Log z OTLIST2:
OTListIt Extras logfile created on: 2009-04-21 10:55:14 - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Ewa\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
766,73 Mb Total Physical Memory | 512,70 Mb Available Physical Memory | 66,87% Memory free
1,08 Gb Paging File | 0,87 Gb Available in Paging File | 80,77% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 16,82 Gb Total Space | 2,88 Gb Free Space | 17,14% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 39,06 Gb Total Space | 35,23 Gb Free Space | 90,19% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 55,88 Gb Total Space | 52,42 Gb Free Space | 93,81% Space Free | Partition Type: NTFS
Drive Y: | 55,88 Gb Total Space | 52,42 Gb Free Space | 93,81% Space Free | Partition Type: NTFS
Drive Z: | 55,88 Gb Total Space | 52,42 Gb Free Space | 93,81% Space Free | Partition Type: NTFS
Computer Name: KSIEGOWOSC
Current User Name: Ewa
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
[HKEY_USERS\S-1-5-21-796845957-362288127-839522115-1003\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008-04-13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008-04-13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007-09-26 13:35:38 | 01,848,616 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup
[2008-04-20 13:14:38 | 01,262,592 | ---- | M] (Nix-Ware.com Paweł Barut) -- C:\DOS-PR08\DOSprinter\DOSprint.exe:*:Enabled:DOS printer
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05381030-963D-4779-BECA-0D7D49268EDB}" = Płatnik 7.03.001
"{135BA9A6-495A-4FE9-B1A1-AB4DA449CAB1}" = hppLJP2015
"{1F73D672-6175-4A1D-B3C1-420439D03D0F}" = Product_SF_Full_QFolder
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java 6 Update 13
"{29CBFC23-05A7-4286-93B8-BABE29BC1045}" = Nero 7 Essentials
"{2DB2E8BB-C478-4882-B53D-1E34C70952F7}" = d2System ver_ I_3_3_11b
"{300A2961-B2B5-4889-9CB9-5C2A570D08AD}" = Debugging Tools for Windows (x86)
"{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{414C803A-6115-4DB6-BD4E-FD81EA6BC71C}" = Product_SF_Min_QFolder
"{561D20B1-766E-4EA5-8A1D-B7357D903673}" = hppIOFiles
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58ECE031-9AAD-4011-B34A-BC78E77527E2}" = hppMSRedist
"{6441FECE-0E73-4326-81BF-68503E897820}" = CorePLS_Min_QFolder
"{64CB2553-C109-4132-AA51-1F421B515FD1}" = Microsoft .NET Framework 1.1 Polish Language Pack
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{69E6C13B-CF6B-47A6-B7A5-77FE82B2CB40}" = hppFonts
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ECB6EE7-DF64-4F26-9273-9525FC11A417}" = Instalacja programu mks_vir 2k7
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7A178F2E-92F6-437C-A709-69685D1C0F2B}" = hppTLBXFXP2015
"{8C0118CC-F720-45FF-A4DA-44AD77B2E73C}" = CorePLS_Full_QFolder
"{90110415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{93C069D4-2F86-4570-A6DF-BFABBA1E4AFD}" = hpzTLBXFX
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AAA11090-6E99-4655-AAF5-57EB5F677D0C}" = MarketResearch
"{ABDF78D0-6F94-440B-917F-22803D165F14}" = Platinum Guard
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B96A7F3B-AF29-489A-AE84-1DDF5942971C}" = proCertum CardManager
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB3B7C24-30A1-4961-8039-94919F5ED2EE}" = Noiseware Community Edition
"{CFB61D8C-D651-4D7C-80B4-C78676A0AF1F}" = hppusgP2015
"{D9B4D7EE-481C-4C36-86AB-A8F7417725FF}" = LightScribe 1.6.43.1
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{EDAE4F43-833C-443B-8DB5-129F897DF3E8}" = hppWebRegMM
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F38D0F99-1BFC-47AB-AC36-8D9D43700CFB}" = hppManualsP2015
"7-Zip" = 7-Zip 4.43 beta
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0 CE
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AviSynth" = AviSynth 2.5
"e-PFRON OffLine" = e-PFRON OffLine 1.3.5
"HijackThis" = HijackThis 2.0.2
"HP LaserJet P2015" = HP LaserJet P2015 Series 1.0
"HPExtendedCapabilities" = HP Extended Capabilities 6.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"IrfanView" = IrfanView (remove only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Niezbędnik CD_is1" = Niezbędnik CD
"NixWareDOSprinter" = Nix-Ware.com DOS printer emulator (tylko usuwanie)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PABS 4.1_is1" = PABS 4.1
"PITy 2007_is1" = PITy 2007 dla Windows kompilacja:1.0.1.2
"PITy 2008_is1" = PITy 2008 dla Windows kompilacja:1.0.2.1
"RealPlayer 6.0" = RealPlayer
"Registry Mechanic_is1" = Registry Mechanic 8.0
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"VLC media player" = VLC media player 0.9.8a
"Webshots Desktop_is1" = Webshots Desktop
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = Archiwizator WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.1
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2009-04-07 06:27:37 | Computer Name = KSIEGOWOSC | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd vlc.exe, wersja 0.9.8.1, moduł powodujący
błąd libvlccore.dll, wersja 0.9.8.1, adres błędu 0x0007d6a0.
Error - 2009-04-07 09:50:31 | Computer Name = KSIEGOWOSC | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca P2.exe, wersja 7.3.10.502, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.
Error - 2009-04-09 01:51:26 | Computer Name = KSIEGOWOSC | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd msimn.exe, wersja 6.0.2900.5512, moduł powodujący
błąd , wersja 0.0.0.0, adres błędu 0x00000000.
Error - 2009-04-14 06:01:44 | Computer Name = KSIEGOWOSC | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd repman.exe, wersja 3.3.22.4, moduł powodujący
błąd repman.exe, wersja 3.3.22.4, adres błędu 0x0013b3f5.
