Skocz do zawartości
  • 👋 Witaj na MPCForum!

    Przeglądasz forum jako gość, co oznacza, że wiele świetnych funkcji jest jeszcze przed Tobą! 😎

    • Pełny dostęp do działów i ukrytych treści
    • Możliwość pisania i odpowiadania w tematach
    • System prywatnych wiadomości
    • Zbieranie reputacji i rozwijanie swojego profilu
    • Członkostwo w jednej z największych społeczności graczy

    👉 Dołączenie zajmie Ci mniej niż minutę – a zyskasz znacznie więcej!

    Zarejestruj się teraz

[Problem] ESET NOD 32


lol121xx

Rekomendowane odpowiedzi

Opublikowano

Witam mam problem z esetem, gdy go włączam wywala mi błąd "odczytanie konfiguracji zapory nie powiodło się" po czym program włącza się ale zapory nie działają. Ktoś wie jak to naprawić ?

Opublikowano
http://www.eset.pl/Pomoc,f,2918,act,show/Odczytanie_konfiguracji_zapory_nie_powiodlo_sie_W_czym_problem_i_jak_go_rozwiazac_

1364047611-U477327.png

 

STOP komentarzom typu: "AMD to gówno"! Zanim coś napiszesz, to pomyśl jak odbiorą to inni !

 

 

 

Nie pisać mi na PW w sprawach pomocy od tego macie dział komputery!!!

I nie pomagam na PW!

 

 

 

 

gardenscapes cheats

 

bakery story 2 cheat

Opublikowano

Mam win 7 i chyba sp1

Zaraz dam loga z otl

@Edit log z OTL

OTL logfile created on: 12/22/2012 11:48:32 AM - Run 1
OTL by OldTimer - Version 3.2.69.0	 Folder = A:\Users\user\Desktop
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd

4.00 Gb Total Physical Memory | 2.32 Gb Available Physical Memory | 57.98% Memory free
14.00 Gb Paging File | 12.00 Gb Available in Paging File | 85.72% Paging File free
Paging file location(s): c:\pagefile.sys 0 0g:\pagefile.sys 6144 6144 [binary data]

%SystemDrive% = A: | %SystemRoot% = A:\Windows | %ProgramFiles% = A:\Program Files (x86)
Drive C: | 20.02 Gb Total Space | 7.52 Gb Free Space | 37.55% Space Free | Partition Type: NTFS
Drive D: | 129.02 Gb Total Space | 16.70 Gb Free Space | 12.94% Space Free | Partition Type: NTFS
Drive F: | 31.25 Gb Total Space | 1.05 Gb Free Space | 3.35% Space Free | Partition Type: NTFS
Drive G: | 29.30 Gb Total Space | 16.59 Gb Free Space | 56.62% Space Free | Partition Type: NTFS
Drive H: | 55.30 Gb Total Space | 10.62 Gb Free Space | 19.20% Space Free | Partition Type: NTFS
Drive N: | 520.50 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: USER-PC | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 1 Day

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012/12/22 11:48:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- A:\Users\user\Desktop\OTL.exe
PRC - [2012/12/12 18:58:22 | 001,807,800 | ---- | M] (Adobe Systems, Inc.) -- A:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
PRC - [2012/12/10 17:29:46 | 002,254,768 | ---- | M] (LogMeIn Inc.) -- A:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2012/12/05 17:29:00 | 000,916,960 | ---- | M] (Mozilla Corporation) -- A:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/12/05 15:40:02 | 000,597,880 | ---- | M] (BlueStack Systems, Inc.) -- A:\Program Files (x86)\BlueStacks\HD-Agent.exe
PRC - [2012/12/05 15:39:26 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) -- A:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
PRC - [2012/12/05 13:55:33 | 000,076,888 | ---- | M] () -- A:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/11/16 21:01:16 | 006,211,904 | ---- | M] (OnLive, Inc.) -- A:\Program Files (x86)\OnLive\OnLive.exe
PRC - [2012/03/01 01:02:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) -- A:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/02/29 21:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- A:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/05/14 15:47:54 | 000,731,840 | ---- | M] (ESET) -- A:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/12/19 19:33:43 | 000,643,072 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\HD-Agent\0dbaea356be985e489fc74912681a9d3\HD-Agent.ni.exe
MOD - [2012/12/19 19:33:41 | 000,155,136 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\JSON\c2332f3bb6e67e8dcc79877b07938b1e\JSON.ni.dll
MOD - [2012/12/12 18:58:22 | 014,586,296 | ---- | M] () -- A:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
MOD - [2012/12/05 17:28:59 | 002,397,152 | ---- | M] () -- A:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/02/29 21:26:28 | 000,360,768 | ---- | M] () -- A:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2009/07/14 05:56:03 | 011,804,160 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\3871fc2b96345aa6f3be81d9e3c97160\System.Web.ni.dll
MOD - [2009/07/14 05:55:34 | 000,212,992 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e71959f4ec6eb386889050ac139835c7\System.ServiceProcess.ni.dll
MOD - [2009/07/14 05:55:32 | 012,430,848 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll
MOD - [2009/07/14 05:55:26 | 001,586,688 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll
MOD - [2009/07/14 05:55:09 | 005,452,800 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll
MOD - [2009/07/14 05:55:06 | 000,971,264 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll
MOD - [2009/07/14 05:55:05 | 007,949,312 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll
MOD - [2009/07/14 05:55:00 | 011,490,816 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll
MOD - [2009/06/10 22:10:44 | 000,311,296 | ---- | M] () -- A:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009/06/10 22:10:44 | 000,204,800 | ---- | M] () -- A:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pl_b77a5c561934e089\System.resources.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- A:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2009/07/14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- A:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:[b]64bit:[/b] - [2009/07/14 02:39:29 | 000,010,240 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- A:\Windows\SysNative\regedt32.exe -- (.EsetTrialReset)
SRV:[b]64bit:[/b] - [2009/05/14 15:54:26 | 000,023,296 | ---- | M] (ESET) [On_Demand | Stopped] -- A:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV:[b]64bit:[/b] - [2009/05/14 15:47:54 | 000,731,840 | ---- | M] (ESET) [Auto | Running] -- A:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV - [2012/12/12 18:58:23 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- A:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/10 17:29:46 | 002,465,712 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- A:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012/12/05 17:28:59 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- A:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/12/05 15:39:26 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- A:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc)
SRV - [2012/12/05 15:39:08 | 000,393,080 | ---- | M] (BlueStack Systems, Inc.) [Auto | Stopped] -- A:\Program Files (x86)\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)
SRV - [2012/12/05 13:55:33 | 000,076,888 | ---- | M] () [Auto | Running] -- A:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/09/14 18:43:44 | 002,552,176 | ---- | M] (O&O Software GmbH) [Auto | Running] -- D:\Patryk\A prograamy\o&o\oodag.exe -- (OODefragAgent)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- A:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/01 01:02:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- A:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/02/29 21:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- A:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- A:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/07/14 02:14:30 | 000,009,216 | ---- | M] (Microsoft Corporation) [Auto | Unknown] -- A:\Windows\SysWow64\regedt32.exe -- (.EsetTrialReset)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- A:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2006/10/27 00:47:54 | 000,065,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- G:\msoffice\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2012/09/27 17:16:46 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- A:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:[b]64bit:[/b] - [2011/06/10 14:34:52 | 000,539,240 | ---- | M] (Realtek										    ) [Kernel | On_Demand | Running] -- A:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2009/12/22 10:26:36 | 000,038,456 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- A:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- A:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- A:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2009/05/14 15:49:56 | 000,121,152 | ---- | M] (ESET) [Kernel | Auto | Running] -- A:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:[b]64bit:[/b] - [2009/05/14 15:47:16 | 000,134,024 | ---- | M] (ESET) [Kernel | System | Running] -- A:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:[b]64bit:[/b] - [2009/05/14 15:41:14 | 000,142,776 | ---- | M] (ESET) [File_System | Auto | Running] -- A:\Windows\SysNative\drivers\eamon.sys -- (eamon)
DRV:[b]64bit:[/b] - [2009/05/05 02:00:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- A:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie)
DRV:[b]64bit:[/b] - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- A:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:[b]64bit:[/b] - [2008/08/08 14:31:26 | 000,062,960 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\h648103.sys -- (h648103)
DRV:[b]64bit:[/b] - [2008/08/08 14:31:22 | 000,065,776 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\h648101.sys -- (h648101)
DRV:[b]64bit:[/b] - [2008/08/08 14:31:20 | 000,063,856 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\h647906.sys -- (h647906)
DRV - [2012/12/05 15:39:18 | 000,071,032 | ---- | M] (BlueStack Systems) [Kernel | Auto | Running] -- A:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys -- (BstHdDrv)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- A:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2008/08/08 14:31:18 | 000,043,192 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysWOW64\drivers\hid8101.sys -- (hid8101)
DRV - [2008/08/08 14:31:18 | 000,040,856 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysWOW64\drivers\hid8103.sys -- (hid8103)
DRV - [2008/08/08 14:31:16 | 000,041,272 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysWOW64\drivers\hid7906.sys -- (hid7906)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = A:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.startup.homepage: "Google.pl"
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: A:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: A:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: A:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: A:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: A:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: A:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.132.0: A:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: A:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: A:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: A:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: A:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: A:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: A:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: A:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: A:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: A:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@onlive.com/OnLiveGameClientDetector,version=1.0.0: A:\Program Files (x86)\OnLive\Plugin\npolgdet.dll (OnLive)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: A:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: A:\Program Files (x86)\Mozilla Firefox\components [2012/12/05 17:29:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: A:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: A:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: A:\Program Files (x86)\Mozilla Firefox\components [2012/12/05 17:29:00 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: A:\Program Files (x86)\Mozilla Firefox\plugins

