Logi, zabezpieczenie komputera, danych. Programy antywirusowe antyspyware, firewall itp.

Regulamin forum

1. Każdy temat powinien odzwierciedlać treść wątku.
2. W przypadku wklejania logów; należy je wykonać od razu przynajmniej z dwóch narzędzi: FRST oraz z GMER
3. Wszelkie logi proszę publikować na przeznaczonych do tego stronach a w poście wklejać tylko link.
4. Nie wskazane jest skracanie logów, należy wkleić cały - od początku, do końca.
5. Nie wskazane jest podczepianie się do tematów innych użytkowników - proszę założyć nowy temat w dziale Bezpieczeństwo, ułatwi to pomoc sprawdzającemu.
6. Osoby nie posiadające odpowiedniej wiedzy, nie powinny sprawdzać logów, ponieważ grozi to poważnym uszkodzeniem systemu lub aplikacji zainstalowanych na komputerze.
7. Należy dokładnie opisać problem, występujące objawy oraz wszelkie podjęte działania.
8. Każdy skrypt jest unikatowy, napisany dla każdego przypadku z osobna, więc nie może być stosowany przez innych.
9. W przypadku zamieszczenia zrzutu ekranu (screenshot'a) proszę korzystać z zewnętrznego serwisu oferującego hosting zdjęć.
Wyślij odpowiedź

Przy włączeniu komputera pojawia się błąd FsUSBService

03 Lis 2011, 19:24

Witam, od kilku dni komputer chodzi dosyć topornie, przy włączeniu pojawia mi się błąd FsUSBService, dlatego proszę o sprawdzenie logów:

HT: http://www.wklej.eu/index.php?id=6024b8d851
OTL: http://www.wklej.eu/index.php?id=12400f6980
OTL extras: http://www.wklej.eu/index.php?id=c8d268259f
Gmer: Zaraz będzie

Jeżeli potrzebujecie coś jeszcze to proszę pisać, pozdrawiam.

Re: Dziwne zachowania komputera - Prośba o sprawdzenie logów

03 Lis 2011, 19:47

Odinstaluj -> HiJackThis, Conduit Engine, ESET Online Scanner, PCSafeDoctor, uTorrentBar Toolbar, Ant.com Download Toolbar, VShareToolBar.

Następnie uruchom OTL -> w oknie Własne opcje skanowania/skrypt wklej:

Kod:
:OTL

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/419
IE - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTo1.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
CHR - plugin: Google Update (Enabled) = C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
[2011-11-03 17:40:04 | 000,001,062 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2844641534-2190261356-4039628113-1001UA.job
[2011-11-03 17:40:02 | 000,001,010 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2844641534-2190261356-4039628113-1001Core.job
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:302A9871

:Files
C:\Users\Patryk\AppData\Local\Google\Update
C:\Users\Patryk\Desktop\ComboFix.exe
C:\Users\Patryk\Desktop\HiJackThis.lnk
C:\Windows\PEV.exe
C:\Windows\sed.exe
C:\Windows\grep.exe
C:\Windows\zip.exe
C:\Windows\MusiccityDownload.exe

:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=-
"SysTrayApp"=-
[HKEY_USERS\S-1-5-21-2844641534-2190261356-4039628113-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"RGSC"=-

:Commands
[clearallrestorepoints]
[emptytemp]


Klikasz Wykonaj skrypt. Dajesz log z usuwania. Następnie podajesz nowe logi z OTL.

Re: Dziwne zachowania komputera - Prośba o sprawdzenie logów

03 Lis 2011, 20:59

Z usuwania:

Kod:
All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ not found.
File C:\Program Files\uTorrentBar\tbuTo1.dll not found.
HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-2844641534-2190261356-4039628113-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ not found.
File C:\Program Files\uTorrentBar\tbuTo1.dll not found.
HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll moved successfully.
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
File C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll not found.
File C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll not found.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2844641534-2190261356-4039628113-1001UA.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2844641534-2190261356-4039628113-1001Core.job moved successfully.
Unable to delete ADS Alternate Data Stream - 119 bytes  C:\ProgramData\TEMP:302A9871 .
========== FILES ==========
C:\Users\Patryk\AppData\Local\Google\Update\Install folder moved successfully.
C:\Users\Patryk\AppData\Local\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96} folder moved successfully.
C:\Users\Patryk\AppData\Local\Google\Update\Download\{52108E14-C9AB-4399-9374-13B6E4F68B1D} folder moved successfully.
C:\Users\Patryk\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\15.0.874.106 folder moved successfully.
C:\Users\Patryk\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D} folder moved successfully.
C:\Users\Patryk\AppData\Local\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.79 folder moved successfully.
C:\Users\Patryk\AppData\Local\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D} folder moved successfully.
C:\Users\Patryk\AppData\Local\Google\Update\Download folder moved successfully.
C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.79 folder moved successfully.
C:\Users\Patryk\AppData\Local\Google\Update folder moved successfully.
C:\Users\Patryk\Desktop\ComboFix.exe moved successfully.
File\Folder C:\Users\Patryk\Desktop\HiJackThis.lnk not found.
C:\Windows\PEV.exe moved successfully.
C:\Windows\sed.exe moved successfully.
C:\Windows\grep.exe moved successfully.
C:\Windows\zip.exe moved successfully.
C:\Windows\MusiccityDownload.exe moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\StartCCC deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SysTrayApp deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2844641534-2190261356-4039628113-1001\Software\Microsoft\Windows\CurrentVersion\Run\\RGSC deleted successfully.
========== COMMANDS ==========

