ADVERTISEMENT

Extras.Txt

nx7300 - Przeglądarka firefox została zablokowana prawdopodobnie infekcja ukash

Witam wszystkich. Wczoraj przeglądałem jedną stronę i niestety kliknąłem gdzie nie trzeba, a potem pojawiło się okno UWAGA POLIZJA. Laptop nie jest zablokowany mogę normalnie na nim działać tylko gdy uruchomię przeglądarkę Firefox to pojawia się na pasku dodatkowe okno z treścią UWAGA Pańska przeglądarka została zablokowana ze względów bezpieczeństwa z wskazanych niżej przyczyn. Wszystkie działania tego komputera zostały zarejestrowane. Wszystkie pliki są szyfrowane itp. czyli tzw. POLIZJA. Robiłem skan Dr Web i Avira ale nic to nie pomogło. Da radę jakoś to usunąć, poniżej przedstawiam logi z OTL. Pozdrawiam


Download file - link to post

OTL Extras logfile created on: 2013-10-13 15:36:01 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Arni\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1,99 Gb Total Physical Memory | 1,14 Gb Available Physical Memory | 57,13% Memory free
3,84 Gb Paging File | 3,03 Gb Available in Paging File | 78,92% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 23,90 Gb Total Space | 3,63 Gb Free Space | 15,20% Space Free | Partition Type: NTFS
Drive D: | 43,94 Gb Total Space | 42,40 Gb Free Space | 96,49% Space Free | Partition Type: NTFS
Drive E: | 43,94 Gb Total Space | 27,96 Gb Free Space | 63,62% Space Free | Partition Type: NTFS

Computer Name: ARNI-E9EE6C2F71 | User Name: Arni | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (All) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ & lt; extension & gt; ]
.bat [@ = batfile] -- " %1 " %*
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- " %1 " %*
.com [@ = comfile] -- " %1 " %*
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL " %1 " ,%*
.exe [@ = exefile] -- " %1 " %*
.hlp [@ = hlpfile] -- C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf [@ = inffile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\WINDOWS\System32\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- " %1 " %*
.reg [@ = regfile] -- C:\WINDOWS\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- " %1 " /S
.txt [@ = txtfile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1993962763-1500820517-1417001333-1003\SOFTWARE\Classes\ & lt; extension & gt; ]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ & lt; key & gt; \shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- " %1 " %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- " C:\WINDOWS\hh.exe " %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- " %1 " %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- " %1 " %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL " %1 " ,%*
exefile [open] -- " %1 " %*
helpfile [open] -- winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] -- %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\WINDOWS\system32\mshta.exe " %1 " %* (Microsoft Corporation)
htmlfile [edit] -- " C:\Program Files\Microsoft Office\Office12\msohtmed.exe " %1 (Microsoft Corporation)
htmlfile [open] -- " C:\Program Files\Internet Explorer\IEXPLORE.EXE " -nohome (Microsoft Corporation)
htmlfile [opennew] -- " C:\Program Files\Internet Explorer\IEXPLORE.EXE " %1 (Microsoft Corporation)
htmlfile [print] -- " C:\Program Files\Microsoft Office\Office12\msohtmed.exe " /p %1 (Microsoft Corporation)
http [open] -- " C:\Program Files\Internet Explorer\IEXPLORE.EXE " -nohome (Microsoft Corporation)
https [open] -- " C:\Program Files\Internet Explorer\IEXPLORE.EXE " -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- " C:\WINDOWS\system32\rundll32.exe " " C:\WINDOWS\system32\ieframe.dll " ,OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- " C:\WINDOWS\system32\rundll32.exe " " C:\WINDOWS\system32\mshtml.dll " ,PrintHTML " %1 " (Microsoft Corporation)
jsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\System32\CScript.exe " %1 " %* (Microsoft Corporation)
jsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- %SystemRoot%\System32\CScript.exe " %1 " %* (Microsoft Corporation)
jsefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- " %1 " %*
regfile [edit] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] -- regedit.exe " %1 " (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] -- " %1 "
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- " %1 " /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt " %1 " " %2 " " %3 " " %4 " (Microsoft Corporation)
vbefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\CScript.exe " %1 " %* (Microsoft Corporation)
vbefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\CScript.exe " %1 " %* (Microsoft Corporation)
vbsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] -- %SystemRoot%\System32\CScript.exe " %1 " %* (Microsoft Corporation)
wsffile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] -- %SystemRoot%\System32\WScript.exe " %1 " %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- " D:\Program Files\Winamp\winamp.exe " /BOOKMARK " %1 " (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- " D:\Program Files\Winamp\winamp.exe " /ADD " %1 " (Nullsoft, Inc.)
Directory [Winamp.Play] -- " D:\Program Files\Winamp\winamp.exe " " %1 " (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- " C:\Program Files\Internet Explorer\IEXPLORE.EXE " %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- " C:\Program Files\Internet Explorer\iexplore.exe " (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
" FirstRunDisabled " = 1
" AntiVirusDisableNotify " = 0
" FirewallDisableNotify " = 0
" UpdatesDisableNotify " = 0
" AntiVirusOverride " = 0
" FirewallOverride " = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[color=#E56717]========== System Restore Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
" DisableSR " = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
" Start " = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
" Start " = 2

