nie chce zamieszczać nowego tematu i robić bałaganu więc opisze wszystko tutaj tamten problem to był chyba problem programu do pobierania fresh download gdy go usunąłem i zmieniłem na inny problemu nie ma ale za to dzisiaj pojawił się inny wczoraj szukałem trochę na googlach na zagranicznych stronkach i wpadło mi trochę nieprzyjaznego oprogramowania czego efektem po dzisiejszym włączeniu komputera był brak ikonek oraz pasku startu czyli w menadżerze brak procesu explorer.exe wyświetlił się też komunikat że nie może go znaleźć... próbowałem uruchomić go samemu ale się nie udało więc zabrałem się za skanowanie komputera bo zauważyłem kilka nieznanych mi wcześniej procesów po kolei zrobiłem skan F-Secure Online Virus Scanner wykrył trochę szkodliwego oprogramowania i usunął dalej Kaspersky Anti-Virus Web Scanner także coś znalazł coś usunoł... potem zrobiłem skan programem który mi wcześniej poleciłeś Dr. Web CureIt ten z kolei znalazł najwięcej bo powyrzej 20plików które też usunoł jednak problem nie zniknoł... znikneło kilka niepokojących mnie procesów ale jak nie było tak dalej nie ma explorera dlatego podaje kilka logów
OTL
- Kod: Zaznacz wszystko
OTL logfile created on: 2009-07-03 08:55:02 - Run 2
OTL by OldTimer - Version 3.0.6.3 Folder = C:\Documents and Settings\XP\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
1022,48 Mb Total Physical Memory | 692,03 Mb Available Physical Memory | 67,68% Memory free
2,40 Gb Paging File | 2,21 Gb Available in Paging File | 91,84% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38,16 Gb Total Space | 4,06 Gb Free Space | 10,65% Space Free | Partition Type: NTFS
Drive D: | 524,03 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 4,65 Gb Total Space | 0,38 Gb Free Space | 8,09% Space Free | Partition Type: NTFS
Drive F: | 4,88 Gb Total Space | 1,69 Gb Free Space | 34,54% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: XP-OLMWF7U33DFU
Current User Name: XP
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2009-07-03 07:58:00 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVGLS\avgwdsvc.exe
PRC - [2009-05-07 11:18:44 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2005-01-28 01:36:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe
PRC - [2009-07-03 07:58:05 | 00,594,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVGLS\avgnsx.exe
PRC - [2008-04-14 22:51:52 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2008-04-14 22:51:52 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe
PRC - [2009-06-13 09:32:56 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008-08-08 07:04:10 | 01,091,768 | ---- | M] (C. Ghisler & Co.) -- C:\totalcmd\TOTALCMD.EXE
PRC - [2009-07-03 08:54:58 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\XP\Pulpit\OTL.exe
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - [2008-04-14 22:49:54 | 00,100,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\6to4svc.dll -- (6to4 [Auto | Running])
SRV - [2005-09-23 07:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009-07-03 07:58:00 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVGLS\avgwdsvc.exe -- (avg8wd [Auto | Running])
SRV - [2005-09-23 07:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008-04-14 22:50:46 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2009-05-07 11:18:44 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2006-10-27 00:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2006-10-26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006-10-26 13:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007-11-06 22:22:26 | 00,092,792 | ---- | M] (CACE Technologies) -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd [On_Demand | Stopped])
SRV - [2005-01-28 01:36:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2009-07-03 07:58:23 | 00,253,832 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86 [System | Running])
DRV - [2009-07-03 07:58:22 | 00,108,296 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX [System | Running])
DRV - [2003-05-01 12:08:52 | 00,743,367 | ---- | M] (C-Media Inc) -- C:\WINDOWS\System32\drivers\cmuda.sys -- (cmuda [On_Demand | Running])
DRV - [2009-07-03 08:04:00 | 00,070,144 | ---- | M] () -- C:\Documents and Settings\XP\Ustawienia lokalne\temp\OnlineScanner\Anti-Virus\fsgk.sys -- (F-Secure Standalone Minifilter [On_Demand | Stopped])
DRV - [2008-04-14 00:15:30 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running])
