Strona startowa qooqle, jak usunąć ? PROSZĘ O POMOC

witam,

mam problem ze stroną startową qooqle. Nie mogę jej usunąć. Przeglądałam już wątki w tym temacie i ściągnęłam OTL ale nie mogę wkleic logów bo włącza mi się tylko na 3 sekundy i nic nie mogę z tym zrobić. Mógłby mi ktoś pomóc??

Wykonaj pełne skanowanie programem Malwarebytes:

http://www.dobreprogramy.pl/Malwarebyte … 13117.html

usuń co znajdzie i pokaż raport, następnie spróbuj uruchomić OTL

Malwarebytes’ Anti-Malware 1.50.1.1100

http://www.malwarebytes.org

Wersja bazy: 6531

Windows 5.1.2600 Dodatek Service Pack 3

Internet Explorer 6.0.2900.5512

2011-05-08 12:46:31

mbam-log-2011-05-08 (12-46-31).txt

Typ skanowania: Pełne skanowanie (C:|D:|E:|)

Przeskanowano obiektów: 185008

Upłynęło: 32 minut(y), 44 sekund(y)

Zainfekowanych procesów w pamięci: 1

Zainfekowanych modułów w pamięci: 0

Zainfekowanych kluczy rejestru: 0

Zainfekowanych wartości rejestru: 4

Zainfekowane informacje rejestru systemowego: 1

Zainfekowanych folderów: 0

Zainfekowanych plików: 6

Zainfekowanych procesów w pamięci:

c:\documents and settings\x\dane aplikacji\VolPanel.exe (Redir.Qooqlle) -> 912 -> Unloaded process successfully.

Zainfekowanych modułów w pamięci:

(Nie znaleziono zagrożeń)

Zainfekowanych kluczy rejestru:

(Nie znaleziono zagrożeń)

Zainfekowanych wartości rejestru:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\TunesHelper (Redir.Qooqlle) -> Value: TunesHelper -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Readar_sl (Redir.Qooqlle) -> Value: Readar_sl -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\VolPanel32 (Redir.Qooqlle) -> Value: VolPanel32 -> Quarantined and deleted successfully.

Zainfekowane informacje rejestru systemowego:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Redir.Qooqlle) -> Bad: (http://www.qooqlle.com/) Good: (http://www.google.com) -> Quarantined and deleted successfully.

Zainfekowanych folderów:

(Nie znaleziono zagrożeń)

Zainfekowanych plików:

c:\documents and settings\x\ustawienia lokalne\Temp\nse72.tmp\NSISdlGG.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.

c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.

e:\programy\autocad2008\autocad 2008 keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.

c:\documents and settings\all users\tuneshelper.exe (Redir.Qooqlle) -> Quarantined and deleted successfully.

c:\documents and settings\x\dane aplikacji\VolPanel.exe (Redir.Qooqlle) -> Quarantined and deleted successfully.

c:\documents and settings\x\dane aplikacji\readar_sl.exe (Redir.Qooqlle) -> Quarantined and deleted successfully.

Dodane 08.05.2011 (N) 12:56

wyżej jest raport i OTL włączył się bez problemu. Więc co dalej??

Większośc się usunęło, ale podaj jeszcze te logi z OTL instrukcja:

otl-gmer-rsit-dss-inne-instrukcje-t370405.html

OTL Extras logfile created on: 2011-05-08 13:35:12 - Run 1

OTL by OldTimer - Version 3.2.22.3 Folder = d:\Moje dokumenty\Downloads

Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.5512)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

895,00 Mb Total Physical Memory | 333,00 Mb Available Physical Memory | 37,00% Memory free

2,00 Gb Paging File | 2,00 Gb Available in Paging File | 77,00% Paging File free

Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19,53 Gb Total Space | 8,91 Gb Free Space | 45,61% Space Free | Partition Type: NTFS

Drive D: | 29,29 Gb Total Space | 18,57 Gb Free Space | 63,39% Space Free | Partition Type: NTFS

Drive E: | 62,96 Gb Total Space | 44,45 Gb Free Space | 70,60% Space Free | Partition Type: NTFS

Drive F: | 546,76 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: X-4E6954B5D7424 | User Name: x | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes]

.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL “%1”,%*

.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-1177238915-1801674531-1810155577-1004\SOFTWARE\Classes]

.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\shell[command]\command]

batfile [open] – “%1” %*

cmdfile [open] – “%1” %*

comfile [open] – “%1” %*

cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL “%1”,%*

exefile [open] – “%1” %*

htmlfile [edit] – “C:\Program Files\Microsoft Office\Office14\msohtmed.exe” %1 (Microsoft Corporation)

htmlfile [print] – “C:\Program Files\Microsoft Office\Office14\msohtmed.exe” /p %1 (Microsoft Corporation)

InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l

piffile [open] – “%1” %*

regfile [merge] – Reg Error: Key error.

scrfile [config] – “%1”

scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] – “%1” /S

txtfile [edit] – Reg Error: Key error.

Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] – “C:\Program Files\Winamp\winamp.exe” /BOOKMARK “%1” (Nullsoft, Inc.)

Directory [Winamp.Enqueue] – “C:\Program Files\Winamp\winamp.exe” /ADD “%1” (Nullsoft, Inc.)

Directory [Winamp.Play] – “C:\Program Files\Winamp\winamp.exe” “%1” (Nullsoft, Inc.)

Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

“FirstRunDisabled” = 1

“AntiVirusDisableNotify” = 0

“FirewallDisableNotify” = 0

“UpdatesDisableNotify” = 0

“AntiVirusOverride” = 0

“FirewallOverride” = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

“DisableSR” = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

“Start” = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

“Start” = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

“C:\Program Files\Microsoft Office\Office14\GROOVE.EXE” = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)

“C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE” = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)

“C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE” = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)

“E:\programy\Gadu-Gadu 10\gg.exe” = E:\programy\Gadu-Gadu 10\gg.exe:*:Enabled:Gadu-Gadu 10 – (GG Network S.A.)

“C:\Documents and Settings\x\Pulpit\StrongDC.exe” = C:\Documents and Settings\x\Pulpit\StrongDC.exe:*:Enabled:StrongDC++

“E:\programy\sdc221\StrongDC.exe” = E:\programy\sdc221\StrongDC.exe:*:Enabled:StrongDC++ – ()

“E:\programy\AxessManager.exe” = E:\programy\AxessManager.exe:*:Enabled:AxessManager Application – (Axesstel Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

“{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}” = PDFCreator

“{01008697-BDFF-D63E-028F-3D761B9ECFCD}” = Catalyst Control Center Localization Japanese

“{055EE59D-217B-43A7-ABFF-507B966405D8}” = ATI Catalyst Control Center

“{08F40849-1FEC-2FCD-DB52-DE763E0502A3}” = CCC Help Polish

“{09C85E5A-3E10-4268-904C-BACEF16ECEF0}” = ESET NOD32 Antivirus

“{0A755762-EED8-47AB-A446-505766F93D43}” = Atheros Communications Inc.® L2 Fast Ethernet Driver

“{0E0153EE-02B7-0B65-1702-25C52177B486}” = Catalyst Control Center Localization Danish

“{0E02DEDE-3FBB-3220-6B36-0D52B51A0BED}” = Catalyst Control Center Localization French

“{0E5922EE-B18C-F8FF-0BF5-359422A2C5A0}” = CCC Help Swedish

“{0ECA0FC5-F931-E6F7-3799-1828D0E5B00B}” = CCC Help Chinese Standard

“{13EF8260-2655-1AAD-3471-7F12CC8E8D7B}” = Catalyst Control Center Graphics Full Existing

“{161B2582-D82E-8B24-E0C0-FBBB3A85C08B}” = CCC Help Greek

“{1781F757-10E2-49F1-D4F3-4AA8DA2E2FDF}” = CCC Help Turkish

“{1A455F58-7718-2D02-9DF6-D0E5042AFE2B}” = CCC Help Chinese Traditional

“{1B5FA043-94A4-91F4-A907-DC03A0D33104}” = Catalyst Control Center Localization Chinese Traditional

