Skocz do zawartości


Zdjęcie

Usypianie Visty


  • Zamknięty Temat jest zamknięty
6 odpowiedzi w tym temacie

#1 Jezierski

Jezierski

    Nie truć na gg.

  • 351 postów

Napisano 09 03 2009 - 17:04

Siema, miałem do niedawna english wersje win vista , w menu start było sleep i często z tego korzystałem lecz zdecydowałem się spolszczyć ją bo miałem czasami małe problemy. Wszystko ok po polsku tylko nie ma uśpij a jest wstrzymaj i jest też taki znaczek... " Zapisuje sesje i przełącza komputer w stan niskiego poboru energii..."

No i jest problem taki że w eng wersji gdy klikałem sleep to on najpierw przyspieszał działanie coolerów i po chwili nie było go słychac ... był na tzw. czuwaniu a teraz gdy klikam np. wstrzymaj to tylko monitor się czarny robi i pisze entering power saving czy cos ale komputer słychać nadal : / raz mi się udało go uśpić niewiem jak... czy to jakiś błąd i może jest jakać komenda gdzie moge uśpić go ręcznie ? : / :)

  • 0

#2 Macsch15

Macsch15

    Profesjonalista

  • 3 705 postów

Napisano 09 03 2009 - 17:57

Spróbuj go z hibernować
Dołączona grafika

  • 0

#3 Jezierski

Jezierski

    Nie truć na gg.

  • 351 postów

Napisano 09 03 2009 - 18:27

no mam tam zaznaczone że jest to włączone : /
  • 0

#4 Macsch15

Macsch15

    Profesjonalista

  • 3 705 postów

Napisano 11 03 2009 - 16:13

Podobne problemy :
http://peb.pl/logi-do-sprawdzenia/308382-v...hibernacja.html
Też coś w tym temacie :
http://forum.dobreprogramy.pl/\/viewt...22&t=220564


spróbuj zaktualizować vistę ...

Aha i u mnie jest to samo ( NA XP ) tyle że jak go włączę w stań uśpienia to procuje tylko wiatraczek od zasilacza...
Ale nie próbowałem tego w żaden sposób naprawić/zmienić bo bardzo rzadko korzystam ze stanu uśpienia :)
  • 0

#5 Jezierski

Jezierski

    Nie truć na gg.

  • 351 postów

Napisano 12 03 2009 - 22:19

niestety nie znalazłem nic co by MI pomogło ale widze że tam koleś miał jakiegoś wirusa w logach.. tu masz logi z hijack this:
CODE-BOX
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:32:01, on 2008-11-02
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Windows\system32\svchost.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\conime.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\ehome\ehtray.exe
C:\Programy\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\ANDRZEJ\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\notepad.exe
C:\Users\ANDRZEJ\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\ANDRZEJ\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\mcupdate.EXE
C:\Windows\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL (file missing)
O2 - BHO: Game.OS - {3A303EF6-2598-4D2D-B4DA-DEFA7CD0DC51} - C:\Windows\system32\ifsndu.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL (file missing)
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SoftickPPP] "C:\Program Files\Softick\PPP\Bin\PPPGate.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programy\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Google Update] "C:\Users\ANDRZEJ\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O13 - Gopher Prefix:
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Futuremark Measurement Services Client) - http://www.yougamers.com/systeminfo/MSC3.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
A TUTAJ Z ComboFix:

