Skocz do zawartości

Ukash - log po przywróceniu systemu


Rekomendowane odpowiedzi

Przywróciłem system i w wyniku tego Ukash już się nie pojawia. Ale nie jestem pewien, czy został usunięty z komputera. Wklejam aktualny log z OTL.

 

Jednocześnie avast przeniósł do kwarantanny plik: C:Documents and settings\user\Ustawienia lokalne\Temp\0.325048933110728967f76.exe (opis wirusa: Win32:Downloader-NDF [Trj]). Jak go usunąć.

 

OTL logfile created on: 2012-07-14 19:29:57 - Run 1

OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\user\Pulpit

Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

 

3,00 Gb Total Physical Memory | 2,45 Gb Available Physical Memory | 81,80% Memory free

10,65 Gb Paging File | 10,31 Gb Available in Paging File | 96,77% Paging File free

Paging file location(s): [binary data over 100 bytes]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 39,06 Gb Total Space | 7,61 Gb Free Space | 19,47% Space Free | Partition Type: NTFS

Drive D: | 149,04 Gb Total Space | 34,94 Gb Free Space | 23,44% Space Free | Partition Type: NTFS

Drive F: | 109,98 Gb Total Space | 83,59 Gb Free Space | 76,00% Space Free | Partition Type: NTFS

Drive G: | 3,93 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF

 

Computer Name: KAROLINA | User Name: user | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2012-07-14 19:29:28 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Pulpit\OTL.exe

PRC - [2012-04-04 18:47:32 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe

PRC - [2012-02-23 00:52:45 | 002,972,688 | ---- | M] (TMRG, Inc.) -- C:\Program Files\RelevantKnowledge\rlvknlg.exe

PRC - [2011-11-10 11:17:04 | 003,514,176 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe

PRC - [2010-12-31 22:06:35 | 003,395,600 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe

PRC - [2010-12-31 22:06:34 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

PRC - [2008-04-14 19:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2007-03-06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe

PRC - [2007-01-04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe

PRC - [2006-11-02 05:45:00 | 000,056,832 | R--- | M] (Cognizance Corporation) -- C:\Program Files\Bioscrypt\VeriSoft\Bin\asghost.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2012-07-14 13:19:49 | 001,783,296 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12071401\algo.dll

MOD - [2012-07-12 19:10:17 | 001,782,272 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12071201\algo.dll

MOD - [2011-09-14 09:44:28 | 000,192,048 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll

MOD - [2009-09-04 09:19:30 | 000,644,096 | ---- | M] () -- C:\Program Files\IZArc\IZArcCM.dll

MOD - [2009-01-11 00:15:44 | 000,159,744 | ---- | M] () -- C:\Program Files\SubEdit-Player\codec\MatroskaSplitter\mmfinfo.dll

MOD - [2009-01-11 00:14:06 | 000,023,552 | ---- | M] () -- C:\Program Files\SubEdit-Player\codec\MatroskaSplitter\mkunicode.dll

MOD - [2008-04-14 19:20:37 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll

MOD - [2007-10-29 13:00:00 | 000,015,360 | ---- | M] () -- C:\WINDOWS\system32\tsd32.dll

MOD - [2007-03-20 13:39:08 | 000,116,248 | ---- | M] () -- C:\Program Files\InterVideo\Common\Bin\MpgTsRdr.ax

MOD - [2003-05-19 19:24:40 | 000,119,808 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll

 

 

========== Win32 Services (SafeList) ==========

 

SRV - [2012-06-16 13:09:04 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)

SRV - [2012-04-04 18:47:32 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe -- (JavaQuickStarterService)

SRV - [2012-02-29 09:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)

SRV - [2010-12-31 22:06:34 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)

SRV - [2007-03-06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service)

SRV - [2007-01-04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)

SRV - [2006-10-09 20:38:00 | 000,069,120 | R--- | M] (Cognizance Corporation) [Auto | Running] -- C:\Program Files\Bioscrypt\VeriSoft\Bin\ASWLNPkg.dll -- (ASBroker)

SRV - [2006-06-21 19:14:00 | 000,131,584 | R--- | M] (Cognizance Corporation) [Auto | Running] -- C:\Program Files\Bioscrypt\VeriSoft\Bin\ASChnl.dll -- (ASChannel)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before Last Install)

DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before First Install)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)

DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\soqwx32.sys -- (soqwx32)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)

DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)

DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)

DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)

DRV - File not found [Kernel | System | Stopped] -- -- (Changer)

DRV - [2011-12-23 12:15:49 | 000,239,168 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01)

DRV - [2011-09-06 22:38:05 | 000,442,200 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)

DRV - [2011-09-06 22:37:53 | 000,320,856 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)

DRV - [2011-09-06 22:36:38 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)

DRV - [2011-09-06 22:36:36 | 000,052,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)

DRV - [2011-09-06 22:36:23 | 000,110,552 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)

DRV - [2011-09-06 22:36:12 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)

DRV - [2011-09-06 22:33:11 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)

DRV - [2008-09-26 19:01:00 | 000,101,376 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)

DRV - [2008-05-02 11:58:12 | 000,017,536 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)

DRV - [2007-10-16 18:38:30 | 004,615,168 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2007-10-03 21:31:40 | 000,102,656 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)

DRV - [2007-07-11 09:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HpqRemHid.sys -- (HpqRemHid)

DRV - [2007-06-18 16:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)

DRV - [2007-04-30 06:37:20 | 002,206,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Sterownik karty Intel®

DRV - [2007-03-21 22:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)

DRV - [2007-02-24 14:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)

DRV - [2007-01-29 18:26:24 | 000,984,832 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smserial.sys -- (smserial)

DRV - [2007-01-23 16:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://pl.v9.com/opc/opc_1324638970_006801

IE - HKCU\..\URLSearchHook: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSof0.dll (Conduit Ltd.)

IE - HKCU\..\SearchScopes,DefaultScope = {B76E7A85-7322-428b-AB33-19A6A5FD1E73}

IE - HKCU\..\SearchScopes\${searchCLSID}: "URL" = http://search.yahoo.com/search?ei=ISO-8859-1&fr=megaup&q={searchTerms}

IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=DVS2&o=1586&src=crm&q={searchTerms}&locale=&apn_ptnrs=^AAA&apn_dtid=^YYYYYY^YY^PL&apn_uid=cf53e512-f20a-47ee-8071-98b6a976fabe&apn_sauid=8806E261-148D-4942-901B-46EDD6445009

IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2405280

IE - HKCU\..\SearchScopes\{B76E7A85-7322-428b-AB33-19A6A5FD1E73}: "URL" = http://www.bsplayer-search.com/search?q={searchTerms}

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

 

========== FireFox ==========

 

FF - prefs.js..browser.search.defaultengine: "Ask.com"

FF - prefs.js..browser.search.defaultenginename: "Ask.com"

FF - prefs.js..browser.search.order.1: "Ask.com"

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - prefs.js..browser.search.suggest.enabled: false

FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..browser.startup.homepage: "google.pl"

FF - prefs.js..extensions.enabledItems: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}:3.3.3.2

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2

FF - prefs.js..extensions.enabledItems: player@vividas.com:4.1.0

FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=DVS2&o=1586&locale=en_US&apn_uid=cf53e512-f20a-47ee-8071-98b6a976fabe&apn_ptnrs=^AAA&apn_sauid=8806E261-148D-4942-901B-46EDD6445009&apn_dtid=^YYYYYY^YY^PL&q="

FF - user.js - File not found

 

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\2.bin\NPFunWeb.dll (Fun Web Products, Inc.)

FF - HKLM\Software\MozillaPlugins\@ganymede/NAVY,version=1.0: C:\Program Files\Ganymede\Plugins\NAVY\NPNAVY.dll (Ganymede Technologies)

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.1864: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.1924: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.857: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-06-16 13:09:05 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-05-30 14:33:52 | 000,000,000 | ---D | M]

 

[2009-03-04 22:01:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Extensions

[2012-05-30 14:33:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\extensions

[2012-05-30 14:23:05 | 000,000,000 | ---D | M] (ST-Eng7 Community Toolbar) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}

[2011-10-29 18:36:32 | 000,000,000 | ---D | M] (20-20 3D Viewer - IKEA) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\extensions\2020Player_IKEA@2020Technologies.com

