1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154.
155.
156.
157.
158.
159.
160.
161.
162.
163.
164.
165.
166.
167.
168.
169.
170.
171.
172.
173.
174.
175.
176.
177.
178.
179.
180.
181.
182.
183.
184.
185.
186.
187.
188.
189.
190.
191.
192.
193.
194.
195.
196.
197.
198.
199.
200.
201.
202.
203.
204.
205.
206.
207.
208.
209.
210.
211.
212.
213.
214.
215.
216.
217.
218.
219.
220.
221.
222.
223.
224.
225.
226.
227.
228.
229.
230.
231.
232.
233.
234.
235.
236.
237.
238.
239.
240.
241.
242.
243.
244.
245.
246.
247.
248.
249.
250.
251.
252.
253.
254.
255.
256.
257.
258.
259.
260.
261.
262.
263.
264.
265.
266.
267.
268.
269.
270.
271.
272.
273.
274.
275.
276.
277.
278.
279.
280.
281.
282.
283.
284.
285.
286.
287.
288.
289.
290.
291.
292.
293.
294.
295.
296.
297.
298.
299.
300.
301.
302.
303.
304.
305.
306.
307.
308.
309.
310.
311.
312.
313.
314.
315.
316.
317.
318.
319.
320.
321.
322.
323.
324.
325.
326.
327.
328.
329.
330.
331.
332.
333.
334.
335.
336.
337.
338.
339.
340.
341.
342.
343.
344.
345.
346.
347.
348.
349.
350.
351.
352.
353.
354.
355.
356.
357.
358.
359.
360.
361.
362.
363.
364.
365.
366.
367.
368.
369.
370.
371.
372.
373.
374.
375.
376.
377.
378.
379.
380.
381.
382.
383.
384.
385.
386.
387.
388.
389.
390.
391.
392.
393.
394.
395.
396.
397.
398.
399.
400.
401.
402.
403.
404.
405.
406.
407.
408.
409.
410.
411.
412.
413.
414.
415.
416.
417.
418.
419.
420.
421.
422.
423.
424.
425.
426.
427.
428.
429.
430.
431.
432.
433.
434.
435.
436.
437.
438.
439.
440.
441.
442.
443.
444.
445.
446.
447.
448.
449.
450.
451.
452.
453.
454.
455.
456.
457.
458.
459.
460.
461.
462.
463.
464.
465.
466.
467.
468.
469.
470.
471.
472.
473.
474.
475.
476.
477.
478.
479.
480.
481.
482.
483.
484.
485.
486.
487.
488.
489.
490.
491.
492.
493.
494.
495.
496. | Logfile of random\'s system information tool 1.08 (written by random/random)
Run by Vobis at 2010-09-03 22:46:24
Microsoft Windows 7 Home Premium
System drive C: has 170 GB (85%) free of 201 GB
Total RAM: 4087 MB (45% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:46:36, on 2010-09-03
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\\Windows\\SysWOW64\\svchost.exe
C:\\Program Files (x86)\\Common Files\\Nero\\Nero BackItUp 4\\NBService.exe
C:\\Program Files (x86)\\Norton Internet Security\\Engine\\17.7.0.12\\ccSvcHst.exe
c:\\Program Files (x86)\\Common Files\\Protexis\\License Service\\PsiService_2.exe
C:\\Program Files (x86)\\Microsoft\\Search Enhancement Pack\\SeaPort\\SeaPort.exe
C:\\Program Files (x86)\\Intel\\Intel(R) Rapid Storage Technology\\IAStorDataMgrSvc.exe
C:\\Program Files (x86)\\EIZO\\ScreenSlicer\\ESCSlicer.exe
C:\\Program Files (x86)\\Norton Internet Security\\Engine\\17.7.0.12\\ccSvcHst.exe
C:\\Program Files (x86)\\NEC Electronics\\USB 3.0 Host Controller Driver\\Application\\nusb3mon.exe
C:\\Program Files (x86)\\Intel\\Intel(R) Rapid Storage Technology\\IAStorIcon.exe
C:\\Program Files (x86)\\ArcSoft\\SimHD IM Plug-In\\ArcSoft SimHD IM Plug-In.exe
C:\\Program Files (x86)\\EIZO\\ScreenManager Pro for LCD\\Lcdctrl.exe
C:\\Program Files (x86)\\Spyware Doctor\\pctsAuxs.exe
C:\\Program Files (x86)\\Spyware Doctor\\pctsSvc.exe
C:\\Program Files (x86)\\Spyware Doctor\\pctsTray.exe
C:\\Program Files (x86)\\Spyware Doctor\\BDT\\BDTUpdateService.exe
C:\\Program Files (x86)\\Spyware Doctor\\pctsGui.exe
C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe
C:\\Program Files (x86)\\Mozilla Firefox\\plugin-container.exe
C:\\Users\\Vobis\\Downloads\\RSIT.exe
C:\\Program Files (x86)\\trend micro\\Vobis.exe
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://www.vobis.pl
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://www.google.pl/
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant =
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,CustomizeSearch =
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Window Title = Program Windows Internet Explorer dostarczony przez Vobis.pl
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\\Windows\\system32\\userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\\Program Files (x86)\\Common Files\\Adobe\\Acrobat\\ActiveX\\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\\Program Files (x86)\\Spyware Doctor\\BDT\\PCTBrowserDefender.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\\Program Files (x86)\\Norton Internet Security\\Engine\\17.7.0.12\\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\\Program Files (x86)\\Norton Internet Security\\Engine\\17.7.0.12\\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\\Program Files (x86)\\Microsoft\\Search Enhancement Pack\\Search Helper\\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\\PROGRA~2\\MIF5BA~1\\Office14\\GROOVEEX.DLL