[2012/08/02 21:19:18 | 000,000,000 | ---D | M] (No name found) -- A:\Users\user\AppData\Roaming\mozilla\Extensions
[2012/12/13 15:27:44 | 000,000,000 | ---D | M] (No name found) -- A:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\vm5b5ipa.default\extensions
[2012/12/04 18:05:57 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- A:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\vm5b5ipa.default\extensions\[email protected]
[2012/08/31 15:26:36 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- A:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\vm5b5ipa.default\extensions\[email protected]
[2012/12/11 19:29:33 | 000,009,505 | ---- | M] () (No name found) -- A:\Users\user\AppData\Roaming\mozilla\firefox\profiles\vm5b5ipa.default\extensions\[email protected]
[2012/11/24 17:15:48 | 000,804,627 | ---- | M] () (No name found) -- A:\Users\user\AppData\Roaming\mozilla\firefox\profiles\vm5b5ipa.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/12/13 15:27:44 | 000,243,496 | ---- | M] () (No name found) -- A:\Users\user\AppData\Roaming\mozilla\firefox\profiles\vm5b5ipa.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012/12/05 17:28:53 | 000,000,000 | ---D | M] (No name found) -- A:\Program Files (x86)\mozilla firefox\extensions
[2012/12/05 17:28:53 | 000,000,000 | ---D | M] (Skype Click to Call) -- A:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/12/05 17:29:00 | 000,262,112 | ---- | M] (Mozilla Foundation) -- A:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/08/31 15:25:40 | 000,002,767 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml
[2012/01/28 19:53:10 | 000,002,310 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/08/31 15:25:40 | 000,001,406 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml
[2012/08/31 15:25:40 | 000,000,917 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml
[2012/08/31 15:25:40 | 000,000,858 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml
[2012/08/31 15:25:40 | 000,001,183 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml
[2012/08/31 15:25:40 | 000,001,683 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml

[color=#E56717]========== Chrome  ==========[/color]

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = A:\Program Files (x86)\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = A:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = A:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = A:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = A:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = A:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = A:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = A:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = A:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Java(TM) Platform SE 7 U5 (Enabled) = A:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = A:\Windows\SysWOW64\npDeployJava1.dll
CHR - Extension: Don't Starve = A:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiledapehlkhdehbhppgmekfalnlfajc\1.0.0.37_0\
CHR - Extension: avast! WebRep = A:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - A:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - A:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - A:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - G:\msoffice\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - A:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - A:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [egui] A:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:[b]64bit:[/b] - HKLM..\Run: [OODefragTray] D:\Patryk\A prograamy\o&o\oodtray.exe (O&O Software GmbH)
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] A:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [blueStacks Agent] A:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
O4 - HKLM..\Run: [GrooveMonitor] G:\msoffice\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] A:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] A:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - G:\msoffice\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - G:\msoffice\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\msoffice\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\msoffice\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\msoffice\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E841FEF0-F520-4B0D-98B7-A59A9EFF1687}: DhcpNameServer = 192.168.1.254 8.8.8.8
O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - G:\msoffice\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - A:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - A:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - A:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (A:\Windows\system32\userinit.exe) - A:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - A:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - A:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - G:\msoffice\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/11/27 14:54:54 | 000,000,175 | R--- | M] () - N:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{0944bd21-08a2-11e2-993b-6c626d387f8e}\Shell - "" = AutoRun
O33 - MountPoints2\{0944bd21-08a2-11e2-993b-6c626d387f8e}\Shell\AutoRun\command - "" = N:\setup.exe -- [2006/11/27 14:51:00 | 000,463,152 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\{0944bd21-08a2-11e2-993b-6c626d387f8e}\Shell\configure\command - "" = N:\setup.exe -- [2006/11/27 14:51:00 | 000,463,152 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\{0944bd21-08a2-11e2-993b-6c626d387f8e}\Shell\install\command - "" = N:\setup.exe -- [2006/11/27 14:51:00 | 000,463,152 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (OODBS)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 1 Day ==========[/color]

[2012/12/22 11:47:59 | 000,602,112 | ---- | C] (OldTimer Tools) -- A:\Users\user\Desktop\OTL.exe
[2012/12/22 11:46:31 | 000,000,000 | ---D | C] -- A:\Users\user\Documents\OnLive App
[2012/12/22 11:46:21 | 000,000,000 | ---D | C] -- A:\Users\user\AppData\Roaming\OnLive App
[2012/12/22 11:46:21 | 000,000,000 | ---D | C] -- A:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnLive
[2012/12/22 11:46:18 | 000,000,000 | ---D | C] -- A:\Program Files (x86)\OnLive
[2012/12/22 11:40:16 | 006,659,832 | ---- | C] (OnLive) -- A:\Users\user\Desktop\OnLive_Setup.exe
[2012/12/22 11:04:07 | 000,000,000 | ---D | C] -- A:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2012/12/22 10:48:19 | 000,000,000 | ---D | C] -- A:\Users\user\Desktop\nod32-4.0.437.x64-PL
[2012/12/22 10:36:00 | 000,000,000 | ---D | C] -- A:\Windows\SysWow64\updfiles
[2012/12/22 10:28:12 | 000,000,000 | ---D | C] -- A:\Users\user\AppData\Roaming\ESET
[2012/12/22 10:27:04 | 000,000,000 | ---D | C] -- A:\ProgramData\ESET
[2012/12/22 10:27:04 | 000,000,000 | ---D | C] -- A:\Program Files\ESET
[2012/08/19 09:44:30 | 002,982,912 | ---- | C] (Python Software Foundation) -- A:\Users\user\AppData\Roaming\python27.dll

[color=#E56717]========== Files - Modified Within 1 Day ==========[/color]

