Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112
Problem z antimalware 2010 • programosy.pl

  • Ogłoszenie:

Problem z antimalware 2010

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Problem z antimalware 2010

Postprzez qrminator 11 Kwi 2010, 22:47

reklama
Witam, koleżanka ma problem z kompem, ma na kompie antimalware 2010
log z otl:
Kod: Zaznacz wszystko
OTL logfile created on: 10-04-11 22:40:20 - Run 2
OTL by OldTimer - Version 3.2.1.1     Folder = D:\
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yy-MM-dd

1,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 81,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 97,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 16,84 Gb Total Space | 3,32 Gb Free Space | 19,73% Space Free | Partition Type: FAT32
Drive D: | 39,07 Gb Total Space | 26,82 Gb Free Space | 68,66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KOMPUTER
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2010-04-11 22:02:17 | 000,561,664 | ---- | M] (OldTimer Tools) -- D:\OTL.exe
PRC - [2010-03-09 12:24:10 | 002,769,336 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010-03-09 12:24:08 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010-01-15 14:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2008-06-27 03:36:58 | 001,424,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


[color=#E56717]========== Modules (SafeList) ==========[/color]

MOD - [2010-04-11 22:02:17 | 000,561,664 | ---- | M] (OldTimer Tools) -- D:\OTL.exe


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - File not found [On_Demand | Stopped] --  -- (CiSvc)
SRV - File not found [On_Demand | Stopped] --  -- (ALG)
SRV - [2010-03-09 12:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010-03-09 12:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010-03-09 12:24:08 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Start_Pending] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010-01-15 14:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2006-03-03 21:03:10 | 000,069,632 | ---- | M] (HP) [Unknown | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2005-08-02 23:18:50 | 000,086,016 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2010-03-09 12:12:54 | 000,046,672 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010-03-09 12:12:34 | 000,162,640 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)
DRV - [2010-03-09 12:09:08 | 000,023,376 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010-03-09 12:08:42 | 000,100,432 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010-03-09 12:08:30 | 000,019,024 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010-03-09 12:08:16 | 000,028,880 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009-09-29 08:11:22 | 000,012,160 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lgbtport.sys -- (LgBttPort)
DRV - [2009-09-29 08:11:20 | 000,012,928 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lgvmodem.sys -- (LGVMODEM)
DRV - [2009-09-29 08:11:20 | 000,010,496 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lgbtbus.sys -- (lgbusenum)
DRV - [2009-08-03 21:25:46 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008-06-16 01:28:36 | 000,077,312 | ---- | M] (VIA Technologies inc,.ltd) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\viasraid.sys -- (viasraid)
DRV - [2008-06-16 01:28:36 | 000,062,208 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\si3112.sys -- (Si3112)
DRV - [2006-07-13 03:33:14 | 000,040,064 | R--- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ESD7SK.sys -- (ESDCR)
DRV - [2006-07-13 03:33:06 | 000,061,568 | R--- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\EMS7SK.sys -- (EMSCR)
DRV - [2006-06-23 10:54:06 | 000,180,608 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8187.sys -- (RTLWUSB)
DRV - [2006-04-13 07:09:56 | 000,204,160 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vinyl97.sys -- (VIAudio) Vinyl AC'97 Audio Controller (WDM)
DRV - [2006-04-05 10:40:36 | 000,962,304 | R--- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smserial.sys -- (smserial)
DRV - [2006-02-23 04:39:06 | 000,011,264 | R--- | M] (VIA Technologies,Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\xfilt.sys -- (xfilt)
DRV - [2006-02-23 04:38:32 | 000,009,728 | R--- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\videX32.sys -- (videX32)
DRV - [2005-07-28 11:13:14 | 000,190,592 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.startup.homepage: "http://cinema-city.pl/index.php?module=movie&action=repertoire&dd=2010-02-10"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2008-12-09 21:44:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2008-12-09 21:44:18 | 000,000,000 | ---D | M]