O2 - BHO: Pomocnik rejestrowania za pomocą identyfikatora Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\Windows Live\\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\\PROGRA~2\\MIF5BA~1\\Office14\\URLREDIR.DLL
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\\Program Files (x86)\\Windows Live\\Toolbar\\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\\Program Files (x86)\\Windows Live\\Toolbar\\wltcore.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\\Program Files (x86)\\Norton Internet Security\\Engine\\17.7.0.12\\coIEPlg.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\\Program Files (x86)\\Spyware Doctor\\BDT\\PCTBrowserDefender.dll
O4 - HKLM\\..\\Run: [HDAudDeck] C:\\Program Files (x86)\\VIA\\VIAudioi\\VDeck\\VDeck.exe -r
O4 - HKLM\\..\\Run: [NUSB3MON] \"C:\\Program Files (x86)\\NEC Electronics\\USB 3.0 Host Controller Driver\\Application\\nusb3mon.exe\"
O4 - HKLM\\..\\Run: [IAStorIcon] C:\\Program Files (x86)\\Intel\\Intel(R) Rapid Storage Technology\\IAStorIcon.exe
O4 - HKLM\\..\\Run: [NBKeyScan] \"C:\\Program Files (x86)\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe\"
O4 - HKLM\\..\\Run: [StartCCC] \"C:\\Program Files (x86)\\ATI Technologies\\ATI.ACE\\Core-Static\\CLIStart.exe\" MSRun
O4 - HKLM\\..\\Run: [ATICustomerCare] \"C:\\Program Files (x86)\\ATI\\ATICustomerCare\\ATICustomerCare.exe\"
O4 - HKLM\\..\\Run: [ArcSimHDHook] \"C:\\Program Files (x86)\\ArcSoft\\SimHD IM Plug-In\\ArcSoft SimHD IM Plug-In.exe\"
O4 - HKLM\\..\\Run: [ScreenManager Pro for LCD] C:\\Program Files (x86)\\EIZO\\ScreenManager Pro for LCD\\Lcdctrl.exe
O4 - HKLM\\..\\Run: [SwitchBoard] C:\\Program Files (x86)\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe
O4 - HKLM\\..\\Run: [AdobeCS5ServiceManager] \"C:\\Program Files (x86)\\Common Files\\Adobe\\CS5ServiceManager\\CS5ServiceManager.exe\" -launchedbylogin
O4 - HKLM\\..\\Run: [Adobe Reader Speed Launcher] \"C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\"
O4 - HKLM\\..\\Run: [ISTray] \"C:\\Program Files (x86)\\Spyware Doctor\\pctsTray.exe\"
O4 - HKCU\\..\\Run: [OfficeSyncProcess] \"C:\\Program Files\\Microsoft Office\\Office14\\MSOSYNC.EXE\"
O4 - HKCU\\..\\Run: [Metropolis] rundll32.exe C:\\Windows\\system32\\sshnas21.dll,GetHandle
O4 - HKCU\\..\\Run: [RegistryBooster] \"C:\\Program Files (x86)\\Uniblue\\RegistryBooster\\launcher.exe\" delay 20000
O4 - HKUS\\S-1-5-19\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /autoRun (User \'USŁUGA LOKALNA\')
O4 - HKUS\\S-1-5-19\\..\\RunOnce: [mctadmin] C:\\Windows\\System32\\mctadmin.exe (User \'USŁUGA LOKALNA\')
O4 - HKUS\\S-1-5-20\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /autoRun (User \'USŁUGA SIECIOWA\')
O4 - HKUS\\S-1-5-20\\..\\RunOnce: [mctadmin] C:\\Windows\\System32\\mctadmin.exe (User \'USŁUGA SIECIOWA\')
O4 - Startup: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk = C:\\Program Files\\Microsoft Office\\Office14\\ONENOTEM.EXE
O4 - Global Startup: EIZO ScreenSlicer.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\\Windows\\system32\\GPhotos.scr/200
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\\PROGRA~1\\MICROS~2\\Office14\\EXCEL.EXE/3000
O8 - Extra context menu item: Wyślij &do programu OneNote - res://C:\\PROGRA~1\\MICROS~2\\Office14\\ONBttnIE.dll/105
O9 - Extra button: Wpis w blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\\Program Files (x86)\\Windows Live\\Writer\\WriterBrowserExtension.dll
O9 - Extra \'Tools\' menuitem: &Wpis w blogu w Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\\Program Files (x86)\\Windows Live\\Writer\\WriterBrowserExtension.dll
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\Program Files (x86)\\Microsoft Office\\Office14\\ONBttnIE.dll
O9 - Extra \'Tools\' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\Program Files (x86)\\Microsoft Office\\Office14\\ONBttnIE.dll
O9 - Extra button: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\\Program Files (x86)\\Microsoft Office\\Office14\\ONBttnIELinkedNotes.dll
O9 - Extra \'Tools\' menuitem: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\\Program Files (x86)\\Microsoft Office\\Office14\\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll
O9 - Extra \'Tools\' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\\program files (x86)\\common files\\microsoft shared\\windows live\\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\\program files (x86)\\common files\\microsoft shared\\windows live\\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\PROGRA~2\\COMMON~1\\Skype\\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\MSOXMLMF.DLL
