Skocz do zawartości

asd.exe zamieniający się w nie uruchamiaj tego.exe


Rekomendowane odpowiedzi

Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.

Tutaj jest zakaz dopisywania się do czyjegoś tematu. Wydzielam twój temat w osobny. Zabrakło drugiego loga z OTL - extras.txt. Podczas skanu opcja "Rejestr - skan dodatkowy" ma być zaznaczona na "Użyj filtrowania" Pamiętaj o tym w następnym poście.

 

1. Uruchom OTL i w oknie Własne opcje skanowania/Skrypt wklej następujący tekst:

 

:OTL
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - Reg Error: Key error. File not found
FF - prefs.js..browser.search.defaultthis.engineName: "InnoGames Polska Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832599&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2
FF - prefs.js..keyword.URL: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=eri7F0ib&q="
FF - user.js..browser.search.selectedEngine: "Search"
FF - user.js..keyword.URL: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=eri7F0ib&q="
[2011-05-12 01:42:22 | 000,000,000 | ---D | M] (AOL Toolbar) -- C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}
[2011-05-02 12:27:01 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions\engine@conduit.com
[2011-05-12 02:07:28 | 000,002,352 | ---- | M] () -- C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\6nh7v7o5.default\searchplugins\aol-search.xml
[2010-11-25 13:02:52 | 000,000,935 | ---- | M] () -- C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\6nh7v7o5.default\searchplugins\conduit.xml
O2 - BHO: (no name) - {66D8FBA6-D90F-40A9-AC55-84896F79CA69} - No CLSID value found.
O4:64bit: - HKLM..\Run: [rejestr] C:\Windows\rejestr.exe ()
O4:64bit: - HKLM..\Run: [svhost] File not found
O4 - HKCU..\Run: [jucheed] C:\Windows\jucheed.exe ()
O4 - HKCU..\Run: [svhost] C:\Windows\svchost.exe ()
 
:Commands
[emptyflash]
[emptytemp]

 

Kliknij w Wykonaj skrypt. Zatwierdź restart komputera.

 

2. Następnie uruchamiasz OTL ponownie, tym razem wywołujesz opcję Skanuj. Pokazujesz nowe logi z OTL.

 

 

 

Odnośnik do komentarza

A JESZCZE MAM JEDNO PYTANKO. Jeżeli podłączę dysk przenośny ( a tam tez mam ten plik) to czy nie odnowi on robala w lapku ?

 

To sie pokazało po uruchomieniu.

 

All processes killed

========== OTL ==========

Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ not found.

Prefs.js: "InnoGames Polska Customized Web Search" removed from browser.search.defaultthis.engineName

Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832599&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl

Prefs.js: "Search" removed from browser.search.selectedEngine

Prefs.js: engine@conduit.com:3.2.5.2 removed from extensions.enabledItems

Prefs.js: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=eri7F0ib&q=" removed from keyword.URL

C:\Users\Marcin\AppData\Roaming\Mozilla\FireFox\Profiles\6nh7v7o5.default\user.js moved successfully.

Folder C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\ not found.

Folder C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions\engine@conduit.com\ not found.

C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\6nh7v7o5.default\searchplugins\aol-search.xml moved successfully.

C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\6nh7v7o5.default\searchplugins\conduit.xml moved successfully.

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66D8FBA6-D90F-40A9-AC55-84896F79CA69}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66D8FBA6-D90F-40A9-AC55-84896F79CA69}\ not found.

64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\rejestr deleted successfully.

C:\Windows\rejestr.exe moved successfully.

64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\svhost deleted successfully.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jucheed deleted successfully.

C:\Windows\jucheed.exe moved successfully.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\svhost deleted successfully.

C:\Windows\svchost.exe moved successfully.

========== COMMANDS ==========

 

[EMPTYFLASH]

 

User: All Users

 

User: Default

 

User: Default User

 

User: GościeGoście

->Flash cache emptied: 0 bytes

 

User: Marcin

->Flash cache emptied: 783 bytes

 

User: Public

 

User: User

 

Total Flash Files Cleaned = 0,00 mb

 

 

[EMPTYTEMP]

 

User: All Users

 

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

User: GościeGoście

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 0 bytes

->Flash cache emptied: 0 bytes

 

User: Marcin

->Temp folder emptied: 167002 bytes

->Temporary Internet Files folder emptied: 43916 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 24955575 bytes

->Flash cache emptied: 0 bytes

 

User: Public

 

User: User

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 2286 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes

RecycleBin emptied: 0 bytes

 

Total Files Cleaned = 24,00 mb

 

 

OTL by OldTimer - Version 3.2.22.3 log created on 05212011_131346

 

Files\Folders moved on Reboot...

C:\Users\Marcin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

 

Registry entries deleted on Reboot...

 

 

OK a teraz otl

 

OTL logfile created on: 2011-05-21 13:27:37 - Run 3

OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Marcin\Desktop

64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7600.16385)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

 

4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 63,00% Memory free

8,00 Gb Paging File | 6,00 Gb Available in Paging File | 77,00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 58,57 Gb Total Space | 16,41 Gb Free Space | 28,02% Space Free | Partition Type: NTFS

Drive D: | 211,88 Gb Total Space | 36,33 Gb Free Space | 17,15% Space Free | Partition Type: NTFS

Drive E: | 195,31 Gb Total Space | 29,18 Gb Free Space | 14,94% Space Free | Partition Type: NTFS

Drive G: | 4,38 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF

 

Computer Name: MARCIN-KOMPUTER | User Name: Marcin | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2011-05-21 00:40:45 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Marcin\Desktop\OTL.exe

PRC - [2011-05-11 17:33:41 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

PRC - [2011-04-25 17:30:52 | 003,298,712 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe

PRC - [2011-04-14 18:59:13 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

PRC - [2010-11-22 23:52:46 | 000,718,072 | ---- | M] (Tunngle.net GmbH) -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe

PRC - [2010-11-19 21:08:40 | 000,066,872 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe

PRC - [2010-08-12 15:16:26 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe

PRC - [2010-05-25 16:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe

PRC - [2010-03-08 09:27:49 | 000,041,800 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\Common Files\AOL\1305110212\ee\aolsoftware.exe

PRC - [2009-11-04 07:45:46 | 002,320,920 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

PRC - [2009-11-04 07:45:44 | 000,268,824 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

PRC - [2009-10-13 12:25:54 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe

PRC - [2009-10-13 12:25:30 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe

PRC - [2008-08-04 15:45:16 | 005,779,456 | ---- | M] () -- C:\Program Files (x86)\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe

PRC - [2007-09-02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.exe

 

 

========== Modules (SafeList) ==========

 

MOD - [2011-05-21 00:40:45 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Marcin\Desktop\OTL.exe

MOD - [2011-05-10 10:48:00 | 000,043,520 | ---- | M] (RealNetworks, Inc.) -- C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchrome10browserrecordhelper.dll

MOD - [2011-04-15 14:32:06 | 000,038,304 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\idmmkb.dll

MOD - [2010-08-21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll

MOD - [2009-06-10 23:14:56 | 000,652,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4926_none_508ed732bcbc0e5a\msvcr90.dll

MOD - [2009-06-10 23:14:54 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4926_none_508ed732bcbc0e5a\msvcp90.dll

MOD - [2007-09-02 14:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.dll

 

 

========== Win32 Services (SafeList) ==========

 

SRV:64bit: - [2011-01-06 06:43:34 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)

SRV:64bit: - [2010-12-03 12:09:08 | 000,341,296 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Common Files\Nitro PDF\Reader\1.0\NitroPDFReaderDriverServicex64.exe -- (NitroReaderDriverReadSpool)

SRV:64bit: - [2010-08-12 15:18:40 | 000,042,360 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)

SRV:64bit: - [2010-08-12 15:16:26 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)

SRV:64bit: - [2010-06-08 23:52:16 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)

