• Ogłoszenie:

Rosyjskie okienko

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Rosyjskie okienko

Postprzez Corran 28 Paź 2009, 22:41

reklama
Witam,

nie cala godzine temu na laptopie wyswietlilo mi sie okienko po rosyjsku. Wirus wyłaczyl mi dostep do menedzera zadan oraz karte sieciowa do tego siedzi non stop na wierzchu. Niestety nic z rosyjskiego nie lapie jest tam cos o "uFast Download Manager" i dalej okienko do wklepywania kodow. Co mam wyrzucic?

Log
Kod: Zaznacz wszystko
OTL logfile created on: 2009-10-28 21:30:53 - Run 1
OTL by OldTimer - Version 3.0.22.1     Folder = H:\
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1,24 Gb Total Physical Memory | 0,82 Gb Available Physical Memory | 66,02% Memory free
1,60 Gb Paging File | 1,27 Gb Available in Paging File | 79,58% Paging File free
Paging file location(s): C:\pagefile.sys 512 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9,77 Gb Total Space | 1,42 Gb Free Space | 14,53% Space Free | Partition Type: NTFS
Drive D: | 27,49 Gb Total Space | 4,75 Gb Free Space | 17,29% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 484,98 Mb Total Space | 484,27 Mb Free Space | 99,85% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: ANIA
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2009-10-28 21:27:46 | 00,521,728 | ---- | M] (OldTimer Tools) -- H:\OTL.exe
PRC - [2009-10-27 23:15:00 | 00,096,256 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\uFast Download Manager\PropetyuFastManager.exe
PRC - [2009-10-27 23:15:00 | 00,058,877 | ---- | M] () -- C:\WINDOWS\System32\restorer32_a.exe
PRC - [2009-07-14 10:19:40 | 10,707,560 | ---- | M] (GG Network S.A.) -- C:\Program Files\Nowe Gadu-Gadu\gg.exe
PRC - [2009-07-14 09:15:16 | 00,077,824 | ---- | M] () -- C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
PRC - [2009-02-06 17:39:29 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2008-10-15 13:31:53 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
PRC - [2008-10-15 13:30:02 | 00,151,297 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
PRC - [2007-07-12 03:00:36 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
PRC - [2007-03-06 09:35:02 | 00,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
PRC - [2006-10-27 00:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2005-10-25 05:56:00 | 00,061,440 | R--- | M] (Vimicro) -- C:\WINDOWS\VM303_STI.EXE
PRC - [2005-06-21 10:51:38 | 00,081,920 | ---- | M] () -- C:\Program Files\Launch Manager\Wbutton.exe
PRC - [2005-06-06 13:18:38 | 00,241,664 | ---- | M] () -- C:\Program Files\Launch Manager\OSDCtrl.exe
PRC - [2005-06-06 10:52:10 | 00,069,632 | ---- | M] (Wistron) -- C:\Program Files\Launch Manager\HotkeyApp.exe
PRC - [2005-05-03 23:04:28 | 09,150,464 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
PRC - [2005-04-15 10:01:46 | 00,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2005-03-30 14:29:48 | 00,032,768 | ---- | M] () -- C:\Program Files\Launch Manager\LaunchAp.exe
PRC - [2005-02-04 10:12:58 | 00,102,490 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2005-02-04 10:11:48 | 00,708,698 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2005-01-23 09:36:10 | 00,155,648 | R--- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxtray.exe
PRC - [2005-01-23 09:31:34 | 00,126,976 | R--- | M] (Intel Corporation) -- C:\WINDOWS\System32\hkcmd.exe
PRC - [2004-09-22 21:57:44 | 01,571,840 | ---- | M] (ASUSTeK COMPUTER INC.) -- C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
PRC - [2004-08-11 00:45:04 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe
PRC - [2004-08-04 00:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.exe
PRC - [2003-06-19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2002-08-30 14:02:48 | 00,094,208 | ---- | M] () -- C:\Program Files\Launch Manager\PowerKey.exe

