przytom Opublikowano 19 Maja 2011 Zgłoś Udostępnij Opublikowano 19 Maja 2011 (edytowane) Witam. Mam windows 7 x64. Po włożeniu jakiś dysków zewnętrznych czy to pen drive, czy karta pamieci pojawia się ten pliczek.... OTL: Mój link Extras: Mój link Mógłbym także zasięgnąć waszej pomocy ? Edytowane 20 Maja 2011 przez picasso Przeklejam treść z duplikatu tutaj, usuwając także niewiarygodny na x64 GMER. //picasso Odnośnik do komentarza
Landuss Opublikowano 20 Maja 2011 Zgłoś Udostępnij Opublikowano 20 Maja 2011 Tutaj jest zakaz dopisywania się do czyjegoś tematu. Wydzielam twój temat w osobny. Zabrakło drugiego loga z OTL - extras.txt. Podczas skanu opcja "Rejestr - skan dodatkowy" ma być zaznaczona na "Użyj filtrowania" Pamiętaj o tym w następnym poście. 1. Uruchom OTL i w oknie Własne opcje skanowania/Skrypt wklej następujący tekst: :OTL IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - Reg Error: Key error. File not found FF - prefs.js..browser.search.defaultthis.engineName: "InnoGames Polska Customized Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832599&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.selectedEngine: "Search" FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2 FF - prefs.js..keyword.URL: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=eri7F0ib&q=" FF - user.js..browser.search.selectedEngine: "Search" FF - user.js..keyword.URL: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=eri7F0ib&q=" [2011-05-12 01:42:22 | 000,000,000 | ---D | M] (AOL Toolbar) -- C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2011-05-02 12:27:01 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions\engine@conduit.com [2011-05-12 02:07:28 | 000,002,352 | ---- | M] () -- C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\6nh7v7o5.default\searchplugins\aol-search.xml [2010-11-25 13:02:52 | 000,000,935 | ---- | M] () -- C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\6nh7v7o5.default\searchplugins\conduit.xml O2 - BHO: (no name) - {66D8FBA6-D90F-40A9-AC55-84896F79CA69} - No CLSID value found. O4:64bit: - HKLM..\Run: [rejestr] C:\Windows\rejestr.exe () O4:64bit: - HKLM..\Run: [svhost] File not found O4 - HKCU..\Run: [jucheed] C:\Windows\jucheed.exe () O4 - HKCU..\Run: [svhost] C:\Windows\svchost.exe () :Commands [emptyflash] [emptytemp] Kliknij w Wykonaj skrypt. Zatwierdź restart komputera. 2. Następnie uruchamiasz OTL ponownie, tym razem wywołujesz opcję Skanuj. Pokazujesz nowe logi z OTL. Odnośnik do komentarza
przytom Opublikowano 20 Maja 2011 Autor Zgłoś Udostępnij Opublikowano 20 Maja 2011 A JESZCZE MAM JEDNO PYTANKO. Jeżeli podłączę dysk przenośny ( a tam tez mam ten plik) to czy nie odnowi on robala w lapku ? To sie pokazało po uruchomieniu. All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ not found. Prefs.js: "InnoGames Polska Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2832599&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl Prefs.js: "Search" removed from browser.search.selectedEngine Prefs.js: engine@conduit.com:3.2.5.2 removed from extensions.enabledItems Prefs.js: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=eri7F0ib&q=" removed from keyword.URL C:\Users\Marcin\AppData\Roaming\Mozilla\FireFox\Profiles\6nh7v7o5.default\user.js moved successfully. Folder C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\ not found. Folder C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions\engine@conduit.com\ not found. C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\6nh7v7o5.default\searchplugins\aol-search.xml moved successfully. C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\6nh7v7o5.default\searchplugins\conduit.xml moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66D8FBA6-D90F-40A9-AC55-84896F79CA69}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66D8FBA6-D90F-40A9-AC55-84896F79CA69}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\rejestr deleted successfully. C:\Windows\rejestr.exe moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\svhost deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jucheed deleted successfully. C:\Windows\jucheed.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\svhost deleted successfully. C:\Windows\svchost.exe moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User: Default User User: GościeGoście ->Flash cache emptied: 0 bytes User: Marcin ->Flash cache emptied: 783 bytes User: Public User: User Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: GościeGoście ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Marcin ->Temp folder emptied: 167002 bytes ->Temporary Internet Files folder emptied: 43916 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 24955575 bytes ->Flash cache emptied: 0 bytes User: Public User: User %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2286 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 24,00 mb OTL by OldTimer - Version 3.2.22.3 log created on 05212011_131346 Files\Folders moved on Reboot... C:\Users\Marcin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot... OK a teraz otl OTL logfile created on: 2011-05-21 13:27:37 - Run 3 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Marcin\Desktop 64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 63,00% Memory free 8,00 Gb Paging File | 6,00 Gb Available in Paging File | 77,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 58,57 Gb Total Space | 16,41 Gb Free Space | 28,02% Space Free | Partition Type: NTFS Drive D: | 211,88 Gb Total Space | 36,33 Gb Free Space | 17,15% Space Free | Partition Type: NTFS Drive E: | 195,31 Gb Total Space | 29,18 Gb Free Space | 14,94% Space Free | Partition Type: NTFS Drive G: | 4,38 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: MARCIN-KOMPUTER | User Name: Marcin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011-05-21 00:40:45 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Marcin\Desktop\OTL.exe PRC - [2011-05-11 17:33:41 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe PRC - [2011-04-25 17:30:52 | 003,298,712 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe PRC - [2011-04-14 18:59:13 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2010-11-22 23:52:46 | 000,718,072 | ---- | M] (Tunngle.net GmbH) -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe PRC - [2010-11-19 21:08:40 | 000,066,872 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2010-08-12 15:16:26 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe PRC - [2010-05-25 16:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe PRC - [2010-03-08 09:27:49 | 000,041,800 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\Common Files\AOL\1305110212\ee\aolsoftware.exe PRC - [2009-11-04 07:45:46 | 002,320,920 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe PRC - [2009-11-04 07:45:44 | 000,268,824 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe PRC - [2009-10-13 12:25:54 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe PRC - [2009-10-13 12:25:30 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe PRC - [2008-08-04 15:45:16 | 005,779,456 | ---- | M] () -- C:\Program Files (x86)\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe PRC - [2007-09-02 14:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.exe ========== Modules (SafeList) ========== MOD - [2011-05-21 00:40:45 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Marcin\Desktop\OTL.exe MOD - [2011-05-10 10:48:00 | 000,043,520 | ---- | M] (RealNetworks, Inc.) -- C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchrome10browserrecordhelper.dll MOD - [2011-04-15 14:32:06 | 000,038,304 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\idmmkb.dll MOD - [2010-08-21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll MOD - [2009-06-10 23:14:56 | 000,652,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4926_none_508ed732bcbc0e5a\msvcr90.dll MOD - [2009-06-10 23:14:54 | 000,569,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4926_none_508ed732bcbc0e5a\msvcp90.dll MOD - [2007-09-02 14:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.dll ========== Win32 Services (SafeList) ========== SRV:64bit: - [2011-01-06 06:43:34 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64) SRV:64bit: - [2010-12-03 12:09:08 | 000,341,296 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Common Files\Nitro PDF\Reader\1.0\NitroPDFReaderDriverServicex64.exe -- (NitroReaderDriverReadSpool) SRV:64bit: - [2010-08-12 15:18:40 | 000,042,360 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv) SRV:64bit: - [2010-08-12 15:16:26 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn) SRV:64bit: - [2010-06-08 23:52:16 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2010-01-19 18:26:58 | 001,420,560 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) SRV:64bit: - [2010-01-19 18:08:16 | 000,315,664 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS) SRV:64bit: - [2010-01-19 18:05:22 | 000,831,760 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) SRV:64bit: - [2009-07-14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2009-07-14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2011-01-07 01:48:59 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service) SRV - [2011-01-06 06:43:31 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010-11-22 23:52:46 | 000,718,072 | ---- | M] (Tunngle.net GmbH) [Auto | Running] -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService) SRV - [2010-11-19 21:08:40 | 000,066,872 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2010-06-25 19:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental) SRV - [2009-11-04 07:45:46 | 002,320,920 | R--- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel® SRV - [2009-11-04 07:45:44 | 000,268,824 | R--- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel® SRV - [2009-10-13 12:25:30 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel® SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008-08-04 15:45:16 | 005,779,456 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe -- (MySQL) SRV - [2007-05-31 11:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007-05-31 11:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) SRV - [2006-10-23 14:50:35 | 000,046,640 | R--- | M] (AOL LLC) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011-03-28 19:46:40 | 000,146,568 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP) DRV:64bit: - [2010-07-29 14:31:26 | 000,168,544 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm) DRV:64bit: - [2010-07-29 14:31:26 | 000,141,264 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv) DRV:64bit: - [2010-07-29 14:31:26 | 000,126,320 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr) DRV:64bit: - [2010-06-25 19:07:26 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF) DRV:64bit: - [2010-06-09 02:54:18 | 006,790,656 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2010-06-08 23:19:36 | 000,221,184 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2010-06-08 23:10:46 | 010,322,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd) DRV:64bit: - [2010-06-08 23:10:46 | 010,322,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2010-02-10 09:01:58 | 000,158,720 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd) DRV:64bit: - [2010-01-13 09:37:18 | 007,675,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) Sterownik karty Intel® DRV:64bit: - [2010-01-07 21:51:38 | 000,271,872 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel® DRV:64bit: - [2009-12-03 01:01:24 | 000,213,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService) DRV:64bit: - [2009-10-13 12:16:40 | 000,409,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:64bit: - [2009-09-17 06:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel® DRV:64bit: - [2009-09-16 08:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle) DRV:64bit: - [2009-09-02 19:58:08 | 000,225,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV:64bit: - [2009-08-13 09:38:24 | 000,029,184 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcp.sys -- (BthAvrcp) DRV:64bit: - [2009-07-14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2009-07-14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009-07-14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009-07-14 02:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx) DRV:64bit: - [2009-06-10 23:01:06 | 001,146,880 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem) DRV:64bit: - [2009-06-10 22:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2009-06-10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2006-11-30 00:24:49 | 000,024,064 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wanatw64.sys -- (wanatw) WAN Miniport (ATW) DRV - [2010-01-29 12:40:14 | 000,115,600 | ---- | M] (EZB Systems, Inc.) [File_System | System | Running] -- C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys -- (ISODrive) DRV - [2009-09-02 19:58:08 | 000,225,280 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV - [2008-08-14 08:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "" FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.selectedEngine: "" FF - prefs.js..browser.search.update: false FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.google.pl/" FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-05-11 17:33:55 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011-05-11 17:33:52 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011-05-11 17:34:08 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011-01-12 04:04:08 | 000,000,000 | ---D | M] [2010-11-19 19:10:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcin\AppData\Roaming\mozilla\Extensions [2011-05-21 01:31:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions [2011-02-03 22:44:31 | 000,000,000 | ---D | M] (HP Detect) -- C:\Users\Marcin\AppData\Roaming\mozilla\Firefox\Profiles\6nh7v7o5.