SRV:64bit: - [2010-01-19 18:26:58 | 001,420,560 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)

SRV:64bit: - [2010-01-19 18:08:16 | 000,315,664 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)

SRV:64bit: - [2010-01-19 18:05:22 | 000,831,760 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)

SRV:64bit: - [2009-07-14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009-07-14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)

SRV - [2011-01-07 01:48:59 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service)

SRV - [2011-01-06 06:43:31 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)

SRV - [2010-11-22 23:52:46 | 000,718,072 | ---- | M] (Tunngle.net GmbH) [Auto | Running] -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService)

SRV - [2010-11-19 21:08:40 | 000,066,872 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)

SRV - [2010-06-25 19:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)

SRV - [2009-11-04 07:45:46 | 002,320,920 | R--- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®

SRV - [2009-11-04 07:45:44 | 000,268,824 | R--- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®

SRV - [2009-10-13 12:25:30 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®

SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2008-08-04 15:45:16 | 005,779,456 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe -- (MySQL)

SRV - [2007-05-31 11:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)

SRV - [2007-05-31 11:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)

SRV - [2006-10-23 14:50:35 | 000,046,640 | R--- | M] (AOL LLC) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2011-03-28 19:46:40 | 000,146,568 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP)

DRV:64bit: - [2010-07-29 14:31:26 | 000,168,544 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)

DRV:64bit: - [2010-07-29 14:31:26 | 000,141,264 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)

DRV:64bit: - [2010-07-29 14:31:26 | 000,126,320 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)

DRV:64bit: - [2010-06-25 19:07:26 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)

DRV:64bit: - [2010-06-09 02:54:18 | 006,790,656 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)

DRV:64bit: - [2010-06-08 23:19:36 | 000,221,184 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)

DRV:64bit: - [2010-06-08 23:10:46 | 010,322,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)

DRV:64bit: - [2010-06-08 23:10:46 | 010,322,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)

DRV:64bit: - [2010-02-10 09:01:58 | 000,158,720 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)

DRV:64bit: - [2010-01-13 09:37:18 | 007,675,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) Sterownik karty Intel®

DRV:64bit: - [2010-01-07 21:51:38 | 000,271,872 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel®

DRV:64bit: - [2009-12-03 01:01:24 | 000,213,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)

DRV:64bit: - [2009-10-13 12:16:40 | 000,409,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)

DRV:64bit: - [2009-09-17 06:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel®

DRV:64bit: - [2009-09-16 08:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle)

DRV:64bit: - [2009-09-02 19:58:08 | 000,225,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)

DRV:64bit: - [2009-08-13 09:38:24 | 000,029,184 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcp.sys -- (BthAvrcp)

DRV:64bit: - [2009-07-14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV:64bit: - [2009-07-14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV:64bit: - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009-07-14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV:64bit: - [2009-07-14 02:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)

DRV:64bit: - [2009-06-10 23:01:06 | 001,146,880 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)

DRV:64bit: - [2009-06-10 22:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)

DRV:64bit: - [2009-06-10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV:64bit: - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2006-11-30 00:24:49 | 000,024,064 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wanatw64.sys -- (wanatw) WAN Miniport (ATW)

DRV - [2010-01-29 12:40:14 | 000,115,600 | ---- | M] (EZB Systems, Inc.) [File_System | System | Running] -- C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys -- (ISODrive)

DRV - [2009-09-02 19:58:08 | 000,225,280 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\RtsUStor.sys -- (RSUSBSTOR)

DRV - [2008-08-14 08:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

 

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..browser.search.defaultthis.engineName: ""

FF - prefs.js..browser.search.defaulturl: ""

FF - prefs.js..browser.search.selectedEngine: ""

FF - prefs.js..browser.search.update: false

FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"

 

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-05-11 17:33:55 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011-05-11 17:33:52 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011-05-11 17:34:08 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011-01-12 04:04:08 | 000,000,000 | ---D | M]

 

[2010-11-19 19:10:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcin\AppData\Roaming\mozilla\Extensions

[2011-05-21 01:31:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions

[2011-02-03 22:44:31 | 000,000,000 | ---D | M] (HP Detect) -- C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}

[2011-03-04 23:14:02 | 000,002,197 | ---- | M] () -- C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\6nh7v7o5.default\searchplugins\google-search.xml

[2011-05-01 22:07:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

[2010-11-20 04:22:19 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

[2011-01-17 18:13:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

File not found (No name found) --

[2011-05-11 17:33:55 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT

[2011-05-16 14:55:27 | 000,000,000 | ---D | M] (IDM CC) -- C:\USERS\MARCIN\APPDATA\ROAMING\IDM\IDMMZCC3

() (No name found) -- C:\USERS\MARCIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6NH7V7O5.DEFAULT\EXTENSIONS\{46551EC9-40F0-4E47-8E18-8E5CF550CFB8}.XPI

[2011-04-14 18:59:14 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll

[2010-11-12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

[2010-09-21 17:30:02 | 000,120,296 | ---- | M] ( ) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npganymedenet.dll

[2010-07-12 18:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll

[2010-01-01 10:00:00 | 000,002,767 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\allegro-pl.xml

[2010-01-01 10:00:00 | 000,001,406 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\fbc-pl.xml

[2011-03-04 23:14:02 | 000,002,197 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\google-search.xml

[2010-01-01 10:00:00 | 000,000,917 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\merlin-pl.xml

[2010-01-01 10:00:00 | 000,000,858 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\pwn-pl.xml

[2010-01-01 10:00:00 | 000,001,183 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-pl.xml

[2010-01-01 10:00:00 | 000,001,683 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wp-pl.xml

 

O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)

O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)

O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)

O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)

O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [iAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [igfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [intelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)

O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)

O4:64bit: - HKLM..\Run: [TNOD UP] C:\Program Files (x86)\TNod User & Password Finder\TNODUP.exe (Tukero[X]Team)

O4:64bit: - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation)

O4 - HKLM..\Run: [HostManager] C:\Program Files (x86)\Common Files\AOL\1305110212\ee\aolsoftware.exe (AOL Inc.)

O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)

O4 - HKCU..\Run: [iDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)

O4 - HKCU..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1

O8:64bit: - Extra context menu item: Ściągnij przez IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()

O8:64bit: - Extra context menu item: Ściągnij wszystkie linki przez IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()

O8:64bit: - Extra context menu item: 使用快车3下载 - C:\Users\Marcin\AppData\Roaming\FlashGetBHO\GetUrl.htm ()

O8:64bit: - Extra context menu item: 使用快车3下载全部链接 - C:\Users\Marcin\AppData\Roaming\FlashGetBHO\GetAllUrl.htm ()

O8 - Extra context menu item: Ściągnij przez IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()

O8 - Extra context menu item: Ściągnij wszystkie linki przez IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()

O8 - Extra context menu item: 使用快车3下载 - C:\Users\Marcin\AppData\Roaming\FlashGetBHO\GetUrl.htm ()

O8 - Extra context menu item: 使用快车3下载全部链接 - C:\Users\Marcin\AppData\Roaming\FlashGetBHO\GetAllUrl.htm ()

O13 - gopher Prefix: missing

O13 - gopher Prefix: missing

O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)

O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1302869998152 (MUCatalogWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)

O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 95.160.170.92 88.156.222.92

O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2011-03-25 00:45:38 | 000,437,782 | R--- | M] () - G:\autorun.ico -- [ UDF ]

O32 - AutoRun File - [2010-02-11 05:05:02 | 000,000,047 | R--- | M] () - G:\autorun.inf -- [ UDF ]

O33 - MountPoints2\{93197af5-f3f2-11df-b00c-806e6f6e6963}\Shell - "" = AutoRun

O33 - MountPoints2\{93197af5-f3f2-11df-b00c-806e6f6e6963}\Shell\AutoRun\command - "" = F:\CDSetup.exe