“{1BCC4A3D-5B42-3BB2-D346-75834617B031}” = Catalyst Control Center Localization Korean

“{1C4C0D80-780A-6580-92CE-F2E9F94BA5D6}” = Catalyst Control Center Localization Turkish

“{1CBCC734-E92F-C744-D86C-3699D5351045}” = Nero 7 Demo

“{1E21422B-B426-0E85-2333-A230E99375E3}” = Catalyst Control Center Localization Polish

“{21527237-ECE2-43C8-29C5-E43C5F17FCCC}” = CCC Help French

“{26A24AE4-039D-4CA4-87B4-2F83216023FF}” = Java 6 Update 24

“{28006915-2739-4EBE-B5E8-49B25D32EB33}” = Atheros Client Installation Program

“{332CC6BF-E6C7-48EE-BA3D-435E576AD67F}” = PaperPort Image Printer

“{34D10029-5B88-C2A8-BDF8-A168EA0E8C76}” = CCC Help Czech

“{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}” = WebFldrs XP

“{36CDA33B-909B-4719-97D1-C4B99309BDC7}” = ATI Parental Control & Encoder

“{37B83E46-5932-2FB0-6CE1-B3AF3B5C9327}” = Catalyst Control Center Localization Portuguese

“{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}” = DAEMON Tools

“{41A40398-A4D5-11FD-DD2F-9B9A9148A4D8}” = CCC Help Spanish

“{4A03706F-666A-4037-7777-5F2748764D10}” = Java Auto Updater

“{4D342F33-3DAA-02A8-CBBA-763755683E5B}” = CCC Help Japanese

“{51A86EBC-C476-01F7-B0A8-A163CF72332D}” = CCC Help Danish

“{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}” = VBA (2627.01)

“{5783F2D7-6001-0415-0002-0060B0CE6BBA}” = AutoCAD 2008 - Polski

“{589F60BC-2712-FB88-7CF0-BE9E09DDD892}” = ccc-core-static

“{59D97AA9-EF5F-8A54-04F3-98E1D9AFE43B}” = Catalyst Control Center Localization Thai

“{5AF71003-1797-4D93-9F37-4F2125CBF539}” = Microsoft .NET Framework 2.0 Language Pack - PLK

“{64CBF40D-A9E9-5DCC-326D-F9B428DB11EA}” = CCC Help Russian

“{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}” = PowerDVD

“{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}” = Microsoft .NET Framework 2.0

“{73B9D273-503E-548B-2811-771CD745F76B}” = Catalyst Control Center Localization Italian

“{7D83EA87-9B6D-672A-D359-8186DD63FD2B}” = Catalyst Control Center Localization Russian

“{837b34e3-7c30-493c-8f6a-2b0f04e2912c}” = Microsoft Visual C++ 2005 Redistributable

“{86004E46-F949-A425-F5EA-2DA9E6CB00D1}” = CCC Help Italian

“{86C83CC2-4CE2-3834-24F2-0DC23CAD27AC}” = CCC Help Portuguese

“{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}” = Microsoft Silverlight

“{8F722FA9-B994-4C9B-B292-FD32D6206EDF}” = ASUS WLAN Card Utilities/Driver

“{90140000-0010-0415-0000-0000000FF1CE}” = Microsoft Software Update for Web Folders (Polish) 14

“{90140000-0011-0000-0000-0000000FF1CE}” = Microsoft Office Professional Plus 2010

“{90140000-0015-0415-0000-0000000FF1CE}” = Microsoft Office Access MUI (Polish) 2010

“{90140000-0016-0415-0000-0000000FF1CE}” = Microsoft Office Excel MUI (Polish) 2010

“{90140000-0018-0415-0000-0000000FF1CE}” = Microsoft Office PowerPoint MUI (Polish) 2010

“{90140000-0019-0415-0000-0000000FF1CE}” = Microsoft Office Publisher MUI (Polish) 2010

“{90140000-001A-0415-0000-0000000FF1CE}” = Microsoft Office Outlook MUI (Polish) 2010

“{90140000-001B-0415-0000-0000000FF1CE}” = Microsoft Office Word MUI (Polish) 2010

“{90140000-001F-0407-0000-0000000FF1CE}” = Microsoft Office Proof (German) 2010

“{90140000-001F-0409-0000-0000000FF1CE}” = Microsoft Office Proof (English) 2010

“{90140000-001F-0415-0000-0000000FF1CE}” = Microsoft Office Proof (Polish) 2010

“{90140000-002C-0415-0000-0000000FF1CE}” = Microsoft Office Proofing (Polish) 2010

“{90140000-0044-0415-0000-0000000FF1CE}” = Microsoft Office InfoPath MUI (Polish) 2010

“{90140000-006E-0415-0000-0000000FF1CE}” = Microsoft Office Shared MUI (Polish) 2010

“{90140000-00A1-0415-0000-0000000FF1CE}” = Microsoft Office OneNote MUI (Polish) 2010

“{90140000-00BA-0415-0000-0000000FF1CE}” = Microsoft Office Groove MUI (Polish) 2010

“{95416EF4-F37F-7412-E58C-C0F8F554D8A0}” = Catalyst Control Center Localization Hungarian

“{954F2AC8-A4C9-F202-FC15-D4BDC86081A1}” = Catalyst Control Center Graphics Full New

“{9A346205-EA92-4406-B1AB-50379DA3F057}” = Autodesk DWF Viewer 7

“{9A660264-A765-2AFF-6CFD-47CBFFDE4B31}” = Catalyst Control Center Localization Greek

“{9C58BEB2-82EE-A18F-0ECF-BC47CD18ADAF}” = Catalyst Control Center Localization Czech

“{A0B139A7-E8D5-49E8-A7BF-12421E652208}” = pdfforge Toolbar v4.3

“{A0DBDF40-559F-11E0-82E2-001D0926B1BF}” = Google Earth Plug-in

“{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}” = Brother MFL-Pro Suite

“{A4166DFB-8A6F-DB48-7436-7C5C3D8A0213}” = CCC Help Korean

“{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}” = Google Update Helper

“{AC76BA86-7AD7-1033-7B44-AA0000000001}” = Adobe Reader X (10.0.1)

“{AE63DAEF-870F-0E50-1D6C-453C229C1F06}” = Catalyst Control Center Localization Norwegian

“{AEB9948B-4FF2-47C9-990E-47014492A0FE}” = MSXML 6.0 Parser

“{B4B85B5E-E63A-F5EC-5045-CA818585038D}” = CCC Help English

“{B52D7A21-03E5-4C0C-82FA-FD8EB4C92149}” = AxessManager

“{B6C89654-A6A2-477C-873B-724EC1C56407}” = ScanSoft PaperPort 11

“{BA848FB0-91AB-FBD4-7D3E-B92A29006D13}” = Catalyst Control Center Core Implementation

“{BB65C393-C76E-4F06-9B0C-2124AA8AF97B}” = Adobe Flash Player 9 ActiveX

“{BB6D06CF-5E6C-6FB2-A0E5-2B08C05379A3}” = ccc-utility

“{BF30E962-D03D-0794-2C67-34C1C5ADE795}” = CCC Help Hungarian

“{C8B23990-260A-1D86-9300-1A367BFD4A97}” = CCC Help Thai

“{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}” = Bluetooth Stack for Windows

“{CF9912FD-41EE-88F6-6E65-C2BA86C44BD3}” = CCC Help German

“{CFFCBF25-740B-7A73-3D05-7758FCF3CC99}” = CCC Help Norwegian

“{D0DFF16B-9262-54C9-4F08-54380031CC68}” = Catalyst Control Center Localization German

