wkleiłem log bo gdzies na necie podobny problem rozwiązało "zfiksowanie" niektórych logów.
wklejam ten z OTL :
OTL logfile created on: 2010-05-13 15:42:13 - Run 1OTL by OldTimer - Version 3.2.4.1 Folder = D:\Download\POBRANEWindows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstationInternet Explorer (Version = 7.0.6002.18005)Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 68,00% Memory free7,00 Gb Paging File | 6,00 Gb Available in Paging File | 83,00% Paging File freePaging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program FilesDrive C: | 46,82 Gb Total Space | 18,62 Gb Free Space | 39,78% Space Free | Partition Type: NTFSDrive D: | 651,82 Gb Total Space | 171,02 Gb Free Space | 26,24% Space Free | Partition Type: NTFSE: Drive not present or media not loadedF: Drive not present or media not loadedG: Drive not present or media not loadedH: Drive not present or media not loadedI: Drive not present or media not loaded Computer Name: JEZIER-PCCurrent User Name: JezieRLogged in as Administrator. Current Boot Mode: NormalScan Mode: Current userCompany Name Whitelist: OffSkip Microsoft Files: OffFile Age = 30 DaysOutput = Standard ========== Processes (SafeList) ========== PRC - [2010-05-13 15:41:52 | 000,570,880 | ---- | M] (OldTimer Tools) -- D:\Download\POBRANE\OTL.exePRC - [2010-04-26 19:13:25 | 000,531,440 | ---- | M] (Google Inc.) -- C:\Users\JezieR\AppData\Local\Google\Chrome\Application\chrome.exePRC - [2010-04-14 12:29:58 | 000,188,136 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exePRC - [2010-04-14 12:29:58 | 000,141,792 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exePRC - [2010-04-01 23:05:04 | 001,180,976 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exePRC - [2010-03-18 10:01:20 | 000,136,176 | ---- | M] (Google Inc.) -- C:\Users\JezieR\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exePRC - [2010-01-11 22:00:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exePRC - [2010-01-05 18:04:02 | 000,170,144 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exePRC - [2009-12-23 23:34:20 | 000,370,688 | ---- | M] (StarWind Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exePRC - [2009-12-14 21:08:40 | 000,271,480 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exePRC - [2009-10-05 19:03:28 | 002,174,976 | ---- | M] (Gainward Co.) -- C:\Program Files\EXPERTool\TBPANEL.exePRC - [2009-07-17 15:32:00 | 003,576,320 | ---- | M] (Native Instruments GmbH) -- C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exePRC - [2009-04-10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exePRC - [2009-01-23 10:46:14 | 000,203,280 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exePRC - [2009-01-16 16:31:58 | 000,161,064 | ---- | M] (Seagate Technology LLC) -- D:\Programy\Sync\FreeAgentService.exePRC - [2007-11-16 16:13:00 | 000,090,112 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files\WinFast\WFDTV\DTVSchdl.exePRC - [2004-12-13 04:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe ========== Modules (SafeList) ========== MOD - [2010-05-13 15:41:52 | 000,570,880 | ---- | M] (OldTimer Tools) -- D:\Download\POBRANE\OTL.exeMOD - [2009-04-10 23:21:40 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dllMOD - [2009-01-23 10:46:18 | 000,013,840 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\sahook.dllMOD - [2008-01-21 04:24:37 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx ========== Win32 Services (SafeList) ========== SRV - [2010-05-08 00:06:06 | 000,390,952 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)SRV - [2010-04-14 12:29:58 | 000,188,136 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)SRV - [2010-04-14 12:29:58 | 000,141,792 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe -- (mfevtp)SRV - [2010-03-10 11:16:56 | 000,364,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)SRV - [2010-01-11 22:00:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)SRV - [2010-01-05 18:04:02 | 000,170,144 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)SRV - [2009-12-23 23:34:20 | 