDOWSsystem32wbsys.dll (Stardock.Net, Inc)

O20 - AppInit_DLLs: (C:WINDOWSsystem32guard32.dll) - C:WINDOWSsystem32guard32.dll (COMODO)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:WINDOWSexplorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:WINDOWSsystem32userinit.exe) - C:WINDOWSsystem32userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UIHost - (C:Documents and SettingsAll UsersDane aplikacjiTuneUp SoftwareTuneUp UtilitiesWinStylertu_logonui.exe) - C:Documents and SettingsAll UsersDane aplikacjiTuneUp SoftwareTuneUp UtilitiesWinStylertu_logonui.exe (Microsoft Corporation)

O20 - WinlogonNotifyAtiExtEvent: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found

O20 - WinlogonNotifyWBSrv: DllName - (C:Program FilesStardockObject DesktopWindowBlindswbsrv.dll) - File not found

O22 - SharedTaskScheduler: {1984D045-52CF-49cd-DB77-08F378FEA4DB} - ObjectDockShellExt - No CLSID value found.

O24 - Desktop Components:0 (Bieżąca strona główna) - About:Home

O24 - Desktop WallPaper: C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp

O24 - Desktop BackupWallPaper: C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2011-10-30 18:37:54 | 000,000,000 | ---- | M] () - C:AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2{ef1c13d8-0c8c-11e1-93c4-00138fdb5109}ShellAutoRuncommand - "" = G:InstallTomTomHOME.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM..comfile [open] -- "%1" %*

O35 - HKLM..exefile [open] -- "%1" %*

O37 - HKLM...com [@ = comfile] -- "%1" %*

O37 - HKLM...exe [@ = exefile] -- "%1" %*

O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2012-07-03 11:45:57 | 000,000,000 | ---D | C] -- C:_OTL

[2012-07-03 10:39:57 | 000,000,000 | -HSD | C] -- C:Documents and SettingsMateuszRecent

[2012-07-02 17:04:43 | 000,000,000 | ---D | C] -- C:Program FilesTrend Micro

[2012-07-02 17:04:43 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMenu StartProgramyHiJackThis

[2012-07-02 15:28:59 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersMenu StartProgramyGOM Player

[2012-07-01 18:04:32 | 000,661,600 | ---- | C] (Wellbia.com Co., Ltd.) -- C:WINDOWSSystem32xsherlock.xem

[2012-07-01 16:55:09 | 000,230,920 | ---- | C] (WEBZEN, INC.) -- C:WINDOWSSystem32EPWZCmnCtrl.dll

[2012-07-01 16:55:08 | 000,000,000 | ---D | C] -- C:Program FilesWEBZEN

[2012-07-01 16:54:58 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersDane aplikacjiWEBZEN

[2012-07-01 15:07:19 | 000,000,000 | ---D | C] -- C:WINDOWSerdnt

[2012-07-01 13:53:40 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyKONAMI

[2012-07-01 11:10:51 | 000,000,000 | ---D | C] -- C:WINDOWSSystem32AGEIA

[2012-07-01 11:10:50 | 000,000,000 | ---D | C] -- C:Program FilesAGEIA Technologies

[2012-07-01 10:40:33 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjiMozilla

[2012-06-30 20:55:19 | 000,000,000 | ---D | C] -- C:Program FilesUbisoft

[2012-06-30 20:20:30 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyNBA LIVE 08

[2012-06-30 19:55:43 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyChillstream

[2012-06-30 19:11:19 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersDane aplikacjiWindows Genuine Advantage

[2012-06-30 18:39:56 | 001,112,288 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32WdfCoInstaller01007.dll

[2012-06-30 18:39:55 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersMenu StartProgramyMicrosoft Xbox 360 Accessories

[2012-06-30 18:39:54 | 000,000,000 | ---D | C] -- C:Program FilesMicrosoft Xbox 360 Accessories

[2012-06-30 13:37:24 | 000,000,000 | ---D | C] -- C:Program FilesMozilla Maintenance Service

[2012-06-30 13:37:19 | 000,000,000 | ---D | C] -- C:Program FilesMozilla Firefox

[2012-06-30 11:45:03 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyMount&Blade Warband Savegames

[2012-06-30 11:43:57 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjiMount&Blade Warband

[2012-06-30 11:43:49 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyMount&Blade Warband

[2012-06-30 11:29:53 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyMount&Blade With Fire and Sword

[2012-06-30 11:29:53 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjiMount&Blade With Fire and Sword

[2012-06-29 22:53:35 | 004,137,464 | ---- | C] (INCA Internet Co., Ltd.) -- C:WINDOWSSystem32GameMon.des

[2012-06-29 22:49:11 | 000,004,682 | ---- | C] (INCA Internet Co., Ltd.) -- C:WINDOWSSystem32npptNT2.sys

[2012-06-29 22:48:18 | 000,000,000 | ---D | C] -- C:Program FilesCommon FilesINCA Shared

[2012-06-29 19:18:49 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyTom Clancy's H.A.W.X

[2012-06-29 16:29:00 | 003,563,520 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32physxcore.dll

[2012-06-29 16:29:00 | 000,057,856 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32physxloader.dll

[2012-06-29 16:28:52 | 000,387,072 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32physxcooking.dll

[2012-06-28 17:44:38 | 000,000,000 | ---D | C] -- C:WINDOWSPerformance

[2012-06-28 17:44:29 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiMicrosoft Corporation

[2012-06-28 14:45:10 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjiRovio

[2012-06-28 13:41:56 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiDeployment

[2012-06-28 10:13:07 | 000,013,824 | ---- | C] (Loghain) -- C:Documents and SettingsMateuszMoje dokumentygiveme2entitlements_v2.exe

[2012-06-27 18:09:06 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyOpenLieroX

[2012-06-27 16:04:36 | 000,171,520 | ---- | C] (Microsoft Corporation) -- C:WINDOWSSystem32msconfig.exe

[2012-06-26 16:58:01 | 000,000,000 | ---D | C] -- C:WINDOWSSxsCaPendDel

[2012-06-26 09:03:02 | 000,000,000 | ---D | C] -- C:WINDOWSusgwmt

[2012-06-22 14:42:50 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyDragon age save editor

[2012-06-22 10:11:27 | 000,000,000 | ---D | C] -- C:Program FilesOrigin Games

[2012-06-22 10:11:25 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiOrigin

[2012-06-22 10:03:11 | 000,000,000 | ---D | C] -- C:Program FilesOrigin

[2012-06-21 14:34:16 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMenu StartProgramyRevo Uninstaller

[2012-06-19 10:50:19 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjicom.bwsf.DragonAgeLegends

[2012-06-19 10:14:31 | 000,000,000 | ---D | C] -- C:Program FilesCommon FilesAdobe AIR

[2012-06-18 17:14:44 | 000,000,000 | ---D | C] -- C:Program FilesNVIDIA Corporation

[2012-06-18 17:09:37 | 014,757,888 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvoglnt.dll

[2012-06-18 17:09:37 | 002,646,632 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvcuvenc.dll

[2012-06-18 17:09:37 | 000,061,440 | ---- | C] (Khronos Group) -- C:WINDOWSSystem32OpenCL.dll

[2012-06-18 17:09:35 | 011,647,592 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvcompiler.dll

[2012-06-18 17:09:35 | 006,432,128 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nv4_disp.dll

[2012-06-18 17:09:35 | 001,097,728 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvapi.dll

[2012-06-18 17:09:35 | 000,227,944 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvcodins.dll

[2012-06-18 17:09:35 | 000,227,944 | ---- | C] (NVIDIA Corporation) -- C:WINDOWSSystem32nvcod.dll

[2012-06-18 14:30:37 | 000,000,000 | ---D | C] -- C:Program FilesSystemRequirementsLab

[2012-06-17 12:54:04 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll Usersdocuments

[2012-06-14 13:08:55 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersDokumentystalker-stcs

[2012-06-14 13:00:18 | 000,000,000 | ---D | C] -- C:Program FilesAnti-Vibrate Oscar Editor

[2012-06-13 15:32:24 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentySquare Enix

[2012-06-13 15:32:11 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacji119615131254924532

[2012-06-13 15:32:01 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacji119611918619387124

[2012-06-13 11:08:14 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMenu StartProgramyMultimedia Keyboard Driver

[2012-06-13 11:08:00 | 000,000,000 | ---D | C] -- C:Program FilesMultimedia Keyboard Driver

[2012-06-13 08:31:02 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszDane aplikacjiTropico 3

[2012-06-09 15:11:50 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszMoje dokumentyWBGames

[2012-06-09 13:18:30 | 000,000,000 | ---D | C] -- C:Program FilesLG Electronics

[2012-06-09 10:02:56 | 000,000,000 | ---D | C] -- C:Program FilesblueMSX

[2012-06-07 18:22:14 | 000,000,000 | ---D | C] -- C:Program FilesparticleIllusion_3

[2012-06-07 11:45:50 | 000,000,000 | ---D | C] -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjistorage

[2012-06-05 19:42:53 | 000,000,000 | ---D | C] -- C:Documents and SettingsAll UsersPulpit

[8 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]

[5 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]

[2 C:Program Files*.tmp files -> C:Program Files*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2012-07-03 11:46:09 | 000,003,386 | ---- | M] () -- C:WINDOWSSystem32NOTEPAD.ini

[2012-07-03 11:38:00 | 000,000,930 | ---- | M] () -- C:WINDOWStasksAdobe Flash Player Updater.job

[2012-07-03 11:34:16 | 023,445,072 | ---- | M] () -- C:Documents and SettingsMateuszMoje dokumentyFirefox 13.0.1 (pl) - 2012-07-03.pcv

[2012-07-03 11:33:07 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:WINDOWSSystem32FlashPlayerApp.exe

[2012-07-03 11:33:07 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:WINDOWSSystem32FlashPlayerCPLApp.cpl

[2012-07-03 11:17:58 | 000,280,403 | ---- | M] () -- C:WINDOWSSystem32NvApps.xml

[2012-07-03 11:17:53 | 000,002,048 | --S- | M] () -- C:WINDOWSbootstat.dat

[2012-07-03 09:49:02 | 000,000,223 | RHS- | M] () -- C:boot.ini

[2012-07-02 23:06:38 | 000,066,093 | ---- | M] () -- C:Documents and SettingsMateusz.recently-used.xbel

[2012-07-02 20:56:11 | 000,216,856 | ---- | M] () -- C:WINDOWSSystem32FNTCACHE.DAT

[2012-07-02 12:46:29 | 000,000,664 | ---- | M] () -- C:WINDOWSSystem32d3d9caps.dat

[2012-07-02 09:12:43 | 000,000,552 | ---- | M] () -- C:WINDOWSSystem32d3d8caps.dat

[2012-07-01 18:04:32 | 000,661,600 | ---- | M] (Wellbia.com Co., Ltd.) -- C:WINDOWSSystem32xsherlock.xem

[2012-07-01 10:40:21 | 000,000,448 | ---- | M] () -- C:Documents and SettingsMateuszMoje dokumentyremember password.URL