[2012/12/22 11:50:00 | 000,001,044 | ---- | M] () -- A:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/22 11:48:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- A:\Users\user\Desktop\OTL.exe
[2012/12/22 11:46:21 | 000,001,855 | ---- | M] () -- A:\Users\Public\Desktop\OnLive.lnk
[2012/12/22 11:41:48 | 004,929,146 | ---- | M] () -- A:\Windows\SysWow64\em023_32.dat
[2012/12/22 11:41:47 | 001,384,391 | ---- | M] () -- A:\Windows\SysWow64\em009_64.dat
[2012/12/22 11:41:47 | 000,038,604 | ---- | M] () -- A:\Windows\SysWow64\em013_32.dat
[2012/12/22 11:41:47 | 000,038,041 | ---- | M] () -- A:\Windows\SysWow64\em013_64.dat
[2012/12/22 11:41:46 | 001,104,324 | ---- | M] () -- A:\Windows\SysWow64\em009_32.dat
[2012/12/22 11:41:46 | 000,077,288 | ---- | M] () -- A:\Windows\SysWow64\em006_64.dat
[2012/12/22 11:41:45 | 000,829,329 | ---- | M] () -- A:\Windows\SysWow64\em004_32.dat
[2012/12/22 11:41:45 | 000,776,832 | ---- | M] () -- A:\Windows\SysWow64\em003_32.dat
[2012/12/22 11:41:45 | 000,089,137 | ---- | M] () -- A:\Windows\SysWow64\em006_32.dat
[2012/12/22 11:41:45 | 000,063,506 | ---- | M] () -- A:\Windows\SysWow64\em005_32.dat
[2012/12/22 11:41:44 | 034,924,075 | ---- | M] () -- A:\Windows\SysWow64\em002_32.dat
[2012/12/22 11:41:29 | 000,522,676 | ---- | M] () -- A:\Windows\SysWow64\em001_32.dat
[2012/12/22 11:41:29 | 000,066,929 | ---- | M] () -- A:\Windows\SysWow64\em000_64.dat
[2012/12/22 11:41:29 | 000,055,770 | ---- | M] () -- A:\Windows\SysWow64\em000_32.dat
[2012/12/22 11:40:30 | 006,659,832 | ---- | M] (OnLive) -- A:\Users\user\Desktop\OnLive_Setup.exe
[2012/12/22 11:15:14 | 000,010,016 | -H-- | M] () -- A:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/22 11:15:14 | 000,010,016 | -H-- | M] () -- A:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/22 11:11:17 | 000,006,113 | ---- | M] () -- A:\Windows\SysWow64\EpfwUser.dat
[2012/12/22 11:09:50 | 000,001,040 | ---- | M] () -- A:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/22 11:09:20 | 000,067,584 | --S- | M] () -- A:\Windows\bootstat.dat
[2012/12/22 11:09:19 | 3220,578,304 | -HS- | M] () -- A:\hiberfil.sys
[2012/12/22 11:09:17 | 000,079,112 | ---- | M] () -- A:\Windows\SysNative\oodbs.lor
[2012/12/22 10:56:00 | 000,000,930 | ---- | M] () -- A:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/22 10:47:42 | 035,472,477 | ---- | M] () -- A:\Users\user\Desktop\nod32-4.0.437.x64-PL.rar

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2012/12/22 11:46:21 | 000,001,855 | ---- | C] () -- A:\Users\Public\Desktop\OnLive.lnk
[2012/12/22 11:41:48 | 034,924,075 | ---- | C] () -- A:\Windows\SysWow64\em002_32.dat
[2012/12/22 11:41:48 | 004,929,146 | ---- | C] () -- A:\Windows\SysWow64\em023_32.dat
[2012/12/22 11:41:48 | 001,384,391 | ---- | C] () -- A:\Windows\SysWow64\em009_64.dat
[2012/12/22 11:41:48 | 001,104,324 | ---- | C] () -- A:\Windows\SysWow64\em009_32.dat
[2012/12/22 11:41:48 | 000,829,329 | ---- | C] () -- A:\Windows\SysWow64\em004_32.dat
[2012/12/22 11:41:48 | 000,776,832 | ---- | C] () -- A:\Windows\SysWow64\em003_32.dat
[2012/12/22 11:41:48 | 000,522,676 | ---- | C] () -- A:\Windows\SysWow64\em001_32.dat
[2012/12/22 11:41:48 | 000,089,137 | ---- | C] () -- A:\Windows\SysWow64\em006_32.dat
[2012/12/22 11:41:48 | 000,077,288 | ---- | C] () -- A:\Windows\SysWow64\em006_64.dat
[2012/12/22 11:41:48 | 000,066,929 | ---- | C] () -- A:\Windows\SysWow64\em000_64.dat
[2012/12/22 11:41:48 | 000,063,506 | ---- | C] () -- A:\Windows\SysWow64\em005_32.dat
[2012/12/22 11:41:48 | 000,055,770 | ---- | C] () -- A:\Windows\SysWow64\em000_32.dat
[2012/12/22 11:41:48 | 000,038,604 | ---- | C] () -- A:\Windows\SysWow64\em013_32.dat
[2012/12/22 11:41:48 | 000,038,041 | ---- | C] () -- A:\Windows\SysWow64\em013_64.dat
[2012/12/22 10:45:08 | 035,472,477 | ---- | C] () -- A:\Users\user\Desktop\nod32-4.0.437.x64-PL.rar
[2012/12/22 10:32:46 | 000,006,113 | ---- | C] () -- A:\Windows\SysWow64\EpfwUser.dat
[2012/12/16 21:48:40 | 000,003,584 | ---- | C] () -- A:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/11/11 17:10:26 | 002,577,776 | ---- | C] () -- A:\Windows\SysWow64\pbsvc_heroes.exe
[2012/10/02 15:52:05 | 000,484,352 | ---- | C] () -- A:\Windows\SysWow64\lame_enc.dll
[2012/09/27 20:31:14 | 001,636,610 | ---- | C] () -- A:\Windows\SysWow64\PerfStringBackup.INI
[2012/09/09 13:34:13 | 000,639,488 | ---- | C] () -- A:\Windows\SysWow64\ficvdec_x86.dll
[2012/08/19 09:44:30 | 004,109,312 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxmsw28uh_core_vc.dll
[2012/08/19 09:44:30 | 001,623,040 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxbase28uh_vc.dll
[2012/08/19 09:44:30 | 001,245,696 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._core_.pyd
[2012/08/19 09:44:30 | 001,195,008 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._controls_.pyd
[2012/08/19 09:44:30 | 001,167,360 | ---- | C] () -- A:\Users\user\AppData\Roaming\_ssl.pyd
[2012/08/19 09:44:30 | 000,927,744 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxmsw28uh_adv_vc.dll
[2012/08/19 09:44:30 | 000,926,720 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._gdi_.pyd
[2012/08/19 09:44:30 | 000,858,112 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._windows_.pyd
[2012/08/19 09:44:30 | 000,838,144 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._misc_.pyd
[2012/08/19 09:44:30 | 000,627,712 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxmsw28uh_html_vc.dll
[2012/08/19 09:44:30 | 000,471,552 | ---- | C] () -- A:\Users\user\AppData\Roaming\_hashlib.pyd
[2012/08/19 09:44:30 | 000,157,184 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxbase28uh_net_vc.dll
[2012/08/19 09:44:30 | 000,046,080 | ---- | C] () -- A:\Users\user\AppData\Roaming\_socket.pyd
[2012/08/19 09:44:30 | 000,031,744 | ---- | C] () -- A:\Users\user\AppData\Roaming\ForceOP.exe
[2012/08/04 09:24:46 | 000,281,520 | ---- | C] () -- A:\Windows\SysWow64\PnkBstrB.exe
[2012/08/04 09:24:45 | 000,076,888 | ---- | C] () -- A:\Windows\SysWow64\PnkBstrA.exe
[2012/02/29 21:26:56 | 000,416,064 | ---- | C] () -- A:\Windows\SysWow64\nvStreaming.exe
[2011/09/19 08:07:46 | 000,015,360 | ---- | C] () -- A:\Windows\SysWow64\bdmjpeg.dll
[2011/09/19 08:07:32 | 000,058,368 | ---- | C] () -- A:\Windows\SysWow64\bdmpegv.dll
[2003/04/09 10:28:44 | 000,233,472 | R--- | C] () -- A:\Users\user\AppData\Roaming\MafiaSetup.exe

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- A:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = A:\Windows\SysNative\shell32.dll -- [2009/07/14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009/07/14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = A:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = A:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >

Opublikowano

Otwórz OTL i w oknie własne opcje skanowania /wklej :

 

:OTL
O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
:Commands
[emptytemp]

I kliknij na wykonaj skrypt .

