[code] OTS logfile created on: 2009-09-02 14:14:41 - Run 1 OTS by OldTimer - Version 3.0.10.3 Folder = C:\Documents and Settings\Bobcok\Pulpit Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 959,48 Mb Total Physical Memory | 527,23 Mb Available Physical Memory | 54,95% Memory free 2,85 Gb Paging File | 2,46 Gb Available in Paging File | 86,20% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 29,29 Gb Total Space | 10,32 Gb Free Space | 35,24% Space Free | Partition Type: NTFS Drive D: | 59,57 Gb Total Space | 3,31 Gb Free Space | 5,56% Space Free | Partition Type: NTFS Drive E: | 60,18 Gb Total Space | 3,49 Gb Free Space | 5,81% Space Free | Partition Type: NTFS F: Drive not present or media not loaded Drive G: | 29,88 Gb Total Space | 1,80 Gb Free Space | 6,03% Space Free | Partition Type: NTFS H: Drive not present or media not loaded Drive I: | 46,44 Gb Total Space | 4,55 Gb Free Space | 9,79% Space Free | Partition Type: NTFS Computer Name: BOBCOK_GORA Current User Name: Bobcok Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days [Processes - Safe List] acrord32.exe -> C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\AcroRd32.exe -> [2004-07-06 12:10:34 | 07,684,158 | ---- | M] (Adobe Systems Incorporated) braviax.exe -> C:\WINDOWS\System32\braviax.exe -> [2009-09-02 13:16:52 | 00,011,264 | ---- | M] () dtvschdl.exe -> C:\Program Files\WinFast\WFDTV\DTVSchdl.exe -> [2007-11-16 17:13:00 | 00,090,112 | ---- | M] (Leadtek Research Inc.) egui.exe -> C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe -> [2009-03-19 11:44:28 | 02,029,640 | ---- | M] (ESET) ekrn.exe -> C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -> [2009-03-19 11:44:50 | 00,731,840 | ---- | M] (ESET) explorer.exe -> C:\WINDOWS\Explorer.EXE -> [2007-10-17 21:30:07 | 00,974,848 | ---- | M] (Microsoft Corporation) groovemonitor.exe -> C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe -> [2006-10-27 01:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) jqs.exe -> C:\Program Files\Java\jre6\bin\jqs.exe -> [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) jusched.exe -> C:\Program Files\Java\jre6\bin\jusched.exe -> [2009-07-25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) mdnsresponder.exe -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2006-02-28 13:42:38 | 00,229,376 | ---- | M] (Apple Computer, Inc.) ots.exe -> C:\Documents and Settings\Bobcok\Pulpit\OTS.exe -> [2009-09-02 14:06:23 | 00,514,048 | ---- | M] (OldTimer Tools) soundman.exe -> C:\WINDOWS\SOUNDMAN.EXE -> [2007-10-17 20:20:32 | 00,577,536 | ---- | M] (Realtek Semiconductor Corp.) sys32_nov.exe -> C:\Documents and Settings\Bobcok\sys32_nov.exe -> [2009-09-01 20:18:53 | 00,029,216 | ---- | M] () sys32_nov.exe -> C:\Documents and Settings\Bobcok\sys32_nov.exe -> [2009-09-01 20:18:53 | 00,029,216 | ---- | M] () sys32_nov.exe -> C:\WINDOWS\System32\sys32_nov.exe -> [2009-09-01 20:18:52 | 00,029,216 | ---- | M] () ulcdrsvr.exe -> C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -> [2005-01-31 10:45:20 | 00,049,152 | ---- | M] (Ulead Systems, Inc.) vcddaemon.exe -> C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe -> [2006-04-29 15:21:28 | 00,094,208 | ---- | M] (Elaborate Bytes AG) wfwiz.exe -> C:\Program Files\WinFast\WFDTV\WFWIZ.exe -> [2007-11-15 16:55:12 | 02,850,816 | ---- | M] (Leadtek Research Inc.) wisptis.exe -> C:\WINDOWS\System32\WISPTIS.EXE -> [2006-10-26 14:45:04 | 00,293,376 | ---- | M] (Microsoft Corporation) [Win32 Services - Safe List] (aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2005-09-23 08:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) (Bonjour Service) ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## [Win32_Own | Auto | Running] -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2006-02-28 13:42:38 | 00,229,376 | ---- | M] (Apple Computer, Inc.) (clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2005-09-23 08:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) (EhttpSrv) ESET HTTP Server [Win32_Own | On_Demand | Stopped] -> C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -> [2009-03-19 11:48:08 | 00,020,680 | ---- | M] (ESET) (ekrn) ESET Service [Win32_Own | Auto | Running] -> C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -> [2009-03-19 11:44:50 | 00,731,840 | ---- | M] (ESET) (FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2009-02-06 01:01:24 | 00,654,848 | ---- | M] (Macrovision Europe Ltd.) (helpsvc) Pomoc i obsługa techniczna [Win32_Shared | Auto | Running] -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2004-08-04 04:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) (Irmon) Monitor podczerwieni [Win32_Shared | Auto | Running] -> C:\WINDOWS\System32\irmon.dll -> [2004-08-04 02:44:02 | 00,027,648 | ---- | M] (Microsoft Corporation) (JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> C:\Program Files\Java\jre6\bin\jqs.exe -> [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) (Microsoft Office Groove Audit Service) Microsoft Office Groove Audit Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -> [2006-10-27 01:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) (npggsvc) nProtect GameGuard Service [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\System32\GameMon.des -> [2009-02-17 02:39:00 | 02,736,890 | ---- | M] (INCA Internet Co., Ltd.) (NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Stopped] -> C:\WINDOWS\System32\nvsvc32.exe -> [2006-10-22 13:22:00 | 00,159,810 | ---- | M] (NVIDIA Corporation) (odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2006-10-26 20:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) (ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -> [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) (UleadBurningHelper) Ulead Burning Helper [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -> [2005-01-31 10:45:20 | 00,049,152 | ---- | M] (Ulead Systems, Inc.) (WMPNetworkSvc) Usługa udostępniania w sieci programu Windows Media Player [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Windows Media Player\WMPNetwk.exe -> [2006-12-01 12:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) [Driver Services - Safe List] (ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\ALCXWDM.SYS -> [2007-10-17 20:20:02 | 04,108,992 | ---- | M] (Realtek Semiconductor Corp.) (cmuda3) C-Media PCI Audio Interface [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\cmudax3.sys -> [2008-12-03 14:32:06 | 01,519,424 | ---- | M] (C-Media Inc) (CX23880) WinFast CX2388x WDM Video Capture. [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\cx88vid.sys -> [2006-10-18 12:37:26 | 00,162,944 | ---- | M] (Leadtek Research Inc.) (CXAVXBAR) WinFast CX2388x WDM Crossbar. [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\cxavxbar.sys -> [2006-10-18 12:38:38 | 00,009,728 | ---- | M] (Leadtek Research Inc.) (CXTUNE) WinFast CX2388x