000,370,688 | ---- | M] (StarWind Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)SRV - [2009-12-14 21:08:40 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)SRV - [2009-12-14 21:08:40 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)SRV - [2009-12-14 21:08:40 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)SRV - [2009-12-14 21:08:40 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)SRV - [2009-12-14 21:08:40 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)SRV - [2009-10-27 10:26:36 | 000,657,408 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)SRV - [2009-09-25 03:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)SRV - [2009-07-17 15:32:00 | 003,576,320 | ---- | M] (Native Instruments GmbH) [Auto | Running] -- C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe -- (NIHardwareService)SRV - [2009-01-23 10:46:14 | 000,203,280 | ---- | M] () [Auto | Running] -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)SRV - [2009-01-16 16:31:58 | 000,161,064 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- D:\Programy\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service)SRV - [2008-01-21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)SRV - [2007-05-31 10:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)SRV - [2007-05-31 10:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)SRV - [2006-06-05 15:22:34 | 001,129,000 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007\RpcSandraSrv.exe -- (SandraTheSrv)SRV - [2006-06-05 15:18:30 | 000,117,288 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007\Win32\RpcDataSrv.exe -- (SandraDataSrv)SRV - [2004-12-13 04:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper) ========== Driver Services (SafeList) ========== DRV - [2010-04-17 23:41:54 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)DRV - [2010-04-14 12:29:58 | 000,385,536 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\mfehidk.sys -- (mfehidk)DRV - [2010-04-14 12:29:58 | 000,312,616 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)DRV - [2010-04-14 12:29:58 | 000,160,720 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)DRV - [2010-04-14 12:29:58 | 000,152,320 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)DRV - [2010-04-14 12:29:58 | 000,095,568 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)DRV - [2010-04-14 12:29:58 | 000,083,496 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)DRV - [2010-04-14 12:29:58 | 000,064,304 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)DRV - [2010-04-14 12:29:58 | 000,055,456 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cfwids.sys -- (cfwids)DRV - [2010-04-14 12:29:58 | 000,051,688 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)DRV - [2009-11-28 23:49:35 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)DRV - [2009-11-28 23:49:34 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)DRV - [2009-10-06 12:52:50 | 000,007,936 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)DRV - [2009-10-06 12:52:34 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)DRV - [2009-10-06 12:52:34 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)DRV - [2009-10-06 12:52:34 | 000,007,936 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)DRV - [2009-08-04 18:56:26 | 000,040,560 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\hotcore3.sys -- (hotcore3)DRV - [2009-04-10 21:42:54 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (winusb)DRV - [2008-12-25 00:56:42 | 000,433,792 | ---- | M] (Leadtek Research Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wfeaglxt.sys -- (WFLR6654) WinFast TV2000 XP Expert (FM1216MK3)DRV - [2008-08-26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)DRV - [2008-05-16 20:31:00 | 007,465,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)DRV - [2008-01-21 04:23:27 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)DRV - [2008-01-21 04:23:27 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)DRV - [2008-01-21 04:23:27 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)DRV - [2008-01-21 