O33 - MountPoints2\F\Shell - "" = AutoRun

O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\CDSetup.exe

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2011-05-21 00:53:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TNod User & Password Finder

[2011-05-21 00:53:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TNod User & Password Finder

[2011-05-21 00:47:58 | 000,000,000 | ---D | C] -- C:\_OTL

[2011-05-21 00:40:46 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Marcin\Desktop\OTL.exe

[2011-05-20 15:48:17 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Desktop\Z TELEFONU

[2011-05-16 21:35:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace

[2011-05-16 15:08:21 | 000,000,000 | -H-D | C] -- C:\Users\Marcin\AppData\Roaming\SecuROM

[2011-05-16 15:08:21 | 000,000,000 | -H-D | C] -- C:\Users\Marcin\AppData\Roaming\Marcin

[2011-05-16 15:08:21 | 000,000,000 | -H-D | C] -- C:\Users\Marcin\AppData\Roaming\BlueSoft

[2011-05-16 14:35:24 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

[2011-05-13 10:01:32 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Desktop\to i owo

[2011-05-12 11:24:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Object

[2011-05-12 01:42:33 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Roaming\AOL

[2011-05-12 01:42:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL

[2011-05-12 01:42:22 | 000,058,696 | ---- | C] (AOL Inc.) -- C:\Windows\SysWow64\AOLParconLink.exe

[2011-05-12 01:42:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Software Update Utility

[2011-05-12 01:42:04 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\AOL Downloads

[2011-05-12 01:42:02 | 000,024,064 | ---- | C] (America Online, Inc.) -- C:\Windows\SysNative\drivers\wanatw64.sys

[2011-05-12 01:41:59 | 000,000,000 | ---D | C] -- C:\ProgramData\AOL OCP

[2011-05-12 01:41:54 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\AOL

[2011-05-12 01:41:40 | 000,000,000 | ---D | C] -- C:\ProgramData\AOL

[2011-05-12 01:35:40 | 000,000,000 | ---D | C] -- C:\ProgramData\AOL Downloads

[2011-05-11 17:33:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared

[2011-05-11 17:33:52 | 000,198,848 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll

[2011-05-11 17:33:44 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll

[2011-05-11 17:33:44 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll

[2011-05-11 17:33:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real

[2011-05-11 17:33:43 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll

[2011-05-11 17:33:41 | 000,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp71.dll

[2011-05-11 17:33:41 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr71.dll

[2011-05-11 12:36:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AOL

[2011-05-11 12:36:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AOL Desktop 9.6

[2011-05-11 12:36:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AOL

[2011-05-11 12:36:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\aolshare

[2011-05-10 10:47:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Real

[2011-05-10 10:47:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Real

[2011-05-10 10:47:39 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Roaming\Real

[2011-05-03 22:12:41 | 000,000,000 | ---D | C] -- C:\Temp

[2011-04-29 21:30:21 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\Apps

[2011-04-29 21:30:20 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\Deployment

[2011-04-28 00:26:02 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Documents\ArmA 2 Other Profiles

[2011-04-28 00:25:52 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Documents\ArmA 2

[2011-04-26 16:46:36 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive

[2011-04-26 16:46:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bohemia Interactive

[2011-04-26 16:25:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive

[2011-04-26 16:12:34 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Documents\SKIDROW

[2011-04-26 16:12:33 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\ArmA 2 REINFORCEMENTS

[2011-04-25 23:52:36 | 000,163,840 | ---- | C] (America Online) -- C:\Windows\SysWow64\jgdw400.dll

[2011-04-25 23:52:36 | 000,027,648 | ---- | C] (Johnson-Grace Company) -- C:\Windows\SysWow64\jgpl400.dll

[2011-04-25 17:41:51 | 000,146,568 | ---- | C] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys

[2011-04-25 00:43:13 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Documents\Alpha Protocol

[2011-04-25 00:42:04 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Roaming\SEGA Corporation

[2011-04-25 00:42:01 | 000,000,000 | ---D | C] -- C:\ProgramData\SEGA Corporation

[2011-04-24 23:28:44 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallShield

[2011-04-24 23:09:53 | 000,073,728 | ---- | C] (Macrovision Corporation) -- C:\Windows\SysWow64\ISUSPM.cpl

[2011-04-23 02:23:49 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Application Data

[2011-04-22 23:14:06 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\fat32format

 

========== Files - Modified Within 30 Days ==========

 

[2011-05-21 13:22:12 | 000,014,960 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2011-05-21 13:22:12 | 000,014,960 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2011-05-21 13:19:18 | 001,552,302 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2011-05-21 13:19:18 | 000,697,438 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat

[2011-05-21 13:19:18 | 000,615,958 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2011-05-21 13:19:18 | 000,136,896 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat

[2011-05-21 13:19:18 | 000,107,594 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2011-05-21 13:14:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2011-05-21 13:14:52 | 3055,693,824 | -HS- | M] () -- C:\hiberfil.sys

[2011-05-21 13:14:12 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\Access.dat

[2011-05-21 01:12:31 | 000,302,080 | ---- | M] () -- C:\Users\Marcin\Desktop\tx5rp0sb.exe

[2011-05-21 01:04:32 | 000,302,080 | ---- | M] () -- C:\Users\Marcin\Desktop\l3owgs9d.exe

[2011-05-21 00:40:45 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Marcin\Desktop\OTL.exe

[2011-05-20 15:52:54 | 052,720,183 | ---- | M] () -- C:\Users\Marcin\Desktop\ESET.rar

[2011-05-17 00:36:32 | 111,093,341 | ---- | M] () -- C:\Users\Marcin\Desktop\R.W.PL.01-02.2011.pdf

[2011-05-17 00:29:46 | 107,694,980 | ---- | M] () -- C:\Users\Marcin\Desktop\R.W.PL.02.2011.pdf

[2011-05-16 21:31:26 | 000,001,479 | ---- | M] () -- C:\Users\Public\Desktop\Operation Flashpoint ® Red River.lnk

[2011-05-16 14:35:24 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

[2011-05-13 01:16:53 | 000,009,728 | ---- | M] () -- C:\Users\Marcin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011-05-12 07:44:39 | 000,034,103 | ---- | M] () -- C:\Users\Marcin\Documents\sciaga-51778.rtf

[2011-05-12 02:07:18 | 000,000,002 | ---- | M] () -- C:\Windows\msoffice.ini

[2011-05-12 01:35:51 | 000,058,696 | ---- | M] (AOL Inc.) -- C:\Windows\SysWow64\AOLParconLink.exe

[2011-05-12 01:35:39 | 000,000,335 | ---- | M] () -- C:\Windows\nsreg.dat

[2011-05-11 20:20:48 | 000,202,448 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe

[2011-05-11 17:33:52 | 000,198,848 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll

[2011-05-11 17:33:44 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll

[2011-05-11 17:33:44 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll

[2011-05-11 17:33:43 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll

[2011-05-11 17:33:41 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp71.dll

[2011-05-11 17:33:41 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr71.dll

[2011-05-11 12:37:45 | 000,000,989 | ---- | M] () -- C:\Users\Public\Desktop\AOL Desktop 9.6.lnk

[2011-05-03 12:55:07 | 000,334,378 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0382.jpg

[2011-04-29 11:56:57 | 000,337,091 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0386.jpg

[2011-04-29 11:49:10 | 000,319,130 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0387.jpg

[2011-04-29 11:49:08 | 000,353,563 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0388.jpg

[2011-04-29 11:47:41 | 000,428,156 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0393.jpg

[2011-04-29 11:47:32 | 000,285,559 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0383.jpg

[2011-04-29 11:47:31 | 000,307,280 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0381.jpg

[2011-04-26 16:49:33 | 000,000,927 | ---- | M] () -- C:\Users\Public\Desktop\Uruchom ARMA 2 REINFORCEMENTS.lnk