[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - File not found --  -- (MkS_Scan [On_Demand | Stopped])
SRV - [2009-03-12 08:55:54 | 00,137,200 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008-10-15 13:31:53 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe -- (AntiVirScheduler [Auto | Running])
SRV - [2008-10-15 13:30:02 | 00,151,297 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe -- (AntiVirService [Auto | Running])
SRV - [2008-07-29 20:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008-07-29 18:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008-07-29 18:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008-07-25 10:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008-07-25 10:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007-12-10 13:59:04 | 00,353,280 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [On_Demand | Stopped])
SRV - [2007-03-06 09:35:02 | 00,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service [Auto | Running])
SRV - [2006-10-27 00:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2006-10-26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006-10-26 13:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2005-05-03 23:04:28 | 09,150,464 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe -- (MSSQL$PINNACLESYS [Auto | Running])
SRV - [2005-05-03 21:50:28 | 00,073,728 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe -- (MSSQLServerADHelper [On_Demand | Stopped])
SRV - [2005-05-03 20:42:56 | 00,323,584 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE -- (SQLAgent$PINNACLESYS [On_Demand | Stopped])
SRV - [2005-04-03 23:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2004-08-11 00:45:04 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])
SRV - [2004-08-04 00:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2003-06-19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2009-05-30 15:29:29 | 00,075,096 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\avipbb.sys -- (avipbb [System | Running])
DRV - [2009-05-30 15:28:43 | 00,052,056 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys -- (avgntflt [On_Demand | Running])
DRV - [2009-05-30 15:28:39 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys -- (avgio [System | Running])
DRV - [2008-11-20 20:19:06 | 00,043,872 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2008-07-10 14:29:52 | 00,101,376 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys -- (hwdatacard [On_Demand | Stopped])
DRV - [2007-12-11 16:52:18 | 00,639,224 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2007-08-27 18:19:14 | 00,015,781 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\System32\DRIVERS\mdc8021x.sys -- (MDC8021X [Auto | Running])
DRV - [2007-03-01 09:34:22 | 00,028,352 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running])
DRV - [2007-02-22 10:15:56 | 00,137,216 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcd.sys -- (nmwcd [On_Demand | Stopped])
DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdcm.sys -- (nmwcdcm [On_Demand | Stopped])
DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdcj.sys -- (nmwcdcj [On_Demand | Stopped])
DRV - [2007-02-22 10:15:14 | 00,008,320 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdc.sys -- (nmwcdc [On_Demand | Stopped])
DRV - [2005-10-27 07:34:06 | 00,390,849 | R--- | M] (Vimicro Corporation) -- C:\WINDOWS\System32\Drivers\usbVM303.sys -- (ZSMC303 [On_Demand | Stopped])
DRV - [2005-06-02 18:28:38 | 00,171,008 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\System32\DRIVERS\MarvinBus.sys -- (MarvinBus [On_Demand | Running])
DRV - [2005-04-19 09:40:52 | 02,317,504 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
DRV - [2005-02-09 11:59:00 | 00,014,165 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\System32\drivers\pclepci.sys -- (PCLEPCI [System | Running])
DRV - [2005-02-04 09:59:46 | 00,193,216 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\System32\DRIVERS\SynTP.sys -- (SynTP [On_Demand | Running])
DRV - [2005-01-23 10:05:06 | 00,804,317 | R--- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys -- (ialm [On_Demand | Running])
DRV - [2004-12-15 14:18:34 | 00,207,232 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSFHWICH.sys -- (HSFHWICH [On_Demand | Running])
DRV - [2004-12-15 14:18:28 | 00,703,232 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys -- (winachsf [On_Demand | Running])
DRV - [2004-12-15 14:18:26 | 01,038,208 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSF_DP.sys -- (HSF_DP [On_Demand | Running])
DRV - [2004-08-03 23:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Stopped])
DRV - [2004-07-29 15:29:58 | 00,211,072 | ---- | M] (Ralink Technology Inc.) -- C:\WINDOWS\System32\DRIVERS\RT2500.sys -- (RT2500 [On_Demand | Stopped])
DRV - [2004-07-17 11:36:38 | 00,027,440 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2004-04-16 13:57:58 | 00,010,368 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\System32\drivers\pfc.sys -- (pfc [On_Demand | Running])
DRV - [2004-03-17 10:04:14 | 00,013,059 | ---- | M] (Conexant) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys -- (mdmxsdk [Auto | Running])
DRV - [2003-04-28 10:27:06 | 00,009,867 | ---- | M] () -- C:\WINDOWS\System32\drivers\HOTKEY.sys -- (Hotkey [System | Running])
DRV - [2002-09-09 18:54:06 | 00,016,269 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\ASNDIS5.SYS -- (ASNDIS5 [On_Demand | Running])
DRV - [2001-08-17 22:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Stopped])
DRV - [2001-08-17 21:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
DRV - [2000-12-19 17:29:52 | 00,002,343 | ---- | M] () -- C:\Program Files\Launch Manager\POWERKEY.sys -- (POWERKEY [On_Demand | Running])

[color=#E56717]========== Modules (SafeList) ==========[/color]

MOD - [2009-10-28 21:27:46 | 00,521,728 | ---- | M] (OldTimer Tools) -- H:\OTL.exe
MOD - [2005-02-04 10:12:50 | 00,069,722 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\System32\SynTPFcs.dll
MOD - [2004-08-04 00:42:34 | 01,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.pl/ig?hl=pl"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {C20C76E7-E8F7-4109-8498-CF3B2CA4E570}:3.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.6
FF - prefs.js..extensions.enabledItems: zabij@sledzia.net:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-09-01 13:42:18 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-10-13 11:07:53 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-18 18:23:53 | 00,000,000 | ---D | M]