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2} [2011-03-04 23:14:02 | 000,002,197 | ---- | M] () -- C:\Users\Marcin\AppData\Roaming\Mozilla\Firefox\Profiles\6nh7v7o5.default\searchplugins\google-search.xml [2011-05-01 22:07:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2010-11-20 04:22:19 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011-01-17 18:13:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} File not found (No name found) -- [2011-05-11 17:33:55 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT [2011-05-16 14:55:27 | 000,000,000 | ---D | M] (IDM CC) -- C:\USERS\MARCIN\APPDATA\ROAMING\IDM\IDMMZCC3 () (No name found) -- C:\USERS\MARCIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6NH7V7O5.DEFAULT\EXTENSIONS\{46551EC9-40F0-4E47-8E18-8E5CF550CFB8}.XPI [2011-04-14 18:59:14 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll [2010-11-12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll [2010-09-21 17:30:02 | 000,120,296 | ---- | M] ( ) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npganymedenet.dll [2010-07-12 18:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll [2010-01-01 10:00:00 | 000,002,767 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\allegro-pl.xml [2010-01-01 10:00:00 | 000,001,406 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\fbc-pl.xml [2011-03-04 23:14:02 | 000,002,197 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\google-search.xml [2010-01-01 10:00:00 | 000,000,917 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\merlin-pl.xml [2010-01-01 10:00:00 | 000,000,858 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\pwn-pl.xml [2010-01-01 10:00:00 | 000,001,183 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-pl.xml [2010-01-01 10:00:00 | 000,001,683 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.) O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [iAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [igfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [intelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [TNOD UP] C:\Program Files (x86)\TNod User & Password Finder\TNODUP.exe (Tukero[X]Team) O4:64bit: - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdcBase.exe (Microsoft Corporation) O4 - HKLM..\Run: [HostManager] C:\Program Files (x86)\Common Files\AOL\1305110212\ee\aolsoftware.exe (AOL Inc.) O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.) O4 - HKCU..\Run: [iDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.) O4 - HKCU..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O8:64bit: - Extra context menu item: Ściągnij przez IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm () O8:64bit: - Extra context menu item: Ściągnij wszystkie linki przez IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm () O8:64bit: - Extra context menu item: 使用快车3下载 - C:\Users\Marcin\AppData\Roaming\FlashGetBHO\GetUrl.htm () O8:64bit: - Extra context menu item: 使用快车3下载全部链接 - C:\Users\Marcin\AppData\Roaming\FlashGetBHO\GetAllUrl.htm () O8 - Extra context menu item: Ściągnij przez IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm () O8 - Extra context menu item: Ściągnij wszystkie linki przez IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm () O8 - Extra context menu item: 使用快车3下载 - C:\Users\Marcin\AppData\Roaming\FlashGetBHO\GetUrl.htm () O8 - Extra context menu item: 使用快车3下载全部链接 - C:\Users\Marcin\AppData\Roaming\FlashGetBHO\GetAllUrl.htm () O13 - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5) O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1302869998152 (MUCatalogWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 95.160.170.92 88.156.222.92 O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011-03-25 00:45:38 | 000,437,782 | R--- | M] () - G:\autorun.ico -- [ UDF ] O32 - AutoRun File - [2010-02-11 05:05:02 | 000,000,047 | R--- | M] () - G:\autorun.inf -- [ UDF ] O33 - MountPoints2\{93197af5-f3f2-11df-b00c-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{93197af5-f3f2-11df-b00c-806e6f6e6963}\Shell\AutoRun\command - "" = F:\CDSetup.exe O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\CDSetup.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011-05-21 00:53:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TNod User & Password Finder [2011-05-21 00:53:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TNod User & Password Finder [2011-05-21 00:47:58 | 000,000,000 | ---D | C] -- C:\_OTL [2011-05-21 00:40:46 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Marcin\Desktop\OTL.exe [2011-05-20 15:48:17 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Desktop\Z TELEFONU [2011-05-16 21:35:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace [2011-05-16 15:08:21 | 000,000,000 | -H-D | C] -- C:\Users\Marcin\AppData\Roaming\SecuROM [2011-05-16 15:08:21 | 000,000,000 | -H-D | C] -- C:\Users\Marcin\AppData\Roaming\Marcin [2011-05-16 15:08:21 | 000,000,000 | -H-D | C] -- C:\Users\Marcin\AppData\Roaming\BlueSoft [2011-05-16 14:35:24 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2011-05-13 10:01:32 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Desktop\to i owo [2011-05-12 11:24:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Object [2011-05-12 01:42:33 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Roaming\AOL [2011-05-12 01:42:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL [2011-05-12 01:42:22 | 000,058,696 | ---- | C] (AOL Inc.) -- C:\Windows\SysWow64\AOLParconLink.exe [2011-05-12 01:42:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Software Update Utility [2011-05-12 01:42:04 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\AOL Downloads [2011-05-12 01:42:02 | 000,024,064 | ---- | C] (America Online, Inc.) -- C:\Windows\SysNative\drivers\wanatw64.sys [2011-05-12 01:41:59 | 000,000,000 | ---D | C] -- C:\ProgramData\AOL OCP [2011-05-12 01:41:54 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\AOL [2011-05-12 01:41:40 | 000,000,000 | ---D | C] -- C:\ProgramData\AOL [2011-05-12 01:35:40 | 000,000,000 | ---D | C] -- C:\ProgramData\AOL Downloads [2011-05-11 17:33:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared [2011-05-11 17:33:52 | 000,198,848 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll [2011-05-11 17:33:44 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll [2011-05-11 17:33:44 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll [2011-05-11 17:33:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real [2011-05-11 17:33:43 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll [2011-05-11 17:33:41 | 000,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp71.dll [2011-05-11 17:33:41 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr71.dll [2011-05-11 12:36:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AOL [2011-05-11 12:36:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AOL Desktop 9.6 [2011-05-11 12:36:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AOL [2011-05-11 12:36:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\aolshare [2011-05-10 10:47:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Real [2011-05-10 10:47:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Real [2011-05-10 10:47:39 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Roaming\Real [2011-05-03 22:12:41 | 000,000,000 | ---D | C] -- C:\Temp [2011-04-29 21:30:21 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\Apps [2011-04-29 21:30:20 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\Deployment [2011-04-28 00:26:02 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Documents\ArmA 2 Other Profiles [2011-04-28 00:25:52 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Documents\ArmA 2 [2011-04-26 16:46:36 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive [2011-04-26 16:46:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bohemia Interactive [2011-04-26 16:25:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive [2011-04-26 16:12:34 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Documents\SKIDROW [2011-04-26 16:12:33 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Local\ArmA 2 REINFORCEMENTS [2011-04-25 23:52:36 | 000,163,840 | ---- | C] (America Online) -- C:\Windows\SysWow64\jgdw400.dll [2011-04-25 23:52:36 | 000,027,648 | ---- | C] (Johnson-Grace Company) -- C:\Windows\SysWow64\jgpl400.dll [2011-04-25 17:41:51 | 000,146,568 | ---- | C] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys [2011-04-25 00:43:13 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Documents\Alpha Protocol [2011-04-25 00:42:04 | 000,000,000 | ---D | C] -- C:\Users\Marcin\AppData\Roaming\SEGA Corporation [2011-04-25 00:42:01 | 000,000,000 | ---D | C] -- C:\ProgramData\SEGA Corporation [2011-04-24 23:28:44 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallShield [2011-04-24 23:09:53 | 000,073,728 | ---- | C] (Macrovision Corporation) -- C:\Windows\SysWow64\ISUSPM.cpl [2011-04-23 02:23:49 | 000,000,000 | ---D | C] -- C:\Users\Marcin\Application Data [2011-04-22 23:14:06 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\fat32format ========== Files - Modified Within 30 Days ========== [2011-05-21 13:22:12 | 000,014,960 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011-05-21 13:22:12 | 000,014,960 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011-05-21 13:19:18 | 001,552,302 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2011-05-21 13:19:18 | 000,697,438 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2011-05-21 13:19:18 | 000,615,958 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2011-05-21 13:19:18 | 000,136,896 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2011-05-21 13:19:18 | 000,107,594 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2011-05-21 13:14:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011-05-21 13:14:52 | 3055,693,824 | -HS- | M] () -- C:\hiberfil.sys [2011-05-21 13:14:12 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\Access.dat [2011-05-21 01:12:31 | 000,302,080 | ---- | M] () -- C:\Users\Marcin\Desktop\tx5rp0sb.exe [2011-05-21 01:04:32 | 000,302,080 | ---- | M] () -- C:\Users\Marcin\Desktop\l3owgs9d.exe [2011-05-21 00:40:45 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Marcin\Desktop\OTL.exe [2011-05-20 15:52:54 | 052,720,183 | ---- | M] () -- C:\Users\Marcin\Desktop\ESET.rar [2011-05-17 00:36:32 | 111,093,341 | ---- | M] () -- C:\Users\Marcin\Desktop\R.W.PL.01-02.2011.pdf [2011-05-17 00:29:46 | 107,694,980 | ---- | M] () -- C:\Users\Marcin\Desktop\R.W.PL.02.2011.pdf [2011-05-16 21:31:26 | 000,001,479 | ---- | M] () -- C:\Users\Public\Desktop\Operation Flashpoint ® Red River.lnk [2011-05-16 14:35:24 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2011-05-13 01:16:53 | 000,009,728 | ---- | M] () -- C:\Users\Marcin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-05-12 07:44:39 | 000,034,103 | ---- | M] () -- C:\Users\Marcin\Documents\sciaga-51778.rtf [2011-05-12 02:07:18 | 000,000,002 | ---- | M] () -- C:\Windows\msoffice.ini [2011-05-12 01:35:51 | 000,058,696 | ---- | M] (AOL Inc.) -- C:\Windows\SysWow64\AOLParconLink.exe [2011-05-12 01:35:39 | 000,000,335 | ---- | M] () -- C:\Windows\nsreg.dat [2011-05-11 20:20:48 | 000,202,448 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe [2011-05-11 17:33:52 | 000,198,848 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\rmoc3260.dll [2011-05-11 17:33:44 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5016.dll [2011-05-11 17:33:44 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\SysWow64\pndx5032.dll [2011-05-11 17:33:43 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll [2011-05-11 17:33:41 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp71.dll [2011-05-11 17:33:41 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr71.dll [2011-05-11 12:37:45 | 000,000,989 | ---- | M] () -- C:\Users\Public\Desktop\AOL Desktop 9.6.lnk [2011-05-03 12:55:07 | 000,334,378 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0382.jpg [2011-04-29 11:56:57 | 000,337,091 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0386.jpg [2011-04-29 11:49:10 | 000,319,130 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0387.jpg [2011-04-29 11:49:08 | 000,353,563 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0388.jpg [2011-04-29 11:47:41 | 000,428,156 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0393.jpg [2011-04-29 11:47:32 | 000,285,559 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0383.jpg [2011-04-29 11:47:31 | 000,307,280 | ---- | M] () -- C:\Users\Marcin\Documents\IMG_0381.jpg [2011-04-26 16:49:33 | 000,000,927 | ---- | M] () -- C:\Users\Public\Desktop\Uruchom ARMA 2 REINFORCEMENTS.lnk [2011-04-25 23:52:36 | 000,163,840 | ---- | M] (America Online) -- C:\Windows\SysWow64\jgdw400.dll [2011-04-25 23:52:36 | 000,027,648 | ---- | M] (Johnson-Grace Company) -- C:\Windows\SysWow64\jgpl400.dll [2011-04-25 21:08:38 | 000,001,150 | ---- | M] () -- C:\Users\Marcin\Desktop\APGame.lnk [2011-04-21 16:32:59 | 000,369,296 | ---- | M] () -- C:\Users\Marcin\Documents\Dj Olimp B-day party.jpg [2011-04-21 15:06:00 | 000,593,504 | ---- | M] () -- C:\Users\Marcin\Documents\lany(2).jpg [2011-04-21 14:57:18 | 000,597,972 | ---- | M] () -- C:\Users\Marcin\Documents\lany(1).jpg [2011-04-21 14:57:09 | 000,597,972 | ---- | M] () -- C:\Users\Marcin\Documents\lany.jpg [2011-04-21 14:28:04 | 000,543,440 | ---- | M] () -- C:\Users\Marcin\Documents\lany poniedziałek(1).jpg [2011-04-21 14:19:25 | 000,555,397 | ---- | M] () -- C:\Users\Marcin\Documents\lany poniedziałek.jpg ========== Files Created - No Company Name ========== [2011-05-21 01:12:37 | 000,302,080 | ---- | C] () -- C:\Users\Marcin\Desktop\tx5rp0sb.exe [2011-05-21 01:04:34 | 000,302,080 | ---- | C] () -- C:\Users\Marcin\Desktop\l3owgs9d.exe [2011-05-20 15:52:54 | 052,720,183 | ---- | C] () -- C:\Users\Marcin\Desktop\ESET.rar [2011-05-17 00:36:31 | 111,093,341 | ---- | C] () -- C:\Users\Marcin\Desktop\R.W.PL.01-02.2011.pdf [2011-05-17 00:29:46 | 107,694,980 | ---- | C] () -- C:\Users\Marcin\Desktop\R.W.PL.02.2011.pdf [2011-05-16 21:31:26 | 000,001,479 | ---- | C] () -- C:\Users\Public\Desktop\Operation Flashpoint ® Red River.lnk [2011-05-12 07:44:39 | 000,034,103 | ---- | C] () -- C:\Users\Marcin\Documents\sciaga-51778.rtf [2011-05-12 02:07:18 | 000,000,002 | ---- | C] () -- C:\Windows\msoffice.ini [2011-05-11 12:37:45 | 000,000,989 | ---- | C] () -- C:\Users\Public\Desktop\AOL Desktop 9.6.lnk [2011-05-01 22:07:13 | 000,001,150 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2011-04-29 11:56:40 | 000,337,091 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0386.jpg [2011-04-29 11:48:48 | 000,319,130 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0387.jpg [2011-04-29 11:48:47 | 000,353,563 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0388.jpg [2011-04-29 11:47:22 | 000,428,156 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0393.jpg [2011-04-29 11:47:07 | 000,285,559 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0383.jpg [2011-04-29 11:47:05 | 000,334,378 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0382.jpg [2011-04-29 11:47:05 | 000,307,280 | ---- | C] () -- C:\Users\Marcin\Documents\IMG_0381.jpg [2011-04-26 16:49:33 | 000,000,927 | ---- | C] () -- C:\Users\Public\Desktop\Uruchom ARMA 2 REINFORCEMENTS.lnk [2011-04-25 21:08:38 | 000,001,150 | ---- | C] () -- C:\Users\Marcin\Desktop\APGame.lnk [2011-04-24 00:09:55 | 000,049,233 | ---- | C] () -- C:\Windows\fat32format.exe [2011-04-21 16:32:41 | 000,369,296 | ---- | C] () -- C:\Users\Marcin\Documents\Dj Olimp B-day party.jpg [2011-04-21 15:05:37 | 000,593,504 | ---- | C] () -- C:\Users\Marcin\Documents\lany(2).jpg [2011-04-21 14:56:53 | 000,597,972 | ---- | C] () -- C:\Users\Marcin\Documents\lany(1).jpg [2011-04-21 14:56:46 | 000,597,972 | ---- | C] () -- C:\Users\Marcin\Documents\lany.jpg [2011-04-21 14:27:43 | 000,543,440 | ---- | C] () -- C:\Users\Marcin\Documents\lany poniedziałek(1).jpg [2011-04-21 14:19:04 | 000,555,397 | ---- | C] () -- C:\Users\Marcin\Documents\lany poniedziałek.jpg [2011-04-09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2011-03-18 16:39:28 | 000,000,094 | ---- | C] () -- C:\Users\Marcin\AppData\Local\fusioncache.dat [2011-03-18 16:37:37 | 001,576,536 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011-03-02 15:47:24 | 000,001,770 | ---- | C] () -- C:\Windows\SysWow64\secushr.dat [2011-03-02 14:09:58 | 000,000,468 | ---- | C] () -- C:\Windows\SysWow64\secustat.dat [2011-03-02 14:04:57 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI [2011-02-09 23:22:37 | 000,000,017 | ---- | C] () -- C:\Users\Marcin\AppData\Local\resmon.resmoncfg [2011-02-07 15:25:54 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat [2011-02-01 11:10:31 | 000,036,864 | ---- | C] () -- C:\Windows\hpfsched.exe [2011-02-01 11:10:26 | 000,004,760 | ---- | C] () -- C:\Windows\hphmdl11.dat [2011-01-11 03:20:17 | 000,009,728 | ---- | C] () -- C:\Users\Marcin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-01-07 02:14:21 | 000,000,000 | ---- | C] () -- C:\Users\Marcin\AppData\Roaming\AVSMediaPlayer.m3u [2010-12-29 03:08:45 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll [2010-11-22 00:58:18 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2010-11-20 04:13:12 | 000,002,110 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat [2010-11-19 21:08:56 | 000,202,448 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2010-11-19 21:08:40 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2010-11-19 20:27:45 | 000,000,313 | ---- | C] () -- C:\Windows\CODUO.ini [2010-11-19 20:21:30 | 000,000,713 | ---- | C] () -- C:\Windows\COD.INI [2010-11-19 19:22:59 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2010-11-19 19:09:58 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat [2010-11-17 23:42:54 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin [2010-11-17 23:42:54 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin [2010-11-17 23:42:53 | 000,002,110 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2010-08-25 20:34:30 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin [2010-08-25 19:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll [2010-08-25 19:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll [2010-06-25 19:03:12 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll [2009-07-14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009-07-14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2009-07-14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2009-07-14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009-07-14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009-07-13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009-06-10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat ========== Alternate Data Streams ========== @Alternate Data Stream - 55920 bytes -> C:\ProgramData:$SS_DESCRIPTOR_LVVWVBGV0VFBTLX4D06YH7LVUTPXGJMBKE1R0WT1VH7E24F7PHCTVF4VMVFVVX4VM < End of report > i extras OTL Extras logfile created on: 2011-05-21 13:27:37 - Run 3 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Marcin\Desktop 64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 63,00% Memory free 8,00 Gb Paging File | 6,00 Gb Available in Paging File | 77,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 58,57 Gb Total Space | 16,41 Gb Free Space | 28,02% Space Free | Partition Type: NTFS Drive D: | 211,88 Gb Total Space | 36,33 Gb Free Space | 17,15% Space Free | Partition Type: NTFS Drive E: | 195,31 Gb Total Space | 29,18 Gb Free Space | 14,94% Space Free | Partition Type: NTFS Drive G: | 4,38 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: MARCIN-KOMPUTER | User Name: Marcin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) .js[@ = JSFile] -- C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe (Macromedia, Inc.) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .js [@ = JSFile] -- C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe (Macromedia, Inc.) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) jsfile [edit] -- "C:\Program Files (x86)\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.) jsfile [open] -- "C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1" (Macromedia, Inc.) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) jsfile [edit] -- "C:\Program Files (x86)\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.) jsfile [open] -- "C:\Program Files (x86)\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1" (Macromedia, Inc.) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DisableUnicastResponsesToMulticastBroadcast" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3 "C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3 ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0CB41726-DEBA-46E1-B48B-873F012ACAA1}" = Nitro PDF Reader "{16CC554E-7E33-4C60-9EE4-A781DCAB65A8}" = ESET NOD32 Antivirus "{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64 "{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64 "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{64798798-D0C8-4246-56FB-5C5D8A61615C}" = ATI Catalyst Install Manager "{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64 "{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64 "{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4 "{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4 "{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64 "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2010 "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4 "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64 "{A8725474-37EF-7FCE-DB35-D2CCE7A4C462}" = ccc-utility64 "{B90E5EBE-DF18-44D5-9D18-689ADEE9DA6C}" = Oprogramowanie Intel® PROSet/Wireless WiFi "{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit) "{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4 "CCleaner" = CCleaner "KLiteCodecPack64_is1" = K-Lite Codec Pack (64-bit) v4.5.0 "ProInst" = Intel PROSet Wireless "TNod" = TNod User & Password Finder "WinRAR archiver" = Archiwizator WinRAR [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4 "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4 "{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4 "{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004 "{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8 "{08DE5112-C279-F317-EB93-4D30708A3AE4}" = CCC Help Czech "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler "{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4 "{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4 "{11742D23-0668-5AA8-19FA-8F88FADC1ABE}" = Catalyst Control Center Graphics Light "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4 "{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4 "{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB "{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR "{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1 "{1AFF250C-F408-DBBA-ECBE-33467D3F76BC}" = CCC Help Chinese Standard "{1B33B869-A7B8-3F7B-CB3D-54D1A2A16B37}" = Catalyst Control Center Graphics Previews Vista "{1E445925-273D-4186-88A0-B8D1B6B119E2}" = WRC FIA World Rally Championship "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{22EDD164-65D5-41DD-961E-08C7CDA4D471}" = Bridge! "{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback 10 "{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10 "{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java 6 Update 23 "{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10 "{27BA485D-529E-F94D-C8C5-499547E6493A}" = CCC