[2011-04-25 23:52:36 | 000,163,840 | ---- | M] (America Online) -- C:\Windows\SysWow64\jgdw400.dll

[2011-04-25 23:52:36 | 000,027,648 | ---- | M] (Johnson-Grace Company) -- C:\Windows\SysWow64\jgpl400.dll

[2011-04-25 21:08:38 | 000,001,150 | ---- | M] () -- C:\Users\Marcin\Desktop\APGame.lnk

[2011-04-21 16:32:59 | 000,369,296 | ---- | M] () -- C:\Users\Marcin\Documents\Dj Olimp B-day party.jpg

[2011-04-21 15:06:00 | 000,593,504 | ---- | M] () -- C:\Users\Marcin\Documents\lany(2).jpg

[2011-04-21 14:57:18 | 000,597,972 | ---- | M] () -- C:\Users\Marcin\Documents\lany(1).jpg

[2011-04-21 14:57:09 | 000,597,972 | ---- | M] () -- C:\Users\Marcin\Documents\lany.jpg

[2011-04-21 14:28:04 | 000,543,440 | ---- | M] () -- C:\Users\Marcin\Documents\lany poniedziałek(1).jpg

[2011-04-21 14:19:25 | 000,555,397 | ---- | M] () -- C:\Users\Marcin\Documents\lany poniedziałek.jpg

 

========== Files Created - No Company Name ==========

 

[2011-05-21 01:12:37 | 000,302,080 | ---- | C] () -- C:\Users\Marcin\Desktop\tx5rp0sb.exe

[2011-05-21 01:04:34 | 000,302,080 | ---- | C] () -- C:\Users\Marcin\Desktop\l3owgs9d.exe

[2011-05-20 15:52:54 | 052,720,183 | ---- | C] () -- C:\Users\Marcin\Desktop\ESET.rar

[2011-05-17 00:36:31 | 111,093,341 | ---- | C] () -- C:\Users\Marcin\Desktop\R.W.PL.01-02.2011.pdf

[2011-05-17 00:29:46 | 107,694,980 | ---- | C] () -- C:\Users\Marcin\Desktop\R.W.PL.02.2011.pdf

[2011-05-16 21:31:26 | 000,001,479 | ---- | C] () -- C:\Users\Public\Desktop\Operation Flashpoint ® Red River.lnk

[2011-05-12 07:44:39 | 000,034,103 | ---- | C] () -- C:\Users\Marcin\Documents\sciaga-51778.rtf

[2011-05-12 02:07:18 | 000,000,002 | ---- | C] () -- C:\Windows\msoffice.ini

[2011-05-11 12:37:45 | 000,000,989 | ---- | C] () -- C:\Users\Public\Desktop\AOL Desktop 9.6.lnk

[2011-05-01 22:07:13 | 000,001,150 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk

[2011-04-29 11:56:40 | 000,337,091 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0386.jpg

[2011-04-29 11:48:48 | 000,319,130 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0387.jpg

[2011-04-29 11:48:47 | 000,353,563 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0388.jpg

[2011-04-29 11:47:22 | 000,428,156 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0393.jpg

[2011-04-29 11:47:07 | 000,285,559 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0383.jpg

[2011-04-29 11:47:05 | 000,334,378 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0382.jpg

[2011-04-29 11:47:05 | 000,307,280 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0381.jpg

[2011-04-26 16:49:33 | 000,000,927 | ---- | C] () -- C:\Users\Public\Desktop\Uruchom ARMA 2 REINFORCEMENTS.lnk

[2011-04-25 21:08:38 | 000,001,150 | ---- | C] () -- C:\Users\Marcin\Desktop\APGame.lnk

[2011-04-24 00:09:55 | 000,049,233 | ---- | C] () -- C:\Windows\fat32format.exe

[2011-04-21 16:32:41 | 000,369,296 | ---- | C] () -- C:\Users\Marcin\Documents\Dj Olimp B-day party.jpg

[2011-04-21 15:05:37 | 000,593,504 | ---- | C] () -- C:\Users\Marcin\Documents\lany(2).jpg

[2011-04-21 14:56:53 | 000,597,972 | ---- | C] () -- C:\Users\Marcin\Documents\lany(1).jpg

[2011-04-21 14:56:46 | 000,597,972 | ---- | C] () -- C:\Users\Marcin\Documents\lany.jpg

[2011-04-21 14:27:43 | 000,543,440 | ---- | C] () -- C:\Users\Marcin\Documents\lany poniedziałek(1).jpg

[2011-04-21 14:19:04 | 000,555,397 | ---- | C] () -- C:\Users\Marcin\Documents\lany poniedziałek.jpg

[2011-04-09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat

[2011-03-18 16:39:28 | 000,000,094 | ---- | C] () -- C:\Users\Marcin\AppData\Local\fusioncache.dat

[2011-03-18 16:37:37 | 001,576,536 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2011-03-02 15:47:24 | 000,001,770 | ---- | C] () -- C:\Windows\SysWow64\secushr.dat

[2011-03-02 14:09:58 | 000,000,468 | ---- | C] () -- C:\Windows\SysWow64\secustat.dat

[2011-03-02 14:04:57 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI

[2011-02-09 23:22:37 | 000,000,017 | ---- | C] () -- C:\Users\Marcin\AppData\Local\resmon.resmoncfg

[2011-02-07 15:25:54 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat

[2011-02-01 11:10:31 | 000,036,864 | ---- | C] () -- C:\Windows\hpfsched.exe

[2011-02-01 11:10:26 | 000,004,760 | ---- | C] () -- C:\Windows\hphmdl11.dat

[2011-01-11 03:20:17 | 000,009,728 | ---- | C] () -- C:\Users\Marcin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011-01-07 02:14:21 | 000,000,000 | ---- | C] () -- C:\Users\Marcin\AppData\Roaming\AVSMediaPlayer.m3u

[2010-12-29 03:08:45 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll

[2010-11-22 00:58:18 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll

[2010-11-20 04:13:12 | 000,002,110 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat

[2010-11-19 21:08:56 | 000,202,448 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe

[2010-11-19 21:08:40 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe

[2010-11-19 20:27:45 | 000,000,313 | ---- | C] () -- C:\Windows\CODUO.ini

[2010-11-19 20:21:30 | 000,000,713 | ---- | C] () -- C:\Windows\COD.INI

[2010-11-19 19:22:59 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin

[2010-11-19 19:09:58 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat

[2010-11-17 23:42:54 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin

[2010-11-17 23:42:54 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin

[2010-11-17 23:42:53 | 000,002,110 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

[2010-08-25 20:34:30 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin

[2010-08-25 19:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll

[2010-08-25 19:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll

[2010-06-25 19:03:12 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll

[2009-07-14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat

[2009-07-14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT

[2009-07-14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat

[2009-07-14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin

[2009-07-14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll

[2009-07-13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

[2009-06-10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 55920 bytes -> C:\ProgramData:$SS_DESCRIPTOR_LVVWVBGV0VFBTLX4D06YH7LVUTPXGJMBKE1R0WT1VH7E24F7PHCTVF4VMVFVVX4VM

 

< End of report >

 

 

 

 

i extras

OTL Extras logfile created on: 2011-05-21 13:27:37 - Run 3

OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Marcin\Desktop

64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7600.16385)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

 

4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 63,00% Memory free

8,00 Gb Paging File | 6,00 Gb Available in Paging File | 77,00% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 58,57 Gb Total Space | 16,41 Gb Free Space | 28,02% Space Free | Partition Type: NTFS

Drive D: | 211,88 Gb Total Space | 36,33 Gb Free Space | 17,15% Space Free | Partition Type: NTFS

Drive E: | 195,31 Gb Total Space | 29,18 Gb Free Space | 14,94% Space Free | Partition Type: NTFS

Drive G: | 4,38 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF

 

Computer Name: MARCIN-KOMPUTER | User Name: Marcin | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

.js[@ = JSFile] -- C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe (Macromedia, Inc.)