DRV - [2003-04-15 04:39:46 | 00,090,907 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys -- (ialm [On_Demand | Running])
DRV - [2008-04-14 00:23:10 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\NMnt.sys -- (nm [On_Demand | Stopped])
DRV - [2007-11-06 22:22:06 | 00,034,064 | ---- | M] (CACE Technologies) -- C:\WINDOWS\System32\drivers\npf.sys -- (NPF [On_Demand | Stopped])
DRV - [2001-08-17 23:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008-08-20 19:58:58 | 00,044,944 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2002-10-04 04:04:10 | 00,046,976 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\DRIVERS\R8139n51.SYS -- (rtl8139 [On_Demand | Running])
DRV - [2009-03-15 12:25:46 | 00,056,268 | ---- | M] (PowerISO Computing, Inc.) -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu [System | Running])
DRV - [2008-04-13 22:09:18 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [Auto | Running])
DRV - [2008-04-14 00:30:04 | 00,225,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\tcpip6.sys -- (Tcpip6 [System | Running])
DRV - [2003-04-15 04:40:54 | 00,113,504 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\drivers\ialmsbw.sys -- ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Running])
DRV - [2003-04-15 04:40:46 | 00,078,752 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\drivers\ialmkchw.sys -- ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running])
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101687&l=dis
IE - URLSearchHook: {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\PROGRA~1\DAP\SBSearch.dll File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://pl.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:pl:official"
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.3.1.313
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.1.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11
FF - prefs.js..keyword.URL: "http://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=GGSV5&o=101684&locale=en_US&q="
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-05-07 11:18:44 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVGLS\Firefox [2009-07-03 07:58:00 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\mozilla firefox 3.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-07-02 21:01:25 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\mozilla firefox 3.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-06-26 19:32:42 | 00,000,000 | ---D | M]
[2009-05-06 23:56:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\XP\Dane aplikacji\mozilla\Extensions
[2009-05-06 23:56:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\XP\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-07-03 08:51:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\XP\Dane aplikacji\mozilla\Firefox\Profiles\dsackb59.default\extensions
[2009-06-04 18:58:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\XP\Dane aplikacji\mozilla\Firefox\Profiles\dsackb59.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2009-07-02 21:01:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\XP\Dane aplikacji\mozilla\Firefox\Profiles\dsackb59.default\extensions\toolbar@ask.com
[2009-07-02 21:06:19 | 00,002,240 | ---- | M] () -- C:\Documents and Settings\XP\Dane aplikacji\Mozilla\FireFox\Profiles\dsackb59.default\searchplugins\askcom.xml
[2009-07-03 08:51:35 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-06-13 09:33:06 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-05-07 11:18:59 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009-06-13 09:32:54 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-06-13 09:32:55 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-05-07 11:18:44 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2007-03-27 09:48:51 | 00,717,312 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2007-03-27 09:49:32 | 00,094,208 | ---- | M] (DivX, Inc) -- C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2009-06-13 09:32:58 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006-10-26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2003-05-15 10:01:48 | 00,133,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008-09-10 21:56:44 | 00,144,960 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2008-09-10 21:37:54 | 00,094,208 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2006-06-03 18:43:22 | 00,000,896 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2008-04-03 19:19:08 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2008-04-16 06:08:20 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2007-03-31 19:11:54 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2006-06-03 18:43:22 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2008-03-28 23:36:04 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2007-01-05 13:40:56 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVGLS\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll File not found