Error - 2009-04-14 06:15:08 | Computer Name = KSIEGOWOSC | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca vlc.exe, wersja 0.9.8.1, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.
Error - 2009-04-14 06:17:03 | Computer Name = KSIEGOWOSC | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca vlc.exe, wersja 0.9.8.1, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.
Error - 2009-04-20 02:45:24 | Computer Name = KSIEGOWOSC | Source = MsiInstaller | ID = 11704
Description = Produkt: Microsoft Office Professional Edition 2003 -- Błąd 1704.
Instalacja Noiseware Community Edition jest aktualnie wstrzymana. Musisz cofnąć
zmiany uczynione przez tę instalację, aby kontynuować. Czy chcesz cofnąć te zmiany?
Error - 2009-04-21 03:23:54 | Computer Name = KSIEGOWOSC | Source = WmiAdapter | ID = 4099
Description = Otwarcie usługi nie powiodło się.
Error - 2009-04-21 04:02:35 | Computer Name = KSIEGOWOSC | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd windbg.exe, wersja 6.11.1.404, moduł powodujący
błąd unknown, wersja 0.0.0.0, adres błędu 0x00520076.
Error - 2009-04-21 04:54:37 | Computer Name = KSIEGOWOSC | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca iexplore.exe, wersja 8.0.6001.18702, moduł
zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.
[ System Events ]
Error - 2009-04-21 03:23:54 | Computer Name = KSIEGOWOSC | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi Karta wydajności WMI z powodu następującego
błędu: %%1053
Error - 2009-04-21 04:47:10 | Computer Name = KSIEGOWOSC | Source = DCOM | ID = 10005
Description = Model DCOM odebrał błąd „%1053” podczas próby uruchomienia usługi
mks_scan z argumentami „-Service” w celu uruchomienia serwera: {0B3B62DF-96A8-42BC-9C0C-A6CCE7E0BA03}
Error - 2009-04-21 04:47:11 | Computer Name = KSIEGOWOSC | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą MkS_Scan.
Error - 2009-04-21 04:47:11 | Computer Name = KSIEGOWOSC | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi MkS_Scan z powodu następującego błędu:
%%1053
Error - 2009-04-21 04:47:45 | Computer Name = KSIEGOWOSC | Source = DCOM | ID = 10005
Description = Model DCOM odebrał błąd „%1053” podczas próby uruchomienia usługi
mks_scan z argumentami „-Service” w celu uruchomienia serwera: {0B3B62DF-96A8-42BC-9C0C-A6CCE7E0BA03}
Error - 2009-04-21 04:47:46 | Computer Name = KSIEGOWOSC | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą MkS_Scan.
Error - 2009-04-21 04:47:46 | Computer Name = KSIEGOWOSC | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi MkS_Scan z powodu następującego błędu:
%%1053
Error - 2009-04-21 04:48:24 | Computer Name = KSIEGOWOSC | Source = DCOM | ID = 10005
Description = Model DCOM odebrał błąd „%1053” podczas próby uruchomienia usługi
mks_scan z argumentami „-Service” w celu uruchomienia serwera: {0B3B62DF-96A8-42BC-9C0C-A6CCE7E0BA03}
Error - 2009-04-21 04:48:24 | Computer Name = KSIEGOWOSC | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą MkS_Scan.
Error - 2009-04-21 04:48:24 | Computer Name = KSIEGOWOSC | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi MkS_Scan z powodu następującego błędu:
%%1053
< End of report >
OTListIt logfile created on: 2009-04-21 10:55:14 - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Ewa\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
766,73 Mb Total Physical Memory | 512,70 Mb Available Physical Memory | 66,87% Memory free
1,08 Gb Paging File | 0,87 Gb Available in Paging File | 80,77% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 16,82 Gb Total Space | 2,88 Gb Free Space | 17,14% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 39,06 Gb Total Space | 35,23 Gb Free Space | 90,19% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 55,88 Gb Total Space | 52,42 Gb Free Space | 93,81% Space Free | Partition Type: NTFS
Drive Y: | 55,88 Gb Total Space | 52,42 Gb Free Space | 93,81% Space Free | Partition Type: NTFS
Drive Z: | 55,88 Gb Total Space | 52,42 Gb Free Space | 93,81% Space Free | Partition Type: NTFS
Computer Name: KSIEGOWOSC
Current User Name: Ewa
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2008-04-14 19:21:16 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2003-05-05 08:57:30 | 00,143,360 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
PRC - [2007-03-14 08:20:38 | 00,520,192 | ---- | M] (MkS Sp. z o.o.) -- C:\Program Files\mks_vir_2007\bin\mks_mail.exe
PRC - [2007-07-05 07:46:42 | 00,663,552 | ---- | M] (MKS Sp z o.o.) -- C:\Program Files\mks_vir_2007\bin\mkstray.exe
PRC - [2007-03-23 08:40:18 | 00,303,104 | ---- | M] () -- C:\Program Files\mks_vir_2007\bin\mksregmon.exe
PRC - [2003-10-31 19:42:40 | 00,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2006-06-15 08:43:20 | 00,049,152 | ---- | M] (HP) -- C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
PRC - [2005-02-16 23:11:42 | 00,049,152 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
PRC - [2009-03-09 05:19:18 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008-10-16 12:56:22 | 01,960,448 | ---- | M] () -- C:\WINDOWS\system32\winsys.exe
PRC - [2009-03-09 05:19:16 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2007-04-19 13:35:46 | 00,075,304 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2007-03-06 08:14:18 | 00,253,952 | ---- | M] () -- C:\Program Files\mks_vir_2007\bin\MksPC.exe
PRC - [2007-03-26 16:28:00 | 00,570,880 | ---- | M] (MKS Sp. z o. o.) -- C:\Program Files\mks_vir_2007\bin\mksupdate.exe
PRC - [2008-03-17 14:30:36 | 00,389,120 | ---- | M] () -- C:\Program Files\mks_vir_2007\bin\mksvirmonsvc.exe
PRC - [2002-09-20 16:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
PRC - [2009-02-06 12:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2008-04-14 19:21:44 | 00,139,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\taskmgr.exe
PRC - [2009-04-21 10:43:54 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ewa\Pulpit\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2007-10-24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007-10-24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2007-10-18 09:02:30 | 00,138,168 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008-04-14 19:20:44 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2009-03-09 05:19:16 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2007-04-19 13:35:46 | 00,075,304 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