[2008-08-30 16:19:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Extensions
[2008-08-30 16:19:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-10-27 11:17:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions
[2009-09-01 16:10:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009-09-09 21:51:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2008-06-24 07:20:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\{6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89}
[2008-11-17 19:25:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\{C20C76E7-E8F7-4109-8498-CF3B2CA4E570}
[2008-12-18 06:49:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-09-26 10:37:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\zabij@sledzia.net
[2008-02-12 13:45:20 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\FireFox\Profiles\ceprbuxq.default\searchplugins\wikipedia-polski.xml
[2009-05-23 16:51:00 | 00,001,972 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\FireFox\Profiles\ceprbuxq.default\searchplugins\wrzuta.xml
[2009-10-25 23:01:29 | 00,002,431 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\FireFox\Profiles\ceprbuxq.default\searchplugins\youtube---videos.xml
[2009-10-27 11:17:02 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-09-18 18:23:53 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007-08-29 21:05:42 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2009-09-18 18:23:47 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-09-18 18:23:47 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-09-18 18:23:48 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006-10-26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2009-07-28 06:40:24 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2008-09-30 15:41:23 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2008-09-30 15:41:23 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008-09-30 15:41:23 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2008-09-30 15:41:23 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2008-09-30 15:41:23 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2008-09-30 15:41:23 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: (152 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
O1 - Hosts: 94.232.248.66 antivguardian.com
O1 - Hosts: 94.232.248.66 www.antivguardian.com
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\user\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE (Vimicro)
O4 - HKLM..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe (ASUSTeK COMPUTER INC.)
O4 - HKLM..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe (Wistron)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
O4 - HKLM..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe ()
O4 - HKLM..\Run: [PowerKey] C:\Program Files\Launch Manager\PowerKey.exe ()
O4 - HKLM..\Run: [Regedit32] C:\WINDOWS\System32\regedit.exe File not found
O4 - HKLM..\Run: [restorer32_a] C:\WINDOWS\System32\restorer32_a.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [sysgif32] C:\WINDOWS\Temp\wpv931255703227.exe File not found
O4 - HKLM..\Run: [Wbutton] C:\Program Files\Launch Manager\Wbutton.exe ()
O4 - HKCU..\Run: [Nowe Gadu-Gadu] C:\Program Files\Nowe Gadu-Gadu\gg.exe (GG Network S.A.)
O4 - HKCU..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe (Franmo Software)
O4 - HKCU..\Run: [restorer32_a] C:\Documents and Settings\user\restorer32_a.exe File not found
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\zavupd32.exe (PokerStars)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {266BB960-7DA8-11D4-A849-00008321B7D9} http://amadeusvista.com/vwp/common/cabs/VistaPWComms.CAB (Amadeus Cmd Page Cross Communication)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {3D518D7D-422F-4787-AC71-10BB552E897B} http://amadeusvista.com/vwp/common/cabs/SP2Patch.CAB (Amadeus_SP2_Patcher Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {EBE01DF7-D451-11D5-A842-000102A97CAB} http://amadeusvista.com/vwp/common/cabs/AmadeusInit.CAB (AmadeusInit.Init)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (rundll32.exe) -  File not found
O20 - HKLM Winlogon: Shell - (pqrs.tmo) - C:\WINDOWS\System32\pqrs.tmo ()
O20 - HKLM Winlogon: Shell - (printer) -  File not found
O20 - HKLM Winlogon: UserInit - (C:\DOCUME~1\user\DANEAP~1\UFASTD~1\PROPET~1.EXE) - C:\Documents and Settings\user\Dane aplikacji\uFast Download Manager\PropetyuFastManager.exe ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-09-18 20:05:21 | 00,000,067 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{09a11d54-a29d-11de-88d8-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{09a11d54-a29d-11de-88d8-000ae4edb0a7}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- File not found
O33 - MountPoints2\{2774707e-ae07-11dc-8848-000ae4edb0a7}\Shell\Auto\command - "" = G:\activexdebugger32.exe -- File not found
O33 - MountPoints2\{2774707e-ae07-11dc-8848-000ae4edb0a7}\Shell\explore\Command - "" = G:\activexdebugger32.exe -- File not found
O33 - MountPoints2\{2774707e-ae07-11dc-8848-000ae4edb0a7}\Shell\open\Command - "" = G:\activexdebugger32.exe -- File not found
O33 - MountPoints2\{3ac4f4cf-c4d0-11dc-8859-0018f3f85f55}\Shell\Auto\command - "" = Windows.scr
O33 - MountPoints2\{4093c1df-a9ee-11dd-8882-afbd987038c8}\Shell - "" = AutoRun
O33 - MountPoints2\{4484a396-9b1d-11de-88d0-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{4484a396-9b1d-11de-88d0-000ae4edb0a7}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- File not found
O33 - MountPoints2\{4484a397-9b1d-11de-88d0-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{4484a397-9b1d-11de-88d0-000ae4edb0a7}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- File not found
O33 - MountPoints2\{52cfea13-9e14-11dd-887f-0018f3f85f55}\Shell - "" = AutoRun
O33 - MountPoints2\{52cfea13-9e14-11dd-887f-0018f3f85f55}\Shell\AutoRun\command - "" = C:\WINDOWS\explorer.exe -- [2004-08-04 00:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\{6181b903-54bb-11dc-87f9-000ae4edb0a7}\Shell\AutoRun\command - "" = G:\USBNB.exe -- File not found
O33 - MountPoints2\{6de7762e-9b1c-11de-88cf-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{6de7762e-9b1c-11de-88cf-000ae4edb0a7}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- File not found
O33 - MountPoints2\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\Shell\AutoRun\command - "" = G:\iqe68o.bat -- File not found
O33 - MountPoints2\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\Shell\explore\Command - "" = G:\iqe68o.bat -- File not found
O33 - MountPoints2\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\Shell\open\Command - "" = G:\iqe68o.bat -- File not found
O33 - MountPoints2\{c6afa104-9bd1-11de-88d1-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{c6afa104-9bd1-11de-88d1-000ae4edb0a7}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- File not found
O33 - MountPoints2\{c6afa105-9bd1-11de-88d1-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{c6afa105-9bd1-11de-88d1-000ae4edb0a7}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck) -  File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) -  File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2009-10-27 23:15:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Dane aplikacji\uFast Download Manager
[2009-10-27 23:14:59 | 00,000,000 | ---D | C] -- C:\Program Files\uFast Download Manager
[2009-10-28 21:00:14 | 00,000,000 | ---D | C] -- C:\!KillBox
[2009-10-28 21:00:11 | 00,059,392 | ---- | C] (Option^Explicit Software                        vbtechcd@gmail.com) -- C:\Documents and Settings\user\Pulpit\KillBox.exe
[2009-10-27 16:33:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\praca magistrska
[2009-10-17 08:07:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Alexandre Desplat - Coco Avant Chanel [2009]
[2009-10-15 08:22:04 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009-10-12 20:59:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\chorwacja

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[1 C:\WINDOWS\System32\*.tmp files]
[2009-10-28 21:30:02 | 01,181,938 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-10-28 21:30:02 | 00,523,360 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2009-10-28 21:30:02 | 00,463,974 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-10-28 21:30:02 | 00,099,022 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2009-10-28 21:30:02 | 00,080,712 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-10-28 21:29:11 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2009-10-28 21:25:23 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-10-28 21:25:21 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-10-28 21:24:33 | 00,000,573 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-10-28 21:24:33 | 00,000,271 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-10-28 21:24:33 | 00,000,210 | -HS- | M] () -- C:\boot.ini
[2009-10-28 21:17:58 | 03,771,994 | -H-- | M] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-10-28 20:44:44 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-10-27 23:15:00 | 00,058,877 | ---- | M] () -- C:\WINDOWS\System32\restorer32_a.exe
[2009-10-27 23:14:59 | 00,027,136 | ---- | M] () -- C:\WINDOWS\System32\pqrs.tmo
[2009-10-26 22:58:55 | 00,035,308 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\rajd III.JPG
[2009-10-21 23:49:34 | 00,200,192 | ---- | M] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-10-20 12:29:18 | 00,064,512 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\OrganizacjaImprez.doc
[2009-10-18 11:19:31 | 00,025,220 | ---- | M] () -- C:\Documents and Settings\user\Moje dokumenty\tour salon1.pdf
[2009-10-16 23:49:46 | 90,414,709 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\AD-CAC.rar
[2009-10-15 10:34:41 | 00,072,704 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\Geograficzno.doc
[2009-10-15 08:19:59 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-10-11 14:09:54 | 00,027,136 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\v_rok.xls