[2012-06-30 19:11:23 | 000,002,206 | ---- | M] () -- C:WINDOWSSystem32wpa.dbl

[2012-06-30 18:40:40 | 000,000,000 | -H-- | M] () -- C:WINDOWSSystem32driversMsft_Kernel_xusb21_01007.Wdf

[2012-06-29 20:17:51 | 000,002,657 | ---- | M] () -- C:WINDOWSSystem32CONFIG.NT

[2012-06-28 15:02:25 | 000,002,601 | ---- | M] () -- C:Documents and SettingsAll UsersDokumentyGlobal.sw2

[2012-06-28 14:52:42 | 000,353,688 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswSP.sys

[2012-06-28 14:52:42 | 000,054,232 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswTdi.sys

[2012-06-28 14:52:37 | 000,721,000 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswSnx.sys

[2012-06-28 14:52:37 | 000,097,352 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswmon2.sys

[2012-06-28 14:52:37 | 000,089,624 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswmon.sys

[2012-06-28 14:52:37 | 000,035,928 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswRdr.sys

[2012-06-28 14:52:36 | 000,025,256 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaavmker4.sys

[2012-06-28 14:52:36 | 000,021,256 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32driversaswFsBlk.sys

[2012-06-28 14:52:20 | 000,041,224 | ---- | M] (AVAST Software) -- C:WINDOWSavastSS.scr

[2012-06-28 14:51:49 | 000,227,648 | ---- | M] (AVAST Software) -- C:WINDOWSSystem32aswBoot.exe

[2012-06-26 15:38:00 | 000,000,023 | ---- | M] () -- C:WINDOWSBlendSettings.ini

[2012-06-23 17:15:51 | 000,000,438 | ---- | M] () -- C:WINDOWStasksKonserwacja 1 kliknięciem.job

[2012-06-22 10:03:18 | 000,000,661 | ---- | M] () -- C:Documents and SettingsAll UsersPulpitOrigin.lnk

[2012-06-21 14:49:13 | 022,954,388 | ---- | M] () -- C:Documents and SettingsMateuszMoje dokumentyFirefox 13.0.1 (pl) - 2012-06-21.pcv

[2012-06-18 16:35:59 | 140,259,328 | ---- | M] () -- C:WINDOWSMEMORY.DMP

[2012-06-18 15:19:36 | 000,563,636 | ---- | M] () -- C:WINDOWSSystem32perfh015.dat

[2012-06-18 15:19:36 | 000,501,072 | ---- | M] () -- C:WINDOWSSystem32perfh009.dat

[2012-06-18 15:19:36 | 000,109,070 | ---- | M] () -- C:WINDOWSSystem32perfc015.dat

[2012-06-18 15:19:36 | 000,087,420 | ---- | M] () -- C:WINDOWSSystem32perfc009.dat

[2012-06-18 08:31:33 | 000,000,202 | ---- | M] () -- C:WINDOWSNeroDigital.ini

[2012-06-14 11:04:15 | 000,003,083 | ---- | M] () -- C:Documents and SettingsMateuszMoje dokumentyresetdma.vbs

[2012-06-09 14:22:09 | 000,002,413 | ---- | M] () -- C:WINDOWSSystem32lgAxconfig.ini

[2012-06-07 18:25:22 | 021,145,805 | ---- | M] () -- C:Documents and SettingsMateuszMoje dokumentyFirefox 13.0 (pl) - 2012-06-07.pcv

[8 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]

[5 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]

[2 C:Program Files*.tmp files -> C:Program Files*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2012-07-03 11:33:51 | 023,445,072 | ---- | C] () -- C:Documents and SettingsMateuszMoje dokumentyFirefox 13.0.1 (pl) - 2012-07-03.pcv

[2012-07-02 23:06:38 | 000,066,093 | ---- | C] () -- C:Documents and SettingsMateusz.recently-used.xbel

[2012-07-02 09:12:43 | 000,000,552 | ---- | C] () -- C:WINDOWSSystem32d3d8caps.dat

[2012-07-01 10:40:21 | 000,000,448 | ---- | C] () -- C:Documents and SettingsMateuszMoje dokumentyremember password.URL

[2012-06-30 18:40:40 | 000,000,000 | -H-- | C] () -- C:WINDOWSSystem32driversMsft_Kernel_xusb21_01007.Wdf

[2012-06-30 13:37:24 | 000,000,743 | ---- | C] () -- C:Documents and SettingsAll UsersMenu StartProgramyMozilla Firefox.lnk

[2012-06-29 22:49:11 | 000,005,174 | ---- | C] () -- C:WINDOWSSystem32nppt9x.vxd

[2012-06-22 10:03:18 | 000,000,661 | ---- | C] () -- C:Documents and SettingsAll UsersPulpitOrigin.lnk

[2012-06-21 14:48:47 | 022,954,388 | ---- | C] () -- C:Documents and SettingsMateuszMoje dokumentyFirefox 13.0.1 (pl) - 2012-06-21.pcv

[2012-06-18 17:09:35 | 002,183,470 | ---- | C] () -- C:WINDOWSSystem32nvdata.bin

[2012-06-17 16:56:16 | 000,112,688 | ---- | C] () -- C:WINDOWSSystem32SH31W32.DLL

[2012-06-16 18:00:47 | 000,009,046 | ---- | C] () -- C:WINDOWSSystem32nvinfo.pb

[2012-06-16 17:18:59 | 000,001,950 | ---- | C] () -- C:WINDOWSSystem32driversREGISTER.SYS