 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Patryk
->Temp folder emptied: 502401429 bytes
->Temporary Internet Files folder emptied: 11391163 bytes
->Java cache emptied: 4940227 bytes
->Google Chrome cache emptied: 158557242 bytes
->Opera cache emptied: 3643104 bytes
->Flash cache emptied: 86018 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 654464 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 650,00 mb
 
 
OTL by OldTimer - Version 3.2.31.0 log created on 11032011_195058

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...


Nowe logi:

Kod:
OTL logfile created on: 2011-11-03 19:55:40 - Run 2
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Users\Patryk\Downloads
 Ultimate Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
 
2,00 Gb Total Physical Memory | 1,06 Gb Available Physical Memory | 53,01% Memory free
4,47 Gb Paging File | 3,39 Gb Available in Paging File | 75,79% Paging File free
Paging file location(s): [Binary data over 100 bytes]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48,73 Gb Total Space | 1,96 Gb Free Space | 4,03% Space Free | Partition Type: NTFS
Drive D: | 146,92 Gb Total Space | 0,35 Gb Free Space | 0,24% Space Free | Partition Type: NTFS
Drive E: | 176,66 Gb Total Space | 5,30 Gb Free Space | 3,00% Space Free | Partition Type: NTFS
 
Computer Name: PATRYK-PC | User Name: Patryk | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
[color=#E56717]========== Processes (SafeList) ==========[/color]
 
PRC - [2011-11-03 18:16:26 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Patryk\Downloads\OTL.exe
PRC - [2011-10-20 12:58:40 | 002,497,352 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2011-10-07 18:47:13 | 001,883,328 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011-09-08 18:30:10 | 000,401,408 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2011-09-08 18:29:46 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2011-08-04 13:34:46 | 001,361,288 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011-07-16 10:56:22 | 000,024,992 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\AllShare\AllShareDMS\AllShareDMS.exe
PRC - [2011-04-22 13:21:10 | 000,092,592 | ---- | M] (TomTom) -- E:\Zainstalowane\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2011-03-29 18:43:34 | 000,399,736 | ---- | M] (BitTorrent, Inc.) -- E:\Zainstalowane\uTorrent\uTorrent.exe
PRC - [2011-02-26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011-01-24 14:07:58 | 000,151,432 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
PRC - [2010-10-25 10:03:52 | 000,217,088 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe
PRC - [2009-08-29 07:00:12 | 000,966,656 | ---- | M] () -- C:\Users\Patryk\Local Settings\Apps\F.lux\flux.exe
PRC - [2009-07-14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009-07-14 02:14:12 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2009-06-11 15:59:58 | 000,217,185 | ---- | M] (IDT, Inc.) -- c:\Program Files\IDT\v114_ECS_D_6207.2V7_6099.8xp_G2.0V_RC_SDC\WDM\stacsv.exe
 
 
[color=#E56717]========== Modules (No Company Name) ==========[/color]
 
MOD - [2011-10-26 09:10:46 | 000,420,920 | ---- | M] () -- C:\Users\Patryk\AppData\Local\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
MOD - [2011-10-26 09:10:45 | 003,702,840 | ---- | M] () -- C:\Users\Patryk\AppData\Local\Google\Chrome\Application\15.0.874.106\pdf.dll
MOD - [2011-10-26 09:09:09 | 000,122,952 | ---- | M] () -- C:\Users\Patryk\AppData\Local\Google\Chrome\Application\15.0.874.106\avutil-51.dll
MOD - [2011-10-26 09:09:07 | 000,222,280 | ---- | M] () -- C:\Users\Patryk\AppData\Local\Google\Chrome\Application\15.0.874.106\avformat-53.dll
MOD - [2011-10-26 09:09:06 | 001,745,992 | ---- | M] () -- C:\Users\Patryk\AppData\Local\Google\Chrome\Application\15.0.874.106\avcodec-53.dll
MOD - [2011-10-26 06:14:43 | 008,587,936 | ---- | M] () -- C:\Users\Patryk\AppData\Local\Google\Chrome\Application\15.0.874.106\gcswf32.dll
MOD - [2011-10-26 06:14:43 | 008,587,936 | ---- | M] () -- C:\Users\Patryk\AppData\Local\Google\Chrome\APPLIC~1\150874~1.106\gcswf32.dll
MOD - [2010-11-21 15:54:34 | 000,094,208 | ---- | M] () -- E:\Zainstalowane\FileZilla FTP Client\fzshellext.dll
MOD - [2009-08-29 07:00:12 | 000,966,656 | ---- | M] () -- C:\Users\Patryk\Local Settings\Apps\F.lux\flux.exe
 