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
" EnableFirewall " = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
" 1900:UDP " = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
" 2869:TCP " = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
" %windir%\Network Diagnostic\xpnetdiag.exe " = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
" %windir%\system32\sessmgr.exe " = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
" %windir%\Network Diagnostic\xpnetdiag.exe " = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
" %windir%\system32\sessmgr.exe " = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
" C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe " = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Development Company, L.P.)
" C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe " = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Development Company, L.P.)
" C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe " = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe -- (Hewlett-Packard Development Company, L.P.)
" C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe " = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe -- (Hewlett-Packard Development Company, L.P.)
" C:\Program Files\HP\Digital Imaging\bin\hposid01.exe " = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Development Company, L.P.)
" C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe " = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe -- ()
" C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe " = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard)
" C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe " = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe -- (Hewlett-Packard Development Company, L.P.)
" C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe " = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard)
" C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe " = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe -- (Hewlett-Packard Development Company, L.P.)
" C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe " = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe -- (Hewlett-Packard)
" C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe " = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe -- ( )
" C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe " = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Development Company, L.P.)
" C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe " = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe -- (Hewlett-Packard Development Company, L.P.)
" C:\Program Files\Sony Mobile\Update Service\Update Service.exe " = C:\Program Files\Sony Mobile\Update Service\Update Service.exe:*:Enabled:Update Service -- ()
" C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe " = C:\Program Files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe:LocalSubNet:Enabled:Pinnacle Streaming Server -- (Avid Development GmbH)
" D:\Program Files\ArcSoft\TotalMedia 3.5\TotalMedia.exe " = D:\Program Files\ArcSoft\TotalMedia 3.5\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3.5 -- (ArcSoft, Inc.)
" C:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe " = C:\Program Files\Sony Ericsson\Update Engine\Sony Ericsson Update Engine.exe:*:Enabled:Update Engine -- ()
" C:\Program Files\Nero\Nero 12\Nero BackItUp\BackItUp.exe " = C:\Program Files\Nero\Nero 12\Nero BackItUp\BackItUp.exe:*:Enabled:Nero BackItUp -- (Nero AG)
" C:\Program Files\Nero\KM\KwikMedia.exe " = C:\Program Files\Nero\KM\KwikMedia.exe:*:Enabled:Nero Kwik Media -- (Nero AG)


