OTL Extras logfile created on: 2012-10-02 15:05:08 - Run 1 OTL by OldTimer - Version 3.2.70.1 Folder = D:\Documents and Settings\Mikołaj\Pulpit Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1023,53 Mb Total Physical Memory | 640,84 Mb Available Physical Memory | 62,61% Memory free 2,41 Gb Paging File | 2,10 Gb Available in Paging File | 87,13% Paging File free Paging file location(s): D:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 39,13 Gb Total Space | 39,04 Gb Free Space | 99,77% Space Free | Partition Type: NTFS Drive D: | 35,42 Gb Total Space | 26,39 Gb Free Space | 74,51% Space Free | Partition Type: NTFS Drive F: | 592,46 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: X-46865DB03D2B4 | User Name: Mikołaj | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = Opera.HTML] -- D:\Program Files\Opera\Opera.exe (Opera Software) .inf [@ = inffile] -- %SystemRoot%\System32\NOTEPAD.EXE %1 .ini [@ = inifile] -- %SystemRoot%\System32\NOTEPAD.EXE %1 .txt [@ = txtfile] -- %SystemRoot%\system32\NOTEPAD.EXE %1 [HKEY_CURRENT_USER\SOFTWARE\Classes\] .html [@ = Opera.HTML] -- D:\Program Files\Opera\Opera.exe (Opera Software) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Unable to open value key http [open] -- "D:\Program Files\Opera\Opera.exe" "%1" (Opera Software) https [open] -- "D:\Program Files\Opera\Opera.exe" "%1" (Opera Software) inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 inffile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 inifile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 inifile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 jsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 jsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 jsefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 jsefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\NOTEPAD.EXE %1 regfile [merge] -- Reg Error: Unable to open value key regfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Unable to open value key txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" vbefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 vbefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 vbsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 vbsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 wsffile [edit] -- %SystemRoot%\System32\Notepad.exe %1 wsffile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [color=#E56717]========== System Restore Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation) "D:\Program Files\Opera\opera.exe" = D:\Program Files\Opera\Opera.exe:*:Enabled:ipsec -- (Opera Software) "D:\Program Files\WapSter\WapSter AQQ\AQQ.exe" = D:\Program Files\WapSter\WapSter AQQ\AQQ.exe:*:Enabled:AQQ Instant Messenger -- (Creative Team S.A.) "K:\RECYCLER\f2f60eea.exe" = K:\RECYCLER\f2f60eea.exe:*:Enabled:ipsec "D:\WINDOWS\system32\wscntfy.exe" = D:\WINDOWS\system32\wscntfy.exe:*:Enabled:ipsec -- (Microsoft Corporation) "D:\WINDOWS\system32\userinit.exe" = D:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec -- (Microsoft Corporation) "D:\WINDOWS\system32\userinit.exe" = D:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec -- (Microsoft Corporation) "D:\WINDOWS\Explorer.EXE" = D:\WINDOWS\Explorer.EXE:*:Enabled:ipsec -- (Microsoft Corporation) "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winfkij.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winfkij.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winrqeuwp.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winrqeuwp.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\windrlfpj.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\windrlfpj.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wingudjyw.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wingudjyw.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\npnbj.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\npnbj.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\lnkdv.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\lnkdv.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\evfwb.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\evfwb.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\runval.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\runval.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\mtglr.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\mtglr.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wtbh.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wtbh.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winnbst.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winnbst.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\pgovg.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\pgovg.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winqpnha.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winqpnha.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\mdimx.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\mdimx.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winsjvex.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winsjvex.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winrtid.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winrtid.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winrtid.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winrtid.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\ybdw.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\ybdw.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\gegf.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\gegf.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\oofnnb.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\oofnnb.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winemfek.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winemfek.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wingmecw.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wingmecw.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\muxnwr.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\muxnwr.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winxclrdf.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winxclrdf.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\nifok.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\nifok.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winlsisjc.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winlsisjc.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\hhrm.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\hhrm.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wingwumsv.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wingwumsv.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winlrae.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winlrae.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\pcymj.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\pcymj.