“{D4D6E41D-0C9B-26C2-E2DA-81AB5360D343}” = Catalyst Control Center Localization Finnish

“{D899BA24-BEB5-EA33-A9E1-25552690CD14}” = Skins

“{DC24971E-1946-445D-8A82-CE685433FA7D}” = Realtek USB 2.0 Card Reader

“{E084BCDD-4307-DD43-BF32-AEFC57EF7E75}” = Catalyst Control Center Localization Spanish

“{E6BEC2A5-2B88-2210-5DE5-8F0DAA89A1AD}” = Catalyst Control Center Localization Dutch

“{ED7CD350-E9A6-C13B-1987-B0585175CA66}” = Catalyst Control Center Localization Swedish

“{EF468294-5893-016F-D1FD-36BE11E67BFA}” = CCC Help Finnish

“{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}” = Realtek High Definition Audio Driver

“{F6C36218-55AE-3095-D123-BEDECCC3A5E6}” = Catalyst Control Center Localization Chinese Standard

“{F8A01A89-6892-4387-D2C7-6C391557F01E}” = Catalyst Control Center Graphics Light

“{FEA08F47-FF91-DE5E-2D86-BD20A632452B}” = CCC Help Dutch

“Adobe Flash Player Plugin” = Adobe Flash Player 10 Plugin

“All ATI Software” = Narzędzie Software Uninstall Utility firmy ATI

“ATI Display Driver” = ATI Display Driver

“AutoCAD 2008 - Polski” = AutoCAD 2008 - Polski

“ffdshow_is1” = ffdshow v1.1.3631 [2010-11-15]

“Gadu-Gadu 10” = Gadu-Gadu 10

“IDNMitigationAPIs” = Microsoft Internationalized Domain Names Mitigation APIs

“ipla” = ipla 2.3

“KLiteCodecPack_is1” = K-Lite Codec Pack 6.2.0 (Basic)

“Malwarebytes’ Anti-Malware_is1” = Malwarebytes’ Anti-Malware

“Microsoft .NET Framework 2.0” = Microsoft .NET Framework 2.0

“Microsoft .NET Framework 2.0 Language Pack - PLK” = Microsoft .NET Framework 2.0 — pakiet języka polskiego

“Mozilla Firefox (3.6.12)” = Mozilla Firefox (3.6.12)

“NapiProjekt_is1” = NapiProjekt 1.0.6.9

“Office14.PROPLUS” = Microsoft Office Professional Plus 2010

“Rainlendar2” = Rainlendar2 (remove only)

“RealPlayer 6.0” = RealPlayer

“SubEdit-Player_is1” = SubEdit-Player

“USB2.0 1.3M WebCam” = USB2.0 1.3M WebCam

“Winamp” = Winamp

“WinRAR archiver” = Archiwizator WinRAR

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1177238915-1801674531-1810155577-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

“Google Chrome” = Google Chrome

“Winamp Detect” = Detektor Winampa

========== Last 10 Event Log Errors ==========

[Application Events]

Error - 2011-04-21 06:08:00 | Computer Name = X-4E6954B5D7424 | Source = Application Error | ID = 1000

Description = Aplikacja powodująca błąd silverlight.configuration.exe, wersja 4.0.51204.0,

moduł powodujący błąd silverlight.configuration.exe, wersja 4.0.51204.0, adres

błędu 0x0003ccb0.

Error - 2011-04-22 14:10:50 | Computer Name = X-4E6954B5D7424 | Source = MsiInstaller | ID = 10005

Description = Produkt: ESET NOD32 Antivirus – Błąd 5001. Komputer nie został ponownie

uruchomiony po odinstalowaniu programu. Należy uruchomić ponownie komputer i uruchomić

program instalacyjny.

Error - 2011-04-27 06:57:59 | Computer Name = X-4E6954B5D7424 | Source = Microsoft Office 14 | ID = 5000

Description = EventType officelifeboathang, P1 winword.exe, P2 14.0.4762.1000, P3

ntdll.dll, P4 5.1.2600.5512, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

Error - 2011-05-06 07:04:59 | Computer Name = X-4E6954B5D7424 | Source = Application Hang | ID = 1002

Description = Aplikacja zawieszająca subedit.exe, wersja 1.0.0.4072, moduł zawieszenia

hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

Error - 2011-05-06 07:21:07 | Computer Name = X-4E6954B5D7424 | Source = Application Hang | ID = 1002

Description = Aplikacja zawieszająca subedit.exe, wersja 1.0.0.4072, moduł zawieszenia

hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

Error - 2011-05-06 07:22:12 | Computer Name = X-4E6954B5D7424 | Source = Application Hang | ID = 1002

Description = Aplikacja zawieszająca subedit.exe, wersja 1.0.0.4072, moduł zawieszenia

hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

Error - 2011-05-06 14:28:35 | Computer Name = X-4E6954B5D7424 | Source = Application Error | ID = 1000

Description = Aplikacja powodująca błąd chrome.exe, wersja 0.0.0.0, moduł powodujący

błąd gcswf32.dll, wersja 10.2.154.27, adres błędu 0x00386c86.

[System Events]

Error - 2011-03-18 04:47:05 | Computer Name = X-4E6954B5D7424 | Source = Service Control Manager | ID = 7023

Description = Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący

błąd: %%2147500037

Error - 2011-03-21 04:21:07 | Computer Name = X-4E6954B5D7424 | Source = Service Control Manager | ID = 7023

Description = Usługa Karta wydajności WMI zakończyła działanie; wystąpił następujący

błąd: %%2147500037

< End of report >

Podałaś tylko extras.txt a trzeba jeszcze OTL.txt ponieważ powstaja 2 logi :slight_smile:

już podaje :slight_smile: nie zauważyłam drugiego :stuck_out_tongue:

OTL logfile created on: 2011-05-08 13:35:12 - Run 1

OTL by OldTimer - Version 3.2.22.3 Folder = d:\Moje dokumenty\Downloads

Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.5512)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

895,00 Mb Total Physical Memory | 333,00 Mb Available Physical Memory | 37,00% Memory free

2,00 Gb Paging File | 2,00 Gb Available in Paging File | 77,00% Paging File free

Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 19,53 Gb Total Space | 8,91 Gb Free Space | 45,61% Space Free | Partition Type: NTFS

Drive D: | 29,29 Gb Total Space | 18,57 Gb Free Space | 63,39% Space Free | Partition Type: NTFS

Drive E: | 62,96 Gb Total Space | 44,45 Gb Free Space | 70,60% Space Free | Partition Type: NTFS

Drive F: | 546,76 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: X-4E6954B5D7424 | User Name: x | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011-05-08 12:52:20 | 000,580,608 | ---- | M] (OldTimer Tools) – d:\Moje dokumenty\Downloads\OTL.exe

PRC - [2011-04-28 12:15:17 | 001,010,232 | ---- | M] (Google Inc.) – C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe

PRC - [2011-02-04 15:24:32 | 002,346,496 | ---- | M] () – E:\programy\Rainlendar2\Rainlendar2.exe

PRC - [2011-02-01 17:26:28 | 000,185,896 | ---- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe

PRC - [2009-02-06 14:23:36 | 000,727,720 | ---- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

PRC - [2009-02-06 14:23:12 | 002,021,400 | ---- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

PRC - [2008-04-15 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe

PRC - [2007-05-03 18:42:56 | 000,376,921 | ---- | M] (Atheros Communications, Inc.) – C:\Program Files\Atheros\ACU.exe

PRC - [2007-05-03 18:42:38 | 000,364,629 | ---- | M] (Atheros) – C:\WINDOWS\system32\acs.exe

PRC - [2007-04-19 07:42:34 | 000,024,576 | ---- | M] (Syntek America Inc.) – C:\WINDOWS\system32\StkCSrv.exe

PRC - [2007-03-02 17:48:00 | 000,098,304 | ---- | M] (Brother Industries, Ltd.) – C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe

PRC - [2006-05-16 12:42:52 | 001,777,664 | ---- | M] (TOSHIBA CORPORATION.) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

PRC - [2006-04-07 18:36:46 | 000,290,816 | ---- | M] (TOSHIBA CORPORATION.) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe

PRC - [2006-01-27 19:17:50 | 000,221,184 | ---- | M] (TOSHIBA CORPORATION.) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe

PRC - [2006-01-23 22:47:32 | 000,073,728 | ---- | M] (TOSHIBA CORPORATION.) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe

PRC - [2004-08-22 18:05:02 | 000,081,920 | ---- | M] (DAEMON’S HOME) – C:\Program Files\D-Tools\daemon.exe

========== Modules (SafeList) ==========

MOD - [2011-05-08 12:52:20 | 000,580,608 | ---- | M] (OldTimer Tools) – d:\Moje dokumenty\Downloads\OTL.exe

MOD - [2008-04-15 14:00:00 | 001,054,208 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – -- (HidServ)

SRV - File not found [On_Demand | Stopped] – -- (AppMgmt)

SRV - [2011-03-14 17:18:51 | 000,085,096 | ---- | M] (Autodesk) [On_Demand | Stopped] – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe – (Autodesk Licensing Service)

SRV - [2010-03-25 11:25:22 | 030,969,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE – (Microsoft SharePoint Workspace Audit Service)

SRV - [2009-02-06 14:27:06 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe – (EhttpSrv)

SRV - [2009-02-06 14:23:36 | 000,727,720 | ---- | M] (ESET) [Auto | Running] – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe – (ekrn)

SRV - [2008-04-15 14:00:00 | 000,003,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] – C:\WINDOWS\System32\regedt32.exe – (.EsetTrialReset)

SRV - [2007-05-03 18:42:38 | 000,364,629 | ---- | M] (Atheros) [Auto | Running] – C:\WINDOWS\system32\acs.exe – (ACS)

SRV - [2007-04-19 07:42:34 | 000,024,576 | ---- | M] (Syntek America Inc.) [Auto | Running] – C:\WINDOWS\system32\StkCSrv.exe – (StkSSrv)

========== Driver Services (SafeList) ==========

DRV - [2009-02-06 14:24:24 | 000,093,336 | ---- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\epfwtdir.sys – (epfwtdir)

DRV - [2009-02-06 14:23:18 | 000,106,208 | ---- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ehdrv.sys – (ehdrv)

DRV - [2009-02-06 14:19:52 | 000,113,448 | ---- | M] (ESET) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\eamon.sys – (eamon)

DRV - [2007-08-21 17:50:54 | 000,030,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l251x86.sys – (AtcL002)

DRV - [2007-06-06 11:40:26 | 001,260,672 | ---- | M] (Syntek) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\StkCMini.sys – (StkCMini)

DRV - [2007-03-28 20:52:18 | 000,057,024 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wsimd.sys – (WSIMD)

DRV - [2007-01-16 22:51:28 | 001,957,376 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)

DRV - [2006-11-03 10:32:30 | 004,394,496 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.Sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2006-10-12 17:28:42 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)

DRV - [2006-08-09 08:15:14 | 001,116,544 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynMini.sys – (SynMini)

DRV - [2006-08-09 08:15:14 | 000,007,808 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynScan.sys – (SynScan)

DRV - [2006-05-18 22:46:16 | 000,110,976 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\tosrfbd.sys – (Tosrfbd)

DRV - [2006-05-09 12:21:54 | 000,040,192 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\tosrfusb.sys – (Tosrfusb)

DRV - [2006-05-09 11:33:54 | 000,062,848 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\tosrfhid.sys – (Tosrfhid)

DRV - [2006-04-19 14:57:44 | 000,047,488 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\tosporte.sys – (tosporte)

DRV - [2006-03-16 11:45:12 | 000,037,632 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\tosrfbnp.sys – (Tosrfbnp)

DRV - [2006-03-15 11:52:40 | 000,052,864 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\tosrfsnd.sys – (TosRfSnd) Bluetooth Audio Device (WDM)

DRV - [2005-08-01 17:45:08 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\tosrfcom.sys – (Tosrfcom)

DRV - [2005-07-11 19:58:56 | 000,003,712 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\toshidpt.sys – (toshidpt)

DRV - [2005-01-06 14:42:42 | 000,018,612 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\tosrfnds.sys – (tosrfnds)

DRV - [2004-08-22 17:31:48 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\d347prt.sys – (d347prt)

DRV - [2004-08-22 17:31:10 | 000,155,136 | ---- | M] ( ) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\d347bus.sys – (d347bus)

DRV - [2002-09-09 20:54:06 | 000,016,269 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\ASNDIS5.sys – (ASNDIS5)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKU.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0

IE - HKU\S-1-5-21-1177238915-1801674531-1810155577-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

IE - HKU\S-1-5-21-1177238915-1801674531-1810155577-1004…\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - Reg Error: Value error. File not found

IE - HKU\S-1-5-21-1177238915-1801674531-1810155577-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0

========== FireFox ==========

FF - prefs.js…browser.search.selectedEngine: “qooqlle”

FF - prefs.js…browser.search.useDBForOrder: true

FF - prefs.js…browser.startup.homepage: “http://www.qooqlle.com/

FF - prefs.js…extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js…extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:4.0.0

FF - prefs.js…extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2

FF - prefs.js…extensions.enabledItems: cssreloader@kenneth.io:1.0.2

FF - prefs.js…extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6

FF - prefs.js…network.proxy.backup.ftp: “127.0.0.1”

FF - prefs.js…network.proxy.backup.ftp_port: 9666

FF - prefs.js…network.proxy.backup.gopher: “127.0.0.1”

FF - prefs.js…network.proxy.backup.gopher_port: 9666

FF - prefs.js…network.proxy.backup.socks: “127.0.0.1”

FF - prefs.js…network.proxy.backup.socks_port: 9666

FF - prefs.js…network.proxy.backup.ssl: “127.0.0.1”

FF - prefs.js…network.proxy.backup.ssl_port: 9666

FF - prefs.js…network.proxy.ftp: “127.0.0.1”

FF - prefs.js…network.proxy.ftp_port: 9666

FF - prefs.js…network.proxy.gopher: “127.0.0.1”

FF - prefs.js…network.proxy.gopher_port: 9666

FF - prefs.js…network.proxy.http: “127.0.0.1”

FF - prefs.js…network.proxy.http_port: 9666

FF - prefs.js…network.proxy.share_proxy_settings: true

FF - prefs.js…network.proxy.socks: “127.0.0.1”

FF - prefs.js…network.proxy.socks_port: 9666

FF - prefs.js…network.proxy.ssl: “127.0.0.1”

FF - prefs.js…network.proxy.ssl_port: 9666

FF - prefs.js…network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\Components: C:\Program Files\Mozilla Firefox\components [2011-02-01 17:39:09 | 000,000,000 | —D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-05-07 13:39:35 | 000,000,000 | —D | M]

FF - HKLM\software\mozilla\Thunderbird\Extensions\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011-04-22 20:14:38 | 000,000,000 | —D | M]

[2011-02-01 17:39:23 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\x\Dane aplikacji\Mozilla\Extensions

[2011-02-01 17:39:23 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\azd4z2i5.default\extensions

[2011-05-08 10:38:14 | 000,001,860 | ---- | M] () – C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\azd4z2i5.default\searchplugins\search.xml

[2011-03-19 00:35:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

[2011-02-03 21:08:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

[2011-03-19 00:35:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}

[2011-02-03 21:07:56 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF

File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS{9AA46F4F-4DC7-4C06-97AF-5035170633FE}

[2011-02-02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

[2010-10-27 07:37:26 | 000,002,767 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml

[2010-10-27 07:37:26 | 000,001,406 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml

[2010-10-27 07:37:26 | 000,000,917 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml

[2010-10-27 07:37:26 | 000,000,858 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml

[2010-10-27 07:37:26 | 000,001,183 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml

[2010-10-27 07:37:26 | 000,001,683 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2008-04-15 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)

O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)

O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - Reg Error: Value error. File not found

O4 - HKLM…\Run: [] File not found

O4 - HKLM…\Run: [ACU] C:\Program Files\Atheros\ACU.exe (Atheros Communications, Inc.)