O23 - Service: SAS Core Service (!SASCORE) - Unknown owner - C:\\Program Files\\SUPERAntiSpyware\\SASCORE64.EXE (file missing)
O23 - Service: @%SystemRoot%\\system32\\Alg.exe,-112 (ALG) - Unknown owner - C:\\Windows\\System32\\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\\Windows\\system32\\atiesrxx.exe (file missing)
O23 - Service: Browser Defender Update Service - Unknown owner - C:\\Program Files (x86)\\Spyware Doctor\\BDT\\BDTUpdateService.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\\Program Files (x86)\\Ashampoo\\Ashampoo WinOptimizer 7\\Dfsdks.exe
O23 - Service: @%SystemRoot%\\system32\\efssvc.dll,-100 (EFS) - Unknown owner - C:\\Windows\\System32\\lsass.exe (file missing)
O23 - Service: @%systemroot%\\system32\\fxsresm.dll,-118 (Fax) - Unknown owner - C:\\Windows\\system32\\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\\Program Files (x86)\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\\Program Files (x86)\\Intel\\Intel(R) Rapid Storage Technology\\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\\Windows\\System32\\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\\Program Files (x86)\\Common Files\\Nero\\Nero BackItUp 4\\NBService.exe
O23 - Service: @%SystemRoot%\\System32\\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\\Program Files (x86)\\Norton Internet Security\\Engine\\17.7.0.12\\ccSvcHst.exe
O23 - Service: @%systemroot%\\system32\\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\\Program Files (x86)\\Common Files\\Protexis\\License Service\\PsiService_2.exe
O23 - Service: @%systemroot%\\system32\\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\\Windows\\system32\\locator.exe (file missing)
O23 - Service: @%SystemRoot%\\system32\\samsrv.dll,-1 (SamSs) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\\Program Files (x86)\\Spyware Doctor\\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\\Program Files (x86)\\Spyware Doctor\\pctsSvc.exe
O23 - Service: @%SystemRoot%\\system32\\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\\Windows\\System32\\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\\system32\\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\\Windows\\System32\\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\\system32\\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\\Windows\\system32\\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\\Program Files (x86)\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe
O23 - Service: @%SystemRoot%\\system32\\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\\Windows\\system32\\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\\system32\\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\\system32\\vds.exe,-100 (vds) - Unknown owner - C:\\Windows\\System32\\vds.exe (file missing)
O23 - Service: @%systemroot%\\system32\\vssvc.exe,-102 (VSS) - Unknown owner - C:\\Windows\\system32\\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\\system32\\Wat\\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\\Windows\\system32\\Wat\\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\\system32\\wbengine.exe,-104 (wbengine) - Unknown owner - C:\\Windows\\system32\\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\\system32\\wbem\\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\\Windows\\system32\\wbem\\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\\Windows Media Player\\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\\Program Files (x86)\\Windows Media Player\\wmpnetwk.exe (file missing)
--
End of file - 13584 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\\Program Files (x86)\\Common Files\\Adobe\\Acrobat\\ActiveX\\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\\Program Files (x86)\\Spyware Doctor\\BDT\\PCTBrowserDefender.dll [2010-01-22 567248]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\\Program Files (x86)\\Norton Internet Security\\Engine\\17.7.0.12\\coIEPlg.dll [2010-05-13 394608]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\\Program Files (x86)\\Norton Internet Security\\Engine\\17.7.0.12\\IPSBHO.DLL [2010-05-14 79224]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\\Program Files (x86)\\Microsoft\\Search Enhancement Pack\\Search Helper\\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\\PROGRA~2\\MIF5BA~1\\Office14\\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocnik rejestrowania za pomocą identyfikatora