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winpgpsp.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winpgpsp.exe:*:Enabled:ipsec "D:\PROGRA~1\WapSter\WAPSTE~1\AQQ.exe" = D:\PROGRA~1\WapSter\WAPSTE~1\AQQ.exe:*:Enabled:ipsec -- (Creative Team S.A.) "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winyvmnt.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winyvmnt.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\oivvs.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\oivvs.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\nrgkn.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\nrgkn.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\qnmk.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\qnmk.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winknug.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winknug.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winknug.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winknug.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winbrunp.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winbrunp.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\windkjox.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\windkjox.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\hhqoj.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\hhqoj.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winasbh.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winasbh.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\qxlx.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\qxlx.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\lejr.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\lejr.exe:*:Enabled:ipsec "D:\Program Files\Analog Devices\SoundMAX\SMTray.exe" = D:\Program Files\Analog Devices\SoundMAX\SMTray.exe:*:Enabled:ipsec -- (Analog Devices, Inc.) "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winrddf.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winrddf.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\qxbq.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\qxbq.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\uypct.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\uypct.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winvdhao.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winvdhao.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winvdhao.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winvdhao.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\ukvxo.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\ukvxo.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wintnwc.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wintnwc.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winwuthc.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winwuthc.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winwjesr.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winwjesr.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winpmrjp.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winpmrjp.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\jdgsf.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\jdgsf.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winhpdpr.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winhpdpr.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\iccnyu.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\iccnyu.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\pmcf.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\pmcf.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winrxgto.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winrxgto.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\cvbvrg.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\cvbvrg.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winixacr.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winixacr.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wpxaoa.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wpxaoa.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winmigui.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winmigui.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\lqpra.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\lqpra.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winhokjoh.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winhokjoh.exe:*:Enabled:ipsec "D:\WINDOWS\system32\wuauclt.exe" = D:\WINDOWS\system32\wuauclt.exe:*:Enabled:ipsec -- (Microsoft Corporation) "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winjanhc.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winjanhc.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winelya.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winelya.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\svpcs.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\svpcs.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winqhwcr.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winqhwcr.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winqhwcr.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winqhwcr.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\cyyv.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\cyyv.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winkvvjr.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winkvvjr.exe:*:Enabled:ipsec "D:\Program Files\Internet Explorer\iexplore.exe" = D:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:ipsec -- (Microsoft Corporation) "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\windtign.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\windtign.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wingnxdec.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wingnxdec.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winqvga.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winqvga.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winiepu.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winiepu.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wingbxgsl.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wingbxgsl.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winbvuaw.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winbvuaw.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wincipj.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wincipj.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winqygaen.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winqygaen.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winboswkc.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winboswkc.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\xver.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\xver.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winplnblf.