[2011-04-08 16:58:43 | 000,000,000 | ---D | M] (Vividas player plugin) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\extensions\player@vividas.com

[2011-06-11 23:04:48 | 000,002,571 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\searchplugins\askcom.xml

[2009-09-30 11:08:32 | 000,000,888 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\searchplugins\conduit.xml

[2012-01-02 13:44:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2011-10-30 17:26:42 | 000,000,000 | ---D | M] ("Babylon Spelling and Proofreading") -- C:\Program Files\Mozilla Firefox\extensions\adapter@babylontc.com

[2011-10-30 17:26:41 | 000,000,000 | ---D | M] (Babylon OCR) -- C:\Program Files\Mozilla Firefox\extensions\ocr@babylon.com

[2012-06-16 13:09:05 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll

[2011-07-19 05:05:25 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

[2009-07-31 13:06:48 | 001,654,784 | ---- | M] (LizardTech) -- C:\Program Files\mozilla firefox\plugins\npdjvu.dll

[2011-07-15 13:23:18 | 000,530,600 | ---- | M] (Ganymede Technologies) -- C:\Program Files\mozilla firefox\plugins\NPNAVY.dll

[2011-03-16 14:19:26 | 000,180,896 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npVividasPlayer.dll

[2010-01-14 00:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll

[2012-02-28 11:29:26 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml

[2012-02-28 11:29:26 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml

[2012-02-28 11:29:26 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml

[2012-02-28 11:29:26 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml

[2012-02-28 11:29:26 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml

[2012-02-28 11:29:26 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

 

========== Chrome ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}

CHR - homepage: http://google.pl/

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\8.0.552.237\pdf.dll

CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\8.0.552.237\gears.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\8.0.552.237\gcswf32.dll

CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll

CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll

CHR - plugin: Java Platform SE 6 U21 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll

CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll

CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll

CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll

CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll

CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll

CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll

CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll

CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll

CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Update\1.2.183.39\npGoogleOneClick8.dll

CHR - plugin: Fun Web Products Plugin Stub (Enabled) = C:\Program Files\FunWebProducts\Installr\2.bin\NPFunWeb.dll

CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll

CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll

CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

CHR - plugin: Default Plug-in (Enabled) = default_plugin

 

O1 HOSTS File: ([2010-02-06 17:01:02 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)

O2 - BHO: (Softonic-Eng7 Toolbar) - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSof0.dll (Conduit Ltd.)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)

O2 - BHO: (Babylon IE plugin) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll File not found

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found

O3 - HKLM\..\Toolbar: (Softonic-Eng7 Toolbar) - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSof0.dll (Conduit Ltd.)

O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2C688203-7EB3-4327-9995-1CB417BA23F9} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (Softonic-Eng7 Toolbar) - {414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - C:\Program Files\Softonic-Eng7\tbSof0.dll (Conduit Ltd.)

O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)

O4 - HKLM..\Run: [babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart File not found

O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)

O4 - HKLM..\Run: [RelevantKnowledge] C:\Program Files\RelevantKnowledge\rlvknlg.exe (TMRG, Inc.)

O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)

O4 - HKLM..\RunOnce: [aswAhAScr.dll] C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe ()

O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found

O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found

O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found

O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Java Plug-in 1.7.0_04)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)

O16 - DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Java Plug-in 1.7.0_04)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.7.0_04)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.62 62.179.1.63

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBAB1337-C151-46AD-AD6C-ECD0B4FDB466}: DhcpNameServer = 62.179.1.62 62.179.1.63

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - AppInit_DLLs: (apshook.dll) - C:\WINDOWS\System32\APSHook.dll (Cognizance Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - Winlogon\Notify\OneCard: DllName - (C:\Program Files\Bioscrypt\VeriSoft\Bin\ASWLNPkg.dll) - C:\Program Files\Bioscrypt\VeriSoft\Bin\ASWLNPkg.dll (Cognizance Corporation)

O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {93994DE8-8239-4655-B1D1-5F4E91300429} - C:\Program Files\DVD Region+CSS Free\DVDShell.dll (Fengtao Software Inc.)