Windows Live - C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\Windows Live\\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\\Program Files (x86)\\Skype\\Toolbars\\Internet Explorer\\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\\PROGRA~2\\MIF5BA~1\\Office14\\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\\Program Files (x86)\\Windows Live\\Toolbar\\wltcore.dll [2008-12-08 1067352]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\\Program Files (x86)\\Windows Live\\Toolbar\\wltcore.dll [2008-12-08 1067352]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\\Program Files (x86)\\Norton Internet Security\\Engine\\17.7.0.12\\coIEPlg.dll [2010-05-13 394608]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\\Program Files (x86)\\Spyware Doctor\\BDT\\PCTBrowserDefender.dll [2010-01-22 567248]
[HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run]
\"HDAudDeck\"=C:\\Program Files (x86)\\VIA\\VIAudioi\\VDeck\\VDeck.exe [2009-07-15 2245120]
\"NUSB3MON\"=C:\\Program Files (x86)\\NEC Electronics\\USB 3.0 Host Controller Driver\\Application\\nusb3mon.exe [2009-10-21 106496]
\"IAStorIcon\"=C:\\Program Files (x86)\\Intel\\Intel(R) Rapid Storage Technology\\IAStorIcon.exe [2009-10-02 284696]
\"NBKeyScan\"=C:\\Program Files (x86)\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe []
\"StartCCC\"=C:\\Program Files (x86)\\ATI Technologies\\ATI.ACE\\Core-Static\\CLIStart.exe [2010-05-27 98304]
\"ATICustomerCare\"=C:\\Program Files (x86)\\ATI\\ATICustomerCare\\ATICustomerCare.exe [2010-03-04 311296]
\"ArcSimHDHook\"=C:\\Program Files (x86)\\ArcSoft\\SimHD IM Plug-In\\ArcSoft SimHD IM Plug-In.exe [2009-05-27 110592]
\"ScreenManager Pro for LCD\"=C:\\Program Files (x86)\\EIZO\\ScreenManager Pro for LCD\\Lcdctrl.exe [2009-05-28 11650736]
\"SwitchBoard\"=C:\\Program Files (x86)\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe [2010-02-19 517096]
\"AdobeCS5ServiceManager\"=C:\\Program Files (x86)\\Common Files\\Adobe\\CS5ServiceManager\\CS5ServiceManager.exe [2010-07-22 402432]
\"Adobe Reader Speed Launcher\"=C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe [2009-12-22 35760]
\"ISTray\"=C:\\Program Files (x86)\\Spyware Doctor\\pctsTray.exe [2010-05-11 1287120]
[HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run]
\"OfficeSyncProcess\"=C:\\Program Files\\Microsoft Office\\Office14\\MSOSYNC.EXE [2010-03-16 908160]
\"AdobeBridge\"= []
\"Metropolis\"=C:\\Windows\\system32\\sshnas21.dll,GetHandle []
\"RegistryBooster\"=C:\\Program Files (x86)\\Uniblue\\RegistryBooster\\launcher.exe delay 20000 []
C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup
EIZO ScreenSlicer.lnk - C:\\Windows\\Installer\\{292A177D-723F-4537-9985-BC8BFCD8B63D}\\ESCSlicer.exe1_87A06423E78E426E924121140A36B659.exe
C:\\Users\\Vobis\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup
Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk - C:\\Program Files (x86)\\Microsoft Office\\Office14\\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellExecuteHooks]
\"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}\"=C:\\PROGRA~2\\MIF5BA~1\\Office14\\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\\system\\currentcontrolset\\control\\securityproviders]
\"SecurityProviders\"=credssp.dll
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal\\!SASCORE]
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\network\\!SASCORE]
[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\network\\AFD]
[HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System]
\"DisableTaskMgr\"=0
[HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System]
\"ConsentPromptBehaviorAdmin\"=0
\"ConsentPromptBehaviorUser\"=3
\"EnableLUA\"=0
\"EnableUIADesktopToggle\"=0
\"PromptOnSecureDesktop\"=0
\"dontdisplaylastusername\"=0
\"legalnoticecaption\"=
\"legalnoticetext\"=
\"shutdownwithoutlogon\"=1
\"undockwithoutlogon\"=1
\"DisableTaskMgr\"=0
[HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\explorer]
\"NoDriveTypeAutoRun\"=145
\"NoActiveDesktopChanges\"=0
\"NoSetActiveDesktop\"=0
[HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\explorer]
\"NoActiveDesktop\"=1
\"NoActiveDesktopChanges\"=0
\"ForceActiveDesktopOn\"=0
\"NoSetActiveDesktop\"=0
[HKEY_LOCAL_MACHINE\\system\\currentcontrolset\\services\\sharedaccess\\parameters\\firewallpolicy\\standardprofile\\authorizedapplications\\list]
[HKEY_LOCAL_MACHINE\\system\\currentcontrolset\\services\\sharedaccess\\parameters\\firewallpolicy\\domainprofile\\authorizedapplications\\list]
======File associations======
.js - edit - C:\\Windows\\System32\\Notepad.exe %1
