Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112
Log z otl - heur.suspicious@22523103 • programosy.pl

  • Ogłoszenie:

Log z otl - heur.suspicious@22523103

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Log z otl - heur.suspicious@22523103

Postprzez JA30 09 Wrz 2009, 09:22

reklama
Witam ponownie,mam raport z wczoraj, dziś po skanowaniu COMODO wyskoczyło że mam to Heur.Suspicious@22523103, być może że ten log już nieaktualny, jeśli tak zrobię drugi.Proszę o wskazówki z czego jeszcze wkleić. :ok:

Dodano Dzisiaj, 09:24:
Kod: Zaznacz wszystko
[code][/code]OTL logfile created on: 2009-09-08 15:15:31 - Run 1
OTL by OldTimer - Version 3.0.10.7     Folder = C:\Users\aga\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1,99 Gb Total Physical Memory | 1,17 Gb Available Physical Memory | 58,72% Memory free
4,00 Gb Paging File | 3,36 Gb Available in Paging File | 83,97% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 149,05 Gb Total Space | 124,40 Gb Free Space | 83,47% Space Free | Partition Type: NTFS
Drive D: | 498,72 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 10,50 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: MOJKOMPUTER
Current User Name: aga
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2008-10-29 08:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2008-01-21 04:33:00 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008-02-13 07:52:10 | 04,915,200 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2009-02-26 13:57:20 | 00,141,848 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxtray.exe
PRC - [2009-02-26 13:57:12 | 00,173,592 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hkcmd.exe
PRC - [2009-02-26 13:57:16 | 00,150,552 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpers.exe
PRC - [2008-01-21 04:32:56 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2009-02-06 16:51:30 | 09,302,632 | ---- | M] (GG Network S.A.) -- C:\Program Files\Nowe Gadu-Gadu\gg.exe
PRC - [2007-06-27 20:03:40 | 00,152,872 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2008-01-21 04:34:48 | 00,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WUDFHost.exe
PRC - [2007-06-27 20:04:00 | 00,279,848 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
PRC - [2007-06-27 20:04:00 | 01,213,736 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2009-02-26 13:57:18 | 00,252,952 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.exe
PRC - [2009-02-06 16:13:32 | 00,014,336 | ---- | M] () -- C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
PRC - [2007-05-29 14:43:50 | 00,917,504 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Program Files\Huawei technologies\Mobile Connect\Mobile Connect.exe
PRC - [2009-04-24 11:54:23 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-09-08 15:13:04 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Users\aga\Downloads\OTL.exe