Pokaż log usuwania .

Zabrakło 2 loga EXTRAS bo nie zaznaczyłeś rejestr dodatkowy na użyj filtrowania .

Zrób tego loga i go dorzuc.

1364047611-U477327.png

 

STOP komentarzom typu: "AMD to gówno"! Zanim coś napiszesz, to pomyśl jak odbiorą to inni !

 

 

 

Nie pisać mi na PW w sprawach pomocy od tego macie dział komputery!!!

I nie pomagam na PW!

 

 

 

 

gardenscapes cheats

 

bakery story 2 cheat

Opublikowano

log po usunięciu

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: user
->Temp folder emptied: 841848615 bytes
->Temporary Internet Files folder emptied: 16190195 bytes
->Java cache emptied: 1026735 bytes
->FireFox cache emptied: 640811153 bytes
->Google Chrome cache emptied: 244608683 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 17853 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 62429 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50668 bytes
RecycleBin emptied: 4212290794 bytes

Total Files Cleaned = 5,681.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 12222012_122451
Files\Folders moved on Reboot...
A:\Users\user\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...

@Edit Eset teraz wywala taki problem : "Inicjalizacja skanera wirusów nie powiodła się.Ochrona antywirusowa nie będzie działać poprawnie"

Opublikowano

log z rejestru dodatkowego

OTL logfile created on: 12/22/2012 1:00:04 PM - Run 3
OTL by OldTimer - Version 3.2.69.0	 Folder = A:\Users\user\Desktop
64bit- Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd

4.00 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 59.47% Memory free
14.00 Gb Paging File | 12.06 Gb Available in Paging File | 86.19% Paging File free
Paging file location(s): c:\pagefile.sys 0 0g:\pagefile.sys 6144 6144 [binary data]

%SystemDrive% = A: | %SystemRoot% = A:\Windows | %ProgramFiles% = A:\Program Files (x86)
Drive C: | 20.02 Gb Total Space | 7.52 Gb Free Space | 37.55% Space Free | Partition Type: NTFS
Drive D: | 129.02 Gb Total Space | 20.62 Gb Free Space | 15.98% Space Free | Partition Type: NTFS
Drive F: | 31.25 Gb Total Space | 1.05 Gb Free Space | 3.35% Space Free | Partition Type: NTFS
Drive G: | 29.30 Gb Total Space | 16.59 Gb Free Space | 56.62% Space Free | Partition Type: NTFS
Drive H: | 55.30 Gb Total Space | 10.62 Gb Free Space | 19.20% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 1 Day

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2012/12/22 11:48:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- A:\Users\user\Desktop\OTL.exe
PRC - [2012/12/12 18:58:22 | 001,807,800 | ---- | M] (Adobe Systems, Inc.) -- A:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe
PRC - [2012/12/10 17:29:46 | 002,254,768 | ---- | M] (LogMeIn Inc.) -- A:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2012/12/05 17:29:00 | 000,916,960 | ---- | M] (Mozilla Corporation) -- A:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/12/05 15:40:02 | 000,597,880 | ---- | M] (BlueStack Systems, Inc.) -- A:\Program Files (x86)\BlueStacks\HD-Agent.exe
PRC - [2012/12/05 15:39:26 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) -- A:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
PRC - [2012/12/05 13:55:33 | 000,076,888 | ---- | M] () -- A:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/03/01 01:02:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) -- A:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/02/29 21:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- A:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/09/24 20:02:05 | 001,510,912 | ---- | M] (AIMP DevTeam) -- D:\Patryk\AA Muzyka\Aimp\AIMP3.exe
PRC - [2009/05/14 15:47:54 | 000,731,840 | ---- | M] (ESET) -- A:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/12/19 19:33:43 | 000,643,072 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\HD-Agent\0dbaea356be985e489fc74912681a9d3\HD-Agent.ni.exe
MOD - [2012/12/19 19:33:41 | 000,155,136 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\JSON\c2332f3bb6e67e8dcc79877b07938b1e\JSON.ni.dll
MOD - [2012/12/12 18:58:22 | 014,586,296 | ---- | M] () -- A:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
MOD - [2012/12/05 17:28:59 | 002,397,152 | ---- | M] () -- A:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/02/29 21:26:28 | 000,360,768 | ---- | M] () -- A:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2011/09/24 20:02:06 | 000,443,904 | ---- | M] () -- D:\Patryk\AA Muzyka\Aimp\sqlite3.dll
MOD - [2011/09/24 20:02:05 | 001,198,592 | ---- | M] () -- D:\Patryk\AA Muzyka\Aimp\Modules\aimp_libvorbis.dll
MOD - [2011/09/24 20:02:05 | 000,060,416 | ---- | M] () -- D:\Patryk\AA Muzyka\Aimp\Modules\aimp_lastfm.dll
MOD - [2011/09/24 20:02:03 | 000,237,568 | ---- | M] () -- D:\Patryk\AA Muzyka\Aimp\Plugins\OptimFROG.dll
MOD - [2011/09/24 20:02:01 | 000,216,576 | ---- | M] () -- D:\Patryk\AA Muzyka\Aimp\Plugins\libdca.dll
MOD - [2011/09/24 20:02:00 | 001,794,560 | ---- | M] () -- D:\Patryk\AA Muzyka\Aimp\Plugins\PandemicAnalogMeter.dll
MOD - [2011/09/24 20:02:00 | 000,026,624 | ---- | M] () -- D:\Patryk\AA Muzyka\Aimp\Plugins\Aorta.svp
MOD - [2009/07/14 05:56:03 | 011,804,160 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\3871fc2b96345aa6f3be81d9e3c97160\System.Web.ni.dll
MOD - [2009/07/14 05:55:32 | 012,430,848 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll
MOD - [2009/07/14 05:55:26 | 001,586,688 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll
MOD - [2009/07/14 05:55:09 | 005,452,800 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll
MOD - [2009/07/14 05:55:06 | 000,971,264 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll
MOD - [2009/07/14 05:55:05 | 007,949,312 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll
MOD - [2009/07/14 05:55:00 | 011,490,816 | ---- | M] () -- A:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll
MOD - [2009/06/10 22:10:44 | 000,311,296 | ---- | M] () -- A:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll
MOD - [2009/06/10 22:10:44 | 000,204,800 | ---- | M] () -- A:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pl_b77a5c561934e089\System.resources.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- A:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2009/07/14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- A:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:[b]64bit:[/b] - [2009/07/14 02:39:29 | 000,010,240 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- A:\Windows\SysNative\regedt32.exe -- (.EsetTrialReset)
SRV:[b]64bit:[/b] - [2009/05/14 15:54:26 | 000,023,296 | ---- | M] (ESET) [On_Demand | Stopped] -- A:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV:[b]64bit:[/b] - [2009/05/14 15:47:54 | 000,731,840 | ---- | M] (ESET) [Auto | Running] -- A:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV - [2012/12/12 18:58:23 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- A:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/10 17:29:46 | 002,465,712 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- A:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012/12/05 17:28:59 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- A:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/12/05 15:39:26 | 000,384,888 | ---- | M] (BlueStack Systems, Inc.) [Auto | Running] -- A:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe -- (BstHdLogRotatorSvc)
SRV - [2012/12/05 15:39:08 | 000,393,080 | ---- | M] (BlueStack Systems, Inc.) [Auto | Stopped] -- A:\Program Files (x86)\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)
SRV - [2012/12/05 13:55:33 | 000,076,888 | ---- | M] () [Auto | Running] -- A:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/09/14 18:43:44 | 002,552,176 | ---- | M] (O&O Software GmbH) [Auto | Running] -- D:\Patryk\A prograamy\o&o\oodag.exe -- (OODefragAgent)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- A:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/01 01:02:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- A:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/02/29 21:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- A:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- A:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/07/14 02:14:30 | 000,009,216 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- A:\Windows\SysWow64\regedt32.exe -- (.EsetTrialReset)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- A:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2006/10/27 00:47:54 | 000,065,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- G:\msoffice\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2012/09/27 17:16:46 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- A:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:[b]64bit:[/b] - [2011/06/10 14:34:52 | 000,539,240 | ---- | M] (Realtek										    ) [Kernel | On_Demand | Running] -- A:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2009/12/22 10:26:36 | 000,038,456 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- A:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- A:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- A:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2009/05/14 15:49:56 | 000,121,152 | ---- | M] (ESET) [Kernel | Auto | Running] -- A:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:[b]64bit:[/b] - [2009/05/14 15:47:16 | 000,134,024 | ---- | M] (ESET) [Kernel | System | Running] -- A:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:[b]64bit:[/b] - [2009/05/14 15:41:14 | 000,142,776 | ---- | M] (ESET) [File_System | Auto | Running] -- A:\Windows\SysNative\drivers\eamon.sys -- (eamon)
DRV:[b]64bit:[/b] - [2009/05/05 02:00:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- A:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie)
DRV:[b]64bit:[/b] - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- A:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:[b]64bit:[/b] - [2008/08/08 14:31:26 | 000,062,960 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\h648103.sys -- (h648103)
DRV:[b]64bit:[/b] - [2008/08/08 14:31:22 | 000,065,776 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\h648101.sys -- (h648101)
DRV:[b]64bit:[/b] - [2008/08/08 14:31:20 | 000,063,856 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysNative\drivers\h647906.sys -- (h647906)
DRV - [2012/12/05 15:39:18 | 000,071,032 | ---- | M] (BlueStack Systems) [Kernel | Auto | Running] -- A:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys -- (BstHdDrv)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- A:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2008/08/08 14:31:18 | 000,043,192 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysWOW64\drivers\hid8101.sys -- (hid8101)
DRV - [2008/08/08 14:31:18 | 000,040,856 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysWOW64\drivers\hid8103.sys -- (hid8103)
DRV - [2008/08/08 14:31:16 | 000,041,272 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- A:\Windows\SysWOW64\drivers\hid7906.sys -- (hid7906)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = A:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.startup.homepage: "Google.pl"
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: A:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: A:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: A:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: A:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: A:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: A:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.132.0: A:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: A:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: A:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: A:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: A:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: A:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: A:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: A:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: A:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: A:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@onlive.com/OnLiveGameClientDetector,version=1.0.0: A:\Program Files (x86)\OnLive\Plugin\npolgdet.dll (OnLive)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: A:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: A:\Program Files (x86)\Mozilla Firefox\components [2012/12/05 17:29:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: A:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: A:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: A:\Program Files (x86)\Mozilla Firefox\components [2012/12/05 17:29:00 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: A:\Program Files (x86)\Mozilla Firefox\plugins