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winplnblf.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\jkba.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\jkba.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wwtyef.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\wwtyef.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\uexnld.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\uexnld.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\sndp.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\sndp.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winfypmqp.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winfypmqp.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\euywy.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\euywy.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\psvf.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\psvf.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winlxri.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winlxri.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winlxri.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winlxri.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\valqeh.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\valqeh.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\tnntk.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\tnntk.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\cijtiu.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\cijtiu.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\kjrdei.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\kjrdei.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\qkce.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\qkce.exe:*:Enabled:ipsec "D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winmgdtw.exe" = D:\DOCUME~1\MIKOAJ~1\USTAWI~1\Temp\winmgdtw.exe:*:Enabled:ipsec "D:\WINDOWS\system32\taskmgr.exe" = D:\WINDOWS\system32\taskmgr.exe:*:Enabled:ipsec -- (Microsoft Corporation) [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0 "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari "{E91E8912-769D-42F0-8408-0E329443BABC}" = Ralink Wireless LAN Card "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "7-Zip" = 7-Zip 9.20 "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "AQQ" = WapSter AQQ "ie8" = Windows Internet Explorer 8 "Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0 "Opera 12.02.1578" = Opera 12.02 [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 2012-10-02 08:44:25 | Computer Name = X-46865DB03D2B4 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.2649, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2012-10-02 08:51:56 | Computer Name = X-46865DB03D2B4 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.2649, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2012-10-02 08:53:04 | Computer Name = X-46865DB03D2B4 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.2649, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2012-10-02 08:54:21 | Computer Name = X-46865DB03D2B4 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.2649, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2012-10-02 08:55:30 | Computer Name = X-46865DB03D2B4 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.2649, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. [ Application Events ] Error - 2012-10-02 08:44:25 | Computer Name = X-46865DB03D2B4 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.2649, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2012-10-02 08:51:56 | Computer Name = X-46865DB03D2B4 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.2649, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2012-10-02 08:53:04 | Computer Name = X-46865DB03D2B4 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.2649, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2012-10-02 08:54:21 | Computer Name = X-46865DB03D2B4 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.2649, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2012-10-02 08:55:30 | Computer Name = X-46865DB03D2B4 | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca explorer.exe, wersja 6.0.2900.2649, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. [ System Events ] Error - 2012-09-26 14:13:02 | Computer Name = X-46865DB03D2B4 | Source = SideBySide | ID = 16842784 Description = Nie można odnaleźć zestawu zależnego Microsoft.VC90.CRT; ostatni błąd: Odnośny zestaw nie jest zainstalowany w tym systemie. Error - 2012-09-26 14:13:02 | Computer Name = X-46865DB03D2B4 | Source = SideBySide | ID = 16842811 Description = Resolve Partial Assembly nie powiodło się dla Microsoft.VC90.CRT. Odpowiedni komunikat o błędzie: Odnośny zestaw nie jest zainstalowany w tym systemie. . Error - 2012-09-26 14:13:02 | Computer Name = X-46865DB03D2B4 | Source = SideBySide | ID = 16842811 Description = Generate Activation Context nie powiodło się dla D:\Program Files\Testy na Prawo Jazdy - B\Testy-Prawo-Jazdy-B.exe. Odpowiedni komunikat o błędzie: Operacja ukończona pomyślnie. . Error - 2012-09-26 14:18:13 | Computer Name = X-46865DB03D2B4 | Source = SideBySide | ID = 16842784 Description = Nie można odnaleźć zestawu zależnego Microsoft.VC90.CRT; ostatni błąd: Odnośny zestaw nie jest zainstalowany w tym systemie. Error - 2012-09-26 14:18:13 | Computer Name = X-46865DB03D2B4 | Source = SideBySide | ID = 16842811 Description = Resolve Partial Assembly nie powiodło się dla Microsoft.VC90.CRT. Odpowiedni komunikat o błędzie: Odnośny zestaw nie jest zainstalowany w tym systemie. . Error - 2012-09-26 14:18:13 | Computer Name = X-46865DB03D2B4 | Source = SideBySide | ID = 16842811 Description = Generate Activation Context nie powiodło się dla D:\Program Files\Testy na Prawo Jazdy - B\Testy-Prawo-Jazdy-B.exe. Odpowiedni komunikat o błędzie: Operacja ukończona pomyślnie. . Error - 2012-09-26 14:20:31 | Computer Name = X-46865DB03D2B4 | Source = SideBySide | ID = 16842784 Description = Nie można odnaleźć zestawu zależnego Microsoft.VC90.CRT; ostatni błąd: Odnośny zestaw nie jest zainstalowany w tym systemie. Error - 2012-09-26 14:20:31 | Computer Name = X-46865DB03D2B4 | Source = SideBySide | ID = 16842811 Description = Resolve Partial Assembly nie powiodło się dla Microsoft.VC90.CRT. Odpowiedni komunikat o błędzie: Odnośny zestaw nie jest zainstalowany w tym systemie. . Error - 2012-09-26 14:20:31 | Computer Name = X-46865DB03D2B4 | Source = SideBySide | ID = 16842811 Description = Generate Activation Context nie powiodło się dla D:\Program Files\Testy na Prawo Jazdy - B\Testy-Prawo-Jazdy-B.exe. Odpowiedni komunikat o błędzie: Operacja ukończona pomyślnie. . Error - 2012-10-02 08:10:56 | Computer Name = X-46865DB03D2B4 | Source = Dhcp | ID = 1002 Description = Adres IP połączenia 192.168.1.103 dla karty sieciowej o adresie 000E2ECE3BCA został zabroniony przez serwer DHCP 0.0.0.0 (Serwer DHCP wysłał komunikat DHCPNACK). < End of report >