[2012-06-14 11:04:14 | 000,003,083 | ---- | C] () -- C:Documents and SettingsMateuszMoje dokumentyresetdma.vbs

[2012-06-07 18:24:59 | 021,145,805 | ---- | C] () -- C:Documents and SettingsMateuszMoje dokumentyFirefox 13.0 (pl) - 2012-06-07.pcv

[2012-05-20 20:07:34 | 000,034,678 | ---- | C] () -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjirecently-used.xbel

[2012-05-13 16:15:37 | 000,233,472 | ---- | C] () -- C:WINDOWSSystem32cmirmdrv.exe

[2012-05-13 16:15:36 | 000,028,672 | ---- | C] () -- C:WINDOWSSystem32cmirmdrv.dll

[2012-05-13 16:15:35 | 000,136,302 | ---- | C] () -- C:WINDOWSCmuda.ini

[2012-05-13 16:15:34 | 000,225,280 | ---- | C] () -- C:WINDOWSCmiRmRedundDir.exe

[2012-05-12 21:53:12 | 000,000,736 | ---- | C] () -- C:WINDOWSsetup.ini

[2012-05-01 10:36:45 | 000,000,025 | ---- | C] () -- C:WINDOWSpopcinfot.dat

[2012-04-26 19:17:13 | 000,000,016 | ---- | C] () -- C:WINDOWSSystem32msvcsv60.dll

[2012-04-26 19:17:13 | 000,000,016 | ---- | C] () -- C:WINDOWSmsocreg32.dat

[2012-04-24 18:38:03 | 000,000,857 | ---- | C] () -- C:WINDOWSclient.config.ini

[2012-04-17 12:58:55 | 000,043,520 | ---- | C] () -- C:WINDOWSSystem32CmdLineExt03.dll

[2012-04-17 11:32:28 | 000,000,077 | ---- | C] () -- C:Documents and SettingsMateuszDane aplikacjimainhst.zgh

[2012-04-02 18:33:14 | 000,064,918 | ---- | C] () -- C:Documents and SettingsMateuszKLR320 Bloody Justice.png

[2012-02-17 16:31:46 | 000,000,414 | RHS- | C] () -- C:Documents and SettingsAll Usersntuser.pol

[2012-02-16 13:06:14 | 000,138,904 | ---- | C] () -- C:Documents and SettingsMateuszDane aplikacjiPnkBstrK.sys

[2012-02-08 11:17:17 | 000,000,537 | ---- | C] () -- C:WINDOWSFICEDULA.INI

[2012-02-05 17:56:50 | 000,000,128 | R--- | C] () -- C:Documents and SettingsMateuszValid.Ext

[2012-01-28 19:15:37 | 000,074,752 | ---- | C] () -- C:WINDOWSSystem32ff_vfw.dll

[2012-01-27 17:35:31 | 000,053,248 | ---- | C] () -- C:WINDOWSSystem32CommonDL.dll

[2012-01-27 17:35:31 | 000,002,413 | ---- | C] () -- C:WINDOWSSystem32lgAxconfig.ini

[2012-01-19 20:45:06 | 000,000,041 | ---- | C] () -- C:WINDOWSlz_tcm.ini

[2012-01-11 17:16:05 | 000,000,057 | ---- | C] () -- C:WINDOWSnfsc_patch.ini

[2012-01-01 19:39:44 | 000,516,096 | ---- | C] () -- C:WINDOWSSystem32VTFLib.dll

[2011-12-27 12:35:35 | 000,000,202 | ---- | C] () -- C:WINDOWSNeroDigital.ini

[2011-12-26 20:28:00 | 000,122,880 | ---- | C] () -- C:WINDOWSUnGins.exe

[2011-12-19 19:28:55 | 000,000,000 | ---- | C] () -- C:WINDOWSWB.ini

[2011-12-05 12:14:08 | 000,000,001 | ---- | C] () -- C:Documents and SettingsMateuszSI.bin

[2011-12-01 19:56:42 | 000,083,872 | ---- | C] () -- C:WINDOWSSystem32driversatksgt.sys

[2011-12-01 19:56:42 | 000,025,888 | ---- | C] () -- C:WINDOWSSystem32driverslirsgt.sys

[2011-11-25 21:30:10 | 000,004,096 | ---- | C] () -- C:WINDOWSd3dx.dat

[2011-11-18 13:39:21 | 000,000,001 | ---- | C] () -- C:Documents and SettingsAll UsersDane aplikacjiflagposition.out

[2011-11-17 11:04:21 | 000,354,816 | ---- | C] () -- C:WINDOWSSystem32psisdecd.dll

[2011-11-14 13:49:39 | 000,000,155 | ---- | C] () -- C:WINDOWSwinamp.ini

[2011-11-14 10:45:16 | 000,000,056 | RHS- | C] () -- C:WINDOWSSystem320D4F86FFD5.sys

[2011-11-14 10:43:20 | 000,001,890 | -HS- | C] () -- C:WINDOWSSystem32KGyGaAvL.sys

[2011-11-09 21:17:49 | 000,175,616 | ---- | C] () -- C:WINDOWSSystem32unrar.dll

[2011-11-08 11:49:22 | 000,000,001 | ---- | C] () -- C:WINDOWSSystem32SI.bin

[2011-11-07 11:24:27 | 000,075,264 | ---- | C] () -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjiDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011-11-06 17:56:48 | 000,000,000 | ---- | C] () -- C:WINDOWSPowerReg.dat

[2011-11-05 12:00:13 | 000,000,132 | ---- | C] () -- C:Documents and SettingsMateuszUstawienia lokalneDane aplikacjifusioncache.dat