.js - open - C:\\Windows\\System32\\WScript.exe \"%1\" %*
======List of files/folders created in the last 1 months======
2010-09-03 22:46:25 ----D---- C:\\Program Files (x86)\\trend micro
2010-09-03 22:46:24 ----D---- C:\\rsit
2010-09-03 22:06:03 ----A---- C:\\Windows\\SGDetectionTool.dll
2010-09-03 22:06:03 ----A---- C:\\Windows\\PCTBDRes.dll
2010-09-03 22:06:03 ----A---- C:\\Windows\\PCTBDCore.dll
2010-09-03 22:06:03 ----A---- C:\\Windows\\BDTSupport.dll
2010-09-03 22:05:28 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\PC Tools
2010-09-03 22:05:28 ----D---- C:\\ProgramData\\PC Tools
2010-09-03 22:05:28 ----D---- C:\\Program Files (x86)\\Spyware Doctor
2010-09-03 22:05:28 ----D---- C:\\Program Files (x86)\\Common Files\\PC Tools
2010-09-03 22:05:10 ----AD---- C:\\ProgramData\\TEMP
2010-09-03 19:05:07 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\Malwarebytes
2010-09-03 19:05:02 ----D---- C:\\ProgramData\\Malwarebytes
2010-09-03 19:05:02 ----D---- C:\\Program Files (x86)\\Malwarebytes\' Anti-Malware
2010-09-02 21:49:01 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\Tific
2010-09-02 19:26:02 ----D---- C:\\Program Files (x86)\\Uniblue
2010-09-02 18:54:58 ----D---- C:\\ProgramData\\PrevxCSI
2010-09-01 22:49:27 ----D---- C:\\Program Files (x86)\\uTorrent
2010-09-01 22:48:33 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\uTorrent
2010-09-01 22:44:53 ----D---- C:\\Program Files (x86)\\Common Files\\Corel
2010-09-01 22:37:41 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\Uniblue
2010-09-01 21:40:34 ----D---- C:\\ProgramData\\SUPERAntiSpyware.com
2010-09-01 21:40:31 ----D---- C:\\ProgramData\\!SASCORE
2010-08-27 19:15:15 ----A---- C:\\Windows\\SysWOW64\\D3DX9_42.dll
2010-08-27 19:15:15 ----A---- C:\\Windows\\SysWOW64\\d3dx10_42.dll
2010-08-27 19:15:12 ----D---- C:\\Windows\\SysWOW64\\xlive
2010-08-27 19:15:09 ----D---- C:\\Program Files (x86)\\Microsoft Games for Windows - LIVE
2010-08-26 19:24:43 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\THQ
2010-08-26 19:24:04 ----RHD---- C:\\Users\\Vobis\\AppData\\Roaming\\SecuROM
2010-08-26 19:24:03 ----A---- C:\\Windows\\SysWOW64\\CmdLineExt_x64.dll
2010-08-26 19:22:00 ----D---- C:\\ProgramData\\InstallShield
2010-08-26 19:16:23 ----A---- C:\\Windows\\SysWOW64\\xactengine2_8.dll
2010-08-26 19:16:23 ----A---- C:\\Windows\\SysWOW64\\x3daudio1_2.dll
2010-08-26 19:16:23 ----A---- C:\\Windows\\SysWOW64\\d3dx9_34.dll
2010-08-26 19:16:23 ----A---- C:\\Windows\\SysWOW64\\d3dx10_34.dll
2010-08-26 19:16:23 ----A---- C:\\Windows\\SysWOW64\\D3DCompiler_34.dll
2010-08-26 19:16:22 ----A---- C:\\Windows\\SysWOW64\\xinput1_3.dll
2010-08-26 19:16:22 ----A---- C:\\Windows\\SysWOW64\\xactengine2_7.dll
2010-08-26 19:16:22 ----A---- C:\\Windows\\SysWOW64\\d3dx10_33.dll
2010-08-26 19:16:22 ----A---- C:\\Windows\\SysWOW64\\D3DCompiler_33.dll
2010-08-26 19:16:21 ----A---- C:\\Windows\\SysWOW64\\xactengine2_5.dll
2010-08-26 19:16:21 ----A---- C:\\Windows\\SysWOW64\\d3dx9_33.dll
2010-08-26 19:16:21 ----A---- C:\\Windows\\SysWOW64\\d3dx10.dll
2010-08-26 19:16:20 ----A---- C:\\Windows\\SysWOW64\\xactengine2_4.dll
2010-08-26 19:16:20 ----A---- C:\\Windows\\SysWOW64\\x3daudio1_1.dll
2010-08-26 19:16:20 ----A---- C:\\Windows\\SysWOW64\\d3dx9_31.dll
2010-08-26 19:16:19 ----A---- C:\\Windows\\SysWOW64\\xinput1_2.dll
2010-08-26 19:16:19 ----A---- C:\\Windows\\SysWOW64\\xactengine2_3.dll
2010-08-26 19:16:19 ----A---- C:\\Windows\\SysWOW64\\xactengine2_2.dll
2010-08-26 19:16:18 ----A---- C:\\Windows\\SysWOW64\\xinput1_1.dll
2010-08-26 19:16:18 ----A---- C:\\Windows\\SysWOW64\\xactengine2_1.dll
2010-08-26 19:16:15 ----A---- C:\\Windows\\SysWOW64\\x3daudio1_0.dll
2010-08-26 19:16:15 ----A---- C:\\Windows\\SysWOW64\\d3dx9_29.dll
2010-08-26 19:16:14 ----A---- C:\\Windows\\SysWOW64\\d3dx9_27.dll
2010-08-26 19:16:14 ----A---- C:\\Windows\\SysWOW64\\d3dx9_26.dll
2010-08-26 19:16:13 ----A---- C:\\Windows\\SysWOW64\\d3dx9_25.dll
2010-08-26 19:16:13 ----A---- C:\\Windows\\SysWOW64\\d3dx9_24.dll
2010-08-25 20:48:56 ----A---- C:\\Windows\\SysWOW64\\oleaut32.dll
2010-08-22 18:53:45 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\skypePM
2010-08-22 18:50:19 ----D---- C:\\ProgramData\\regid.1986-12.com.adobe
2010-08-22 18:47:49 ----D---- C:\\Program Files (x86)\\Adobe Media Player
2010-08-22 18:46:35 ----D---- C:\\Program Files (x86)\\Common Files\\Adobe AIR
2010-08-22 18:35:55 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\Skype
2010-08-22 18:34:23 ----RD---- C:\\Program Files (x86)\\Skype