 
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
 
SRV - [2011-10-11 02:27:12 | 000,102,752 | ---- | M] (BlueStack Systems, Inc.) [Auto | Stopped] -- C:\Program Files\BlueStacks\HD-Service.exe -- (BstHdAndroidSvc)
SRV - [2011-10-07 18:47:13 | 001,883,328 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011-09-08 18:29:46 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011-08-04 13:34:46 | 001,361,288 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011-07-16 10:56:22 | 000,024,992 | ---- | M] (Samsung Electronics Co., Ltd.) [Auto | Running] -- C:\Program Files\Samsung\AllShare\AllShareDMS\AllShareDMS.exe -- (SamsungAllShareV2.0)
SRV - [2011-07-16 10:56:18 | 000,027,584 | ---- | M] (Samsung Electronics Co., Ltd.) [On_Demand | Stopped] -- C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe -- (SimpleSlideShowServer)
SRV - [2011-04-22 13:21:10 | 000,092,592 | ---- | M] (TomTom) [Auto | Running] -- E:\Zainstalowane\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2011-03-16 09:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011-01-24 14:07:58 | 000,151,432 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe -- (CLPSLS)
SRV - [2010-12-02 20:48:47 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010-10-25 10:03:52 | 000,217,088 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010-05-02 22:34:28 | 005,027,328 | ---- | M] (Moonware Studios) [On_Demand | Stopped] -- E:\Zainstalowane\wLite\wService.exe -- (wxpSvc)
SRV - [2009-07-14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009-07-14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009-06-11 15:59:58 | 000,217,185 | ---- | M] (IDT, Inc.) [Auto | Running] -- c:\Program Files\IDT\v114_ECS_D_6207.2V7_6099.8xp_G2.0V_RC_SDC\WDM\stacsv.exe -- (STacSV)
 
 
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
 
DRV - [2011-10-11 02:28:10 | 000,067,424 | ---- | M] (BlueStack Systems) [Kernel | Auto | Stopped] -- C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys -- (BstHdDrv)
DRV - [2011-10-07 18:47:53 | 000,082,400 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\inspect.sys -- (inspect)
DRV - [2011-10-07 18:47:52 | 000,039,640 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2011-10-07 18:47:51 | 000,488,208 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2011-10-07 18:47:50 | 000,019,600 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmderd.sys -- (cmderd)
DRV - [2011-09-21 14:03:32 | 000,022,656 | ---- | M] (Dev47Apps) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\droidcam.sys -- (DroidCam)
DRV - [2011-09-08 19:26:10 | 008,606,208 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2011-09-08 19:26:10 | 008,606,208 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2011-09-08 17:52:20 | 000,248,832 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2011-07-20 08:46:02 | 000,132,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2011-07-20 08:46:02 | 000,104,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2011-07-20 08:46:02 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2011-07-20 08:45:52 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011-07-20 08:45:52 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus) SAMSUNG Android USB Composite Device driver (WDM)
DRV - [2011-07-20 08:45:52 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadadb.sys -- (androidusb)
DRV - [2011-07-20 08:45:52 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdfl.sys -- (ssadmdfl) SAMSUNG Android USB Modem (Filter)
DRV - [2011-06-06 23:06:54 | 000,211,984 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdW73.sys -- (AtiHDAudioService)
DRV - [2010-12-09 17:52:16 | 000,010,536 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\hmonitor45.sys -- (Hmonitor45)
DRV - [2010-12-08 17:26:02 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010-11-09 14:35:30 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\cpuz135_x32.sys -- (cpuz135)
DRV - [2010-10-25 10:03:52 | 000,036,640 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010-10-21 14:11:02 | 000,081,680 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV - [2010-02-16 16:02:02 | 000,021,504 | ---- | M] (http://www.atmel.com) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\libusb0.sys -- (libusb0)
DRV - [2009-11-12 15:16:10 | 000,012,672 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\GF0268.sys -- (GF0268)
DRV - [2009-07-14 02:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009-07-14 02:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009-07-14 02:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009-07-14 00:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009-07-14 00:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009-07-14 00:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009-06-11 15:59:58 | 000,407,552 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2009-03-30 03:09:28 | 000,239,336 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\System32\drivers\RsFx0103.sys -- (RsFx0103)
DRV - [2009-03-18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008-11-23 10:23:04 | 000,097,792 | ---- | M] (T0r0 2008) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\NSHE.SYS -- (NSHE)
DRV - [2008-07-22 07:42:58 | 000,051,200 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2006-12-13 11:10:18 | 000,030,656 | ---- | M] (Eutron) [Kernel | System | Running] -- C:\Windows\System32\drivers\eusk2par.sys -- (eusk2par)
DRV - [2006-11-22 10:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Stopped] -- C:\Windows\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2006-09-24 14:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\Windows\system32\speedfan.sys -- (speedfan)
DRV - [1996-04-03 20:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\giveio.sys -- (giveio)
 
 
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== Internet Explorer ==========[/color]
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
[color=#E56717]========== FireFox ==========[/color]
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Zainstalowane\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Patryk\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: E:\Zainstalowane\MT\components [2010-12-17 17:06:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: E:\Zainstalowane\MT\plugins
 