[2012/08/02 21:19:18 | 000,000,000 | ---D | M] (No name found) -- A:\Users\user\AppData\Roaming\mozilla\Extensions
[2012/12/13 15:27:44 | 000,000,000 | ---D | M] (No name found) -- A:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\vm5b5ipa.default\extensions
[2012/12/04 18:05:57 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- A:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\vm5b5ipa.default\extensions\[email protected]
[2012/08/31 15:26:36 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- A:\Users\user\AppData\Roaming\mozilla\Firefox\Profiles\vm5b5ipa.default\extensions\[email protected]
[2012/12/11 19:29:33 | 000,009,505 | ---- | M] () (No name found) -- A:\Users\user\AppData\Roaming\mozilla\firefox\profiles\vm5b5ipa.default\extensions\[email protected]
[2012/11/24 17:15:48 | 000,804,627 | ---- | M] () (No name found) -- A:\Users\user\AppData\Roaming\mozilla\firefox\profiles\vm5b5ipa.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/12/13 15:27:44 | 000,243,496 | ---- | M] () (No name found) -- A:\Users\user\AppData\Roaming\mozilla\firefox\profiles\vm5b5ipa.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012/12/05 17:28:53 | 000,000,000 | ---D | M] (No name found) -- A:\Program Files (x86)\mozilla firefox\extensions
[2012/12/05 17:28:53 | 000,000,000 | ---D | M] (Skype Click to Call) -- A:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/12/05 17:29:00 | 000,262,112 | ---- | M] (Mozilla Foundation) -- A:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/08/31 15:25:40 | 000,002,767 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml
[2012/01/28 19:53:10 | 000,002,310 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/08/31 15:25:40 | 000,001,406 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml
[2012/08/31 15:25:40 | 000,000,917 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml
[2012/08/31 15:25:40 | 000,000,858 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml
[2012/08/31 15:25:40 | 000,001,183 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml
[2012/08/31 15:25:40 | 000,001,683 | ---- | M] () -- A:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml

[color=#E56717]========== Chrome  ==========[/color]

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = A:\Program Files (x86)\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = A:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = A:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = A:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = A:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = A:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = A:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = A:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = A:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Java(TM) Platform SE 7 U5 (Enabled) = A:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = A:\Windows\SysWOW64\npDeployJava1.dll
CHR - Extension: Don't Starve = A:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiledapehlkhdehbhppgmekfalnlfajc\1.0.0.37_0\
CHR - Extension: avast! WebRep = A:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - A:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - A:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - A:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - G:\msoffice\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - A:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - A:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [egui] A:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:[b]64bit:[/b] - HKLM..\Run: [OODefragTray] D:\Patryk\A prograamy\o&o\oodtray.exe (O&O Software GmbH)
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] A:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [blueStacks Agent] A:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
O4 - HKLM..\Run: [GrooveMonitor] G:\msoffice\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] A:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] A:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - G:\msoffice\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - G:\msoffice\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\msoffice\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\msoffice\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\msoffice\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E841FEF0-F520-4B0D-98B7-A59A9EFF1687}: DhcpNameServer = 192.168.1.254 8.8.8.8
O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - G:\msoffice\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - A:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - A:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - A:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (A:\Windows\system32\userinit.exe) - A:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - A:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - A:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - G:\msoffice\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (OODBS)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 1 Day ==========[/color]