WDM TVTuner. [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\CX88TUNE.sys -> [2006-10-18 12:37:56 | 00,050,816 | ---- | M] (Leadtek Research Inc.) (eamon) eamon [File_System | Auto | Running] -> C:\WINDOWS\System32\DRIVERS\eamon.sys -> [2009-03-19 11:41:38 | 00,113,960 | ---- | M] (ESET) (ehdrv) ehdrv [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\ehdrv.sys -> [2009-03-19 11:44:34 | 00,107,256 | ---- | M] (ESET) (ElbyCDFL) ElbyCDFL [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\ElbyCDFL.sys -> [2004-08-31 20:07:08 | 00,026,240 | ---- | M] (SlySoft, Inc.) (ElbyCDIO) ElbyCDIO Driver [Kernel | Auto | Running] -> C:\WINDOWS\System32\Drivers\ElbyCDIO.sys -> [2007-08-07 21:48:33 | 00,025,160 | ---- | M] (Elaborate Bytes AG) (ElbyDelay) ElbyDelay [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\ElbyDelay.sys -> [2007-02-16 02:56:49 | 00,011,984 | ---- | M] (Elaborate Bytes AG) (epfwtdir) epfwtdir [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\epfwtdir.sys -> [2009-03-19 11:45:38 | 00,093,848 | ---- | M] (ESET) (gameenum) Licznik portów gier [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\gameenum.sys -> [2004-08-03 23:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) (irsir) Sterownik portu szeregowego podczerwieni Microsoft [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\irsir.sys -> [2001-08-17 23:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation) (nm) Sterownik monitora sieci [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\NMnt.sys -> [2004-08-04 02:59:52 | 00,040,320 | ---- | M] (Microsoft Corporation) (NPPTNT2) NPPTNT2 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\npptNT2.sys -> [2005-01-03 08:43:08 | 00,004,682 | ---- | M] (INCA Internet Co., Ltd.) (nv) nv [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -> [2006-10-22 13:22:00 | 03,994,624 | ---- | M] (NVIDIA Corporation) (nvatabus) nvatabus [Kernel | Boot | Running] -> C:\WINDOWS\System32\drivers\nvatabus.sys -> [2007-10-17 20:23:27 | 00,105,344 | ---- | M] (NVIDIA Corporation) (NVENETFD) NVIDIA nForce Networking Controller Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\NVENETFD.sys -> [2007-10-17 20:22:31 | 00,034,176 | ---- | M] (NVIDIA Corporation) (nvnetbus) NVIDIA Network Bus Enumerator [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\nvnetbus.sys -> [2007-10-17 20:22:31 | 00,013,056 | ---- | M] (NVIDIA Corporation) (Ptilink) Sterownik bezpośredniego połączenia kablowego [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ptilink.sys -> [2001-08-18 03:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> C:\WINDOWS\System32\Drivers\PxHelp20.sys -> [2007-03-08 01:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\secdrv.sys -> [2004-07-17 15:36:38 | 00,027,440 | ---- | M] () (V0260VID) Live! Cam Vista IM [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\V0260Vid.sys -> [2006-04-01 17:16:44 | 00,162,176 | R--- | M] (Creative Technology Ltd.) (VClone) VClone [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\VClone.sys -> [2008-05-30 15:22:36 | 00,025,344 | ---- | M] (Elaborate Bytes AG) (WFIOCTL) WFIOCTL [Kernel | On_Demand | Running] -> C:\Program Files\WinFast\WFDTV\WFIOCTL.SYS -> [2005-01-06 17:55:38 | 00,009,446 | ---- | M] (Leadtek Research Inc.) [Registry - Safe List] < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://www.google.com/ie -> HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> [binary data] -> HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://www.google.com -> HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.google.com -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: Main\\"Start Page" -> about:blank -> HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: Main\\"Start Page" -> about:blank -> HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> HKEY_USERS\S-1-5-19\: Main\\"Start Page" -> about:blank -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> HKEY_USERS\S-1-5-20\: Main\\"Start Page" -> about:blank -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\] > -> -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\: Main\\"Search Page" -> http://www.google.com -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\: Main\\"Start Page" -> http://www.google.com -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\: "ProxyEnable" -> 0 -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\: "ProxyOverride" -> *.local -> < FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla HKLM\software\mozilla\Firefox\extensions -> -> HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com -> C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2009-03-16 23:59:40 | 00,000,000 | ---D | M] HKLM\software\mozilla\Thunderbird\Extensions -> -> HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com -> C:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\MOZILLA THUNDERBIRD -> < FireFox Extensions [User Folders] > -> < HOSTS File > (742 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> Reset Hosts 127.0.0.1 localhost < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "braviax" -> [] -> File not found "CloneCDTray" -> C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe ["C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s] -> [2004-09-02 23:57:25 | 00,057,344 | ---- | M] (SlySoft, Inc.) "CmPCIaudio" -> [RunDll32 CMICNFG3.cpl,CMICtrlWnd] -> File not found "egui" -> C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe ["C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice] -> [2009-03-19 11:44:28 | 02,029,640 | ---- | M] (ESET) "GrooveMonitor" -> C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe ["C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"] -> [2006-10-27 01:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) "KernelFaultCheck" -> [%systemroot%\system32\dumprep 0 -k] -> File not found "NeroFilterCheck" -> C:\WINDOWS\System32\NeroCheck.exe [C:\WINDOWS\system32\NeroCheck.exe] -> [2001-07-09 11:50:42 | 00,155,648 | ---- | M] (Ahead Software Gmbh) "NvCplDaemon" -> C:\WINDOWS\System32\NvCpl.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2006-10-22 13:22:00 | 07,700,480 | ---- | M] (NVIDIA Corporation) "NvMediaCenter" -> C:\WINDOWS\System32\NvMcTray.