[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2008-07-27 20:03:13 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008-01-21 04:33:18 | 01,013,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running])
SRV - [2008-06-20 03:14:44 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008-06-20 03:14:31 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008-06-20 03:14:31 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007-06-27 20:04:00 | 00,279,848 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Running])
SRV - File not found --  -- (Norton Internet Security [Auto | Stopped])
SRV - [2007-08-24 04:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007-10-18 12:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
SRV - [2008-01-21 04:33:00 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
SRV - [2007-10-25 16:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
SRV - [2008-01-21 04:35:20 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2008-01-21 04:32:46 | 00,422,968 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx [Disabled | Stopped])
DRV - [2008-01-21 04:32:51 | 00,300,600 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci [Disabled | Stopped])
DRV - [2008-01-21 04:32:52 | 00,101,432 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m [Disabled | Stopped])
DRV - [2008-01-21 04:32:53 | 00,149,560 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320 [Disabled | Stopped])
DRV - [2006-11-02 11:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx [Disabled | Stopped])
DRV - [2008-01-21 04:32:21 | 00,017,464 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\system32\drivers\aliide.sys -- (aliide [Disabled | Stopped])
DRV - [2008-01-21 04:32:49 | 00,079,416 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arc.sys -- (arc [Disabled | Stopped])
DRV - [2008-01-21 04:32:50 | 00,079,928 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas [Disabled | Stopped])
DRV - [2006-11-02 10:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo [On_Demand | Stopped])
DRV - [2006-11-02 10:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp [On_Demand | Stopped])
DRV - [2006-11-02 10:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserid.sys -- (Brserid [Disabled | Stopped])
DRV - [2006-11-02 10:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm [Disabled | Stopped])
DRV - [2006-11-02 10:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm [Disabled | Stopped])
DRV - [2006-11-02 10:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer [On_Demand | Stopped])
DRV - [2008-01-21 04:32:21 | 00,019,000 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide [Disabled | Stopped])
DRV - [2008-01-21 04:32:50 | 00,118,784 | ---- | M] (Intel Corporation) -- C:\Windows\System32\DRIVERS\E1G60I32.sys -- (E1G60 [On_Demand | Stopped])
DRV - [2008-01-21 04:32:48 | 00,342,584 | ---- | M] (Emulex) -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor [Disabled | Stopped])
DRV - [2009-09-08 11:01:02 | 00,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\Windows\gdrv.sys -- (gdrv [On_Demand | Stopped])
DRV - [2008-01-21 04:32:52 | 00,040,504 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs [Disabled | Stopped])
DRV - [2007-04-20 10:44:10 | 00,101,376 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\DRIVERS\ewusbmdm.sys -- (hwdatacard [On_Demand | Running])
DRV - [2008-01-21 04:32:49 | 00,235,064 | ---- | M] (Intel Corporation) -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV [Disabled | Stopped])
DRV - [2009-02-26 13:39:50 | 04,569,088 | ---- | M] (Intel Corporation) -- C:\Windows\System32\DRIVERS\igdkmd32.sys -- (igfx [On_Demand | Running])
DRV - [2006-11-02 11:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp [Disabled | Stopped])
DRV - [2008-02-14 11:03:10 | 02,061,528 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2006-11-02 11:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi [Disabled | Stopped])
DRV - [2006-11-02 11:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid [Disabled | Stopped])
DRV - [2008-01-21 04:32:49 | 00,096,312 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])
DRV - [2008-01-21 04:32:51 | 00,089,656 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])
DRV - [2008-01-21 04:32:48 | 00,096,312 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])
DRV - [2008-01-21 04:32:53 | 00,031,288 | ---- | M] (LSI Corporation) -- C:\Windows\system32\drivers\megasas.sys -- (megasas [Disabled | Stopped])
DRV - [2008-01-21 04:32:52 | 00,386,616 | ---- | M] (LSI Corporation, Inc.) -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR [Disabled | Stopped])
DRV - [2006-11-02 11:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x [Disabled | Stopped])
DRV - [2006-11-02 11:50:19 | 00,045,160 | ---- | M] (IBM Corporation) -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960 [Disabled | Stopped])
DRV - [2006-11-02 09:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi [Disabled | Stopped])
DRV - [2008-01-21 04:32:47 | 00,102,968 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid [Disabled | Stopped])
DRV - [2008-01-21 04:32:47 | 00,045,112 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor [Disabled | Stopped])
DRV - [2008-01-21 04:32:50 | 01,122,360 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300 [Disabled | Stopped])
DRV - [2006-11-02 11:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx [Disabled | Stopped])
DRV - [2008-05-02 13:59:40 | 00,122,368 | ---- | M] (Realtek Corporation                                            ) -- C:\Windows\System32\DRIVERS\Rtlh86.sys -- (RTL8169 [On_Demand | Running])
DRV - [2006-11-02 08:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv [Auto | Running])
DRV - [2008-01-21 04:32:52 | 00,074,808 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])
DRV - [2006-11-02 11:50:05 | 00,035,944 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx [Disabled | Stopped])
DRV - [2006-11-02 11:49:56 | 00,031,848 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi [Disabled | Stopped])
DRV - [2006-11-02 11:50:03 | 00,034,920 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3 [Disabled | Stopped])
DRV - [2008-01-21 04:32:45 | 00,238,648 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci [Disabled | Stopped])
DRV - [2006-11-02 11:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata [Disabled | Stopped])
DRV - [2008-01-21 04:32:49 | 00,115,816 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2 [Disabled | Stopped])
DRV - [2008-01-21 04:32:21 | 00,020,024 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\system32\drivers\viaide.sys -- (viaide [Disabled | Stopped])
DRV - [2008-01-21 04:32:49 | 00,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid [Disabled | Stopped])

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.startup.homepage: "www.google.pl"
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-03-18 13:48:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-09-07 22:11:17 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-08 13:50:41 | 00,000,000 | ---D | M]