04:23:26 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)DRV - [2008-01-21 04:23:26 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)DRV - [2008-01-21 04:23:26 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)DRV - [2008-01-21 04:23:25 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)DRV - [2008-01-21 04:23:25 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R)DRV - [2008-01-21 04:23:25 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)DRV - [2008-01-21 04:23:24 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)DRV - [2008-01-21 04:23:24 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)DRV - [2008-01-21 04:23:24 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)DRV - [2008-01-21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)DRV - [2008-01-21 04:23:23 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)DRV - [2008-01-21 04:23:23 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)DRV - [2008-01-21 04:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)DRV - [2008-01-21 04:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)DRV - [2008-01-21 04:23:23 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)DRV - [2008-01-21 04:23:22 | 000,342,584 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)DRV - [2008-01-21 04:23:21 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)DRV - [2008-01-21 04:23:21 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)DRV - [2008-01-21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)DRV - [2008-01-21 04:23:20 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)DRV - [2008-01-21 04:23:00 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)DRV - [2008-01-21 04:23:00 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)DRV - [2008-01-21 04:23:00 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)DRV - [2007-12-15 18:38:46 | 000,014,672 | ---- | M] (OpenLibSys.org) [Kernel | On_Demand | Stopped] -- D:\Download\POBRANE\setfsb_2_2_134_98\WinRing0.sys -- (WinRing0_1_0_1)DRV - [2007-11-06 09:06:48 | 000,131,672 | ---- | M] (Paragon) [Kernel | System | Running] -- C:\Windows\System32\drivers\Uim_IM.sys -- (Uim_IM)DRV - [2007-11-06 09:06:48 | 000,032,080 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | System | Running] -- C:\Windows\System32\drivers\UimBus.sys -- (UimBus)DRV - [2007-03-16 11:11:38 | 000,012,256 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\TBPanel.sys -- (TBPanel)DRV - [2007-03-16 11:11:38 | 000,012,256 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TBPanel.sys -- (Cardex)DRV - [2006-11-10 15:08:50 | 000,024,064 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\ATITool.sys -- (ATITool)DRV - [2006-11-02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)DRV - [2006-11-02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)DRV - [2006-11-02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)DRV - [2006-11-02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)DRV - [2006-11-02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)DRV - [2006-11-02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)DRV - [2006-11-02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)DRV - [2006-11-02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)DRV - [2006-11-02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)DRV - [2006-11-02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)DRV - [2006-11-02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)DRV - [2006-11-02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)DRV - [2006-11-02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)DRV - [2006-11-02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)DRV - [2006-11-02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)DRV - [2006-11-02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)DRV - [2006-11-02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)DRV - [2006-11-02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)DRV - [2005-10-10 10:24:24 | 000,019,416 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007\sandra.sys -- (SANDRA)DRV - [2005-01-06 16:55:38 | 000,009,446 | ---- | M] (Leadtek Research Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\WinFast\WFDTV\WFIOCTL.sys -- (WFIOCTL)DRV - [2002-09-16 17:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\PQNTDRV.sys -- (PQNTDrv) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htmIE - HKLM\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.) IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1098640IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1IE - HKCU\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "free-downloads.net Customized Web Search"FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource=3&q={searchTerms}"FF - prefs.js..browser.search.selectedEngine: "free-downloads.net Customized Web Search"FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT1098640&SearchSource=13"FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.5.0FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.8FF - prefs.js..extensions.enabledItems: bkmrksync@nokia.com:1.0.0.723FF - prefs.js..extensions.enabledItems: {ecdee021-0d17-467f-a1ff-c7a115230949}:2.5.6.0 FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010-03-03 00:21:59 | 000,000,000 | ---D | M]FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009-12-24 21:27:52 | 000,000,000 | ---D | M]FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-04-28 15:46:57 | 000,000,000 | ---D | M]FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-04-26 16:30:57 | 000,000,000 | ---D | M] [2009-10-16 00:46:53 | 000,000,000 | ---D | M] -- C:\Users\JezieR\AppData\Roaming\Mozilla\Extensions[2010-05-12 23:52:35 | 000,000,000 | ---D | M] -- C:\Users\JezieR\AppData\Roaming\Mozilla\Firefox\Profiles\vckpysma.default\extensions[2009-10-16 20:30:50 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\JezieR\AppData\Roaming\Mozilla\Firefox\Profiles\vckpysma.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}[2010-01-26 22:17:20 | 000,000,000 | ---D | M] (ReloadEvery) -- C:\Users\JezieR\AppData\Roaming\Mozilla\Firefox\Profiles\vckpysma.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}[2010-04-17 23:45:26 | 000,000,000 | ---D | M] (free-downloads.net Toolbar) -- C:\Users\JezieR\AppData\Roaming\Mozilla\Firefox\Profiles\vckpysma.default\extensions\{ecdee021-0d17-467f-a1ff-c7a115230949}[2010-01-26 19:51:14 | 000,000,000 | ---D | M] -- C:\Users\JezieR\AppData\Roaming\Mozilla\Firefox\Profiles\vckpysma.default\extensions\firebug@software.joehewitt.com[2010-01-27 19:58:15 | 000,000,000 | ---D | M] -- C:\Users\JezieR\AppData\Roaming\Mozilla\Firefox\Profiles\vckpysma.default\extensions\staged-xpis[2010-01-20 12:16:28 | 000,000,939 | ---- | M] () -- C:\Users\JezieR\AppData\Roaming\Mozilla\Firefox\Profiles\vckpysma.default\searchplugins\conduit.xml[2009-12-18 15:45:23 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions[2010-04-14 12:29:58 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Mozilla Firefox\components\Scriptff.dll[2009-10-14 23:51:28 | 000,120,296 | ---- | M] ( ) -- C:\Program Files\Mozilla Firefox\plugins\npganymedenet.dll[2009-08-24 21:19:13 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml[2009-08-24 21:19:13 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml[2009-08-24 21:19:13 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml[2009-08-24 21:19:13 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml[2009-08-24 21:19:13 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml[2009-08-24 21:19:13 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2010-04-23 16:05:10 | 000,000,990 | ---- | M]) - C:\Windows\System32\drivers\etc\hostsO1 - Hosts: 127.0.0.1 localhostO1 - Hosts: ::1 localhostO1 - Hosts: 127.0.0.1 static3.cdn.ubi.comO1 - Hosts: 127.0.0.1 ubisoft-orbit.s3.amazonaws.comO1 - Hosts: 127.0.0.1 onlineconfigservice.ubi.comO1 - Hosts: 127.0.0.1 orbitservice.ubi.comO1 - Hosts: 127.0.0.1 ubisoft-orbit-savegames.s3.amazonaws.comO1 - Hosts: O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100428154657.dll (McAfee, Inc.)O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()O2 - BHO: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()O3 - HKLM\..