SRV - [2007-04-10 10:39:02 | 00,270,336 | ---- | M] (MKS Sp z o.o.) -- C:\Program Files\mks_vir_2007\bin\MksFwall.exe -- (MksFwall [Disabled | Stopped])
SRV - [2007-03-06 08:14:18 | 00,253,952 | ---- | M] () -- C:\Program Files\mks_vir_2007\bin\MksPC.exe -- (MksPC [Auto | Running])
SRV - [2007-03-26 16:28:00 | 00,570,880 | ---- | M] (MKS Sp. z o. o.) -- C:\Program Files\mks_vir_2007\bin\mksupdate.exe -- (MksUpdate [Auto | Running])
SRV - [2008-03-17 14:30:36 | 00,389,120 | ---- | M] () -- C:\Program Files\mks_vir_2007\bin\mksvirmonsvc.exe -- (MksVirMonSvc [Auto | Running])
SRV - [2009-03-09 07:34:34 | 00,270,336 | ---- | M] () -- C:\Program Files\mks_vir_2007\bin\mks_scan.exe -- (MkS_Scan [On_Demand | Stopped])
SRV - [2007-09-17 10:36:18 | 00,800,040 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService [On_Demand | Stopped])
SRV - [2007-06-27 19:04:00 | 00,279,848 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
SRV - [2008-04-14 19:20:42 | 00,065,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\nwwks.dll -- (NWCWorkstation1 [Disabled | Stopped])
SRV - [2003-07-28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2002-09-20 16:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default) [Auto | Running])
SRV - [2006-12-01 11:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2006-03-24 19:14:00 | 00,033,536 | R--- | M] (Advanced Card Systems Ltd) -- C:\WINDOWS\system32\DRIVERS\a38usb.sys -- (ACSSCR [On_Demand | Stopped])
DRV - [2002-04-01 07:15:00 | 00,004,816 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (aeaudio [On_Demand | Running])
DRV - [2001-08-17 21:28:04 | 00,067,167 | ---- | M] (Conexant) -- C:\WINDOWS\system32\DRIVERS\HSF_BSC2.sys -- (basic2 [On_Demand | Running])
DRV - [2001-08-17 21:28:06 | 00,289,887 | ---- | M] (Conexant) -- C:\WINDOWS\system32\DRIVERS\HSF_FALL.sys -- (Fallback [Auto | Running])
DRV - [2001-08-17 21:28:06 | 00,115,807 | ---- | M] (Conexant) -- C:\WINDOWS\system32\DRIVERS\HSF_FSKS.sys -- (Fsks [Auto | Running])
DRV - [2006-06-12 11:36:30 | 00,009,344 | ---- | M] (Hewlett Packard) -- C:\WINDOWS\system32\drivers\hpfxbulk.sys -- (HPFXBULK [On_Demand | Running])
DRV - [2001-08-17 21:28:10 | 00,542,879 | ---- | M] (Conexant) -- C:\WINDOWS\system32\DRIVERS\HSF_MSFT.sys -- (hsf_msft [On_Demand | Running])
DRV - [2001-08-17 21:28:08 | 00,391,199 | ---- | M] (Conexant) -- C:\WINDOWS\system32\DRIVERS\HSF_K56K.sys -- (K56 [Auto | Running])
DRV - [2007-03-29 08:22:04 | 00,011,776 | ---- | M] () -- C:\WINDOWS\system32\mksidsf.sys -- (mksidsf [On_Demand | Stopped])
DRV - [2007-08-13 07:44:16 | 00,385,024 | ---- | M] () -- C:\Program Files\mks_vir_2007\bin\MksMonEn.sys -- (MksMonEn [On_Demand | Stopped])
DRV - [2007-03-23 08:40:16 | 00,089,600 | ---- | M] () -- C:\Program Files\mks_vir_2007\bin\MksMonEv.sys -- (MksMonEv [On_Demand | Stopped])
DRV - [2007-02-07 14:35:36 | 00,026,624 | ---- | M] () -- C:\Program Files\mks_vir_2007\bin\MksMonFd.sys -- (MksMonFd [On_Demand | Running])
DRV - [2001-08-17 21:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Running])
DRV - [2004-08-03 22:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2008-06-19 16:24:30 | 00,028,544 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot [Boot | Running])
DRV - [2008-04-17 08:23:48 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\System32\Drivers\pcouffin.sys -- (pcouffin [On_Demand | Stopped])
DRV - [2006-03-02 12:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2001-08-17 21:28:10 | 00,057,471 | ---- | M] (Conexant) -- C:\WINDOWS\system32\DRIVERS\HSF_SAMP.sys -- (Rksample [On_Demand | Running])
DRV - [2004-08-03 22:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\system32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Running])
DRV - [2007-11-13 11:25:56 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2003-08-12 13:15:48 | 00,578,368 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])
DRV - [2001-08-17 21:28:06 | 00,199,711 | ---- | M] (Conexant) -- C:\WINDOWS\system32\DRIVERS\HSF_FAXX.sys -- (SoftFax [Auto | Running])
DRV - [2008-07-17 09:13:16 | 00,716,272 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2001-08-17 21:28:12 | 00,050,751 | ---- | M] (Conexant) -- C:\WINDOWS\system32\DRIVERS\HSF_TONE.sys -- (Tones [Auto | Running])
DRV - [2001-08-17 21:28:12 | 00,488,383 | ---- | M] (Conexant) -- C:\WINDOWS\system32\DRIVERS\HSF_V124.sys -- (V124 [Auto | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-796845957-362288127-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-796845957-362288127-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-796845957-362288127-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKU\S-1-5-21-796845957-362288127-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-796845957-362288127-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.onet.pl/
IE - HKU\S-1-5-21-796845957-362288127-839522115-1003\S-1-5-21-796845957-362288127-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-796845957-362288127-839522115-1003\S-1-5-21-796845957-362288127-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://beta.onet.pl/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=utf-8&fr=megaup&p="
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008-12-01 07:56:56 | 00,000,000 | ---D | M]
[2008-07-10 15:04:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ewa\Dane aplikacji\mozilla\Extensions
[2008-07-10 15:04:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ewa\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2007-04-27 09:17:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ewa\Dane aplikacji\mozilla\Firefox\Profiles\06rab3mv.default\extensions
[2007-09-05 09:03:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ewa\Dane aplikacji\mozilla\Firefox\Profiles\06rab3mv.default\extensions\{991A772A-BA13-4c1d-A9EF-F897F31DEC7D}
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-796845957-362288127-839522115-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKU\S-1-5-21-796845957-362288127-839522115-1003\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [mks_mail] C:\Program Files\mks_vir_2007\bin\mks_mail.exe (MkS Sp. z o.o.)