[color=#E56717]========== Files - No Company Name ==========[/color]
[2009-10-27 23:15:11 | 00,027,136 | ---- | C] () -- C:\WINDOWS\System32\pqrs.tmo
[2009-10-27 23:15:00 | 00,058,877 | ---- | C] () -- C:\WINDOWS\System32\restorer32_a.exe
[2009-10-27 23:14:53 | 00,000,020 | ---- | C] () -- C:\Documents and Settings\user\Dane aplikacji\wiaserva.log
[2009-10-26 22:58:54 | 00,035,308 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\rajd III.JPG
[2009-10-20 12:29:17 | 00,064,512 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\OrganizacjaImprez.doc
[2009-10-18 11:19:31 | 00,025,220 | ---- | C] () -- C:\Documents and Settings\user\Moje dokumenty\tour salon1.pdf
[2009-10-16 23:27:39 | 90,414,709 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\AD-CAC.rar
[2009-10-15 10:34:40 | 00,072,704 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\Geograficzno.doc
[2009-10-11 14:09:53 | 00,027,136 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\v_rok.xls
[2009-04-21 22:30:49 | 00,010,593 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2009-03-01 12:06:34 | 00,000,035 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2009-01-18 20:35:31 | 00,000,055 | ---- | C] () -- C:\WINDOWS\AWF Screensaver.ini
[2008-12-26 11:25:17 | 00,001,870 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008-12-13 18:34:13 | 00,000,167 | ---- | C] () -- C:\WINDOWS\usdthank.ini
[2008-12-13 18:34:12 | 00,000,031 | ---- | C] () -- C:\WINDOWS\idc.ini
[2008-09-18 20:21:24 | 00,000,129 | ---- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\fusioncache.dat
[2008-09-18 20:05:21 | 00,001,196 | ---- | C] () -- C:\WINDOWS\VFO.INI
[2008-04-06 18:33:16 | 00,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS75.DLL
[2007-12-11 16:52:18 | 00,639,224 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007-09-18 19:03:23 | 00,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007-08-29 10:52:31 | 00,200,192 | ---- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007-08-27 18:08:42 | 00,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007-08-27 17:49:41 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007-08-27 17:49:41 | 00,593,920 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007-08-27 17:49:41 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007-08-27 17:49:40 | 00,010,752 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007-08-27 17:49:40 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007-08-27 17:47:24 | 00,009,867 | ---- | C] () -- C:\WINDOWS\System32\drivers\HOTKEY.sys
[2007-08-27 17:45:47 | 00,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007-08-25 14:52:32 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
[2007-08-25 14:01:22 | 03,771,994 | -H-- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2007-08-25 13:59:43 | 00,086,552 | ---- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2007-08-25 13:56:26 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\user\Dane aplikacji\desktop.ini
[2004-07-17 11:36:38 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2002-03-17 01:00:00 | 00,007,420 | ---- | C] () -- C:\WINDOWS\UA000088.DLL
[2001-07-21 23:16:20 | 00,000,573 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-21 23:15:52 | 00,000,271 | ---- | C] () -- C:\WINDOWS\system.ini

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:888AFB86
< End of report >


pzdr
Senatus Populusque Romanus
Awatar użytkownika
Corran
~user
 
Posty: 220
Dołączenie: 09 Mar 2005, 17:02
Miejscowość: Poznań



Rosyjskie okienko

Postprzez wojtas 29 Paź 2009, 09:05

Uruchom OTL i w oknie Custom Scans/Fixes wklej :

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
O1 - Hosts: 94.232.248.66 antivguardian.com
O1 - Hosts: 94.232.248.66 www.antivguardian.com
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [Regedit32] C:\WINDOWS\System32\regedit.exe File not found
O4 - HKLM..\Run: [restorer32_a] C:\WINDOWS\System32\restorer32_a.exe ()
O4 - HKLM..\Run: [sysgif32] C:\WINDOWS\Temp\wpv931255703227.exe File not found
O4 - HKCU..\Run: [restorer32_a] C:\Documents and Settings\user\restorer32_a.exe File not found
O4 - Startup: C:\Documents and Settings\user\Menu Start\Programy\Autostart\zavupd32.exe (PokerStars)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O20 - HKLM Winlogon: Shell - (rundll32.exe) - File not found
O20 - HKLM Winlogon: Shell - (pqrs.tmo) - C:\WINDOWS\System32\pqrs.tmo ()
O20 - HKLM Winlogon: Shell - (printer) - File not found
O20 - HKLM Winlogon: UserInit - (C:\DOCUME~1\user\DANEAP~1\UFASTD~1\PROPET~1.EXE) - C:\Documents and Settings\user\Dane aplikacji\uFast Download Manager\PropetyuFastManager.exe ()
O33 - MountPoints2\{09a11d54-a29d-11de-88d8-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{09a11d54-a29d-11de-88d8-000ae4edb0a7}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- File not found
O33 - MountPoints2\{2774707e-ae07-11dc-8848-000ae4edb0a7}\Shell\Auto\command - "" = G:\activexdebugger32.exe -- File not found
O33 - MountPoints2\{2774707e-ae07-11dc-8848-000ae4edb0a7}\Shell\explore\Command - "" = G:\activexdebugger32.exe -- File not found
O33 - MountPoints2\{2774707e-ae07-11dc-8848-000ae4edb0a7}\Shell\open\Command - "" = G:\activexdebugger32.exe -- File not found
O33 - MountPoints2\{3ac4f4cf-c4d0-11dc-8859-0018f3f85f55}\Shell\Auto\command - "" = Windows.scr
O33 - MountPoints2\{4093c1df-a9ee-11dd-8882-afbd987038c8}\Shell - "" = AutoRun
O33 - MountPoints2\{4484a396-9b1d-11de-88d0-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{4484a396-9b1d-11de-88d0-000ae4edb0a7}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- File not found
O33 - MountPoints2\{4484a397-9b1d-11de-88d0-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{4484a397-9b1d-11de-88d0-000ae4edb0a7}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- File not found
O33 - MountPoints2\{52cfea13-9e14-11dd-887f-0018f3f85f55}\Shell - "" = AutoRun
O33 - MountPoints2\{52cfea13-9e14-11dd-887f-0018f3f85f55}\Shell\AutoRun\command - "" = C:\WINDOWS\explorer.exe -- [2004-08-04 00:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation)
O33 - MountPoints2\{6181b903-54bb-11dc-87f9-000ae4edb0a7}\Shell\AutoRun\command - "" = G:\USBNB.exe -- File not found
O33 - MountPoints2\{6de7762e-9b1c-11de-88cf-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{6de7762e-9b1c-11de-88cf-000ae4edb0a7}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- File not found
O33 - MountPoints2\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\Shell\AutoRun\command - "" = G:\iqe68o.bat -- File not found
O33 - MountPoints2\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\Shell\explore\Command - "" = G:\iqe68o.bat -- File not found
O33 - MountPoints2\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\Shell\open\Command - "" = G:\iqe68o.bat -- File not found
O33 - MountPoints2\{c6afa104-9bd1-11de-88d1-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{c6afa104-9bd1-11de-88d1-000ae4edb0a7}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- File not found
O33 - MountPoints2\{c6afa105-9bd1-11de-88d1-000ae4edb0a7}\Shell - "" = AutoRun
O33 - MountPoints2\{c6afa105-9bd1-11de-88d1-000ae4edb0a7}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- File not found