[2011-11-02 13:35:27 | 000,000,088 | ---- | C] () -- C:WINDOWSStyleBuilder.INI

[2011-10-30 21:03:32 | 000,000,023 | ---- | C] () -- C:WINDOWSBlendSettings.ini

[2011-10-30 19:34:21 | 000,000,092 | ---- | C] () -- C:WINDOWSCMISETUP.INI

[2011-10-30 19:34:19 | 000,000,026 | ---- | C] () -- C:WINDOWSCMCDPLAY.INI

[2011-10-30 19:34:18 | 000,000,010 | ---- | C] () -- C:WINDOWSWininit.ini

[2011-10-30 19:34:17 | 000,266,240 | ---- | C] () -- C:WINDOWSCMIUninstall.exe

[2011-10-30 19:34:17 | 000,028,672 | ---- | C] () -- C:WINDOWSCMIRmDriver.dll

[2011-10-30 19:30:33 | 000,003,386 | ---- | C] () -- C:WINDOWSSystem32NOTEPAD.ini

[2011-10-30 19:27:13 | 000,004,293 | ---- | C] () -- C:WINDOWSODBCINST.INI

[2011-10-30 19:26:52 | 000,283,648 | ---- | C] () -- C:WINDOWSNOTEPAD.EXE

[2011-10-30 19:25:50 | 000,216,856 | ---- | C] () -- C:WINDOWSSystem32FNTCACHE.DAT

[2011-10-30 19:24:57 | 000,244,224 | ---- | C] () -- C:WINDOWSSystem32NvRaidMan.exe

[2011-10-30 19:10:00 | 000,000,664 | ---- | C] () -- C:WINDOWSSystem32d3d9caps.dat

[2011-10-30 18:51:46 | 000,002,048 | --S- | C] () -- C:WINDOWSbootstat.dat

[2011-10-30 18:40:06 | 000,000,047 | ---- | C] () -- C:WINDOWSTransBar.ini

[2011-10-30 18:37:59 | 000,652,287 | ---- | C] () -- C:WINDOWSNowe_konto.exe

[2011-10-30 18:34:32 | 000,021,856 | ---- | C] () -- C:WINDOWSSystem32emptyregdb.dat

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 5120 bytes -> C:Documents and SettingsAll UsersDane aplikacjidesktop.ini:gs5sys

@Alternate Data Stream - 48 bytes -> C:Documents and SettingsAll UsersDRM:احتضان

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszSzablony:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszPulpit:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszMoje dokumenty:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszDane aplikacjidesktop.ini:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsMateuszCookies:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsAll UsersSzablony:gs5sys

@Alternate Data Stream - 1536 bytes -> C:Documents and SettingsAll UsersDokumentydesktop.ini:gs5sys

@Alternate Data Stream - 129 bytes -> C:Documents and SettingsAll UsersDane aplikacjiTEMP:05EE1EEF

@Alternate Data Stream - 123 bytes -> C:Documents and SettingsAll UsersDane aplikacjiTEMP:8CE646EE

@Alternate Data Stream - 121 bytes -> C:Documents and SettingsAll UsersDane aplikacjiTEMP:C31F31E6

@Alternate Data Stream - 118 bytes -> C:Documents and SettingsAll UsersDane aplikacjiTEMP:D06A4C76

 

< End of report >

 

 

 

 

EXTRAS

 

 

OTL Extras logfile created on: 2012-07-03 11:48:35 - Run 1

OTL by OldTimer - Version 3.2.53.1 Folder = C:Documents and SettingsMateuszPulpitProgramy

Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

 

1.50 Gb Total Physical Memory | 0.82 Gb Available Physical Memory | 54.37% Memory free

5.48 Gb Paging File | 4.82 Gb Available in Paging File | 87.92% Paging File free

Paging file location(s): C:pagefile.sys 4096 4096 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files

Drive C: | 64.45 Gb Total Space | 47.25 Gb Free Space | 73.30% Space Free | Partition Type: NTFS

Drive D: | 300.00 Gb Total Space | 237.98 Gb Free Space | 79.33% Space Free | Partition Type: NTFS

Drive E: | 250.10 Gb Total Space | 99.56 Gb Free Space | 39.81% Space Free | Partition Type: NTFS

Drive F: | 316.96 Gb Total Space | 191.65 Gb Free Space | 60.47% Space Free | Partition Type: NTFS

 

Computer Name: WELCOMETOHELL66 | User Name: Mateusz | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINESOFTWAREClasses<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.html [@ = Opera.HTML] -- C:Program FilesOperaOpera.exe (Opera Software)

.inf [@ = inffile] -- C:WINDOWSSystem32NOTEPAD.EXE ()

.ini [@ = inifile] -- C:WINDOWSSystem32NOTEPAD.EXE ()

.txt [@ = txtfile] -- C:WINDOWSSystem32NOTEPAD.EXE ()

 

[HKEY_CURRENT_USERSOFTWAREClasses<extension>]

.html [@ = FirefoxHTML] -- C:Program FilesMozilla Firefoxfirefox.exe (Mozilla Corporation)

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINESOFTWAREClasses<key>shell[command]command]

batfile [edit] -- %SystemRoot%System32NOTEPAD.EXE %1 ()

batfile [open] -- "%1" %*

batfile [print] -- %SystemRoot%System32NOTEPAD.EXE /p %1 ()

cmdfile [edit] -- %SystemRoot%System32NOTEPAD.EXE %1 ()

cmdfile [open] -- "%1" %*

cmdfile [print] -- %SystemRoot%System32NOTEPAD.EXE /p %1 ()

