janeb Opublikowano 14 Lipca 2012 Zgłoś Udostępnij Opublikowano 14 Lipca 2012 Przywróciłem system i w wyniku tego Ukash już się nie pojawia. Ale nie jestem pewien, czy został usunięty z komputera. Wklejam aktualny log z OTL. Jednocześnie avast przeniósł do kwarantanny plik: C:Documents and settings\user\Ustawienia lokalne\Temp\0.325048933110728967f76.exe (opis wirusa: Win32:Downloader-NDF [Trj]). Jak go usunąć. OTL logfile created on: 2012-07-14 19:29:57 - Run 1 OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\user\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 2,45 Gb Available Physical Memory | 81,80% Memory free 10,65 Gb Paging File | 10,31 Gb Available in Paging File | 96,77% Paging File free Paging file location(s): [binary data over 100 bytes] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 39,06 Gb Total Space | 7,61 Gb Free Space | 19,47% Space Free | Partition Type: NTFS Drive D: | 149,04 Gb Total Space | 34,94 Gb Free Space | 23,44% Space Free | Partition Type: NTFS Drive F: | 109,98 Gb Total Space | 83,59 Gb Free Space | 76,00% Space Free | Partition Type: NTFS Drive G: | 3,93 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: KAROLINA | User Name: user | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012-07-14 19:29:28 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Pulpit\OTL.exe PRC - [2012-04-04 18:47:32 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe PRC - [2012-02-23 00:52:45 | 002,972,688 | ---- | M] (TMRG, Inc.) -- C:\Program Files\RelevantKnowledge\rlvknlg.exe PRC - [2011-11-10 11:17:04 | 003,514,176 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe PRC - [2010-12-31 22:06:35 | 003,395,600 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe PRC - [2010-12-31 22:06:34 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe PRC - [2008-04-14 19:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007-03-06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe PRC - [2007-01-04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe PRC - [2006-11-02 05:45:00 | 000,056,832 | R--- | M] (Cognizance Corporation) -- C:\Program Files\Bioscrypt\VeriSoft\Bin\asghost.exe ========== Modules (No Company Name) ========== MOD - [2012-07-14 13:19:49 | 001,783,296 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12071401\algo.dll MOD - [2012-07-12 19:10:17 | 001,782,272 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12071201\algo.dll MOD - [2011-09-14 09:44:28 | 000,192,048 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll MOD - [2009-09-04 09:19:30 | 000,644,096 | ---- | M] () -- C:\Program Files\IZArc\IZArcCM.dll MOD - [2009-01-11 00:15:44 | 000,159,744 | ---- | M] () -- C:\Program Files\SubEdit-Player\codec\MatroskaSplitter\mmfinfo.dll MOD - [2009-01-11 00:14:06 | 000,023,552 | ---- | M] () -- C:\Program Files\SubEdit-Player\codec\MatroskaSplitter\mkunicode.dll MOD - [2008-04-14 19:20:37 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2007-10-29 13:00:00 | 000,015,360 | ---- | M] () -- C:\WINDOWS\system32\tsd32.dll MOD - [2007-03-20 13:39:08 | 000,116,248 | ---- | M] () -- C:\Program Files\InterVideo\Common\Bin\MpgTsRdr.ax MOD - [2003-05-19 19:24:40 | 000,119,808 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll ========== Win32 Services (SafeList) ========== SRV - [2012-06-16 13:09:04 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-04-04 18:47:32 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2012-02-29 09:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2010-12-31 22:06:34 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2007-03-06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service) SRV - [2007-01-04 19:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr) SRV - [2006-10-09 20:38:00 | 000,069,120 | R--- | M] (Cognizance Corporation) [Auto | Running] -- C:\Program Files\Bioscrypt\VeriSoft\Bin\ASWLNPkg.dll -- (ASBroker) SRV - [2006-06-21 19:14:00 | 000,131,584 | R--- | M] (Cognizance Corporation) [Auto | Running] -- C:\Program Files\Bioscrypt\VeriSoft\Bin\ASChnl.dll -- (ASChannel) ========== Driver Services (SafeList) ========== DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before Last Install) DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before First Install) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\soqwx32.sys -- (soqwx32) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2011-12-23 