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

.js [@ = JSFile] -- C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe (Macromedia, Inc.)

 

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

 

========== Shell Spawning ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %* File not found

cmdfile [open] -- "%1" %* File not found

comfile [open] -- "%1" %* File not found

exefile [open] -- "%1" %* File not found

helpfile [open] -- Reg Error: Key error.

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

jsfile [edit] -- "C:\Program Files (x86)\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)

jsfile [open] -- "C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1" (Macromedia, Inc.)

piffile [open] -- "%1" %* File not found

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1" File not found

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found

scrfile [open] -- "%1" /S File not found

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

jsfile [edit] -- "C:\Program Files (x86)\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)

jsfile [open] -- "C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1" (Macromedia, Inc.)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

"DisableUnicastResponsesToMulticastBroadcast" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3

"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{0CB41726-DEBA-46E1-B48B-873F012ACAA1}" = Nitro PDF Reader

"{16CC554E-7E33-4C60-9EE4-A781DCAB65A8}" = ESET NOD32 Antivirus

"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64

"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64

"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

"{64798798-D0C8-4246-56FB-5C5D8A61615C}" = ATI Catalyst Install Manager

"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64

"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64

"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4

"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4

"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64

"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010

"{90140000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2010

"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager

"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4

"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant

"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64

"{A8725474-37EF-7FCE-DB35-D2CCE7A4C462}" = ccc-utility64

"{B90E5EBE-DF18-44D5-9D18-689ADEE9DA6C}" = Oprogramowanie Intel® PROSet/Wireless WiFi

"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)

"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4

"CCleaner" = CCleaner

"KLiteCodecPack64_is1" = K-Lite Codec Pack (64-bit) v4.5.0

"ProInst" = Intel PROSet Wireless

"TNod" = TNod User & Password Finder

"WinRAR archiver" = Archiwizator WinRAR

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4

"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4

"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4

"{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004

"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8

"{08DE5112-C279-F317-EB93-4D30708A3AE4}" = CCC Help Czech

"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler

"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4

"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup

"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4

"{11742D23-0668-5AA8-19FA-8F88FADC1ABE}" = Catalyst Control Center Graphics Light

"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4

"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4

"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB

"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR

"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1

"{1AFF250C-F408-DBBA-ECBE-33467D3F76BC}" = CCC Help Chinese Standard

"{1B33B869-A7B8-3F7B-CB3D-54D1A2A16B37}" = Catalyst Control Center Graphics Previews Vista

"{1E445925-273D-4186-88A0-B8D1B6B119E2}" = WRC FIA World Rally Championship

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{22EDD164-65D5-41DD-961E-08C7CDA4D471}" = Bridge!

"{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback 10

"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10

"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java 6 Update 23

"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10

"{27BA485D-529E-F94D-C8C5-499547E6493A}" = CCC Help Danish

"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1

"{2D2E4682-3B5C-5A3C-1379-F497BCC8B55C}" = CCC Help Chinese Traditional

"{32BB5A09-D930-EB57-737D-7B0BAD29D5D2}" = CCC Help Japanese

"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4

"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player

"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4

"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4

"{3D735073-A39C-F5B4-5A9F-CC8B5177251D}" = CCC Help Hungarian

"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin

"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX

"{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}" = FIFA 11

"{406AD3D7-F5BB-49C1-A280-6BCB5F6BC099}" = MySQL Server 5.0

"{409597FD-C9EE-4658-8B13-535DFF22B666}_is1" = Milionerzy 2.0.6

"{434D083E-7E9A-4D3A-914B-121000008100}" = Operation Flashpoint ®: Red River

"{488CC14B-15FC-AFFB-F8E4-72B97F7A7C00}" = CCC Help Polish

"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace

"{52EC4C05-0290-D8DB-948E-4BE0C8FE5F4D}" = CCC Help Norwegian

"{53128B2F-8A2B-5FC7-B735-3826B294BE7D}" = Catalyst Control Center Graphics Full New

"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI

"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries

"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager

"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4

"{5833B2D1-B2C1-2819-1EA5-EE23C772DF01}" = CCC Help English

"{6291FC10-FDF0-4022-A1A5-710C728D49C2}" = Vancouver 2010

"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic

"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4

"{63C48CA5-C5D3-2E46-06A4-1A06791A20AB}" = CCC Help Korean

"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support

"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components

"{679A64E7-14CD-FF36-1470-9DED77603F7B}" = CCC Help Russian

"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4

"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK

"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729

"{6BC27278-28F6-D98A-587C-591FD8DDDC4C}" = PowerXpressHybrid

"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10

"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10

"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

"{74B5512F-E710-8F87-4597-B126F54BD6D1}" = CCC Help Thai

"{7703D8FE-8C98-8CD9-A946-475DC6BBA04C}" = CCC Help Spanish

"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime

"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10

"{7B034E4B-A41A-7B9F-9820-C58C4CC99716}" = Catalyst Control Center Core Implementation

"{7D73203D-5854-3B87-25A7-9025829EB076}" = CCC Help Finnish

"{7ED5371F-F4EA-48F9-B8F7-C8777AD9DF69}" = Borland Turbo C++

"{81DD0597-29EB-4FA0-8223-4F41362B2E72}" = NBA 2K11

"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4

"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4

"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8B743AA0-53B2-11D2-808A-00600895FB43}" = Heroes of Might and Magic III - Złota Edycja

"{8BCD960B-2ECC-595C-F934-543061F10F2B}" = CCC Help Italian

"{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}" = SWAT 4

"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010

"{90140000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010

"{90140000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010

"{90140000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010

"{90140000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010

"{90140000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010

"{90140000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010

"{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010

"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010

"{90140000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010

"{90140000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010

"{90140000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010

"{90140000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010

"{90140000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010

"{90140000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010

"{909F8EBC-EC7F-48FF-0085-475D818F0F31}" = Need for Speed Underground 2

"{92942F31-C642-7839-BA61-CC5E1DD9397D}" = CCC Help Swedish

"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4

"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4

"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{A2092B2A-A4FB-4464-A4C0-023D2C9993F8}" = m-Router 3.1

"{A5F481DE-A5D2-725F-A0F3-1E663272D198}" = PX Profile Update

"{A662E280-64A8-4CF5-8407-13D0808602B3}" = Call of Duty - United Offensive

"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries

"{AC08BBA0-96B9-431A-A7D0-D8598E493775}" = RESIDENT EVIL 5

"{AC76BA86-7AD7-1045-7B44-A94000000001}" = Adobe Reader 9.4.4 - Polish

"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect

"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4

"{B6E3F2A0-DDBB-4F0A-BA7C-09138605DDAC}" = WRC FIA World Rally Championship

"{BA659DC5-F577-4364-903D-20C16DD4BDB3}" = Catalyst Control Center - Branding

"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module

"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10

"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4

"{C85F4BE3-0725-1D9C-50D7-27A5F8CBE6EF}" = CCC Help Greek

"{CA659543-232D-9B74-7058-A8C2DDA16405}" = ccc-core-static

"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw

"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86

"{CD0A677F-D3BB-1187-1669-AE2960659370}" = Catalyst Control Center Localization All

"{CF83661A-F6FC-39A7-9552-B86E1239CC40}" = CCC Help Turkish

"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005

"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.22 Game

"{D37FE0E3-B1A9-4E41-AB5D-DA62E04D2C42}" = Alpha Protocol

"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver

"{D850DA0F-468D-9BCE-D601-A41D294F1BD8}" = Catalyst Control Center InstallProxy

"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10

"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4

"{E81E7CD7-74D6-E355-F19A-427F1B2EE3BF}" = Catalyst Control Center Graphics Full Existing

"{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}" = Microsoft .NET Framework SDK (English) 1.1