O2 - BHO: (Ask.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {98C92840-EB1C-40BD-B6A5-395EC9CD6510} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVGLS\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE (Microsoft Corporation)
O4 - HKLM..\RunOnce: [AVG frw] File not found
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: FreshDownload - {793519b5-cad5-479f-94f2-8c8e833dc589} - C:\Program Files\FreshDevices\FreshDownload\fd.exe File not found
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab (F-Secure Online Scanner 4.0 Launcher)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.113.224.35 217.113.224.36
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVGLS\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-05-01 19:04:47 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001-10-26 18:12:38 | 00,000,112 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2009-02-27 20:29:03 | 00,000,000 | ---- | M] () - F:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[4 C:\WINDOWS\*.tmp files]
[2009-07-03 08:54:57 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\XP\Pulpit\OTL.exe
[2009-07-03 08:30:07 | 00,000,000 | ---D | C] -- C:\Avenger
[2009-07-03 07:58:24 | 00,001,520 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\AVG LinkScanner®.lnk
[2009-07-03 07:58:23 | 00,253,832 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009-07-03 07:58:22 | 00,108,296 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009-07-03 07:58:00 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009-07-03 07:57:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\avg8ls
[2009-07-03 07:42:09 | 00,001,740 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\HijackThis.lnk
[2009-07-03 07:41:18 | 00,396,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF3090.exe
[2009-07-03 07:41:18 | 00,000,000 | --SD | C] -- C:\ComboFix
[2009-07-03 00:46:48 | 01,106,807 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Full_Metal_Panic!-1090-fr.jpg
[2009-07-03 00:46:31 | 01,226,884 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Full_Metal_Panic!-1089-fr.jpg
[2009-07-03 00:42:29 | 01,100,123 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Full_Metal_Panic!-1088-fr.jpg
[2009-07-03 00:35:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Pulpit\Full_Metal_Panic_ep01_24_Rahvin_AnimeSubInfo_id16993
[2009-07-03 00:35:31 | 00,140,364 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\Full_Metal_Panic_ep01_24_Rahvin_AnimeSubInfo_id16993.zip
[2009-07-02 22:00:55 | 00,029,696 | ---- | C] () -- C:\WINDOWS\System32\lcb.exe
[2009-07-02 21:39:43 | 00,000,023 | ---- | C] () -- C:\WINDOWS\DownloadStudio.INI
[2009-07-02 21:27:25 | 00,000,000 | ---D | C] -- C:\Program Files\LeechGet 2009
[2009-07-02 21:26:05 | 03,054,220 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\LeechGet_2.1_2009.exe
[2009-07-02 21:03:51 | 00,000,000 | ---D | C] -- C:\Program Files\LeechGet 2007
[2009-07-02 21:02:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\AskToolbar
[2009-07-02 21:01:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Dane aplikacji\GetGo Software
[2009-07-02 21:01:41 | 00,000,000 | ---D | C] -- C:\Program Files\GetGo Software
[2009-07-02 21:01:34 | 00,000,228 | ---- | C] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2009-07-02 21:01:30 | 00,000,000 | ---D | C] -- C:\Program Files\Ask.com
[2009-07-02 20:53:57 | 02,695,444 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\LeechGet2.1.exe
[2009-07-02 20:53:02 | 04,060,312 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\GetGoSetup.exe
[2009-07-02 20:51:14 | 00,000,033 | ---- | C] () -- C:\WINDOWS\DownloadStudioScheduleMonitor.INI
[2009-07-02 20:51:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Dane aplikacji\Conceiva
[2009-07-02 20:50:54 | 00,000,000 | ---D | C] -- C:\Program Files\WinPcap
[2009-07-02 20:33:25 | 03,224,463 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\fgf173.exe