12:15:49 | 000,239,168 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2011-09-06 22:38:05 | 000,442,200 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2011-09-06 22:37:53 | 000,320,856 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2011-09-06 22:36:38 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2011-09-06 22:36:36 | 000,052,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2011-09-06 22:36:23 | 000,110,552 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2011-09-06 22:36:12 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2011-09-06 22:33:11 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2008-09-26 19:01:00 | 000,101,376 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2008-05-02 11:58:12 | 000,017,536 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2007-10-16 18:38:30 | 004,615,168 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2007-10-03 21:31:40 | 000,102,656 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2007-07-11 09:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HpqRemHid.sys -- (HpqRemHid) DRV - [2007-06-18 16:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr) DRV - [2007-04-30 06:37:20 | 002,206,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Sterownik karty Intel® DRV - [2007-03-21 22:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp) DRV - [2007-02-24 14:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk) DRV - [2007-01-29 18:26:24 | 000,984,832 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smserial.sys -- (smserial) DRV - [2007-01-23 16:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://pl.v9.com/opc/opc_1324638970_006801 IE - HKCU\..\URLSearchHook: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSof0.dll (Conduit Ltd.) IE - HKCU\..\SearchScopes,DefaultScope = {B76E7A85-7322-428b-AB33-19A6A5FD1E73} IE - HKCU\..\SearchScopes\${searchCLSID}: "URL" = http://search.yahoo.com/search?ei=ISO-8859-1&fr=megaup&q={searchTerms} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=DVS2&o=1586&src=crm&q={searchTerms}&locale=&apn_ptnrs=^AAA&apn_dtid=^YYYYYY^YY^PL&apn_uid=cf53e512-f20a-47ee-8071-98b6a976fabe&apn_sauid=8806E261-148D-4942-901B-46EDD6445009 IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2405280 IE - HKCU\..\SearchScopes\{B76E7A85-7322-428b-AB33-19A6A5FD1E73}: "URL" = http://www.bsplayer-search.com/search?q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.suggest.enabled: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "google.pl" FF - prefs.js..extensions.enabledItems: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}:3.3.3.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2 FF - prefs.js..extensions.enabledItems: player@vividas.com:4.1.0 FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=DVS2&o=1586&locale=en_US&apn_uid=cf53e512-f20a-47ee-8071-98b6a976fabe&apn_ptnrs=^AAA&apn_sauid=8806E261-148D-4942-901B-46EDD6445009&apn_dtid=^YYYYYY^YY^PL&q=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\2.bin\NPFunWeb.dll (Fun Web Products, Inc.) FF - HKLM\Software\MozillaPlugins\@ganymede/NAVY,version=1.0: C:\Program Files\Ganymede\Plugins\NAVY\NPNAVY.dll (Ganymede Technologies) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.1864: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.1924: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.857: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-06-16 13:09:05 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-05-30 14:33:52 | 000,000,000 | ---D | M] [2009-03-04 22:01:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Extensions [2012-05-30 14:33:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\extensions [2012-05-30 14:23:05 | 000,000,000 | ---D | M] (ST-Eng7 Community Toolbar) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} [2011-10-29 18:36:32 | 000,000,000 | ---D | M] (20-20 3D Viewer - IKEA) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\extensions\2020Player_IKEA@2020Technologies.com [2011-04-08 16:58:43 | 000,000,000 | ---D | M] (Vividas player plugin) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\extensions\player@vividas.com [2011-06-11 23:04:48 | 000,002,571 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\searchplugins\askcom.xml [2009-09-30 11:08:32 | 000,000,888 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\searchplugins\conduit.xml [2012-01-02 13:44:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011-10-30 17:26:42 | 000,000,000 | ---D | M] ("Babylon Spelling and Proofreading") -- C:\Program Files\Mozilla Firefox\extensions\adapter@babylontc.com [2011-10-30 17:26:41 | 000,000,000 | ---D | M] (Babylon OCR) -- C:\Program Files\Mozilla Firefox\extensions\ocr@babylon.com [2012-06-16 13:09:05 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011-07-19 05:05:25 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2009-07-31 13:06:48 | 001,654,784 | ---- | M] (LizardTech) -- C:\Program Files\mozilla firefox\plugins\npdjvu.dll [2011-07-15 13:23:18 | 000,530,600 | ---- | M] (Ganymede Technologies) -- C:\Program Files\mozilla firefox\plugins\NPNAVY.dll [2011-03-16 14:19:26 | 000,180,896 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npVividasPlayer.dll [2010-01-14 00:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll [2012-02-28 11:29:26 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2012-02-28 11:29:26 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2012-02-28 11:29:26 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2012-02-28 11:29:26 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2012-02-28 11:29:26 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-02-28 11:29:26 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml ========== Chrome ========== CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms} CHR - homepage: http://google.pl/ CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\8.0.552.237\pdf.dll CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\8.0.552.237\gears.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\8.0.552.237\gcswf32.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java Platform SE 6 U21 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Google\Update\1.2.183.39\npGoogleOneClick8.dll CHR - plugin: Fun Web Products Plugin Stub (Enabled) = C:\Program Files\FunWebProducts\Installr\2.bin\NPFunWeb.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin O1 HOSTS File: ([2010-02-06 17:01:02 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Softonic-Eng7 Toolbar) - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSof0.dll (Conduit Ltd.) O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Babylon IE plugin) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll File not found O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found O3 - HKLM\..\Toolbar: (Softonic-Eng7 Toolbar) - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSof0.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2C688203-7EB3-4327-9995-1CB417BA23F9} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (Softonic-Eng7 Toolbar) - {414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - C:\Program Files\Softonic-Eng7\tbSof0.dll (Conduit Ltd.) O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart File not found O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [RelevantKnowledge] C:\Program Files\RelevantKnowledge\rlvknlg.exe (TMRG, Inc.) O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKLM..\RunOnce: [aswAhAScr.dll] C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe () O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Java Plug-in 1.7.0_04) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Java Plug-in 1.7.0_04) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.7.0_04) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.62 62.179.1.63 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBAB1337-C151-46AD-AD6C-ECD0B4FDB466}: DhcpNameServer = 62.179.1.62 62.179.1.63 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - AppInit_DLLs: (apshook.dll) - C:\WINDOWS\System32\APSHook.dll (Cognizance Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\OneCard: DllName - (C:\Program Files\Bioscrypt\VeriSoft\Bin\ASWLNPkg.dll) - C:\Program Files\Bioscrypt\VeriSoft\Bin\ASWLNPkg.dll (Cognizance Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {93994DE8-8239-4655-B1D1-5F4E91300429} - C:\Program Files\DVD Region+CSS Free\DVDShell.dll (Fengtao Software Inc.) O30 - LSA: Authentication Packages - (ows\s) - File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-04-27 11:08:13 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{bb90c2e4-287a-11e0-894c-001cbf6b201e}\Shell - "" = AutoRun O33 - MountPoints2\{bb90c2e4-287a-11e0-894c-001cbf6b201e}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{bb90c2e7-287a-11e0-894c-001cbf6b201e}\Shell - "" = AutoRun O33 - MountPoints2\{bb90c2e7-287a-11e0-894c-001cbf6b201e}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{bda1f723-6ccd-11e0-8a02-001cbf6b201e}\Shell - "" = AutoRun O33 - MountPoints2\{bda1f723-6ccd-11e0-8a02-001cbf6b201e}\Shell\AutoRun\command - "" = G:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2012-07-14 19:29:21 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Pulpit\OTL.exe [2012-07-14 19:26:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\RelevantKnowledge [2012-07-14 19:25:42 | 000,442,200 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012-07-14 00:38:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\seyprfyisvwfagg [2012-07-13 17:44:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Little Things [2012-07-13 12:08:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\channel ORANGE (Explicit Version) [2012-07-11 23:22:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Lotus Plaza - Spooky Action At a Distance (2012) 320 [2012-07-11 17:13:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Queen Discography @ 320Kbps [Aufseher] [2012-07-11 11:45:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\[usaBit.com] - The.Perfect.Family.2011.HDTV.AC3-5.1.XviD-SiC [2012-07-10 19:15:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\La Escalera De Caracol (1945) [DVD5][PAL][Eng-Spa][WwW.ZoNaTorrent.CoM] [2012-07-10 19:11:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\The Dark Mirror (1946 and 2009 versions) [2012-07-10 19:07:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Die.Bitteren.Tranen.der.Petra.von.Kant.Rainer.Werner.Fassbinder.1972 [2012-07-02 00:14:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Black Kids [2012-07-01 18:52:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Sun Kil Moon-Among The Leaves (2012) 320Kbit(mp3) DMT [2012-06-28 23:56:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Spandau Ballet - Gold [The Best of] [2011-03-07 18:34:44 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\user\Dane aplikacji\pcouffin.sys [8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012-07-14 19:29:28 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Pulpit\OTL.exe [2012-07-14 19:25:42 | 000,002,645 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2012-07-14 19:21:08 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-07-14 19:21:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-07-14 03:16:37 | 000,001,028 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012-07-14 02:22:00 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012-07-14 00:38:05 | 000,000,051 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\vwugkkwnoifgvdo [2012-07-13 23:14:21 | 009,591,788 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\Herb Alpert & Tijuana Brass - This Guy's in Love With You.mp3 [2012-07-13 13:31:21 | 008,191,573 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\03 In the Same Room.m4a [2012-07-12 22:58:53 | 000,229,888 | ---- | M] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-07-12 18:03:58 | 000,295,664 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-07-12 11:10:53 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012-07-11 23:26:45 | 007,758,704 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\onlyinmydreams.mp3 [2012-07-09 15:12:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2012-07-09 01:51:20 | 007,389,331 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\Sonic Youth - Bad Moon Rising - 08 - Death Valley '69 (W. Lydia Lun.mp3 [2012-07-08 21:58:30 | 000,002,565 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\ACDSee 9 Photo Manager.lnk [2012-07-02 08:51:02 | 003,897,244 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\Queen - under pressure.mp3 [8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files Created - No Company Name ========== [2012-07-14 00:38:02 | 000,000,051 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\vwugkkwnoifgvdo [2012-07-13 23:12:28 | 009,591,788 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\Herb Alpert & Tijuana Brass - This Guy's in Love With You.mp3 [2012-07-13 13:30:03 | 008,191,573 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\03 In the Same Room.m4a [2012-07-11 