[2012/12/22 12:24:51 | 000,000,000 | ---D | C] -- A:\_OTL
[2012/12/22 11:47:59 | 000,602,112 | ---- | C] (OldTimer Tools) -- A:\Users\user\Desktop\OTL.exe
[2012/12/22 11:46:31 | 000,000,000 | ---D | C] -- A:\Users\user\Documents\OnLive App
[2012/12/22 11:46:21 | 000,000,000 | ---D | C] -- A:\Users\user\AppData\Roaming\OnLive App
[2012/12/22 11:46:21 | 000,000,000 | ---D | C] -- A:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnLive
[2012/12/22 11:46:18 | 000,000,000 | ---D | C] -- A:\Program Files (x86)\OnLive
[2012/12/22 11:40:16 | 006,659,832 | ---- | C] (OnLive) -- A:\Users\user\Desktop\OnLive_Setup.exe
[2012/12/22 11:04:07 | 000,000,000 | ---D | C] -- A:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2012/12/22 10:48:19 | 000,000,000 | ---D | C] -- A:\Users\user\Desktop\nod32-4.0.437.x64-PL
[2012/12/22 10:36:00 | 000,000,000 | ---D | C] -- A:\Windows\SysWow64\updfiles
[2012/12/22 10:28:12 | 000,000,000 | ---D | C] -- A:\Users\user\AppData\Roaming\ESET
[2012/12/22 10:27:04 | 000,000,000 | ---D | C] -- A:\ProgramData\ESET
[2012/12/22 10:27:04 | 000,000,000 | ---D | C] -- A:\Program Files\ESET
[2012/08/19 09:44:30 | 002,982,912 | ---- | C] (Python Software Foundation) -- A:\Users\user\AppData\Roaming\python27.dll

[color=#E56717]========== Files - Modified Within 1 Day ==========[/color]

[2012/12/22 12:56:00 | 000,000,930 | ---- | M] () -- A:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/22 12:50:00 | 000,001,044 | ---- | M] () -- A:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/22 12:36:12 | 034,934,665 | ---- | M] () -- A:\Windows\SysWow64\em002_32.dat
[2012/12/22 12:36:12 | 004,910,327 | ---- | M] () -- A:\Windows\SysWow64\em023_32.dat
[2012/12/22 12:31:48 | 000,010,016 | -H-- | M] () -- A:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/22 12:31:48 | 000,010,016 | -H-- | M] () -- A:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/22 12:26:41 | 000,006,113 | ---- | M] () -- A:\Windows\SysWow64\EpfwUser.dat
[2012/12/22 12:26:38 | 000,001,040 | ---- | M] () -- A:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/22 12:26:29 | 000,067,584 | --S- | M] () -- A:\Windows\bootstat.dat
[2012/12/22 12:26:28 | 3220,578,304 | -HS- | M] () -- A:\hiberfil.sys
[2012/12/22 12:26:27 | 000,080,388 | ---- | M] () -- A:\Windows\SysNative\oodbs.lor
[2012/12/22 11:48:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- A:\Users\user\Desktop\OTL.exe
[2012/12/22 11:46:21 | 000,001,855 | ---- | M] () -- A:\Users\Public\Desktop\OnLive.lnk
[2012/12/22 11:41:47 | 001,384,391 | ---- | M] () -- A:\Windows\SysWow64\em009_64.dat
[2012/12/22 11:41:47 | 000,038,604 | ---- | M] () -- A:\Windows\SysWow64\em013_32.dat
[2012/12/22 11:41:47 | 000,038,041 | ---- | M] () -- A:\Windows\SysWow64\em013_64.dat
[2012/12/22 11:41:46 | 001,104,324 | ---- | M] () -- A:\Windows\SysWow64\em009_32.dat
[2012/12/22 11:41:46 | 000,077,288 | ---- | M] () -- A:\Windows\SysWow64\em006_64.dat
[2012/12/22 11:41:45 | 000,829,329 | ---- | M] () -- A:\Windows\SysWow64\em004_32.dat
[2012/12/22 11:41:45 | 000,776,832 | ---- | M] () -- A:\Windows\SysWow64\em003_32.dat
[2012/12/22 11:41:45 | 000,089,137 | ---- | M] () -- A:\Windows\SysWow64\em006_32.dat
[2012/12/22 11:41:45 | 000,063,506 | ---- | M] () -- A:\Windows\SysWow64\em005_32.dat
[2012/12/22 11:41:29 | 000,522,676 | ---- | M] () -- A:\Windows\SysWow64\em001_32.dat
[2012/12/22 11:41:29 | 000,066,929 | ---- | M] () -- A:\Windows\SysWow64\em000_64.dat
[2012/12/22 11:41:29 | 000,055,770 | ---- | M] () -- A:\Windows\SysWow64\em000_32.dat
[2012/12/22 11:40:30 | 006,659,832 | ---- | M] (OnLive) -- A:\Users\user\Desktop\OnLive_Setup.exe
[2012/12/22 10:47:42 | 035,472,477 | ---- | M] () -- A:\Users\user\Desktop\nod32-4.0.437.x64-PL.rar

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2012/12/22 11:46:21 | 000,001,855 | ---- | C] () -- A:\Users\Public\Desktop\OnLive.lnk
[2012/12/22 11:41:48 | 034,934,665 | ---- | C] () -- A:\Windows\SysWow64\em002_32.dat
[2012/12/22 11:41:48 | 004,910,327 | ---- | C] () -- A:\Windows\SysWow64\em023_32.dat
[2012/12/22 11:41:48 | 001,384,391 | ---- | C] () -- A:\Windows\SysWow64\em009_64.dat
[2012/12/22 11:41:48 | 001,104,324 | ---- | C] () -- A:\Windows\SysWow64\em009_32.dat
[2012/12/22 11:41:48 | 000,829,329 | ---- | C] () -- A:\Windows\SysWow64\em004_32.dat
[2012/12/22 11:41:48 | 000,776,832 | ---- | C] () -- A:\Windows\SysWow64\em003_32.dat
[2012/12/22 11:41:48 | 000,522,676 | ---- | C] () -- A:\Windows\SysWow64\em001_32.dat
[2012/12/22 11:41:48 | 000,089,137 | ---- | C] () -- A:\Windows\SysWow64\em006_32.dat
[2012/12/22 11:41:48 | 000,077,288 | ---- | C] () -- A:\Windows\SysWow64\em006_64.dat
[2012/12/22 11:41:48 | 000,066,929 | ---- | C] () -- A:\Windows\SysWow64\em000_64.dat
[2012/12/22 11:41:48 | 000,063,506 | ---- | C] () -- A:\Windows\SysWow64\em005_32.dat
[2012/12/22 11:41:48 | 000,055,770 | ---- | C] () -- A:\Windows\SysWow64\em000_32.dat
[2012/12/22 11:41:48 | 000,038,604 | ---- | C] () -- A:\Windows\SysWow64\em013_32.dat
[2012/12/22 11:41:48 | 000,038,041 | ---- | C] () -- A:\Windows\SysWow64\em013_64.dat
[2012/12/22 10:45:08 | 035,472,477 | ---- | C] () -- A:\Users\user\Desktop\nod32-4.0.437.x64-PL.rar
[2012/12/22 10:32:46 | 000,006,113 | ---- | C] () -- A:\Windows\SysWow64\EpfwUser.dat
[2012/12/16 21:48:40 | 000,003,584 | ---- | C] () -- A:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/11/11 17:10:26 | 002,577,776 | ---- | C] () -- A:\Windows\SysWow64\pbsvc_heroes.exe
[2012/10/02 15:52:05 | 000,484,352 | ---- | C] () -- A:\Windows\SysWow64\lame_enc.dll
[2012/09/27 20:31:14 | 001,636,610 | ---- | C] () -- A:\Windows\SysWow64\PerfStringBackup.INI
[2012/09/09 13:34:13 | 000,639,488 | ---- | C] () -- A:\Windows\SysWow64\ficvdec_x86.dll
[2012/08/19 09:44:30 | 004,109,312 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxmsw28uh_core_vc.dll
[2012/08/19 09:44:30 | 001,623,040 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxbase28uh_vc.dll
[2012/08/19 09:44:30 | 001,245,696 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._core_.pyd
[2012/08/19 09:44:30 | 001,195,008 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._controls_.pyd
[2012/08/19 09:44:30 | 001,167,360 | ---- | C] () -- A:\Users\user\AppData\Roaming\_ssl.pyd
[2012/08/19 09:44:30 | 000,927,744 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxmsw28uh_adv_vc.dll
[2012/08/19 09:44:30 | 000,926,720 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._gdi_.pyd
[2012/08/19 09:44:30 | 000,858,112 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._windows_.pyd
[2012/08/19 09:44:30 | 000,838,144 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._misc_.pyd
[2012/08/19 09:44:30 | 000,627,712 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxmsw28uh_html_vc.dll
[2012/08/19 09:44:30 | 000,471,552 | ---- | C] () -- A:\Users\user\AppData\Roaming\_hashlib.pyd
[2012/08/19 09:44:30 | 000,157,184 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxbase28uh_net_vc.dll
[2012/08/19 09:44:30 | 000,046,080 | ---- | C] () -- A:\Users\user\AppData\Roaming\_socket.pyd
[2012/08/19 09:44:30 | 000,031,744 | ---- | C] () -- A:\Users\user\AppData\Roaming\ForceOP.exe
[2012/08/04 09:24:46 | 000,281,520 | ---- | C] () -- A:\Windows\SysWow64\PnkBstrB.exe
[2012/08/04 09:24:45 | 000,076,888 | ---- | C] () -- A:\Windows\SysWow64\PnkBstrA.exe
[2012/02/29 21:26:56 | 000,416,064 | ---- | C] () -- A:\Windows\SysWow64\nvStreaming.exe
[2011/09/19 08:07:46 | 000,015,360 | ---- | C] () -- A:\Windows\SysWow64\bdmjpeg.dll
[2011/09/19 08:07:32 | 000,058,368 | ---- | C] () -- A:\Windows\SysWow64\bdmpegv.dll
[2003/04/09 10:28:44 | 000,233,472 | R--- | C] () -- A:\Users\user\AppData\Roaming\MafiaSetup.exe