O4 - HKLM..\Run: [MKSRegmon] C:\Program Files\mks_vir_2007\bin\mksregmon.exe ()
O4 - HKLM..\Run: [mkstray] C:\Program Files\mks_vir_2007\bin\mkstray.exe (MKS Sp z o.o.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on (HP)
O4 - HKU\S-1-5-21-796845957-362288127-839522115-1003..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H (PC Tools)
O4 - Startup: C:\Documents and Settings\Ewa\Menu Start\Programy\Autostart\winsys.exe.lnk = C:\WINDOWS\system32\winsys.exe ()
O4 - Startup: C:\Documents and Settings\Ewa\Menu Start\Programy\Autostart\winword.exe.lnk = C:\WINDOWS\system32\winword.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-796845957-362288127-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-796845957-362288127-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-796845957-362288127-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-796845957-362288127-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-796845957-362288127-839522115-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\mks_vir_2007\bin\mkslsp.dll ()
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}
http://acs.pandasoftware.com/betaactivesca...s/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/get/shock...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{7C132743-38D9-48B6-9906-3CD27D1A49C4}\\NameServer = 194.204.159.1,194.204.152.34
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007-02-12 13:38:54 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[108 C:\WINDOWS\*.tmp files]
[2009-04-21 10:43:51 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Ewa\Pulpit\OTListIt2.exe
[2009-04-21 09:57:25 | 00,000,000 | ---D | C] -- C:\Program Files\Debugging Tools for Windows (x86)
[2009-04-21 09:56:16 | 17,815,040 | ---- | C] () -- C:\Documents and Settings\Ewa\Pulpit\dbg_x86_6.11.1.404.msi
[2009-04-21 09:38:21 | 13,709,800 | ---- | C] (Doctor Web, Ltd.) -- C:\Documents and Settings\Ewa\Pulpit\launch.exe
[2009-04-21 09:09:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Plugins
[2009-04-21 09:06:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
[2009-04-21 09:06:49 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\STKIT432.DLL
[2009-04-21 09:06:49 | 00,000,642 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Registry Mechanic.lnk
[2009-04-21 09:06:46 | 00,000,000 | ---D | C] -- C:\Program Files\Registry Mechanic
[2009-04-21 09:05:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ewa\Pulpit\Registry Mechanic 8
[2009-04-21 09:05:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ewa\Dane aplikacji\WinRAR
[2009-04-21 09:05:04 | 01,309,117 | ---- | C] () -- C:\Documents and Settings\Ewa\Pulpit\wrar380pl.exe
[2009-04-21 09:05:01 | 07,486,053 | ---- | C] () -- C:\Documents and Settings\Ewa\Pulpit\Registry_Mechanic_8.rar
[2009-04-21 08:30:53 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009-04-21 08:30:53 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009-04-21 08:30:53 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009-04-21 08:30:53 | 00,109,568 | ---- | C] () -- C:\WINDOWS\vFind.exe
[2009-04-21 08:30:53 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009-04-21 08:30:53 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009-04-21 08:30:53 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009-04-21 08:30:53 | 00,029,696 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009-04-21 08:30:45 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009-04-21 08:23:21 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009-04-21 08:22:11 | 02,999,426 | R--- | C] () -- C:\Documents and Settings\Ewa\Pulpit\ComboFix.exe
[2009-04-20 07:33:00 | 00,000,023 | ---- | C] () -- C:\WINDOWS\System32\ceeefddd5_z.ocx
[2009-04-17 11:01:02 | 00,027,136 | ---- | C] () -- C:\Documents and Settings\Ewa\Moje dokumenty\rOZLICZENIE KÓŁ RR- zajęcia ruchowe.xls
[2009-04-17 10:09:44 | 00,000,000 | -HSD | C] -- C:\FOUND.021
[2009-04-16 07:43:36 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009-04-16 07:43:25 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcss.dll
[2009-04-16 07:43:25 | 00,285,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pdh.dll
[2009-04-16 07:43:25 | 00,111,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\services.exe
[2009-04-16 07:43:24 | 00,473,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fastprox.dll
[2009-04-16 07:43:23 | 00,686,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advapi32.dll
[2009-04-16 07:43:22 | 00,731,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009-04-16 07:43:22 | 00,722,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntdll.dll
[2009-04-16 07:43:22 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009-04-16 07:42:05 | 01,203,922 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009-04-16 07:42:05 | 00,218,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wordpad.exe
[2009-04-14 10:05:28 | 00,000,026 | ---- | C] () -- C:\WINDOWS\Zone.Identifier
[2009-04-14 07:57:22 | 00,000,000 | -HSD | C] -- C:\FOUND.020
[2009-04-09 08:21:22 | 00,000,000 | -HSD | C] -- C:\FOUND.019
[2009-04-09 08:05:54 | 00,000,000 | ---D | C] -- C:\Hewlett-Packard
[2009-04-07 14:02:07 | 00,028,160 | ---- | C] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Aktualizacja harmonogramów 85412-85415-80113.xls
[2009-04-07 14:01:30 | 00,030,208 | ---- | C] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Aktualizacja harmonogramów-80146-85446.xls