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2006-10-22 13:22:00 | 00,086,016 | ---- | M] (NVIDIA Corporation) "nwiz" -> C:\WINDOWS\System32\nwiz.exe [nwiz.exe /install] -> [2006-10-22 13:22:00 | 01,622,016 | ---- | M] () "Onet.pl AutoUpdate" -> C:\Program Files\Common Files\Onet.pl\NewAutoUpdate.exe ["C:\Program Files\Common Files\Onet.pl\NewAutoUpdate.exe" /updateexetsr] -> File not found "PC Antispyware 2010" -> C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe ["C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe" /hide] -> [2009-09-01 21:20:56 | 00,598,599 | ---- | M] () "QuickTime Task" -> C:\Program Files\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2009-02-06 00:14:06 | 00,098,304 | ---- | M] (Apple Computer, Inc.) "Regedit32" -> C:\WINDOWS\System32\regedit.exe [C:\WINDOWS\system32\regedit.exe] -> File not found "SoundMan" -> C:\WINDOWS\SOUNDMAN.EXE [SOUNDMAN.EXE] -> [2007-10-17 20:20:32 | 00,577,536 | ---- | M] (Realtek Semiconductor Corp.) "SunJavaUpdateSched" -> C:\Program Files\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2009-07-25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) "sys32_nov" -> C:\WINDOWS\System32\sys32_nov.exe [C:\WINDOWS\system32\sys32_nov.exe] -> [2009-09-01 20:18:52 | 00,029,216 | ---- | M] () "VirtualCloneDrive" -> C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe ["C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s] -> [2006-04-29 15:21:28 | 00,094,208 | ---- | M] (Elaborate Bytes AG) "WinFast Schedule" -> C:\Program Files\WinFast\WFDTV\WFWIZ.exe [C:\Program Files\WinFast\WFDTV\WFWIZ.exe] -> [2007-11-15 16:55:12 | 02,850,816 | ---- | M] (Leadtek Research Inc.) "WinFastDTV" -> C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [C:\Program Files\WinFast\WFDTV\DTVSchdl.exe] -> [2007-11-16 17:13:00 | 00,090,112 | ---- | M] (Leadtek Research Inc.) < RunOnce [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "nltide_2" -> [regsvr32 /s /n /i:U shell32] -> File not found "nltide_3" -> C:\WINDOWS\System32\advpack.dll [rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N] -> [2007-10-09 02:01:30 | 00,124,928 | ---- | M] (Microsoft Corporation) < RunOnce [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "nltide_2" -> [regsvr32 /s /n /i:U shell32] -> File not found "nltide_3" -> C:\WINDOWS\System32\advpack.dll [rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N] -> [2007-10-09 02:01:30 | 00,124,928 | ---- | M] (Microsoft Corporation) < RunOnce [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "nltide_2" -> [regsvr32 /s /n /i:U shell32] -> File not found "nltide_3" -> C:\WINDOWS\System32\advpack.dll [rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N] -> [2007-10-09 02:01:30 | 00,124,928 | ---- | M] (Microsoft Corporation) < RunOnce [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> "nltide_2" -> [regsvr32 /s /n /i:U shell32] -> File not found "nltide_3" -> C:\WINDOWS\System32\advpack.dll [rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N] -> [2007-10-09 02:01:30 | 00,124,928 | ---- | M] (Microsoft Corporation) < Run [HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\] > -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> "braviax" -> [] -> File not found "Nowe Gadu-Gadu" -> C:\Program Files\Nowe Gadu-Gadu\gg.exe ["C:\Program Files\Nowe Gadu-Gadu\gg.exe"] -> [2009-07-27 17:42:10 | 10,719,848 | ---- | M] (GG Network S.A.) "sys32_nov" -> C:\Documents and Settings\Bobcok\sys32_nov.exe [C:\Documents and Settings\Bobcok\sys32_nov.exe] -> [2009-09-01 20:18:53 | 00,029,216 | ---- | M] () "uTorrent" -> C:\Program Files\uTorrent\uTorrent.exe ["C:\Program Files\uTorrent\uTorrent.exe"] -> [2009-07-19 12:35:17 | 00,288,048 | ---- | M] (BitTorrent, Inc.) < All Users Startup Folder > -> C:\Documents and Settings\All Users\Menu Start\Programy\Autostart -> < Bobcok Startup Folder > -> C:\Documents and Settings\Bobcok\Menu Start\Programy\Autostart -> -> C:\Documents and Settings\Bobcok\Menu Start\Programy\Autostart\ikowin32.exe -> [2004-08-04 04:44:28 | 00,026,624 | R-S- | M] () < Default User Startup Folder > -> C:\Documents and Settings\Default User\Menu Start\Programy\Autostart -> < CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [177] -> File not found < CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System \\"dontdisplaylastusername" -> [0] -> File not found \\"legalnoticecaption" -> [] -> File not found \\"legalnoticetext" -> [] -> File not found \\"shutdownwithoutlogon" -> [1] -> File not found \\"undockwithoutlogon" -> [1] -> File not found \\"NoInternetOpenWith" -> [1] -> File not found \\"DisableStatusMessages" -> [1] -> File not found \\"VerboseStatus" -> [0] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [255] -> File not found \\"NoSMMyPictures" -> [1] -> File not found \\"NoSMConfigurePrograms" -> [1] -> File not found \\"ClearRecentDocsOnExit" -> [1] -> File not found \\"NoRecentDocsMenu" -> [1] -> File not found \\"NoRecentDocsHistory" -> [1] -> File not found \\"NoStartBanner" -> [1] -> File not found \\"NoLowDiskSpaceChecks" -> [1] -> File not found \\"NoSMHelp" -> [1] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [255] -> File not found \\"NoSMMyPictures" -> [1] -> File not found \\"NoSMConfigurePrograms" -> [1] -> File not found \\"ClearRecentDocsOnExit" -> [1] -> File not found \\"NoRecentDocsMenu" -> [1] -> File not found \\"NoRecentDocsHistory" -> [1] -> File not found \\"NoStartBanner" -> [1] -> File not found \\"NoLowDiskSpaceChecks" -> [1] -> File not found \\"NoSMHelp" -> [1] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [255] -> File not found \\"NoSMMyPictures" -> [1] -> File not found \\"NoSMConfigurePrograms" -> [1] -> File not found \\"ClearRecentDocsOnExit" -> [1] -> File not found \\"NoRecentDocsMenu" -> [1] -> File not found \\"NoRecentDocsHistory" -> [1] -> File not found \\"NoStartBanner" -> [1] -> File not found \\"NoLowDiskSpaceChecks" -> [1] -> File not found \\"NoSMHelp" -> [1] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [255] -> File not found \\"NoSMMyPictures" -> [1] -> File not found \\"NoSMConfigurePrograms" -> [1] -> File not found \\"ClearRecentDocsOnExit" -> [1] -> File not found \\"NoRecentDocsMenu" -> [1] -> File not found \\"NoRecentDocsHistory" -> [1] -> File not found \\"NoStartBanner" -> [1] -> File not found \\"NoLowDiskSpaceChecks" -> [1] -> File not found \\"NoSMHelp" -> [1] -> File not found < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003] > -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer \\"NoDriveTypeAutoRun" -> [255] -> File not found \\"NoSMMyPictures" -> [1] -> File not found \\"NoSMConfigurePrograms" -> [1] -> File not found \\"ClearRecentDocsOnExit" -> [1] -> File not found \\"NoRecentDocsMenu" -> [1] -> File not found \\"NoRecentDocsHistory" -> [1] -> File not found \\"NoStartBanner" -> [1] -> File not found \\"NoLowDiskSpaceChecks" -> [1] -> File not found \\"NoSMHelp" -> [1] -> File not found \\"ForceClassicControlPanel" -> [1] -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\] > -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\Software\Microsoft\Internet Explorer\MenuExt\ -> E&ksportuj do programu Microsoft Excel -> C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000] -> [2006-10-27 16:07:36 | 17,891,112 | ---- | M] (Microsoft Corporation) < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2006-10-26 21:12:22 | 00,040,424 | ---- | M] (Microsoft Corporation) {e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2007-10-09 01:58:14 | 00,557,568 | ---- | M] (Microsoft Corporation) < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix "" -> http:// < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\] > -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\] > -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {33564D57-0000-0010-8000-00AA00389B71} [HKLM] -> http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB [Reg Error: Key error.] -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab [Java Plug-in 1.6.0_15] -> {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab [Java Plug-in 1.6.0_15] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab [Java Plug-in 1.6.0_15] -> {D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] -> < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> DhcpNameServer -> 217.8.168.244 157.25.5.18 192.168.1.1 -> < Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {74B7D77E-F466-42AF-B01F-576EAD9807FB}\\DhcpNameServer -> 217.8.168.244 157.25.5.18 192.168.1.1 (NVIDIA nForce Networking Controller) -> < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> cru629.dat -> -> File not found FILES\COM -> -> File not found *MultiFile Done* -> -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> Explorer.exe -> C:\WINDOWS\explorer.exe -> [2007-10-17 21:30:07 | 00,974,848 | ---- | M] (Microsoft Corporation) *MultiFile Done* -> -> < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" [HKLM] -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [Groove GFS Stub Execution Hook] -> [2006-10-27 01:48:42 | 02,210,608 | ---- | M] (Microsoft Corporation) < Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2007-10-09 01:58:14 | 00,557,568 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004-08-04 04:44:28 | 00,141,824 | ---- | M] (Microsoft Corporation) < Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> "%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2007-10-09 01:58:14 | 00,557,568 | ---- | M] (Microsoft Corporation) "%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004-08-04 04:44:28 | 00,141,824 | ---- | M] (Microsoft Corporation) "C:\ijji\ENGLISH\u_skid.exe" -> C:\ijji\ENGLISH\u_skid.exe [C:\ijji\ENGLISH\u_skid.exe:*:Enabled:] -> File not found "C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2006-02-28 13:42:38 | 00,229,376 | ---- | M] (Apple Computer, Inc.) "C:\Program Files\DriftCity\DriftCity.exe" -> C:\Program Files\DriftCity\DriftCity.exe [C:\Program Files\DriftCity\DriftCity.exe:*:Enabled:DriftCity] -> File not found "C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe" -> C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe [C:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe:*:Enabled:Java(TM) Platform SE binary] -> [2009-03-09 05:19:13 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) "C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" -> C:\Program Files\Microsoft Office\Office12\GROOVE.EXE [C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove] -> [2006-10-27 16:37:44 | 00,338,216 | ---- | M] (Microsoft Corporation) "C:\Program Files\Nowe Gadu-Gadu\gg.exe" -> C:\Program Files\Nowe Gadu-Gadu\gg.exe [C:\Program Files\Nowe Gadu-Gadu\gg.exe:*:Enabled:Nowe Gadu-Gadu beta] -> [2009-07-27 17:42:10 | 10,719,848 | ---- | M] (GG Network S.A.) "C:\Program Files\Raptr\Raptr.exe" -> C:\Program Files\Raptr\Raptr.exe [C:\Program Files\Raptr\Raptr.exe:*:Enabled:Raptr Client] -> File not found "C:\Program Files\Skype\Phone\Skype.exe" -> C:\Program Files\Skype\Phone\Skype.exe [C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype] -> [2008-02-06 19:24:10 | 21,898,024 | R--- | M] (Skype Technologies S.A.) "C:\Program Files\uTorrent\uTorrent.exe" -> C:\Program Files\uTorrent\uTorrent.exe [C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent] -> [2009-07-19 12:35:17 | 00,288,048 | ---- | M] (BitTorrent, Inc.) < SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> "AlternateShell" -> cmd.exe -> < CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom -> "AutoRun" -> 1 -> "DisplayName" -> Sterownik stacji dysków CD-ROM -> "ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found < Drives with AutoRun files > -> -> C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2009-02-05 23:51:35 | 00,000,000 | ---- | M] () G:\AUTOEXEC.BAT [] -> G:\AUTOEXEC.BAT [ NTFS ] -> [2008-01-13 16:53:38 | 00,000,000 | ---- | M] () < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> [Registry - Additional Scans - Safe List] < EventViewer Logs - Last 10 Errors > -> Event Information -> Description Application [ Error ] 2009-09-01 15:09:35 Computer Name = BOBCOK_GORA | Source = SecurityCenter | ID = 1802 -> Description = Usługa Centrum zabezpieczeń systemu Windows nie może ustanowić kwerend zdarzeń z WMI, aby monitorować zaporę i program antywirusowy innej firmy. Application [ Error ] 2009-09-01 15:09:39 Computer Name = BOBCOK_GORA | Source = Userenv | ID = 1090 -> Description = System Windows nie może zarejestrować stanu sesji RSoP (Resultant Set of Policies - wynikowego zestawu zasad). Próba połączenia z WMI nie powiodła się. Dlatego żadne następne rejestrowanie zasad RSoP dla tej aplikacji nie zostanie wykonane. Application [ Error ] 2009-09-01 15:09:39 Computer Name = BOBCOK_GORA | Source = Userenv | ID = 1090 -> Description = System Windows nie może zarejestrować stanu sesji RSoP (Resultant Set of Policies - wynikowego zestawu zasad). Próba połączenia z WMI nie powiodła się. Dlatego żadne następne rejestrowanie zasad RSoP dla tej aplikacji nie zostanie wykonane. Application [ Error ] 2009-09-01 16:45:39 Computer Name = BOBCOK_GORA | Source = Userenv | ID = 1090 -> Description = System Windows nie może zarejestrować stanu sesji RSoP (Resultant Set of Policies - wynikowego zestawu zasad). Próba połączenia z WMI nie powiodła się. Dlatego żadne następne rejestrowanie zasad RSoP dla tej aplikacji nie zostanie wykonane. Application [ Error ] 2009-09-01 16:49:39 Computer Name = BOBCOK_GORA | Source = Userenv | ID = 1090 -> Description = System Windows nie może zarejestrować stanu sesji RSoP (Resultant Set of Policies - wynikowego zestawu zasad). Próba połączenia z WMI nie powiodła się. Dlatego żadne następne rejestrowanie zasad RSoP dla tej aplikacji nie zostanie wykonane. Application [ Error ] 2009-09-01 18:30:40 Computer Name = BOBCOK_GORA | Source = Userenv | ID = 1090 -> Description = System Windows nie może zarejestrować stanu sesji RSoP (Resultant Set of Policies - wynikowego zestawu zasad). Próba połączenia z WMI nie powiodła się. Dlatego żadne następne rejestrowanie zasad RSoP dla tej aplikacji nie zostanie wykonane. Application [ Error ] 2009-09-01 18:30:40 Computer Name = BOBCOK_GORA | Source = Userenv | ID = 1090 -> Description = System Windows nie może zarejestrować stanu sesji RSoP (Resultant Set of Policies - wynikowego zestawu zasad). Próba połączenia z WMI nie powiodła się. Dlatego żadne następne