\Toolbar: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)O3 - HKCU\..\Toolbar\WebBrowser: (free-downloads.net Toolbar) - {ECDEE021-0D17-467F-A1FF-C7A115230949} - C:\Program Files\free-downloads.net\tbfree.dll (Conduit Ltd.)O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)O4 - HKLM..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe (Leadtek Research Inc.)O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)O4 - HKCU..\Run: [GAINWARD] C:\Program Files\EXPERTool\TBPanel.exe (Gainward Co.)O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)O13 - gopher Prefix: missingO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)O24 - Desktop WallPaper: C:\Users\JezieR\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpgO24 - Desktop BackupWallPaper: C:\Users\JezieR\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpgO28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)O32 - HKLM CDRom: AutoRun - 1O32 - AutoRun File - [2009-12-28 01:38:22 | 000,000,026 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]O32 - AutoRun File - [2006-09-18 23:43:36 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]O33 - MountPoints2\{18e21256-a05e-11de-abe6-00219b0151e9}\Shell\AutoRun\command - "" = E:\ph.exe -- File not foundO33 - MountPoints2\{18e21256-a05e-11de-abe6-00219b0151e9}\Shell\open\Command - "" = E:\ph.exe -- File not foundO33 - MountPoints2\{5e0d15eb-f2d6-11de-b391-00219b0151e9}\Shell - "" = AutoRunO33 - MountPoints2\{5e0d15eb-f2d6-11de-b391-00219b0151e9}\Shell\AutoRun\command - "" = K:\autorun.exe -- File not foundO33 - MountPoints2\{7fbc0ee1-affb-11de-b5bf-00219b0151e9}\Shell\AutoRun\command - "" = E:\wrsf.exe -- File not foundO33 - MountPoints2\{7fbc0ee1-affb-11de-b5bf-00219b0151e9}\Shell\open\Command - "" = E:\wrsf.exe -- File not foundO33 - MountPoints2\{7fbc0ee5-affb-11de-b5bf-00219b0151e9}\Shell\AutoRun\command - "" = K:\wrsf.exe -- File not foundO33 - MountPoints2\{7fbc0ee5-affb-11de-b5bf-00219b0151e9}\Shell\open\Command - "" = K:\wrsf.exe -- File not foundO33 - MountPoints2\{e78877f1-924b-11de-aae4-00219b0151e9}\Shell - "" = AutoRunO33 - MountPoints2\{e78877f1-924b-11de-aae4-00219b0151e9}\Shell\AutoRun\command - "" = L:\autorun.exe -- File not foundO34 - HKLM BootExecute: (autocheck autochk *) - File not foundO35 - HKLM\..comfile [open] -- "%1" %*O35 - HKLM\..exefile [open] -- "%1" %*O37 - HKLM\...com [@ = comfile] -- "%1" %*O37 - HKLM\...exe [@ = exefile] -- "%1" %*O37 - HKCU\...com [@ = comfile] -- Reg Error: Key error. File not foundO37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found ========== Files/Folders - Created Within 30 Days ========== [2010-05-12 22:10:07 | 000,000,000 | --SD | C] -- C:\ComboFix[2010-05-12 22:09:47 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe[2010-05-12 21:24:40 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe[2010-05-12 21:24:40 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe[2010-05-12 21:24:40 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe[2010-05-12 21:21:05 | 000,318,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CF1829.exe[2010-05-12 21:20:38 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT[2010-05-12 21:20:37 | 000,318,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CF1659.exe[2010-05-12 21:20:17 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\swsc.exe[2010-05-12 21:20:15 | 000,000,000 | ---D | C] -- C:\Qoobox[2010-05-11 23:01:12 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent[2010-04-24 18:01:04 | 000,000,000 | ---D | C] -- C:\Program Files\Audio Phonics, Inc[2010-04-24 18:00:16 | 000,299,520 | ---- | C] (InstallShield Corporation, Inc.) -- C:\Windows\uninst.exe[2010-04-23 16:05:17 | 000,000,000 | ---D | C] -- C:\Users\JezieR\Desktop\AC2 Emulator 0.44[2010-04-23 15:58:22 | 000,000,000 | ---D | C] -- C:\Program Files\Ubisoft[2010-04-21 15:23:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe[2010-04-21 15:00:31 | 000,000,000 | ---D | C] -- C:\Program