2010-08-22 18:34:23 ----D---- C:\\Program Files (x86)\\Common Files\\Skype
2010-08-22 18:34:22 ----D---- C:\\ProgramData\\Skype
2010-08-21 21:57:39 ----D---- C:\\ProgramData\\Bitstream
2010-08-21 20:41:02 ----A---- C:\\Windows\\SysWOW64\\DfSdkBt32.exe
2010-08-21 20:04:41 ----D---- C:\\Program Files (x86)\\Ashampoo
2010-08-21 19:12:48 ----A---- C:\\ProgramData\\mazuki.dll
2010-08-21 19:01:58 ----D---- C:\\Program Files (x86)\\Common Files\\Akamai
2010-08-21 18:17:58 ----D---- C:\\Windows\\PCHEALTH
2010-08-21 18:16:58 ----D---- C:\\Program Files (x86)\\Microsoft Visual Studio 8
2010-08-21 18:16:27 ----D---- C:\\Program Files (x86)\\Microsoft Analysis Services
2010-08-21 18:16:22 ----D---- C:\\Program Files (x86)\\Microsoft Office
2010-08-21 18:16:10 ----RHD---- C:\\MSOCache
2010-08-15 18:01:38 ----D---- C:\\ProgramData\\Protexis
2010-08-15 18:01:37 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\Corel
2010-08-15 17:58:34 ----D---- C:\\Program Files (x86)\\Microsoft SDKs
2010-08-15 17:58:33 ----D---- C:\\Program Files (x86)\\Microsoft.NET
2010-08-15 17:58:33 ----D---- C:\\Program Files (x86)\\Microsoft Visual Studio 9.0
2010-08-15 17:58:05 ----D---- C:\\ProgramData\\Corel
2010-08-15 17:58:05 ----D---- C:\\Program Files (x86)\\Common Files\\Protexis
2010-08-15 17:56:42 ----D---- C:\\Program Files (x86)\\Corel
2010-08-15 16:41:40 ----A---- C:\\Windows\\BcdLog.txt
2010-08-15 16:40:12 ----D---- C:\\Program Files (x86)\\EASEUS
2010-08-15 15:12:41 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\WinRAR
2010-08-14 18:57:44 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\vlc
2010-08-14 18:57:43 ----D---- C:\\Program Files (x86)\\Flash Player
2010-08-14 18:57:37 ----D---- C:\\Program Files (x86)\\Conduit
2010-08-14 17:55:20 ----D---- C:\\Program Files (x86)\\Google
2010-08-13 22:10:30 ----D---- C:\\Program Files (x86)\\DAEMON Tools Lite
2010-08-13 22:09:42 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\DAEMON Tools Lite
2010-08-13 22:09:38 ----D---- C:\\ProgramData\\DAEMON Tools Lite
2010-08-13 20:06:22 ----D---- C:\\Program Files (x86)\\Real Alternative
2010-08-13 20:06:22 ----A---- C:\\Windows\\SysWOW64\\rmoc3260.dll
2010-08-13 20:06:22 ----A---- C:\\Windows\\SysWOW64\\pndx5032.dll
2010-08-13 20:06:22 ----A---- C:\\Windows\\SysWOW64\\pndx5016.dll
2010-08-13 20:06:22 ----A---- C:\\Windows\\SysWOW64\\pncrt.dll
2010-08-13 20:06:22 ----A---- C:\\Windows\\SysWOW64\\msvcr71.dll
2010-08-13 20:06:22 ----A---- C:\\Windows\\SysWOW64\\msvcp71.dll
2010-08-12 22:36:47 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\EIZO
2010-08-12 22:36:45 ----D---- C:\\Program Files (x86)\\EIZO
2010-08-12 21:25:08 ----D---- C:\\ProgramData\\ALLPlayer
2010-08-12 21:25:08 ----A---- C:\\Windows\\SysWOW64\\xvidcore.dll
2010-08-12 21:25:08 ----A---- C:\\Windows\\SysWOW64\\libFLAC.dll
2010-08-12 21:25:07 ----D---- C:\\Program Files (x86)\\NAPI-PROJEKT
2010-08-12 21:25:04 ----D---- C:\\Program Files (x86)\\ALLPlayer
2010-08-12 21:13:30 ----D---- C:\\ProgramData\\McAfee
2010-08-12 20:12:11 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\Mozilla
2010-08-12 20:12:02 ----D---- C:\\Program Files (x86)\\Mozilla Firefox
2010-08-12 18:03:34 ----A---- C:\\Windows\\SysWOW64\\schannel.dll
2010-08-12 18:03:20 ----A---- C:\\Windows\\SysWOW64\\shell32.dll
2010-08-12 18:03:17 ----A---- C:\\Windows\\SysWOW64\\ntkrnlpa.exe
2010-08-12 18:03:16 ----A---- C:\\Windows\\SysWOW64\\ntoskrnl.exe
2010-08-12 18:03:14 ----A---- C:\\Windows\\SysWOW64\\mshtml.dll
2010-08-12 18:03:13 ----A---- C:\\Windows\\SysWOW64\\wininet.dll
2010-08-12 18:03:13 ----A---- C:\\Windows\\SysWOW64\\urlmon.dll
2010-08-12 18:03:13 ----A---- C:\\Windows\\SysWOW64\\mstime.dll
2010-08-12 18:03:13 ----A---- C:\\Windows\\SysWOW64\\msfeedssync.exe
2010-08-12 18:03:13 ----A---- C:\\Windows\\SysWOW64\\msfeedsbs.dll
2010-08-12 18:03:13 ----A---- C:\\Windows\\SysWOW64\\jsproxy.dll
2010-08-12 18:03:13 ----A---- C:\\Windows\\SysWOW64\\ieui.dll
2010-08-12 18:03:13 ----A---- C:\\Windows\\SysWOW64\\iepeers.dll
2010-08-12 18:03:13 ----A---- C:\\Windows\\SysWOW64\\ieframe.dll
2010-08-12 18:03:13 ----A---- C:\\Windows\\SysWOW64\\iedkcs32.dll
2010-08-12 18:03:07 ----A---- C:\\Windows\\SysWOW64\\rtutils.dll
2010-08-12 18:03:06 ----A---- C:\\Windows\\SysWOW64\\iccvid.dll
2010-08-12 18:03:05 ----A---- C:\\Windows\\SysWOW64\\msxml3.dll
2010-08-12 17:40:09 ----D---- C:\\Program Files (x86)\\Common Files\\Symantec Shared
======List of files/folders modified in the last 1 months======
2010-09-03 22:46:30 ----D---- C:\\Windows\\Temp
2010-09-03 22:46:25 ----RD---- C:\\Program Files (x86)