[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
" {01E9B2FF-DAF4-4529-9CC9-2101625517C7} " = nero.prerequisites.msi
" {052A1E34-A54B-458C-A4E3-24C3E054754A} " = Nero Kwik Media
" {0708FF30-78C0-47B0-81F0-C84604DC769C} " = Nero Express Help (CHM)
" {0A0CADCF-78DA-33C4-A350-CD51849B9702} " = Microsoft .NET Framework 4 Extended
" {0B311221-05A5-4766-8D03-7A6446794156} " = Nero RescueAgent Help (CHM)
" {0E2B0B41-7E08-4F9F-B21F-41C4133F43B7} " = mLogView
" {18D10072035C4515918F7E37EAFAACFC} " = AutoUpdate
" {1943C3BD-4462-4612-92C3-D36DD917C447} " = Nero Recode
" {1B6F5E51-575E-4693-BCA2-7543570D076D} " = Nero Kwik Themes Basic
" {1F16820E-D0E7-4636-939E-45CBFEFB06E1} " = Nero Kwik Media Help (CHM)
" {1F1C2DFC-2D24-3E06-BCB8-725134ADF989} " = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
" {2376813B-2E5A-4641-B7B3-A0D5ADB55229} " = HPPhotoSmartExpress
" {23FB368F-1399-4EAC-817C-4B83ECBE3D83} " = mProSafe
" {2432E589-6256-4513-B0BF-EFA8E325D5F0} " = Nero SharedVideoCodecs
" {24C4BB38-F45D-4247-90B9-7E6CAA877FF3} " = TotalMedia Setup
" {26A24AE4-039D-4CA4-87B4-2F83217025FF} " = Java 7 Update 25
" {2890E324-6F3B-4975-8B95-E7D6D80E0226} " = Nero Burning ROM Help (CHM)
" {29E44E9D-ACB2-4D2D-849F-5361C941B7E1} " = ArcSoft TotalMedia 3.5
" {29F67D84-3A70-456E-806A-52301B02070B} " = Nero Effects Basic
" {2AFF2951-86B1-3C53-B34D-B440F11E7D0A} " = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PLK
" {3248F0A8-6813-11D6-A77B-00B0D0150060} " = J2SE Runtime Environment 5.0 Update 6
" {34D2AB40-150D-475D-AE32-BD23FB5EE355} " = HP Quick Launch Buttons 6.00 D2
" {350C9415-3D7C-4EE8-BAA9-00BCB3D54227} " = WebFldrs XP
" {363790D2-DA98-41DD-9C9F-69FA36B169DE} " = PanoStandAlone
" {3A9FC03D-C685-4831-94CF-4EDFD3749497} " = Microsoft SQL Server Compact 3.5 SP2 ENU
" {3AAB08A3-F129-4BD5-B409-AE674F93759D} " = Prerequisite installer
" {3C3901C5-3455-3E0A-A214-0B093A5070A6} " = Microsoft .NET Framework 4 Client Profile
" {3E9D596A-61D4-4239-BD19-2DB984D2A16F} " = mIWA
" {3F4EC965-28EF-45C3-B063-04B25D4E9679} " = HP Integrated Module with Bluetooth wireless technology
" {4302B2DD-D958-40E3-BAF3-B07FFE1978CE} " = HP Wireless Assistant 2.00 E1
" {433E3E7F-4510-41F9-B9FB-55D8ECB30259} " = HD Writer AE 5.0
" {45B8A76B-57EC-4242-B019-066400CD8428} " = BufferChm
" {4A03706F-666A-4037-7777-5F2748764D10} " = Java Auto Updater
" {4EA684E9-5C81-4033-A696-3019EC57AC3A} " = HPProductAssistant
" {4F75616F-49C7-4EA2-8725-7E1A7AB1949C} " = Nero InfoTool 11 Help (CHM)
" {56C049BE-79E9-4502-BEA7-9754A3E60F9B} " = neroxml
" {5963F4B4-D138-47CD-ADEF-470E87E185BD} " = Nero Burning ROM
" {5A0DDC27-88E5-3CAD-BC3D-28FFD05CA6B9} " = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PLK
" {5B79E730-D897-4B8F-A1AD-7BB2D1F22B96} " = Nero Blu-ray Player Help (CHM)
" {5D97A4A7-C274-4B63-86D9-07A33435F505} " = InterVideo DVD Check
" {64BEF779-5053-48AF-A3D8-B70EBC1C70E7} " = Nero 11 InfoTool
" {65BB0407-4CC8-4DC7-952E-3EEFDF05602A} " = Nero Update
" {66910000-8B30-4973-A159-6371345AFFA5} " = WebReg