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [print] -- "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" /p %1 (Microsoft Corporation)

http [open] -- "C:Program FilesOperaOpera.exe" "%1" (Opera Software)

https [open] -- "C:Program FilesOperaOpera.exe" "%1" (Opera Software)

inffile [open] -- %SystemRoot%System32NOTEPAD.EXE %1 ()

inffile [print] -- %SystemRoot%System32NOTEPAD.EXE /p %1 ()

inifile [open] -- %SystemRoot%System32NOTEPAD.EXE %1 ()

inifile [print] -- %SystemRoot%System32NOTEPAD.EXE /p %1 ()

jsfile [edit] -- %SystemRoot%System32Notepad.exe %1 ()

jsfile [print] -- %SystemRoot%System32Notepad.exe /p %1 ()

jsefile [edit] -- %SystemRoot%System32Notepad.exe %1 ()

jsefile [print] -- %SystemRoot%System32Notepad.exe /p %1 ()

piffile [open] -- "%1" %*

regfile [edit] -- %SystemRoot%system32NOTEPAD.EXE %1 ()

regfile [merge] -- Reg Error: Key error.

regfile [print] -- %SystemRoot%system32NOTEPAD.EXE /p %1 ()

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

txtfile [open] -- %SystemRoot%system32NOTEPAD.EXE %1 ()

txtfile [print] -- %SystemRoot%system32NOTEPAD.EXE /p %1 ()

txtfile [printto] -- %SystemRoot%system32notepad.exe /pt "%1" "%2" "%3" "%4" ()

vbefile [edit] -- %SystemRoot%System32Notepad.exe %1 ()

vbefile [print] -- %SystemRoot%System32Notepad.exe /p %1 ()

vbsfile [edit] -- %SystemRoot%System32Notepad.exe %1 ()

vbsfile [print] -- %SystemRoot%System32Notepad.exe /p %1 ()

wsffile [edit] -- %SystemRoot%System32Notepad.exe %1 ()

wsffile [print] -- %SystemRoot%System32Notepad.exe /p %1 ()

Unknown [openas] -- %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /k cd "%L" (Microsoft Corporation)

Directory [find] -- %SystemRoot%Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:Program FilesWinampWinamp.exe" /BOOKMARK "%1" (Nullsoft)

Directory [Winamp.Enqueue] -- "C:Program FilesWinampWinamp.exe" /ADD "%1" (Nullsoft)

Directory [Winamp.Play] -- "C:Program FilesWinampWinamp.exe" "%1" (Nullsoft)

Folder [open] -- %SystemRoot%Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]

 

========== System Restore Settings ==========

 

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]

"DisableSR" = 0

 

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSr]

"Start" = 0

 

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSrService]

"Start" = 2

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfile]

 

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfile]

"EnableFirewall" = 0

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyDomainProfileAuthorizedApplicationsList]

 

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList]

"C:Program FilesuTorrentuTorrent.exe" = C:Program FilesuTorrentuTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

"C:Program FilesMicrosoft OfficeOffice14ONENOTE.EXE" = C:Program FilesMicrosoft OfficeOffice14ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)

"D:GrySteamSteam.exe" = D:GrySteamSteam.exe:*:Enabled:Steam -- (Valve Corporation)

"C:Program FilesOperaopera.exe" = C:Program FilesOperaopera.exe:*:Enabled:Opera Internet Browser -- (Opera Software)

"C:Program FilesOperapluginwrapperopera_plugin_wrapper.exe" = C:Program FilesOperapluginwrapperopera_plugin_wrapper.exe:*:Enabled:Opera Internet Browser - Plugin wrapper -- (Opera Software)

"D:GryMass EffectBinariesMassEffect.exe" = D:GryMass EffectBinariesMassEffect.exe:*:Enabled:Mass Effect Game -- (BioWare)

"D:GryMass EffectMassEffectLauncher.exe" = D:GryMass EffectMassEffectLauncher.exe:*:Enabled:Mass Effect Launcher -- (BioWare)

"D:GryH.A.W.XHAWX.exe" = D:GryH.A.W.XHAWX.exe:*:Enabled:Tom Clancy's H.A.W.X -- ()

"C:Program FilesUbisoftUbisoft Game LauncherUbisoftGameLauncher.exe" = C:Program FilesUbisoftUbisoft Game LauncherUbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher -- (Ubisoft)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]

"{0049D352-1D20-4FFB-8EF6-81CFBDF3ADE5}" = Soul of the Ultimate Nation

"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam

"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended

"{153C7D89-9CF4-4719-A551-C5BF45236DB5}" = redist

"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser

"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319

"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1

"{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect

"{1E184DD3-07B4-4C7E-B1C2-1993BC74F392}" = Devil May Cry 3 Edycja Specjalna

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java™ 7 Update 4

"{31C63A8A-D9AB-4300-828B-86B41F59FAE1}" = Multimedia Keyboard Driver

"{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile

"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX

"{41785C66-90F2-40CE-8CB5-1C94BFC97280}" = Microsoft Chart Controls for Microsoft .NET Framework 3.5

"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4F0C7CCF-5666-474B-B02E-AC514A95EC93}" = NVIDIA GAME System Software 2.8.1

"{55A29068-F2CE-456C-9148-C869879E2357}" = TuneUp Utilities 2009

"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR

"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2

"{6E36A172-06FB-4BC8-B7FC-D30D219E6776}" = Tom Clancy's H.A.W.X

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{90120000-008A-0409-0000-0000000FF1CE}" = Microsoft Office 2007 Recent Documents Gadget