[2009-07-02 20:33:05 | 02,129,325 | ---- | C] ( ) -- C:\Documents and Settings\XP\Pulpit\freshdow.exe
[2009-07-02 20:31:45 | 26,019,088 | ---- | C] (Macrovision Corporation) -- C:\Documents and Settings\XP\Pulpit\downloadstudio-setup.exe
[2009-07-01 02:00:40 | 00,315,973 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\Panstwowa Inspekcja Pracy.jpg
[2009-06-30 08:37:06 | 00,402,833 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Tokkô-2460-fr.jpg
[2009-06-30 08:36:55 | 00,900,167 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Tokkô-2466-fr.jpg
[2009-06-30 08:36:31 | 00,929,855 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Tokkô-2465-en.jpg
[2009-06-30 08:36:12 | 00,323,837 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Tokkô-2459-en.jpg
[2009-06-29 15:40:36 | 07,855,890 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\P53_S36_PIKUJ_300dpi.jpg zwinin.jpg
[2009-06-28 20:21:06 | 00,005,808 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\_gg__Code_Geass_-_Picture_Book_22.25__E776C879_.mkv
[2009-06-28 00:07:11 | 00,045,903 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\grill-12.jpg
[2009-06-27 20:56:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Dane aplikacji\ReGet Software
[2009-06-27 20:56:01 | 00,001,672 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\ReGet Deluxe.lnk
[2009-06-27 20:55:58 | 00,000,065 | ---- | C] () -- C:\WINDOWS\english.lng
[2009-06-27 20:55:56 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\ReGet Shared
[2009-06-27 20:55:55 | 00,000,000 | ---D | C] -- C:\Program Files\ReGet Software
[2009-06-27 20:44:08 | 00,090,112 | ---- | C] (MindVision Software) -- C:\WINDOWS\unvise32.exe
[2009-06-27 20:36:50 | 00,000,000 | ---D | C] -- C:\Program Files\GetRight
[2009-06-27 20:20:51 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009-06-27 18:43:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\dllcache\cache
[2009-06-27 18:36:35 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009-06-27 18:36:32 | 00,262,400 | ---- | C] () -- C:\cmldr
[2009-06-27 18:36:28 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009-06-27 18:30:42 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009-06-27 18:30:42 | 00,155,136 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009-06-27 18:30:42 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009-06-27 18:30:42 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009-06-27 18:30:42 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009-06-27 18:30:42 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009-06-27 18:30:41 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009-06-27 18:30:41 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009-06-27 18:30:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009-06-27 18:30:01 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009-06-27 18:25:23 | 03,042,087 | R--- | C] () -- C:\Documents and Settings\XP\Pulpit\ComboFix.exe
[2009-06-26 20:30:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Dane aplikacji\Malwarebytes
[2009-06-26 20:30:34 | 00,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2009-06-26 20:30:32 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-06-26 20:30:30 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009-06-26 20:30:30 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009-06-26 20:30:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
[2009-06-26 17:54:45 | 00,000,000 | ---D | C] -- C:\WINDOWS\BDOSCAN8
[2009-06-26 17:44:53 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009-06-26 00:42:33 | 00,019,968 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\s131.xls
[2009-06-25 23:39:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Desktop
[2009-06-25 23:39:05 | 00,000,000 | ---D | C] -- C:\Program Files\FreshDevices
[2009-06-25 18:30:44 | 00,000,162 | ---- | C] () -- C:\Documents and Settings\XP\Moje dokumenty\flash.lst
[2009-06-25 16:49:34 | 00,000,000 | ---D | C] -- C:\Program Files\FlashGet
[2009-06-24 18:32:35 | 00,114,230 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\FGXL_SPOL_(www.programs.pl).exe
[2009-06-22 12:52:18 | 00,000,000 | ---D | C] -- C:\Program Files\Gabest
[2009-06-22 12:44:21 | 06,833,525 | ---- | C] (CCCP Project ) -- C:\Documents and Settings\XP\Pulpit\Combined-Community-Codec-Pack-2008-09-21.exe
[2009-06-22 12:08:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Dane aplikacji\Aegisub
[2009-06-22 12:07:14 | 00,000,000 | ---D | C] -- C:\Program Files\Aegisub