Files\Free PDF to Word Doc Converter[2010-04-18 23:06:59 | 000,009,344 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeclnk.sys[2010-04-18 23:06:30 | 000,385,536 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfehidk.sys[2010-04-18 23:06:30 | 000,312,616 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfefirek.sys[2010-04-18 23:06:30 | 000,160,720 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfewfpk.sys[2010-04-18 23:06:30 | 000,152,320 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeavfk.sys[2010-04-18 23:06:30 | 000,095,568 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeapfk.sys[2010-04-18 23:06:30 | 000,083,496 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mferkdet.sys[2010-04-18 23:06:30 | 000,064,304 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfenlfk.sys[2010-04-18 23:06:30 | 000,055,456 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\cfwids.sys[2010-04-18 23:06:30 | 000,051,688 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfebopk.sys[2010-04-18 22:36:08 | 000,000,000 | ---D | C] -- C:\Users\JezieR\Documents\Native Instruments[2010-04-18 22:35:52 | 000,000,000 | -H-D | C] -- C:\ProgramData\{D69A48BF-7653-4AA8-94BC-5847522A4573}[2010-04-18 22:34:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Digidesign[2010-04-18 22:34:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Native Instruments[2010-04-18 22:34:35 | 000,000,000 | -H-D | C] -- C:\ProgramData\{0CC51CB2-911C-40BB-BC1B-BD3CAC590222}[2010-04-18 22:34:16 | 000,000,000 | -H-D | C] -- C:\ProgramData\{D7CFB71A-972A-44FF-AE44-8780EB53ABB2}[2010-04-18 22:34:13 | 000,000,000 | ---D | C] -- C:\Program Files\Native Instruments[2010-04-18 22:34:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Native Instruments[2010-04-17 23:45:27 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit[2010-04-17 23:45:26 | 000,000,000 | ---D | C] -- C:\Program Files\free-downloads.net[2010-04-17 23:44:37 | 000,000,000 | ---D | C] -- C:\Program Files\Alcohol Soft[2010-04-17 21:54:19 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight[2010-04-17 21:25:33 | 000,000,000 | ---D | C] -- C:\Users\JezieR\AppData\Roaming\ipla[2010-04-17 21:25:33 | 000,000,000 | ---D | C] -- C:\ProgramData\ipla[2010-04-14 17:53:43 | 003,600,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe[2010-04-14 17:53:43 | 003,548,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe[2010-04-14 17:53:41 | 000,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll[2010-04-14 17:53:31 | 000,220,672 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\System32\l3codecp.acm[2010-04-14 17:53:31 | 000,062,464 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\System32\l3codeca.acm[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ][1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010-05-13 15:45:14 | 006,291,456 | -HS- | M] () -- C:\Users\JezieR\NTUSER.DAT[2010-05-13 15:39:56 | 000,001,062 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1700171713-3824331562-2899236527-1000UA.job[2010-05-13 15:39:56 | 000,001,036 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job[2010-05-13 15:39:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat[2010-05-13 14:29:09 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk[2010-05-13 14:20:48 | 000,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI[2010-05-13 14:20:48 | 000,586,980 | ---- | M] () -- C:\Windows\System32\perfh009.dat[2010-05-13 14:20:48 | 000,101,052 | ---- | M] () -- C:\Windows\System32\perfc009.dat[2010-05-13 14:15:03 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job[2010-05-13 14:14:30 | 000,003,840 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0[2010-05-13 14:14:30 | 000,003,840 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0[2010-05-13 14:14:29 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT[2010-05-13 00:42:02 | 000,524,288 | -HS- | M] () -- C:\Users\JezieR\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms[2010-05-13 00:42:02 | 000,065,536 | -HS- | M] () -- C:\Users\JezieR\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf[2010-05-13 00:41:44 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat[2010-05-13 00:41:31 | 002,830,116 | -H-- | M] () -- C:\Users\JezieR\AppData\Local\IconCache.db[2010-05-12 23:21:41 | 000,000,641 | ---- | M] () -- C:\Users\JezieR\Desktop\World of Warcraft.lnk[2010-05-12 22:49:41 | 000,000,780 | ---- | M] () -- C:\Users\JezieR\Desktop\HijackThis - Shortcut.lnk[2010-05-12 21:21:30 | 003,686,869 | R--- | M] () -- C:\Users\JezieR\Desktop\ComboFix.exe[2010-05-12 21:21:00 | 000,318,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\CF1829.exe[2010-05-12 21:20:08 | 000,318,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\CF1659.exe[2010-05-12 18:29:36 | 002,333,736 | ---- | M] () -- C:\Users\JezieR\P5111466.JPG[2010-05-12 18:29:13 | 002,851,360 | ---- | M] () -- C:\Users\JezieR\P5111456.JPG[2010-05-11 23:01:14 | 000,000,752 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk[2010-05-11 18:18:06 | 002,840,849 | ---- | M] () -- C:\Users\JezieR\P5111468.JPG[2010-05-11 18:17:32 | 003,296,361 | ---- | M] () -- C:\Users\JezieR\P5111467.JPG[2010-05-11 18:12:36 | 002,499,277 | ---- | M] () -- C:\Users\JezieR\P5111463.JPG[2010-05-11 18:11:14 | 003,520,044 | ---- | M] () -- C:\Users\JezieR\P5111462.JPG[2010-05-11 18:11:02 | 003,155,369 | ---- | M] () -- C:\Users\JezieR\P5111461.JPG[2010-05-11 18:06:50 | 002,950,571 | ---- | M] () -- C:\Users\JezieR\P5111460.JPG[2010-05-11 18:04:14 | 003,822,086 | ---- | M] () -- C:\Users\JezieR\P5111457.JPG[2010-05-09 16:40:45 | 000,029,696 | ---- | M] () -- C:\Users\JezieR\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini[2010-05-05 16:52:00 | 000,015,561 | ---- | M] () -- C:\Users\JezieR\Desktop\JezieR.wpl[2010-04-30 12:40:06 | 000,584,267 | ---- | M] () -- C:\Users\JezieR\Desktop\dddd.xps[2010-04-30 12:22:37 | 000,379,736 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT[2010-04-29 19:38:32 | 000,002,257 | ---- | M] () -- C:\Users\JezieR\Desktop\Ventrilo.lnk[2010-04-26 17:15:22 | 000,017,227 | ---- | M] () -- C:\Users\JezieR\Desktop\fiZyka.docx[2010-04-26 16:30:58 | 000,001,887 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk[2010-04-26 15:58:12 | 000,256,512 | ---- | M] () -- C:\Windows\PEV.exe[2010-04-24 18:01:06 | 000,001,082 | ---- | M] () -- C:\Users\JezieR\Desktop\AP Guitar Tuner 1.02.lnk[2010-04-23 16:05:50 | 000,000,491 | ---- | M] () -- C:\Users\JezieR\Desktop\Assassins Creed II.lnk[2010-04-23 16:05:10 | 000,000,990 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts[2010-04-21 15:00:31 | 000,000,862 | ---- | M] () -- C:\Users\JezieR\Desktop\Free PDF to Word Doc Converter.lnk[2010-04-18 22:35:46 | 000,000,589 | ---- | M] () -- C:\Users\Public\Desktop\Guitar Rig 4.lnk[2010-04-17 23:59:02 | 000,000,110 | ---- | M] () -- C:\Users\JezieR\Documents\ax_files.xml[2010-04-17 23:45:12 | 000,000,973 | ---- | M] () -- C:\Users\Public\Desktop\Alcohol 120%.lnk[2010-04-17 23:41:54 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) -- C:\Windows\System32\drivers\sptd.sys[2010-04-17 21:25:32 | 000,000,458 | ---- | M] () -- C:\Users\Public\Desktop\ipla.lnk[2010-04-14 12:29:58 | 000,385,536 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfehidk.sys[2010-04-14 12:29:58 | 000,312,616 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfefirek.sys[2010-04-14 12:29:58 | 000,160,720 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfewfpk.sys[2010-04-14 12:29:58 | 000,152,320 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeavfk.sys[2010-04-14 12:29:58 | 000,095,568 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeapfk.sys[2010-04-14 12:29:58 | 000,083,496 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mferkdet.sys[2010-04-14 12:29:58 | 000,064,304 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfenlfk.sys[2010-04-14 12:29:58 | 000,055,456 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\cfwids.sys[2010-04-14 12:29:58 | 000,051,688 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfebopk.sys[2010-04-14 12:29:58 | 000,009,344 