O4 - HKLM…\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM…\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)

O4 - HKLM…\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)

O4 - HKLM…\Run: [DAEMON Tools-1033] C:\Program Files\D-Tools\daemon.exe (DAEMON’S HOME)

O4 - HKLM…\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)

O4 - HKLM…\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)

O4 - HKLM…\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKU\S-1-5-21-1177238915-1801674531-1810155577-1004…\Run: [] File not found

O4 - HKU\S-1-5-21-1177238915-1801674531-1810155577-1004…\Run: [Gadu-Gadu 10] E:\programy\Gadu-Gadu 10\gg.exe (GG Network S.A.)

O4 - HKU\S-1-5-21-1177238915-1801674531-1810155577-1004…\Run: [Google Update] File not found

O4 - HKU\S-1-5-21-1177238915-1801674531-1810155577-1004…\Run: [Rainlendar2] E:\programy\Rainlendar2\Rainlendar2.exe ()

O4 - HKU\S-1-5-21-1177238915-1801674531-1810155577-1004…\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()

O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ()

O7 - HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1177238915-1801674531-1810155577-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: Wyślij &do programu OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra ‘Tools’ menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)

O9 - Extra ‘Tools’ menuitem : &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_24)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)

O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2011-02-01 14:40:06 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT – [NTFS]

O33 - MountPoints2{3a62ff27-44be-11e0-8859-001bfcdc41e6}\Shell - “” = Autorun

O33 - MountPoints2{3a62ff27-44be-11e0-8859-001bfcdc41e6}\Shell\AutoRun\command - “” = C:\WINDOWS\System32\setup.exe – [2008-04-15 14:00:00 | 000,023,040 | ---- | M] (Microsoft Corporation)

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM…comfile [open] – “%1” %*

O35 - HKLM…exefile [open] – “%1” %*

O37 - HKLM…com [@ = comfile] – “%1” %*

O37 - HKLM…exe [@ = exefile] – “%1” %*

NetSvcs: 6to4 - File not found

NetSvcs: AppMgmt - File not found

NetSvcs: HidServ - File not found

NetSvcs: Ias - File not found

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

SafeBootMin: AppMgmt - File not found

SafeBootMin: Base - Driver Group

SafeBootMin: Boot Bus Extender - Driver Group

SafeBootMin: Boot file system - Driver Group

SafeBootMin: File system - Driver Group

SafeBootMin: Filter - Driver Group

SafeBootMin: PCI Configuration - Driver Group

SafeBootMin: PNP Filter - Driver Group

SafeBootMin: Primary disk - Driver Group

SafeBootMin: SCSI Class - Driver Group

SafeBootMin: sermouse.sys - Driver

SafeBootMin: System Bus Extender - Driver Group

SafeBootMin: vga.sys - Driver

SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: AppMgmt - File not found

SafeBootNet: Base - Driver Group

SafeBootNet: Boot Bus Extender - Driver Group

SafeBootNet: Boot file system - Driver Group

SafeBootNet: File system - Driver Group

SafeBootNet: Filter - Driver Group

SafeBootNet: NDIS Wrapper - Driver Group

SafeBootNet: NetBIOSGroup - Driver Group

SafeBootNet: NetDDEGroup - Driver Group

SafeBootNet: Network - Driver Group

SafeBootNet: NetworkProvider - Driver Group

SafeBootNet: PCI Configuration - Driver Group

SafeBootNet: PNP Filter - Driver Group

SafeBootNet: PNP_TDI - Driver Group

SafeBootNet: Primary disk - Driver Group

SafeBootNet: SCSI Class - Driver Group

SafeBootNet: sermouse.sys - Driver

SafeBootNet: Streams Drivers - Driver Group

SafeBootNet: System Bus Extender - Driver Group

SafeBootNet: TDI - Driver Group

SafeBootNet: vga.sys - Driver

SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers

SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive

SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive

SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller

SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc

SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard

SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse

SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net

SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient

SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService

SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans

SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters

SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter

SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System

SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive

SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume

SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

========== Files/Folders - Created Within 30 Days ==========

[2011-05-08 12:12:31 | 000,000,000 | —D | C] – C:\Documents and Settings\x\Dane aplikacji\Malwarebytes

[2011-05-08 12:12:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes’ Anti-Malware

[2011-05-08 12:12:21 | 000,038,224 | ---- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2011-05-08 12:12:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes

[2011-05-08 12:12:17 | 000,020,952 | ---- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

[2011-05-08 12:12:17 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes’ Anti-Malware

[2011-05-07 15:31:09 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF

[2011-05-07 13:38:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe

[2011-05-07 13:38:45 | 000,000,000 | —D | C] – C:\Program Files\Adobe

[2011-05-07 13:38:19 | 000,000,000 | —D | C] – C:\Documents and Settings\x\Moje dokumenty

[2011-05-07 13:38:15 | 000,000,000 | -HSD | C] – C:\Config.Msi

[2011-05-06 13:24:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\SubEdit-Player

[2011-04-28 15:20:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\Axesstel

[2011-04-22 22:01:18 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution

[2011-04-22 22:00:21 | 000,000,000 | --SD | C] – C:\Documents and Settings\x\UserData

[2011-04-22 20:14:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\ESET

[2011-04-20 18:58:15 | 000,000,000 | —D | C] – C:\Documents and Settings\x\Dane aplikacji\CyberLink

[2011-04-19 10:28:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\RDRM

[2011-04-19 10:28:23 | 000,000,000 | —D | C] – C:\Documents and Settings\x\Dane aplikacji\ipla

[2011-04-19 10:28:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\ipla

[2011-04-19 10:28:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\K-Lite Codec Pack

[2011-04-19 10:28:10 | 000,000,000 | —D | C] – C:\Program Files\K-Lite Codec Pack

[2011-04-19 10:27:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\ipla

[2011-04-19 10:26:45 | 000,000,000 | —D | C] – C:\Program Files\ipla

[2011-04-19 10:26:31 | 001,700,352 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\gdiplus.dll

[2011-04-18 18:30:14 | 000,000,000 | —D | C] – C:\Documents and Settings\x\Pulpit\kadzidło mapy

[2011-02-03 00:17:31 | 000,155,136 | ---- | C] ( ) – C:\WINDOWS\System32\drivers\d347bus.sys

[2011-02-03 00:17:31 | 000,005,248 | ---- | C] ( ) – C:\WINDOWS\System32\drivers\d347prt.sys

[3 C:\WINDOWS*.tmp files -> C:\WINDOWS*.tmp ->]

[1 C:\WINDOWS\System32*.tmp files -> C:\WINDOWS\System32*.tmp ->]

========== Files - Modified Within 30 Days ==========

[2011-05-08 13:34:00 | 000,001,116 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1801674531-1810155577-1004UA.job

[2011-05-08 13:04:00 | 000,001,026 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2011-05-08 12:48:34 | 000,001,022 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2011-05-08 12:48:32 | 000,000,006 | -H-- | M] () – C:\WINDOWS\tasks\SA.DAT

[2011-05-08 12:48:28 | 000,002,048 | --S- | M] () – C:\WINDOWS\bootstat.dat

[2011-05-08 12:47:20 | 005,242,880 | -H-- | M] () – C:\Documents and Settings\x\NTUSER.DAT

[2011-05-08 12:47:20 | 000,000,188 | -HS- | M] () – C:\Documents and Settings\x\ntuser.ini

