
Antyvirus Pro 2010 który w żaden sposób nie da się usunąć i jest agresywny

- Kod: Zaznacz wszystko
OTL logfile created on: 2009-10-19 20:36:09 - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = C:\Documents and Settings\admin\Pulpit
Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
446,42 Mb Total Physical Memory | 161,92 Mb Available Physical Memory | 36,27% Memory free
1,03 Gb Paging File | 0,71 Gb Available in Paging File | 68,50% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 62,02 Gb Free Space | 83,22% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: XPN24
Current User Name: admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2009-10-19 20:36:02 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin\Pulpit\OTL.exe
PRC - [2009-10-19 13:31:04 | 00,232,560 | ---- | M] (vikbnerobeb) -- C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe
PRC - [2009-10-19 13:26:34 | 00,273,920 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\svcst.exe
PRC - [2009-10-19 13:26:34 | 00,273,920 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\seres.exe
PRC - [2009-10-19 13:17:15 | 00,139,264 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\UAService7.exe
PRC - [2009-09-15 10:50:43 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-03-05 16:07:20 | 02,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008-04-14 19:21:16 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2006-12-19 05:12:00 | 16,062,464 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - [2009-10-19 13:17:15 | 00,139,264 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\UAService7.exe -- (UserAccess7 [Auto | Running])
SRV - [2009-07-21 15:54:38 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Disabled | Stopped])
SRV - [2008-04-14 19:20:44 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2006-12-01 11:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [Disabled | Stopped])
SRV - [2006-08-16 09:35:00 | 00,155,715 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Disabled | Stopped])
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2009-10-19 13:17:16 | 00,006,432 | ---- | M] (Sony DADC Austria AG.) -- C:\Documents and Settings\admin\Ustawienia lokalne\Temp\sony_ssm.sys -- (sony_ssm.sys [On_Demand | Stopped])
DRV - [2008-04-13 18:39:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008-04-13 18:36:05 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2006-12-21 10:26:00 | 04,405,248 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2006-08-16 09:35:00 | 03,959,712 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2006-07-11 15:38:30 | 00,020,480 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
DRV - [2006-07-11 15:38:28 | 00,057,856 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
DRV - [2006-06-28 11:38:56 | 00,105,088 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata [Boot | Running])
DRV - [2006-03-02 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2006-03-02 14:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Drivers\RootMdm.sys -- (ROOTMODEM [On_Demand | Stopped])
DRV - [2001-08-17 21:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "http://search.orbitdownloader.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-07-21 15:54:46 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-09-15 18:16:10 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-15 10:50:58 | 00,000,000 | ---D | M]
[2009-07-06 09:42:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\mozilla\Extensions
[2009-07-06 09:42:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-09-01 18:08:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\mozilla\Firefox\Profiles\zu74cfnw.default\extensions
[2009-10-19 17:25:05 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-09-15 10:50:58 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-10-05 19:24:20 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009-07-21 15:55:44 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009-09-15 10:50:37 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-09-15 10:50:37 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-07-21 15:54:42 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009-09-15 10:50:48 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2003-05-15 10:01:48 | 00,133,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009-08-31 14:40:12 | 00,636,408 | ---- | M] (Ganymede Technologies) -- C:\Program Files\mozilla firefox\plugins\NPSNOOKER.dll
[2009-09-15 10:50:51 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2009-09-15 10:50:52 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2009-09-15 10:50:52 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-09-15 10:50:52 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2009-09-15 10:50:52 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2009-09-15 10:50:52 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2009-09-15 10:50:52 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
O1 HOSTS File: (327701 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 11212 more lines...