O30 - LSA: Authentication Packages - (ows\s) - File not found

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2008-04-27 11:08:13 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\{bb90c2e4-287a-11e0-894c-001cbf6b201e}\Shell - "" = AutoRun

O33 - MountPoints2\{bb90c2e4-287a-11e0-894c-001cbf6b201e}\Shell\AutoRun\command - "" = G:\AutoRun.exe

O33 - MountPoints2\{bb90c2e7-287a-11e0-894c-001cbf6b201e}\Shell - "" = AutoRun

O33 - MountPoints2\{bb90c2e7-287a-11e0-894c-001cbf6b201e}\Shell\AutoRun\command - "" = G:\AutoRun.exe

O33 - MountPoints2\{bda1f723-6ccd-11e0-8a02-001cbf6b201e}\Shell - "" = AutoRun

O33 - MountPoints2\{bda1f723-6ccd-11e0-8a02-001cbf6b201e}\Shell\AutoRun\command - "" = G:\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2012-07-14 19:29:21 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Pulpit\OTL.exe

[2012-07-14 19:26:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\RelevantKnowledge

[2012-07-14 19:25:42 | 000,442,200 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys

[2012-07-14 00:38:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\seyprfyisvwfagg

[2012-07-13 17:44:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Little Things

[2012-07-13 12:08:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\channel ORANGE (Explicit Version)

[2012-07-11 23:22:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Lotus Plaza - Spooky Action At a Distance (2012) 320

[2012-07-11 17:13:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Queen Discography @ 320Kbps [Aufseher]

[2012-07-11 11:45:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\[usaBit.com] - The.Perfect.Family.2011.HDTV.AC3-5.1.XviD-SiC

[2012-07-10 19:15:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\La Escalera De Caracol (1945) [DVD5][PAL][Eng-Spa][WwW.ZoNaTorrent.CoM]

[2012-07-10 19:11:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\The Dark Mirror (1946 and 2009 versions)

[2012-07-10 19:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Die.Bitteren.Tranen.der.Petra.von.Kant.Rainer.Werner.Fassbinder.1972

[2012-07-02 00:14:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Black Kids

[2012-07-01 18:52:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Sun Kil Moon-Among The Leaves (2012) 320Kbit(mp3) DMT

[2012-06-28 23:56:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Spandau Ballet - Gold [The Best of]

[2011-03-07 18:34:44 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\user\Dane aplikacji\pcouffin.sys

[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2012-07-14 19:29:28 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Pulpit\OTL.exe

[2012-07-14 19:25:42 | 000,002,645 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT

[2012-07-14 19:21:08 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2012-07-14 19:21:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2012-07-14 03:16:37 | 000,001,028 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2012-07-14 02:22:00 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2012-07-14 00:38:05 | 000,000,051 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\vwugkkwnoifgvdo

[2012-07-13 23:14:21 | 009,591,788 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\Herb Alpert & Tijuana Brass - This Guy's in Love With You.mp3

[2012-07-13 13:31:21 | 008,191,573 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\03 In the Same Room.m4a

[2012-07-12 22:58:53 | 000,229,888 | ---- | M] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012-07-12 18:03:58 | 000,295,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2012-07-12 11:10:53 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2012-07-11 23:26:45 | 007,758,704 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\onlyinmydreams.mp3

[2012-07-09 15:12:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2012-07-09 01:51:20 | 007,389,331 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\Sonic Youth - Bad Moon Rising - 08 - Death Valley '69 (W. Lydia Lun.mp3

[2012-07-08 21:58:30 | 000,002,565 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\ACDSee 9 Photo Manager.lnk

[2012-07-02 08:51:02 | 003,897,244 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\Queen - under pressure.mp3

[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2012-07-14 00:38:02 | 000,000,051 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\vwugkkwnoifgvdo

[2012-07-13 23:12:28 | 009,591,788 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\Herb Alpert & Tijuana Brass - This Guy's in Love With You.mp3

[2012-07-13 13:30:03 | 008,191,573 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\03 In the Same Room.m4a

[2012-07-11 23:26:14 | 007,758,704 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\onlyinmydreams.mp3