"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14

"{90140000-0010-0415-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Polish) 14

"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010

"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010

"{90140000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010

"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010

"{90140000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010

"{90140000-0017-0415-0000-0000000FF1CE}" = Microsoft Office SharePoint Designer MUI (Polish) 2010

"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010

"{90140000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010

"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010

"{90140000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010

"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010

"{90140000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010

"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010

"{90140000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010

"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010

"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010

"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010

"{90140000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010

"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010

"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010

"{90140000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010

"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010

"{90140000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010

"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010

"{90140000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010

"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010

"{90140000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010

"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010

"{90140000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010

"{90140000-0100-0415-0000-0000000FF1CE}" = Microsoft Office O MUI (Polish) 2010

"{90140000-0101-0415-0000-0000000FF1CE}" = Microsoft Office X MUI (Polish) 2010

"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010

"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010

"{95723791-2C44-454B-9220-C65D47D70E9C}" = WEBZEN Browser Extension

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AC76BA86-7AD7-1045-7B44-A70000000000}" = Adobe Reader 7.0 - Polish

"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver

"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86

"{BB05D173-9681-4812-A7FA-BD4042A3DA00}" = Alky for Applications (Windows XP)

"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2

"{D8A790CB-CF32-4135-AAAE-6BA5A75C5DBF}" = OSCAR Editor

"{DCFD26A8-60A5-4C69-A52D-264D0386FDB3}" = Microsoft Xbox 360 Accessories 1.2

"{E239F8B2-AE00-467D-9F05-47C8E1FAAFA7}" = WD Align - Powered by Acronis

"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86

"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE

"{FD416706-875C-4B0B-A23A-9E740DAE029E}" = Tom Clancy's Rainbow Six Vegas 2

"{FD8E178D-8B4E-42DA-B434-EFF270329B1C}" = COMODO Internet Security

"{FEFAF112-4DA8-479C-89E2-7DE25091711A}" = Call of Juarez - Więzy Krwi

"7-Zip" = 7-Zip 9.20

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"AIDA64 Extreme Edition_is1" = AIDA64 Extreme Edition v1.60

"Ashampoo Burning Studio 2010_is1" = Ashampoo Burning Studio 2010

"avast" = avast! Free Antivirus

"C-Media Audio" = C-Media 3D Audio

"EAX™ Unified (SHELL)" = EAX™ Unified (SHELL)

"Everything" = Everything 1.2.1.371

"ffdshow_is1" = ffdshow v1.1.3984 [2011-09-22]

"FormatFactory" = FormatFactory 2.60

"Foxit Reader" = Foxit Reader

"GOM Player" = GOM Player

"InstallShield_{31C63A8A-D9AB-4300-828B-86B41F59FAE1}" = Multimedia Keyboard Driver

"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare™ 1.6 Patch

"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare™ 1.7 Patch

"InstallShield_{D8A790CB-CF32-4135-AAAE-6BA5A75C5DBF}" = Anti-Vibrate Oscar Editor

"IrfanView" = IrfanView (remove only)

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.61.0.1400

"Metin2_is1" = Metin2

"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended

"MozBackup" = MozBackup 1.5.1

"Mozilla Firefox 13.0.1 (x86 pl)" = Mozilla Firefox 13.0.1 (x86 pl)

"MozillaMaintenanceService" = Mozilla Maintenance Service

"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs

"NVIDIA Display Control Panel" = NVIDIA Display Control Panel

"NVIDIA Drivers" = NVIDIA Drivers

"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager

"Office14.PROPLUS" = Microsoft Office Professional Plus 2010

"OpenAL" = OpenAL

"Opera 12.00.1467" = Opera 12.00

"Origin" = Origin

"RealAlt_is1" = Real Alternative 1.9.0

"Revo Uninstaller" = Revo Uninstaller 1.94

"RivaTuner" = RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition

"RocketDock_is1" = RocketDock 1.3.5

"Steam App 215" = Source SDK Base 2006

"uTorrent" = µTorrent

"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9

"Winamp" = Winamp (remove only)

"WinGimp-2.0_is1" = GIMP 2.6.5

"WinRAR archiver" = WinRAR 4.11 (32-bit)

"Xbox_360_CC_Driver" = Xbox 360 Controller for Windows

 

========== HKEY_CURRENT_USER Uninstall List ==========

 

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]

 

========== Last 20 Event Log Errors ==========

 

[ Application Events ]

Error - 2012-05-21 11:35:05 | Computer Name = WELCOMETOHELL66 | Source = MsiInstaller | ID = 10005

Description = Produkt: BioShock 2 -- Instalacja nie powiodła się. Uruchom instalatora,

aby zainstalować aktualizację.

 

Error - 2012-05-22 13:08:58 | Computer Name = WELCOMETOHELL66 | Source = MsiInstaller | ID = 11706

Description = Produkt: Far Cry (Patch 1.4) -- Błąd 1706. Pakiet instalacyjny dla

produktu Far Cry (Patch 1.4) nie został odnaleziony. Spróbuj uruchomić instalację

ponownie przy użyciu aktualnej kopii pakietu instalacyjnego 'Far Cry (Patch 1.4).msi'.

 

Error - 2012-05-23 07:10:11 | Computer Name = WELCOMETOHELL66 | Source = MsiInstaller | ID = 11704

Description = Product: InstallScriptMSIEngine -- Error 1704.An installation for

Fable - The Lost Chapters is currently suspended. You must undo the changes made

by that installation to continue. Do you want to undo those changes?