c:\program files\Mozilla Firefox\components\bvvzwunmegp.dll
c:\program files\Mozilla Firefox\components\e7cfca94-11a7-0944-abae-1e8866418a8b.dll
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\5066b423-da47-6ff4-1be7-2c95a3bc78b4
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\636E.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\7020.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\8627.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\9547.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\Antiphishing Component Update 8
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\B3D5.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\BEAB.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\Component Update 216
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\Component Update 367
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\Component Update 474
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\Component Update 506
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\Component Update 534
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\Component Update 651
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\Component Update 736
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\Component Update 904
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\D218.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\E449.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\FB34.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1074.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1093.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp10B9.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp118.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp12EA.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1370.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp13A6.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp13BE.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp13CE.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp13FC.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp147.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1506.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp16AB.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp18CD.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp19D6.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp19ED.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1A91.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1B0E.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1CB3.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1D94.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1DDA.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1E78.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1FDE.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp1FFE.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2236.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp225E.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2413.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp24CE.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2589.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp25F6.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp286.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2866.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2B72.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2C0E.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2C43.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2E.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2E50.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2EAD.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp2FE4.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp301C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3069.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3072.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp30FE.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp31C9.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp32AA.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3365.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp33BC.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp34CD.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3542.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp362C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp363C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp36D6.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp372C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3745.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3901.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3A60.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3B61.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3B8A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3BAF.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3DD8.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3ED.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3F02.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp3F10.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp402A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp40CE.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp40D6.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp410C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4134.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4198.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4205.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp428B.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4336.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4365.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp449C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp44C4.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp453.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp482.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4A47.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4A8.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4ABC.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4B8E.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4BB6.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4D53.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4DA9.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp4EF.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5002.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp50EB.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5108.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp517C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp51B6.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5247.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp527F.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5292.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp538B.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp53AA.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5437.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5612.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp56CE.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp573A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp586D.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5926.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5A10.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5A43.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5AE3.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5B60.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5BDC.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5CE6.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5D.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp5D9.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp60F.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp62E1.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp62EE.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp636A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp637A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp63E0.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp640A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp6454.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp656.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp694.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp6B08.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp6CAE.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp6CCD.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp6D12.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp6EB1.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp6FE1.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp715F.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp7249.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp7362.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp73C0.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp747A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp7584.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp758C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp76F.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp7BD.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp7BEA.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp7F05.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp7FDF.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp812.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp825F.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp8488.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp8572.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp85A2.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp8617.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp87E4.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp8B4D.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp8BB3.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp8C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp8C0F.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp8FBF.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp904.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp9054.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp91BB.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp9470.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp9490.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp97A4.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp985F.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp9A0.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmp9B4B.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpA0F5.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpA286.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpA4C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpA4E5.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpA542.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpA654.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpA8A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpA8FB.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpA977.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpAAA7.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpAB91.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpABC8.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpACA3.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpAD8D.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpAF30.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpB033.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpB4A5.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpB74D.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpB835.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpB918.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpB966.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpB99C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpBB8F.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpBD63.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpBF11.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpC26A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpC2FF.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpC528.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpC85E.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpCA85.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpD2CA.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpD5AC.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpD83C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpD87A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpD8DF.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpDB50.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpDB56.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpDC30.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpDE44.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpE028.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpE178.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpE44C.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpE60.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpE61A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpE69D.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpE758.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpE9C7.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpEAF8.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpEB3F.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpEF92.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpEFF0.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF037.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF075.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF0B4.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF102.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF1CD.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF212.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF21B.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF277.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF278.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF2F5.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF40D.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF466.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF4E8.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF575.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF601.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF66E.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF67E.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF6DA.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF6DC.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF72A.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF749.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF778.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF797.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF7A6.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF7C6.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF814.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF843.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpF871.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpFA55.tmp
c:\users\ANDRZEJ\AppData\Local\Microsoft\Windows\Temporary Internet Files\tmpFCB3.tmp
c:\users\ANDRZEJ\AppData\Roaming\Microsoft\Windows\Start Menu\Cheap Pharmacy Online.url
c:\users\ANDRZEJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lsass.exe
c:\users\ANDRZEJ\AppData\Roaming\Microsoft\Windows\Start Menu\Search Online.url
c:\users\ANDRZEJ\AppData\Roaming\Microsoft\Windows\Start Menu\SMS TRAP.url
c:\users\ANDRZEJ\AppData\Roaming\Microsoft\Windows\Start Menu\VIP Casino.url
c:\users\ANDRZEJ\FAVORI~1\Search Online.url
c:\users\ANDRZEJ\FAVORI~1\SMS TRAP.url
c:\users\ANDRZEJ\Favorites\Search Online.url
c:\users\ANDRZEJ\Favorites\SMS TRAP.url
c:\windows\system32\bvvzwunmegp.dll
c:\windows\system32\rmwiclyqepi.dll

.
((((((((((((((((((((((((( Pliki utworzone od 2009-02-12 do 2009-03-12 )))))))))))))))))))))))))))))))
.