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeclnk.sys[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ][1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2010-05-13 14:29:09 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk[2010-05-12 22:49:41 | 000,000,780 | ---- | C] () -- C:\Users\JezieR\Desktop\HijackThis - Shortcut.lnk[2010-05-12 22:43:51 | 000,008,747 | ---- | C] () -- C:\Users\JezieR\hijackthis.log[2010-05-12 21:24:40 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe[2010-05-12 21:24:40 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe[2010-05-12 21:24:40 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe[2010-05-12 21:24:40 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe[2010-05-12 21:24:40 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe[2010-05-12 21:20:38 | 003,686,869 | R--- | C] () -- C:\Users\JezieR\Desktop\ComboFix.exe[2010-05-12 18:28:47 | 002,840,849 | ---- | C] () -- C:\Users\JezieR\P5111468.JPG[2010-05-12 18:28:43 | 003,296,361 | ---- | C] () -- C:\Users\JezieR\P5111467.JPG[2010-05-12 18:28:34 | 003,520,044 | ---- | C] () -- C:\Users\JezieR\P5111462.JPG[2010-05-12 18:28:34 | 003,155,369 | ---- | C] () -- C:\Users\JezieR\P5111461.JPG[2010-05-12 18:28:34 | 002,950,571 | ---- | C] () -- C:\Users\JezieR\P5111460.JPG[2010-05-12 18:28:34 | 002,499,277 | ---- | C] () -- C:\Users\JezieR\P5111463.JPG[2010-05-12 18:28:34 | 002,333,736 | ---- | C] () -- C:\Users\JezieR\P5111466.JPG[2010-05-12 18:28:33 | 003,822,086 | ---- | C] () -- C:\Users\JezieR\P5111457.JPG[2010-05-12 18:28:33 | 002,851,360 | ---- | C] () -- C:\Users\JezieR\P5111456.JPG[2010-05-11 23:01:14 | 000,000,752 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk[2010-04-30 12:40:04 | 000,584,267 | ---- | C] () -- C:\Users\JezieR\Desktop\dddd.xps[2010-04-24 18:01:06 | 000,001,082 | ---- | C] () -- C:\Users\JezieR\Desktop\AP Guitar Tuner 1.02.lnk[2010-04-23 16:05:50 | 000,000,491 | ---- | C] () -- C:\Users\JezieR\Desktop\Assassins Creed II.lnk[2010-04-21 15:23:24 | 000,001,887 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk[2010-04-21 15:00:31 | 000,000,862 | ---- | C] () -- C:\Users\JezieR\Desktop\Free PDF to Word Doc Converter.lnk[2010-04-18 22:35:46 | 000,000,589 | ---- | C] () -- C:\Users\Public\Desktop\Guitar Rig 4.lnk[2010-04-17 23:50:15 | 000,000,110 | ---- | C] () -- C:\Users\JezieR\Documents\ax_files.xml[2010-04-17 23:45:12 | 000,000,973 | ---- | C] () -- C:\Users\Public\Desktop\Alcohol 120%.lnk[2010-04-17 21:25:32 | 000,000,458 | ---- | C] () -- C:\Users\Public\Desktop\ipla.lnk[2009-12-24 22:05:34 | 001,032,192 | ---- | C] () -- C:\Windows\System32\vorbisenc.dll[2009-12-24 22:05:34 | 000,102,400 | ---- | C] () -- C:\Windows\System32\vorbisfile.dll[2009-12-24 22:05:33 | 001,253,376 | ---- | C] () -- C:\Windows\System32\vorbis.dll[2009-12-24 22:05:33 | 000,061,440 | ---- | C] () -- C:\Windows\System32\ogg.dll[2009-11-28 23:49:35 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys[2009-11-28 23:49:34 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys[2009-11-06 11:58:04 | 000,178,975 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat[2009-08-29 16:54:55 | 000,011,568 | ---- | C] () -- C:\Windows\System32\drivers\UimFIO.sys[2009-08-29 16:54:20 | 000,013,576 | ---- | C] () -- C:\Windows\System32\wnaspi32.dll[2009-08-22 13:47:07 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll[2009-08-03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll[2008-07-10 10:44:23 | 000,007,237 | ---- | C] () -- C:\Windows\cadx2.ini[2006-11-10 15:08:50 | 000,024,064 | ---- | C] () -- C:\Windows\System32\drivers\ATITool.sys[2006-11-02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll[2006-11-02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini ========== Alternate Data Streams ========== @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:DFC5A2B2< End of report >
i "extras?" z otl :
niewiem czy tylko ja nie mam takiej opcji jak spoiler albo cos takiego ?
bo w tej chwili kółeczko mychy wymieka...
// jest codebox / mac
Użytkownik Macsch15 edytował ten post 13 05 2010 - 15:49