Nie działa McAfee

Witam!

Z niewyjaśnionych przyczyn nie można uruchomić MCAfee Security Center. Próba ponownej instalacji nie udała się, ponieważ program nie może połączyć się z serwerem producenta. Program jest orginalny - licencja z tp, w ramach usługi neostrada. Wykryłam obecność wirusa - dobryskaner ( ze strony dobreprogramy.pl) znalazł 13 zainfekowanych plików. Proszę o sprawdzenie loga z OTL.

OTL logfile created on: 2010-10-23 17:02:46 - Run 1

OTL by OldTimer - Version 3.2.16.0 Folder = C:\Documents and Settings\Właściciel\Pulpit

Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd


1 013,00 Mb Total Physical Memory | 488,00 Mb Available Physical Memory | 48,00% Memory free

4,00 Gb Paging File | 3,00 Gb Available in Paging File | 77,00% Paging File free

Paging file location(s): [Binary data over 100 bytes]


%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 74,44 Gb Total Space | 39,16 Gb Free Space | 52,60% Space Free | Partition Type: NTFS

Drive D: | 74,60 Gb Total Space | 63,10 Gb Free Space | 84,59% Space Free | Partition Type: NTFS


Computer Name: W-3DBE15FD69754 | User Name: Właściciel | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days


[color=#E56717]========== Processes (SafeList) ==========[/color]


PRC - [2010-10-23 17:01:20 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Pulpit\OTL_3.2.16.0(dobreprogramy.pl).exe

PRC - [2010-10-23 15:21:46 | 000,265,808 | ---- | M] (ArcaBit) -- C:\Documents and Settings\Właściciel\Pulpit\ArcaVirMicroScan\avms.exe

PRC - [2010-10-20 17:33:20 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe

PRC - [2010-10-12 11:08:06 | 000,724,152 | ---- | M] (iolo technologies, LLC) -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe

PRC - [2010-08-24 14:57:38 | 000,188,136 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe

PRC - [2010-08-24 14:57:38 | 000,171,168 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe

PRC - [2010-08-24 14:57:38 | 000,141,792 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\system32\mfevtps.exe

PRC - [2010-04-01 11:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe

PRC - [2010-03-10 10:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

PRC - [2008-12-04 13:24:30 | 000,665,424 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe

PRC - [2008-04-14 19:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe



[color=#E56717]========== Modules (SafeList) ==========[/color]


MOD - [2010-10-23 17:01:20 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Pulpit\OTL_3.2.16.0(dobreprogramy.pl).exe

MOD - [2010-08-23 18:12:53 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll

MOD - [2008-04-14 19:16:32 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx



[color=#E56717]========== Win32 Services (SafeList) ==========[/color]


SRV - File not found [On_Demand | Stopped] -- -- (Tsfs_crtp)

SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)

SRV - [2010-10-12 11:08:06 | 000,724,152 | ---- | M] (iolo technologies, LLC) [Auto | Running] -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe -- (ioloSystemService)

SRV - [2010-10-12 11:08:06 | 000,724,152 | ---- | M] (iolo technologies, LLC) [Auto | Running] -- C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe -- (ioloFileInfoList)

SRV - [2010-08-24 14:57:38 | 000,188,136 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)

SRV - [2010-08-24 14:57:38 | 000,171,168 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)

SRV - [2010-08-24 14:57:38 | 000,141,792 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\WINDOWS\System32\mfevtps.exe -- (mfevtp)

SRV - [2010-08-20 17:44:12 | 000,030,192 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-051210-111108)

SRV - [2010-06-14 15:07:14 | 000,615,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)

SRV - [2010-04-15 09:45:10 | 000,364,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)

SRV - [2010-03-18 16:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -- (aspnet_state)

SRV - [2010-03-18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)

SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2010-03-18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)

SRV - [2010-03-10 10:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (MSK80Service)

SRV - [2010-03-10 10:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)

SRV - [2010-03-10 10:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)

SRV - [2010-03-10 10:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)

SRV - [2010-03-10 10:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)

SRV - [2010-03-10 10:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)



[color=#E56717]========== Driver Services (SafeList) ==========[/color]


DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\PCANDIS5.SYS -- (PCANDIS5)

DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\mfetdi2k.sys -- (mfetdi2k)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\MTiCtwl.sys -- (MagicTune)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\WACICI~1\USTAWI~1\Temp\catchme.sys -- (catchme)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\adiusbaw.sys -- (adiusbaw)

DRV - File not found [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\Drivers\adildr.sys -- (ADILOADER) General Purpose USB Driver (adildr.sys)

DRV - [2010-08-25 17:07:29 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)

DRV - [2010-08-24 14:57:38 | 000,386,712 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)