[2009-06-22 12:03:18 | 25,265,044 | ---- | C] (Aegisub Team ) -- C:\Documents and Settings\XP\Pulpit\aegisub-r2494-setup.exe
[2009-06-21 11:03:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
[2009-06-21 11:02:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\SpeedBit
[2009-06-21 11:02:33 | 00,000,000 | ---D | C] -- C:\Program Files\DAP
[2009-06-21 10:57:24 | 09,437,208 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\dap91.exe
[2009-06-21 10:28:42 | 00,210,049 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\aegikc4.jpg
[2009-06-20 19:00:03 | 00,400,405 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\tydzien.mp3
[2009-06-20 17:31:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Pulpit\sita
[2009-06-18 23:10:30 | 01,739,720 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\444.jpg
[2009-06-18 23:10:02 | 01,678,298 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\299.jpg
[2009-06-18 23:09:18 | 01,246,400 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\179.jpg
[2009-06-16 14:50:43 | 03,241,307 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\DSC00572.JPG
[2009-06-16 14:48:59 | 00,026,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\USBSTOR.SYS
[2009-06-14 21:29:06 | 00,015,962 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\Baśń.docx
[2009-06-14 21:23:36 | 00,002,513 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\Microsoft Office Word 2007.lnk
[2009-06-14 00:01:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Moje dokumenty\Notesy programu OneNote
[2009-06-12 00:33:08 | 00,961,525 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Kenshin-1936-en.jpg
[2009-06-12 00:32:58 | 01,008,087 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Kenshin-2036-fr.jpg
[2009-06-12 00:32:49 | 00,972,010 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Kenshin-2034-fr.jpg
[2009-06-12 00:32:36 | 01,278,036 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Kenshin-2033-fr.jpg
[2009-06-11 21:58:46 | 00,159,430 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\Zakladki 2009-06-11.json
[2009-06-11 16:36:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Moje dokumenty\NeroVision
[2009-06-10 22:14:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Dane aplikacji\Ahead
[2009-06-10 19:08:04 | 00,000,000 | ---D | C] -- C:\Program Files\Metin2_PL
[2009-06-10 10:53:07 | 00,000,937 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\Skrót do NeroStartSmart.lnk
[2009-06-10 10:52:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\Ahead
[2009-06-08 11:19:43 | 00,000,766 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\VirtualDubMod.lnk
[2009-06-08 11:19:41 | 00,000,000 | ---D | C] -- C:\Program Files\VirtualDubMod
[2009-06-08 08:34:30 | 00,000,000 | ---D | C] -- C:\Setup
[2009-06-08 08:34:30 | 00,000,000 | ---D | C] -- C:\Redist
[2009-06-08 08:34:30 | 00,000,000 | ---D | C] -- C:\Program Files\Nero
[2009-06-08 08:34:30 | 00,000,000 | ---D | C] -- C:\Cab
[2009-06-07 07:36:32 | 00,000,659 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\Gadu-Gadu.lnk
[2009-06-07 07:36:29 | 00,000,000 | ---D | C] -- C:\Program Files\Gadu-Gadu
[2009-06-07 07:33:17 | 00,000,000 | ---D | C] -- C:\haker
[2009-06-06 20:28:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Dane aplikacji\uTorrent
[2009-06-06 19:46:20 | 00,001,557 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\mkvmerge GUI.lnk
[2009-06-06 19:46:07 | 00,000,000 | ---D | C] -- C:\Program Files\MKVtoolnix
[2009-06-05 16:55:16 | 00,000,104 | ---- | C] () -- C:\Documents and Settings\XP\Moje dokumenty\Internet.lnk
[2009-06-05 16:17:09 | 00,000,788 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\Skrót do IDMan.lnk
[2009-06-05 16:14:35 | 00,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2009-06-05 16:11:09 | 00,046,695 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\lista.ef2
[2009-06-05 03:14:44 | 00,839,680 | ---- | C] (http://www.mp3dev.org/) -- C:\WINDOWS\System32\lameACM.acm
[2009-06-05 03:14:44 | 00,000,414 | ---- | C] () -- C:\WINDOWS\System32\lame_acm.xml
[2009-06-05 03:14:43 | 00,217,088 | ---- | C] (www.helixcommunity.org) -- C:\WINDOWS\System32\yv12vfw.dll
[2009-06-05 03:14:43 | 00,118,784 | ---- | C] (fccHandler) -- C:\WINDOWS\System32\ac3acm.acm
[2009-06-05 03:14:42 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009-06-05 03:14:42 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009-06-05 03:14:40 | 00,684,032 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divx.dll