[2011-07-24 19:06:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\Extensions
[2010-12-14 19:41:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011-07-24 19:06:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\Extensions\[email protected]
 
[color=#E56717]========== Chrome  ==========[/color]
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Disabled) = E:\Zainstalowane\ar\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = E:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: 20-20 3D Viewer for IKEA (Enabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbjlpbcjbhgeeloohnpbcfblhnkhffm\5.0.7.0_0\NP_2020Player_IKEA.dll
CHR - plugin: Intel(R) Threading Building Blocks for Windows (Enabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbjlpbcjbhgeeloohnpbcfblhnkhffm\5.0.7.0_0\tbb.dll
CHR - plugin: Intel(R) Threading Building Blocks for Windows (Enabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbjlpbcjbhgeeloohnpbcfblhnkhffm\5.0.7.0_0\tbbmalloc.dll
CHR - plugin: Java Deployment Toolkit 7.0.0.147 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 7 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Patryk\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = E:\Zainstalowane\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
 
O1 HOSTS File: ([2011-10-30 13:45:48 | 000,000,067 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: 127.0.0.1 validation.sls.microsoft.com
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001..\Run: [F.lux] C:\Users\Patryk\Local Settings\Apps\F.lux\flux.exe ()
O4 - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001..\Run: [uTorrent] E:\Zainstalowane\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: + Offline &Explorer: Download the link - E:\Zainstalowane\Offline Explorer Pro\Add_UrlO.htm ()
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - E:\Zainstalowane\Offline Explorer Pro\Add_AllO.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 10.0.0)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.7.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C1A76EC2-EEAB-4539-8E0F-172955FC87C2}: DhcpNameServer = 195.66.73.11 195.66.73.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C1A76EC2-EEAB-4539-8E0F-172955FC87C2}: NameServer = 156.154.70.22,156.154.71.22
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\Windows\System32\guard32.dll) -C:\Windows\System32\guard32.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\System32\guard32.dll) -C:\Windows\System32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011-07-29 19:32:07 | 000,110,066 | ---- | M] () - C:\AutoMapaSetupLog.txt -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[2011-11-03 19:50:58 | 000,000,000 | ---D | C] -- C:\_OTL
[2011-11-02 19:47:12 | 000,000,000 | ---D | C] -- C:\Users\Patryk\Documents\Battlefield 3
[2011-11-01 19:36:12 | 000,000,000 | ---D | C] -- C:\ProgramData\RELOADED
[2011-10-31 21:49:54 | 000,000,000 | ---D | C] -- C:\Users\Patryk\Documents\Stronghold 3
[2011-10-31 20:22:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefly Studios
[2011-10-30 14:49:42 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011-10-30 14:15:51 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011-10-30 14:14:21 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011-10-19 18:20:11 | 000,033,984 | ---- | C] (COMODO) -- C:\Windows\System32\cmdcsr.dll
[2011-10-18 17:37:51 | 000,000,000 | ---D | C] -- C:\Users\Patryk\Documents\Moja Muzyka
[2011-10-13 17:28:22 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Local\BlueStacks
[2011-10-13 17:28:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
[2011-10-13 17:28:22 | 000,000,000 | ---D | C] -- C:\Program Files\BlueStacks
[2011-10-13 17:28:20 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueStacks
[2011-10-12 20:30:32 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011-10-12 20:30:30 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011-10-12 20:30:29 | 001,798,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011-10-12 20:30:28 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011-10-12 20:30:26 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011-10-12 13:50:39 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2011-10-12 13:50:39 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2011-10-12 13:50:37 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2011-10-12 13:50:36 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Mpeg2Data.ax
[2011-10-12 13:50:35 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSDvbNP.ax
[2011-10-12 13:49:35 | 002,332,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011-10-11 15:51:01 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Local\temp
[2011-10-07 12:11:03 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Roaming\IDoser
[2011-10-07 12:10:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I-Doser Free
[2011-10-07 12:10:52 | 000,000,000 | ---D | C] -- C:\Program Files\I-Doser Free
[2011-10-07 12:10:52 | 000,000,000 | ---D | C] -- C:\Users\Patryk\Documents\Dose Files
[2011-10-06 18:57:14 | 000,214,408 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2011-10-06 18:57:14 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2011-10-06 18:57:13 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
 