rejestrowanie zasad RSoP dla tej aplikacji nie zostanie wykonane. Application [ Error ] 2009-09-02 07:17:03 Computer Name = BOBCOK_GORA | Source = SecurityCenter | ID = 1802 -> Description = Usługa Centrum zabezpieczeń systemu Windows nie może ustanowić kwerend zdarzeń z WMI, aby monitorować zaporę i program antywirusowy innej firmy. Application [ Error ] 2009-09-02 07:17:05 Computer Name = BOBCOK_GORA | Source = Userenv | ID = 1090 -> Description = System Windows nie może zarejestrować stanu sesji RSoP (Resultant Set of Policies - wynikowego zestawu zasad). Próba połączenia z WMI nie powiodła się. Dlatego żadne następne rejestrowanie zasad RSoP dla tej aplikacji nie zostanie wykonane. Application [ Error ] 2009-09-02 07:17:05 Computer Name = BOBCOK_GORA | Source = Userenv | ID = 1090 -> Description = System Windows nie może zarejestrować stanu sesji RSoP (Resultant Set of Policies - wynikowego zestawu zasad). Próba połączenia z WMI nie powiodła się. Dlatego żadne następne rejestrowanie zasad RSoP dla tej aplikacji nie zostanie wykonane. System [ Error ] 2009-09-01 14:32:20 Computer Name = BOBCOK_GORA | Source = Service Control Manager | ID = 7000 -> Description = Nie można uruchomić usługi BuddyVM z powodu następującego błędu: %%3 System [ Error ] 2009-09-01 14:37:07 Computer Name = BOBCOK_GORA | Source = Service Control Manager | ID = 7034 -> Description = Usługa ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. System [ Error ] 2009-09-01 14:37:58 Computer Name = BOBCOK_GORA | Source = Service Control Manager | ID = 7034 -> Description = Usługa NVIDIA Display Driver Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. System [ Error ] 2009-09-01 14:38:13 Computer Name = BOBCOK_GORA | Source = Service Control Manager | ID = 7034 -> Description = Usługa Java Quick Starter niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. System [ Error ] 2009-09-01 14:40:08 Computer Name = BOBCOK_GORA | Source = Service Control Manager | ID = 7034 -> Description = Usługa Ulead Burning Helper niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. System [ Error ] 2009-09-01 14:44:49 Computer Name = BOBCOK_GORA | Source = Service Control Manager | ID = 7000 -> Description = Nie można uruchomić usługi BuddyVM z powodu następującego błędu: %%3 System [ Error ] 2009-09-01 15:10:52 Computer Name = BOBCOK_GORA | Source = Service Control Manager | ID = 7000 -> Description = Nie można uruchomić usługi BuddyVM z powodu następującego błędu: %%3 System [ Error ] 2009-09-01 15:10:52 Computer Name = BOBCOK_GORA | Source = Service Control Manager | ID = 7026 -> Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: Beep System [ Error ] 2009-09-02 07:18:15 Computer Name = BOBCOK_GORA | Source = Service Control Manager | ID = 7000 -> Description = Nie można uruchomić usługi BuddyVM z powodu następującego błędu: %%3 System [ Error ] 2009-09-02 07:18:15 Computer Name = BOBCOK_GORA | Source = Service Control Manager | ID = 7034 -> Description = Usługa NVIDIA Display Driver Service niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. [Files/Folders - Created Within 30 Days] OTS.exe -> C:\Documents and Settings\Bobcok\Pulpit\OTS.exe -> [2009-09-02 14:06:15 | 00,514,048 | ---- | C] (OldTimer Tools) wahyzuvi.dl -> C:\Documents and Settings\Bobcok\Dane aplikacji\wahyzuvi.dl -> [2009-09-02 13:22:45 | 00,019,444 | ---- | C] () rotiquzyl.scr -> C:\Program Files\Common Files\rotiquzyl.scr -> [2009-09-02 13:22:45 | 00,019,221 | ---- | C] () ymek.vbs -> C:\Documents and Settings\All Users\Dane aplikacji\ymek.vbs -> [2009-09-02 13:22:45 | 00,018,919 | ---- | C] () subeboq.lib -> C:\WINDOWS\System32\subeboq.lib -> [2009-09-02 13:22:45 | 00,018,324 | ---- | C] () elydinev.bat -> C:\WINDOWS\elydinev.bat -> [2009-09-02 13:22:45 | 00,017,741 | ---- | C] () irytuwesew.db -> C:\WINDOWS\irytuwesew.db -> [2009-09-02 13:22:45 | 00,017,197 | ---- | C] () daxogi.lib -> C:\Documents and Settings\All Users\Dokumenty\daxogi.lib -> [2009-09-02 13:22:45 | 00,017,140 | ---- | C] () vusy.ban -> C:\Documents and Settings\All Users\Dokumenty\vusy.ban -> [2009-09-02 13:22:45 | 00,016,711 | ---- | C] () omoraqyqev.bin -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\omoraqyqev.bin -> [2009-09-02 13:22:45 | 00,016,665 | ---- | C] () ojum.dll -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\ojum.dll -> [2009-09-02 13:22:45 | 00,016,282 | ---- | C] () kemufot.pif -> C:\Program Files\Common Files\kemufot.pif -> [2009-09-02 13:22:45 | 00,015,988 | ---- | C] () ykudimiqe.exe -> C:\Documents and Settings\All Users\Dane aplikacji\ykudimiqe.exe -> [2009-09-02 13:22:45 | 00,015,898 | ---- | C] () adah.lib -> C:\WINDOWS\System32\adah.lib -> [2009-09-02 13:22:45 | 00,015,039 | ---- | C] () linunise.vbs -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\linunise.vbs -> [2009-09-02 13:22:45 | 00,014,836 | ---- | C] () waku.dat -> C:\WINDOWS\waku.dat -> [2009-09-02 13:22:45 | 00,014,588 | ---- | C] () oboqe.dl -> C:\Documents and Settings\All Users\Dane aplikacji\oboqe.dl -> [2009-09-02 13:22:45 | 00,014,584 | ---- | C] () irarajariq.lib -> C:\Program Files\Common Files\irarajariq.lib -> [2009-09-02 13:22:45 | 00,014,561 | ---- | C] () edyzy._sy -> C:\Documents and Settings\Bobcok\Dane aplikacji\edyzy._sy -> [2009-09-02 13:22:45 | 00,013,881 | ---- | C] () sosok.exe -> C:\WINDOWS\sosok.exe -> [2009-09-02 13:22:45 | 00,013,876 | ---- | C] () oficenof.pif -> C:\Program Files\Common Files\oficenof.pif -> [2009-09-02 13:22:45 | 00,013,621 | ---- | C] () nakyjuny.ban -> C:\WINDOWS\nakyjuny.ban -> [2009-09-02 13:22:45 | 00,013,520 | ---- | C] () enemecis.com -> C:\Program Files\Common Files\enemecis.com -> [2009-09-02 13:22:45 | 00,012,550 | ---- | C] () xynoje.exe -> C:\WINDOWS\xynoje.exe -> [2009-09-02 13:22:45 | 00,011,176 | ---- | C] () ytusa.com -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\ytusa.com -> [2009-09-02 13:22:45 | 00,010,677 | ---- | C] () PC_Antispyware2010.lnk -> C:\Documents and Settings\Bobcok\Pulpit\PC_Antispyware2010.lnk -> [2009-09-02 13:22:30 | 00,001,686 | ---- | C] () PC_Antispyware2010 -> C:\Program Files\PC_Antispyware2010 -> [2009-09-02 13:22:25 | 00,000,000 | ---D | C] oashdihasidhasuidhiasdhiashdiuasdhasd -> C:\Documents and Settings\Bobcok\oashdihasidhasuidhiasdhiashdiuasdhasd -> [2009-09-02 13:17:40 | 00,000,001 | ---- | C] () wisdstr.exe -> C:\WINDOWS\System32\wisdstr.exe -> [2009-09-02 13:17:12 | 00,191,159 | ---- | C] () figaro.sys -> C:\WINDOWS\System32\dllcache\figaro.sys -> [2009-09-02 13:16:51 | 00,029,184 | ---- | C] () beep.sys -> C:\WINDOWS\System32\drivers\beep.sys -> [2009-09-02 13:16:51 | 00,029,184 | ---- | C] () beep.sys -> C:\WINDOWS\System32\dllcache\beep.sys -> [2009-09-02 13:16:51 | 00,029,184 | ---- | C] () Recent -> C:\Documents and Settings\Bobcok\Recent -> [2009-09-02 00:51:34 | 00,000,000 | ---D | C] 1.JPG -> C:\Documents and Settings\Bobcok\Pulpit\1.JPG -> [2009-09-01 22:13:02 | 00,059,606 | ---- | C] () FIX.BAT -> C:\Documents and Settings\Bobcok\Pulpit\FIX.BAT -> [2009-09-01 21:56:26 | 00,000,210 | ---- | C] () HijackThis.exe -> C:\Documents and Settings\Bobcok\Pulpit\HijackThis.exe -> [2009-09-01 21:55:13 | 00,401,720 | ---- | C] (Trend Micro Inc.) HiJackThis.zip -> C:\Documents and Settings\Bobcok\Pulpit\HiJackThis.zip -> [2009-09-01 21:54:58 | 00,318,369 | ---- | C] () delself.bat -> C:\Documents and Settings\Bobcok\delself.bat -> [2009-09-01 20:43:26 | 00,000,142 | ---- | C] () braviax.exe -> C:\WINDOWS\braviax.exe -> [2009-09-01 20:30:24 | 00,011,264 | ---- | C] () braviax.exe -> C:\WINDOWS\System32\braviax.exe -> [2009-09-01 20:19:27 | 00,011,264 | ---- | C] () sys32_nov.exe -> C:\WINDOWS\System32\sys32_nov.exe -> [2009-09-01 20:18:52 | 00,029,216 | ---- | C] () sys32_nov.exe -> C:\Documents and Settings\Bobcok\sys32_nov.exe -> [2009-09-01 20:18:52 | 00,029,216 | ---- | C] () Guitar.Hero.5.RF.XBOX360-MARVEL.torrent -> C:\Documents and Settings\Bobcok\Pulpit\Guitar.Hero.5.RF.XBOX360-MARVEL.torrent -> [2009-08-30 18:59:32 | 00,069,091 | ---- | C] () Tiger4207 (Pure TnA).torrent -> C:\Documents and Settings\Bobcok\Pulpit\Tiger4207 (Pure TnA).torrent -> [2009-08-30 13:59:00 | 00,023,754 | ---- | C] () OpenFM -> C:\Documents and Settings\All Users\Dane aplikacji\OpenFM -> [2009-08-17 00:09:59 | 00,000,000 | ---D | C] Ela -> C:\Ela -> [2009-08-12 18:41:01 | 00,000,000 | ---D | C] Garmin -> C:\Garmin -> [2009-08-12 18:37:41 | 00,000,000 | ---D | C] wincmd.ini -> C:\WINDOWS\wincmd.ini -> [2009-06-18 02:49:45 | 00,001,190 | ---- | C] () vidx16.dll -> C:\WINDOWS\System32\vidx16.dll -> [2009-04-24 16:57:56 | 00,010,240 | ---- | C] () Cmicnfg3.ini.cfl -> C:\WINDOWS\Cmicnfg3.ini.cfl -> [2009-04-23 23:35:26 | 00,000,066 | ---- | C] () Cmicnfg3.ini.cfg -> C:\WINDOWS\Cmicnfg3.ini.cfg -> [2009-04-23 23:35:01 | 00,001,480 | ---- | C] () cmudax3.ini -> C:\WINDOWS\cmudax3.ini -> [2009-04-23 23:34:59 | 00,002,532 | ---- | C] () RemoteControl.dll -> C:\WINDOWS\System32\RemoteControl.dll -> [2009-02-20 01:21:08 | 00,175,104 | ---- | C] () NeroDigital.ini -> C:\WINDOWS\NeroDigital.ini -> [2009-02-09 00:20:16 | 00,000,116 | ---- | C] () Dvbpws.dll -> C:\WINDOWS\System32\Dvbpws.dll -> [2009-02-07 18:55:24 | 00,000,002 | ---- | C] () MAZEPC.INI -> C:\WINDOWS\MAZEPC.INI -> [2009-02-07 16:18:57 | 00,000,746 | ---- | C] () unrar.dll -> C:\WINDOWS\System32\unrar.dll -> [2009-02-07 02:09:48 | 00,164,352 | ---- | C] () avisplitter.ini -> C:\WINDOWS\avisplitter.ini -> [2009-02-07 02:09:47 | 00,000,038 | ---- | C] () qt-dx331.dll -> C:\WINDOWS\System32\qt-dx331.dll -> [2009-02-07 02:09:39 | 03,596,288 | ---- | C] () xvidcore.dll -> C:\WINDOWS\System32\xvidcore.dll -> [2009-02-07 02:09:39 | 00,755,027 | ---- | C] () xvidvfw.dll -> C:\WINDOWS\System32\xvidvfw.dll -> [2009-02-07 02:09:39 | 00,159,839 | ---- | C] () ff_vfw.dll -> C:\WINDOWS\System32\ff_vfw.dll -> [2009-02-07 02:09:31 | 00,007,680 | ---- | C] () ff_vfw.dll.manifest -> C:\WINDOWS\System32\ff_vfw.dll.manifest -> [2009-02-07 02:09:31 | 00,000,547 | ---- | C] () ULead32.ini -> C:\WINDOWS\ULead32.ini -> [2009-02-06 01:19:27 | 00,000,330 | ---- | C] () RTLCPAPI.dll -> C:\WINDOWS\System32\RTLCPAPI.dll -> [2007-10-17 20:20:23 | 00,147,456 | ---- | C] () nvwdmcpl.dll -> C:\WINDOWS\System32\nvwdmcpl.dll -> [2006-10-22 13:22:00 | 01,662,976 | ---- | C] () nview.dll -> C:\WINDOWS\System32\nview.dll -> [2006-10-22 13:22:00 | 01,470,464 | ---- | C] () nvwimg.dll -> C:\WINDOWS\System32\nvwimg.dll -> [2006-10-22 13:22:00 | 01,019,904 | ---- | C] () nvhwvid.dll -> C:\WINDOWS\System32\nvhwvid.dll -> [2006-10-22 13:22:00 | 00,581,632 | ---- | C] () nvshell.dll -> C:\WINDOWS\System32\nvshell.dll -> [2006-10-22 13:22:00 | 00,466,944 | ---- | C] () nvnt4cpl.dll -> C:\WINDOWS\System32\nvnt4cpl.dll -> [2006-10-22 13:22:00 | 00,286,720 | ---- | C] () nvapi.dll -> C:\WINDOWS\System32\nvapi.dll -> [2006-10-22 13:22:00 | 00,212,992 | ---- | C] () secdrv.sys -> C:\WINDOWS\System32\drivers\secdrv.sys -> [2004-07-17 15:36:38 | 00,027,440 | ---- | C] () win.ini -> C:\WINDOWS\win.ini -> [2001-07-22 04:16:20 | 00,000,573 | ---- | C] () system.ini -> C:\WINDOWS\system.ini -> [2001-07-22 04:15:52 | 00,000,231 | ---- | C] () [Files/Folders - Modified Within 30 Days] 69 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 264 C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\*.tmp files -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\*.tmp -> 13 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> OTS.exe -> C:\Documents and Settings\Bobcok\Pulpit\OTS.exe -> [2009-09-02 14:06:23 | 00,514,048 | ---- | M] (OldTimer Tools) linunise.vbs -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\linunise.vbs -> [2009-09-02 13:22:46 | 00,014,836 | ---- | M] () wahyzuvi.dl -> C:\Documents and Settings\Bobcok\Dane aplikacji\wahyzuvi.dl -> [2009-09-02 13:22:45 | 00,019,444 | ---- | M] () rotiquzyl.scr -> C:\Program Files\Common Files\rotiquzyl.scr -> [2009-09-02 13:22:45 | 00,019,221 | ---- | M] () ymek.vbs -> C:\Documents and Settings\All Users\Dane aplikacji\ymek.vbs -> [2009-09-02 13:22:45 | 00,018,919 | ---- | M] () subeboq.lib -> C:\WINDOWS\System32\subeboq.lib -> [2009-09-02 13:22:45 | 00,018,324 | ---- | M] () elydinev.bat -> C:\WINDOWS\elydinev.bat -> [2009-09-02 13:22:45 | 00,017,741 | ---- | M] () irytuwesew.db -> C:\WINDOWS\irytuwesew.db -> [2009-09-02 13:22:45 | 00,017,197 | ---- | M] () daxogi.lib -> C:\Documents and Settings\All Users\Dokumenty\daxogi.lib -> [2009-09-02 13:22:45 | 00,017,140 | ---- | M] () vusy.ban -> C:\Documents and Settings\All Users\Dokumenty\vusy.ban -> [2009-09-02 13:22:45 | 00,016,711 | ---- | M] () omoraqyqev.bin -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\omoraqyqev.bin -> [2009-09-02 13:22:45 | 00,016,665 | ---- | M] () ojum.dll -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\ojum.dll -> [2009-09-02 13:22:45 | 00,016,282 | ---- | M] () kemufot.pif -> C:\Program Files\Common Files\kemufot.pif -> [2009-09-02 13:22:45 | 00,015,988 | ---- | M] () ykudimiqe.exe -> C:\Documents and Settings\All Users\Dane aplikacji\ykudimiqe.exe -> [2009-09-02 13:22:45 | 00,015,898 | ---- | M] () adah.lib -> C:\WINDOWS\System32\adah.lib -> [2009-09-02 13:22:45 | 00,015,039 | ---- | M] () waku.dat -> C:\WINDOWS\waku.dat -> [2009-09-02 13:22:45 | 00,014,588 | ---- | M] () oboqe.dl -> C:\Documents and Settings\All Users\Dane aplikacji\oboqe.dl -> [2009-09-02 13:22:45 | 00,014,584 | ---- | M] () irarajariq.lib -> C:\Program Files\Common Files\irarajariq.lib -> [2009-09-02 13:22:45 | 00,014,561 | ---- | M] () edyzy._sy -> C:\Documents and Settings\Bobcok\Dane aplikacji\edyzy._sy -> [2009-09-02 13:22:45 | 00,013,881 | ---- | M] () sosok.exe -> C:\WINDOWS\sosok.exe -> [2009-09-02 13:22:45 | 00,013,876 | ---- | M] () oficenof.pif -> C:\Program Files\Common