Help Danish "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2D2E4682-3B5C-5A3C-1379-F497BCC8B55C}" = CCC Help Chinese Traditional "{32BB5A09-D930-EB57-737D-7B0BAD29D5D2}" = CCC Help Japanese "{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4 "{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4 "{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4 "{3D735073-A39C-F5B4-5A9F-CC8B5177251D}" = CCC Help Hungarian "{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin "{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX "{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}" = FIFA 11 "{406AD3D7-F5BB-49C1-A280-6BCB5F6BC099}" = MySQL Server 5.0 "{409597FD-C9EE-4658-8B13-535DFF22B666}_is1" = Milionerzy 2.0.6 "{434D083E-7E9A-4D3A-914B-121000008100}" = Operation Flashpoint ®: Red River "{488CC14B-15FC-AFFB-F8E4-72B97F7A7C00}" = CCC Help Polish "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace "{52EC4C05-0290-D8DB-948E-4BE0C8FE5F4D}" = CCC Help Norwegian "{53128B2F-8A2B-5FC7-B735-3826B294BE7D}" = Catalyst Control Center Graphics Full New "{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI "{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries "{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager "{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4 "{5833B2D1-B2C1-2819-1EA5-EE23C772DF01}" = CCC Help English "{6291FC10-FDF0-4022-A1A5-710C728D49C2}" = Vancouver 2010 "{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic "{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4 "{63C48CA5-C5D3-2E46-06A4-1A06791A20AB}" = CCC Help Korean "{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components "{679A64E7-14CD-FF36-1470-9DED77603F7B}" = CCC Help Russian "{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4 "{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK "{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{6BC27278-28F6-D98A-587C-591FD8DDDC4C}" = PowerXpressHybrid "{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10 "{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10 "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{74B5512F-E710-8F87-4597-B126F54BD6D1}" = CCC Help Thai "{7703D8FE-8C98-8CD9-A946-475DC6BBA04C}" = CCC Help Spanish "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10 "{7B034E4B-A41A-7B9F-9820-C58C4CC99716}" = Catalyst Control Center Core Implementation "{7D73203D-5854-3B87-25A7-9025829EB076}" = CCC Help Finnish "{7ED5371F-F4EA-48F9-B8F7-C8777AD9DF69}" = Borland Turbo C++ "{81DD0597-29EB-4FA0-8223-4F41362B2E72}" = NBA 2K11 "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4 "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8B743AA0-53B2-11D2-808A-00600895FB43}" = Heroes of Might and Magic III - Złota Edycja "{8BCD960B-2ECC-595C-F934-543061F10F2B}" = CCC Help Italian "{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}" = SWAT 4 "{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010 "{90140000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010 "{90140000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010 "{90140000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010 "{90140000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010 "{90140000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010 "{90140000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010 "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010 "{90140000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010 "{90140000-0044-0415-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010 "{90140000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010 "{90140000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010 "{90140000-00BA-0415-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010 "{909F8EBC-EC7F-48FF-0085-475D818F0F31}" = Need for Speed Underground 2 "{92942F31-C642-7839-BA61-CC5E1DD9397D}" = CCC Help Swedish "{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4 "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4 "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A2092B2A-A4FB-4464-A4C0-023D2C9993F8}" = m-Router 3.1 "{A5F481DE-A5D2-725F-A0F3-1E663272D198}" = PX Profile Update "{A662E280-64A8-4CF5-8407-13D0808602B3}" = Call of Duty - United Offensive "{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries "{AC08BBA0-96B9-431A-A7D0-D8598E493775}" = RESIDENT EVIL 5 "{AC76BA86-7AD7-1045-7B44-A94000000001}" = Adobe Reader 9.4.4 - Polish "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect "{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4 "{B6E3F2A0-DDBB-4F0A-BA7C-09138605DDAC}" = WRC FIA World Rally Championship "{BA659DC5-F577-4364-903D-20C16DD4BDB3}" = Catalyst Control Center - Branding "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module "{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10 "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4 "{C85F4BE3-0725-1D9C-50D7-27A5F8CBE6EF}" = CCC Help Greek "{CA659543-232D-9B74-7058-A8C2DDA16405}" = ccc-core-static "{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86 "{CD0A677F-D3BB-1187-1669-AE2960659370}" = Catalyst Control Center Localization All "{CF83661A-F6FC-39A7-9552-B86E1239CC40}" = CCC Help Turkish "{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005 "{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.22 Game "{D37FE0E3-B1A9-4E41-AB5D-DA62E04D2C42}" = Alpha Protocol "{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver "{D850DA0F-468D-9BCE-D601-A41D294F1BD8}" = Catalyst Control Center InstallProxy "{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10 "{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4 "{E81E7CD7-74D6-E355-F19A-427F1B2EE3BF}" = Catalyst Control Center Graphics Full Existing "{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}" = Microsoft .NET Framework SDK (English) 1.1 "{EBC48194-90E6-EBA1-0DD6-9466095E1CAF}" = CCC Help French "{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10 "{EF5B8746-E00C-6306-879E-05444A6839C9}" = CCC Help Portuguese "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable "{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10 "{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic "{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10 "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4 "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4 "{FC09D493-A649-E880-A505-DEAA304E1A8D}" = CCC Help German "{FC8CF7E1-5722-9952-2A56-8C28E2D17A42}" = CCC Help Dutch "{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All "{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4 "ALLPlayer_is1" = ALLPlayer V4.X "AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove) "ARMA 2 REINFORCEMENTS" = ARMA 2 REINFORCEMENTS Uninstall "Ashampoo Burning Studio 10_is1" = Ashampoo Burning Studio 10.0.4 "Call of Duty" = Call of Duty "Call of Duty Modern Warfare 2_is1" = Call of Duty Modern Warfare 2 "Cisco Packet Tracer_is1" = Cisco Packet Tracer 5.2.1 "ClassicPro" = ClassicPro© v1.15 "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player "Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2) "Emergency 2012" = Emergency 2012 "GameDesire-Poker" = GameDesire-Poker "GFWL_{434D083E-7E9A-4D3A-914B-121000008100}" = Operation Flashpoint ®: Red River "Gold Wave Editor Pro_is1" = Gold Wave Editor Pro v10.5.5 "Gordon's Gate Flash Driver" = Gordon's Gate Flash Driver 2.2.0.1 "InstallShield_{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}" = SWAT 4 "InstallShield_{A662E280-64A8-4CF5-8407-13D0808602B3}" = Call of Duty - United Offensive "Internet Download Manager" = Internet Download Manager "ipla" = ipla 2.3 "Komputer i Ty Kurs PHP1.0" = Komputer i Ty Kurs PHP "Left 4 Dead" = Left 4 Dead "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Mozilla Firefox 4.0.1 (x86 pl)" = Mozilla Firefox 4.0.1 (x86 pl) "NapiProjekt_is1" = NapiProjekt 1.0.6.9 "Nowe Gadu-Gadu" = Nowe Gadu-Gadu "Office14.PROPLUS" = Microsoft Office Professional Plus 2010 "OpenAL" = OpenAL "RealPlayer 12.0" = RealPlayer "RocketDock_is1" = RocketDock 1.3.5 "slow_12_60_is1" = Profesor Henry 6.0 Słownictwo poziom 1 i 2 "Sniper - Ghost Warrior_is1" = Sniper - Ghost Warrior "SoftwareUpdUtility" = Download Updater (AOL LLC) "Splinter Cell: Teoria Chaosu_is1" = Splinter Cell: Teoria Chaosu 1.05 PL "Totalcmd" = Total Commander (Remove or Repair) "Tunngle beta_is1" = Tunngle beta "UltraISO_is1" = UltraISO Premium V9.36 "uTorrent" = µTorrent "Winamp" = Winamp "WinPcapInst" = WinPcap 4.1.2 "Wireshark" = Wireshark 1.4.3 "WisBar Advance Desktop_is1" = WisBar Advance Desktop 2.5c ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Winamp Detect" = Detektor Winampa ========== Last 10 Event Log Errors ========== Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt! < End of report > Odnośnik do komentarza
Landuss Opublikowano 20 Maja 2011 Zgłoś Udostępnij Opublikowano 20 Maja 2011 A JESZCZE MAM JEDNO PYTANKO. Jeżeli podłączę dysk przenośny ( a tam tez mam ten plik) to czy nie odnowi on robala w lapku ? Możesz podpiąć urządzenie ale go nie uruchamiaj. W zamian za to uruchom USBFix z opcji Listing i pokaż wynikowy raport. Odnośnik do komentarza
przytom Opublikowano 20 Maja 2011 Autor Zgłoś Udostępnij Opublikowano 20 Maja 2011 Log: ############################## | UsbFix 7.045 | [Listing] User: Marcin (Administrator) # MARCIN-KOMPUTER [Micro-Star International MS-1675] Updated 15/05/2011 by TeamXscript Started at 22:21:42 | 21/05/2011 Website: http://www.teamxscript.org Submit your sample: http://www.teamxscript.org/Upload.php Contact: TeamXscript.ElDesaparecido@gmail.com CPU: Intel® Core i5 CPU M 460 @ 2.53GHz CPU 2: Intel® Core i5 CPU M 460 @ 2.53GHz Microsoft Windows 7 Professional (6.1.7600 64-Bit) # Internet Explorer 8.0.7600.16385 Windows Firewall: Disabled /!\ RAM -> 3886 Mb C:\ (%systemdrive%) -> Fixed drive # 59 Gb (16 Mb free - 27%) [] # NTFS D:\ -> Fixed drive # 212 Gb (36 Mb free - 17%) [GIERKI] # NTFS E:\ -> Fixed drive # 195 Gb (29 Mb free - 15%) [uŻYTKI] # NTFS F:\ -> CD-ROM G:\ -> CD-ROM H:\ -> Fixed drive # 29 Gb (18 Mb free - 60%) [NOWY] # FAT32 J:\ -> Fixed drive # 166 Gb (166 Mb free - 100%) [NTSF] # NTFS K:\ -> Fixed drive # 270 Gb (173 Mb free - 64%) [2_exFAT] # exFAT ################## | Listing | [25/03/2011 - 21:23:31 | SHD ] C:\$Recycle.Bin [19/11/2010 - 18:53:07 | D ] C:\AMD [19/11/2010 - 18:51:18 | D ] C:\ATI [19/11/2010 - 17:34:19 | SHD ] C:\Boot [14/07/2009 - 03:38:58 | RASH | 383562] C:\bootmgr [19/11/2010 - 17:34:21 | RASH | 8192] C:\BOOTSECT.BAK [20/11/2010 - 02:08:36 | D ] C:\Dev-Cpp [14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings [03/02/2011 - 19:20:26 | D ] C:\Download [21/05/2011 - 21:32:49 | ASH | 3055693824] C:\hiberfil.sys [11/05/2011 - 12:37:37 | A | 62390] C:\install.log [19/11/2010 - 18:45:20 | D ] C:\Intel [05/12/2010 - 22:54:08 | RHD ] C:\MSOCache [21/05/2011 - 21:32:51 | ASH | 4074258432] C:\pagefile.sys [14/07/2009 - 05:20:08 | D ] C:\PerfLogs [15/04/2011 - 19:08:51 | RD ] C:\Program Files [21/05/2011 - 01:00:57 | D ] C:\Program Files (x86) [21/05/2011 - 01:00:38 | AHD ] C:\ProgramData [19/11/2010 - 18:41:10 | SHD ] C:\Recovery [21/05/2011 - 14:23:02 | SHD ] C:\System Volume Information [03/05/2011 - 22:30:18 | D ] C:\Temp [10/12/2010 - 00:30:32 | D ] C:\totalcmd [12/04/2011 - 12:39:44 | D ] C:\ToxSickLabs [21/05/2011 - 22:20:36 | D ] C:\UsbFix [21/05/2011 - 22:21:39 | A | 2204] C:\UsbFix.txt [04/04/2011 - 17:29:15 | D ] C:\USBFlashDriver [25/03/2011 - 21:23:28 | RD ] C:\Users [21/05/2011 - 13:13:47 | D ] C:\Windows [26/11/2010 - 19:32:03 | A | 4948] C:\WirelessDiagLog.csv [21/05/2011 - 00:47:58 | D ] C:\_OTL [25/03/2011 - 21:23:31 | SHD ] D:\$RECYCLE.BIN [09/04/2011 - 00:09:56 | D ] D:\Bridge The Construction Game (2011) [03/03/2011 - 21:05:30 | D ] D:\Downloads [15/04/2011 - 00:52:21 | D ] D:\DwnlData [11/03/2011 - 21:57:59 | D ] D:\ELiTE.Hdyk [21/05/2011 - 00:58:22 | D ] D:\GRY [04/05/2011 - 01:17:06 | D ] D:\GRY iso [12/05/2011 - 18:42:23 | D ] D:\Jezyk Angielski Callan Method-Ksiazki i mp3 [19/11/2010 - 16:18:59 | HD ] D:\msdownld.tmp [10/01/2011 - 16:09:44 | D ] D:\OFFICE_2010 [19/03/2011 - 00:41:40 | D ] D:\ProHe6.Slcd1 [21/03/2011 - 01:59:28 | AH | 419430400] D:\ProHe6.Slcd2.part1.rar [21/03/2011 - 02:02:36 | AH | 304746654] D:\ProHe6.Slcd2.part2.rar [21/03/2011 - 02:08:12 | AH | 419430400] D:\ProHe6.Slcd4.part1.rar [21/03/2011 - 02:10:52 | AH | 184033442] D:\ProHe6.Slcd4.part2.rar [17/11/2010 - 17:02:26 | SHD ] D:\System Volume Information [25/03/2011 - 21:23:31 | SHD ] E:\$RECYCLE.BIN [07/04/2011 - 15:57:37 | D ] E:\DO KOMA [20/05/2011 - 15:47:12 | RD ] E:\DOKUMENTY [20/05/2011 - 23:11:18 | RD ] E:\FILMY [25/12/2010 - 01:58:45 | D ] E:\HUMOR [09/02/2011 - 22:09:02 | RD ] E:\MUZYCZKA [06/02/2011 - 03:44:19 | A | 50863] E:\Nowy.ncd [08/04/2011 - 00:45:59 | RD ] E:\POBIERANE [14/04/2011 - 11:37:17 | D ] E:\poradnik [07/04/2011 - 15:40:29 | RD ] E:\PREZENTACJE [21/05/2011 - 01:33:06 | D ] E:\programosy [21/05/2011 - 01:19:09 | RD ] E:\PWSZ [17/11/2010 - 17:02:27 | SHD ] E:\System Volume Information [04/04/2011 - 16:45:05 | RD ] E:\ZDJĘCIA [25/03/2011 - 01:02:21 | RA | 24564] G:\ChainInstall.xml [25/03/2011 - 01:00:12 | RA | 7247] G:\ChainInstall.xml.cat [20/04/2011 - 18:51:34 | RAD ] G:\Crack [29/03/2011 - 10:09:25 | RAD ] G:\EULA [02/03/2011 - 22:58:30 | RA | 183] G:\GFWL_Installer_Autorun.bat [25/03/2011 - 01:34:10 | RA | 4136960] G:\Game.msi [29/03/2011 - 10:11:29 | RAD ] G:\Manuals [25/03/2011 - 00:52:00 | RA | 1994332555] G:\Media1.cab [25/03/2011 - 00:52:14 | RA | 1908090967] G:\Media2.cab [25/03/2011 - 00:46:41 | RA | 531254356] G:\Media3.cab [29/03/2011 - 10:09:25 | RAD ] G:\Readme [29/03/2011 - 10:09:15 | RAD ] G:\Redist [02/03/2011 - 22:58:50 | RA | 440704] G:\Setup.exe [29/03/2011 - 10:09:11 | RAD ] G:\SetupMedia [25/03/2011 - 00:45:38 | RA | 437782] G:\autorun.ico [11/02/2010 - 05:05:02 | RA | 47] G:\autorun.inf [12/03/2010 - 12:37:14 | RA | 187544] G:\xliveinstall.dll [19/04/2011 - 01:03:58 | A | 741148672] H:\psig-white.material.2009.pl.dvdrip.xvid.avi [12/05/2011 - 17:53:42 | A | 41] H:\pmp_usb.ini [01/05/2011 - 15:32:46 | D ] H:\Dom Zły (2009) PL.480p [01/05/2011 - 15:37:56 | D ] H:\Kumple na Zabój - The Matador (2005) [01/05/2011 - 15:46:14 | D ] H:\Pułapka - Hard Candy (2005) PL [12/05/2011 - 17:54:06 | D ] H:\oglądane [11/05/2011 - 20:16:36 | D ] H:\Czarny Łabędź - Black Swan 2010 PL [11/05/2011 - 20:18:00 | D ] H:\Miłość i inne używki - Love and Other Drugs (2010) PL [12/05/2011 - 18:41:04 | SHD ] H:\$RECYCLE.BIN [12/05/2011 - 19:04:28 | A | 52] H:\winamp_metadata.idx [12/05/2011 - 19:04:28 | A | 423] H:\winamp_metadata.dat [12/05/2011 - 19:16:30 | D ] H:\Bez Reguł [18/05/2011 - 16:08:20 | A | 39] H:\autorun.inf [18/05/2011 - 16:08:20 | A | 18944] H:\Nie uruchamiaj tego.exe [17/05/2011 - 20:27:42 | D ] J:\aaa [18/05/2011 - 16:08:24 | A | 39] J:\autorun.inf [18/05/2011 - 16:08:23 | A | 18944] J:\Nie uruchamiaj tego.exe [17/05/2011 - 20:24:15 | SHD ] J:\System Volume Information [22/04/2011 - 23:03:04 | SHD ] K:\$RECYCLE.BIN [24/04/2011 - 00:17:27 | D ] K:\GIERKI_ISO [18/05/2011 - 16:08:30 | A | 39] K:\autorun.inf [18/05/2011 - 16:08:30 | A | 18944] K:\Nie uruchamiaj tego.exe ################## | E.O.F | Odnośnik do komentarza