[2012-07-09 01:48:25 | 007,389,331 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\Sonic Youth - Bad Moon Rising - 08 - Death Valley '69 (W. Lydia Lun.mp3

[2012-07-02 08:46:10 | 003,897,244 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\Queen - under pressure.mp3

[2012-02-16 09:17:08 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll

[2011-12-23 12:19:08 | 000,000,385 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2011-10-30 17:27:00 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll

[2011-09-02 13:59:34 | 000,001,486 | ---- | C] () -- C:\Documents and Settings\user\.recently-used.xbel

[2011-07-21 21:57:33 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\proc-1037709799.bin

[2011-06-18 13:32:57 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011-03-07 18:34:44 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\user\Dane aplikacji\inst.exe

[2011-03-07 18:34:44 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\user\Dane aplikacji\pcouffin.cat

[2011-03-07 18:34:44 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\user\Dane aplikacji\pcouffin.inf

[2011-03-07 18:30:25 | 000,001,057 | ---- | C] () -- C:\Documents and Settings\user\Dane aplikacji\vso_ts_preview.xml

[2010-11-12 22:27:33 | 000,000,100 | ---- | C] () -- C:\WINDOWS\wininit.ini

[2010-02-01 00:27:05 | 000,000,382 | ---- | C] () -- C:\Program Files\Skrót do Program Files.lnk

[2009-08-13 11:27:24 | 000,019,714 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\ucical.exe

[2009-08-13 11:27:24 | 000,018,573 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\cixoruqel.exe

[2009-08-13 11:27:24 | 000,018,424 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\cyxyxyz.ban

[2009-08-13 11:27:24 | 000,016,276 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\puvewi.reg

[2009-08-13 11:27:24 | 000,015,036 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\gybaqifug.bin

[2009-08-13 11:27:24 | 000,014,268 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\izaqe.db

[2009-08-13 11:27:24 | 000,013,841 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\wujoxirap.exe

[2009-08-13 11:27:24 | 000,013,415 | ---- | C] () -- C:\Program Files\Common Files\byki.db

[2009-05-20 00:27:49 | 000,296,960 | ---- | C] () -- C:\Documents and Settings\user\.pyscrobble.cache

[2008-07-20 20:39:35 | 000,002,828 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\KGyGaAvL.sys

[2008-07-20 20:39:35 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\7CE546661D.sys

[2008-05-14 20:59:01 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\user\.rnd

[2008-05-01 12:21:33 | 000,229,888 | ---- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

 

< End of report >

 

OTL Extras logfile created on: 2012-07-14 19:29:57 - Run 1

OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\user\Pulpit

Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

 

3,00 Gb Total Physical Memory | 2,45 Gb Available Physical Memory | 81,80% Memory free

10,65 Gb Paging File | 10,31 Gb Available in Paging File | 96,77% Paging File free

Paging file location(s): [binary data over 100 bytes]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 39,06 Gb Total Space | 7,61 Gb Free Space | 19,47% Space Free | Partition Type: NTFS

Drive D: | 149,04 Gb Total Space | 34,94 Gb Free Space | 23,44% Space Free | Partition Type: NTFS

Drive F: | 109,98 Gb Total Space | 83,59 Gb Free Space | 76,00% Space Free | Partition Type: NTFS

Drive G: | 3,93 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF

 

Computer Name: KAROLINA | User Name: user | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.html [@ = Opera.HTML] -- Reg Error: Key error. File not found

.js [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found

 

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

htmlfile [edit] -- Reg Error: Key error.

http [open] -- "C:\Program Files\Opera\Opera.exe"

https [open] -- "C:\Program Files\Opera\Opera.exe"

jsfile [open] -- C:\PROGRA~1\PANDAS~1\PANDAG~1\PAVSCRIP.EXE "%1" %*

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [ACDSee 9.0.Browse] -- "C:\Program Files\ACD Systems\ACDSee\9.0\ACDSeeQV.exe" "%1" (ACD Systems Ltd.)

Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 1

"FirewallDisableNotify" = 1

"UpdatesDisableNotify" = 1

"AntiVirusOverride" = 0

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

"DisableMonitoring" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

"DisableMonitoring" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

========== System Restore Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DisableNotifications" = 0

"DoNotAllowExceptions" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe" = C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\Opera\Opera.exe" = C:\Program Files\Opera\Opera.exe:*:Enabled:Opera Internet Browser

"C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule

"C:\Program Files\Corel\DVD9\WinDVD.exe" = C:\Program Files\Corel\DVD9\WinDVD.exe:*:Enabled:WinDVD

"C:\Program Files\Gadu-Gadu\gg.exe" = C:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program główny

"C:\Program Files\InterVideo\DVD8\WinDVD.exe" = C:\Program Files\InterVideo\DVD8\WinDVD.exe:*:Enabled:WinDVD -- (InterVideo Inc.)

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe" = C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0

"C:\Documents and Settings\user\Pulpit\utorrent.exe" = C:\Documents and Settings\user\Pulpit\utorrent.exe:*:Enabled:µTorrent

"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour

"C:\Program Files\PPMate\PPMate\ppmate.exe" = C:\Program Files\PPMate\PPMate\ppmate.exe:*:Enabled:PPMate -- (www.ppmate.com)

"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- (Google)

"C:\Program Files\Gadu-Gadu 10\gg.exe" = C:\Program Files\Gadu-Gadu 10\gg.exe:*:Enabled:Gadu-Gadu 10 -- (GG Network S.A.)

"C:\DOCUME~1\user\USTAWI~1\Temp\0.325048933110728967f76.exe" = C:\DOCUME~1\user\USTAWI~1\Temp\0.325048933110728967f76.exe:*:Enabled:ldrsoft

"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:ldrsoft -- (Microsoft Corporation)

"c:\program files\relevantknowledge\rlvknlg.exe" = c:\program files\relevantknowledge\rlvknlg.exe:*:Enabled:rlvknlg.exe -- (TMRG, Inc.)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional

"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator

"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Disc 2

"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = Lizardtech DjVu Control

"{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8

"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime

"{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java 7 Update 4

"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in

"{2ADE2157-7A5E-122C-B51D-EB8A01B15943}" = DeepBurner v1.9.0.228

"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8

"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0

"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7

"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 B2

"{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{364AA9A6-22E2-4689-89CD-4EDDFBB0A259}" = Internet Download Manager

"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}" = InterVideo DeviceService

"{55CABB2F-4513-4FF1-B912-B45F93FC5B01}" = AuthenTec Fingerprint Sensor Minimum Install

"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml

"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01

"{5EC188BE-3930-4151-9F65-1D5F65C85BC9}" = OpenOffice.ux.pl 2.3.0

"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM

"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update

"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin

"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable

"{75E9A522-65D2-4200-A95F-C3EF89703263}" = Lyrics Plugin for Winamp

"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system

"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs

"{90850415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003

"{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 4.1

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2

"{B2D41883-3BFC-4BA0-A2F6-5A2C9836C238}" = ACDSee 9 Photo Manager

"{B47A9C26-F1D1-4498-A337-6C4C58F2E5E8}" = Microsoft Producer for Microsoft Office PowerPoint

"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader

"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver

"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver

"{d08d9f98-1c78-4704-87e6-368b0023d831}" = RelevantKnowledge

"{D83899AB-9964-4CFC-A246-F1BD430A455F}" = VeriSoft Access Manager

"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"AbiWord2" = AbiWord 2.6.8

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"Adobe Photoshop 7.0 CE" = Adobe Photoshop 7.0 CE

"Adobe Shockwave Player" = Adobe Shockwave Player 11.6

"ALLPlayer V3.2_is1" = ALLPlayer V3.X

"avast" = avast! Free Antivirus

"AVI Splitter_is1" = AVI Splitter

"Babylon" = Babylon

"Bink and Smacker" = Bink and Smacker

"DAEMON Tools Lite" = DAEMON Tools Lite

"DVD Region+CSS Free_is1" = DVD Region+CSS Free 5.9.8.3

"ffdshow_is1" = ffdshow [rev 2744] [2009-03-05]

"Gadu-Gadu 10" = Gadu-Gadu 10

"GameDesire-GameDesire Sea Battle" = GameDesire-GameDesire Sea Battle

"GEN_LYRICS_IE.DLL" = Winamp Lyrics (Explorer Version) v1.22

"HaaliMkx" = Haali Media Splitter

"ie8" = Windows Internet Explorer 8

"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8

"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8

"IrfanView" = IrfanView (remove only)

"JDownloader" = JDownloader

"LastFM_is1" = Last.fm 1.5.4.27091

"LEd_is1" = LEd Beta 0.52

"Mozilla Firefox 13.0.1 (x86 pl)" = Mozilla Firefox 13.0.1 (x86 pl)

"MozillaMaintenanceService" = Mozilla Maintenance Service

"Mp3 Knife_is1" = Mp3 Knife 3.2

"MWSnap 3" = MWSnap 3

"NAPIPROJEKT_is1" = NAPIPROJEKT 1.0.6.2

"NVIDIA Drivers" = NVIDIA Drivers

"PC_Antispyware2010" = PC Antispyware 2010

"PLAY ONLINE" = PLAY ONLINE

"ppmate" = PPMateÃŁ™Ã‚çµÃ§Ęó 1.7.2.30

"RealAlt_is1" = Real Alternative 1.9.0 Lite

"RealPlayer 6.0" = RealPlayer

"SMSERIAL" = Motorola SM56 Speakerphone Modem

"Softonic-Eng7 Toolbar" = Softonic-Eng7 Toolbar

"SopCast" = SopCast 3.2.4

"SubEdit-Player_is1" = SubEdit-Player

"TVUPlayer" = TVUPlayer 2.4.1.0

"uTorrent" = µTorrent

"VLC media player" = VLC media player 0.9.9

"VSO Image Resizer_is1" = VSO Image Resizer 1.3.4d

"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5

"Winamp" = Winamp

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"Windows XP Service Pack" = Windows XP Service Pack 3

"WinRAR archiver" = Archiwizator WinRAR

"WMFDist11" = Windows Media Format 11 runtime

 

========== HKEY_CURRENT_USER Uninstall List ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"uTorrent" = µTorrent

"Winamp Detect" = Detektor Winampa

 

========== Last 20 Event Log Errors ==========

 

[ Application Events ]

Error - 2012-07-13 19:42:59 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-13 19:43:43 | Computer Name = KAROLINA | Source = Application Error | ID = 1000

Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący

błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d.

 

Error - 2012-07-13 20:17:34 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-13 20:18:44 | Computer Name = KAROLINA | Source = Application Error | ID = 1000

Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący

błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d.

 

Error - 2012-07-13 20:36:12 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-13 20:52:52 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-13 20:55:38 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-13 20:55:56 | Computer Name = KAROLINA | Source = Application Error | ID = 1000

Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący

błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d.

 

Error - 2012-07-13 21:16:44 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-14 13:25:32 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

[ Application Events ]

Error - 2012-07-13 19:42:59 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-13 19:43:43 | Computer Name = KAROLINA | Source = Application Error | ID = 1000

Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący

błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d.

 

Error - 2012-07-13 20:17:34 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-13 20:18:44 | Computer Name = KAROLINA | Source = Application Error | ID = 1000

Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący

błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d.

 

Error - 2012-07-13 20:36:12 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-13 20:52:52 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-13 20:55:38 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-13 20:55:56 | Computer Name = KAROLINA | Source = Application Error | ID = 1000

Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący

błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d.

 

Error - 2012-07-13 21:16:44 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

Error - 2012-07-14 13:25:32 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004

Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie

zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0.

 

[ System Events ]

Error - 2012-07-13 20:53:15 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu

następującego błędu: %%1053

 

Error - 2012-07-13 20:55:43 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7009

Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się

z usługą Windows User Mode Driver Framework.

 

Error - 2012-07-13 20:55:43 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu

następującego błędu: %%1053

 

Error - 2012-07-13 21:17:04 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7009

Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się

z usługą Windows User Mode Driver Framework.

 

Error - 2012-07-13 21:17:04 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu

następującego błędu: %%1053

 

Error - 2012-07-14 13:18:43 | Computer Name = KAROLINA | Source = DCOM | ID = 10005

Description = Model DCOM odebrał błąd "%1084" podczas próby uruchomienia usługi

EventSystem z argumentami "" w celu uruchomienia serwera: {1BE1F766-5536-11D1-B726-00C04FB926AF}

 

Error - 2012-07-14 13:19:13 | Computer Name = KAROLINA | Source = DCOM | ID = 10005

Description = Model DCOM odebrał błąd "%1084" podczas próby uruchomienia usługi

EventSystem z argumentami "" w celu uruchomienia serwera: {1BE1F766-5536-11D1-B726-00C04FB926AF}

 

Error - 2012-07-14 13:25:36 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7022

Description = Usługa avast! Antivirus zawiesiła się podczas uruchamiania.

 

Error - 2012-07-14 13:25:36 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7009

Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się

z usługą Windows User Mode Driver Framework.

 

Error - 2012-07-14 13:25:36 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu

następującego błędu: %%1053

 

 

< End of report >

Odnośnik do komentarza
Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.

Logi wstawiaj opcją ZAŁĄCZNIKI na forum a nie wlepiaj do posta. Tu jeszcze nie koniec roboty.

 

1. Uruchom OTL i w oknie Własne opcje skanowania/Skrypt wklej następujący tekst:

 

:OTL
DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before Last Install)
DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before First Install)
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\soqwx32.sys -- (soqwx32)
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=DVS2&o=1586&locale=en_US&apn_uid=cf53e512-f20a-47ee-8071-98b6a976fabe&apn_ptnrs=^AAA&apn_sauid=8806E261-148D-4942-901B-46EDD6445009&apn_dtid=^YYYYYY^YY^PL&q="
[2012-05-30 14:23:05 | 000,000,000 | ---D | M] (ST-Eng7 Community Toolbar) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
[2011-06-11 23:04:48 | 000,002,571 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\searchplugins\askcom.xml
[2009-09-30 11:08:32 | 000,000,888 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\searchplugins\conduit.xml
[2011-10-30 17:26:42 | 000,000,000 | ---D | M] ("Babylon Spelling and Proofreading") -- C:\Program Files\Mozilla Firefox\extensions\adapter@babylontc.com
[2011-10-30 17:26:41 | 000,000,000 | ---D | M] (Babylon OCR) -- C:\Program Files\Mozilla Firefox\extensions\ocr@babylon.com
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2C688203-7EB3-4327-9995-1CB417BA23F9} - No CLSID value found.
O4 - HKLM..\Run: [babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart File not found
 
:Files
C:\Program Files\Common Files\byki.db
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\ucical.exe
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\cixoruqel.exe
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\cyxyxyz.ban
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\puvewi.reg
C:\Documents and Settings\All Users\Dane aplikacji\gybaqifug.bin
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\izaqe.db
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\wujoxirap.exe
C:\Documents and Settings\All Users\Dane aplikacji\vwugkkwnoifgvdo
C:\Documents and Settings\All Users\Dane aplikacji\seyprfyisvwfagg
 
:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page"="about:blank"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\DOCUME~1\user\USTAWI~1\Temp\0.325048933110728967f76.exe"=-
"c:\program files\relevantknowledge\rlvknlg.exe"=-
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
 
:Commands
[emptytemp]

 

Adnotacja dla innych czytających: skrypt unikatowy - dopasowany tylko i wyłącznie pod ten system, proszę nie stosować na swoich systemach.

 

Kliknij w Wykonaj skrypt. Zatwierdź restart komputera.

 

2. Przez Panel sterowania odinstaluj: Softonic-Eng7 Toolbar / Babylon / RelevantKnowledge

 

Otwórz Firefox i w Dodatkach odmontuj: ST-Eng7 Community Toolbar / Babylon Spelling and Proofreading / Babylon OCR

 

Otwórz Google Chrome i wejdź do Opcji, w Rozszerzeniach odmontuj Fun Web Products Plugin Stub

 

3. Uruchom AdwCleaner z opcji Delete

 

4. Uruchamiasz OTL ponownie, tym razem wywołujesz opcję Skanuj. Pokazujesz nowe logi z OTL

Odnośnik do komentarza
Gość
Ten temat został zamknięty. Brak możliwości dodania odpowiedzi.
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...