[2009-06-05 03:14:37 | 00,067,584 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009-06-05 03:14:37 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009-06-05 03:14:34 | 00,060,273 | ---- | C] (Open Source Software community project) -- C:\WINDOWS\System32\pthreadGC2.dll
[2009-06-04 22:40:00 | 00,000,000 | ---D | C] -- C:\Program Files\Combined Community Codec Pack
[2009-06-04 20:52:35 | 00,000,348 | ---- | C] () -- C:\Documents and Settings\XP\Pulpit\Moje dokumenty.lnk
[2009-06-04 19:20:50 | 00,000,067 | ---- | C] () -- C:\WINDOWS\IDMan.INI
[2009-06-04 19:19:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Dane aplikacji\DMCache
[2009-06-04 19:19:12 | 00,000,000 | ---D | C] -- C:\Program Files\Internet Download Manager
[2009-06-04 18:58:40 | 00,000,000 | ---D | C] -- C:\profiles
[2009-06-04 03:00:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Pulpit\poszukiwanianr5
[2009-06-03 14:46:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\XP\Moje dokumenty\GoD
[2009-05-31 14:32:13 | 00,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2009-05-30 19:10:56 | 00,000,525 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2009-05-17 12:04:43 | 00,000,267 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2009-05-09 22:28:55 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2009-05-08 08:30:32 | 00,000,118 | ---- | C] () -- C:\WINDOWS\holzed.ini
[2009-05-07 23:15:32 | 00,974,848 | R--- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2009-05-07 23:15:32 | 00,028,672 | R--- | C] () -- C:\WINDOWS\System32\vorbisfile.dll
[2009-05-07 23:15:31 | 00,049,152 | R--- | C] () -- C:\WINDOWS\System32\ogg.dll
[2009-05-07 00:00:39 | 00,003,494 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2009-05-02 22:21:25 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009-05-01 19:44:35 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2009-05-01 19:14:57 | 01,900,544 | ---- | C] () -- C:\WINDOWS\System32\cmiwcnfg.dll
[2009-05-01 19:14:57 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
[2009-05-01 19:14:57 | 00,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2009-05-01 19:14:57 | 00,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2009-05-01 19:14:56 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Wininit.ini
[2009-05-01 19:14:43 | 00,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2009-01-05 15:44:10 | 00,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2007-11-06 22:19:28 | 00,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007-03-27 09:55:48 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2002-10-16 00:54:04 | 00,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2001-07-22 00:16:20 | 00,000,687 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 00:15:52 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009-07-03 08:54:58 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\XP\Pulpit\OTL.exe
[2009-07-03 08:53:56 | 00,003,494 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2009-07-03 08:50:03 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-07-03 08:50:00 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-07-03 08:01:00 | 00,000,228 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2009-07-03 07:58:24 | 00,001,520 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\AVG LinkScanner®.lnk
[2009-07-03 07:58:23 | 00,253,832 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009-07-03 07:58:22 | 00,108,296 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009-07-03 07:42:09 | 00,001,740 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\HijackThis.lnk
[2009-07-03 07:41:12 | 00,396,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF3090.exe
[2009-07-03 00:46:57 | 01,106,807 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Full_Metal_Panic!-1090-fr.jpg
[2009-07-03 00:46:40 | 01,226,884 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Full_Metal_Panic!-1089-fr.jpg
[2009-07-03 00:42:34 | 01,100,123 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Full_Metal_Panic!-1088-fr.jpg
[2009-07-03 00:35:29 | 00,140,364 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\Full_Metal_Panic_ep01_24_Rahvin_AnimeSubInfo_id16993.zip
[2009-07-03 00:34:15 | 00,000,687 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-07-03 00:16:02 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009-07-03 00:16:02 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-07-02 23:17:03 | 00,002,725 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Condition Zero csmania.eu.exe.lnk