DRV - [2010-08-24 14:57:38 | 000,312,904 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfefirek.sys -- (mfefirek)

DRV - [2010-08-24 14:57:38 | 000,152,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)

DRV - [2010-08-24 14:57:38 | 000,095,600 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)

DRV - [2010-08-24 14:57:38 | 000,088,544 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfendisk.sys -- (mfendiskmp)

DRV - [2010-08-24 14:57:38 | 000,088,544 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mfendisk.sys -- (mfendisk)

DRV - [2010-08-24 14:57:38 | 000,084,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mferkdet.sys -- (mferkdet)

DRV - [2010-08-24 14:57:38 | 000,055,840 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cfwids.sys -- (cfwids)

DRV - [2010-08-24 14:57:38 | 000,052,104 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)

DRV - [2010-01-13 12:18:36 | 001,730,272 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)

DRV - [2009-12-18 10:58:52 | 000,011,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\SystemRequirementsLab\cpudrv.sys -- (cpudrv)

DRV - [2009-06-30 09:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot)

DRV - [2008-11-11 13:42:00 | 000,024,832 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem)

DRV - [2008-11-11 13:41:00 | 000,019,968 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag)

DRV - [2008-11-11 13:41:00 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus)

DRV - [2008-10-09 15:42:42 | 000,017,408 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\KMWDFILTER.sys -- (KMWDFILTER)

DRV - [2008-08-26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)

DRV - [2008-04-14 14:45:41 | 000,016,376 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)

DRV - [2008-04-13 20:56:49 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)

DRV - [2008-04-13 18:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)

DRV - [2007-09-19 15:44:46 | 000,101,504 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)

DRV - [2007-09-19 11:16:32 | 004,617,728 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2006-07-25 11:47:56 | 000,391,791 | ---- | M] (ZSMC Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZS211.sys -- (ZSMC211) USB PC Camera (ZS211)



[color=#E56717]========== Standard Registry (SafeList) ==========[/color]



[color=#E56717]========== Internet Explorer ==========[/color]


IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 68 2B 18 FD 80 28 CA 01 [binary data]

IE - HKCU\..\URLSearchHook: {08C06D61-F1F3-4799-86F8-BE1A89362C85} - Reg Error: Key error. File not found

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2010-03-06 10:49:30 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010-09-18 14:37:54 | 000,000,000 | ---D | M]


[2010-08-22 18:44:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Extensions

[2010-08-22 18:44:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}


O1 HOSTS File: ([2006-03-02 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()

O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20101021215248.dll (McAfee, Inc.)

O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)

O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)

O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)

O2 - BHO: (no name) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.

O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)

O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)

O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)

O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)

O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)

O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)

O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)

O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)

O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)

O4 - HKCU..\Run: [EPSON SX110 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFBE.EXE (SEIKO EPSON CORPORATION)

O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O9 - Extra 'Tools' menuitem : Ustawienia wtyczki &Gears - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)

O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)

O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)

O16 - DPF: {1E53EA77-34F2-474E-9046-B2B0C86F1821} http://www.eska.pl/streamplayers/OggX.ocx (OggX Control)

O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1246036417906 (MUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl/jinstall-1_4_0_03-win.cab (Java Plug-in 1.4.0_03)

O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)

O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A41} https://www.pekaobiznes24.pl/sme/static/components/SignActivXPEKAO.cab (SignActivX Control)

O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} https://www.bph.pl/pi/components/bph/SignActivX.cab (SignActivX Control)

O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-1_4_0_03-win.cab (Java Plug-in 1.4.0_03)

O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.1.66.0.cab (SysInfo Class)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)

O18 - Protocol\Handler\wpmsg {2E0AC5A0-3597-11D6-B3ED-0001021DC1C3} - C:\Program Files\Spik\url_wpmsg.dll ()

O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)

O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home

O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp

O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp

O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2008-04-14 20:28:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [NTFS]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*


[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]


[2010-10-23 17:01:13 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Pulpit\OTL_3.2.16.0(dobreprogramy.pl).exe

[2010-10-23 15:21:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Dane aplikacji\ArcaVirMicroScan

[2010-10-23 15:21:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Pulpit\ArcaVirMicroScan

[2010-10-23 15:21:28 | 000,265,808 | ---- | C] (ArcaBit) -- C:\Documents and Settings\Właściciel\Pulpit\dobryskaner.exe

[2010-10-21 21:52:48 | 000,009,344 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeclnk.sys

[2010-10-21 21:52:40 | 000,141,792 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\mfevtps.exe

[2010-10-21 21:52:37 | 000,386,712 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys

[2010-10-21 21:52:37 | 000,312,904 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfefirek.sys

[2010-10-21 21:52:37 | 000,152,992 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys

[2010-10-21 21:52:37 | 000,095,600 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeapfk.sys