[2011-05-08 12:12:22 | 000,000,784 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Malwarebytes’ Anti-Malware.lnk

[2011-05-08 10:37:49 | 000,013,646 | ---- | M] () – C:\WINDOWS\System32\wpa.dbl

[2011-05-07 23:34:00 | 000,001,064 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1801674531-1810155577-1004Core.job

[2011-05-07 20:11:14 | 000,044,032 | ---- | M] () – C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011-05-07 13:39:36 | 000,001,734 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Adobe Reader X.lnk

[2011-05-06 13:38:04 | 000,000,116 | ---- | M] () – C:\WINDOWS\NeroDigital.ini

[2011-05-02 11:07:16 | 000,000,664 | ---- | M] () – C:\WINDOWS\System32\d3d9caps.dat

[2011-04-28 15:20:52 | 000,000,281 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\AxessManager.lnk

[2011-04-19 10:26:33 | 001,700,352 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\gdiplus.dll

[2011-04-10 11:47:34 | 000,086,254 | ---- | M] () – C:\Documents and Settings\x\Pulpit\Dostepna_przestrzen_publiczna.pdf

[2011-04-10 09:21:35 | 000,448,586 | ---- | M] () – C:\WINDOWS\System32\perfh015.dat

[2011-04-10 09:21:35 | 000,392,630 | ---- | M] () – C:\WINDOWS\System32\perfh009.dat

[2011-04-10 09:21:35 | 000,074,648 | ---- | M] () – C:\WINDOWS\System32\perfc015.dat

[2011-04-10 09:21:35 | 000,058,930 | ---- | M] () – C:\WINDOWS\System32\perfc009.dat

[2011-04-10 09:21:34 | 000,984,778 | ---- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI

[3 C:\WINDOWS*.tmp files -> C:\WINDOWS*.tmp ->]

[1 C:\WINDOWS\System32*.tmp files -> C:\WINDOWS\System32*.tmp ->]

========== Files Created - No Company Name ==========

[2011-05-08 12:12:22 | 000,000,784 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\Malwarebytes’ Anti-Malware.lnk

[2011-05-07 13:39:36 | 000,001,804 | ---- | C] () – C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader X.lnk

[2011-05-07 13:39:36 | 000,001,734 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\Adobe Reader X.lnk

[2011-04-28 15:20:52 | 000,000,281 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\AxessManager.lnk

[2011-04-19 10:28:14 | 000,165,376 | ---- | C] () – C:\WINDOWS\System32\unrar.dll

[2011-04-10 11:47:33 | 000,086,254 | ---- | C] () – C:\Documents and Settings\x\Pulpit\Dostepna_przestrzen_publiczna.pdf

[2011-03-14 22:07:23 | 000,116,224 | ---- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll

[2011-03-03 23:59:43 | 000,000,116 | ---- | C] () – C:\WINDOWS\NeroDigital.ini

[2011-02-28 16:31:19 | 000,000,404 | ---- | C] () – C:\WINDOWS\BRWMARK.INI

[2011-02-28 16:31:19 | 000,000,027 | ---- | C] () – C:\WINDOWS\BRPP2KA.INI

[2011-02-28 16:29:45 | 000,000,050 | ---- | C] () – C:\WINDOWS\System32\bridf07a.dat

[2011-02-28 16:26:51 | 000,031,567 | ---- | C] () – C:\WINDOWS\maxlink.ini

[2011-02-05 12:35:40 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\SynSvc_.exe

[2011-02-05 12:35:39 | 000,014,848 | R— | C] () – C:\WINDOWS\System32\drivers\SynSam.sys

[2011-02-05 12:35:39 | 000,007,808 | R— | C] () – C:\WINDOWS\System32\drivers\SynScan.sys

[2011-02-05 12:35:35 | 000,498,688 | R— | C] () – C:\WINDOWS\System32\drivers\SynPin.sys

[2011-02-05 12:35:35 | 000,028,800 | R— | C] () – C:\WINDOWS\System32\drivers\SynCamd.sys

[2011-02-05 12:35:34 | 001,116,544 | R— | C] () – C:\WINDOWS\System32\drivers\SynMini.sys

[2011-02-05 12:02:29 | 000,000,098 | ---- | C] () – C:\WINDOWS\WirelessFTP.INI

[2011-02-05 11:58:02 | 000,000,000 | ---- | C] () – C:\WINDOWS\tosOBEX.INI

[2011-02-05 11:10:11 | 000,007,424 | R— | C] () – C:\WINDOWS\System32\drivers\MMIOPORT.SYS

[2011-02-04 20:06:01 | 000,000,664 | ---- | C] () – C:\WINDOWS\System32\d3d9caps.dat

[2011-02-03 00:12:26 | 000,044,032 | ---- | C] () – C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011-02-02 15:28:21 | 000,537,600 | ---- | C] () – C:\WINDOWS\System32\ASWL2K.exe

[2011-02-02 15:28:21 | 000,496,640 | ---- | C] () – C:\WINDOWS\System32\ASWLSVC.exe

[2011-02-02 15:28:21 | 000,159,827 | ---- | C] () – C:\WINDOWS\System32\RemSvc.exe

[2011-02-02 15:03:05 | 000,000,621 | ---- | C] () – C:\WINDOWS\System32\drivers\AW1012d.ini

[2011-02-02 11:57:03 | 000,101,624 | ---- | C] () – C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT

[2011-02-01 20:49:24 | 000,049,152 | ---- | C] () – C:\WINDOWS\System32\ChCfg.exe

[2011-02-01 20:37:25 | 003,107,788 | ---- | C] () – C:\WINDOWS\System32\ativvaxx.dat

[2011-02-01 20:37:24 | 000,145,112 | ---- | C] () – C:\WINDOWS\System32\atiicdxx.dat

[2011-02-01 20:36:59 | 000,045,056 | R— | C] () – C:\WINDOWS\StkUnist.exe

[2011-02-01 20:07:47 | 006,950,674 | -H-- | C] () – C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\IconCache.db

[2011-02-01 17:39:11 | 000,000,000 | ---- | C] () – C:\WINDOWS\nsreg.dat

[2011-02-01 17:27:04 | 000,000,025 | ---- | C] () – C:\WINDOWS\cdplayer.ini

[2011-02-01 15:25:56 | 000,984,778 | ---- | C] () – C:\WINDOWS\System32\PerfStringBackup.INI

[2011-02-01 15:25:55 | 000,004,293 | ---- | C] () – C:\WINDOWS\ODBCINST.INI

[2011-02-01 15:24:30 | 000,349,792 | ---- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

[2011-02-01 14:42:34 | 000,002,048 | --S- | C] () – C:\WINDOWS\bootstat.dat

[2011-02-01 14:40:06 | 000,000,000 | ---- | C] () – C:\WINDOWS\control.ini

[2011-02-01 14:39:06 | 000,000,488 | RH-- | C] () – C:\WINDOWS\System32\logonui.exe.manifest

[2011-02-01 14:39:00 | 000,000,749 | RH-- | C] () – C:\WINDOWS\System32\cdplayer.exe.manifest

[2011-02-01 14:37:09 | 000,021,856 | ---- | C] () – C:\WINDOWS\System32\emptyregdb.dat

[2011-02-01 14:36:51 | 000,000,037 | ---- | C] () – C:\WINDOWS\vbaddin.ini

[2011-02-01 14:36:51 | 000,000,036 | ---- | C] () – C:\WINDOWS\vb.ini

[2011-02-01 14:35:43 | 000,026,717 | ---- | C] () – C:\WINDOWS\System32\tslabels.ini

[2011-02-01 14:35:41 | 000,003,813 | ---- | C] () – C:\WINDOWS\System32\msdtcprf.ini

[2008-04-15 14:00:00 | 013,107,200 | ---- | C] () – C:\WINDOWS\System32\oembios.bin