[2008-12-09 21:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\Mozilla\Extensions
[2008-12-09 21:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\7ud14oj2.default\extensions
[2009-12-13 12:15:38 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\7ud14oj2.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008-12-09 21:44:18 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009-08-24 21:19:14 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2009-08-24 21:19:14 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2009-08-24 21:19:14 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2009-08-24 21:19:14 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2009-08-24 21:19:14 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2009-08-24 21:19:14 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2008-06-16 01:28:36 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 153.19.64.1 153.19.250.100
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-12-09 19:51:38 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2010-04-11 22:34:22 | 000,000,000 | -HSD | C] -- C:\FOUND.003
[2010-04-11 22:19:57 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2010-04-11 22:19:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2010-04-11 22:19:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2010-04-11 22:19:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2010-04-11 22:19:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2010-04-11 22:19:53 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2010-04-11 22:10:40 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010-04-11 22:09:53 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010-04-11 22:09:53 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010-04-11 22:09:53 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010-04-11 22:09:53 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010-04-11 22:09:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010-04-11 22:07:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\User\Recent
[2010-04-11 22:07:12 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010-04-11 22:07:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010-04-09 23:37:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\avG
[2010-04-09 23:37:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\avG
[2010-04-09 15:53:22 | 000,162,640 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010-04-09 15:53:22 | 000,019,024 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010-04-09 15:53:21 | 000,023,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010-04-09 15:53:20 | 000,046,672 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010-04-09 15:53:17 | 000,100,432 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010-04-09 15:53:17 | 000,094,800 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010-04-09 15:53:16 | 000,028,880 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010-04-09 15:53:02 | 000,153,184 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010-04-09 15:53:02 | 000,038,848 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\avastSS.scr
[2010-04-09 15:52:58 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010-04-09 15:52:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software
[2010-04-01 09:56:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\obrazki
[2010-03-31 19:36:50 | 000,000,000 | ---D | C] -- C:\FOUND.002
[2010-03-29 13:40:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\urodzinowo
[2010-03-28 14:14:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\zdj
[2010-03-28 10:20:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\McAfee
[2010-03-25 22:08:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Moje dokumenty\LG Electronics
[2010-03-25 12:39:25 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010-03-25 12:38:12 | 001,164,728 | ---- | C] (NuMedia Soft, Inc.) -- C:\WINDOWS\System32\NMSDVDXU.dll
[2010-03-25 12:38:12 | 000,419,240 | ---- | C] (VideoSoft) -- C:\WINDOWS\System32\Vsflex7L.ocx
[2010-03-25 12:38:11 | 000,630,784 | ---- | C] (ComponentOne) -- C:\WINDOWS\System32\vsflex8u.ocx
[2010-03-25 12:38:11 | 000,244,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Msflxgrd.ocx
[2010-03-25 12:38:06 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\User\Dane aplikacji\{D94BA408-F110-488B-A65E-3AE7945F79E6}
[2010-03-25 12:38:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Dane aplikacji\LG Electronics
[2010-03-25 12:36:55 | 000,000,000 | ---D | C] -- C:\Program Files\LG Electronics
[2010-03-24 12:37:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\McAfee Security Scan
[2010-03-24 12:37:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\McAfee
[2010-03-24 12:37:20 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan
[2010-03-23 11:33:11 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2010-03-16 09:27:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Pulpit\stare
[2008-12-09 19:51:08 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft
[2008-12-09 19:51:08 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft
[2008-12-09 19:27:38 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji\Microsoft
[2008-12-09 19:27:38 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Microsoft
[2006-02-19 03:28:56 | 000,012,288 | ---- | C] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\Fonts\RandFont.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2010-04-11 22:40:36 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010-04-11 22:39:56 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-04-11 22:37:56 | 000,000,350 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\OTL.exe.lnk
[2010-04-11 22:15:14 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010-04-11 22:10:44 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010-04-11 22:07:28 | 003,932,160 | -H-- | M] () -- C:\Documents and Settings\User\NTUSER.DAT
[2010-04-11 22:07:26 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\User\ntuser.ini
[2010-04-11 21:27:04 | 000,000,637 | ---- | M] () -- C:\WINDOWS\win.ini
[2010-04-11 21:27:04 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010-04-11 21:13:12 | 000,000,408 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\fix.reg
[2010-04-11 20:51:14 | 000,011,694 | -HS- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\1ND8Ib1
[2010-04-11 20:51:14 | 000,011,694 | -HS- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\1ND8Ib1
[2010-04-11 09:01:58 | 000,335,360 | -HS- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\277379380.dll