2009-03-11 10:46 . 2008-12-16 04:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 10:46 . 2009-02-09 04:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 10:46 . 2008-11-27 05:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-11 10:46 . 2008-12-16 06:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 10:46 . 2008-12-16 06:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 10:46 . 2008-12-16 06:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-06 00:17 . 2009-03-06 11:07 48,276 --a------ c:\windows\System32\mmycgxlstgpobtwc.exe
2009-03-04 22:59 . 2009-03-04 22:59 <DIR> d-------- c:\windows\pl-PL
2009-03-04 22:51 . 2006-10-22 08:45 632,592 --a------ c:\windows\icardres.dll.mui
2009-03-02 16:15 . 2009-03-02 16:15 622,080 --a------ c:\windows\System32\nsw3C20.dll
2009-02-24 18:56 . 2009-02-24 19:01 <DIR> d-------- C:\fILMY
2009-02-16 21:43 . 2009-02-16 21:43 <DIR> d-------- c:\users\ANDRZEJ\AppData\Roaming\23doors
2009-02-16 21:38 . 2009-02-16 21:38 <DIR> d-------- c:\users\ANDRZEJ\.spidek
2009-02-16 21:38 . 2009-02-16 21:38 <DIR> d-------- c:\program files\Spidek
2009-02-13 01:24 . 2009-02-13 01:24 <DIR> d-------- c:\users\All Users\Blizzard
2009-02-13 01:24 . 2009-02-13 01:24 <DIR> d-------- c:\programdata\Blizzard
2009-02-12 20:18 . 2009-02-12 20:18 9 --a------ c:\windows\wiatraczki.ini

.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-12 18:15 1,498 ----a-w c:\users\ANDRZEJ\AppData\Roaming\wklnhst.dat
2009-03-12 18:05 --------- d---a-w c:\programdata\TEMP
2009-03-12 18:05 --------- d-----w c:\program files\Spyware Doctor
2009-03-12 18:01 --------- d-----w c:\program files\Common Files\Adobe
2009-03-12 17:42 --------- d-----w c:\program files\Windows Mail
2009-03-06 13:05 49,152 ----a-w c:\windows\Help\AIMBOT.EXE
2009-03-05 23:16 --------- d-----w c:\program files\EXPERTool
2009-03-03 23:22 85,647 ----a-w c:\windows\System32\e17ff77f-a087-f2dc-def4-8e1fa092f91b.exe
2009-03-01 18:34 --------- d-----w c:\program files\NCH Software
2009-02-24 18:27 --------- d-----w c:\program files\DivX
2009-02-24 16:16 --------- d-----w c:\program files\Google
2009-02-21 16:45 69,158 ----a-w c:\windows\System32\bvvzwunmegp.dll-uninst.exe
2009-02-07 10:08 --------- d-----w c:\programdata\Electronic Arts
2009-02-06 11:40 8,116 ----a-w c:\windows\System32\ealregsnapshot1.reg
2009-02-06 10:51 --------- d-----w c:\program files\7-Zipnur2
2009-01-24 21:28 --------- d-----w c:\program files\ReflexiveArcade
2009-01-22 17:02 --------- d-----w c:\users\ANDRZEJ\AppData\Roaming\FileZilla
2009-01-22 16:05 --------- d-----w c:\users\ANDRZEJ\AppData\Roaming\GHISLER
2009-01-22 15:38 --------- d-----w c:\programdata\NCH Swift Sound
2009-01-22 15:38 --------- d-----w c:\program files\NCH Swift Sound
2009-01-22 15:35 --------- d-----w c:\users\ANDRZEJ\AppData\Roaming\NCH Swift Sound
2009-01-22 15:35 --------- d-----w c:\programdata\NCH Software
2009-01-22 15:34 --------- d-----w c:\users\ANDRZEJ\AppData\Roaming\NCH Software
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2009-01-12 20:58 --------- d-----w c:\users\ANDRZEJ\AppData\Roaming\Hamachi
2009-01-12 20:51 25,280 ----a-w c:\windows\system32\drivers\hamachi.sys
2009-01-12 17:04 --------- d-----w c:\users\ANDRZEJ\AppData\Roaming\HLSW
2009-01-09 13:05 711 ----a-w c:\users\ANDRZEJ\config.dat
2009-01-06 17:42 85,239 ----a-w c:\windows\System32\cont_milehighads-remove.exe
2008-12-29 21:39 183,112 ----a-w c:\windows\System32\PnkBstrB.exe
2008-09-30 17:34 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-09-30 17:34 56 ---ha-w c:\programdata\ezsidmv.dat
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
2002-08-23 13:44 1,808 ----a-w c:\users\ANDRZEJ\gpr.exe
2007-09-16 07:45 66,408 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2007-09-16 07:45 54,112 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-09-16 07:45 34,688 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-05 19:23 651,264 ----a-w c:\program files\mozilla firefox\components\nsmilehighads.dll
2007-09-16 07:45 46,456 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-09-16 07:45 171,880 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{47726D9E-4DEE-4F18-85A5-EE5363177E64}]
2006-11-02 10:46 96256 --a------ c:\windows\system32\AuxiliaryDisplayClassInstalle.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74e63028-d3e4-ae7a-c31a-70135562d340}]
2009-03-02 16:15 622080 --a------ c:\windows\system32\nsw3C20.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\0_FlingIconOverlay]
@="{02696AD5-FF96-454b-9E00-81DA8B79B678}"
[HKEY_CLASSES_ROOT\CLSID\{02696AD5-FF96-454b-9E00-81DA8B79B678}]
2009-01-22 16:35 81920 --a------ c:\program files\NCH Software\Fling\fldll.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-12-22 221568]
"DAEMON Tools Lite"="c:\programy\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"GAINWARD"="c:\program files\EXPERTool\TBPanel.exe" [2008-07-10 2177576]
"Google Update"="c:\users\ANDRZEJ\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-10-12 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 92704]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-08-25 1168264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 c:\windows\RtHDVCpl.exe]