:Files
C:\Documents and Settings\user\Dane aplikacji\uFast Download Manager
C:\WINDOWS\System32\restorer32_a.exe
C:\Program Files\uFast Download Manager
C:\WINDOWS\System32\pqrs.tmo
C:\Documents and Settings\user\Menu Start\Programy\Autostart\zavupd32.exe

:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db1b3e60-05ac-11de-a5d3-00001cd72a97}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"SuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
"CheckedValue"=dword:00000001
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden]
@=""

:Commands
[emptytemp]
[start explorer]
[Reboot]


Kliknij w Run Fix. I potwierdz reset kompa .

Następnie uruchamiasz OTL z opcją Run Scan. Pokazujesz nowy log OTL.txt oraz raport z czyszczenia kompa

Autor postu otrzymał pochwałę
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Rosyjskie okienko

Postprzez Corran 29 Paź 2009, 20:12

Dziękuje za pomoc, wszystko wyglada dobrze

Raport
Kod: Zaznacz wszystko
All processes killed
========== OTL ==========
Process explorer.exe killed successfully!
94.232.248.66 browser-security.microsoft.com removed from HOSTS file successfully
94.232.248.66 antivguardian.com removed from HOSTS file successfully
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Regedit32 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\restorer32_a deleted successfully.
C:\WINDOWS\System32\restorer32_a.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\sysgif32 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\restorer32_a deleted successfully.
C:\Documents and Settings\user\Menu Start\Programy\Autostart\zavupd32.exe moved successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:rundll32.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:pqrs.tmo deleted successfully.
C:\WINDOWS\System32\pqrs.tmo moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:printer deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\DOCUME~1\user\DANEAP~1\UFASTD~1\PROPET~1.EXE deleted successfully.
C:\Documents and Settings\user\Dane aplikacji\uFast Download Manager\PropetyuFastManager.exe moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09a11d54-a29d-11de-88d8-000ae4edb0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{09a11d54-a29d-11de-88d8-000ae4edb0a7}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09a11d54-a29d-11de-88d8-000ae4edb0a7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{09a11d54-a29d-11de-88d8-000ae4edb0a7}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2774707e-ae07-11dc-8848-000ae4edb0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2774707e-ae07-11dc-8848-000ae4edb0a7}\ not found.
File G:\activexdebugger32.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2774707e-ae07-11dc-8848-000ae4edb0a7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2774707e-ae07-11dc-8848-000ae4edb0a7}\ not found.
File G:\activexdebugger32.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2774707e-ae07-11dc-8848-000ae4edb0a7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2774707e-ae07-11dc-8848-000ae4edb0a7}\ not found.
File G:\activexdebugger32.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ac4f4cf-c4d0-11dc-8859-0018f3f85f55}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3ac4f4cf-c4d0-11dc-8859-0018f3f85f55}\ not found.
File Windows.scr not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4093c1df-a9ee-11dd-8882-afbd987038c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4093c1df-a9ee-11dd-8882-afbd987038c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4484a396-9b1d-11de-88d0-000ae4edb0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4484a396-9b1d-11de-88d0-000ae4edb0a7}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4484a396-9b1d-11de-88d0-000ae4edb0a7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4484a396-9b1d-11de-88d0-000ae4edb0a7}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4484a397-9b1d-11de-88d0-000ae4edb0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4484a397-9b1d-11de-88d0-000ae4edb0a7}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4484a397-9b1d-11de-88d0-000ae4edb0a7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4484a397-9b1d-11de-88d0-000ae4edb0a7}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{52cfea13-9e14-11dd-887f-0018f3f85f55}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52cfea13-9e14-11dd-887f-0018f3f85f55}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{52cfea13-9e14-11dd-887f-0018f3f85f55}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52cfea13-9e14-11dd-887f-0018f3f85f55}\ not found.
Item C:\WINDOWS\explorer.exe is whitelisted and cannot be moved.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6181b903-54bb-11dc-87f9-000ae4edb0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6181b903-54bb-11dc-87f9-000ae4edb0a7}\ not found.
File G:\USBNB.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6de7762e-9b1c-11de-88cf-000ae4edb0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6de7762e-9b1c-11de-88cf-000ae4edb0a7}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6de7762e-9b1c-11de-88cf-000ae4edb0a7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6de7762e-9b1c-11de-88cf-000ae4edb0a7}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\ not found.
File G:\iqe68o.bat not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\ not found.
File G:\iqe68o.bat not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{792f2c3f-cfb0-11dd-8893-0018f3f85f55}\ not found.
File G:\iqe68o.bat not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c6afa104-9bd1-11de-88d1-000ae4edb0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c6afa104-9bd1-11de-88d1-000ae4edb0a7}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c6afa104-9bd1-11de-88d1-000ae4edb0a7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c6afa104-9bd1-11de-88d1-000ae4edb0a7}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c6afa105-9bd1-11de-88d1-000ae4edb0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c6afa105-9bd1-11de-88d1-000ae4edb0a7}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c6afa105-9bd1-11de-88d1-000ae4edb0a7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c6afa105-9bd1-11de-88d1-000ae4edb0a7}\ not found.
File G:\AutoRun.exe not found.
========== FILES ==========
C:\Documents and Settings\user\Dane aplikacji\uFast Download Manager moved successfully.
File\Folder C:\WINDOWS\System32\restorer32_a.exe not found.
C:\Program Files\uFast Download Manager moved successfully.
File\Folder C:\WINDOWS\System32\pqrs.tmo not found.
File\Folder C:\Documents and Settings\user\Menu Start\Programy\Autostart\zavupd32.exe not found.
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db1b3e60-05ac-11de-a5d3-00001cd72a97}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{db1b3e60-05ac-11de-a5d3-00001cd72a97}\ not found.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\\"SuperHidden"|dword:00000001 /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\\"Hidden"|dword:00000001 /E : value set successfully!
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\\"ShowSuperHidden"|dword:00000001 /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\\"CheckedValue"|dword:00000001 /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden\ deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden\\@|"" /E : value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 139907 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: user
File delete failed. C:\Documents and Settings\user\Ustawienia lokalne\Temp\etilqs_rhvMJIuZObllAuTGewvW scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user\Ustawienia lokalne\Temp\Perflib_Perfdata_97c.dat scheduled to be deleted on reboot.
->Temp folder emptied: 536927 bytes
File delete failed. C:\Documents and Settings\user\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 6452989 bytes
->Java cache emptied: 12825618 bytes
File delete failed. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\ceprbuxq.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\ceprbuxq.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\ceprbuxq.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\ceprbuxq.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\ceprbuxq.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
->FireFox cache emptied: 113471515 bytes
->Opera cache emptied: 33465845 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2596 bytes
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4fc.dat scheduled to be deleted on reboot.
Windows Temp folder emptied: 16384 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 159,24 mb