[2008-04-15 14:00:00 | 001,015,477 | ---- | C] () – C:\WINDOWS\System32\esentprf.ini

[2008-04-15 14:00:00 | 000,733,696 | ---- | C] () – C:\WINDOWS\System32\qedwipes.dll

[2008-04-15 14:00:00 | 000,673,088 | ---- | C] () – C:\WINDOWS\System32\mlang.dat

[2008-04-15 14:00:00 | 000,448,586 | ---- | C] () – C:\WINDOWS\System32\perfh015.dat

[2008-04-15 14:00:00 | 000,392,630 | ---- | C] () – C:\WINDOWS\System32\perfh009.dat

[2008-04-15 14:00:00 | 000,355,112 | ---- | C] () – C:\WINDOWS\System32\msjetoledb40.dll

[2008-04-15 14:00:00 | 000,313,828 | ---- | C] () – C:\WINDOWS\System32\perfi015.dat

[2008-04-15 14:00:00 | 000,272,128 | ---- | C] () – C:\WINDOWS\System32\perfi009.dat

[2008-04-15 14:00:00 | 000,270,848 | ---- | C] () – C:\WINDOWS\System32\sbe.dll

[2008-04-15 14:00:00 | 000,253,440 | ---- | C] () – C:\WINDOWS\System32\compatUI.dll

[2008-04-15 14:00:00 | 000,218,003 | ---- | C] () – C:\WINDOWS\System32\dssec.dat

[2008-04-15 14:00:00 | 000,199,168 | ---- | C] () – C:\WINDOWS\System32\ir32_32.dll

[2008-04-15 14:00:00 | 000,186,880 | ---- | C] () – C:\WINDOWS\System32\encdec.dll

[2008-04-15 14:00:00 | 000,094,282 | ---- | C] () – C:\WINDOWS\System32\msencode.dll

[2008-04-15 14:00:00 | 000,074,648 | ---- | C] () – C:\WINDOWS\System32\perfc015.dat

[2008-04-15 14:00:00 | 000,070,656 | ---- | C] () – C:\WINDOWS\System32\amstream.dll

[2008-04-15 14:00:00 | 000,070,622 | ---- | C] () – C:\WINDOWS\System32\edit.com

[2008-04-15 14:00:00 | 000,058,930 | ---- | C] () – C:\WINDOWS\System32\perfc009.dat

[2008-04-15 14:00:00 | 000,053,920 | ---- | C] () – C:\WINDOWS\System32\dosx.exe

[2008-04-15 14:00:00 | 000,053,478 | ---- | C] () – C:\WINDOWS\System32\tcpmon.ini

[2008-04-15 14:00:00 | 000,051,823 | ---- | C] () – C:\WINDOWS\System32\command.com

[2008-04-15 14:00:00 | 000,046,258 | ---- | C] () – C:\WINDOWS\System32\mib.bin

[2008-04-15 14:00:00 | 000,042,809 | ---- | C] () – C:\WINDOWS\System32\key01.sys

[2008-04-15 14:00:00 | 000,042,537 | ---- | C] () – C:\WINDOWS\System32\keyboard.sys

[2008-04-15 14:00:00 | 000,039,434 | ---- | C] () – C:\WINDOWS\System32\mem.exe

[2008-04-15 14:00:00 | 000,035,648 | ---- | C] () – C:\WINDOWS\System32\ntio411.sys

[2008-04-15 14:00:00 | 000,035,424 | ---- | C] () – C:\WINDOWS\System32\ntio412.sys

[2008-04-15 14:00:00 | 000,034,990 | ---- | C] () – C:\WINDOWS\System32\perfd015.dat

[2008-04-15 14:00:00 | 000,034,560 | ---- | C] () – C:\WINDOWS\System32\ntio804.sys

[2008-04-15 14:00:00 | 000,034,560 | ---- | C] () – C:\WINDOWS\System32\ntio404.sys

[2008-04-15 14:00:00 | 000,033,936 | ---- | C] () – C:\WINDOWS\System32\ntio.sys

[2008-04-15 14:00:00 | 000,029,370 | ---- | C] () – C:\WINDOWS\System32\ntdos411.sys

[2008-04-15 14:00:00 | 000,029,274 | ---- | C] () – C:\WINDOWS\System32\ntdos412.sys

[2008-04-15 14:00:00 | 000,029,146 | ---- | C] () – C:\WINDOWS\System32\ntdos804.sys

[2008-04-15 14:00:00 | 000,029,146 | ---- | C] () – C:\WINDOWS\System32\ntdos404.sys

[2008-04-15 14:00:00 | 000,028,626 | ---- | C] () – C:\WINDOWS\System32\perfd009.dat

[2008-04-15 14:00:00 | 000,027,898 | ---- | C] () – C:\WINDOWS\System32\ntdos.sys

[2008-04-15 14:00:00 | 000,027,097 | ---- | C] () – C:\WINDOWS\System32\country.sys

[2008-04-15 14:00:00 | 000,020,986 | ---- | C] () – C:\WINDOWS\System32\debug.exe

[2008-04-15 14:00:00 | 000,019,806 | ---- | C] () – C:\WINDOWS\System32\graphics.com

[2008-04-15 14:00:00 | 000,016,024 | ---- | C] () – C:\WINDOWS\System32\rsvp.ini

[2008-04-15 14:00:00 | 000,015,360 | ---- | C] () – C:\WINDOWS\System32\tsd32.dll

[2008-04-15 14:00:00 | 000,014,913 | ---- | C] () – C:\WINDOWS\System32\kb16.com

[2008-04-15 14:00:00 | 000,014,336 | ---- | C] () – C:\WINDOWS\System32\msdmo.dll

[2008-04-15 14:00:00 | 000,013,819 | ---- | C] () – C:\WINDOWS\System32\pschdprf.ini

[2008-04-15 14:00:00 | 000,013,312 | ---- | C] () – C:\WINDOWS\System32\win87em.dll

[2008-04-15 14:00:00 | 000,012,866 | ---- | C] () – C:\WINDOWS\System32\edlin.exe

[2008-04-15 14:00:00 | 000,012,594 | ---- | C] () – C:\WINDOWS\System32\append.exe

[2008-04-15 14:00:00 | 000,011,859 | ---- | C] () – C:\WINDOWS\System32\setver.exe

[2008-04-15 14:00:00 | 000,009,043 | ---- | C] () – C:\WINDOWS\System32\ansi.sys

[2008-04-15 14:00:00 | 000,008,520 | ---- | C] () – C:\WINDOWS\System32\exe2bin.exe

[2008-04-15 14:00:00 | 000,007,116 | ---- | C] () – C:\WINDOWS\System32\nlsfunc.exe

[2008-04-15 14:00:00 | 000,006,074 | ---- | C] () – C:\WINDOWS\System32\rasctrs.ini

[2008-04-15 14:00:00 | 000,004,976 | ---- | C] () – C:\WINDOWS\System32\himem.sys

[2008-04-15 14:00:00 | 000,004,569 | ---- | C] () – C:\WINDOWS\System32\secupd.dat

[2008-04-15 14:00:00 | 000,004,461 | ---- | C] () – C:\WINDOWS\System32\oembios.dat

[2008-04-15 14:00:00 | 000,003,346 | ---- | C] () – C:\WINDOWS\System32\redir.exe

[2008-04-15 14:00:00 | 000,002,992 | ---- | C] () – C:\WINDOWS\System32\perfci.ini

[2008-04-15 14:00:00 | 000,002,890 | ---- | C] () – C:\WINDOWS\System32\perfwci.ini

[2008-04-15 14:00:00 | 000,001,804 | ---- | C] () – C:\WINDOWS\System32\Dcache.bin

[2008-04-15 14:00:00 | 000,001,405 | ---- | C] () – C:\WINDOWS\msdfmap.ini

[2008-04-15 14:00:00 | 000,001,295 | ---- | C] () – C:\WINDOWS\System32\perffilt.ini