[2010-04-10 13:54:04 | 000,011,750 | -HS- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\2154574951
[2010-04-10 13:54:04 | 000,011,750 | -HS- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\2154574951
[2010-04-09 15:53:24 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\avast! Free Antivirus.lnk
[2010-04-09 15:53:20 | 000,002,645 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010-04-08 17:38:50 | 000,002,184 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-04-06 20:13:34 | 000,059,585 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\02ec5d4edb.jpeg
[2010-04-06 19:05:46 | 000,332,597 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\rozklady.docx
[2010-04-06 15:46:36 | 000,070,144 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\praca z historii filozofii (Sokrates).doc
[2010-04-06 15:45:56 | 002,643,243 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\skanuj0077.jpg
[2010-04-03 16:38:52 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010-03-31 14:03:34 | 000,011,781 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\Agnieszka Kończalska.docx
[2010-03-29 07:28:12 | 000,270,984 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-03-28 14:28:30 | 000,034,304 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-03-28 10:20:16 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk
[2010-03-27 13:31:38 | 000,011,623 | ---- | M] () -- C:\Documents and Settings\User\Moje dokumenty\bio.docx
[2010-03-25 22:14:04 | 006,390,788 | -H-- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2010-03-25 22:05:42 | 000,542,262 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\Ania.JPG
[2010-03-25 12:38:24 | 000,000,811 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\LG PC Suite III.lnk
[2010-03-22 07:36:42 | 001,942,992 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\SSA45794.JPG
[2010-03-22 07:36:24 | 001,983,979 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\SSA45793.JPG
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2010-04-11 22:37:37 | 000,000,350 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\OTL.exe.lnk
[2010-04-11 22:10:43 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010-04-11 22:10:41 | 000,262,400 | ---- | C] () -- C:\cmldr
[2010-04-11 22:09:53 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010-04-11 22:09:53 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010-04-11 22:09:53 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010-04-11 22:09:53 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010-04-11 22:09:53 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010-04-11 20:52:40 | 000,000,408 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\fix.reg
[2010-04-09 23:51:20 | 000,011,750 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\2154574951
[2010-04-09 23:44:10 | 000,335,360 | -HS- | C] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\277379380.dll
[2010-04-09 23:36:47 | 000,011,750 | -HS- | C] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\2154574951
[2010-04-09 23:18:16 | 000,011,694 | -HS- | C] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\1ND8Ib1
[2010-04-09 23:18:16 | 000,011,694 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\1ND8Ib1
[2010-04-09 15:53:23 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\avast! Free Antivirus.lnk
[2010-04-06 20:13:33 | 000,059,585 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\02ec5d4edb.jpeg
[2010-04-06 19:05:44 | 000,332,597 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\rozklady.docx
[2010-04-06 15:46:35 | 000,070,144 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\praca z historii filozofii (Sokrates).doc
[2010-04-06 15:45:53 | 002,643,243 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\skanuj0077.jpg
[2010-03-31 14:03:32 | 000,011,781 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\Agnieszka Kończalska.docx
[2010-03-27 13:31:35 | 000,011,623 | ---- | C] () -- C:\Documents and Settings\User\Moje dokumenty\bio.docx
[2010-03-25 22:05:40 | 000,542,262 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\Ania.JPG
[2010-03-25 12:38:23 | 000,000,811 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\LG PC Suite III.lnk
[2010-03-24 13:37:20 | 000,001,611 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk
[2010-03-22 07:36:40 | 001,942,992 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\SSA45794.JPG
[2010-03-22 07:36:24 | 001,983,979 | ---- | C] () -- C:\Documents and Settings\User\Pulpit\SSA45793.JPG
[2009-12-20 11:36:49 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\KMVIDC32.DLL
[2009-08-03 21:25:45 | 000,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009-06-14 09:58:39 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2009-02-23 11:46:06 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2009-02-06 18:33:17 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009-02-06 18:33:07 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009-02-06 18:33:07 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009-02-06 18:33:06 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009-02-06 18:32:58 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009-02-06 18:32:58 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009-01-27 11:55:55 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\PUTTY.RND
[2009-01-15 12:53:20 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\fusioncache.dat
[2008-12-16 20:57:36 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2008-12-16 20:54:00 | 000,000,749 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log
[2008-12-12 09:48:58 | 000,000,095 | ---- | C] () -- C:\Documents and Settings\User\default.pls
[2008-12-12 09:47:03 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-12-12 09:46:59 | 000,034,304 | ---- | C] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008-12-11 13:36:51 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\User\.rnd
[2008-12-09 21:49:37 | 003,932,160 | -H-- | C] () -- C:\Documents and Settings\User\NTUSER.DAT
[2008-12-09 21:14:35 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2008-12-09 21:10:34 | 000,356,352 | R--- | C] () -- C:\WINDOWS\EMCRI.dll
[2008-12-09 20:49:38 | 000,024,576 | -H-- | C] () -- C:\Documents and Settings\User\ntuser.dat.LOG
[2008-12-09 20:49:38 | 000,000,188 | -HS- | C] () -- C:\Documents and Settings\User\ntuser.ini
[2008-07-03 21:54:20 | 000,000,818 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005-08-02 23:24:01 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2001-07-07 03:00:02 | 000,003,234 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI
< End of report >
Awatar użytkownika
qrminator
~user
 