"{EBC48194-90E6-EBA1-0DD6-9466095E1CAF}" = CCC Help French

"{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10

"{EF5B8746-E00C-6306-879E-05444A6839C9}" = CCC Help Portuguese

"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable

"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10

"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic

"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10

"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4

"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4

"{FC09D493-A649-E880-A505-DEAA304E1A8D}" = CCC Help German

"{FC8CF7E1-5722-9952-2A56-8C28E2D17A42}" = CCC Help Dutch

"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All

"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4

"ALLPlayer_is1" = ALLPlayer V4.X

"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)

"ARMA 2 REINFORCEMENTS" = ARMA 2 REINFORCEMENTS Uninstall

"Ashampoo Burning Studio 10_is1" = Ashampoo Burning Studio 10.0.4

"Call of Duty" = Call of Duty

"Call of Duty Modern Warfare 2_is1" = Call of Duty Modern Warfare 2

"Cisco Packet Tracer_is1" = Cisco Packet Tracer 5.2.1

"ClassicPro" = ClassicPro© v1.15

"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player

"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)

"Emergency 2012" = Emergency 2012

"GameDesire-Poker" = GameDesire-Poker

"GFWL_{434D083E-7E9A-4D3A-914B-121000008100}" = Operation Flashpoint ®: Red River

"Gold Wave Editor Pro_is1" = Gold Wave Editor Pro v10.5.5

"Gordon's Gate Flash Driver" = Gordon's Gate Flash Driver 2.2.0.1

"InstallShield_{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}" = SWAT 4

"InstallShield_{A662E280-64A8-4CF5-8407-13D0808602B3}" = Call of Duty - United Offensive

"Internet Download Manager" = Internet Download Manager

"ipla" = ipla 2.3

"Komputer i Ty Kurs PHP1.0" = Komputer i Ty Kurs PHP

"Left 4 Dead" = Left 4 Dead

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Mozilla Firefox 4.0.1 (x86 pl)" = Mozilla Firefox 4.0.1 (x86 pl)

"NapiProjekt_is1" = NapiProjekt 1.0.6.9

"Nowe Gadu-Gadu" = Nowe Gadu-Gadu

"Office14.PROPLUS" = Microsoft Office Professional Plus 2010

"OpenAL" = OpenAL

"RealPlayer 12.0" = RealPlayer

"RocketDock_is1" = RocketDock 1.3.5

"slow_12_60_is1" = Profesor Henry 6.0 Słownictwo poziom 1 i 2

"Sniper - Ghost Warrior_is1" = Sniper - Ghost Warrior

"SoftwareUpdUtility" = Download Updater (AOL LLC)

"Splinter Cell: Teoria Chaosu_is1" = Splinter Cell: Teoria Chaosu 1.05 PL

"Totalcmd" = Total Commander (Remove or Repair)

"Tunngle beta_is1" = Tunngle beta

"UltraISO_is1" = UltraISO Premium V9.36

"uTorrent" = µTorrent

"Winamp" = Winamp

"WinPcapInst" = WinPcap 4.1.2

"Wireshark" = Wireshark 1.4.3

"WisBar Advance Desktop_is1" = WisBar Advance Desktop 2.5c

 

========== HKEY_CURRENT_USER Uninstall List ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Winamp Detect" = Detektor Winampa

 

========== Last 10 Event Log Errors ==========

 

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

 

< End of report >

Odnośnik do komentarza

Log:

 

############################## | UsbFix 7.045 | [Listing]

 

User: Marcin (Administrator) # MARCIN-KOMPUTER [Micro-Star International MS-1675]

Updated 15/05/2011 by TeamXscript

Started at 22:21:42 | 21/05/2011

Website: http://www.teamxscript.org

Submit your sample: http://www.teamxscript.org/Upload.php

Contact: TeamXscript.ElDesaparecido@gmail.com

 

CPU: Intel® Core i5 CPU M 460 @ 2.53GHz

CPU 2: Intel® Core i5 CPU M 460 @ 2.53GHz

Microsoft Windows 7 Professional (6.1.7600 64-Bit) #

Internet Explorer 8.0.7600.16385

 

Windows Firewall: Disabled /!\

RAM -> 3886 Mb

C:\ (%systemdrive%) -> Fixed drive # 59 Gb (16 Mb free - 27%) [] # NTFS

D:\ -> Fixed drive # 212 Gb (36 Mb free - 17%) [GIERKI] # NTFS

E:\ -> Fixed drive # 195 Gb (29 Mb free - 15%) [uŻYTKI] # NTFS

F:\ -> CD-ROM

G:\ -> CD-ROM

H:\ -> Fixed drive # 29 Gb (18 Mb free - 60%) [NOWY] # FAT32

J:\ -> Fixed drive # 166 Gb (166 Mb free - 100%) [NTSF] # NTFS

K:\ -> Fixed drive # 270 Gb (173 Mb free - 64%) [2_exFAT] # exFAT

 

################## | Listing |

 

[25/03/2011 - 21:23:31 | SHD ] C:\$Recycle.Bin

[19/11/2010 - 18:53:07 | D ] C:\AMD

[19/11/2010 - 18:51:18 | D ] C:\ATI

[19/11/2010 - 17:34:19 | SHD ] C:\Boot

[14/07/2009 - 03:38:58 | RASH | 383562] C:\bootmgr

[19/11/2010 - 17:34:21 | RASH | 8192] C:\BOOTSECT.BAK

[20/11/2010 - 02:08:36 | D ] C:\Dev-Cpp

[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings

[03/02/2011 - 19:20:26 | D ] C:\Download

[21/05/2011 - 21:32:49 | ASH | 3055693824] C:\hiberfil.sys

[11/05/2011 - 12:37:37 | A | 62390] C:\install.log

[19/11/2010 - 18:45:20 | D ] C:\Intel

[05/12/2010 - 22:54:08 | RHD ] C:\MSOCache

[21/05/2011 - 21:32:51 | ASH | 4074258432] C:\pagefile.sys

[14/07/2009 - 05:20:08 | D ] C:\PerfLogs

[15/04/2011 - 19:08:51 | RD ] C:\Program Files

[21/05/2011 - 01:00:57 | D ] C:\Program Files (x86)

[21/05/2011 - 01:00:38 | AHD ] C:\ProgramData

[19/11/2010 - 18:41:10 | SHD ] C:\Recovery

[21/05/2011 - 14:23:02 | SHD ] C:\System Volume Information

[03/05/2011 - 22:30:18 | D ] C:\Temp

[10/12/2010 - 00:30:32 | D ] C:\totalcmd

[12/04/2011 - 12:39:44 | D ] C:\ToxSickLabs

[21/05/2011 - 22:20:36 | D ] C:\UsbFix

[21/05/2011 - 22:21:39 | A | 2204] C:\UsbFix.txt

[04/04/2011 - 17:29:15 | D ] C:\USBFlashDriver

[25/03/2011 - 21:23:28 | RD ] C:\Users

[21/05/2011 - 13:13:47 | D ] C:\Windows

[26/11/2010 - 19:32:03 | A | 4948] C:\WirelessDiagLog.csv

[21/05/2011 - 00:47:58 | D ] C:\_OTL

[25/03/2011 - 21:23:31 | SHD ] D:\$RECYCLE.BIN

[09/04/2011 - 00:09:56 | D ] D:\Bridge The Construction Game (2011)