[2009-07-02 22:00:48 | 00,029,696 | ---- | M] () -- C:\WINDOWS\System32\lcb.exe
[2009-07-02 21:39:43 | 00,000,023 | ---- | M] () -- C:\WINDOWS\DownloadStudio.INI
[2009-07-02 21:26:33 | 03,054,220 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\LeechGet_2.1_2009.exe
[2009-07-02 20:55:59 | 02,695,444 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\LeechGet2.1.exe
[2009-07-02 20:53:39 | 04,060,312 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\GetGoSetup.exe
[2009-07-02 20:52:33 | 00,000,033 | ---- | M] () -- C:\WINDOWS\DownloadStudioScheduleMonitor.INI
[2009-07-02 20:41:06 | 26,019,088 | ---- | M] (Macrovision Corporation) -- C:\Documents and Settings\XP\Pulpit\downloadstudio-setup.exe
[2009-07-02 20:39:47 | 03,224,463 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\fgf173.exe
[2009-07-02 20:33:16 | 02,129,325 | ---- | M] ( ) -- C:\Documents and Settings\XP\Pulpit\freshdow.exe
[2009-07-01 20:06:09 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-07-01 14:52:53 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-07-01 02:00:44 | 00,315,973 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\Panstwowa Inspekcja Pracy.jpg
[2009-06-30 08:37:06 | 00,402,833 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Tokkô-2460-fr.jpg
[2009-06-30 08:36:58 | 00,900,167 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Tokkô-2466-fr.jpg
[2009-06-30 08:36:35 | 00,929,855 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Tokkô-2465-en.jpg
[2009-06-30 08:36:11 | 00,323,837 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Tokkô-2459-en.jpg
[2009-06-29 15:40:39 | 07,855,890 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\P53_S36_PIKUJ_300dpi.jpg zwinin.jpg
[2009-06-29 03:32:27 | 00,005,808 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\_gg__Code_Geass_-_Picture_Book_22.25__E776C879_.mkv
[2009-06-28 00:07:14 | 00,045,903 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\grill-12.jpg
[2009-06-27 20:56:01 | 00,001,672 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\ReGet Deluxe.lnk
[2009-06-27 20:55:58 | 00,000,065 | ---- | M] () -- C:\WINDOWS\english.lng
[2009-06-27 20:07:22 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009-06-27 18:26:47 | 03,042,087 | R--- | M] () -- C:\Documents and Settings\XP\Pulpit\ComboFix.exe
[2009-06-26 20:30:34 | 00,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2009-06-26 19:11:20 | 00,000,211 | ---- | M] () -- C:\Boot.bak
[2009-06-26 14:07:20 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-06-26 00:42:29 | 00,019,968 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\s131.xls
[2009-06-25 18:30:45 | 00,000,162 | ---- | M] () -- C:\Documents and Settings\XP\Moje dokumenty\flash.lst
[2009-06-24 18:32:41 | 00,114,230 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\FGXL_SPOL_(www.programs.pl).exe
[2009-06-22 18:25:13 | 00,000,267 | ---- | M] () -- C:\WINDOWS\wcx_ftp.ini
[2009-06-22 12:45:14 | 06,833,525 | ---- | M] (CCCP Project ) -- C:\Documents and Settings\XP\Pulpit\Combined-Community-Codec-Pack-2008-09-21.exe
[2009-06-22 12:06:55 | 25,265,044 | ---- | M] (Aegisub Team ) -- C:\Documents and Settings\XP\Pulpit\aegisub-r2494-setup.exe
[2009-06-21 11:00:20 | 09,437,208 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\dap91.exe
[2009-06-21 10:28:44 | 00,210,049 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\aegikc4.jpg
[2009-06-20 18:59:59 | 00,400,405 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\tydzien.mp3
[2009-06-20 04:44:54 | 00,002,513 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\Microsoft Office Word 2007.lnk
[2009-06-18 23:10:31 | 01,739,720 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\444.jpg
[2009-06-18 23:10:03 | 01,678,298 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\299.jpg
[2009-06-18 23:09:24 | 01,246,400 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\179.jpg
[2009-06-17 11:27:56 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-06-17 11:27:44 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009-06-16 03:39:02 | 02,107,710 | -H-- | M] () -- C:\Documents and Settings\XP\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-06-14 22:39:41 | 00,015,962 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\Baśń.docx
[2009-06-12 00:33:10 | 00,961,525 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Kenshin-1936-en.jpg