Posty: 945
Dołączenie: 23 Cze 2005, 09:33
Pochwały: 38



Problem z antimalware 2010

Postprzez Mikou@j 11 Kwi 2010, 23:22

Przeczytaj obowiazkowe-zasady-wstawiania-logow-wazne-vt117887.html
Słowo problem nic nie mówi, opis problemu wiele.
Brak loga extras i loga z gmera.

Autor postu otrzymał pochwałę
ASUS TUF Gaming FX505DT R5-3550H/16GB || XBOX ONE + LG 43UJ6307 || Nintendo Switch ||
Image
"Nothing is true, everything is permitted"
NIE POMAGAM NA PW :!:
Awatar użytkownika
Mikou@j
»ekspert
»ekspert
 
Posty: 12734
Dołączenie: 03 Sty 2006, 21:48
Miejscowość: Katowice
Pochwały: 1007



Problem z antimalware 2010

Postprzez qrminator 11 Kwi 2010, 23:29

komp ogólnie zawiesza się cokolwiek bym nie zrobił, czasem uda się na moment odpalić internet, explorer wiesza się przy pierwszej próbie wejścia na dysk albo zmiany folderu. nie działa menedżer zadań.
chodzi o to, że ten log udało mi się wygenerować zanim komp się zawiesił..
gmera raczej nie uda mi się odpalić.. otla odpaliłem jakimś cudem, przy następnym uruchomieniu zniknął z dysku
Awatar użytkownika
qrminator
~user
 
Posty: 945
Dołączenie: 23 Cze 2005, 09:33
Pochwały: 38



Problem z antimalware 2010

Postprzez lamar 12 Kwi 2010, 07:46

Gmera nie da się odpalić, ponieważ jest aktywny plik sptd.sys + program emulujący
DRV - [2009-08-03 21:25:46 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)


programy-emulujace-napedy-wazne-vt117886.html

Autor postu otrzymał pochwałę
Intel Core i5 3450 + Zalman Flex || MSI B75A-G43 || Goodram 2x4GB 1333MHz || ASUS HD7870 DirectCU II || WD5000AAKX || SB X-Fi XtremeMusic || XFX Core 550W || Corsair Carbide 300R || Samsung SyncMaster T200.

Nie pomagam na PW!!
Awatar użytkownika
lamar
~user
 
Posty: 1916
Dołączenie: 03 Mar 2010, 20:19
Miejscowość: Rzeszów
Pochwały: 228



Problem z antimalware 2010

Postprzez wojtas 12 Kwi 2010, 09:21

Uruchom OTL i w oknie Custom Scans/Fixes wklej :

:OTL

:Files
C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\1ND8Ib1
C:\Documents and Settings\All Users\Dane aplikacji\1ND8Ib1
C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\277379380.dll
C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\2154574951
C:\Documents and Settings\All Users\Dane aplikacji\2154574951

:Commands
[emptytemp]

Kliknij w Run Fix. I potwierdź reset kompa .

Następnie uruchamiasz OTL z opcją Run Scan. Pokazujesz nowy log OTL.txt oraz raport z czyszczenia komputera + log z Gmera i widzę że odpalany był Combofix, proszę pokazać z niego raport....


___________________________________________________________________________________________

SRV - File not found [On_Demand | Stopped] -- -- (CiSvc)
SRV - File not found [On_Demand | Stopped] -- -- (ALG)


czy to jest modyfikowany system ?

Autor postu otrzymał pochwałę
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Problem z antimalware 2010

Postprzez qrminator 12 Kwi 2010, 14:53

To był windows mx 7 jeśli chodzi o modyfikację.
Problem sam ustąpił, mianowicie w pewnym momencie zaczął działać mededżer i przestał się wieszać..
Nie jestem w stanie określić co go przywróciło do życia bo w sumie nic wtedy konkretnego nie robiłem..
Co do logów kontrolnych to koleżanka pilnie potrzebowała laptopa z powrotem więc nie mam możliwości wygenerowania.
Gdyby problem jakimś cudem powrócił to się odezwę.
Dzięki.
Awatar użytkownika
qrminator
~user
 
Posty: 945
Dołączenie: 23 Cze 2005, 09:33
Pochwały: 38




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 27 gości