[2009-04-07 13:59:12 | 00,243,200 | ---- | C] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Aktulalizacje harmonogramów - WZÓR.xls
[2009-04-07 13:49:12 | 00,000,000 | -HSD | C] -- C:\FOUND.018
[2009-04-07 11:20:24 | 00,000,000 | -HSD | C] -- C:\FOUND.017
[2009-04-06 12:04:32 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\pavboot.sys
[2009-04-06 07:33:06 | 00,000,000 | -HSD | C] -- C:\FOUND.016
[2009-04-02 13:08:18 | 00,000,000 | -HSD | C] -- C:\FOUND.015
[2009-03-31 14:30:49 | 00,245,760 | ---- | C] (Ask.com) -- C:\Program Files\Uninstall Ask Toolbar.dll
[2009-03-31 14:05:19 | 00,000,808 | ---- | C] () -- C:\Documents and Settings\Ewa\Pulpit\HijackThis.lnk
[2009-03-30 15:12:20 | 00,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
[2009-03-30 15:11:53 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009-03-30 15:07:56 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009-03-30 15:04:41 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
[2009-03-30 15:03:05 | 17,223,168 | ---- | C] (Microsoft Corporation) -- C:\windows_xp_pl.exe
[2009-03-30 14:38:36 | 00,000,000 | -HSD | C] -- C:\FOUND.014
[2009-03-30 13:54:40 | 00,000,000 | ---D | C] -- C:\!KillBox
[2009-03-30 13:06:40 | 00,000,000 | -HSD | C] -- C:\FOUND.013
[2009-03-30 08:18:10 | 00,000,000 | -HSD | C] -- C:\FOUND.012
[2009-03-30 07:43:54 | 00,000,000 | -HSD | C] -- C:\FOUND.011
[2009-03-27 15:40:02 | 00,000,000 | -HSD | C] -- C:\FOUND.010
[2009-03-27 15:34:46 | 00,000,000 | -HSD | C] -- C:\FOUND.009
[2009-03-26 14:14:23 | 00,054,272 | ---- | C] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Wzór planów RDW na 2009.1 SSM.xls
[2009-03-26 13:35:20 | 00,054,272 | ---- | C] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Wzór planów RDW na 2009.1 MDK.xls
[2009-03-26 13:09:15 | 00,052,224 | ---- | C] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Wzór planów RDW na 2009.1.xls
[2009-03-25 10:05:26 | 00,000,000 | -HSD | C] -- C:\FOUND.008
[2009-03-23 12:08:00 | 00,021,504 | ---- | C] () -- C:\Documents and Settings\Ewa\Moje dokumenty\PROBIT.doc
[2009-03-23 08:53:10 | 00,065,024 | ---- | C] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Zestawienie zmian.doc
[2009-02-10 12:03:25 | 00,000,030 | ---- | C] () -- C:\WINDOWS\TextSpy.ini
[2008-12-17 23:30:06 | 00,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008-12-17 23:30:06 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008-10-28 13:54:30 | 00,000,462 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2008-10-28 13:54:07 | 00,000,685 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2008-10-16 11:07:36 | 00,001,627 | ---- | C] () -- C:\WINDOWS\System32\Load.ini
[2008-09-02 09:14:06 | 00,110,592 | R--- | C] () -- C:\WINDOWS\System32\usbr38.dll
[2008-07-18 09:16:53 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2008-07-17 09:13:13 | 00,716,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008-06-29 15:24:32 | 00,311,128 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2008-06-29 15:24:32 | 00,168,960 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008-06-29 15:24:31 | 01,526,468 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2008-04-28 14:55:27 | 00,162,816 | ---- | C] () -- C:\WINDOWS\System32\sqlite3.dll
[2007-05-22 09:40:12 | 00,000,946 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007-02-28 11:49:59 | 00,000,270 | ---- | C] () -- C:\WINDOWS\{6ECB6EE7-DF64-4F26-9273-9525FC11A417}_WiseFW.ini
[2007-02-13 09:13:49 | 00,000,334 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2007-02-12 15:06:44 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007-02-12 14:38:25 | 00,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007-02-12 14:16:37 | 00,015,995 | ---- | C] () -- C:\WINDOWS\hplj1300.ini
[2007-02-12 14:07:05 | 00,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2007-02-12 14:02:35 | 00,002,772 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2007-02-12 14:02:32 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007-02-07 14:35:36 | 00,015,360 | ---- | C] () -- C:\WINDOWS\System32\MksFwallt.sys
[2007-02-07 14:35:36 | 00,013,312 | ---- | C] () -- C:\WINDOWS\System32\MksFwallf.sys
[2007-02-07 14:35:36 | 00,011,776 | ---- | C] () -- C:\WINDOWS\System32\MksIdsf.sys
[2007-02-07 14:35:36 | 00,006,144 | ---- | C] () -- C:\WINDOWS\System32\MksIdsa.sys
[2006-06-12 11:36:30 | 00,241,664 | ---- | C] () -- C:\WINDOWS\System32\hppapr04.DLL
[2006-03-02 12:00:00 | 00,000,639 | ---- | C] () -- C:\WINDOWS\win.ini
[2006-03-02 12:00:00 | 00,000,246 | ---- | C] () -- C:\WINDOWS\system.ini
[2006-02-09 14:47:06 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\VSHP1020.DLL
[2003-04-08 11:40:22 | 00,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2003-01-16 17:32:19 | 00,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[2001-07-06 16:30:02 | 00,003,234 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI
[1997-06-18 00:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1997-04-01 00:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[108 C:\WINDOWS\*.tmp files]
[2009-04-21 10:43:54 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ewa\Pulpit\OTListIt2.exe
[2009-04-21 10:10:16 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-04-21 10:09:56 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-04-21 10:09:54 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-04-21 09:58:10 | 00,109,568 | ---- | M] () -- C:\WINDOWS\vFind.exe
[2009-04-21 09:56:18 | 17,815,040 | ---- | M] () -- C:\Documents and Settings\Ewa\Pulpit\dbg_x86_6.11.1.404.msi