2010-09-03 22:13:16 ----D---- C:\\Windows\\System32
2010-09-03 22:13:16 ----D---- C:\\Windows\\inf
2010-09-03 22:06:03 ----D---- C:\\Windows
2010-09-03 22:05:42 ----SHD---- C:\\Windows\\Installer
2010-09-03 22:05:40 ----D---- C:\\Windows\\winsxs
2010-09-03 22:05:28 ----HD---- C:\\ProgramData
2010-09-03 22:05:28 ----D---- C:\\Program Files (x86)\\Common Files
2010-09-03 22:04:11 ----SHD---- C:\\System Volume Information
2010-09-03 22:02:34 ----D---- C:\\Windows\\SysWOW64\\drivers
2010-09-03 19:07:28 ----D---- C:\\Windows\\Tasks
2010-09-02 23:03:28 ----RD---- C:\\Program Files
2010-09-02 20:25:24 ----HD---- C:\\Program Files (x86)\\InstallShield Installation Information
2010-09-02 20:25:24 ----D---- C:\\Windows\\SysWOW64
2010-09-01 22:46:03 ----RSD---- C:\\Windows\\assembly
2010-09-01 22:27:35 ----D---- C:\\Windows\\Microsoft.NET
2010-09-01 22:11:35 ----D---- C:\\Program Files (x86)\\Microsoft Silverlight
2010-09-01 21:36:42 ----D---- C:\\Windows\\SysWOW64\\pl-PL
2010-09-01 21:34:42 ----D---- C:\\Windows\\SysWOW64\\en-US
2010-08-27 19:15:13 ----D---- C:\\Windows\\Logs
2010-08-26 21:24:14 ----D---- C:\\Windows\\Prefetch
2010-08-26 20:59:23 ----SD---- C:\\Users\\Vobis\\AppData\\Roaming\\Microsoft
2010-08-26 19:09:21 ----D---- C:\\Windows\\Downloaded Program Files
2010-08-26 19:09:17 ----D---- C:\\Program Files (x86)\\Common Files\\InstallShield
2010-08-25 21:41:52 ----D---- C:\\Windows\\AppPatch
2010-08-23 19:28:21 ----D---- C:\\Program Files (x86)\\Common Files\\Adobe
2010-08-23 19:27:59 ----D---- C:\\ProgramData\\Adobe
2010-08-23 18:54:57 ----SD---- C:\\ProgramData\\Microsoft
2010-08-23 18:48:55 ----D---- C:\\Users\\Vobis\\AppData\\Roaming\\Adobe
2010-08-23 18:39:47 ----D---- C:\\Program Files (x86)\\Adobe
2010-08-22 18:48:35 ----RSD---- C:\\Windows\\Fonts
2010-08-21 22:17:46 ----D---- C:\\ProgramData\\Microsoft Help
2010-08-21 19:27:38 ----D---- C:\\Windows\\debug
2010-08-21 18:18:31 ----D---- C:\\Windows\\ShellNew
2010-08-21 18:18:05 ----D---- C:\\Program Files (x86)\\MSBuild
2010-08-21 18:17:32 ----D---- C:\\Program Files (x86)\\Common Files\\microsoft shared
2010-08-21 18:16:37 ----A---- C:\\Windows\\win.ini
2010-08-12 20:34:29 ----D---- C:\\Program Files (x86)\\Microsoft
2010-08-12 20:31:35 ----D---- C:\\Program Files (x86)\\Common Files\\System
2010-08-12 20:21:54 ----D---- C:\\Program Files (x86)\\Internet Explorer
2010-08-12 20:21:53 ----D---- C:\\Windows\\SysWOW64\\migration
2010-08-12 17:21:52 ----D---- C:\\ProgramData\\Norton
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel RAID Controller; C:\\Windows\\system32\\DRIVERS\\iaStor.sys []
R0 pciide;pciide; C:\\Windows\\system32\\DRIVERS\\pciide.sys []
R0 PCTCore;PCTools KDS; C:\\Windows\\system32\\drivers\\PCTCore64.sys []
R0 rdyboost;ReadyBoost; C:\\Windows\\System32\\drivers\\rdyboost.sys []
R0 sptd;sptd; C:\\Windows\\System32\\Drivers\\sptd.sys []
R0 SymDS;Symantec Data Store; C:\\Windows\\system32\\drivers\\NISx64\\1107000.00C\\SYMDS64.SYS []
R0 SymEFA;Symantec Extended File Attributes; C:\\Windows\\system32\\drivers\\NISx64\\1107000.00C\\SYMEFA64.SYS []
R1 BHDrvx64;BHDrvx64; \\??\\C:\\ProgramData\\Norton\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\NIS_17.0.0.136\\Definitions\\BASHDefs\\20100810.004\\BHDrvx64.sys [2010-08-10 945200]
R1 ccHP;Symantec Hash Provider; C:\\Windows\\system32\\drivers\\NISx64\\1107000.00C\\ccHPx64.sys []
R1 eeCtrl;Symantec Eraser Control driver; \\??\\C:\\Program Files (x86)\\Common Files\\Symantec Shared\\EENGINE\\eeCtrl64.sys [2010-08-12 475696]
R1 IDSVia64;IDSVia64; \\??\\C:\\ProgramData\\Norton\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\NIS_17.0.0.136\\Definitions\\IPSDefs\\20100901.003\\IDSvia64.sys [2010-08-09 463408]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\\Windows\\system32\\drivers\\NISx64\\1107000.00C\\SRTSPX64.SYS []
R1 SymIRON;Symantec Iron Driver; C:\\Windows\\system32\\drivers\\NISx64\\1107000.00C\\Ironx64.SYS []
R1 SYMTDIv;Symantec Vista Network Dispatch Driver; C:\\Windows\\System32\\Drivers\\NISx64\\1107000.00C\\SYMTDIV.SYS []
R1 vwififlt;Virtual WiFi Filter Driver; C:\\Windows\\system32\\DRIVERS\\vwififlt.sys []
R3 amdkmdag;amdkmdag; C:\\Windows\\system32\\DRIVERS\\atikmdag.sys []
R3 amdkmdap;amdkmdap; C:\\Windows\\system32\\DRIVERS\\atikmpag.sys []
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\\Windows\\system32\\drivers\\AtiHdmi.sys []
R3 BthEnum;Sterownik Bluetooth Request Block; C:\\Windows\\system32\\DRIVERS\\BthEnum.sys []
R3 BthPan;Urządzenie Bluetooth (sieć osobista); C:\\Windows\\system32\\DRIVERS\\bthpan.sys []