[2009-09-07 22:19:18 | 00,000,000 | ---D | M] -- C:\Users\aga\AppData\Roaming\mozilla\Extensions
[2009-09-07 22:19:18 | 00,000,000 | ---D | M] -- C:\Users\aga\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-09-08 14:08:57 | 00,000,000 | ---D | M] -- C:\Users\aga\AppData\Roaming\mozilla\Firefox\Profiles\fuv3k4ro.default\extensions
[2009-09-07 22:11:15 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-09-07 22:11:15 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-04-24 11:54:25 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-04-24 11:54:25 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-04-24 11:54:25 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006-06-03 18:43:22 | 00,000,896 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2008-04-03 19:19:08 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2008-04-16 06:08:20 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2007-03-31 19:11:54 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2006-06-03 18:43:22 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2008-03-28 23:36:04 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2007-01-05 13:40:56 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1             localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Pomocnik rejestracji usługi Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\Skytel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [Nowe Gadu-Gadu] C:\Program Files\Nowe Gadu-Gadu\gg.exe (GG Network S.A.)
O4 - HKCU..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe (Franmo Software)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O9 - Extra Button: Wpis w blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Wpis w blogu w Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter:  - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 23:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2007-05-19 13:36:22 | 00,102,400 | R--- | M] (Huawei Technologies Co., Ltd.) - I:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2006-12-01 12:50:24 | 00,000,046 | R--- | M] () - I:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{0c13be17-9c70-11de-9303-001fd00959a8}\Shell\AutoRun\command - "" = J:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe -- File not found
O33 - MountPoints2\{0c13be17-9c70-11de-9303-001fd00959a8}\Shell\open\command - "" = J:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe -- File not found
O33 - MountPoints2\{cc4b6691-9bd8-11de-a4cb-001fd00959a8}\Shell - "" = AutoRun
O33 - MountPoints2\{cc4b6691-9bd8-11de-a4cb-001fd00959a8}\Shell\AutoRun\command - "" = I:\AutoRun.exe -- [2007-05-19 13:36:22 | 00,102,400 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{cc4b66aa-9bd8-11de-a4cb-001fd00959a8}\Shell - "" = AutoRun
O33 - MountPoints2\{cc4b66aa-9bd8-11de-a4cb-001fd00959a8}\Shell\AutoRun\command - "" = I:\AutoRun.exe -- [2007-05-19 13:36:22 | 00,102,400 | R--- | M] (Huawei Technologies Co., Ltd.)
O34 - HKLM BootExecute: (autocheck) -  File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) -  File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2009-09-08 14:42:32 | 00,000,828 | ---- | C] () -- C:\Users\aga\Desktop\PhotoScape.lnk
[2009-09-08 14:42:22 | 00,000,000 | ---D | C] -- C:\Program Files\PhotoScape
[2009-09-08 14:41:30 | 00,000,824 | ---- | C] () -- C:\Users\aga\Desktop\Odkurzacz.lnk
[2009-09-08 14:41:30 | 00,000,820 | ---- | C] () -- C:\Users\aga\Desktop\Szybkie Czyszczenie Dysku.lnk
[2009-09-08 14:41:25 | 00,000,000 | ---D | C] -- C:\Program Files\Odkurzacz
[2009-09-08 14:11:09 | 00,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2009-09-08 14:00:23 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009-09-08 13:56:01 | 00,000,000 | ---- | C] () -- C:\tmp.xml
[2009-09-08 13:51:35 | 00,000,000 | ---D | C] -- C:\ProgramData\Nokia
[2009-09-08 13:44:21 | 00,091,136 | ---- | C] (Nokia) -- C:\Windows\System32\nmwcdcls.dll
[2009-09-08 13:44:06 | 00,001,995 | ---- | C] () -- C:\Users\Public\Desktop\Nokia Software Updater.lnk
[2009-09-08 13:44:01 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Nokia
[2009-09-08 13:44:00 | 00,000,000 | ---D | C] -- C:\Program Files\Nokia
[2009-09-08 13:43:34 | 00,000,000 | ---D | C] -- C:\ProgramData\Installations