" {66E6CE0C-5A1E-430C-B40A-0C90FF1804A8} " = eSupportQFolder
" {68763C27-235D-4165-A961-FDEA228CE504} " = AiOSoftwareNPI
" {6909F917-5499-482e-9AA1-FAD06A99F231} " = Toolbox
" {6994491D-D491-48F1-AE1F-E179C1FFFC2F} " = HP Photosmart Essential
" {6F5E2F4A-377D-4700-B0E3-8F7F7507EA15} " = CustomerResearchQFolder
" {716E0306-8318-4364-8B8F-0CC4E9376BAC} " = MSXML 4.0 SP2 Parser and SDK
" {7299052b-02a4-4627-81f2-1818da5d550d} " = Microsoft Visual C++ 2005 Redistributable
" {736C803C-DD3B-4015-BC51-AFB9E67B9076} " = Readme
" {7B63B2922B174135AFC0E1377DD81EC2} " = DivX Codec
" {7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A} " = TIPCI
" {7C7AC2D4-1077-45C8-826A-16445B5E0DB7} " = Pinnacle DistanTV Server
" {7E7B7865-6C80-4373-8BC1-C2EB9431F9DE} " = ProductContextNPI
" {828175FA-7307-4DBF-95AD-9CEE086B6F45} " = Welcome App (Start-up experience)
" {8331C3EA-0C91-43AA-A4D4-27221C631139} " = Status
" {837b34e3-7c30-493c-8f6a-2b0f04e2912c} " = Microsoft Visual C++ 2005 Redistributable
" {83FCCFCD-46E3-43FB-A397-78BFD5A8980A} " = Nero Video
" {848A7C68-0ADC-4193-8A89-2CEA78E56A0C} " = Nero Express
" {86847081-B387-4F49-AED1-C9B0A090D66C} " = Nero Recode Help (CHM)
" {87E2B986-07E8-477a-93DC-AF0B6758B192} " = DocProcQFolder
" {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} " = Microsoft Silverlight
" {8A4CE7FD-9657-4B06-9943-E1819F3D5D67} " = DocProc
" {8A708DD8-A5E6-11D4-A706-000629E95E20} " = Intel(R) Graphics Media Accelerator Driver
" {8B928BA1-EDEC-4227-A2DA-DD83026C36F5} " = mPfMgr
" {8C6BB412-D3A8-4AAE-A01B-35B681789D68} " = mHelp
" {8CE4E6E9-9D55-43FB-9DDB-688C976BFC05} " = Unload
" {90120000-0010-0415-0000-0000000FF1CE} " = Microsoft Software Update for Web Folders (Polish) 12
" {90120000-0015-0415-0000-0000000FF1CE} " = Microsoft Office Access MUI (Polish) 2007
" {90120000-0016-0415-0000-0000000FF1CE} " = Microsoft Office Excel MUI (Polish) 2007
" {90120000-0018-0415-0000-0000000FF1CE} " = Microsoft Office PowerPoint MUI (Polish) 2007
" {90120000-0019-0415-0000-0000000FF1CE} " = Microsoft Office Publisher MUI (Polish) 2007
" {90120000-001A-0415-0000-0000000FF1CE} " = Microsoft Office Outlook MUI (Polish) 2007
" {90120000-001B-0415-0000-0000000FF1CE} " = Microsoft Office Word MUI (Polish) 2007
" {90120000-001F-0407-0000-0000000FF1CE} " = Microsoft Office Proof (German) 2007
" {90120000-001F-0409-0000-0000000FF1CE} " = Microsoft Office Proof (English) 2007
" {90120000-001F-0415-0000-0000000FF1CE} " = Microsoft Office Proof (Polish) 2007
" {90120000-002C-0415-0000-0000000FF1CE} " = Microsoft Office Proofing (Polish) 2007
" {90120000-0030-0000-0000-0000000FF1CE} " = Microsoft Office Enterprise 2007
" {90120000-0044-0415-0000-0000000FF1CE} " = Microsoft Office InfoPath MUI (Polish) 2007
" {90120000-006E-0415-0000-0000000FF1CE} " = Microsoft Office Shared MUI (Polish) 2007
" {90120000-00A1-0415-0000-0000000FF1CE} " = Microsoft Office OneNote MUI (Polish) 2007
" {90120000-00BA-0415-0000-0000000FF1CE} " = Microsoft Office Groove MUI (Polish) 2007
" {90B0D222-8C21-4B35-9262-53B042F18AF9} " = mPfWiz