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
 
[2011-11-03 20:03:03 | 001,474,832 | ---- | M] () -- C:\Windows\System32\drivers\sfi.dat
[2011-11-03 19:53:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011-11-03 19:53:05 | 1610,113,024 | -HS- | M] () -- C:\hiberfil.sys
[2011-11-03 19:52:26 | 000,017,360 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011-11-03 19:52:25 | 000,017,360 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011-11-03 19:49:47 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI
[2011-11-03 18:54:20 | 000,012,538 | ---- | M] () -- C:\Users\Patryk\Documents\Jan kochanowski.rtf
[2011-11-03 18:16:01 | 000,000,000 | ---- | M] () -- C:\Users\Patryk\defogger_reenable
[2011-11-03 17:42:45 | 000,000,022 | ---- | M] () -- C:\Windows\tpcsd
[2011-10-31 20:22:10 | 000,001,059 | ---- | M] () -- C:\Users\Public\Desktop\Stronghold 3 x64.lnk
[2011-10-30 16:44:17 | 000,803,238 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2011-10-30 16:44:17 | 000,717,462 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011-10-30 16:44:17 | 000,472,896 | ---- | M] () -- C:\Windows\System32\perfh011.dat
[2011-10-30 16:44:17 | 000,179,016 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2011-10-30 16:44:17 | 000,145,484 | ---- | M] () -- C:\Windows\System32\perfc011.dat
[2011-10-30 16:44:17 | 000,145,484 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011-10-30 14:49:46 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011-10-30 13:55:44 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\slwga.dll
[2011-10-30 13:55:41 | 000,409,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\systemcpl.dll
[2011-10-30 13:53:30 | 000,376,274 | RHS- | M] () -- C:\MLKVX
[2011-10-30 13:53:30 | 000,000,020 | RHS- | M] () -- C:\win7.ld
[2011-10-30 13:48:29 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2011-10-30 13:45:48 | 000,000,067 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011-10-30 13:20:57 | 000,018,230 | ---- | M] () -- C:\Users\Patryk\Documents\Bez tqwsdytułu 1.odt
[2011-10-22 14:02:58 | 000,000,235 | ---- | M] () -- C:\Users\Patryk\Desktop\Pliki do gta.exe
[2011-10-22 13:58:38 | 000,060,295 | ---- | M] () -- C:\Users\Patryk\Documents\TR_DETAILS_20111022145722.pdf
[2011-10-16 12:31:24 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011-10-13 15:13:06 | 000,291,472 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011-10-09 14:06:40 | 000,011,243 | ---- | M] () -- C:\Users\Patryk\Documents\balladyna.odt
[2011-10-08 23:00:00 | 009,047,084 | ---- | M] () -- C:\Users\Patryk\Documents\ts3_recording_11_10_08_23_23_7.wav
[2011-10-08 22:53:19 | 000,000,000 | ---- | M] () -- C:\Windows\System32\ts3_recording_11_10_08_23_23_7.wav
[2011-10-07 18:47:53 | 000,082,400 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\inspect.sys
[2011-10-07 18:47:52 | 000,039,640 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmdhlp.sys
[2011-10-07 18:47:51 | 000,488,208 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmdGuard.sys
[2011-10-07 18:47:50 | 000,019,600 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmderd.sys
[2011-10-07 18:47:11 | 000,033,984 | ---- | M] (COMODO) -- C:\Windows\System32\cmdcsr.dll
[2011-10-07 18:47:10 | 000,300,200 | ---- | M] (COMODO) -- C:\Windows\System32\guard32.dll
[2011-10-07 12:10:52 | 000,000,985 | ---- | M] () -- C:\Users\Public\Desktop\I-Doser Free.lnk
 
[color=#E56717]========== Files Created - No Company Name ==========[/color]
 
[2011-11-03 19:49:47 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011-11-03 18:54:20 | 000,012,538 | ---- | C] () -- C:\Users\Patryk\Documents\Jan kochanowski.rtf
[2011-11-03 18:16:01 | 000,000,000 | ---- | C] () -- C:\Users\Patryk\defogger_reenable
[2011-11-03 17:42:45 | 000,000,022 | ---- | C] () -- C:\Windows\tpcsd
[2011-10-31 20:22:10 | 000,001,059 | ---- | C] () -- C:\Users\Public\Desktop\Stronghold 3 x64.lnk
[2011-10-30 14:49:46 | 000,000,969 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011-10-30 13:53:30 | 000,376,274 | RHS- | C] () -- C:\MLKVX
[2011-10-30 13:53:11 | 000,000,020 | RHS- | C] () -- C:\win7.ld
[2011-10-30 13:20:55 | 000,018,230 | ---- | C] () -- C:\Users\Patryk\Documents\Bez tqwsdytułu 1.odt
[2011-10-22 13:58:38 | 000,060,295 | ---- | C] () -- C:\Users\Patryk\Documents\TR_DETAILS_20111022145722.pdf
[2011-10-21 17:41:50 | 000,000,235 | ---- | C] () -- C:\Users\Patryk\Desktop\Pliki do gta.exe
[2011-10-09 14:06:39 | 000,011,243 | ---- | C] () -- C:\Users\Patryk\Documents\balladyna.odt
[2011-10-08 22:53:22 | 009,047,084 | ---- | C] () -- C:\Users\Patryk\Documents\ts3_recording_11_10_08_23_23_7.wav
[2011-10-08 22:53:19 | 000,000,000 | ---- | C] () -- C:\Windows\System32\ts3_recording_11_10_08_23_23_7.wav
[2011-10-07 12:10:52 | 000,000,985 | ---- | C] () -- C:\Users\Public\Desktop\I-Doser Free.lnk
[2011-09-21 14:06:57 | 000,000,033 | ---- | C] () -- C:\ProgramData\droidcam-settings
[2011-09-14 10:47:40 | 000,053,760 | ---- | C] () -- C:\Windows\System32\OVDecode.dll
[2011-08-29 07:55:59 | 000,001,626 | ---- | C] () -- C:\Users\Patryk\AppData\Local\auto_install.bat
[2011-08-29 07:55:59 | 000,001,481 | ---- | C] () -- C:\Users\Patryk\AppData\Local\dc.bat
[2011-08-29 07:55:59 | 000,001,288 | ---- | C] () -- C:\Users\Patryk\AppData\Local\cc.bat
[2011-08-26 15:34:14 | 000,239,869 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2011-08-13 22:56:54 | 000,112,640 | ---- | C] () -- C:\Windows\lsb_un20.exe
[2011-07-27 16:11:36 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011-07-27 16:11:36 | 000,036,640 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011-07-19 17:08:09 | 000,045,286 | ---- | C] () -- C:\Users\Patryk\AppData\Roaming\room_v3.dat
[2011-07-15 09:38:02 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011-06-07 10:13:38 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011-06-07 10:13:38 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011-06-07 10:13:38 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011-06-07 10:13:38 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2011-04-08 17:31:12 | 000,007,168 | ---- | C] () -- C:\Users\Patryk\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-03-22 18:54:20 | 000,000,000 | -H-- | C] () -- C:\Windows\msds.dat
[2011-03-17 18:51:44 | 000,003,929 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2011-03-03 12:40:08 | 000,150,528 | ---- | C] () -- C:\Windows\System32\mkx.dll
[2011-03-03 12:39:56 | 000,109,568 | ---- | C] () -- C:\Windows\System32\avi.dll
[2011-03-03 12:39:46 | 000,141,824 | ---- | C] () -- C:\Windows\System32\mp4.dll
[2011-03-03 12:39:34 | 000,123,392 | ---- | C] () -- C:\Windows\System32\ogm.dll
[2011-03-03 12:39:02 | 000,113,152 | ---- | C] () -- C:\Windows\System32\dsmux.exe
[2011-03-03 12:38:54 | 000,154,112 | ---- | C] () -- C:\Windows\System32\ts.dll
[2011-03-03 12:38:40 | 000,249,856 | ---- | C] () -- C:\Windows\System32\dxr.dll
[2011-03-03 12:38:10 | 000,097,792 | ---- | C] () -- C:\Windows\System32\avs.dll
[2011-03-03 12:38:04 | 000,137,728 | ---- | C] () -- C:\Windows\System32\mkv2vfr.exe
[2011-03-03 12:37:50 | 000,093,184 | ---- | C] () -- C:\Windows\System32\avss.dll
[2011-03-03 12:37:40 | 000,358,400 | ---- | C] () -- C:\Windows\System32\gdsmux.exe
[2011-03-03 12:35:32 | 000,080,384 | ---- | C] () -- C:\Windows\System32\mkzlib.dll
[2011-03-03 12:35:26 | 000,024,576 | ---- | C] () -- C:\Windows\System32\mkunicode.dll
[2011-02-23 18:38:23 | 000,138,264 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011-02-23 18:38:23 | 000,138,056 | ---- | C] () -- C:\Users\Patryk\AppData\Roaming\PnkBstrK.sys
[2011-02-23 18:38:10 | 000,234,768 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011-02-23 18:38:07 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011-02-23 18:38:06 | 000,669,184 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2011-02-22 20:39:04 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011-02-12 10:52:07 | 000,074,752 | ---- | C] () -- C:\Windows\System32\CLEyeDevices.dll
[2011-02-07 19:00:08 | 001,529,856 | ---- | C] () -- C:\Windows\System32\ff_samplerate.dll
[2011-02-07 19:00:08 | 000,925,667 | ---- | C] () -- C:\Windows\System32\ffmpegmt.dll
[2011-02-07 19:00:08 | 000,721,798 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011-02-07 19:00:08 | 000,336,384 | ---- | C] () -- C:\Windows\System32\ff_libfaad2.dll
[2011-02-07 19:00:08 | 000,324,096 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll
[2011-02-07 19:00:08 | 000,216,576 | ---- | C] () -- C:\Windows\System32\ff_libdts.dll
[2011-02-07 19:00:08 | 000,151,552 | ---- | C] () -- C:\Windows\System32\ff_libmad.dll
[2011-02-07 19:00:08 | 000,145,408 | ---- | C] () -- C:\Windows\System32\libmpeg2_ff.dll
[2011-02-07 19:00:08 | 000,140,800 | ---- | C] () -- C:\Windows\System32\ff_unrar.dll
[2011-02-07 19:00:08 | 000,121,856 | ---- | C] () -- C:\Windows\System32\ff_liba52.dll
[2011-02-07 19:00:08 | 000,100,864 | ---- | C] () -- C:\Windows\System32\ff_wmv9.dll
[2011-02-07 19:00:08 | 000,065,024 | ---- | C] () -- C:\Windows\System32\FLT_ffdshow.dll
[2011-02-07 18:45:52 | 000,080,896 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011-02-07 18:39:02 | 004,166,551 | ---- | C] () -- C:\Windows\System32\ffmpeg.dll
[2011-01-21 17:10:04 | 000,077,824 | ---- | C] () -- C:\Windows\System32\CamTraxAPI.dll
[2011-01-09 18:26:35 | 001,474,832 | ---- | C] () -- C:\Windows\System32\drivers\sfi.dat
[2011-01-01 02:15:33 | 000,258,048 | ---- | C] () -- C:\Windows\System32\libFLAC.dll
[2010-12-28 14:05:43 | 000,472,896 | ---- | C] () -- C:\Windows\System32\perfh011.dat
[2010-12-28 14:05:43 | 000,145,484 | ---- | C] () -- C:\Windows\System32\perfc011.dat
[2010-12-28 14:05:43 | 000,141,988 | ---- | C] () -- C:\Windows\System32\perfi011.dat
[2010-12-28 14:05:43 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd011.dat
[2010-12-21 14:51:46 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010-12-18 16:23:27 | 000,028,672 | ---- | C] () -- C:\Windows\System32\hlduinst.exe
[2010-12-17 21:10:26 | 000,100,700 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2010-12-17 20:39:39 | 000,000,082 | ---- | C] () -- C:\Users\Patryk\AppData\Roaming\Movies2iPhone.ini
[2010-12-14 19:41:17 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010-12-09 17:52:16 | 000,010,536 | ---- | C] () -- C:\Windows\System32\drivers\hmonitor45.sys
[2010-12-08 19:51:29 | 000,000,600 | ---- | C] () -- C:\Users\Patryk\AppData\Roaming\winscp.rnd
[2010-12-03 21:00:45 | 000,007,598 | ---- | C] () -- C:\Users\Patryk\AppData\Local\Resmon.ResmonCfg
[2010-12-03 16:42:21 | 000,803,238 | ---- | C] () -- C:\Windows\System32\perfh015.dat
[2010-12-03 16:42:21 | 000,337,158 | ---- | C] () -- C:\Windows\System32\perfi015.dat
[2010-12-03 16:42:21 | 000,179,016 | ---- | C] () -- C:\Windows\System32\perfc015.dat
[2010-12-03 16:42:21 | 000,038,710 | ---- | C] () -- C:\Windows\System32\perfd015.dat
[2010-12-02 19:57:05 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010-12-02 18:58:01 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010-08-18 20:56:38 | 000,000,151 | ---- | C] () -- C:\Windows\System32\Registration.ini
[2009-08-11 22:21:26 | 000,087,552 | ---- | C] () -- C:\Windows\System32\ac3config.exe
[2009-08-11 22:21:20 | 001,021,440 | ---- | C] () -- C:\Windows\System32\ac3filter_intl.dll
[2009-07-14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009-07-14 05:33:53 | 000,291,472 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009-07-14 03:05:48 | 000,717,462 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009-07-14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009-07-14 03:05:48 | 000,145,484 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009-07-14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009-07-14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009-07-14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009-07-14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009-07-14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009-07-14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009-07-14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009-06-10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2008-11-06 16:37:32 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008-10-22 05:29:06 | 000,173,550 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2006-03-04 05:52:00 | 000,088,576 | ---- | C] () -- C:\Windows\System32\OptimFROG.dll
[1996-04-03 20:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys
 
[color=#E56717]========== LOP Check ==========[/color]
 
[2011-10-25 16:43:51 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\.minecraft
[2010-12-08 18:12:58 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\DAEMON Tools Lite
[2011-02-04 21:33:27 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Dev-Cpp
[2011-06-11 22:56:27 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\FileZilla
[2011-09-17 18:15:07 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\FreeHDConverter
[2011-09-01 13:55:48 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\FreeStone Group
[2011-01-29 22:24:59 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\FTPRush
[2011-05-22 15:16:41 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Gadu-Gadu 10
[2011-01-21 20:14:20 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\GameRanger
[2011-09-29 16:03:19 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\GetRightToGo
[2011-04-27 19:50:00 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\gtk-2.0
[2011-06-28 19:53:54 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\HandBrake
[2011-10-07 12:11:47 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\IDoser
[2011-07-03 12:25:03 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\ipla
[2010-12-08 18:23:31 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Leadertech
[2011-09-21 15:37:00 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\LolClient
[2011-03-28 17:18:26 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\MotioninJoy
[2011-09-18 15:13:59 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Nowy folder
[2011-07-12 17:19:02 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Offline Explorer
[2010-12-04 20:36:27 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\OpenFM
[2011-01-16 16:57:05 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\OpenOffice.org
[2011-01-30 18:14:27 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Opera
[2011-04-27 13:08:37 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\QuickStoresToolbar
[2010-12-02 19:53:38 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\RDRM
[2011-08-16 18:30:10 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Samsung
[2011-08-31 18:05:31 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\The Creative Assembly
[2010-12-14 19:41:17 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Thunderbird
[2011-07-24 19:06:02 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\TomTom
[2011-10-08 22:03:54 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\TS3Client
[2010-12-24 13:45:43 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Uniblue
[2011-07-22 21:58:50 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Unity
[2011-11-03 20:03:37 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\uTorrent
[2011-09-30 12:11:15 | 000,032,608 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
[color=#E56717]========== Purity Check ==========[/color]
 
 
 
[color=#E56717]========== Alternate Data Streams ==========[/color]
 
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:302A9871

< End of report >


Błąd przy uruchomieniu wyskakuje nadal, nie wiecie co można na to poradzić? Albo przynajmniej co to jest?

http://imageshack.us/photo/my-images/267/bezbufora.png/ Tutaj screen błędu.

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

06 Lis 2011, 00:12

I co wszystko w porządku z moim komputerem?

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

06 Lis 2011, 14:27

Wejdź w START -> Uruchom -> Msconfig -> zakładka Usługi --> odnajdź tam FsUsbExService i odznacz tę usługę.

Następnie uruchom OTL w oknie własne opcje skanowania/skrypt wklej:

:OTL

O3 - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKU\S-1-5-21-2844641534-2190261356-4039628113-1001\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:302A9871

:Files
C:\WINDOWS\System32\drivers\sfi.dat

:Commands
[clearallrestorepoints]
[emptytemp]


Klikasz Wykonaj skrypt. Dajesz log z usuwania. W OTL -> Sprzątanie.

Zainstaluj SP1 -> http://www.instalki.pl/programy/downloa ... ack_1.html.
Przeczyść dysk i rejestr CCleaner`em -> https://www.instalki.pl/download/programy/windows/narzedzia/narzedzia-systemowe/ccleaner/.
Wykonaj pełne skanowanie Malwarebytes`em Anti-Malware -> https://www.instalki.pl/download/programy/windows/bezpieczenstwo/antyspyware/malwarebytes/, jeśli coś znajdzie usuń i daj raport.
Odinstaluj stare wersję Java`y -> Java(TM) 6 Update 20 i Java(TM) 6 Update 27, gdyż masz już w systemie najnowszą -> Java(TM) 7 .

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

08 Lis 2011, 22:21

All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-2844641534-2190261356-4039628113-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found.
Registry value HKEY_USERS\S-1-5-21-2844641534-2190261356-4039628113-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
Registry value HKEY_USERS\S-1-5-21-2844641534-2190261356-4039628113-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}\ not found.
Unable to delete ADS Alternate Data Stream - 119 bytes C:\ProgramData\TEMP:302A9871 .
========== FILES ==========
File move failed. C:\WINDOWS\System32\drivers\sfi.dat scheduled to be moved on reboot.
========== COMMANDS ==========


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Patryk
->Temp folder emptied: 85649 bytes
->Temporary Internet Files folder emptied: 5275970 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 226123057 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 7453 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 40122 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 221,00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 11082011_212230

Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\System32\drivers\sfi.dat scheduled to be moved on reboot.

Registry entries deleted on Reboot...


Niestety błąd występuje nadal.

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

08 Lis 2011, 22:31

No a wykonałeś to:
Wejdź w START -> Uruchom -> Msconfig -> zakładka Usługi --> odnajdź tam FsUsbExService i odznacz tę usługę.

???

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

09 Lis 2011, 19:19

mati8898 napisał(a):Wejdź w START Uruchom Msconfig zakładka Usługi --> odnajdź tam FsUsbExService i odznacz tę usługę.

???


Ta wykonałem, po odznaczeniu tej opcji i kliknięciu zastosuj usługa znów się włącza.

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

09 Lis 2011, 19:29

Odinstaluj oprogramowanie od Samsunga.

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

19 Lis 2011, 16:28

Niestety nic nie pomaga! Odinstalowałem oprogramowanie samsunga, zainstalowałem ponownie, teraz do tego wszystkiego komputer nie czyta mi telefonu, na 100% ma to ze sobą związek... Już nie wiem co robić...

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

19 Lis 2011, 16:51

Zainstaluj oprogramowanie do telefonu. Podaj jeszcze nowy log z OTL. Spróbuje jeszcze jednej rzeczy... .

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

19 Lis 2011, 17:56

Sterowniki zainstalowałem... Dziwne jest to że gdy podłączam telefon to próbują zainstalować się sterowniki "samsung_android", jednak po chwili dostaję informację że instalacja nie powiodła się, wcześniej ten sterownik instalował się bez problemu. Logi zaraz wstawię.

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

19 Lis 2011, 18:03

OTL: http://www.wklej.eu/index.php?id=e5ff83413f

Extras: http://www.wklej.eu/index.php?id=b3242f5355

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

19 Lis 2011, 21:49

Może dajcie mi jakiś skrypt na usunięcie wszystkiego co związane z Samsungiem, spróbuję zainstalować na nowo i zobaczymy czy to coś da. Kiedyś instalowałem różne pierdoły SDK do androida ADB itd. możliwe że pozostały jakieś resztki i teraz się "gryzą".

Re: Przy włączeniu komputera pojawia się błąd FsUSBService

19 Lis 2011, 22:18

Najlepiej to odinstaluj wszystko od Samsunga Revo Uninstallerem -> https://www.instalki.pl/download/programy/windows/narzedzia/narzedzia-systemowe/revo-uninstaller/ w trybie Zaawansowanym, następnie sprawdź, czy błąd się pojawia, a dopiero później pobierz najnowsze oprogramowanie ze strony producenta i je zainstaluj.
Wyślij odpowiedź