[2009-06-12 00:33:03 | 01,008,087 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Kenshin-2036-fr.jpg
[2009-06-12 00:32:58 | 00,972,010 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Kenshin-2034-fr.jpg
[2009-06-12 00:32:52 | 01,278,036 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\www.animecoversfan.com-Kenshin-2033-fr.jpg
[2009-06-11 21:58:46 | 00,159,430 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\Zakladki 2009-06-11.json
[2009-06-10 11:10:17 | 00,003,380 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-06-10 10:53:07 | 00,000,937 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\Skrót do NeroStartSmart.lnk
[2009-06-08 15:13:49 | 00,000,067 | ---- | M] () -- C:\WINDOWS\IDMan.INI
[2009-06-08 11:19:43 | 00,000,766 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\VirtualDubMod.lnk
[2009-06-08 08:10:10 | 00,155,136 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009-06-07 07:36:32 | 00,000,659 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\Gadu-Gadu.lnk
[2009-06-07 02:05:45 | 00,451,696 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2009-06-07 02:05:45 | 00,395,336 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-06-07 02:05:45 | 00,075,706 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2009-06-07 02:05:45 | 00,059,576 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-06-07 02:05:44 | 00,993,526 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-06-06 19:46:20 | 00,001,557 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\mkvmerge GUI.lnk
[2009-06-05 16:55:16 | 00,000,104 | ---- | M] () -- C:\Documents and Settings\XP\Moje dokumenty\Internet.lnk
[2009-06-05 16:17:09 | 00,000,788 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\Skrót do IDMan.lnk
[2009-06-05 16:11:09 | 00,046,695 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\lista.ef2
[2009-06-04 20:52:35 | 00,000,348 | ---- | M] () -- C:\Documents and Settings\XP\Pulpit\Moje dokumenty.lnk
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 4 bytes -> C:\WINDOWS\win.ini:s1
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:A9662AE0
< End of report >
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:35:37, on 2009-07-03
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVGLS\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVGLS\avgnsx.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\totalcmd\TOTALCMD.EXE
c:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101687&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: SrchHook Class - {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\PROGRA~1\DAP\SBSearch.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVGLS\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: IeMonitorBho Class - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (file missing)
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl Class - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVGLS\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: FreshDownload - {793519b5-cad5-479f-94f2-8c8e833dc589} - C:\Program Files\FreshDevices\FreshDownload\fd.exe (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} (F-Secure Online Scanner 4.0 Launcher) - http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVGLS\avgpp.dll
O23 - Service: AVG LinkScanner® WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVGLS\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 4998 bytes
- Kod: Zaznacz wszystko
na http://www.dragonball.toya.net.pl/combo.txt zamieściłem log z ComboFixa tutaj się niestety nie mieścił..
dodam także że prubowałem przerzucić czy tam podmienić plik explorer.exe komendą expand X:\i386\explorer.ex_ C:\Windows gdzie X to mój napęd robiłem to w cmd w konsoli odzyskiwania nic nie znajdowało:/ w cmd pokazało się coś takiego...
Microsoft Windows XP [Wersja 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\XP>c:\windows\explorer.exe
C:\Documents and Settings\XP>expand D:\i386\explorer.ex_ C:\Windows
Narz©dzie rozwijania plik˘w Microsoft (R) wersja 5.1.2600.0
Copyright (C) Microsoft Corp 1990-1999. Wszelkie prawa zastrzeľone.
Rozszerzanie d:\i386\explorer.ex_ do c:\windows\explorer.ex_.
d:\i386\explorer.ex_: rozszerzono bajt˘w: 344143 do 1005568, przyrost o 192%.
nie wiem czy tak miało być ale dalej nie działa;] przywracanie systemu nie skutkuje zmieniałem także nazwę explorera na inną i próbowałem odpalać ale nie działało;]