23:26:14 | 007,758,704 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\onlyinmydreams.mp3 [2012-07-09 01:48:25 | 007,389,331 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\Sonic Youth - Bad Moon Rising - 08 - Death Valley '69 (W. Lydia Lun.mp3 [2012-07-02 08:46:10 | 003,897,244 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\Queen - under pressure.mp3 [2012-02-16 09:17:08 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2011-12-23 12:19:08 | 000,000,385 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2011-10-30 17:27:00 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll [2011-09-02 13:59:34 | 000,001,486 | ---- | C] () -- C:\Documents and Settings\user\.recently-used.xbel [2011-07-21 21:57:33 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\proc-1037709799.bin [2011-06-18 13:32:57 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2011-03-07 18:34:44 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\user\Dane aplikacji\inst.exe [2011-03-07 18:34:44 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\user\Dane aplikacji\pcouffin.cat [2011-03-07 18:34:44 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\user\Dane aplikacji\pcouffin.inf [2011-03-07 18:30:25 | 000,001,057 | ---- | C] () -- C:\Documents and Settings\user\Dane aplikacji\vso_ts_preview.xml [2010-11-12 22:27:33 | 000,000,100 | ---- | C] () -- C:\WINDOWS\wininit.ini [2010-02-01 00:27:05 | 000,000,382 | ---- | C] () -- C:\Program Files\Skrót do Program Files.lnk [2009-08-13 11:27:24 | 000,019,714 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\ucical.exe [2009-08-13 11:27:24 | 000,018,573 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\cixoruqel.exe [2009-08-13 11:27:24 | 000,018,424 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\cyxyxyz.ban [2009-08-13 11:27:24 | 000,016,276 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\puvewi.reg [2009-08-13 11:27:24 | 000,015,036 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\gybaqifug.bin [2009-08-13 11:27:24 | 000,014,268 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\izaqe.db [2009-08-13 11:27:24 | 000,013,841 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\wujoxirap.exe [2009-08-13 11:27:24 | 000,013,415 | ---- | C] () -- C:\Program Files\Common Files\byki.db [2009-05-20 00:27:49 | 000,296,960 | ---- | C] () -- C:\Documents and Settings\user\.pyscrobble.cache [2008-07-20 20:39:35 | 000,002,828 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\KGyGaAvL.sys [2008-07-20 20:39:35 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\7CE546661D.sys [2008-05-14 20:59:01 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\user\.rnd [2008-05-01 12:21:33 | 000,229,888 | ---- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini < End of report > OTL Extras logfile created on: 2012-07-14 19:29:57 - Run 1 OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\user\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 2,45 Gb Available Physical Memory | 81,80% Memory free 10,65 Gb Paging File | 10,31 Gb Available in Paging File | 96,77% Paging File free Paging file location(s): [binary data over 100 bytes] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 39,06 Gb Total Space | 7,61 Gb Free Space | 19,47% Space Free | Partition Type: NTFS Drive D: | 149,04 Gb Total Space | 34,94 Gb Free Space | 23,44% Space Free | Partition Type: NTFS Drive F: | 109,98 Gb Total Space | 83,59 Gb Free Space | 76,00% Space Free | Partition Type: NTFS Drive G: | 3,93 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: KAROLINA | User Name: user | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* .html [@ = Opera.HTML] -- Reg Error: Key error. File not found .js [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. http [open] -- "C:\Program Files\Opera\Opera.exe" https [open] -- "C:\Program Files\Opera\Opera.exe" jsfile [open] -- C:\PROGRA~1\PANDAS~1\PANDAG~1\PAVSCRIP.EXE "%1" %* piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [ACDSee 9.0.Browse] -- "C:\Program Files\ACD Systems\ACDSee\9.0\ACDSeeQV.exe" "%1" (ACD Systems Ltd.) Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] "DisableMonitoring" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] "DisableMonitoring" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe" = C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\Opera\Opera.exe" = C:\Program Files\Opera\Opera.exe:*:Enabled:Opera Internet Browser "C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule "C:\Program Files\Corel\DVD9\WinDVD.exe" = C:\Program Files\Corel\DVD9\WinDVD.exe:*:Enabled:WinDVD "C:\Program Files\Gadu-Gadu\gg.exe" = C:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program główny "C:\Program Files\InterVideo\DVD8\WinDVD.exe" = C:\Program Files\InterVideo\DVD8\WinDVD.exe:*:Enabled:WinDVD -- (InterVideo Inc.) "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.) "C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe" = C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0 "C:\Documents and Settings\user\Pulpit\utorrent.exe" = C:\Documents and Settings\user\Pulpit\utorrent.exe:*:Enabled:µTorrent "C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour "C:\Program Files\PPMate\PPMate\ppmate.exe" = C:\Program Files\PPMate\PPMate\ppmate.exe:*:Enabled:PPMate -- (www.ppmate.com) "C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- (Google) "C:\Program Files\Gadu-Gadu 10\gg.exe" = C:\Program Files\Gadu-Gadu 10\gg.exe:*:Enabled:Gadu-Gadu 10 -- (GG Network S.A.) "C:\DOCUME~1\user\USTAWI~1\Temp\0.325048933110728967f76.exe" = C:\DOCUME~1\user\USTAWI~1\Temp\0.325048933110728967f76.exe:*:Enabled:ldrsoft "C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:ldrsoft -- (Microsoft Corporation) "c:\program files\relevantknowledge\rlvknlg.exe" = c:\program files\relevantknowledge\rlvknlg.exe:*:Enabled:rlvknlg.exe -- (TMRG, Inc.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Disc 2 "{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = Lizardtech DjVu Control "{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8 "{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime "{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java 7 Update 4 "{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in "{2ADE2157-7A5E-122C-B51D-EB8A01B15943}" = DeepBurner v1.9.0.228 "{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7 "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 B2 "{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{364AA9A6-22E2-4689-89CD-4EDDFBB0A259}" = Internet Download Manager "{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}" = InterVideo DeviceService "{55CABB2F-4513-4FF1-B912-B45F93FC5B01}" = AuthenTec Fingerprint Sensor Minimum Install "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 "{5EC188BE-3930-4151-9F65-1D5F65C85BC9}" = OpenOffice.ux.pl 2.3.0 "{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{75E9A522-65D2-4200-A95F-C3EF89703263}" = Lyrics Plugin for Winamp "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs "{90850415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003 "{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 4.1 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2 "{B2D41883-3BFC-4BA0-A2F6-5A2C9836C238}" = ACDSee 9 Photo Manager "{B47A9C26-F1D1-4498-A337-6C4C58F2E5E8}" = Microsoft Producer for Microsoft Office PowerPoint "{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader "{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver "{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver "{d08d9f98-1c78-4704-87e6-368b0023d831}" = RelevantKnowledge "{D83899AB-9964-4CFC-A246-F1BD430A455F}" = VeriSoft Access Manager "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "AbiWord2" = AbiWord 2.6.8 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Photoshop 7.0 CE" = Adobe Photoshop 7.0 CE "Adobe Shockwave Player" = Adobe Shockwave Player 11.6 "ALLPlayer V3.2_is1" = ALLPlayer V3.X "avast" = avast! Free Antivirus "AVI Splitter_is1" = AVI Splitter "Babylon" = Babylon "Bink and Smacker" = Bink and Smacker "DAEMON Tools Lite" = DAEMON Tools Lite "DVD Region+CSS Free_is1" = DVD Region+CSS Free 5.9.8.3 "ffdshow_is1" = ffdshow [rev 2744] [2009-03-05] "Gadu-Gadu 10" = Gadu-Gadu 10 "GameDesire-GameDesire Sea Battle" = GameDesire-GameDesire Sea Battle "GEN_LYRICS_IE.DLL" = Winamp Lyrics (Explorer Version) v1.22 "HaaliMkx" = Haali Media Splitter "ie8" = Windows Internet Explorer 8 "InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8 "InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8 "IrfanView" = IrfanView (remove only) "JDownloader" = JDownloader "LastFM_is1" = Last.fm 1.5.4.27091 "LEd_is1" = LEd Beta 0.52 "Mozilla Firefox 13.0.1 (x86 pl)" = Mozilla