[2009-09-08 13:42:36 | 00,000,000 | ---D | C] -- C:\Users\aga\Desktop\My Downloads
[2009-09-08 13:41:47 | 00,000,371 | ---- | C] () -- C:\Users\aga\Desktop\Dokumenty — skrót.lnk
[2009-09-08 13:35:49 | 00,005,992 | ---- | C] () -- C:\Users\aga\Documents\list motywacyjny.sxw
[2009-09-08 13:24:09 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Roaming\Ahead
[2009-09-08 10:57:05 | 00,000,553 | R--- | C] () -- C:\Windows\USetup.iss
[2009-09-08 10:53:06 | 01,826,816 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SkyTel.exe
[2009-09-08 10:53:05 | 01,191,936 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlUpd.exe
[2009-09-08 10:53:05 | 00,638,976 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll
[2009-09-08 10:53:05 | 00,167,936 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll
[2009-09-08 10:53:04 | 00,285,216 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkApoApi.dll
[2009-09-08 10:52:59 | 04,915,200 | ---- | C] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
[2009-09-08 10:52:59 | 00,532,480 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl
[2009-09-08 10:52:58 | 02,061,528 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RTKVHDA.sys
[2009-09-08 10:52:54 | 00,319,488 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\HideWin.exe
[2009-09-08 10:07:32 | 00,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2009-09-08 10:07:31 | 00,016,608 | ---- | C] (Windows (R) 2000 DDK provider) -- C:\Windows\gdrv.sys
[2009-09-08 09:44:46 | 00,000,000 | ---D | C] -- C:\Users\Public\Documents\Symantec
[2009-09-08 09:24:15 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Local\Ahead
[2009-09-08 09:12:42 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Roaming\Symantec
[2009-09-08 09:05:23 | 00,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2009-09-08 09:05:19 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2009-09-08 09:03:41 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Local\Adobe
[2009-09-07 22:29:02 | 00,000,907 | ---- | C] () -- C:\Users\aga\Desktop\EVEREST Home Edition.lnk
[2009-09-07 22:29:01 | 00,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2009-09-07 22:27:43 | 00,000,786 | ---- | C] () -- C:\Users\aga\Desktop\Napi-projekt.lnk
[2009-09-07 22:27:43 | 00,000,762 | ---- | C] () -- C:\Users\aga\Desktop\ALLPlayer V3.5.lnk
[2009-09-07 22:27:41 | 00,000,000 | ---D | C] -- C:\Program Files\NAPI-PROJEKT
[2009-09-07 22:27:38 | 00,000,000 | ---D | C] -- C:\Program Files\ALLPlayer
[2009-09-07 22:23:38 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Roaming\Macromedia
[2009-09-07 22:23:38 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Roaming\Adobe
[2009-09-07 22:23:36 | 00,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2009-09-07 22:19:13 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Local\Mozilla
[2009-09-07 22:19:12 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Roaming\Mozilla
[2009-09-07 22:12:53 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Roaming\Nowe Gadu-Gadu
[2009-09-07 22:12:46 | 00,000,810 | ---- | C] () -- C:\Users\Public\Desktop\Nowe Gadu-Gadu.lnk
[2009-09-07 22:12:35 | 00,000,000 | ---D | C] -- C:\Program Files\Nowe Gadu-Gadu
[2009-09-07 22:11:18 | 00,001,724 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009-09-07 22:11:12 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2009-09-07 21:56:38 | 00,000,000 | ---D | C] -- C:\Windows\Minidump
[2009-09-07 21:56:04 | 15,461,4531 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2009-09-07 21:04:06 | 00,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2009-09-07 21:04:06 | 00,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab
[2009-09-07 20:55:26 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Local\MigWiz
[2009-09-07 20:51:30 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
[2009-09-07 20:41:05 | 01,128,665 | -H-- | C] () -- C:\Users\aga\AppData\Local\IconCache.db
[2009-09-07 20:35:46 | 00,101,376 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbmdm.sys
[2009-09-07 20:35:46 | 00,023,424 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\Windows\System32\drivers\ewdcsc.sys
[2009-09-07 20:34:37 | 00,002,010 | ---- | C] () -- C:\Users\Public\Desktop\Mobile Connect.lnk