Landuss Opublikowano 20 Maja 2011 Zgłoś Udostępnij Opublikowano 20 Maja 2011 Przy podpiętym urządzeniu wykonaj kolejny skrypt do OTL: :Files G:\autorun.inf H:\autorun.inf K:\autorun.inf J:\autorun.inf H:\Nie uruchamiaj tego.exe J:\Nie uruchamiaj tego.exe K:\Nie uruchamiaj tego.exe Do wglądu log powstały z usuwania i nowy log z USBFix z opcji Listing. Odnośnik do komentarza
przytom Opublikowano 20 Maja 2011 Autor Zgłoś Udostępnij Opublikowano 20 Maja 2011 Wyniki: ========== FILES ========== File move failed. G:\autorun.inf scheduled to be moved on reboot. H:\autorun.inf moved successfully. K:\autorun.inf moved successfully. J:\autorun.inf moved successfully. H:\Nie uruchamiaj tego.exe moved successfully. J:\Nie uruchamiaj tego.exe moved successfully. K:\Nie uruchamiaj tego.exe moved successfully. OTL by OldTimer - Version 3.2.22.3 log created on 05212011_231246 Files\Folders moved on Reboot... File move failed. G:\autorun.inf scheduled to be moved on reboot. Registry entries deleted on Reboot... oraz nowy Listing - czyli widzę, ze się pousuwały ############################## | UsbFix 7.045 | [Listing] User: Marcin (Administrator) # MARCIN-KOMPUTER [Micro-Star International MS-1675] Updated 15/05/2011 by TeamXscript Started at 23:16:00 | 21/05/2011 Website: http://www.teamxscript.org Submit your sample: http://www.teamxscript.org/Upload.php Contact: TeamXscript.ElDesaparecido@gmail.com CPU: Intel® Core i5 CPU M 460 @ 2.53GHz CPU 2: Intel® Core i5 CPU M 460 @ 2.53GHz Microsoft Windows 7 Professional (6.1.7600 64-Bit) # Internet Explorer 8.0.7600.16385 Windows Firewall: Disabled /!\ RAM -> 3886 Mb C:\ (%systemdrive%) -> Fixed drive # 59 Gb (16 Mb free - 27%) [] # NTFS D:\ -> Fixed drive # 212 Gb (36 Mb free - 17%) [GIERKI] # NTFS E:\ -> Fixed drive # 195 Gb (29 Mb free - 15%) [uŻYTKI] # NTFS F:\ -> CD-ROM G:\ -> CD-ROM H:\ -> Fixed drive # 29 Gb (18 Mb free - 60%) [NOWY] # FAT32 J:\ -> Fixed drive # 166 Gb (166 Mb free - 100%) [NTSF] # NTFS K:\ -> Fixed drive # 270 Gb (173 Mb free - 64%) [2_exFAT] # exFAT ################## | Listing | [25/03/2011 - 21:23:31 | SHD ] C:\$Recycle.Bin [19/11/2010 - 18:53:07 | D ] C:\AMD [19/11/2010 - 18:51:18 | D ] C:\ATI [19/11/2010 - 17:34:19 | SHD ] C:\Boot [14/07/2009 - 03:38:58 | RASH | 383562] C:\bootmgr [19/11/2010 - 17:34:21 | RASH | 8192] C:\BOOTSECT.BAK [20/11/2010 - 02:08:36 | D ] C:\Dev-Cpp [14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings [03/02/2011 - 19:20:26 | D ] C:\Download [21/05/2011 - 23:13:44 | ASH | 3055693824] C:\hiberfil.sys [11/05/2011 - 12:37:37 | A | 62390] C:\install.log [19/11/2010 - 18:45:20 | D ] C:\Intel [05/12/2010 - 22:54:08 | RHD ] C:\MSOCache [21/05/2011 - 23:13:48 | ASH | 4074258432] C:\pagefile.sys [14/07/2009 - 05:20:08 | D ] C:\PerfLogs [15/04/2011 - 19:08:51 | RD ] C:\Program Files [21/05/2011 - 01:00:57 | D ] C:\Program Files (x86) [21/05/2011 - 22:28:16 | AHD ] C:\ProgramData [19/11/2010 - 18:41:10 | SHD ] C:\Recovery [21/05/2011 - 14:23:02 | SHD ] C:\System Volume Information [03/05/2011 - 22:30:18 | D ] C:\Temp [10/12/2010 - 00:30:32 | D ] C:\totalcmd [12/04/2011 - 12:39:44 | D ] C:\ToxSickLabs [21/05/2011 - 22:20:36 | D ] C:\UsbFix [21/05/2011 - 23:15:57 | A | 2204] C:\UsbFix.txt [04/04/2011 - 17:29:15 | D ] C:\USBFlashDriver [25/03/2011 - 21:23:28 | RD ] C:\Users [21/05/2011 - 13:13:47 | D ] C:\Windows [26/11/2010 - 19:32:03 | A | 4948] C:\WirelessDiagLog.csv [21/05/2011 - 00:47:58 | D ] C:\_OTL [25/03/2011 - 21:23:31 | SHD ] D:\$RECYCLE.BIN [09/04/2011 - 00:09:56 | D ] D:\Bridge The Construction Game (2011) [03/03/2011 - 21:05:30 | D ] D:\Downloads [15/04/2011 - 00:52:21 | D ] D:\DwnlData [11/03/2011 - 21:57:59 | D ] D:\ELiTE.Hdyk [21/05/2011 - 00:58:22 | D ] D:\GRY [04/05/2011 - 01:17:06 | D ] D:\GRY iso [12/05/2011 - 18:42:23 | D ] D:\Jezyk Angielski Callan Method-Ksiazki i mp3 [19/11/2010 - 16:18:59 | HD ] D:\msdownld.tmp [10/01/2011 - 16:09:44 | D ] D:\OFFICE_2010 [19/03/2011 - 00:41:40 | D ] D:\ProHe6.Slcd1 [21/03/2011 - 01:59:28 | AH | 419430400] D:\ProHe6.Slcd2.part1.rar [21/03/2011 - 02:02:36 | AH | 304746654] D:\ProHe6.Slcd2.part2.rar [21/03/2011 - 02:08:12 | AH | 419430400] D:\ProHe6.Slcd4.part1.rar [21/03/2011 - 02:10:52 | AH | 184033442] D:\ProHe6.Slcd4.part2.rar [17/11/2010 - 17:02:26 | SHD ] D:\System Volume Information [25/03/2011 - 21:23:31 | SHD ] E:\$RECYCLE.BIN [07/04/2011 - 15:57:37 | D ] E:\DO KOMA [20/05/2011 - 15:47:12 | RD ] E:\DOKUMENTY [20/05/2011 - 23:11:18 | RD ] E:\FILMY [25/12/2010 - 01:58:45 | D ] E:\HUMOR [09/02/2011 - 22:09:02 | RD ] E:\MUZYCZKA [06/02/2011 - 03:44:19 | A | 50863] E:\Nowy.ncd [08/04/2011 - 00:45:59 | RD ] E:\POBIERANE [14/04/2011 - 11:37:17 | D ] E:\poradnik [07/04/2011 - 15:40:29 | RD ] E:\PREZENTACJE [21/05/2011 - 01:33:06 | D ] E:\programosy [21/05/2011 - 01:19:09 | RD ] E:\PWSZ [17/11/2010 - 17:02:27 | SHD ] E:\System Volume Information [04/04/2011 - 16:45:05 | RD ] E:\ZDJĘCIA [25/03/2011 - 01:02:21 | RA | 24564] G:\ChainInstall.xml [25/03/2011 - 01:00:12 | RA | 7247] G:\ChainInstall.xml.cat [20/04/2011 - 18:51:34 | RAD ] G:\Crack [29/03/2011 - 10:09:25 | RAD ] G:\EULA [02/03/2011 - 22:58:30 | RA | 183] G:\GFWL_Installer_Autorun.bat [25/03/2011 - 01:34:10 | RA | 4136960] G:\Game.msi [29/03/2011 - 10:11:29 | RAD ] G:\Manuals [25/03/2011 - 00:52:00 | RA | 1994332555] G:\Media1.cab [25/03/2011 - 00:52:14 | RA | 1908090967] G:\Media2.cab [25/03/2011 - 00:46:41 | RA | 531254356] G:\Media3.cab [29/03/2011 - 10:09:25 | RAD ] G:\Readme [29/03/2011 - 10:09:15 | RAD ] G:\Redist [02/03/2011 - 22:58:50 | RA | 440704] G:\Setup.exe [29/03/2011 - 10:09:11 | RAD ] G:\SetupMedia [25/03/2011 - 00:45:38 | RA | 437782] G:\autorun.ico [11/02/2010 - 05:05:02 | RA | 47] G:\autorun.inf [12/03/2010 - 12:37:14 | RA | 187544] G:\xliveinstall.dll [19/04/2011 - 01:03:58 | A | 741148672] H:\psig-white.material.2009.pl.dvdrip.xvid.avi [12/05/2011 - 17:53:42 | A | 41] H:\pmp_usb.ini [01/05/2011 - 15:32:46 | D ] H:\Dom Zły (2009) PL.480p [01/05/2011 - 15:37:56 | D ] H:\Kumple na Zabój - The Matador (2005) [01/05/2011 - 15:46:14 | D ] H:\Pułapka - Hard Candy (2005) PL [12/05/2011 - 17:54:06 | D ] H:\oglądane [11/05/2011 - 20:16:36 | D ] H:\Czarny Łabędź - Black Swan 2010 PL [11/05/2011 - 20:18:00 | D ] H:\Miłość i inne używki - Love and Other Drugs (2010) PL [12/05/2011 - 18:41:04 | SHD ] H:\$RECYCLE.BIN [12/05/2011 - 19:04:28 | A | 52] H:\winamp_metadata.idx [12/05/2011 - 19:04:28 | A | 423] H:\winamp_metadata.dat [12/05/2011 - 19:16:30 | D ] H:\Bez Reguł [21/05/2011 - 23:14:32 | SHD ] J:\$RECYCLE.BIN [17/05/2011 - 20:27:42 | D ] J:\aaa [21/05/2011 - 23:13:58 | SHD ] J:\System Volume Information [22/04/2011 - 23:03:04 | SHD ] K:\$RECYCLE.BIN [24/04/2011 - 00:17:27 | D ] K:\GIERKI_ISO ################## | E.O.F | Odnośnik do komentarza
Landuss Opublikowano 21 Maja 2011 Zgłoś Udostępnij Opublikowano 21 Maja 2011 Jest w porządku. Wykonaj w takim razie kroki końcowe. 1. Użyj opcji Sprzątanie z OTL. 2. Wykonaj obowiązkową instalację SP1+IE9 dla Windows oraz aktualizację Java: KLIK. 3. Wyzeruj stan przywracania systemu: KLIK Odnośnik do komentarza
przytom Opublikowano 22 Maja 2011 Autor Zgłoś Udostępnij Opublikowano 22 Maja 2011 Dziękuję bardzo za pomoc Odnośnik do komentarza
Rekomendowane odpowiedzi