c:\users\Marcin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-05-13 1058088]

c:\users\ANDRZEJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-05-13 1058088]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-07-23 14:11 10536 c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
SetupExecute REG_MULTI_SZ \0

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoftickPPP

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BroadWave]
--a------ 2009-01-22 16:35 499716 c:\program files\NCH Swift Sound\BroadWave\broadwave.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
--a------ 2009-01-09 21:11 3321856 c:\program files\Electronic Arts\EADM\Core.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FastFox]
--a------ 2009-01-22 16:35 327684 c:\program files\NCH Swift Sound\FastFox\fastfox.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fling]
--a------ 2009-01-22 16:35 475140 c:\program files\NCH Software\Fling\fling.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-07-23 14:03 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-10-12 21:35 133104 c:\users\ANDRZEJ\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-12-10 20:52 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\System32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
--a------ 2008-12-25 14:20 306088 c:\programy\rockstarclub\Rockstar Games Social Club\RGSCLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-08-12 16:13 21741864 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-11-10 05:43 136600 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-07-23 14:03 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinFast Schedule]
--a------ 2007-11-15 14:55 2850816 c:\program files\WinFast\WFDTV\WFWIZ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinFastDTV]
--a------ 2007-11-16 15:13 90112 c:\program files\WinFast\WFDTV\DTVSchdl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 16:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9D2F3776-FCCE-4CF5-A38A-A34DAFFC8533}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{F48D5593-B0ED-45A1-9E62-95288A3515DF}"= UDP:c:\users\ANDRZEJ\AppData\Local\Temp\stInstall.exe:SpeedTouch Home Install Wizard
"{AD7EDFAF-D13D-4E36-A805-8BE3959B77B1}"= TCP:c:\users\ANDRZEJ\AppData\Local\Temp\stInstall.exe:SpeedTouch Home Install Wizard
"{C2E62D14-934B-4504-9DC7-4252886E44B0}"= UDP:c:\program files\Thomson\ST330\service\st330service.exe:ST330 service
"{BB27FF3B-1735-4A13-AEB9-C02DB69807D0}"= TCP:c:\program files\Thomson\ST330\service\st330service.exe:ST330 service
"{1E3676C9-CBD7-4C6D-BC53-132A21F7D765}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5B4421AA-515F-492A-B600-420BAE9EE011}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{FB21FBB4-6D5D-4750-818D-0174BBF725A7}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{B7A30C65-F7F7-4144-9A02-E7982E6A374E}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{620BB0BF-C602-459F-BC0E-618BCFE8670F}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{DE26BACB-3D83-43FC-A03F-CC0B24E92FBA}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{E57B7CC4-7CC7-497D-B14C-8E2F388D8F74}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{D661EE66-52D9-4603-9AEC-86EAFA374C55}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DE4D47AF-5C26-4B94-B495-4D76030ABFD2}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{142E3BAC-3B8F-4358-810B-982B323E699E}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{81F64ABA-3FDF-4178-B784-315D8EA107DE}"= UDP:c:\gry\Assassins\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{697132A9-EE1F-4041-B8DF-53CBD9E63736}"= TCP:c:\gry\Assassins\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{1C10FF15-9A73-4010-B418-87A1120C3F23}"= UDP:c:\gry\Assassins\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{2E337D66-FEE5-4E5A-AB6A-EE6A178CE58F}"= TCP:c:\gry\Assassins\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{B78F1D45-4620-47D2-8CE3-654F34DEB213}"= UDP:c:\gry\Assassins\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{17E72486-602A-4531-9A01-75DC01C1B230}"= TCP:c:\gry\Assassins\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{AECA9B20-F8C0-4CDD-964B-5DD2624825B2}"= UDP:c:\programy\rockstarclub\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club
"{C1A6F303-90C0-468A-9B1B-9BF49C7843A1}"= TCP:c:\programy\rockstarclub\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club
"{4CB6CFEC-66C7-4B67-A71B-853C604A7F20}"= UDP:c:\gry\gta4\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV
"{AC7D602C-18C4-45D6-BC57-7B248D3A96CE}"= TCP:c:\gry\gta4\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV
"{39C8B3CC-02E5-441F-BB3C-4D9802480BF8}"= UDP:85:BroadWave Web Server