R3 BTHUSB;Sterownik USB odbiornika radiowego Bluetooth; C:\\Windows\\System32\\Drivers\\BTHUSB.sys []
R3 dc3d;MS Hardware Device Detection Driver (USB); C:\\Windows\\system32\\DRIVERS\\dc3d.sys []
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \\??\\C:\\Program Files (x86)\\Common Files\\Symantec Shared\\EENGINE\\EraserUtilRebootDrv.sys [2010-08-12 132656]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\\Windows\\system32\\DRIVERS\\ASACPI.sys []
R3 NAVENG;NAVENG; \\??\\C:\\ProgramData\\Norton\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\NIS_17.0.0.136\\Definitions\\VirusDefs\\20100903.004\\ENG64.SYS [2010-08-12 117808]
R3 NAVEX15;NAVEX15; \\??\\C:\\ProgramData\\Norton\\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\\NIS_17.0.0.136\\Definitions\\VirusDefs\\20100903.004\\EX64.SYS [2010-08-12 1791536]
R3 netr7364;Sterownik karty RT73 USB Wireless LAN dla systemu Vista; C:\\Windows\\system32\\DRIVERS\\netr7364.sys []
R3 NuidFltr;NUID filter driver; C:\\Windows\\system32\\DRIVERS\\NuidFltr.sys []
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\\Windows\\system32\\DRIVERS\\nusb3hub.sys []
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver; C:\\Windows\\system32\\DRIVERS\\nusb3xhc.sys []
R3 RFCOMM;Urządzenie Bluetooth (Protokół TDI RFCOMM); C:\\Windows\\system32\\DRIVERS\\rfcomm.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\\Windows\\system32\\DRIVERS\\Rt64win7.sys []
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\\Windows\\System32\\Drivers\\NISx64\\1107000.00C\\SRTSP64.SYS []
R3 SymEvent;SymEvent; \\??\\C:\\Windows\\system32\\Drivers\\SYMEVENT64x86.SYS []
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\\Windows\\system32\\drivers\\viahduaa.sys []
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\\Windows\\system32\\DRIVERS\\vwifimp.sys []
S3 almninb8;almninb8; C:\\Windows\\SysWOW64\\drivers\\almninb8.sys []
S3 atikmdag;atikmdag; C:\\Windows\\system32\\DRIVERS\\atikmdag.sys []
S3 BTHPORT;Sterownik portu Bluetooth; C:\\Windows\\System32\\Drivers\\BTHport.sys []
S3 fssfltr;FssFltr; C:\\Windows\\system32\\DRIVERS\\fssfltr.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Akamai;Akamai NetSession Interface; C:\\Windows\\System32\\svchost.exe [2009-07-14 20992]
R2 AMD External Events Utility;AMD External Events Utility; C:\\Windows\\system32\\atiesrxx.exe []
R2 Browser Defender Update Service;Browser Defender Update Service; C:\\Program Files (x86)\\Spyware Doctor\\BDT\\BDTUpdateService.exe [2010-01-22 112592]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\\Program Files (x86)\\Intel\\Intel(R) Rapid Storage Technology\\IAStorDataMgrSvc.exe [2009-10-02 13336]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\\Program Files (x86)\\Common Files\\Nero\\Nero BackItUp 4\\NBService.exe [2009-10-13 935208]
R2 NIS;Norton Internet Security; C:\\Program Files (x86)\\Norton Internet Security\\Engine\\17.7.0.12\\ccSvcHst.exe [2010-02-26 126392]
R2 PSI_SVC_2;Protexis Licensing V2; c:\\Program Files (x86)\\Common Files\\Protexis\\License Service\\PsiService_2.exe [2010-03-10 189728]
R2 sdAuxService;PC Tools Auxiliary Service; C:\\Program Files (x86)\\Spyware Doctor\\pctsAuxs.exe [2010-03-11 366840]
R2 sdCoreService;PC Tools Security Service; C:\\Program Files (x86)\\Spyware Doctor\\pctsSvc.exe [2010-03-15 1142224]
R2 SeaPort;SeaPort; C:\\Program Files (x86)\\Microsoft\\Search Enhancement Pack\\SeaPort\\SeaPort.exe [2009-05-19 240512]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WLIDSVC.EXE [2009-03-30 2297216]
S2 !SASCORE;SAS Core Service; C:\\Program Files\\SUPERAntiSpyware\\SASCORE64.EXE []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\mscorsvw.exe [2010-03-18 138576]
S3 DfSdkS;Defragmentation-Service; C:\\Program Files (x86)\\Ashampoo\\Ashampoo WinOptimizer 7\\Dfsdks.exe [2009-08-24 544768]
S3 fsssvc;Bezpieczeństwo rodzinne usługi Windows Live; C:\\Program Files (x86)\\Windows Live\\Family Safety\\fsssvc.exe [2008-12-08 533344]
S3 gusvc;Google Updater Service; C:\\Program Files (x86)\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe [2009-12-22 136120]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE [2010-03-25 51456888]
S3 ose64;Office 64 Source Engine; C:\\Program Files\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\\Program Files\\Common Files\\Microsoft Shared\\OfficeSoftwareProtectionPlatform\\OSPPSVC.EXE [2010-01-09 4925184]
S3 SwitchBoard;SwitchBoard; C:\\Program Files (x86)\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\\system32\\Wat\\WatUX.exe,-601; C:\\Windows\\system32\\Wat\\WatAdminSvc.exe []
-----------------EOF----------------- |