OTL by OldTimer - Version 3.0.22.1 log created on 10292009_185822

Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\user\Ustawienia lokalne\Temp\etilqs_rhvMJIuZObllAuTGewvW not found!
File\Folder C:\Documents and Settings\user\Ustawienia lokalne\Temp\Perflib_Perfdata_97c.dat not found!
C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\ceprbuxq.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\ceprbuxq.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\ceprbuxq.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\ceprbuxq.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\ceprbuxq.default\urlclassifier3.sqlite moved successfully.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_4fc.dat not found!

Registry entries deleted on Reboot...


NOwy log:
Kod: Zaznacz wszystko
OTL logfile created on: 2009-10-29 19:03:35 - Run 2
OTL by OldTimer - Version 3.0.22.1     Folder = C:\Documents and Settings\user\Pulpit
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1,24 Gb Total Physical Memory | 0,80 Gb Available Physical Memory | 64,88% Memory free
1,60 Gb Paging File | 1,26 Gb Available in Paging File | 78,74% Paging File free
Paging file location(s): C:\pagefile.sys 512 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9,77 Gb Total Space | 1,51 Gb Free Space | 15,43% Space Free | Partition Type: NTFS
Drive D: | 27,49 Gb Total Space | 4,75 Gb Free Space | 17,29% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANIA
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2009-10-29 18:57:17 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Pulpit\OTL.exe
PRC - [2009-07-14 10:19:40 | 10,707,560 | ---- | M] (GG Network S.A.) -- C:\Program Files\Nowe Gadu-Gadu\gg.exe
PRC - [2009-07-14 09:15:16 | 00,077,824 | ---- | M] () -- C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
PRC - [2009-02-06 17:39:29 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2008-10-15 13:31:53 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
PRC - [2008-10-15 13:30:02 | 00,151,297 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
PRC - [2008-08-16 16:01:10 | 00,264,704 | ---- | M] (Franmo Software) -- C:\Program Files\Odkurzacz\odk_mcd.exe
PRC - [2007-07-12 03:00:36 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
PRC - [2007-03-06 09:35:02 | 00,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
PRC - [2006-10-27 00:47:42 | 00,031,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2005-10-25 05:56:00 | 00,061,440 | R--- | M] (Vimicro) -- C:\WINDOWS\VM303_STI.EXE
PRC - [2005-06-21 10:51:38 | 00,081,920 | ---- | M] () -- C:\Program Files\Launch Manager\Wbutton.exe
PRC - [2005-06-06 13:18:38 | 00,241,664 | ---- | M] () -- C:\Program Files\Launch Manager\OSDCtrl.exe
PRC - [2005-06-06 10:52:10 | 00,069,632 | ---- | M] (Wistron) -- C:\Program Files\Launch Manager\HotkeyApp.exe
PRC - [2005-05-03 23:04:28 | 09,150,464 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
PRC - [2005-04-15 10:01:46 | 00,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2005-03-30 14:29:48 | 00,032,768 | ---- | M] () -- C:\Program Files\Launch Manager\LaunchAp.exe
PRC - [2005-02-04 10:12:58 | 00,102,490 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2005-02-04 10:11:48 | 00,708,698 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2005-01-23 09:36:10 | 00,155,648 | R--- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxtray.exe
PRC - [2005-01-23 09:31:34 | 00,126,976 | R--- | M] (Intel Corporation) -- C:\WINDOWS\System32\hkcmd.exe
PRC - [2004-09-22 21:57:44 | 01,571,840 | ---- | M] (ASUSTeK COMPUTER INC.) -- C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
PRC - [2004-08-11 00:45:04 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe
PRC - [2004-08-04 00:44:26 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
PRC - [2004-08-04 00:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2003-06-19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2002-08-30 14:02:48 | 00,094,208 | ---- | M] () -- C:\Program Files\Launch Manager\PowerKey.exe