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R2 BroadWaveService;BroadWave;c:\program files\NCH Swift Sound\BroadWave\broadwave.exe [2009-01-22 499716]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-04-28 161048]
R2 FlingService;Fling File Transfer;c:\program files\NCH Software\Fling\fling.exe [2009-01-22 475140]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-08-24 356920]
S2 vnccom;vnccom;c:\windows\System32\drivers\vnccom.SYS [2008-09-14 6016]
S3 cglptnt;cglptnt;c:\programy\TC PowerPack\CGLPTNT.SYS [2006-02-02 7888]
S3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFDTV\WFIOCTL.sys [2008-08-07 9446]
S4 gupdate1c9969af3a78b8f;Google Update Service (gupdate1c9969af3a78b8f);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 133104]

--- Inne Usługi/Sterowniki w Pamięci ---

*Deregistered* - mchInjDrv

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{006d111a-994e-11db-be4b-00219b0151e9}]
\shell\AutoRun\command - ur0.com
\shell\open\Command - ur0.com
.
Zawartość folderu 'Zaplanowane zadania'

2009-03-12 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 17:14]

2009-03-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-76595912-626078801-2151686915-1000.job
- c:\users\ANDRZEJ\AppData\Local\Google\Update\GoogleUpdate.exe [2008-10-12 21:35]

2009-02-14 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 18:32]

2009-02-28 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 18:32]
.
- - - - USUNIĘTO PUSTE WPISY - - - -

BHO-{78A55F92-ED4B-FB55-CA8F-FFD1795361C0} - c:\windows\system32\rmwiclyqepi.dll
BHO-{EEFFB028-9BA4-E7B5-EB19-CCA50926D3AA} - c:\windows\system32\bvvzwunmegp.dll
HKLM-Run-RegistryMechanic - (no file)


.
------- Skan uzupełniający -------
.
uStart Page = www.google.pl/
mStart Page = hxxp://www.yahoo.com
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath -

---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-12 21:16:16
Windows 6.0.6001 Service Pack 1 NTFS

skanowanie ukrytych procesów ...

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ...


c:\users\ANDRZEJ\AppData\Local\Temp\catchme.dll

skanowanie pomyślnie ukończone
ukryte pliki: 1

**************************************************************************
.
Czas ukończenia: 2009-03-12 21:18:46
ComboFix-quarantined-files.txt 2009-03-12 20:18:42
ComboFix2.txt 2008-11-02 16:29:42

Przed: 393,762,963,456 bajtów wolnych
Po: 394,001,494,016 bajtów wolnych

523 --- E O F --- 2009-03-11 23:17:27

Użytkownik eunstachy edytował ten post 12 03 2009 - 22:39

  • 0

#6 Macsch15

Macsch15

    Profesjonalista

  • 3 705 postów

Napisano 12 03 2009 - 22:33

W hijacku

O2 - BHO: Game.OS - {3A303EF6-2598-4D2D-B4DA-DEFA7CD0DC51} - C:\Windows\system32\ifsndu.dll
O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL (file missing)


  • 0

#7 Jezierski

Jezierski

    Nie truć na gg.

  • 351 postów

Napisano 12 03 2009 - 23:36

dobra dzięki udało sie :P sfiksowałem te 2 i jest ok a mój Śpioch działa :P dzieki ;)

  • 0




Użytkownicy przeglądający ten temat: 0

0 użytkowników, 0 gości, 0 anonimowych