[03/03/2011 - 21:05:30 | D ] D:\Downloads

[15/04/2011 - 00:52:21 | D ] D:\DwnlData

[11/03/2011 - 21:57:59 | D ] D:\ELiTE.Hdyk

[21/05/2011 - 00:58:22 | D ] D:\GRY

[04/05/2011 - 01:17:06 | D ] D:\GRY iso

[12/05/2011 - 18:42:23 | D ] D:\Jezyk Angielski Callan Method-Ksiazki i mp3

[19/11/2010 - 16:18:59 | HD ] D:\msdownld.tmp

[10/01/2011 - 16:09:44 | D ] D:\OFFICE_2010

[19/03/2011 - 00:41:40 | D ] D:\ProHe6.Slcd1

[21/03/2011 - 01:59:28 | AH | 419430400] D:\ProHe6.Slcd2.part1.rar

[21/03/2011 - 02:02:36 | AH | 304746654] D:\ProHe6.Slcd2.part2.rar

[21/03/2011 - 02:08:12 | AH | 419430400] D:\ProHe6.Slcd4.part1.rar

[21/03/2011 - 02:10:52 | AH | 184033442] D:\ProHe6.Slcd4.part2.rar

[17/11/2010 - 17:02:26 | SHD ] D:\System Volume Information

[25/03/2011 - 21:23:31 | SHD ] E:\$RECYCLE.BIN

[07/04/2011 - 15:57:37 | D ] E:\DO KOMA

[20/05/2011 - 15:47:12 | RD ] E:\DOKUMENTY

[20/05/2011 - 23:11:18 | RD ] E:\FILMY

[25/12/2010 - 01:58:45 | D ] E:\HUMOR

[09/02/2011 - 22:09:02 | RD ] E:\MUZYCZKA

[06/02/2011 - 03:44:19 | A | 50863] E:\Nowy.ncd

[08/04/2011 - 00:45:59 | RD ] E:\POBIERANE

[14/04/2011 - 11:37:17 | D ] E:\poradnik

[07/04/2011 - 15:40:29 | RD ] E:\PREZENTACJE

[21/05/2011 - 01:33:06 | D ] E:\programosy

[21/05/2011 - 01:19:09 | RD ] E:\PWSZ

[17/11/2010 - 17:02:27 | SHD ] E:\System Volume Information

[04/04/2011 - 16:45:05 | RD ] E:\ZDJĘCIA

[25/03/2011 - 01:02:21 | RA | 24564] G:\ChainInstall.xml

[25/03/2011 - 01:00:12 | RA | 7247] G:\ChainInstall.xml.cat

[20/04/2011 - 18:51:34 | RAD ] G:\Crack

[29/03/2011 - 10:09:25 | RAD ] G:\EULA

[02/03/2011 - 22:58:30 | RA | 183] G:\GFWL_Installer_Autorun.bat

[25/03/2011 - 01:34:10 | RA | 4136960] G:\Game.msi

[29/03/2011 - 10:11:29 | RAD ] G:\Manuals

[25/03/2011 - 00:52:00 | RA | 1994332555] G:\Media1.cab

[25/03/2011 - 00:52:14 | RA | 1908090967] G:\Media2.cab

[25/03/2011 - 00:46:41 | RA | 531254356] G:\Media3.cab

[29/03/2011 - 10:09:25 | RAD ] G:\Readme

[29/03/2011 - 10:09:15 | RAD ] G:\Redist

[02/03/2011 - 22:58:50 | RA | 440704] G:\Setup.exe

[29/03/2011 - 10:09:11 | RAD ] G:\SetupMedia

[25/03/2011 - 00:45:38 | RA | 437782] G:\autorun.ico

[11/02/2010 - 05:05:02 | RA | 47] G:\autorun.inf

[12/03/2010 - 12:37:14 | RA | 187544] G:\xliveinstall.dll

[19/04/2011 - 01:03:58 | A | 741148672] H:\psig-white.material.2009.pl.dvdrip.xvid.avi

[12/05/2011 - 17:53:42 | A | 41] H:\pmp_usb.ini

[01/05/2011 - 15:32:46 | D ] H:\Dom Zły (2009) PL.480p

[01/05/2011 - 15:37:56 | D ] H:\Kumple na Zabój - The Matador (2005)

[01/05/2011 - 15:46:14 | D ] H:\Pułapka - Hard Candy (2005) PL

[12/05/2011 - 17:54:06 | D ] H:\oglądane

[11/05/2011 - 20:16:36 | D ] H:\Czarny Łabędź - Black Swan 2010 PL

[11/05/2011 - 20:18:00 | D ] H:\Miłość i inne używki - Love and Other Drugs (2010) PL

[12/05/2011 - 18:41:04 | SHD ] H:\$RECYCLE.BIN

[12/05/2011 - 19:04:28 | A | 52] H:\winamp_metadata.idx

[12/05/2011 - 19:04:28 | A | 423] H:\winamp_metadata.dat

[12/05/2011 - 19:16:30 | D ] H:\Bez Reguł

[18/05/2011 - 16:08:20 | A | 39] H:\autorun.inf

[18/05/2011 - 16:08:20 | A | 18944] H:\Nie uruchamiaj tego.exe

[17/05/2011 - 20:27:42 | D ] J:\aaa

[18/05/2011 - 16:08:24 | A | 39] J:\autorun.inf

[18/05/2011 - 16:08:23 | A | 18944] J:\Nie uruchamiaj tego.exe

[17/05/2011 - 20:24:15 | SHD ] J:\System Volume Information

[22/04/2011 - 23:03:04 | SHD ] K:\$RECYCLE.BIN

[24/04/2011 - 00:17:27 | D ] K:\GIERKI_ISO

[18/05/2011 - 16:08:30 | A | 39] K:\autorun.inf

[18/05/2011 - 16:08:30 | A | 18944] K:\Nie uruchamiaj tego.exe

 

################## | E.O.F |

Odnośnik do komentarza

Wyniki:

 

========== FILES ==========

File move failed. G:\autorun.inf scheduled to be moved on reboot.

H:\autorun.inf moved successfully.

K:\autorun.inf moved successfully.

J:\autorun.inf moved successfully.

H:\Nie uruchamiaj tego.exe moved successfully.

J:\Nie uruchamiaj tego.exe moved successfully.

K:\Nie uruchamiaj tego.exe moved successfully.

 

OTL by OldTimer - Version 3.2.22.3 log created on 05212011_231246

 

Files\Folders moved on Reboot...

File move failed. G:\autorun.inf scheduled to be moved on reboot.

 

Registry entries deleted on Reboot...

 

oraz nowy Listing - czyli widzę, ze się pousuwały

 

############################## | UsbFix 7.045 | [Listing]

 

User: Marcin (Administrator) # MARCIN-KOMPUTER [Micro-Star International MS-1675]

Updated 15/05/2011 by TeamXscript

Started at 23:16:00 | 21/05/2011

Website: http://www.teamxscript.org

Submit your sample: http://www.teamxscript.org/Upload.php

Contact: TeamXscript.ElDesaparecido@gmail.com

 

CPU: Intel® Core i5 CPU M 460 @ 2.53GHz

CPU 2: Intel® Core i5 CPU M 460 @ 2.53GHz

Microsoft Windows 7 Professional (6.1.7600 64-Bit) #

Internet Explorer 8.0.7600.16385

 

Windows Firewall: Disabled /!\

RAM -> 3886 Mb

C:\ (%systemdrive%) -> Fixed drive # 59 Gb (16 Mb free - 27%) [] # NTFS

D:\ -> Fixed drive # 212 Gb (36 Mb free - 17%) [GIERKI] # NTFS

E:\ -> Fixed drive # 195 Gb (29 Mb free - 15%) [uŻYTKI] # NTFS

F:\ -> CD-ROM

G:\ -> CD-ROM

H:\ -> Fixed drive # 29 Gb (18 Mb free - 60%) [NOWY] # FAT32

J:\ -> Fixed drive # 166 Gb (166 Mb free - 100%) [NTSF] # NTFS

K:\ -> Fixed drive # 270 Gb (173 Mb free - 64%) [2_exFAT] # exFAT

 

################## | Listing |

 