[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - File not found --  -- (MkS_Scan [On_Demand | Stopped])
SRV - [2009-03-12 08:55:54 | 00,137,200 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008-10-15 13:31:53 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe -- (AntiVirScheduler [Auto | Running])
SRV - [2008-10-15 13:30:02 | 00,151,297 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe -- (AntiVirService [Auto | Running])
SRV - [2008-07-29 20:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008-07-29 18:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008-07-29 18:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008-07-25 10:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008-07-25 10:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007-12-10 13:59:04 | 00,353,280 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [On_Demand | Stopped])
SRV - [2007-03-06 09:35:02 | 00,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service [Auto | Running])
SRV - [2006-10-27 00:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2006-10-26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006-10-26 13:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2005-05-03 23:04:28 | 09,150,464 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe -- (MSSQL$PINNACLESYS [Auto | Running])
SRV - [2005-05-03 21:50:28 | 00,073,728 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe -- (MSSQLServerADHelper [On_Demand | Stopped])
SRV - [2005-05-03 20:42:56 | 00,323,584 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE -- (SQLAgent$PINNACLESYS [On_Demand | Stopped])
SRV - [2005-04-03 23:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2004-08-11 00:45:04 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])
SRV - [2004-08-04 00:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2003-06-19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2009-05-30 15:29:29 | 00,075,096 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\avipbb.sys -- (avipbb [System | Running])
DRV - [2009-05-30 15:28:43 | 00,052,056 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys -- (avgntflt [On_Demand | Running])
DRV - [2009-05-30 15:28:39 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys -- (avgio [System | Running])
DRV - [2008-11-20 20:19:06 | 00,043,872 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2008-07-10 14:29:52 | 00,101,376 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys -- (hwdatacard [On_Demand | Stopped])
DRV - [2007-12-11 16:52:18 | 00,639,224 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2007-08-27 18:19:14 | 00,015,781 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\System32\DRIVERS\mdc8021x.sys -- (MDC8021X [Auto | Running])
DRV - [2007-03-01 09:34:22 | 00,028,352 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running])
DRV - [2007-02-22 10:15:56 | 00,137,216 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcd.sys -- (nmwcd [On_Demand | Stopped])
DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdcm.sys -- (nmwcdcm [On_Demand | Stopped])
DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdcj.sys -- (nmwcdcj [On_Demand | Stopped])
DRV - [2007-02-22 10:15:14 | 00,008,320 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdc.sys -- (nmwcdc [On_Demand | Stopped])
DRV - [2005-10-27 07:34:06 | 00,390,849 | R--- | M] (Vimicro Corporation) -- C:\WINDOWS\System32\Drivers\usbVM303.sys -- (ZSMC303 [On_Demand | Stopped])
DRV - [2005-06-02 18:28:38 | 00,171,008 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\System32\DRIVERS\MarvinBus.sys -- (MarvinBus [On_Demand | Running])
DRV - [2005-04-19 09:40:52 | 02,317,504 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
DRV - [2005-02-09 11:59:00 | 00,014,165 | ---- | M] (Pinnacle Systems GmbH) -- C:\WINDOWS\System32\drivers\pclepci.sys -- (PCLEPCI [System | Running])
DRV - [2005-02-04 09:59:46 | 00,193,216 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\System32\DRIVERS\SynTP.sys -- (SynTP [On_Demand | Running])
DRV - [2005-01-23 10:05:06 | 00,804,317 | R--- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys -- (ialm [On_Demand | Running])
DRV - [2004-12-15 14:18:34 | 00,207,232 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSFHWICH.sys -- (HSFHWICH [On_Demand | Running])
DRV - [2004-12-15 14:18:28 | 00,703,232 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys -- (winachsf [On_Demand | Running])
DRV - [2004-12-15 14:18:26 | 01,038,208 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSF_DP.sys -- (HSF_DP [On_Demand | Running])
DRV - [2004-08-03 23:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Running])
DRV - [2004-07-29 15:29:58 | 00,211,072 | ---- | M] (Ralink Technology Inc.) -- C:\WINDOWS\System32\DRIVERS\RT2500.sys -- (RT2500 [On_Demand | Running])
DRV - [2004-07-17 11:36:38 | 00,027,440 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2004-04-16 13:57:58 | 00,010,368 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\System32\drivers\pfc.sys -- (pfc [On_Demand | Running])
DRV - [2004-03-17 10:04:14 | 00,013,059 | ---- | M] (Conexant) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys -- (mdmxsdk [Auto | Running])
DRV - [2003-04-28 10:27:06 | 00,009,867 | ---- | M] () -- C:\WINDOWS\System32\drivers\HOTKEY.sys -- (Hotkey [System | Running])
DRV - [2002-09-09 18:54:06 | 00,016,269 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\ASNDIS5.SYS -- (ASNDIS5 [On_Demand | Running])
DRV - [2001-08-17 22:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Stopped])
DRV - [2001-08-17 21:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
DRV - [2000-12-19 17:29:52 | 00,002,343 | ---- | M] () -- C:\Program Files\Launch Manager\POWERKEY.sys -- (POWERKEY [On_Demand | Running])

[color=#E56717]========== Modules (SafeList) ==========[/color]

MOD - [2009-10-29 18:57:17 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Pulpit\OTL.exe
MOD - [2005-02-04 10:12:50 | 00,069,722 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\System32\SynTPFcs.dll
MOD - [2004-08-04 00:42:34 | 01,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.pl/ig?hl=pl"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {C20C76E7-E8F7-4109-8498-CF3B2CA4E570}:3.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.6
FF - prefs.js..extensions.enabledItems: zabij@sledzia.net:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.15

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-09-01 13:42:18 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-10-29 09:10:19 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-10-29 09:10:17 | 00,000,000 | ---D | M]

[2008-08-30 16:19:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Extensions
[2008-08-30 16:19:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-10-28 22:27:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions
[2009-09-01 16:10:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009-09-09 21:51:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2008-06-24 07:20:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\{6D53ADB7-6AD5-4A59-BFE4-7B57D2F4AA89}
[2008-11-17 19:25:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\{C20C76E7-E8F7-4109-8498-CF3B2CA4E570}
[2008-12-18 06:49:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-09-26 10:37:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\mozilla\Firefox\Profiles\ceprbuxq.default\extensions\zabij@sledzia.net
[2008-02-12 13:45:20 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\FireFox\Profiles\ceprbuxq.default\searchplugins\wikipedia-polski.xml
[2009-05-23 16:51:00 | 00,001,972 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\FireFox\Profiles\ceprbuxq.default\searchplugins\wrzuta.xml
[2009-10-25 23:01:29 | 00,002,431 | ---- | M] () -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\FireFox\Profiles\ceprbuxq.default\searchplugins\youtube---videos.xml
[2009-10-28 22:27:39 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-10-29 09:10:17 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007-08-29 21:05:42 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2009-10-29 09:10:10 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-10-29 09:10:10 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-10-29 09:10:11 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006-10-26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2009-07-28 06:40:24 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2008-09-30 15:41:23 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2008-09-30 15:41:23 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008-09-30 15:41:23 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2008-09-30 15:41:23 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2008-09-30 15:41:23 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2008-09-30 15:41:23 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: (74 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\user\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.)
O4 - HKLM..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE (Vimicro)
O4 - HKLM..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe (ASUSTeK COMPUTER INC.)
O4 - HKLM..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe (Wistron)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe ()
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\HotkeyApp.exe (Wistron)
O4 - HKLM..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe ()
O4 - HKLM..\Run: [PowerKey] C:\Program Files\Launch Manager\PowerKey.exe ()
O4 - HKLM..\Run: [Regedit32] C:\WINDOWS\System32\regedit.exe File not found
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Wbutton] C:\Program Files\Launch Manager\Wbutton.exe ()
O4 - HKCU..\Run: [Nowe Gadu-Gadu] C:\Program Files\Nowe Gadu-Gadu\gg.exe (GG Network S.A.)
O4 - HKCU..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe (Franmo Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {266BB960-7DA8-11D4-A849-00008321B7D9} http://amadeusvista.com/vwp/common/cabs/VistaPWComms.CAB (Amadeus Cmd Page Cross Communication)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {3D518D7D-422F-4787-AC71-10BB552E897B} http://amadeusvista.com/vwp/common/cabs/SP2Patch.CAB (Amadeus_SP2_Patcher Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {EBE01DF7-D451-11D5-A842-000102A97CAB} http://amadeusvista.com/vwp/common/cabs/AmadeusInit.CAB (AmadeusInit.Init)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-09-18 20:05:21 | 00,000,067 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) -  File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) -  File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2009-10-29 18:58:22 | 00,000,000 | ---D | C] -- C:\_OTL
[2009-10-29 18:57:14 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Pulpit\OTL.exe
[2009-10-28 23:51:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\ewidencja
[2009-10-28 21:00:14 | 00,000,000 | ---D | C] -- C:\!KillBox
[2009-10-28 21:00:11 | 00,059,392 | ---- | C] (Option^Explicit Software                        vbtechcd@gmail.com) -- C:\Documents and Settings\user\Pulpit\KillBox.exe
[2009-10-27 16:33:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\praca magistrska
[2009-10-17 08:07:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\Alexandre Desplat - Coco Avant Chanel [2009]
[2009-10-15 08:22:04 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009-10-12 20:59:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Pulpit\chorwacja

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2009-10-29 19:02:54 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2009-10-29 19:01:11 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-10-29 19:01:08 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-10-29 18:57:17 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Pulpit\OTL.exe
[2009-10-28 21:30:02 | 01,181,938 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-10-28 21:30:02 | 00,523,360 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2009-10-28 21:30:02 | 00,463,974 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-10-28 21:30:02 | 00,099,022 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2009-10-28 21:30:02 | 00,080,712 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-10-28 21:24:33 | 00,000,573 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-10-28 21:24:33 | 00,000,271 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-10-28 21:24:33 | 00,000,210 | -HS- | M] () -- C:\boot.ini
[2009-10-28 21:17:58 | 03,771,994 | -H-- | M] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-10-28 20:44:44 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-10-26 22:58:55 | 00,035,308 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\rajd III.JPG
[2009-10-21 23:49:34 | 00,200,192 | ---- | M] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-10-20 12:29:18 | 00,064,512 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\OrganizacjaImprez.doc
[2009-10-18 11:19:31 | 00,025,220 | ---- | M] () -- C:\Documents and Settings\user\Moje dokumenty\tour salon1.pdf
[2009-10-16 23:49:46 | 90,414,709 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\AD-CAC.rar
[2009-10-15 10:34:41 | 00,072,704 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\Geograficzno.doc
[2009-10-15 08:19:59 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-10-11 14:09:54 | 00,027,136 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\v_rok.xls

[color=#E56717]========== Files - No Company Name ==========[/color]
[2009-10-27 23:14:53 | 00,000,020 | ---- | C] () -- C:\Documents and Settings\user\Dane aplikacji\wiaserva.log
[2009-10-26 22:58:54 | 00,035,308 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\rajd III.JPG
[2009-10-20 12:29:17 | 00,064,512 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\OrganizacjaImprez.doc
[2009-10-18 11:19:31 | 00,025,220 | ---- | C] () -- C:\Documents and Settings\user\Moje dokumenty\tour salon1.pdf
[2009-10-16 23:27:39 | 90,414,709 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\AD-CAC.rar
[2009-10-15 10:34:40 | 00,072,704 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\Geograficzno.doc
[2009-10-11 14:09:53 | 00,027,136 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\v_rok.xls
[2009-04-21 22:30:49 | 00,010,593 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2009-03-01 12:06:34 | 00,000,035 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2009-01-18 20:35:31 | 00,000,055 | ---- | C] () -- C:\WINDOWS\AWF Screensaver.ini
[2008-12-26 11:25:17 | 00,001,870 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008-12-13 18:34:13 | 00,000,167 | ---- | C] () -- C:\WINDOWS\usdthank.ini
[2008-12-13 18:34:12 | 00,000,031 | ---- | C] () -- C:\WINDOWS\idc.ini
[2008-09-18 20:21:24 | 00,000,129 | ---- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\fusioncache.dat
[2008-09-18 20:05:21 | 00,001,196 | ---- | C] () -- C:\WINDOWS\VFO.INI
[2008-04-06 18:33:16 | 00,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS75.DLL
[2007-12-11 16:52:18 | 00,639,224 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007-09-18 19:03:23 | 00,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007-08-29 10:52:31 | 00,200,192 | ---- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007-08-27 18:08:42 | 00,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007-08-27 17:49:41 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007-08-27 17:49:41 | 00,593,920 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007-08-27 17:49:41 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2007-08-27 17:49:40 | 00,010,752 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007-08-27 17:49:40 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007-08-27 17:47:24 | 00,009,867 | ---- | C] () -- C:\WINDOWS\System32\drivers\HOTKEY.sys
[2007-08-27 17:45:47 | 00,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2007-08-25 14:52:32 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
[2007-08-25 14:01:22 | 03,771,994 | -H-- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2007-08-25 13:59:43 | 00,086,552 | ---- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2007-08-25 13:56:26 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\user\Dane aplikacji\desktop.ini
[2004-07-17 11:36:38 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2002-03-17 01:00:00 | 00,007,420 | ---- | C] () -- C:\WINDOWS\UA000088.DLL
[2001-07-21 23:16:20 | 00,000,573 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-21 23:15:52 | 00,000,271 | ---- | C] () -- C:\WINDOWS\system.ini

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:888AFB86
< End of report >


Pozdrawiam :wink:
Senatus Populusque Romanus
Awatar użytkownika
Corran
~user
 
Posty: 220
Dołączenie: 09 Mar 2005, 17:02
Miejscowość: Poznań



Rosyjskie okienko

Postprzez wojtas 29 Paź 2009, 23:44

1.Uruchom OTL z opcji CleanUp
2. wykonaj optymalizację windowsa
3.Wyłącz przywracanie systemu ( właściwości mój komputer-zakładka przywracanie - wyłącz przywracanie na wszystkich dyskach). Po chwili włącz je powrotem]
4. zrób skan Malwarebytes Anti-Malware (usuń co znajdzie )
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 9 gości