Firefox 13.0.1 (x86 pl) "MozillaMaintenanceService" = Mozilla Maintenance Service "Mp3 Knife_is1" = Mp3 Knife 3.2 "MWSnap 3" = MWSnap 3 "NAPIPROJEKT_is1" = NAPIPROJEKT 1.0.6.2 "NVIDIA Drivers" = NVIDIA Drivers "PC_Antispyware2010" = PC Antispyware 2010 "PLAY ONLINE" = PLAY ONLINE "ppmate" = PPMateÃŁ™Ã‚çµÃ§Ęó 1.7.2.30 "RealAlt_is1" = Real Alternative 1.9.0 Lite "RealPlayer 6.0" = RealPlayer "SMSERIAL" = Motorola SM56 Speakerphone Modem "Softonic-Eng7 Toolbar" = Softonic-Eng7 Toolbar "SopCast" = SopCast 3.2.4 "SubEdit-Player_is1" = SubEdit-Player "TVUPlayer" = TVUPlayer 2.4.1.0 "uTorrent" = µTorrent "VLC media player" = VLC media player 0.9.9 "VSO Image Resizer_is1" = VSO Image Resizer 1.3.4d "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 "Winamp" = Winamp "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = Archiwizator WinRAR "WMFDist11" = Windows Media Format 11 runtime ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "uTorrent" = µTorrent "Winamp Detect" = Detektor Winampa ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 2012-07-13 19:42:59 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-13 19:43:43 | Computer Name = KAROLINA | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d. Error - 2012-07-13 20:17:34 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-13 20:18:44 | Computer Name = KAROLINA | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d. Error - 2012-07-13 20:36:12 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-13 20:52:52 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-13 20:55:38 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-13 20:55:56 | Computer Name = KAROLINA | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d. Error - 2012-07-13 21:16:44 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-14 13:25:32 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. [ Application Events ] Error - 2012-07-13 19:42:59 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-13 19:43:43 | Computer Name = KAROLINA | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d. Error - 2012-07-13 20:17:34 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-13 20:18:44 | Computer Name = KAROLINA | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d. Error - 2012-07-13 20:36:12 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-13 20:52:52 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-13 20:55:38 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-13 20:55:56 | Computer Name = KAROLINA | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd rlvknlg.exe, wersja 1.3.333.307, moduł powodujący błąd rlvknlg.exe, wersja 1.3.333.307, adres błędu 0x001da03d. Error - 2012-07-13 21:16:44 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. Error - 2012-07-14 13:25:32 | Computer Name = KAROLINA | Source = PerfNet | ID = 2004 Description = Nie można otworzyć usługi Server. Dane wydajności usługi Server nie zostaną zwrócone. Zwrócony kod stanu to dane DWORD 0. [ System Events ] Error - 2012-07-13 20:53:15 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu następującego błędu: %%1053 Error - 2012-07-13 20:55:43 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7009 Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się z usługą Windows User Mode Driver Framework. Error - 2012-07-13 20:55:43 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu następującego błędu: %%1053 Error - 2012-07-13 21:17:04 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7009 Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się z usługą Windows User Mode Driver Framework. Error - 2012-07-13 21:17:04 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu następującego błędu: %%1053 Error - 2012-07-14 13:18:43 | Computer Name = KAROLINA | Source = DCOM | ID = 10005 Description = Model DCOM odebrał błąd "%1084" podczas próby uruchomienia usługi EventSystem z argumentami "" w celu uruchomienia serwera: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error - 2012-07-14 13:19:13 | Computer Name = KAROLINA | Source = DCOM | ID = 10005 Description = Model DCOM odebrał błąd "%1084" podczas próby uruchomienia usługi EventSystem z argumentami "" w celu uruchomienia serwera: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error - 2012-07-14 13:25:36 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7022 Description = Usługa avast! Antivirus zawiesiła się podczas uruchamiania. Error - 2012-07-14 13:25:36 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7009 Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się z usługą Windows User Mode Driver Framework. Error - 2012-07-14 13:25:36 | Computer Name = KAROLINA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu następującego błędu: %%1053 < End of report > Odnośnik do komentarza