Files\oficenof.pif -> [2009-09-02 13:22:45 | 00,013,621 | ---- | M] () nakyjuny.ban -> C:\WINDOWS\nakyjuny.ban -> [2009-09-02 13:22:45 | 00,013,520 | ---- | M] () enemecis.com -> C:\Program Files\Common Files\enemecis.com -> [2009-09-02 13:22:45 | 00,012,550 | ---- | M] () xynoje.exe -> C:\WINDOWS\xynoje.exe -> [2009-09-02 13:22:45 | 00,011,176 | ---- | M] () ytusa.com -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\ytusa.com -> [2009-09-02 13:22:45 | 00,010,677 | ---- | M] () PC_Antispyware2010.lnk -> C:\Documents and Settings\Bobcok\Pulpit\PC_Antispyware2010.lnk -> [2009-09-02 13:22:30 | 00,001,686 | ---- | M] () oashdihasidhasuidhiasdhiashdiuasdhasd -> C:\Documents and Settings\Bobcok\oashdihasidhasuidhiasdhiashdiuasdhasd -> [2009-09-02 13:17:40 | 00,000,001 | ---- | M] () wisdstr.exe -> C:\WINDOWS\System32\wisdstr.exe -> [2009-09-02 13:17:16 | 00,191,159 | ---- | M] () figaro.sys -> C:\WINDOWS\System32\dllcache\figaro.sys -> [2009-09-02 13:16:54 | 00,029,184 | ---- | M] () beep.sys -> C:\WINDOWS\System32\drivers\beep.sys -> [2009-09-02 13:16:54 | 00,029,184 | ---- | M] () beep.sys -> C:\WINDOWS\System32\dllcache\beep.sys -> [2009-09-02 13:16:54 | 00,029,184 | ---- | M] () braviax.exe -> C:\WINDOWS\System32\braviax.exe -> [2009-09-02 13:16:52 | 00,011,264 | ---- | M] () Perflib_Perfdata_518.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_518.dat -> [2009-09-02 13:16:49 | 00,016,384 | ---- | M] () nvapps.xml -> C:\WINDOWS\System32\nvapps.xml -> [2009-09-02 13:16:47 | 00,088,566 | ---- | M] () SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2009-09-02 13:16:35 | 00,000,006 | -H-- | M] () bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2009-09-02 13:16:29 | 00,002,048 | --S- | M] () NTUSER.DAT -> C:\Documents and Settings\Bobcok\NTUSER.DAT -> [2009-09-02 00:51:57 | 04,194,304 | -H-- | M] () ntuser.ini -> C:\Documents and Settings\Bobcok\ntuser.ini -> [2009-09-02 00:51:44 | 00,000,188 | -HS- | M] () 1.JPG -> C:\Documents and Settings\Bobcok\Pulpit\1.JPG -> [2009-09-01 22:14:08 | 00,059,606 | ---- | M] () FIX.BAT -> C:\Documents and Settings\Bobcok\Pulpit\FIX.BAT -> [2009-09-01 21:56:26 | 00,000,210 | ---- | M] () HiJackThis.zip -> C:\Documents and Settings\Bobcok\Pulpit\HiJackThis.zip -> [2009-09-01 21:54:59 | 00,318,369 | ---- | M] () CddbLangPL.dll -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\WLZ264F.tmp\CddbLangPL.dll -> [2009-09-01 21:46:10 | 00,099,568 | ---- | M] (Gracenote) delself.bat -> C:\Documents and Settings\Bobcok\delself.bat -> [2009-09-01 20:43:27 | 00,000,142 | ---- | M] () Perflib_Perfdata_544.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_544.dat -> [2009-09-01 20:43:21 | 00,016,384 | ---- | M] () braviax.exe -> C:\WINDOWS\braviax.exe -> [2009-09-01 20:42:54 | 00,011,264 | ---- | M] () sys32_nov.exe -> C:\Documents and Settings\Bobcok\sys32_nov.exe -> [2009-09-01 20:18:53 | 00,029,216 | ---- | M] () sys32_nov.exe -> C:\WINDOWS\System32\sys32_nov.exe -> [2009-09-01 20:18:52 | 00,029,216 | ---- | M] () wpv131251705172.exe -> C:\WINDOWS\Temp\wpv131251705172.exe -> [2009-09-01 20:18:50 | 00,029,216 | ---- | M] () DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009-09-01 09:51:44 | 00,199,168 | ---- | M] () qmgr0.dat -> C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr0.dat -> [2009-08-31 10:29:12 | 00,004,232 | ---- | M] () qmgr1.dat -> C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr1.dat -> [2009-08-31 10:28:24 | 00,005,344 | ---- | M] () Guitar.Hero.5.RF.XBOX360-MARVEL.torrent -> C:\Documents and Settings\Bobcok\Pulpit\Guitar.Hero.5.RF.XBOX360-MARVEL.torrent -> [2009-08-30 18:59:16 | 00,069,091 | ---- | M] () NeroDigital.ini -> C:\WINDOWS\NeroDigital.ini -> [2009-08-30 18:01:39 | 00,000,116 | ---- | M] () Dvbpws.dll -> C:\WINDOWS\System32\Dvbpws.dll -> [2009-08-30 15:04:41 | 00,000,002 | ---- | M] () Tiger4207 (Pure TnA).torrent -> C:\Documents and Settings\Bobcok\Pulpit\Tiger4207 (Pure TnA).torrent -> [2009-08-30 13:58:36 | 00,023,754 | ---- | M] () wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2009-08-28 20:05:51 | 00,002,206 | ---- | M] () Perflib_Perfdata_520.dat -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\Perflib_Perfdata_520.dat -> [2009-08-19 08:16:38 | 00,016,384 | ---- | M] () Perflib_Perfdata_3b0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_3b0.dat -> [2009-08-19 08:16:09 | 00,016,384 | ---- | M] () win.ini -> C:\WINDOWS\win.ini -> [2009-08-14 16:22:20 | 00,000,573 | ---- | M] () Perflib_Perfdata_4b8.dat -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\Perflib_Perfdata_4b8.dat -> [2009-08-13 20:32:45 | 00,016,384 | ---- | M] () Perflib_Perfdata_4e4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_4e4.dat -> [2009-08-13 20:32:20 | 00,016,384 | ---- | M] () Perflib_Perfdata_4c8.dat -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\Perflib_Perfdata_4c8.dat -> [2009-08-13 10:34:59 | 00,016,384 | ---- | M] () Perflib_Perfdata_3e0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_3e0.dat -> [2009-08-13 10:34:36 | 00,016,384 | ---- | M] () Perflib_Perfdata_634.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_634.dat -> [2009-08-06 15:41:52 | 00,016,384 | ---- | M] () Perflib_Perfdata_47c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_47c.dat -> [2009-08-05 09:43:15 | 00,016,384 | ---- | M] () Perflib_Perfdata_3dc.dat -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\Perflib_Perfdata_3dc.dat -> [2009-08-02 11:47:34 | 00,016,384 | ---- | M] () Perflib_Perfdata_704.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_704.dat -> [2009-08-02 11:47:12 | 00,016,384 | ---- | M] () Perflib_Perfdata_530.dat -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\Perflib_Perfdata_530.dat -> [2009-08-02 07:58:12 | 00,016,384 | ---- | M] () Perflib_Perfdata_c4.dat -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\Perflib_Perfdata_c4.dat -> [2009-08-02 07:49:57 | 00,016,384 | ---- | M] () Perflib_Perfdata_71c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_71c.dat -> [2009-08-02 07:49:28 | 00,016,384 | ---- | M] () jre-6u15-windows-i586-iftw.exe -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\jre-6u15-windows-i586-iftw.exe -> [2009-08-01 19:29:47 | 00,714,528 | ---- | M] (Sun Microsystems, Inc.) nowegg.upgr.exe -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\nowegg.upgr.exe -> [2009-07-29 00:16:57 | 18,648,504 | ---- | M] () CddbLangPL.dll -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\WLZ71A1.tmp\CddbLangPL.dll -> [2009-07-25 23:16:31 | 00,099,568 | ---- | M] (Gracenote) Perflib_Perfdata_4f0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_4f0.dat -> [2009-07-10 20:03:18 | 00,016,384 | ---- | M] () Perflib_Perfdata_3ac.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_3ac.dat -> [2009-07-09 18:47:33 | 00,016,384 | ---- | M] () Perflib_Perfdata_514.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_514.dat -> [2009-06-30 13:20:42 | 00,016,384 | ---- | M] () Perflib_Perfdata_244.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_244.dat -> [2009-06-29 09:51:01 | 00,016,384 | ---- | M] () Perflib_Perfdata_5f0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_5f0.dat -> [2009-06-21 11:40:39 | 00,016,384 | ---- | M] () Perflib_Perfdata_6f4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6f4.dat -> [2009-06-17 10:21:55 | 00,016,384 | ---- | M] () Perflib_Perfdata_508.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_508.dat -> [2009-06-13 23:08:35 | 00,016,384 | ---- | M] () Perflib_Perfdata_4dc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_4dc.dat -> [2009-05-20 11:59:56 | 00,016,384 | ---- | M] () raptrpatch.exe -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\raptrpatch.exe -> [2009-05-10 17:10:26 | 22,018,696 | ---- | M] () Perflib_Perfdata_4ac.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_4ac.dat -> [2009-05-06 10:22:51 | 00,016,384 | ---- | M] () Perflib_Perfdata_40c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_40c.dat -> [2009-05-03 10:02:06 | 00,016,384 | ---- | M] () jre-6u13-windows-i586-p-iftw.exe -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\jre-6u13-windows-i586-p-iftw.exe -> [2009-03-25 09:02:45 | 00,607,640 | ---- | M] (Sun Microsystems, Inc.) Perflib_Perfdata_740.dat -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\Perflib_Perfdata_740.dat -> [2009-03-04 16:44:29 | 00,016,384 | ---- | M] () opa12.dat -> C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\OFFICE\DATA\opa12.dat -> [2009-02-07 16:50:02 | 00,008,206 | ---- | M] () Perflib_Perfdata_b0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b0.dat -> [2009-02-05 23:57:36 | 00,016,384 | ---- | M] () ose00000.exe -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\ose00000.exe -> [2006-10-28 00:14:30 | 00,145,184 | R--- | M] (Microsoft Corporation) CTPBSEQ.EXE -> C:\WINDOWS\Temp\CTPBSEQ.EXE -> [2005-05-31 19:02:00 | 00,065,536 | R--- | M] (Creative Technology Ltd.) MINYANUST.EXE -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\MINYANML\MINYANUST.EXE -> [2004-10-15 05:34:00 | 00,536,576 | ---- | M] ( ) dsetup32.dll -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\MINYANML\dsetup32.dll -> [2004-10-02 01:07:00 | 02,242,560 | ---- | M] (Microsoft Corporation) dsetup.dll -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\MINYANML\dsetup.dll -> [2004-10-02 01:07:00 | 00,062,976 | ---- | M] (Microsoft Corporation) CountryCode.dat -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\{C9E22F39-F299-485E-A2D7-7DC676FEA6D3}\{31E1050B-F69F-4A16-8F5A-E44D31901250}\CountryCode.dat -> [2003-10-29 08:29:48 | 00,006,125 | ---- | M] () [File - Lop Check] Dane aplikacji -> C:\Documents and Settings\All Users\Dane aplikacji -> [2009-09-02 13:22:45 | 00,000,000 | RH-D | M] 2DBoy -> C:\Documents and Settings\All Users\Dane aplikacji\2DBoy -> [2009-04-11 10:14:04 | 00,000,000 | ---D | M] ACD Systems -> C:\Documents and Settings\All Users\Dane aplikacji\ACD Systems -> [2009-03-12 21:16:09 | 00,000,000 | ---D | M] Easy CD-DA Extractor -> C:\Documents and Settings\All Users\Dane aplikacji\Easy CD-DA Extractor -> [2009-02-17 13:03:06 | 00,000,000 | ---D | M] ESET -> C:\Documents and Settings\All Users\Dane aplikacji\ESET -> [2009-02-05 23:58:10 | 00,000,000 | ---D | M] OpenFM -> C:\Documents and Settings\All Users\Dane aplikacji\OpenFM -> [2009-08-17 00:11:22 | 00,000,000 | ---D | M] PC Drivers Headquarters -> C:\Documents and Settings\All Users\Dane aplikacji\PC Drivers Headquarters -> [2009-04-23 23:03:28 | 00,000,000 | ---D | M] SmartSound Software Inc -> C:\Documents and Settings\All Users\Dane aplikacji\SmartSound Software Inc -> [2009-02-15 22:43:19 | 00,000,000 | ---D | M] TEMP -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP -> [2009-02-17 13:03:12 | 00,000,000 | ---D | M] Ulead Systems -> C:\Documents and Settings\All Users\Dane aplikacji\Ulead Systems -> [2009-02-15 22:43:36 | 00,000,000 | ---D | M] Dane aplikacji -> C:\Documents and Settings\Bobcok\Dane aplikacji -> [2009-09-02 13:22:45 | 00,000,000 | RH-D | M] ACD Systems -> C:\Documents and Settings\Bobcok\Dane aplikacji\ACD Systems -> [2009-03-12 21:16:35 | 00,000,000 | ---D | M] AutoUpdate -> C:\Documents and Settings\Bobcok\Dane aplikacji\AutoUpdate -> [2009-02-20 02:01:40 | 00,000,000 | ---D | M] BESTplayer -> C:\Documents and Settings\Bobcok\Dane aplikacji\BESTplayer -> [2009-08-31 17:18:33 | 00,000,000 | ---D | M] com.raptr.Raptr.848BBC53270CAC248E8FA0F339176201CDEB525F.1 -> C:\Documents and Settings\Bobcok\Dane aplikacji\com.raptr.Raptr.848BBC53270CAC248E8FA0F339176201CDEB525F.1 -> [2009-05-10 17:12:00 | 00,000,000 | ---D | M] Gadu-Gadu -> C:\Documents and Settings\Bobcok\Dane aplikacji\Gadu-Gadu -> [2009-02-07 15:57:43 | 00,000,000 | ---D | M] ijjigame -> C:\Documents and Settings\Bobcok\Dane aplikacji\ijjigame -> [2009-05-10 19:13:37 | 00,000,000 | -H-D | M] ImgBurn -> C:\Documents and Settings\Bobcok\Dane aplikacji\ImgBurn -> [2009-06-15 00:12:09 | 00,000,000 | ---D | M] Kamerzysta -> C:\Documents and Settings\Bobcok\Dane aplikacji\Kamerzysta -> [2009-02-20 02:08:31 | 00,000,000 | ---D | M] Nowe Gadu-Gadu -> C:\Documents and Settings\Bobcok\Dane aplikacji\Nowe Gadu-Gadu -> [2009-08-17 14:49:06 | 00,000,000 | ---D | M] NPLUTO Corporation -> C:\Documents and Settings\Bobcok\Dane aplikacji\NPLUTO Corporation -> [2009-05-10 19:47:43 | 00,000,000 | ---D | M] OpenFM -> C:\Documents and Settings\Bobcok\Dane aplikacji\OpenFM -> [2009-08-17 00:09:56 | 00,000,000 | ---D | M] Opera -> C:\Documents and Settings\Bobcok\Dane aplikacji\Opera -> [2009-02-06 00:19:04 | 00,000,000 | ---D | M] Pamela -> C:\Documents and Settings\Bobcok\Dane aplikacji\Pamela -> [2009-02-20 01:22:09 | 00,000,000 | ---D | M] Raptr -> C:\Documents and Settings\Bobcok\Dane aplikacji\Raptr -> [2009-05-10 17:11:13 | 00,000,000 | ---D | M] Ulead Systems -> C:\Documents and Settings\Bobcok\Dane aplikacji\Ulead Systems -> [2009-02-15 22:49:39 | 00,000,000 | ---D | M] uTorrent -> C:\Documents and Settings\Bobcok\Dane aplikacji\uTorrent -> [2009-09-02 14:13:50 | 00,000,000 | ---D | M] Dane aplikacji -> C:\Documents and Settings\Default User\Dane aplikacji -> [2009-02-06 00:45:02 | 00,000,000 | RH-D | M] Dane aplikacji -> C:\Documents and Settings\LocalService\Dane aplikacji -> [2009-02-05 23:53:26 | 00,000,000 | ---D | M] Dane aplikacji -> C:\Documents and Settings\NetworkService\Dane aplikacji -> [2009-02-05 23:53:01 | 00,000,000 | ---D | M] C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2009-02-05 23:53:27 | 00,000,000 | --SD | M] desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2001-07-22 04:17:50 | 00,000,065 | RH-- | M] () SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2009-09-02 13:16:35 | 00,000,006 | -H-- | M] () [File - Purity Scan] < End of report > [/code]