[2009-04-21 09:44:22 | 18,843,6480 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2009-04-21 09:38:22 | 13,709,800 | ---- | M] (Doctor Web, Ltd.) -- C:\Documents and Settings\Ewa\Pulpit\launch.exe
[2009-04-21 09:20:16 | 00,302,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-04-21 09:19:16 | 00,000,246 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-04-21 09:06:50 | 00,000,642 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Registry Mechanic.lnk
[2009-04-21 08:13:56 | 02,999,426 | R--- | M] () -- C:\Documents and Settings\Ewa\Pulpit\ComboFix.exe
[2009-04-21 07:55:46 | 00,002,557 | ---- | M] () -- C:\Documents and Settings\Ewa\Pulpit\Microsoft Office Excel 2003.lnk
[2009-04-21 07:38:14 | 00,002,177 | ---- | M] () -- C:\Documents and Settings\Ewa\Pulpit\Platinum Guard.lnk
[2009-04-21 00:51:52 | 07,486,053 | ---- | M] () -- C:\Documents and Settings\Ewa\Pulpit\Registry_Mechanic_8.rar
[2009-04-20 13:40:14 | 00,002,539 | ---- | M] () -- C:\Documents and Settings\Ewa\Pulpit\Microsoft Office Word 2003.lnk
[2009-04-20 11:01:46 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-04-20 11:01:44 | 00,041,984 | ---- | M] () -- C:\Documents and Settings\Ewa\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-04-20 07:33:02 | 00,000,023 | ---- | M] () -- C:\WINDOWS\System32\ceeefddd5_z.ocx
[2009-04-17 11:24:54 | 00,027,136 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\rOZLICZENIE KÓŁ RR- zajęcia ruchowe.xls
[2009-04-17 09:27:14 | 00,000,639 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-04-17 07:51:40 | 00,463,404 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2009-04-17 07:51:40 | 00,405,888 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-04-17 07:51:40 | 00,081,364 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2009-04-17 07:51:40 | 00,063,470 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-04-17 07:51:38 | 01,026,664 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-04-16 16:04:00 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-04-15 12:39:54 | 00,231,936 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\wykonane wydatki.xls
[2009-04-15 09:01:44 | 00,000,026 | ---- | M] () -- C:\WINDOWS\Zone.Identifier
[2009-04-14 12:43:24 | 00,013,030 | ---- | M] () -- C:\PDOXUSRS.NET
[2009-04-14 11:49:42 | 00,002,463 | ---- | M] () -- C:\Documents and Settings\Ewa\Pulpit\d2Navigator.lnk
[2009-04-14 10:25:08 | 00,034,816 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\PLAN FINANSOWY - Fund socj..doc
[2009-04-14 09:57:00 | 00,243,200 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Aktulalizacje harmonogramów - WZÓR.xls
[2009-04-09 14:33:58 | 00,026,112 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Fundusz socjalny-wykonanie.doc
[2009-04-09 08:50:10 | 00,000,000 | ---- | M] () -- C:\WINDOWS\dhsa.qfg
[2009-04-09 08:17:32 | 00,047,360 | ---- | M] (VSO Software) -- C:\Documents and Settings\Ewa\Dane aplikacji\pcouffin.sys
[2009-04-09 08:17:32 | 00,007,887 | ---- | M] () -- C:\Documents and Settings\Ewa\Dane aplikacji\pcouffin.cat
[2009-04-09 08:17:32 | 00,001,144 | ---- | M] () -- C:\Documents and Settings\Ewa\Dane aplikacji\pcouffin.inf
[2009-04-07 14:14:20 | 00,030,208 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Aktualizacja harmonogramów-80146-85446.xls
[2009-04-07 14:10:48 | 00,028,160 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Aktualizacja harmonogramów 85412-85415-80113.xls
[2009-04-06 16:57:24 | 24,921,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009-04-06 13:07:20 | 00,054,272 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Wzór planów RDW na 2009.1 MDK.xls
[2009-04-03 09:12:18 | 00,108,544 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\zus I PODATKI ROZLICZENIE.xls
[2009-03-31 14:05:20 | 00,000,808 | ---- | M] () -- C:\Documents and Settings\Ewa\Pulpit\HijackThis.lnk
[2009-03-30 15:14:36 | 00,000,076 | -HS- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\desktop.ini
[2009-03-30 15:03:06 | 17,223,168 | ---- | M] (Microsoft Corporation) -- C:\windows_xp_pl.exe
[2009-03-27 08:58:36 | 01,203,922 | ---- | M] () -- C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009-03-26 14:22:28 | 00,054,272 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Wzór planów RDW na 2009.1 SSM.xls
[2009-03-26 13:09:16 | 00,052,224 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Wzór planów RDW na 2009.1.xls
[2009-03-23 14:42:30 | 00,000,946 | ---- | M] () -- C:\WINDOWS\cdplayer.ini
[2009-03-23 12:26:34 | 00,000,151 | ---- | M] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2009-03-23 12:08:02 | 00,021,504 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\PROBIT.doc
[2009-03-23 08:56:08 | 00,065,024 | ---- | M] () -- C:\Documents and Settings\Ewa\Moje dokumenty\Zestawienie zmian.doc
< End of report >
Log z Gmer:
GMER 1.0.15.14966 -
http://www.gmer.net
Rootkit scan 2009-04-21 11:15:31
Windows 5.1.2600 Dodatek Service Pack 3
---- System - GMER 1.0.15 ----
SSDT spwb.sys ZwCreateKey [0xF75C50E0]
SSDT spwb.sys ZwEnumerateKey [0xF75E2CA2]
SSDT spwb.sys ZwEnumerateValueKey [0xF75E3030]
SSDT spwb.sys ZwOpenKey [0xF75C50C0]
SSDT spwb.sys ZwQueryKey [0xF75E3108]
SSDT spwb.sys ZwQueryValueKey [0xF75E2F88]
SSDT spwb.sys ZwSetValueKey [0xF75E319A]
INT 0x62 ? 83BDCBF8
INT 0x63 ? 836F4BF8
INT 0x73 ? 836F4BF8
INT 0x73 ? 836F4BF8
INT 0x82 ? 83BDCBF8
INT 0xA4 ? 836F4BF8
INT 0xB4 ? 836F4BF8
---- Kernel code sections - GMER 1.0.15 ----
? spwb.sys Nie można odnaleźć określonego pliku. !
.text USBPORT.SYS!DllUnload F713D8AC 5 Bytes JMP 836F41D8
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\internet explorer\iexplore.exe[172] USER32.dll!DialogBoxParamW 7E3747AB 5 Bytes JMP 00C09315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[172] USER32.dll!CreateWindowExW 7E37D0A3 5 Bytes JMP 00CE4832 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[172] USER32.dll!DialogBoxIndirectParamW 7E382072 5 Bytes JMP 00DFE021 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[172] USER32.dll!MessageBoxIndirectA 7E38A082 5 Bytes JMP 00DFDF51 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[172] USER32.dll!DialogBoxParamA 7E38B144 5 Bytes JMP 00DFDFBE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[172] USER32.dll!MessageBoxExW 7E3A0838 5 Bytes JMP 00DFDE22 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[172] USER32.dll!MessageBoxExA 7E3A085C 5 Bytes JMP 00DFDE84 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[172] USER32.dll!DialogBoxIndirectParamA 7E3A6D7D 5 Bytes JMP 00DFE084 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[172] USER32.dll!MessageBoxIndirectW 7E3B64D5 5 Bytes JMP 00DFDEE6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!DialogBoxParamW 7E3747AB 5 Bytes JMP 00C09315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00CDDBCB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!CallNextHookEx 7E37B3C6 5 Bytes JMP 00CDDD81 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!CreateWindowExW 7E37D0A3 5 Bytes JMP 00CE4832 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00C41CA2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!DialogBoxIndirectParamW 7E382072 5 Bytes JMP 00DFE021 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!MessageBoxIndirectA 7E38A082 5 Bytes JMP 00DFDF51 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!DialogBoxParamA 7E38B144 5 Bytes JMP 00DFDFBE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!MessageBoxExW 7E3A0838 5 Bytes JMP 00DFDE22 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!MessageBoxExA 7E3A085C 5 Bytes JMP 00DFDE84 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!DialogBoxIndirectParamA 7E3A6D7D 5 Bytes JMP 00DFE084 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] USER32.dll!MessageBoxIndirectW 7E3B64D5 5 Bytes JMP 00DFDEE6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[420] ole32.dll!CoCreateInstance 774F057E 5 Bytes JMP 00CE488E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!DialogBoxParamW 7E3747AB 5 Bytes JMP 00C09315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00CDDBCB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!CallNextHookEx 7E37B3C6 5 Bytes JMP 00CDDD81 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!CreateWindowExW 7E37D0A3 5 Bytes JMP 00CE4832 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00C41CA2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!DialogBoxIndirectParamW 7E382072 5 Bytes JMP 00DFE021 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!MessageBoxIndirectA 7E38A082 5 Bytes JMP 00DFDF51 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!DialogBoxParamA 7E38B144 5 Bytes JMP 00DFDFBE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!MessageBoxExW 7E3A0838 5 Bytes JMP 00DFDE22 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!MessageBoxExA 7E3A085C 5 Bytes JMP 00DFDE84 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!DialogBoxIndirectParamA 7E3A6D7D 5 Bytes JMP 00DFE084 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] USER32.dll!MessageBoxIndirectW 7E3B64D5 5 Bytes JMP 00DFDEE6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[1096] ole32.dll!CoCreateInstance 774F057E 5 Bytes JMP 00CE488E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!DialogBoxParamW 7E3747AB 5 Bytes JMP 00C09315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00CDDBCB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!CallNextHookEx 7E37B3C6 5 Bytes JMP 00CDDD81 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!CreateWindowExW 7E37D0A3 5 Bytes JMP 00CE4832 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00C41CA2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!DialogBoxIndirectParamW 7E382072 5 Bytes JMP 00DFE021 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!MessageBoxIndirectA 7E38A082 5 Bytes JMP 00DFDF51 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!DialogBoxParamA 7E38B144 5 Bytes JMP 00DFDFBE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!MessageBoxExW 7E3A0838 5 Bytes JMP 00DFDE22 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!MessageBoxExA 7E3A085C 5 Bytes JMP 00DFDE84 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!DialogBoxIndirectParamA 7E3A6D7D 5 Bytes JMP 00DFE084 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] USER32.dll!MessageBoxIndirectW 7E3B64D5 5 Bytes JMP 00DFDEE6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2116] ole32.dll!CoCreateInstance 774F057E 5 Bytes JMP 00CE488E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!DialogBoxParamW 7E3747AB 5 Bytes JMP 00C09315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00CDDBCB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!CallNextHookEx 7E37B3C6 5 Bytes JMP 00CDDD81 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!CreateWindowExW 7E37D0A3 5 Bytes JMP 00CE4832 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00C41CA2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!DialogBoxIndirectParamW 7E382072 5 Bytes JMP 00DFE021 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!MessageBoxIndirectA 7E38A082 5 Bytes JMP 00DFDF51 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!DialogBoxParamA 7E38B144 5 Bytes JMP 00DFDFBE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!MessageBoxExW 7E3A0838 5 Bytes JMP 00DFDE22 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!MessageBoxExA 7E3A085C 5 Bytes JMP 00DFDE84 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!DialogBoxIndirectParamA 7E3A6D7D 5 Bytes JMP 00DFE084 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] USER32.dll!MessageBoxIndirectW 7E3B64D5 5 Bytes JMP 00DFDEE6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2184] ole32.dll!CoCreateInstance 774F057E 5 Bytes JMP 00CE488E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!DialogBoxParamW 7E3747AB 5 Bytes JMP 00C09315 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 00CDDBCB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!CallNextHookEx 7E37B3C6 5 Bytes JMP 00CDDD81 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!CreateWindowExW 7E37D0A3 5 Bytes JMP 00CE4832 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00C41CA2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!DialogBoxIndirectParamW 7E382072 5 Bytes JMP 00DFE021 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!MessageBoxIndirectA 7E38A082 5 Bytes JMP 00DFDF51 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!DialogBoxParamA 7E38B144 5 Bytes JMP 00DFDFBE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!MessageBoxExW 7E3A0838 5 Bytes JMP 00DFDE22 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!MessageBoxExA 7E3A085C 5 Bytes JMP 00DFDE84 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!DialogBoxIndirectParamA 7E3A6D7D 5 Bytes JMP 00DFE084 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] USER32.dll!MessageBoxIndirectW 7E3B64D5 5 Bytes JMP 00DFDEE6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3780] ole32.dll!CoCreateInstance 774F057E 5 Bytes JMP 00CE488E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 83B722D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F75F593C] spwb.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F75F5990] spwb.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F75C6040] spwb.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F75C613C] spwb.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F75C60BE] spwb.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F75C67FC] spwb.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F75C66D2] spwb.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 836F42D8
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F75D5D92] spwb.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\internet explorer\iexplore.exe[420] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [017B18FD] C:\Program Files\internet explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\internet explorer\iexplore.exe[1096] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [017B18FD] C:\Program Files\internet explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\internet explorer\iexplore.exe[2116] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [017B18FD] C:\Program Files\internet explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\internet explorer\iexplore.exe[2184] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [017B18FD] C:\Program Files\internet explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\internet explorer\iexplore.exe[3780] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [017B18FD] C:\Program Files\internet explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 83894500
Device \FileSystem\Fastfat \FatCdrom 83BDB1F8
Device \Driver\usbuhci \Device\USBPDO-0 836421F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 83B701F8
Device \Driver\dmio \Device\DmControl\DmConfig 83B701F8
Device \Driver\dmio \Device\DmControl\DmPnP 83B701F8
Device \Driver\dmio \Device\DmControl\DmInfo 83B701F8
Device \Driver\usbuhci \Device\USBPDO-1 836421F8
Device \Driver\usbuhci \Device\USBPDO-2 836421F8
Device \Driver\usbuhci \Device\USBPDO-3 836421F8
Device \Driver\usbehci \Device\USBPDO-4 8362B1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 83BDD1F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 83BDD1F8
Device \Driver\Cdrom \Device\CdRom0 836D9500
Device \Driver\Cdrom \Device\CdRom1 836D9500
Device \Driver\NetBT \Device\NetBt_Wins_Export 837E3500
Device \Driver\NetBT \Device\NetbiosSmb 837E3500
Device \Driver\usbuhci \Device\USBFDO-0 836421F8
Device \Driver\usbuhci \Device\USBFDO-1 836421F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 837D2500
Device \Driver\usbuhci \Device\USBFDO-2 836421F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{7C132743-38D9-48B6-9906-3CD27D1A49C4} 837E3500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 837D2500
Device \Driver\usbuhci \Device\USBFDO-3 836421F8
Device \Driver\usbehci \Device\USBFDO-4 8362B1F8
Device \Driver\Ftdisk \Device\FtControl 83BDD1F8
Device \FileSystem\Fastfat \Fat 83BDB1F8
Device \FileSystem\Cdfs \Cdfs 838CB500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x3E 0x7C 0xCB 0x77 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x3E 0x7C 0xCB 0x77 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x3E 0x7C 0xCB 0x77 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\iexplore@Count 2397
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\iexplore@Count 2397
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore@Count 2396
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\iexplore@Count 2394
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore@Count 787
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore@LoadTimeCount 475
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{29024DC2-9758-A6A4-5F65-D052D00800AF}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{29024DC2-9758-A6A4-5F65-D052D00800AF}@jadlmkejdgdfnkhmodgl 0x69 0x61 0x66 0x67 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{29024DC2-9758-A6A4-5F65-D052D00800AF}@oajlglamoimhnnpdgcbppfagfjopao 0x6A 0x61 0x66 0x67 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{29024DC2-9758-A6A4-5F65-D052D00800AF}@nalceloagoanleiikimnpeoonbjm 0x6A 0x61 0x66 0x67 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{29024DC2-9758-A6A4-5F65-D052D00800AF}@abfmodlgeiepnmcikcicadhhlplmfhhodf 0x65 0x62 0x6D 0x63 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{29024DC2-9758-A6A4-5F65-D052D00800AF}@pafmodlgeiepnmcikcicadhhlpimmhnk 0x64 0x62 0x64 0x67 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{29024DC2-9758-A6A4-5F65-D052D00800AF}@bbkmlggaidhlkenhinldnedfpfeeahkgphjp 0x64 0x62 0x64 0x67 ...
---- EOF - GMER 1.0.15 ----