" {91810AFC-A4F8-4EBA-A5AA-B198BBC81144} " = InterVideo WinDVD
" {91B33C97-0FBA-74AE-E802-D782F5C8AA89}_is1 " = Ashampoo Burning Studio 2013 v.11.0.6
" {94658027-9F16-4509-BBD7-A59FE57C3023} " = mZConfig
" {95E152CF-0EB5-4BFA-B6EE-8FC7F9601BA5} " = Nero 12
" {996512CF-F35B-48DE-9291-557FA5316967} " = ScannerCopy
" {9A25302D-30C0-39D9-BD6F-21E6EC160475} " = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
" {9C9D0F85-5658-4A5E-95A9-65F7DB2916EE} " = Broadcom 440x 10/100 Integrated Controller
" {9CC89556-3578-48DD-8408-04E66EBEF401} " = mXML
" {9EFDFBA8-9174-3C61-8645-28376C5CA994} " = Microsoft .NET Framework 3.5 Language Pack SP1 - plk
" {9FC8D8F8-AF3A-4488-98AF-51C6DEC732F2} " = c3100_Help
" {A2FE691E-3F8E-4E30-AA7D-FF17AC77EA87} " = Nero Blu-ray Player
" {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7} " = Microsoft .NET Framework 3.0 Service Pack 2
" {A7A0BF2E-31CC-49E3-9913-52C503EB969D} " = Nero Audio Pack 1
" {A90E924E-1B35-44B0-978E-3F6F89FBC960} " = Nero InfoTool 11
" {AB5D51AE-EBC3-438D-872C-705C7C2084B0} " = DeviceManagementQFolder
" {ABC88553-8770-4B97-B43E-5A90647A5B63} " = Nero ControlCenter
" {AC76BA86-7AD7-1045-7B44-AB0000000001} " = Adobe Reader XI - Polish
" {ACE49D50-19CD-44A6-B192-46F985283B26} " = Nero PiP Effects Basic
" {AE052EF7-2640-48D7-8915-69B810D975CB} " = HP BIOS Configuration for ProtectTools 2.00 C3
" {B128179D-A5E1-43AC-9422-12A109ECD2A0} " = Nero Video Help (CHM)
" {B953732D-B623-4E84-B369-CFFF7B1AE06F} " = Nero RescueAgent
" {BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E} " = HP Software Update
" {BCC0552D-76C0-4130-BFBD-49BE49ACC594} " = COMODO Internet Security
" {BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C} " = HP Photosmart, Officejet and Deskjet 7.0.A
" {BEBEE34D-84A2-4EDD-8BEA-96CC54371263} " = Nero Core Components
" {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} " = Microsoft .NET Framework 2.0 Service Pack 2
" {C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476} " = SolutionCenter
" {C8753E28-2680-49BF-BD48-DD38FD086EFE} " = AiO_Scan_CDA
" {C994C746-C6D0-4EBA-B09E-DF7B18381B69} " = Nero ControlCenter Help (CHM)
" {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} " = Microsoft .NET Framework 1.1
" {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} " = Microsoft .NET Framework 3.5 SP1
" {DA2D3078-A58C-45E8-8EE0-18B8BE6B34F7} " = Nero BackItUp
" {DBC20735-34E6-4E97-A9E5-2066B66B243D} " = TrayApp
" {E17BCB76-9924-4BD5-B6D6-50D3407B4E74} " = Nero Disc Menus Basic
" {E1B80DEE-A795-4258-8445-074C06AE3AB8} " = MarketResearch
" {E81667C6-2856-46D6-ABEA-6A2F42166779} " = mCore
" {EB8C9964-09AC-48bf-8B98-027609C78251} " = C3100
" {EF0D1292-8FC1-41BE-9740-DBC134F66415} " = Nero BackItUp Help (CHM)
" {F09EF8F2-0976-42C1-8D9D-8DF78337C6E3} " = Sony PC Companion 2.10.174
" {F0A37341-D692-11D4-A984-009027EC0A9C} " = SoundMAX
" {F0BFC7EF-9CF8-44EE-91B0-158884CD87C5} " = mMHouse
" {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} " = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
" {F157460F-720E-482f-8625-AD7843891E5F} " = InstantShareDevicesMFC
" {F3760724-B29D-465B-BC53-E5D72095BCC4} " = Scan
" {F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA} " = Pinnacle TVCenter Pro
" {F6076EF9-08E1-442F-B6A2-BFB61B295A14} " = Fax_CDA
" {F6090A17-0967-4A8A-B3C3-422A1B514D49} " = mDrWiFi
" {FAC7B331-57C8-4962-AF58-93C0BF688B39} " = ATI Hybrid TV Tuner Driver v6.14.10.393 32bit XP
" {FB15E224-67C3-491F-9F5C-F257BC418412} " = Destinations
" {FBB980B0-63F8-4B48-8D65-90F1D9F81D9F} " = NewCopy_CDA
" {FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4} " = mWlsSafe
" Adobe Flash Player Plugin " = Adobe Flash Player 11 Plugin
" Agere Systems Soft Modem " = Agere Systems HDA Modem
" Avira AntiVir Desktop " = Avira Free Antivirus
" Broadcom 802.11b Network Adapter " = Broadcom 802.11 Wireless LAN Adapter
" CCleaner " = CCleaner
" CrystalDiskInfo_is1 " = CrystalDiskInfo 5.6.2
" ENTERPRISE " = Microsoft Office Enterprise 2007
" FormatFactory " = FormatFactory 3.0.1
" HaaliMkx " = Haali Media Splitter
" HP Imaging Device Functions " = HP Imaging Device Functions 7.0
" HP Solution Center & Imaging Support Tools " = HP Solution Center 7.0
" HPExtendedCapabilities " = HP Customer Participation Program 7.0
" HPOCR " = OCR Software by I.R.I.S 7.0
" InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A} " = Texas Instruments PCIxx21/x515/xx12 drivers.
" InstallShield_{FAC7B331-57C8-4962-AF58-93C0BF688B39} " = ATI Hybrid TV Tuner Driver v6.14.10.393 32bit XP
" IrfanView " = IrfanView (remove only)
" Magic ISO Maker v5.4 (build 0251) " = Magic ISO Maker v5.4 (build 0251)
" Malwarebytes' Anti-Malware_is1 " = Malwarebytes Anti-Malware wersja 1.75.0.1300
" Microsoft .NET Framework 3.5 Language Pack SP1 - plk " = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK
" Microsoft .NET Framework 3.5 SP1 " = Microsoft .NET Framework 3.5 SP1
" Microsoft .NET Framework 4 Client Profile " = Microsoft .NET Framework 4 Client Profile
" Microsoft .NET Framework 4 Extended " = Microsoft .NET Framework 4 Extended
" Mirillis Splash Lite " = Splash Lite
" Mozilla Firefox 24.0 (x86 pl) " = Mozilla Firefox 24.0 (x86 pl)
" Mozilla Thunderbird 17.0.8 (x86 pl) " = Mozilla Thunderbird 17.0.8 (x86 pl)
" MozillaMaintenanceService " = Mozilla Maintenance Service
" NapiProjekt_is1 " = NapiProjekt (2.1.0.2287)
" NeroVision!UninstallKey " = Nero Digital
" ProInst " = Oprogramowanie Intel(R) PROSet/Wireless
" Przelewy.NET " = Przelewy.NET 0.1
" SubEdit-Player_is1 " = SubEdit-Player
" Swansoft CNC Simulator " = Swansoft CNC Simulator 6.60
" SynTPDeinstKey " = Synaptics Pointing Device Driver
" Totalcmd " = Total Commander (Remove or Repair)
" Update Engine " = Sony Ericsson Update Engine
" Update Service " = Sony Mobile Update Service
" Wdf01009 " = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
" Winamp " = Winamp
" WinRAR archiver " = WinRAR 4.20 (32-bitowy)
" winusb0200 " = Microsoft WinUsb 2.0
" XPSEPSCLP " = XML Paper Specification Shared Components Language Pack 1.0

[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]

[HKEY_USERS\S-1-5-21-1993962763-1500820517-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
" GG " = GG
" Winamp Detect " = Detektor Winampa

[color=#E56717]========== Last 20 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2013-07-08 17:10:17 | Computer Name = ARNI-E9EE6C2F71 | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd formatfactory.exe, wersja 3.0.1.1, moduł
powodujący błąd msvcr100.dll, wersja 10.0.40219.1, adres błędu 0x0008d6fd.

Error - 2013-07-09 06:49:12 | Computer Name = ARNI-E9EE6C2F71 | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd nero.exe, wersja 12.0.28.0, moduł powodujący
błąd user32.dll, wersja 5.1.2600.5512, adres błędu 0x00019728.

Error - 2013-07-09 13:38:46 | Computer Name = ARNI-E9EE6C2F71 | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca NeroVision.exe, wersja 12.0.8.0, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

Error - 2013-07-12 14:56:57 | Computer Name = ARNI-E9EE6C2F71 | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd nero.exe, wersja 12.0.28.0, moduł powodujący
błąd user32.dll, wersja 5.1.2600.5512, adres błędu 0x00019728.

Error - 2013-07-13 10:15:13 | Computer Name = ARNI-E9EE6C2F71 | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd nero.exe, wersja 12.0.28.0, moduł powodujący
błąd user32.dll, wersja 5.1.2600.5512, adres błędu 0x00019728.

Error - 2013-07-14 12:22:51 | Computer Name = ARNI-E9EE6C2F71 | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca NeroVision.exe, wersja 3.1.0.25, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

Error - 2013-08-07 02:28:13 | Computer Name = ARNI-E9EE6C2F71 | Source = WmiAdapter | ID = 4099
Description = Otwarcie usługi nie powiodło się.

Error - 2013-10-10 13:46:58 | Computer Name = ARNI-E9EE6C2F71 | Source = MsiInstaller | ID = 10005
Description = Produkt: Mastercam X7 -- System operacyjny nie jest odpowiedni do
uruchomienia programu Mastercam X7.

[ System Events ]
Error - 2013-10-07 15:50:41 | Computer Name = ARNI-E9EE6C2F71 | Source = W32Time | ID = 39452701
Description = Dostawca czasu NtpClient jest skonfigurowany, tak aby pobierać czas
z jednego lub kilku źródeł czasu, jednak żadne ze źródeł jest obecnie niedostępne.
Przez 14 min nie nastąpi próba kontaktu ze źródłem. NtpClient nie ma źródła dokładnego
czasu.


& lt; End of report & gt;