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- A:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = A:\Windows\SysNative\shell32.dll -- [2009/07/14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009/07/14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = A:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = A:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >

Opublikowano

To jest log OTL.

Ustaw wszystko na brak .

A rejestr -skan dodatkowy na użyj filtrowania i klik na skanuj.

1364047611-U477327.png

 

STOP komentarzom typu: "AMD to gówno"! Zanim coś napiszesz, to pomyśl jak odbiorą to inni !

 

 

 

Nie pisać mi na PW w sprawach pomocy od tego macie dział komputery!!!

I nie pomagam na PW!

 

 

 

 

gardenscapes cheats

 

bakery story 2 cheat

Opublikowano

Zrobiłem tak jak kazałeś ;p

OTL logfile created on: 12/22/2012 1:44:12 PM - Run 4
OTL by OldTimer - Version 3.2.69.0	 Folder = A:\Users\user\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd

4.00 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 55.18% Memory free
14.00 Gb Paging File | 11.89 Gb Available in Paging File | 84.95% Paging File free
Paging file location(s): c:\pagefile.sys 0 0g:\pagefile.sys 6144 6144 [binary data]

%SystemDrive% = A: | %SystemRoot% = A:\Windows | %ProgramFiles% = A:\Program Files (x86)
Drive C: | 20.02 Gb Total Space | 7.52 Gb Free Space | 37.55% Space Free | Partition Type: NTFS
Drive D: | 129.02 Gb Total Space | 20.62 Gb Free Space | 15.98% Space Free | Partition Type: NTFS
Drive F: | 31.25 Gb Total Space | 1.05 Gb Free Space | 3.35% Space Free | Partition Type: NTFS
Drive G: | 29.30 Gb Total Space | 16.59 Gb Free Space | 56.62% Space Free | Partition Type: NTFS
Drive H: | 55.30 Gb Total Space | 10.62 Gb Free Space | 19.20% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 1 Day

[color=#E56717]========== Files/Folders - Created Within 1 Day ==========[/color]

[2012/12/22 12:24:51 | 000,000,000 | ---D | C] -- A:\_OTL
[2012/12/22 11:47:59 | 000,602,112 | ---- | C] (OldTimer Tools) -- A:\Users\user\Desktop\OTL.exe
[2012/12/22 11:46:31 | 000,000,000 | ---D | C] -- A:\Users\user\Documents\OnLive App
[2012/12/22 11:46:21 | 000,000,000 | ---D | C] -- A:\Users\user\AppData\Roaming\OnLive App
[2012/12/22 11:46:21 | 000,000,000 | ---D | C] -- A:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnLive
[2012/12/22 11:46:18 | 000,000,000 | ---D | C] -- A:\Program Files (x86)\OnLive
[2012/12/22 11:40:16 | 006,659,832 | ---- | C] (OnLive) -- A:\Users\user\Desktop\OnLive_Setup.exe
[2012/12/22 11:04:07 | 000,000,000 | ---D | C] -- A:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2012/12/22 10:48:19 | 000,000,000 | ---D | C] -- A:\Users\user\Desktop\nod32-4.0.437.x64-PL
[2012/12/22 10:36:00 | 000,000,000 | ---D | C] -- A:\Windows\SysWow64\updfiles
[2012/12/22 10:28:12 | 000,000,000 | ---D | C] -- A:\Users\user\AppData\Roaming\ESET
[2012/12/22 10:27:04 | 000,000,000 | ---D | C] -- A:\ProgramData\ESET
[2012/12/22 10:27:04 | 000,000,000 | ---D | C] -- A:\Program Files\ESET
[2012/08/19 09:44:30 | 002,982,912 | ---- | C] (Python Software Foundation) -- A:\Users\user\AppData\Roaming\python27.dll

[color=#E56717]========== Files - Modified Within 1 Day ==========[/color]

[2012/12/22 12:56:00 | 000,000,930 | ---- | M] () -- A:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/22 12:50:00 | 000,001,044 | ---- | M] () -- A:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/22 12:36:12 | 034,934,665 | ---- | M] () -- A:\Windows\SysWow64\em002_32.dat
[2012/12/22 12:36:12 | 004,910,327 | ---- | M] () -- A:\Windows\SysWow64\em023_32.dat
[2012/12/22 12:31:48 | 000,010,016 | -H-- | M] () -- A:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/22 12:31:48 | 000,010,016 | -H-- | M] () -- A:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/22 12:26:41 | 000,006,113 | ---- | M] () -- A:\Windows\SysWow64\EpfwUser.dat
[2012/12/22 12:26:38 | 000,001,040 | ---- | M] () -- A:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/22 12:26:29 | 000,067,584 | --S- | M] () -- A:\Windows\bootstat.dat
[2012/12/22 12:26:28 | 3220,578,304 | -HS- | M] () -- A:\hiberfil.sys
[2012/12/22 12:26:27 | 000,080,388 | ---- | M] () -- A:\Windows\SysNative\oodbs.lor
[2012/12/22 11:48:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- A:\Users\user\Desktop\OTL.exe
[2012/12/22 11:46:21 | 000,001,855 | ---- | M] () -- A:\Users\Public\Desktop\OnLive.lnk
[2012/12/22 11:41:47 | 001,384,391 | ---- | M] () -- A:\Windows\SysWow64\em009_64.dat
[2012/12/22 11:41:47 | 000,038,604 | ---- | M] () -- A:\Windows\SysWow64\em013_32.dat
[2012/12/22 11:41:47 | 000,038,041 | ---- | M] () -- A:\Windows\SysWow64\em013_64.dat
[2012/12/22 11:41:46 | 001,104,324 | ---- | M] () -- A:\Windows\SysWow64\em009_32.dat
[2012/12/22 11:41:46 | 000,077,288 | ---- | M] () -- A:\Windows\SysWow64\em006_64.dat
[2012/12/22 11:41:45 | 000,829,329 | ---- | M] () -- A:\Windows\SysWow64\em004_32.dat
[2012/12/22 11:41:45 | 000,776,832 | ---- | M] () -- A:\Windows\SysWow64\em003_32.dat
[2012/12/22 11:41:45 | 000,089,137 | ---- | M] () -- A:\Windows\SysWow64\em006_32.dat
[2012/12/22 11:41:45 | 000,063,506 | ---- | M] () -- A:\Windows\SysWow64\em005_32.dat
[2012/12/22 11:41:29 | 000,522,676 | ---- | M] () -- A:\Windows\SysWow64\em001_32.dat
[2012/12/22 11:41:29 | 000,066,929 | ---- | M] () -- A:\Windows\SysWow64\em000_64.dat
[2012/12/22 11:41:29 | 000,055,770 | ---- | M] () -- A:\Windows\SysWow64\em000_32.dat
[2012/12/22 11:40:30 | 006,659,832 | ---- | M] (OnLive) -- A:\Users\user\Desktop\OnLive_Setup.exe
[2012/12/22 10:47:42 | 035,472,477 | ---- | M] () -- A:\Users\user\Desktop\nod32-4.0.437.x64-PL.rar

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2012/12/22 11:46:21 | 000,001,855 | ---- | C] () -- A:\Users\Public\Desktop\OnLive.lnk
[2012/12/22 11:41:48 | 034,934,665 | ---- | C] () -- A:\Windows\SysWow64\em002_32.dat
[2012/12/22 11:41:48 | 004,910,327 | ---- | C] () -- A:\Windows\SysWow64\em023_32.dat
[2012/12/22 11:41:48 | 001,384,391 | ---- | C] () -- A:\Windows\SysWow64\em009_64.dat
[2012/12/22 11:41:48 | 001,104,324 | ---- | C] () -- A:\Windows\SysWow64\em009_32.dat
[2012/12/22 11:41:48 | 000,829,329 | ---- | C] () -- A:\Windows\SysWow64\em004_32.dat
[2012/12/22 11:41:48 | 000,776,832 | ---- | C] () -- A:\Windows\SysWow64\em003_32.dat
[2012/12/22 11:41:48 | 000,522,676 | ---- | C] () -- A:\Windows\SysWow64\em001_32.dat
[2012/12/22 11:41:48 | 000,089,137 | ---- | C] () -- A:\Windows\SysWow64\em006_32.dat
[2012/12/22 11:41:48 | 000,077,288 | ---- | C] () -- A:\Windows\SysWow64\em006_64.dat
[2012/12/22 11:41:48 | 000,066,929 | ---- | C] () -- A:\Windows\SysWow64\em000_64.dat
[2012/12/22 11:41:48 | 000,063,506 | ---- | C] () -- A:\Windows\SysWow64\em005_32.dat
[2012/12/22 11:41:48 | 000,055,770 | ---- | C] () -- A:\Windows\SysWow64\em000_32.dat
[2012/12/22 11:41:48 | 000,038,604 | ---- | C] () -- A:\Windows\SysWow64\em013_32.dat
[2012/12/22 11:41:48 | 000,038,041 | ---- | C] () -- A:\Windows\SysWow64\em013_64.dat
[2012/12/22 10:45:08 | 035,472,477 | ---- | C] () -- A:\Users\user\Desktop\nod32-4.0.437.x64-PL.rar
[2012/12/22 10:32:46 | 000,006,113 | ---- | C] () -- A:\Windows\SysWow64\EpfwUser.dat
[2012/12/16 21:48:40 | 000,003,584 | ---- | C] () -- A:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/11/11 17:10:26 | 002,577,776 | ---- | C] () -- A:\Windows\SysWow64\pbsvc_heroes.exe
[2012/10/02 15:52:05 | 000,484,352 | ---- | C] () -- A:\Windows\SysWow64\lame_enc.dll
[2012/09/27 20:31:14 | 001,636,610 | ---- | C] () -- A:\Windows\SysWow64\PerfStringBackup.INI
[2012/09/09 13:34:13 | 000,639,488 | ---- | C] () -- A:\Windows\SysWow64\ficvdec_x86.dll
[2012/08/19 09:44:30 | 004,109,312 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxmsw28uh_core_vc.dll
[2012/08/19 09:44:30 | 001,623,040 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxbase28uh_vc.dll
[2012/08/19 09:44:30 | 001,245,696 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._core_.pyd
[2012/08/19 09:44:30 | 001,195,008 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._controls_.pyd
[2012/08/19 09:44:30 | 001,167,360 | ---- | C] () -- A:\Users\user\AppData\Roaming\_ssl.pyd
[2012/08/19 09:44:30 | 000,927,744 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxmsw28uh_adv_vc.dll
[2012/08/19 09:44:30 | 000,926,720 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._gdi_.pyd
[2012/08/19 09:44:30 | 000,858,112 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._windows_.pyd
[2012/08/19 09:44:30 | 000,838,144 | ---- | C] () -- A:\Users\user\AppData\Roaming\wx._misc_.pyd
[2012/08/19 09:44:30 | 000,627,712 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxmsw28uh_html_vc.dll
[2012/08/19 09:44:30 | 000,471,552 | ---- | C] () -- A:\Users\user\AppData\Roaming\_hashlib.pyd
[2012/08/19 09:44:30 | 000,157,184 | ---- | C] () -- A:\Users\user\AppData\Roaming\wxbase28uh_net_vc.dll
[2012/08/19 09:44:30 | 000,046,080 | ---- | C] () -- A:\Users\user\AppData\Roaming\_socket.pyd
[2012/08/19 09:44:30 | 000,031,744 | ---- | C] () -- A:\Users\user\AppData\Roaming\ForceOP.exe
[2012/08/04 09:24:46 | 000,281,520 | ---- | C] () -- A:\Windows\SysWow64\PnkBstrB.exe
[2012/08/04 09:24:45 | 000,076,888 | ---- | C] () -- A:\Windows\SysWow64\PnkBstrA.exe
[2012/02/29 21:26:56 | 000,416,064 | ---- | C] () -- A:\Windows\SysWow64\nvStreaming.exe
[2011/09/19 08:07:46 | 000,015,360 | ---- | C] () -- A:\Windows\SysWow64\bdmjpeg.dll
[2011/09/19 08:07:32 | 000,058,368 | ---- | C] () -- A:\Windows\SysWow64\bdmpegv.dll
[2003/04/09 10:28:44 | 000,233,472 | R--- | C] () -- A:\Users\user\AppData\Roaming\MafiaSetup.exe

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- A:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = A:\Windows\SysNative\shell32.dll -- [2009/07/14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009/07/14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = A:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = A:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >

@Edit dodaje zdjęcie z ESETU to może coś pomoże

http://img59.imageshack.us/img59/4427/esety.png

Opublikowano

Przecież to log OTL .

Pokaż mi na ssy twoje ustawienia jak zaczynasz wykonywac loga .

1364047611-U477327.png

 

STOP komentarzom typu: "AMD to gówno"! Zanim coś napiszesz, to pomyśl jak odbiorą to inni !

 

 

 

Nie pisać mi na PW w sprawach pomocy od tego macie dział komputery!!!

I nie pomagam na PW!

 

 

 

 

gardenscapes cheats

 

bakery story 2 cheat

Opublikowano

Jeszcze jedno wyłącz zaporę systemową Windows , jeśli zainstalowałeś Kaspersky IS.

SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- A:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

1364047611-U477327.png

 

STOP komentarzom typu: "AMD to gówno"! Zanim coś napiszesz, to pomyśl jak odbiorą to inni !

 

 

 

Nie pisać mi na PW w sprawach pomocy od tego macie dział komputery!!!

I nie pomagam na PW!

 

 

 

 

gardenscapes cheats

 

bakery story 2 cheat

Zarchiwizowany

Ten temat przebywa obecnie w archiwum. Dodawanie nowych odpowiedzi zostało zablokowane.

×
×
  • Dodaj nową pozycję...