Landuss Opublikowano 14 Lipca 2012 Zgłoś Udostępnij Opublikowano 14 Lipca 2012 Logi wstawiaj opcją ZAŁĄCZNIKI na forum a nie wlepiaj do posta. Tu jeszcze nie koniec roboty. 1. Uruchom OTL i w oknie Własne opcje skanowania/Skrypt wklej następujący tekst: :OTL DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before Last Install) DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before First Install) DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\soqwx32.sys -- (soqwx32) FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2 FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=DVS2&o=1586&locale=en_US&apn_uid=cf53e512-f20a-47ee-8071-98b6a976fabe&apn_ptnrs=^AAA&apn_sauid=8806E261-148D-4942-901B-46EDD6445009&apn_dtid=^YYYYYY^YY^PL&q=" [2012-05-30 14:23:05 | 000,000,000 | ---D | M] (ST-Eng7 Community Toolbar) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} [2011-06-11 23:04:48 | 000,002,571 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\searchplugins\askcom.xml [2009-09-30 11:08:32 | 000,000,888 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\at1vmx5s.default\searchplugins\conduit.xml [2011-10-30 17:26:42 | 000,000,000 | ---D | M] ("Babylon Spelling and Proofreading") -- C:\Program Files\Mozilla Firefox\extensions\adapter@babylontc.com [2011-10-30 17:26:41 | 000,000,000 | ---D | M] (Babylon OCR) -- C:\Program Files\Mozilla Firefox\extensions\ocr@babylon.com O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2C688203-7EB3-4327-9995-1CB417BA23F9} - No CLSID value found. O4 - HKLM..\Run: [babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart File not found :Files C:\Program Files\Common Files\byki.db C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\ucical.exe C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\cixoruqel.exe C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\cyxyxyz.ban C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\puvewi.reg C:\Documents and Settings\All Users\Dane aplikacji\gybaqifug.bin C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\izaqe.db C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\wujoxirap.exe C:\Documents and Settings\All Users\Dane aplikacji\vwugkkwnoifgvdo C:\Documents and Settings\All Users\Dane aplikacji\seyprfyisvwfagg :Reg [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main] "Start Page"="about:blank" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\DOCUME~1\user\USTAWI~1\Temp\0.325048933110728967f76.exe"=- "c:\program files\relevantknowledge\rlvknlg.exe"=- [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}] [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}] :Commands [emptytemp] Adnotacja dla innych czytających: skrypt unikatowy - dopasowany tylko i wyłącznie pod ten system, proszę nie stosować na swoich systemach. Kliknij w Wykonaj skrypt. Zatwierdź restart komputera. 2. Przez Panel sterowania odinstaluj: Softonic-Eng7 Toolbar / Babylon / RelevantKnowledge Otwórz Firefox i w Dodatkach odmontuj: ST-Eng7 Community Toolbar / Babylon Spelling and Proofreading / Babylon OCR Otwórz Google Chrome i wejdź do Opcji, w Rozszerzeniach odmontuj Fun Web Products Plugin Stub 3. Uruchom AdwCleaner z opcji Delete 4. Uruchamiasz OTL ponownie, tym razem wywołujesz opcję Skanuj. Pokazujesz nowe logi z OTL Odnośnik do komentarza
janeb Opublikowano 14 Lipca 2012 Autor Zgłoś Udostępnij Opublikowano 14 Lipca 2012 W załączniku nowy log. Dzięki za pomoc. OTL.Txt Odnośnik do komentarza
Landuss Opublikowano 14 Lipca 2012 Zgłoś Udostępnij Opublikowano 14 Lipca 2012 Wszystko poprawnie wykonane. Przejdź do finalizacji tematu: 1. Użyj opcji Sprzątanie z OTL. 2. Opróżnij folder przywracania systemu: KLIK 3. Zaktualizuj Adobe Reader do najnowszej wersji: KLIK 4. Dla bezpieczeństwa zmień hasła logowania do serwisów w sieci. Odnośnik do komentarza
janeb Opublikowano 15 Lipca 2012 Autor Zgłoś Udostępnij Opublikowano 15 Lipca 2012 Dziękuję za pomoc. Odnośnik do komentarza
Rekomendowane odpowiedzi