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Microsoft Online Helper!) - {74B43F0D-D296-446A-8FD5-FE0815D65A35} - C:\WINDOWS\System32\neuuqhb.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\admin\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.CPL (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [mserv] C:\Documents and Settings\admin\Dane aplikacji\svcst.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [svchost] C:\Documents and Settings\admin\Dane aplikacji\svcst.exe ()
O4 - Startup: C:\Documents and Settings\admin\Menu Start\Programy\Autostart\isqsys32.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 55924053
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 55924053
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceClassicControlPanel = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\wshbth.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-07-04 11:32:18 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009-07-08 13:43:04 | 00,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[1 C:\WINDOWS\*.tmp files]
[2009-10-19 12:22:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Bluetooth
[2009-10-19 12:32:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Dane aplikacji\GetRightToGo
[2009-10-19 13:02:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Dane aplikacji\WinRAR
[2009-10-19 13:31:05 | 00,000,000 | ---D | C] -- C:\Program Files\AntivirusPro_2010
[2009-10-19 12:19:57 | 00,000,000 | ---D | C] -- C:\Program Files\IVT Corporation
[2009-09-24 15:49:16 | 00,000,000 | ---D | C] -- C:\Program Files\Nowe Gadu-Gadu
[2009-10-19 13:14:02 | 00,000,000 | ---D | C] -- C:\Program Files\Techland
[2009-09-25 17:53:42 | 00,000,000 | ---D | C] -- C:\Program Files\THQ
[2009-09-25 17:46:17 | 00,000,000 | ---D | C] -- C:\Program Files\Ubisoft
[2009-10-19 13:02:18 | 00,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2009-10-19 20:35:45 | 00,521,216 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\admin\Pulpit\OTL.exe
[2009-10-19 17:35:46 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009-10-19 17:34:45 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009-10-19 17:34:45 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009-10-19 17:34:45 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009-10-19 17:34:45 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009-10-19 17:34:40 | 00,000,000 | --SD | C] -- C:\ComboFix
[2009-10-19 17:34:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009-10-19 13:31:11 | 00,168,960 | ---- | C] (Legal Corporation) -- C:\WINDOWS\System32\_scui.cpl
[2009-10-19 13:31:04 | 00,232,560 | ---- | C] (vikbnerobeb) -- C:\Documents and Settings\admin\Dane aplikacji\lizkavd.exe
[2009-10-19 12:22:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Moje dokumenty\Bluetooth
[2009-10-19 12:18:37 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irmon.dll
[2009-10-19 12:18:37 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irmon.dll
[2009-10-19 12:18:37 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wshirda.dll
[2009-10-19 12:18:37 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wshirda.dll
[2009-10-19 12:18:36 | 00,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irftp.exe
[2009-10-19 12:18:36 | 00,152,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irftp.exe
[2009-10-12 15:23:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\admin\Pulpit\OpenOffice.org 3.1 (pl) Installation Files
[2009-09-30 11:11:15 | 00,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
[2009-09-25 19:19:32 | 00,139,264 | ---- | C] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\UAService7.exe
[2009-09-25 17:56:24 | 00,098,304 | ---- | C] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2009-09-25 17:51:47 | 00,230,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_2.dll
[2009-09-25 17:51:47 | 00,229,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_1.dll
[2009-09-25 17:51:47 | 00,062,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_1.dll
[2009-09-25 17:51:46 | 02,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_30.dll
[2009-09-25 17:51:46 | 00,230,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_0.dll
[2009-09-25 17:51:46 | 00,014,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_0.dll
[2009-09-25 17:51:45 | 02,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_29.dll
[2009-09-25 17:51:45 | 02,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_28.dll
[2009-09-25 17:51:45 | 00,061,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput9_1_0.dll
[2009-09-25 17:51:44 | 02,337,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_25.dll
[2009-09-25 17:51:44 | 02,319,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_27.dll
[2009-09-25 17:51:44 | 02,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_26.dll
[2009-09-25 17:51:41 | 02,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_24.dll
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009-10-19 20:36:02 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin\Pulpit\OTL.exe
[2009-10-19 17:59:44 | 00,081,191 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009-10-19 17:59:40 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-10-19 17:59:36 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-10-19 17:35:49 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009-10-19 17:19:45 | 00,000,032 | ---- | M] () -- C:\WINDOWS\0
[2009-10-19 17:13:17 | 00,000,598 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\cmnihu378.cab
[2009-10-19 17:10:49 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\miuevyi83.cab
[2009-10-19 17:03:09 | 04,270,744 | -H-- | M] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-10-19 14:32:08 | 00,000,267 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\dchy8w3hi.cab
[2009-10-19 13:31:30 | 00,019,954 | ---- | M] () -- C:\Program Files\Common Files\ubarazaniz.db
[2009-10-19 13:31:30 | 00,019,610 | ---- | M] () -- C:\WINDOWS\abaqipir.lib
[2009-10-19 13:31:30 | 00,018,290 | ---- | M] () -- C:\Program Files\Common Files\fivi.lib
[2009-10-19 13:31:30 | 00,018,208 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\gowype.scr
[2009-10-19 13:31:30 | 00,017,025 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\xyxu.dll
[2009-10-19 13:31:30 | 00,016,731 | ---- | M] () -- C:\WINDOWS\System32\axulygin.db
[2009-10-19 13:31:30 | 00,016,032 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\ajawofog.bat
[2009-10-19 13:31:30 | 00,015,318 | ---- | M] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\pubefuhuhy.inf
[2009-10-19 13:31:30 | 00,015,123 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\ezina.scr
[2009-10-19 13:31:30 | 00,014,987 | ---- | M] () -- C:\WINDOWS\vacaf.dat
[2009-10-19 13:31:30 | 00,013,590 | ---- | M] () -- C:\Program Files\Common Files\exawo.db
[2009-10-19 13:31:30 | 00,012,898 | ---- | M] () -- C:\Documents and Settings\All Users\Dokumenty\ahoma._sy
[2009-10-19 13:31:30 | 00,012,177 | ---- | M] () -- C:\Documents and Settings\All Users\Dokumenty\gytuzokuta.dll
[2009-10-19 13:31:30 | 00,011,648 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\ezelypa.scr
[2009-10-19 13:31:30 | 00,011,207 | ---- | M] () -- C:\WINDOWS\bidyveco.bin
[2009-10-19 13:31:30 | 00,010,854 | ---- | M] () -- C:\WINDOWS\pefilax.reg
[2009-10-19 13:31:30 | 00,010,538 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\wazolip._dl
[2009-10-19 13:31:30 | 00,010,529 | ---- | M] () -- C:\WINDOWS\System32\cewerici.dat
[2009-10-19 13:31:30 | 00,010,476 | ---- | M] () -- C:\WINDOWS\jubahuludo.inf
[2009-10-19 13:31:30 | 00,010,398 | ---- | M] () -- C:\WINDOWS\xulydaz.reg
[2009-10-19 13:31:29 | 00,019,704 | ---- | M] () -- C:\WINDOWS\System32\sabo.pif
[2009-10-19 13:31:15 | 00,168,960 | ---- | M] (Legal Corporation) -- C:\WINDOWS\System32\_scui.cpl
[2009-10-19 13:31:04 | 00,232,560 | ---- | M] (vikbnerobeb) -- C:\Documents and Settings\admin\Dane aplikacji\lizkavd.exe
[2009-10-19 13:26:34 | 00,273,920 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\svcst.exe
[2009-10-19 13:26:34 | 00,273,920 | ---- | M] () -- C:\Documents and Settings\admin\Dane aplikacji\seres.exe
[2009-10-19 13:17:15 | 00,139,264 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\UAService7.exe
[2009-10-19 13:15:50 | 00,042,496 | ---- | M] () -- C:\WINDOWS\System32\sys.dat
[2009-10-19 13:15:26 | 00,000,332 | ---- | M] () -- C:\WINDOWS\desctemp.dat
[2009-10-19 13:12:56 | 00,000,057 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2009-10-19 12:19:53 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\0
[2009-10-19 12:19:48 | 00,764,054 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-10-19 12:19:48 | 00,355,486 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2009-10-19 12:19:48 | 00,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-10-19 12:19:48 | 00,049,492 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2009-10-19 12:19:48 | 00,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-10-19 12:17:33 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-10-16 11:26:05 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-10-11 08:10:09 | 00,236,544 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009-10-10 10:41:43 | 00,000,754 | ---- | M] () -- C:\WINDOWS\WORDPAD.INI
[2009-10-09 16:37:56 | 00,000,542 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-10-09 16:37:56 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-09-25 17:56:24 | 00,098,304 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2009-09-25 17:55:46 | 00,002,007 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Auta - Przygody w Chłodnicy Górskiej.lnk
[2009-09-24 15:49:46 | 00,000,717 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\OpenFM.lnk
[2009-09-24 15:49:46 | 00,000,688 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Nowe Gadu-Gadu.lnk
[2009-09-22 10:40:14 | 15,430,0312 | ---- | M] () -- C:\Documents and Settings\admin\Pulpit\OOo_3.1.1_Win32Intel_install_wJRE_pl.exe
[2009-09-22 09:24:46 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[color=#E56717]========== Files - No Company Name ==========[/color]
[2009-10-19 17:34:45 | 00,236,544 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009-10-19 17:34:45 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009-10-19 17:34:45 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009-10-19 17:34:45 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009-10-19 17:12:23 | 00,000,598 | ---- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\cmnihu378.cab
[2009-10-19 13:31:30 | 00,019,954 | ---- | C] () -- C:\Program Files\Common Files\ubarazaniz.db
[2009-10-19 13:31:30 | 00,019,610 | ---- | C] () -- C:\WINDOWS\abaqipir.lib
[2009-10-19 13:31:30 | 00,018,290 | ---- | C] () -- C:\Program Files\Common Files\fivi.lib
[2009-10-19 13:31:30 | 00,018,208 | ---- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\gowype.scr
[2009-10-19 13:31:30 | 00,017,025 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\xyxu.dll
[2009-10-19 13:31:30 | 00,016,731 | ---- | C] () -- C:\WINDOWS\System32\axulygin.db
[2009-10-19 13:31:30 | 00,016,032 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\ajawofog.bat
[2009-10-19 13:31:30 | 00,015,318 | ---- | C] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\pubefuhuhy.inf
[2009-10-19 13:31:30 | 00,015,123 | ---- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\ezina.scr
[2009-10-19 13:31:30 | 00,014,987 | ---- | C] () -- C:\WINDOWS\vacaf.dat
[2009-10-19 13:31:30 | 00,013,590 | ---- | C] () -- C:\Program Files\Common Files\exawo.db
[2009-10-19 13:31:30 | 00,012,898 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\ahoma._sy
[2009-10-19 13:31:30 | 00,012,177 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\gytuzokuta.dll
[2009-10-19 13:31:30 | 00,011,648 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\ezelypa.scr
[2009-10-19 13:31:30 | 00,011,207 | ---- | C] () -- C:\WINDOWS\bidyveco.bin
[2009-10-19 13:31:30 | 00,010,854 | ---- | C] () -- C:\WINDOWS\pefilax.reg
[2009-10-19 13:31:30 | 00,010,538 | ---- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\wazolip._dl
[2009-10-19 13:31:30 | 00,010,529 | ---- | C] () -- C:\WINDOWS\System32\cewerici.dat
[2009-10-19 13:31:30 | 00,010,476 | ---- | C] () -- C:\WINDOWS\jubahuludo.inf
[2009-10-19 13:31:30 | 00,010,398 | ---- | C] () -- C:\WINDOWS\xulydaz.reg
[2009-10-19 13:31:29 | 00,019,704 | ---- | C] () -- C:\WINDOWS\System32\sabo.pif
[2009-10-19 13:26:37 | 00,000,014 | ---- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\iniasd.txt
[2009-10-19 13:26:36 | 00,000,016 | ---- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\wiaservg.log
[2009-10-19 13:26:35 | 00,273,920 | ---- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\svcst.exe
[2009-10-19 13:26:35 | 00,273,920 | ---- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\seres.exe
[2009-10-19 13:21:51 | 00,000,267 | ---- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\dchy8w3hi.cab
[2009-10-19 13:21:51 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\miuevyi83.cab
[2009-10-19 13:15:50 | 00,042,496 | ---- | C] () -- C:\WINDOWS\System32\sys.dat
[2009-10-19 13:15:26 | 00,000,332 | ---- | C] () -- C:\WINDOWS\desctemp.dat
[2009-10-19 13:12:56 | 00,000,057 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009-10-19 12:19:53 | 00,000,032 | ---- | C] () -- C:\WINDOWS\0
[2009-10-19 12:19:53 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\0
[2009-09-25 17:55:46 | 00,002,007 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Auta - Przygody w Chłodnicy Górskiej.lnk
[2009-09-24 15:49:46 | 00,000,717 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\OpenFM.lnk
[2009-09-24 15:49:46 | 00,000,688 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Nowe Gadu-Gadu.lnk
[2009-09-14 16:00:54 | 00,004,608 | ---- | C] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-08-28 18:41:43 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009-08-28 18:41:41 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009-08-28 18:41:41 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009-08-28 18:41:40 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009-08-28 18:41:38 | 00,067,584 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009-08-28 18:41:38 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009-08-06 17:19:53 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009-07-06 19:06:53 | 00,017,280 | ---- | C] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2009-07-04 13:20:59 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
[2009-07-04 11:45:05 | 04,270,744 | -H-- | C] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-07-04 11:38:48 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\admin\Dane aplikacji\desktop.ini
[2006-08-16 09:35:00 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006-08-16 09:35:00 | 01,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006-08-16 09:35:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006-08-16 09:35:00 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006-08-16 09:35:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006-08-16 09:35:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006-08-16 09:35:00 | 00,196,608 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006-03-02 14:00:00 | 00,343,936 | ---- | C] () -- C:\WINDOWS\System32\neuuqhb.dll
[2006-03-02 14:00:00 | 00,000,542 | ---- | C] () -- C:\WINDOWS\win.ini
[2006-03-02 14:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2
< End of report >
Jeśli można prosić jakąś radę?!