[25/03/2011 - 21:23:31 | SHD ] C:\$Recycle.Bin

[19/11/2010 - 18:53:07 | D ] C:\AMD

[19/11/2010 - 18:51:18 | D ] C:\ATI

[19/11/2010 - 17:34:19 | SHD ] C:\Boot

[14/07/2009 - 03:38:58 | RASH | 383562] C:\bootmgr

[19/11/2010 - 17:34:21 | RASH | 8192] C:\BOOTSECT.BAK

[20/11/2010 - 02:08:36 | D ] C:\Dev-Cpp

[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings

[03/02/2011 - 19:20:26 | D ] C:\Download

[21/05/2011 - 23:13:44 | ASH | 3055693824] C:\hiberfil.sys

[11/05/2011 - 12:37:37 | A | 62390] C:\install.log

[19/11/2010 - 18:45:20 | D ] C:\Intel

[05/12/2010 - 22:54:08 | RHD ] C:\MSOCache

[21/05/2011 - 23:13:48 | ASH | 4074258432] C:\pagefile.sys

[14/07/2009 - 05:20:08 | D ] C:\PerfLogs

[15/04/2011 - 19:08:51 | RD ] C:\Program Files

[21/05/2011 - 01:00:57 | D ] C:\Program Files (x86)

[21/05/2011 - 22:28:16 | AHD ] C:\ProgramData

[19/11/2010 - 18:41:10 | SHD ] C:\Recovery

[21/05/2011 - 14:23:02 | SHD ] C:\System Volume Information

[03/05/2011 - 22:30:18 | D ] C:\Temp

[10/12/2010 - 00:30:32 | D ] C:\totalcmd

[12/04/2011 - 12:39:44 | D ] C:\ToxSickLabs

[21/05/2011 - 22:20:36 | D ] C:\UsbFix

[21/05/2011 - 23:15:57 | A | 2204] C:\UsbFix.txt

[04/04/2011 - 17:29:15 | D ] C:\USBFlashDriver

[25/03/2011 - 21:23:28 | RD ] C:\Users

[21/05/2011 - 13:13:47 | D ] C:\Windows

[26/11/2010 - 19:32:03 | A | 4948] C:\WirelessDiagLog.csv

[21/05/2011 - 00:47:58 | D ] C:\_OTL

[25/03/2011 - 21:23:31 | SHD ] D:\$RECYCLE.BIN

[09/04/2011 - 00:09:56 | D ] D:\Bridge The Construction Game (2011)

[03/03/2011 - 21:05:30 | D ] D:\Downloads

[15/04/2011 - 00:52:21 | D ] D:\DwnlData

[11/03/2011 - 21:57:59 | D ] D:\ELiTE.Hdyk

[21/05/2011 - 00:58:22 | D ] D:\GRY

[04/05/2011 - 01:17:06 | D ] D:\GRY iso

[12/05/2011 - 18:42:23 | D ] D:\Jezyk Angielski Callan Method-Ksiazki i mp3

[19/11/2010 - 16:18:59 | HD ] D:\msdownld.tmp

[10/01/2011 - 16:09:44 | D ] D:\OFFICE_2010

[19/03/2011 - 00:41:40 | D ] D:\ProHe6.Slcd1

[21/03/2011 - 01:59:28 | AH | 419430400] D:\ProHe6.Slcd2.part1.rar

[21/03/2011 - 02:02:36 | AH | 304746654] D:\ProHe6.Slcd2.part2.rar

[21/03/2011 - 02:08:12 | AH | 419430400] D:\ProHe6.Slcd4.part1.rar

[21/03/2011 - 02:10:52 | AH | 184033442] D:\ProHe6.Slcd4.part2.rar

[17/11/2010 - 17:02:26 | SHD ] D:\System Volume Information

[25/03/2011 - 21:23:31 | SHD ] E:\$RECYCLE.BIN

[07/04/2011 - 15:57:37 | D ] E:\DO KOMA

[20/05/2011 - 15:47:12 | RD ] E:\DOKUMENTY

[20/05/2011 - 23:11:18 | RD ] E:\FILMY

[25/12/2010 - 01:58:45 | D ] E:\HUMOR

[09/02/2011 - 22:09:02 | RD ] E:\MUZYCZKA

[06/02/2011 - 03:44:19 | A | 50863] E:\Nowy.ncd

[08/04/2011 - 00:45:59 | RD ] E:\POBIERANE

[14/04/2011 - 11:37:17 | D ] E:\poradnik

[07/04/2011 - 15:40:29 | RD ] E:\PREZENTACJE

[21/05/2011 - 01:33:06 | D ] E:\programosy

[21/05/2011 - 01:19:09 | RD ] E:\PWSZ

[17/11/2010 - 17:02:27 | SHD ] E:\System Volume Information

[04/04/2011 - 16:45:05 | RD ] E:\ZDJĘCIA

[25/03/2011 - 01:02:21 | RA | 24564] G:\ChainInstall.xml

[25/03/2011 - 01:00:12 | RA | 7247] G:\ChainInstall.xml.cat

[20/04/2011 - 18:51:34 | RAD ] G:\Crack

[29/03/2011 - 10:09:25 | RAD ] G:\EULA

[02/03/2011 - 22:58:30 | RA | 183] G:\GFWL_Installer_Autorun.bat

[25/03/2011 - 01:34:10 | RA | 4136960] G:\Game.msi

[29/03/2011 - 10:11:29 | RAD ] G:\Manuals

[25/03/2011 - 00:52:00 | RA | 1994332555] G:\Media1.cab

[25/03/2011 - 00:52:14 | RA | 1908090967] G:\Media2.cab

[25/03/2011 - 00:46:41 | RA | 531254356] G:\Media3.cab

[29/03/2011 - 10:09:25 | RAD ] G:\Readme

[29/03/2011 - 10:09:15 | RAD ] G:\Redist

[02/03/2011 - 22:58:50 | RA | 440704] G:\Setup.exe

[29/03/2011 - 10:09:11 | RAD ] G:\SetupMedia

[25/03/2011 - 00:45:38 | RA | 437782] G:\autorun.ico

[11/02/2010 - 05:05:02 | RA | 47] G:\autorun.inf

[12/03/2010 - 12:37:14 | RA | 187544] G:\xliveinstall.dll

[19/04/2011 - 01:03:58 | A | 741148672] H:\psig-white.material.2009.pl.dvdrip.xvid.avi

[12/05/2011 - 17:53:42 | A | 41] H:\pmp_usb.ini

[01/05/2011 - 15:32:46 | D ] H:\Dom Zły (2009) PL.480p

[01/05/2011 - 15:37:56 | D ] H:\Kumple na Zabój - The Matador (2005)

[01/05/2011 - 15:46:14 | D ] H:\Pułapka - Hard Candy (2005) PL

[12/05/2011 - 17:54:06 | D ] H:\oglądane

[11/05/2011 - 20:16:36 | D ] H:\Czarny Łabędź - Black Swan 2010 PL

[11/05/2011 - 20:18:00 | D ] H:\Miłość i inne używki - Love and Other Drugs (2010) PL

[12/05/2011 - 18:41:04 | SHD ] H:\$RECYCLE.BIN

[12/05/2011 - 19:04:28 | A | 52] H:\winamp_metadata.idx

[12/05/2011 - 19:04:28 | A | 423] H:\winamp_metadata.dat

[12/05/2011 - 19:16:30 | D ] H:\Bez Reguł

[21/05/2011 - 23:14:32 | SHD ] J:\$RECYCLE.BIN

[17/05/2011 - 20:27:42 | D ] J:\aaa

[21/05/2011 - 23:13:58 | SHD ] J:\System Volume Information

[22/04/2011 - 23:03:04 | SHD ] K:\$RECYCLE.BIN

[24/04/2011 - 00:17:27 | D ] K:\GIERKI_ISO

 

################## | E.O.F |

Odnośnik do komentarza
Gość
Ten temat został zamknięty. Brak możliwości dodania odpowiedzi.
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...