[2009-09-07 20:34:33 | 00,000,000 | ---D | C] -- C:\Program Files\Huawei technologies
[2009-09-07 20:30:58 | 00,099,864 | ---- | C] () -- C:\Users\aga\AppData\Local\GDIPFONTCACHEV1.DAT
[2009-09-07 20:30:08 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Roaming\Identities
[2009-09-07 20:30:05 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Local\VirtualStore
[2009-09-07 20:28:16 | 00,000,000 | --SD | C] -- C:\Users\aga\AppData\Roaming\Microsoft
[2009-09-07 20:28:16 | 00,000,000 | -HSD | C] -- C:\Users\aga\Documents\Moje wideo
[2009-09-07 20:28:16 | 00,000,000 | -HSD | C] -- C:\Users\aga\Documents\Moje obrazy
[2009-09-07 20:28:16 | 00,000,000 | -HSD | C] -- C:\Users\aga\Documents\Moja muzyka
[2009-09-07 20:28:16 | 00,000,000 | -HSD | C] -- C:\Users\aga\AppData\Local\Temporary Internet Files
[2009-09-07 20:28:16 | 00,000,000 | -HSD | C] -- C:\Users\aga\AppData\Local\Historia
[2009-09-07 20:28:16 | 00,000,000 | -HSD | C] -- C:\Users\aga\AppData\Local\Dane aplikacji
[2009-09-07 20:28:16 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Local\Temp
[2009-09-07 20:28:16 | 00,000,000 | ---D | C] -- C:\Users\aga\AppData\Local\Microsoft
[2009-03-18 11:44:43 | 00,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll
[2006-11-02 12:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\win.ini
[2006-11-02 12:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006-11-02 09:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2009-09-08 15:02:00 | 00,000,270 | ---- | M] () -- C:\Windows\tasks\Sprawdź aktualizacje paska narzędzi Windows Live Toolbar.job
[2009-09-08 14:42:42 | 01,468,980 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009-09-08 14:42:42 | 00,661,818 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2009-09-08 14:42:42 | 00,586,980 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009-09-08 14:42:42 | 00,126,702 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2009-09-08 14:42:42 | 00,101,052 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009-09-08 14:42:32 | 00,000,828 | ---- | M] () -- C:\Users\aga\Desktop\PhotoScape.lnk
[2009-09-08 14:41:30 | 00,000,824 | ---- | M] () -- C:\Users\aga\Desktop\Odkurzacz.lnk
[2009-09-08 14:41:30 | 00,000,820 | ---- | M] () -- C:\Users\aga\Desktop\Szybkie Czyszczenie Dysku.lnk
[2009-09-08 14:37:55 | 00,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009-09-08 14:37:55 | 00,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009-09-08 14:37:32 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009-09-08 14:37:29 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009-09-08 14:37:27 | 21,343,80544 | -HS- | M] () -- C:\hiberfil.sys
[2009-09-08 14:36:44 | 01,128,665 | -H-- | M] () -- C:\Users\aga\AppData\Local\IconCache.db
[2009-09-08 13:56:01 | 00,000,000 | ---- | M] () -- C:\tmp.xml
[2009-09-08 13:44:06 | 00,001,995 | ---- | M] () -- C:\Users\Public\Desktop\Nokia Software Updater.lnk
[2009-09-08 13:41:47 | 00,000,371 | ---- | M] () -- C:\Users\aga\Desktop\Dokumenty — skrót.lnk
[2009-09-08 11:01:08 | 00,000,010 | ---- | M] () -- C:\Windows\GSetup.ini
[2009-09-08 11:01:02 | 00,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\Windows\gdrv.sys
[2009-09-08 10:53:09 | 00,319,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\DIFxAPI.dll
[2009-09-08 10:52:54 | 00,319,488 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\HideWin.exe
[2009-09-07 22:29:02 | 00,000,907 | ---- | M] () -- C:\Users\aga\Desktop\EVEREST Home Edition.lnk
[2009-09-07 22:27:43 | 00,000,786 | ---- | M] () -- C:\Users\aga\Desktop\Napi-projekt.lnk
[2009-09-07 22:27:43 | 00,000,762 | ---- | M] () -- C:\Users\aga\Desktop\ALLPlayer V3.5.lnk
[2009-09-07 22:12:46 | 00,000,810 | ---- | M] () -- C:\Users\Public\Desktop\Nowe Gadu-Gadu.lnk
[2009-09-07 22:11:18 | 00,001,724 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009-09-07 21:56:38 | 15,461,4531 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2009-09-07 20:34:37 | 00,002,010 | ---- | M] () -- C:\Users\Public\Desktop\Mobile Connect.lnk
[2009-09-07 20:30:58 | 00,099,864 | ---- | M] () -- C:\Users\aga\AppData\Local\GDIPFONTCACHEV1.DAT
[2009-09-07 20:15:15 | 00,067,891 | ---- | M] () -- C:\Windows\System32\license.rtf

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >[code][/code]
jeżeli czujesz się świetnie- nie przejmuj się przejdzie Ci ;-)
Awatar użytkownika
JA30
~user
 
Posty: 35
Dołączenie: 06 Wrz 2009, 17:57
Miejscowość: raz TU raz TAM



Log z otl - heur.suspicious@22523103

Postprzez Andziorka 09 Wrz 2009, 12:01

W okienko OTL wklejasz poniższe i Run Fix:

:Processes
explorer.exe

:OTL
SRV - File not found -- -- (Norton Internet Security [Auto | Stopped])
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O13 - gopher Prefix: missing
O32 - AutoRun File - [2006-12-01 12:50:24 | 00,000,046 | R--- | M] () - I:\AUTORUN.INF -- [ CDFS O33 - MountPoints2\{0c13be17-9c70-11de-9303-001fd00959a8}\Shell\AutoRun\command - "" = J:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe -- File not found
O33 - MountPoints2\{0c13be17-9c70-11de-9303-001fd00959a8}\Shell\open\command - "" = J:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe -- File not found
O33 - MountPoints2\{cc4b6691-9bd8-11de-a4cb-001fd00959a8}\Shell - "" = AutoRun
O33 - MountPoints2\{cc4b6691-9bd8-11de-a4cb-001fd00959a8}\Shell\AutoRun\command - "" I:\AutoRun.exe -- [2007-05-19 13:36:22 | 00,102,400 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{cc4b66aa-9bd8-11de-a4cb-001fd00959a8}\Shell - "" = AutoRun
O33 - MountPoints2\{cc4b66aa-9bd8-11de-a4cb-001fd00959a8}\Shell\AutoRun\command - "" = I:\AutoRun.exe -- [2007-05-19 13:36:22 | 00,102,400 | R--- | M] (Huawei Technologies Co., Ltd.)


:Commands
[emptytemp]
[start explorer]
[Reboot]


Następnie musisz usunąć klucz: MountPoints2.
Wejdź w: Start>>>Uruchom>>> wpisz: regedit
poszukaj klucza: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Explorer\MountPoints2
Usuwasz MountPoints2
Mamy łańcuchy w głowach, nie na tętnicach.
Awatar użytkownika
Andziorka
~user
 
Posty: 584
Dołączenie: 07 Wrz 2009, 22:01
Pochwały: 71



Log z otl - heur.suspicious@22523103

Postprzez JA30 09 Wrz 2009, 16:00

nie mam takiego klucza,w explorer tego tam nie ma.

Dodano Dzisiaj, 16:03:
mam teraz na pulpicie dwa ustawienia konfig.mogę je usunąć do kosza? czy gdzies przenieść,gdy próbuje usunąc to wyskakuje komun.ze jak usunę do kosza to syst, lub program może przestać działać poprawnie. sciana
jeżeli czujesz się świetnie- nie przejmuj się przejdzie Ci ;-)
Awatar użytkownika
JA30
~user
 
Posty: 35
Dołączenie: 06 Wrz 2009, 17:57
Miejscowość: raz TU raz TAM



Log z otl - heur.suspicious@22523103

Postprzez Andziorka 09 Wrz 2009, 16:36

Kod: Zaznacz wszystko
mam teraz na pulpicie dwa ustawienia konfig.mogę je usunąć do kosza?

co masz?

w jakim explorer?
wejdz tu: poszukaj klucza: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
i usuwasz MountPoints2
Mamy łańcuchy w głowach, nie na tętnicach.
Awatar użytkownika
Andziorka
~user
 
Posty: 584
Dołączenie: 07 Wrz 2009, 22:01
Pochwały: 71



Log z otl - heur.suspicious@22523103

Postprzez JA30 09 Wrz 2009, 17:15

rozumiem ze to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2, jest w edytorze rejestru, a napis MountPoints2 po napisie explorer, jezeli tak to własnie takiego napisu po explorer nie mam w rejestrze.

Dodano Dzisiaj, 17:17:
na pulpicie mam dwie ikonki "deskop ini" i jak chce je przeniesc lub usunąć to wyskakuje mi napis ze jesli to zrobie to system windows lub program moga przestac działać poprawnie i nie wiem co z tym zrobić jak to usunąc z pulpitu i czy smiało moge.
jeżeli czujesz się świetnie- nie przejmuj się przejdzie Ci ;-)
Awatar użytkownika
JA30
~user
 
Posty: 35
Dołączenie: 06 Wrz 2009, 17:57
Miejscowość: raz TU raz TAM



Log z otl - heur.suspicious@22523103

Postprzez Okocza 09 Wrz 2009, 17:19

otwórz notatnik i wklej:

Kod: Zaznacz wszystko
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Explorer\MountPoints2]


zapisujesz jako fix.reg i odpalasz - dodajesz do rejestru.
eMachines E730G - Core i5-430M, 2GiB RAM, ATI Mobility Radeon HD5470, WD 320GiB; Cort Z-44,DR 0.09-0.42, Peavey Backstage
Mac OS X 10.7.4 Lion // Windows 7 Professional x64 // NIE POMAGAM NA PW/GG/E-MAIL
Image
"Moje Ego i Anima spotykają się i wymieniają przepisami na ciasteczka" - Maynard James Keenan
Awatar użytkownika
Okocza
~user
 
Posty: 8001
Dołączenie: 19 Mar 2006, 11:53
Pochwały: 406



Log z otl - heur.suspicious@22523103

Postprzez JA30 09 Wrz 2009, 17:19

a te ikonki to po run fix w OTL się pojawiły.

Dodano Dzisiaj, 17:28:
jesli zrobię tak: "zapisujesz jako fix.reg i odpalasz - dodajesz do rejestru.' to mam poszukać tego klucza i usunąć ten napis MountpPints2, czy mam po prostu juz tak zostawić ?
jeżeli czujesz się świetnie- nie przejmuj się przejdzie Ci ;-)
Awatar użytkownika
JA30
~user
 
Posty: 35
Dołączenie: 06 Wrz 2009, 17:57
Miejscowość: raz TU raz TAM



Log z otl - heur.suspicious@22523103

Postprzez Andziorka 09 Wrz 2009, 18:06

zostawić już.
wejdź w dysk C, narzędzia, opcje folderów, widok, zaznacz: nie pokazuj ukrytych plików i folderów
Mamy łańcuchy w głowach, nie na tętnicach.
Awatar użytkownika
Andziorka
~user
 
Posty: 584
Dołączenie: 07 Wrz 2009, 22:01
Pochwały: 71



Log z otl - heur.suspicious@22523103

Postprzez JA30 09 Wrz 2009, 18:21

nie wiem gdzie są te narzędzia w viscie na C sciana POMOCY!
jeżeli czujesz się świetnie- nie przejmuj się przejdzie Ci ;-)
Awatar użytkownika
JA30
~user
 
Posty: 35
Dołączenie: 06 Wrz 2009, 17:57
Miejscowość: raz TU raz TAM



Log z otl - heur.suspicious@22523103

Postprzez Andziorka 09 Wrz 2009, 18:23

na górze, trzeba rozwinąć je, w pasku
Mamy łańcuchy w głowach, nie na tętnicach.
Awatar użytkownika
Andziorka
~user
 
Posty: 584
Dołączenie: 07 Wrz 2009, 22:01
Pochwały: 71



Log z otl - heur.suspicious@22523103

Postprzez JA30 09 Wrz 2009, 18:32

ok już mam dzięki WIELKIE :)
jeżeli czujesz się świetnie- nie przejmuj się przejdzie Ci ;-)
Awatar użytkownika
JA30
~user
 
Posty: 35
Dołączenie: 06 Wrz 2009, 17:57
Miejscowość: raz TU raz TAM




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 5 gości