[2008-04-15 14:00:00 | 000,001,168 | ---- | C] () – C:\WINDOWS\System32\loadfix.com

[2008-04-15 14:00:00 | 000,000,882 | ---- | C] () – C:\WINDOWS\System32\share.exe

[2008-04-15 14:00:00 | 000,000,882 | ---- | C] () – C:\WINDOWS\System32\fastopen.exe

[2008-04-15 14:00:00 | 000,000,817 | ---- | C] () – C:\WINDOWS\System32\mscdexnt.exe

[2008-04-15 14:00:00 | 000,000,741 | ---- | C] () – C:\WINDOWS\System32\noise.dat

[2008-04-15 14:00:00 | 000,000,552 | ---- | C] () – C:\WINDOWS\win.ini

[2008-04-15 14:00:00 | 000,000,359 | ---- | C] () – C:\WINDOWS\System32\prodspec.ini

[2008-04-15 14:00:00 | 000,000,231 | ---- | C] () – C:\WINDOWS\system.ini

[2005-09-02 15:44:08 | 000,110,592 | ---- | C] () – C:\WINDOWS\System32\TosBtAcc.dll

[2005-07-22 22:30:20 | 000,065,536 | ---- | C] () – C:\WINDOWS\System32\TosCommAPI.dll

[2004-08-22 18:04:56 | 000,069,120 | ---- | C] () – C:\WINDOWS\daemon.dll

[2004-07-20 18:04:02 | 000,094,208 | ---- | C] () – C:\WINDOWS\System32\TosBtHcrpAPI.dll

[2004-01-15 15:43:28 | 000,114,688 | ---- | C] () – C:\WINDOWS\System32\TBTMonUI.dll

[2002-10-06 21:42:58 | 000,237,568 | ---- | C] () – C:\WINDOWS\System32\OggDS.dll

[2002-10-05 02:04:26 | 000,921,600 | ---- | C] () – C:\WINDOWS\System32\vorbisenc.dll

[2002-10-05 02:04:26 | 000,188,416 | ---- | C] () – C:\WINDOWS\System32\VORBIS.DLL

[2002-10-05 02:04:18 | 000,045,056 | ---- | C] () – C:\WINDOWS\System32\OGG.DLL

[2001-10-26 19:29:54 | 000,057,856 | ---- | C] () – C:\WINDOWS\System32\dvdplay.exe

[2001-10-26 19:29:42 | 000,157,696 | ---- | C] () – C:\WINDOWS\System32\paqsp.dll

========== LOP Check ==========

[2011-03-19 21:32:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\Autodesk

[2011-03-02 13:14:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\ESET

[2011-03-02 13:11:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\G DATA

[2011-02-03 17:16:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10

[2011-04-22 16:44:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\ipla

[2011-04-19 10:28:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\RDRM

[2011-02-28 16:26:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\ScanSoft

[2011-03-19 21:32:04 | 000,000,000 | —D | M] – C:\Documents and Settings\x\Dane aplikacji\Autodesk

[2011-02-05 20:54:09 | 000,000,000 | —D | M] – C:\Documents and Settings\x\Dane aplikacji\Gadu-Gadu 10

[2011-05-05 22:24:54 | 000,000,000 | —D | M] – C:\Documents and Settings\x\Dane aplikacji\ipla

[2011-03-14 22:08:04 | 000,000,000 | —D | M] – C:\Documents and Settings\x\Dane aplikacji\Search Settings

[2011-02-05 12:05:33 | 000,000,000 | —D | M] – C:\Documents and Settings\x\Dane aplikacji\Toshiba

========== Purity Check ==========

========== Custom Scans ==========

< %systemdrive%*.* >

[2011-02-02 15:32:04 | 000,000,162 | ---- | M] () – C:\ASWL2K.ini

[2011-02-01 14:40:06 | 000,000,000 | ---- | M] () – C:\AUTOEXEC.BAT

[2011-02-01 14:34:31 | 000,000,211 | -HS- | M] () – C:\boot.ini

[2008-04-15 14:00:00 | 000,004,952 | RHS- | M] () – C:\Bootfont.bin

[2011-02-01 14:40:06 | 000,000,000 | ---- | M] () – C:\CONFIG.SYS

[2011-02-01 14:40:06 | 000,000,000 | RHS- | M] () – C:\IO.SYS

[2011-02-01 14:40:06 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS

[2008-04-15 14:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM

[2008-04-15 14:00:00 | 000,251,152 | RHS- | M] () – C:\ntldr

[2011-05-08 12:48:18 | 1409,286,144 | -HS- | M] () – C:\pagefile.sys

< MD5 for: AGP440.SYS >

[2008-04-15 14:00:00 | 020,110,420 | ---- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:agp440.sys

< MD5 for: ATAPI.SYS >

[2008-04-15 14:00:00 | 020,110,420 | ---- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys

[2008-04-15 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: BEEP.SYS >

[2008-04-15 14:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 – C:\WINDOWS\system32\dllcache\beep.sys

[2008-04-15 14:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 – C:\WINDOWS\system32\drivers\beep.sys

< MD5 for: CDROM.SYS >

[2008-04-15 14:00:00 | 020,110,420 | ---- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys

[2008-04-15 14:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE – C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: NDIS.SYS >

[2008-04-15 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D – C:\WINDOWS\system32\dllcache\ndis.sys

[2008-04-15 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D – C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: USERINIT.EXE >

[2008-04-15 14:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=2A5B37D520508BE6570A3EA79695F5B5 – C:\WINDOWS\system32\dllcache\userinit.exe

[2008-04-15 14:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=2A5B37D520508BE6570A3EA79695F5B5 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >

[2008-04-15 14:00:00 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 – C:\WINDOWS\system32\dllcache\winlogon.exe

[2008-04-15 14:00:00 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 – C:\WINDOWS\system32\winlogon.exe

< End of report >

Wklej w białe okienko OTL i naciśnij wykonaj skrypt:

dajesz log z usuwania

All processes killed

========== OTL ==========

Registry value HKEY_USERS\S-1-5-21-1177238915-1801674531-1810155577-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\{B922D405-6D13-4A2B-AE89-08A030DA4402} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{B922D405-6D13-4A2B-AE89-08A030DA4402}\ deleted successfully.

Prefs.js: “qooqlle” removed from browser.search.selectedEngine

Prefs.js: “http://www.qooqlle.com/” removed from browser.startup.homepage

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{B922D405-6D13-4A2B-AE89-08A030DA4402}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ deleted successfully.

Registry value HKEY_USERS\S-1-5-21-1177238915-1801674531-1810155577-1004\Software\Microsoft\Windows\CurrentVersion\Run\ deleted successfully.

Registry value HKEY_USERS\S-1-5-21-1177238915-1801674531-1810155577-1004\Software\Microsoft\Windows\CurrentVersion\Run\Google Update deleted successfully.

========== REGISTRY ==========

Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\ deleted successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

User: x

->Temp folder emptied: 569133568 bytes

->Temporary Internet Files folder emptied: 12560972 bytes

->Java cache emptied: 2941959 bytes

->FireFox cache emptied: 55818082 bytes

->Google Chrome cache emptied: 265798906 bytes

->Flash cache emptied: 19065 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 2352022 bytes

%systemroot%\System32 .tmp files removed: 2596 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 770007521 bytes

RecycleBin emptied: 1158183330 bytes

Total Files Cleaned = 2 705,00 mb

OTL by OldTimer - Version 3.2.22.3 log created on 05082011_135227

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

Co miało się usunąć to się usunęło, ustaw swoja strone startową w przeglądarkach, jeśli nie ma już problemu to naciśnij w OTL sprzątanie

Juz jest wszystko dobrze :smiley: Bardzo dziękuję za pomoc :slight_smile: