• Ogłoszenie:

Komputer długo się włącza

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Komputer długo się włącza

Postprzez MK89 11 Maj 2009, 16:43

reklama
Witam. Jak widać w temacie mój komp ostatnio strasznie muli. Na dodatek miałem duże problemy z paskiem zadań (nadal mam ze względu na to, że nic się na nim nie ukazuje, nawet, jak minimalizuje przeglądarkę), też problemy miałem z klawiaturą i myszką. Wrzucam log i liczę na Waszą pomoc ;)

Hijack:
Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:39:30, on 2009-05-11
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp3\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\System32\reader_s.exe
C:\Program Files\Nowe Gadu-Gadu\gg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
C:\Documents and Settings\MAT\reader_s.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\Bearshare.exe" /pause
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\MAT\reader_s.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-1343024091-1364589140-725345543-1003\..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe" (User '?')
O4 - HKUS\S-1-5-21-1343024091-1364589140-725345543-1003\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User '?')
O4 - HKUS\S-1-5-21-1343024091-1364589140-725345543-1003\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray (User '?')
O4 - HKUS\S-1-5-21-1343024091-1364589140-725345543-1003\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (User '?')
O4 - HKUS\S-1-5-21-1343024091-1364589140-725345543-1003\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User '?')
O4 - HKUS\S-1-5-21-1343024091-1364589140-725345543-1003\..\Run: [reader_s] C:\Documents and Settings\MAT\reader_s.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-1343024091-1364589140-725345543-1003 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User '?')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2A781DED-C22D-4153-9812-CEA98A32981C} (GameDesire Makao) - http://cached.gamedesire.com/g_bin/pl/cardsmakao_2_0_0_29.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe


Dodano 11.05.2009 18:21:55:
Teraz doszło do tego, że nie mam jeszcze dźwieku (ale to nie problem wgrać sobie sterowniki) - tylko same się chyba nie usunęły oraz strasznie zaczyna mulić mi net po jakiś 30 minutach użytkowania.
MaTiX89
Awatar użytkownika
MK89
~user
 
Posty: 298
Dołączenie: 30 Paź 2005, 14:56
Miejscowość: Świnoujście
Pochwały: 1



Komputer długo się włącza

Postprzez wojtas 11 Maj 2009, 21:22

bedzie ciezko juz podziałac bo najprawdopodobniej jest virut..

Wykonaj to co jest podane w tym temacie

Zastosuj SDFix . Po pobraniu uruchom go a rozpakuje się do C:\SDFix. Uruchom komputer w trybie awaryjnym (F8 przy stracie systemu). Będąc w awaryjnym uruchom plik RunThis.bat z folderu SDFixa. Zatwierdź czyszczenie przez Y. Poczekaj aż ukończy i komputer zresetuje

Potem wejdz do folderu C:\SDFix wrzuc zawartość pliku Report.txt + log zOTListIt2
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Komputer długo się włącza

Postprzez MK89 12 Maj 2009, 18:00

Report z SDFix:
Kod: Zaznacz wszystko
[b]SDFix: Version 1.240 [/b]
Run by MAT on 2009-05-12 at 17:18

Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix

[b]Checking Services [/b]:


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


[b]Checking Files [/b]:

Trojan Files Found:

C:\WINDOWS\system32\2.tmp - Deleted
C:\WINDOWS\system32\D.tmp - Deleted
C:\WINDOWS\system32\2.tmp - Deleted
C:\WINDOWS\system32\22.tmp - Deleted
C:\WINDOWS\system32\123.tmp - Deleted
C:\WINDOWS\system32\calc.exe.tmp - Deleted





Removing Temp Files

[b]ADS Check [/b]:



                                 [b]Final Check [/b]:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-12 17:28:27
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:ef,06,44,4d,13,1e,be,72,bb,c8,c4,5b,5d,4a,2e,44,31,7a,1b,c6,d7,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,16,dd,66,c8,3e,7c,d3,b9,4a,3d,d3,d3,06,48,04,3f,d8,..
"khjeh"=hex:80,40,c4,d9,38,4a,c0,c9,0c,2b,ba,10,08,d4,e1,f5,73,62,a8,17,03,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:bb,a9,be,95,bb,f3,f8,a8,c6,91,8b,2b,7f,3b,8f,a8,a7,81,52,88,e2,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:5f,04,28,53,7a,d1,df,3a,80,91,55,fd,64,79,8c,49,f8,d6,86,2a,a6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:ef,06,44,4d,13,1e,be,72,bb,c8,c4,5b,5d,4a,2e,44,31,7a,1b,c6,d7,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,16,dd,66,c8,3e,7c,d3,b9,4a,3d,d3,d3,06,48,04,3f,d8,..
"khjeh"=hex:80,40,c4,d9,38,4a,c0,c9,0c,2b,ba,10,08,d4,e1,f5,73,62,a8,17,03,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:16,35,95,20,33,a2,31,eb,20,5e,fa,ef,72,e9,9f,4a,f8,97,ff,e5,ef,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:5f,04,28,53,7a,d1,df,3a,80,91,55,fd,64,79,8c,49,f8,d6,86,2a,a6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:ef,06,44,4d,13,1e,be,72,bb,c8,c4,5b,5d,4a,2e,44,31,7a,1b,c6,d7,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,16,dd,66,c8,3e,7c,d3,b9,4a,3d,d3,d3,06,48,04,3f,d8,..
"khjeh"=hex:80,40,c4,d9,38,4a,c0,c9,0c,2b,ba,10,08,d4,e1,f5,73,62,a8,17,03,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:bb,a9,be,95,bb,f3,f8,a8,c6,91,8b,2b,7f,3b,8f,a8,a7,81,52,88,e2,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:5f,04,28,53,7a,d1,df,3a,80,91,55,fd,64,79,8c,49,f8,d6,86,2a,a6,..

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


[b]Remaining Services [/b]:




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"F:\\Infogrames\\Grand Prix 4\\GP4.exe"="F:\\Infogrames\\Grand Prix 4\\GP4.exe:*:Enabled:GP4"
"C:\\Program Files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"="C:\\Program Files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe:*:Enabled:Pro Evolution Soccer 2009"
"C:\\Program Files\\BearShare\\Bearshare.exe"="C:\\Program Files\\BearShare\\Bearshare.exe:*:Enabled:BearShare"
"C:\\Program Files\\Gadu-Gadu\\gg.exe"="C:\\Program Files\\Gadu-Gadu\\gg.exe:*:Enabled:Gadu-Gadu - program gˆ˘wny"
"F:\\-GP8-REL-\\Launcher.exe"="F:\\-GP8-REL-\\Launcher.exe:*:Enabled:MotoGP 08"
"C:\\Program Files\\Capcom\\MotoGP 08\\Launcher.exe"="C:\\Program Files\\Capcom\\MotoGP 08\\Launcher.exe:*:Enabled:MotoGP 08"
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"="C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe:*:Disabled:Football Manager 2008"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"F:\\Gry\\Games\\GP4.exe"="F:\\Gry\\Games\\GP4.exe:*:Disabled:GP4"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"="C:\\Program Files\\Nowe Gadu-Gadu\\gg.exe:*:Enabled:Nowe Gadu-Gadu"
"C:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe"="C:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe:*:Disabled:Football Manager 2009"
"C:\\Documents and Settings\\MAT\\Moje dokumenty\\fm.exe"="C:\\Documents and Settings\\MAT\\Moje dokumenty\\fm.exe:*:Enabled:Football Manager 2009"
"C:\\Games\\GP4.exe"="C:\\Games\\GP4.exe:*:Enabled:GP4"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[b]Remaining Files [/b]:



[b]Files with Hidden Attributes [/b]:

Sun 30 Nov 2008        61,952 ...H. --- "C:\Documents and Settings\MAT\Dane aplikacji\Microsoft\Word\~WRL2909.tmp"

[b]Finished![/b]


Log z OTListlt:
Kod: Zaznacz wszystko
OTListIt logfile created on: 2009-05-12 17:50:25 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.7     Folder = C:\Documents and Settings\MAT\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1022,48 Mb Total Physical Memory | 663,98 Mb Available Physical Memory | 64,94% Memory free
2,40 Gb Paging File | 2,18 Gb Available in Paging File | 90,73% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 27,98 Gb Total Space | 4,94 Gb Free Space | 17,66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 232,88 Gb Total Space | 150,69 Gb Free Space | 64,70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MAT-DC21B81543A
Current User Name: MAT
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

[color=orange]========== Processes (SafeList) ==========[/color]

PRC - [2008-04-14 19:21:16 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2005-10-18 16:00:10 | 00,250,880 | ---- | M] (ASUSTeK COMPUTER INC.) -- C:\WINDOWS\ATKKBService.exe
PRC - [2008-12-14 00:25:49 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2005-12-14 08:51:00 | 00,155,715 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2009-05-12 17:27:23 | 00,049,665 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\reader_s.exe
PRC - [2002-07-23 18:58:06 | 00,022,016 | ---- | M] () -- C:\Program Files\Winamp3\winampa.exe
PRC - [2008-12-14 00:25:50 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009-04-25 16:09:56 | 00,098,816 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2007-04-12 11:33:10 | 16,142,336 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2008-09-25 10:40:00 | 01,370,000 | ---- | M] (PC Tools Research Pty Ltd) -- C:\Program Files\PC Tools AntiVirus\PCTAV.exe
PRC - [2006-10-27 01:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2008-06-12 03:38:00 | 00,034,672 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
PRC - [2009-05-12 17:27:23 | 00,049,665 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\reader_s.exe
PRC - [2009-05-12 17:50:00 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MAT\Pulpit\OTListIt2.exe
PRC - [2009-02-16 16:06:52 | 09,302,632 | ---- | M] (GG Network S.A.) -- C:\Program Files\Nowe Gadu-Gadu\gg.exe
PRC - [2008-09-23 15:17:06 | 21,755,688 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe
PRC - [2009-04-25 14:37:54 | 00,014,336 | ---- | M] () -- C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
PRC - [2009-05-12 17:27:24 | 00,049,665 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\MAT\reader_s.exe

[color=orange]========== Win32 Services (SafeList) ==========[/color]

SRV - [2005-10-18 16:00:10 | 00,250,880 | ---- | M] (ASUSTeK COMPUTER INC.) -- C:\WINDOWS\ATKKBService.exe -- (ATKKeyboardService [Auto | Running])
SRV - [2008-04-14 19:20:44 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Stopped])
SRV - [2006-05-30 15:20:40 | 00,810,496 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe -- (InCDsrv [Auto | Stopped])
SRV - [2008-12-14 00:25:49 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2006-10-27 01:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2005-12-14 08:51:00 | 00,155,715 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2006-10-26 20:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006-10-26 15:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2008-09-23 18:21:50 | 00,995,520 | ---- | M] (PC Tools Research Pty Ltd) -- C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe -- (PCTAVSvc [Auto | Stopped])
SRV - [2004-08-11 02:45:04 | 00,048,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Stopped])

[color=orange]========== Driver Services (SafeList) ==========[/color]

DRV - [2008-07-30 07:51:30 | 00,277,736 | ---- | M] (Protect Software GmbH) -- C:\WINDOWS\system32\drivers\acedrv11.sys -- (acedrv11 [Auto | Running])
DRV - [2006-07-02 00:32:26 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\system32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running])
DRV - [2005-10-18 16:01:38 | 00,011,008 | ---- | M] (ASUSTeK COMPUTER INC.) -- C:\WINDOWS\system32\drivers\atkkbnt.sys -- (asuskbnt [System | Running])
DRV - [2008-02-12 11:44:10 | 00,021,904 | ---- | M] (PC Tools Research Pty Ltd) -- C:\WINDOWS\system32\drivers\AVFilter.sys -- (AVFilter [Auto | Running])
DRV - [2007-12-06 16:51:44 | 00,028,568 | ---- | M] (PC Tools Research Pty Ltd.) -- C:\WINDOWS\system32\drivers\AVHook.sys -- (AVHook [On_Demand | Running])
DRV - [2007-12-06 16:51:44 | 00,021,912 | ---- | M] (PC Tools Research Pty Ltd ) -- C:\WINDOWS\system32\drivers\AVRec.sys -- (AVRec [On_Demand | Running])
DRV - File not found --  -- (catchme [On_Demand | Running])
DRV - [2005-10-19 18:00:00 | 00,011,264 | R--- | M] (ASUSTeK Computer Inc.) -- C:\WINDOWS\system32\drivers\EIO.sys -- (EIO [Auto | Running])
DRV - [2001-08-17 22:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc.              ) -- C:\WINDOWS\system32\DRIVERS\fetnd5.sys -- (FETNDIS [On_Demand | Stopped])
DRV - [2004-04-15 04:57:20 | 00,042,496 | R--- | M] (VIA Technologies, Inc.              ) -- C:\WINDOWS\system32\DRIVERS\fetnd5b.sys -- (FETNDISB [On_Demand | Running])
DRV - [2008-04-13 18:36:05 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2006-05-30 15:18:18 | 00,102,656 | ---- | M] (Nero AG) -- C:\WINDOWS\system32\drivers\InCDFs.sys -- (InCDfs [Disabled | Running])
DRV - [2006-05-30 15:18:38 | 00,029,568 | ---- | M] (Nero AG) -- C:\WINDOWS\system32\drivers\InCDPass.sys -- (InCDPass [System | Running])
DRV - [2006-05-30 15:18:52 | 00,033,792 | ---- | M] (Nero AG) -- C:\WINDOWS\system32\drivers\InCDRm.sys -- (incdrm [System | Running])
DRV - [2007-04-23 12:12:28 | 04,402,176 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2005-12-14 08:51:00 | 03,580,480 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2001-08-17 23:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2001-08-17 22:12:40 | 00,019,017 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\system32\DRIVERS\RTL8029.SYS -- (rtl8029 [On_Demand | Stopped])
DRV - [2008-04-13 18:39:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008-11-02 22:25:26 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2006-10-17 14:22:26 | 00,009,216 | R--- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\videX32.sys -- (videX32 [Boot | Running])
DRV - [2006-10-18 11:39:58 | 00,017,920 | R--- | M] (VIA Technologies,Inc) -- C:\WINDOWS\system32\DRIVERS\xfilt.sys -- (xfilt [Boot | Running])

[color=orange]========== Standard Registry (SafeList) ==========[/color]


[color=orange]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\S-1-5-21-1343024091-1364589140-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=orange]========== FireFox ==========[/color]


FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008-12-14 00:25:54 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009-02-22 00:49:12 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009-02-28 19:12:40 | 00,000,000 | ---D | M]

[2008-11-02 19:08:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MAT\Dane aplikacji\mozilla\Firefox\Profiles\s88z2xzj.default\extensions
[2008-11-02 22:28:16 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\MAT\Dane aplikacji\Mozilla\FireFox\Profiles\s88z2xzj.default\searchplugins\daemon-search.xml
[2009-05-07 09:30:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-01-01 21:28:37 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008-12-14 00:26:20 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2008-12-21 16:43:06 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\talkback@mozilla.org
[2009-01-01 21:28:28 | 00,067,688 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jar50.dll
[2009-01-01 21:28:28 | 00,054,368 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jsd3250.dll
[2009-01-01 21:28:28 | 00,034,944 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\myspell.dll
[2009-01-01 21:28:28 | 00,046,712 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\spellchk.dll
[2009-01-01 21:28:29 | 00,172,136 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\xpinstal.dll
[2008-12-21 16:42:57 | 00,000,904 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2008-12-21 16:42:57 | 00,001,419 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2008-12-21 16:42:57 | 00,002,368 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008-12-21 16:42:57 | 00,000,926 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2008-12-21 16:42:57 | 00,000,866 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2008-12-21 16:42:57 | 00,001,198 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2008-12-21 16:42:57 | 00,001,693 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\..\Toolbar\WebBrowser: (no name) - {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BearShare] "C:\Program Files\BearShare\Bearshare.exe" /pause File not found
O4 - HKLM..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NWEReboot]  File not found
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN (PC Tools Research Pty Ltd)
O4 - HKLM..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe (Lexmark)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe" ()
O4 - HKU\.DEFAULT..\Run: [reader_s] C:\Documents and Settings\MAT\reader_s.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [reader_s] C:\Documents and Settings\MAT\reader_s.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (Nero AG)
O4 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun (DT Soft Ltd)
O4 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray File not found
O4 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe" (GG Network S.A.)
O4 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003..\Run: [reader_s] C:\Documents and Settings\MAT\reader_s.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)
O4 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent File not found
O4 - Startup: C:\Documents and Settings\MAT\Menu Start\Programy\Autostart\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMovingBands = 0
O7 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCloseDragDropBands = 0
O7 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LockTaskbar = 0
O7 - HKU\S-1-5-21-1343024091-1364589140-725345543-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2A781DED-C22D-4153-9812-CEA98A32981C} http://cached.gamedesire.com/g_bin/pl/cardsmakao_2_0_0_29.cab (GameDesire Makao)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter:  - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\Antiwpa: DllName - antiwpa.dll - C:\WINDOWS\system32\antiwpa.dll ()
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-10-31 01:05:51 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{4c271c52-2901-11de-8333-0019dbb4ba5a}\Shell - "" = AutoRun
O33 - MountPoints2\{5e0e6b2a-30e3-11de-8350-0019dbb4ba5a}\Shell - "" = AutoRun
O33 - MountPoints2\{5e0e6b2a-30e3-11de-8350-0019dbb4ba5a}\Shell\Auto\command - "" = H:\setup.exe -- File not found
O33 - MountPoints2\{ac0b3a2b-3d55-11de-8383-0019dbb4ba5a}\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck) -  File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) -  File not found

[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]

[4 C:\WINDOWS\*.tmp files]
[2009-05-12 17:49:59 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\MAT\Pulpit\OTListIt2.exe
[2009-05-12 17:17:26 | 00,580,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2009-05-12 17:13:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2009-05-12 17:08:24 | 00,000,000 | ---D | C] -- C:\SDFix
[2009-05-12 17:08:01 | 01,529,241 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\SDFix.exe
[2009-05-12 16:58:39 | 00,060,960 | ---- | C] (gkweb) -- C:\Documents and Settings\MAT\Pulpit\wwdc.exe
[2009-05-11 16:39:20 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\HijackThis.lnk
[2009-05-11 16:39:20 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009-05-11 16:39:16 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\MAT\Pulpit\HJTInstall.exe
[2009-05-10 21:05:50 | 00,182,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndis.sys
[2009-05-10 20:15:02 | 00,049,665 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\reader_s.exe
[2009-05-10 20:10:27 | 00,000,988 | ---- | C] () -- C:\Documents and Settings\MAT\Menu Start\Programy\Autostart\Adobe Gamma.lnk
[2009-05-10 19:26:07 | 00,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2009-05-10 19:02:53 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2009-05-10 19:02:41 | 15,274,240 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\TU2008TrialPL.exe
[2009-05-10 15:04:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MAT\Pulpit\AB
[2009-05-10 13:40:18 | 00,028,672 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\CYTATY.doc
[2009-05-10 13:28:24 | 00,044,544 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\PREZENTACJA.doc
[2009-05-09 14:40:49 | 00,014,501 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\medaliony.docx
[2009-05-09 10:43:47 | 00,045,884 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\Richard Rorty.docx
[2009-05-09 08:25:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MAT\Pulpit\Nowy folder
[2009-05-07 09:19:35 | 00,000,000 | ---D | C] -- C:\Program Files\SkanerOnline
[2009-05-02 19:33:49 | 00,982,016 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\REC07.WAV
[2009-04-30 19:50:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MAT\Moje dokumenty\WSC Real 09
[2009-04-30 19:43:53 | 00,000,782 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\WSC Real 09.lnk
[2009-04-30 18:53:26 | 00,000,000 | ---D | C] -- C:\Program Files\Blade
[2009-04-30 13:46:17 | 00,323,072 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\hjsplit.exe
[2009-04-29 19:38:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MAT\Pulpit\zakończenie
[2009-04-29 19:37:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MAT\Dane aplikacji\WinRAR
[2009-04-29 12:51:14 | 01,251,761 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\winrar380pro.exe
[2009-04-28 17:15:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MAT\Moje dokumenty\NeroVision
[2009-04-20 22:05:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\KONAMI
[2009-04-20 21:33:34 | 00,000,000 | ---D | C] -- C:\Program Files\KONAMI
[2009-04-16 15:19:54 | 00,237,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009-04-16 15:19:53 | 00,473,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fastprox.dll
[2009-04-16 15:19:53 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcss.dll
[2009-04-16 15:19:53 | 00,285,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pdh.dll
[2009-04-16 15:19:53 | 00,120,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\services.exe
[2009-04-16 15:19:52 | 00,686,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advapi32.dll
[2009-04-16 15:19:51 | 00,731,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009-04-16 15:19:50 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009-04-16 15:19:49 | 00,722,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntdll.dll
[2009-04-16 15:19:15 | 01,203,922 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009-04-16 15:19:15 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wordpad.exe
[2009-04-16 10:09:14 | 06,079,665 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\09. ennio morricone - karol e il dolore.mp3
[2009-04-15 19:00:35 | 02,627,291 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\zygmunt konieczny - jasminum.mp3
[2009-04-15 18:57:55 | 05,024,736 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\grzegorz turnau - bracka.mp3
[2009-04-12 20:53:08 | 04,016,587 | ---- | C] () -- C:\Documents and Settings\MAT\Pulpit\kult - do ani.mp3
[2009-04-11 13:24:13 | 00,000,344 | ---- | C] () -- C:\WINDOWS\Biblia.INI
[2009-01-21 11:35:16 | 00,009,216 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2009-01-01 20:20:02 | 00,060,416 | ---- | C] () -- C:\WINDOWS\System32\antiwpa.dll
[2008-12-21 13:08:52 | 00,000,034 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2008-12-07 19:32:09 | 00,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008-12-07 19:32:08 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2008-12-07 19:31:58 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008-12-07 19:31:55 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008-12-07 19:31:55 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008-12-04 20:46:33 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2008-11-30 16:23:02 | 00,000,052 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2008-11-19 22:30:38 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-11-02 22:25:26 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008-10-31 10:23:42 | 00,071,168 | ---- | C] () -- C:\WINDOWS\System32\lexlelm.dll
[2008-10-31 10:23:42 | 00,000,655 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2008-10-31 10:23:39 | 00,357,888 | ---- | C] () -- C:\WINDOWS\System32\dosfnt32.dll
[2008-10-31 10:23:39 | 00,163,840 | ---- | C] () -- C:\WINDOWS\System32\ldepcl32.dll
[2008-10-31 09:57:34 | 00,000,050 | ---- | C] () -- C:\WINDOWS\Winamp.ini
[2008-10-31 09:57:31 | 00,000,041 | ---- | C] () -- C:\WINDOWS\winampa.ini
[2008-10-31 01:30:36 | 00,010,496 | ---- | C] () -- C:\WINDOWS\System32\ATKOSDMini.DLL
[2008-10-31 01:30:36 | 00,000,018 | ---- | C] () -- C:\WINDOWS\System32\atkid.ini
[2008-10-31 01:30:35 | 00,046,592 | ---- | C] () -- C:\WINDOWS\System32\asfrench.dll
[2008-10-31 01:30:35 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\asrussian.dll
[2008-10-31 01:30:35 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\asgerman.dll
[2008-10-31 01:30:35 | 00,046,080 | ---- | C] () -- C:\WINDOWS\System32\aseng.dll
[2008-10-31 01:30:35 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\askorean.dll
[2008-10-31 01:30:35 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\asjapan.dll
[2008-10-31 01:30:35 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\ASCHT.dll
[2008-10-31 01:30:35 | 00,045,568 | ---- | C] () -- C:\WINDOWS\System32\aschs.dll
[2007-11-26 22:56:28 | 00,151,415 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2005-12-14 08:51:00 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2005-12-14 08:51:00 | 01,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2005-12-14 08:51:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2005-12-14 08:51:00 | 00,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2005-12-14 08:51:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2005-12-14 08:51:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2005-12-14 08:51:00 | 00,090,112 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2001-07-22 00:16:20 | 00,000,670 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 00:15:52 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

[color=orange]========== Files - Modified Within 30 Days ==========[/color]

[6 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009-05-12 17:50:00 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MAT\Pulpit\OTListIt2.exe
[2009-05-12 17:49:12 | 00,061,465 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009-05-12 17:27:23 | 00,049,665 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\reader_s.exe
[2009-05-12 17:23:45 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\MAT\Ustawienia lokalne\desktop.ini
[2009-05-12 17:23:44 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-05-12 17:19:01 | 00,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2009-05-12 17:17:26 | 00,580,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2009-05-12 17:08:08 | 01,529,241 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\SDFix.exe
[2009-05-12 16:58:46 | 00,060,960 | ---- | M] (gkweb) -- C:\Documents and Settings\MAT\Pulpit\wwdc.exe
[2009-05-11 19:11:55 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-05-11 16:39:20 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\HijackThis.lnk
[2009-05-11 16:39:16 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\MAT\Pulpit\HJTInstall.exe
[2009-05-10 21:05:50 | 00,182,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ndis.sys
[2009-05-10 21:05:50 | 00,182,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndis.sys
[2009-05-10 20:10:27 | 00,000,670 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-05-10 20:10:27 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-05-10 20:10:27 | 00,000,223 | RHS- | M] () -- C:\boot.ini
[2009-05-10 16:52:36 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-05-10 13:40:38 | 00,044,544 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\PREZENTACJA.doc
[2009-05-10 13:40:19 | 00,028,672 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\CYTATY.doc
[2009-05-09 20:11:25 | 00,014,501 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\medaliony.docx
[2009-05-09 14:51:34 | 00,045,884 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\Richard Rorty.docx
[2009-04-30 19:43:53 | 00,000,782 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\WSC Real 09.lnk
[2009-04-29 12:51:40 | 01,251,761 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\winrar380pro.exe
[2009-04-28 15:46:29 | 00,002,549 | ---- | M] () -- C:\WINDOWS\System32\Lexmark Z31 Series ColorFine.AD2
[2009-04-25 21:05:59 | 00,139,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\taskmgr.exe
[2009-04-25 14:37:49 | 00,538,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\spider.exe
[2009-04-25 14:37:48 | 00,128,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshearts.exe
[2009-04-25 14:37:46 | 00,150,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\imapi.exe
[2009-04-25 14:37:46 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ctfmon.exe
[2009-04-25 14:37:20 | 00,347,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tourstart.exe
[2009-04-25 14:37:18 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\rundll32.exe
[2009-04-25 14:37:17 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\alg.exe
[2009-04-24 17:34:22 | 00,515,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\logonui.exe
[2009-04-24 17:22:40 | 00,285,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winhlp32.exe
[2009-04-24 17:20:50 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\notepad.exe
[2009-04-22 15:17:03 | 00,012,600 | ---- | M] () -- C:\Documents and Settings\MAT\Moje dokumenty\NR.docx
[2009-04-20 20:59:34 | 00,000,151 | ---- | M] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2009-04-16 20:43:08 | 00,358,390 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2009-04-16 20:43:08 | 00,314,508 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-04-16 20:43:08 | 00,050,336 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2009-04-16 20:43:08 | 00,040,836 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-04-16 20:43:07 | 00,771,882 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-04-16 17:06:05 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-04-16 15:49:04 | 00,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-04-16 10:14:16 | 06,079,665 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\09. ennio morricone - karol e il dolore.mp3
[2009-04-15 19:02:47 | 02,627,291 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\zygmunt konieczny - jasminum.mp3
[2009-04-15 19:02:07 | 05,024,736 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\grzegorz turnau - bracka.mp3
[2009-04-12 20:56:28 | 04,016,587 | ---- | M] () -- C:\Documents and Settings\MAT\Pulpit\kult - do ani.mp3

[color=orange]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 205 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:436DEE1E
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:7E95B6FD
< End of report >
MaTiX89
Awatar użytkownika
MK89
~user
 
Posty: 298
Dołączenie: 30 Paź 2005, 14:56
Miejscowość: Świnoujście
Pochwały: 1



Komputer długo się włącza

Postprzez wojtas 12 Maj 2009, 18:32

zobacz tu :

http://www.searchengines.pl/Infekcje-plikow-wykonywalnych-exe-dll-scr-t122692.html

poczytaj o usuwaniu wirusa
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Komputer długo się włącza

Postprzez MK89 14 Maj 2009, 12:56

Pozbyłem się większości wirusów. Teraz pokazuje, że komp jest "czysty", ale czy na pewno? Wgrałem też nowego windows'a, teraz jednak mam taki problem: http://img13.imageshack.us/my.php?image=beztytuuvoi.jpg

A oto wstawiam log z HiJackThis:
Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:43:36, on 2009-05-14
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS2\System32\smss.exe
C:\WINDOWS2\system32\winlogon.exe
C:\WINDOWS2\system32\services.exe
C:\WINDOWS2\system32\lsass.exe
C:\WINDOWS2\system32\svchost.exe
C:\WINDOWS2\System32\svchost.exe
C:\WINDOWS2\system32\spoolsv.exe
C:\WINDOWS2\Explorer.EXE
C:\WINDOWS2\system32\RUNDLL32.EXE
C:\WINDOWS2\system32\ctfmon.exe
C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
C:\WINDOWS2\ATKKBService.exe
C:\WINDOWS2\system32\nvsvc32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\Program Files\Nowe Gadu-Gadu\open-fm.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\wuauclt.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\dwwin.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\dwwin.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\dwwin.exe
C:\WINDOWS2\system32\dwwin.exe
C:\WINDOWS2\system32\dwwin.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\WINDOWS2\system32\rundll32.exe
C:\Program Files\Nowe Gadu-Gadu\gg.exe
C:\WINDOWS2\system32\dwwin.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS2\system32\dwwin.exe
C:\Documents and Settings\Matson\Pulpit\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS2\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS2\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS2\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS2\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS2\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS2\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS2\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS2\ATKKBService.exe
O23 - Service: Usługa administracyjna Menedżera dysków logicznych (dmadmin) - Unknown owner - C:\WINDOWS2\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS2\system32\nvsvc32.exe
O23 - Service: Menedżer sesji pomocy pulpitu zdalnego (RDSessMgr) - Unknown owner - C:\WINDOWS2\system32\sessmgr.exe
O23 - Service: Karta inteligentna (SCardSvr) - Unknown owner - C:\WINDOWS2\System32\SCardSvr.exe
O23 - Service: Dzienniki wydajności i alerty (SysmonLog) - Unknown owner - C:\WINDOWS2\system32\smlogsvc.exe

--
End of file - 10845 bytes
MaTiX89
Awatar użytkownika
MK89
~user
 
Posty: 298
Dołączenie: 30 Paź 2005, 14:56
Miejscowość: Świnoujście
Pochwały: 1



Komputer długo się włącza

Postprzez wojtas 14 Maj 2009, 15:18

jeszcze raz zastosuj sdfixa i daj z OTListlt
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Re: komputer długo się włącza

Postprzez MK89 14 Maj 2009, 21:01

No jak użyłem SDFix to ponownie uruchamiając kompa nie mam ikon na pulpicie oraz paska startu. Mam poprostu "czysty" pulpit. Obecnie muszę korzystać z trybu awaryjnego, by naprawić ten błąd.

Pozdrawiam.

I dzięki za cierpliwość, jaką wkładacie w nasze problemy. Teraz spróbuje znaleźć coś, aby się tego problemu pozbyć...
MaTiX89
Awatar użytkownika
MK89
~user
 
Posty: 298
Dołączenie: 30 Paź 2005, 14:56
Miejscowość: Świnoujście
Pochwały: 1



Komputer długo się włącza

Postprzez wojtas 14 Maj 2009, 21:38

wejdz do konsoli odzyskiwania i wpisz

expand X:\i386\explorer.ex_ C:\WINDOWS\


a jak nie działa

expand X:\i386\explorer.ex_ C:\WINDOWS\explorer.exe


X - literka Twojego napedu..

i reset kompa
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 15 gości