 

Error - 2012-06-09 04:02:44 | Computer Name = WELCOMETOHELL66 | Source = MsiInstaller | ID = 10005

Description = Product: blueMSX -- The installer has encountered an unexpected error

installing this package. This may indicate a problem with this package. The error

code is 2755. The arguments are: 3, C:DOCUME~1MateuszUSTAWI~1TempRar$DIa0.208bluemsx.msi,

 

 

Error - 2012-06-09 07:18:29 | Computer Name = WELCOMETOHELL66 | Source = MsiInstaller | ID = 11721

Description = Product: LG USB Modem Drivers -- Error 1721.There is a problem with

this Windows Installer package. A program required for this install to complete

could not be run. Contact your support personnel or package vendor. Action: ExeRemover.exe,

location: C:Program FilesLG ElectronicsLG USB Modem DriversExeRemover.exe,

command: C:Program FilesLG ElectronicsLG USB Modem Drivers

 

Error - 2012-06-13 08:21:02 | Computer Name = WELCOMETOHELL66 | Source = MsiInstaller | ID = 10005

Description = Produkt: Doom 3 -- Błąd wewnętrzny 2602. File, game00.pk4

 

Error - 2012-06-14 04:17:02 | Computer Name = WELCOMETOHELL66 | Source = MsiInstaller | ID = 1013

Description = Produkt: NVIDIA PhysX -- Installation terminated

 

Error - 2012-06-14 06:50:41 | Computer Name = WELCOMETOHELL66 | Source = MsiInstaller | ID = 1013

Description = Product: OSCAR Editor -- This installation cannot be run by directly

launching the MSI package. You must run setup.exe.

 

Error - 2012-06-21 04:57:40 | Computer Name = WELCOMETOHELL66 | Source = MsiInstaller | ID = 1013

Description = Produkt: NVIDIA PhysX -- Installation terminated

 

Error - 2012-06-29 13:31:04 | Computer Name = WELCOMETOHELL66 | Source = MsiInstaller | ID = 11704

Description = Product: Unreal Tournament 3 -- Error 1704.An installation for Microsoft

Visual C++ 2005 Redistributable is currently suspended. You must undo the changes

made by that installation to continue. Do you want to undo those changes?

 

[ System Events ]

Error - 2012-07-03 02:49:20 | Computer Name = WELCOMETOHELL66 | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi wscsvc z powodu następującego błędu: %%1083

 

Error - 2012-07-03 03:48:48 | Computer Name = WELCOMETOHELL66 | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Automatic Updates z powodu następującego

błędu: %%1083

 

Error - 2012-07-03 03:48:48 | Computer Name = WELCOMETOHELL66 | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi wscsvc z powodu następującego błędu: %%1083

 

Error - 2012-07-03 03:51:26 | Computer Name = WELCOMETOHELL66 | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Automatic Updates z powodu następującego

błędu: %%1083

 

Error - 2012-07-03 03:51:26 | Computer Name = WELCOMETOHELL66 | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi wscsvc z powodu następującego błędu: %%1083

 

Error - 2012-07-03 04:42:22 | Computer Name = WELCOMETOHELL66 | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Automatic Updates z powodu następującego

błędu: %%1083

 

Error - 2012-07-03 04:42:22 | Computer Name = WELCOMETOHELL66 | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi wscsvc z powodu następującego błędu: %%1083

 

Error - 2012-07-03 05:16:53 | Computer Name = WELCOMETOHELL66 | Source = sr | ID = 1

Description = Filtr Przywracania systemu napotkał nieoczekiwany błąd '0xC000009A'

podczas przetwarzania pliku 'cert8.db' w woluminie 'HarddiskVolume1'. W rezultacie

zostało zatrzymane monitorowanie woluminu.

 

Error - 2012-07-03 05:19:33 | Computer Name = WELCOMETOHELL66 | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Automatic Updates z powodu następującego

błędu: %%1083

 

Error - 2012-07-03 05:19:33 | Computer Name = WELCOMETOHELL66 | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi wscsvc z powodu następującego błędu: %%1083

 

 

< End of report >

 

 

 

 

Podejrzewam, że może mieć to coś związanego z avastem, ponieważ problem praktycznie każdorazowo występuje przy wypakowywaniu dużych archiwów rar >6GB. Kilka dni temu była ostatnia aktualizacja programu i mniej więcej od tamtego czasu błąd się pojawia. Odinstaluje Avasta i dam znać.

 

EDIT: Odinstalowałem Avasta, i narazie jest ok, na forum awasta znalazłem wątek w którym wele osób skarży się na memory leak w najnowszej wersji avasta(7.0.1451) na systemie win xp sp3. Podziałam dzień bez antywirusa i zobaczę czy błąd nie pojawi sie powtórnie.

 

EDIT2: Znalezione na dobreprogramy.pl:

Dołączona grafika

Edytowane przez dzl

Udostępnij tę odpowiedź


Odnośnik do odpowiedzi
Udostępnij na innych stronach

Dołącz do dyskusji

Możesz dodać zawartość już teraz a zarejestrować się później. Jeśli posiadasz już konto, zaloguj się aby dodać zawartość za jego pomocą.

Gość
Dodaj odpowiedź do tematu...

×   Wklejono zawartość z formatowaniem.   Przywróć formatowanie

  Dozwolonych jest tylko 75 emoji.

×   Odnośnik został automatycznie osadzony.   Przywróć wyświetlanie jako odnośnik

×   Przywrócono poprzednią zawartość.   Wyczyść edytor

×   Nie możesz bezpośrednio wkleić grafiki. Dodaj lub załącz grafiki z adresu URL.

Ładowanie


×
×
  • Dodaj nową pozycję...