[2010-10-21 21:52:37 | 000,088,544 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfendisk.sys

[2010-10-21 21:52:37 | 000,084,264 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdet.sys

[2010-10-21 21:52:37 | 000,055,840 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\cfwids.sys

[2010-10-21 21:52:37 | 000,052,104 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfebopk.sys

[2010-10-17 13:12:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\iolo

[2010-10-17 13:12:41 | 002,233,016 | ---- | C] (iolo technologies, LLC) -- C:\WINDOWS\System32\Incinerator.dll

[2010-10-17 13:12:41 | 000,087,688 | ---- | C] (iolo technologies, LLC) -- C:\WINDOWS\System32\IncContxMenu.dll

[2010-10-17 13:12:38 | 000,029,696 | ---- | C] (iolo technologies, LLC) -- C:\WINDOWS\System32\iolobtdfg.exe

[2010-10-17 13:12:38 | 000,011,776 | ---- | C] (iolo technologies, LLC) -- C:\WINDOWS\System32\smrgdf.exe

[2010-10-17 13:12:37 | 000,000,000 | ---D | C] -- C:\Program Files\iolo

[2010-10-17 13:12:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Dane aplikacji\iolo

[2010-10-17 13:12:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\iolo

[2010-10-13 20:21:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Moje dokumenty\BB FlashBack Movies

[2010-10-13 20:21:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Blueberry

[2010-10-13 20:21:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Dane aplikacji\LogSys

[2010-10-13 20:21:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\LogSys

[2010-10-04 16:45:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Gimnazjum

[2010-10-04 16:45:14 | 000,000,000 | ---D | C] -- C:\Program Files\Gimnazjum

[2010-10-04 13:59:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Pulpit\TEST

[2010-10-04 13:55:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\PDF Writer

[2010-10-04 13:55:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Dane aplikacji\PDF Writer

[2010-10-04 13:55:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\PDF Writer

[2010-10-04 13:53:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Moje dokumenty\OTM

[2010-10-04 13:52:04 | 000,227,840 | ---- | C] (Bullzip) -- C:\WINDOWS\System32\bzFlRdr.dll

[2010-10-04 13:52:04 | 000,103,424 | ---- | C] (Bullzip) -- C:\WINDOWS\System32\bzDCT.dll

[2010-10-04 13:52:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Bullzip

[2010-10-04 13:52:03 | 000,135,168 | ---- | C] (Bullzip) -- C:\WINDOWS\System32\bzpdfc.dll

[2010-10-04 13:52:00 | 000,196,096 | ---- | C] (Bullzip) -- C:\WINDOWS\System32\bzpdf.dll

[2010-10-04 13:51:54 | 000,000,000 | ---D | C] -- C:\Program Files\Bullzip

[2010-09-26 19:42:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Pulpit\thunderbird rozszerzenia


[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]


[2010-10-23 17:09:10 | 000,001,152 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-1409082233-839522115-1003UA.job

[2010-10-23 17:01:20 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Pulpit\OTL_3.2.16.0(dobreprogramy.pl).exe

[2010-10-23 16:38:02 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2010-10-23 15:52:24 | 000,000,496 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\Skaner antywirusowy.lnk

[2010-10-23 15:21:33 | 000,265,808 | ---- | M] (ArcaBit) -- C:\Documents and Settings\Właściciel\Pulpit\dobryskaner.exe

[2010-10-23 15:18:43 | 000,001,595 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\McAfee Security Center.lnk

[2010-10-23 15:18:27 | 000,001,040 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2010-10-23 15:18:26 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2010-10-23 15:18:24 | 1062,719,488 | -HS- | M] () -- C:\hiberfil.sys

[2010-10-23 15:18:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2010-10-23 14:45:03 | 003,137,464 | ---- | M] (McAfee, Inc.) -- C:\Documents and Settings\Właściciel\Pulpit\DMSetup-Serial.exe

[2010-10-23 14:44:53 | 000,000,472 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{69588115-945E-4071-9040-6483D3E0E6CC}.job

[2010-10-23 14:41:19 | 000,000,440 | ---- | M] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\spider.sav

[2010-10-21 21:09:00 | 000,001,100 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-1409082233-839522115-1003Core.job

[2010-10-21 18:10:41 | 000,002,341 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\Google Chrome.lnk

[2010-10-20 21:21:37 | 000,449,398 | ---- | M] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\tom 2.pdf

[2010-10-20 21:21:28 | 000,745,683 | ---- | M] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\tom 1.pdf

[2010-10-20 17:36:41 | 000,590,494 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat

[2010-10-20 17:36:41 | 000,504,656 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2010-10-20 17:36:41 | 000,120,082 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat

[2010-10-20 17:36:41 | 000,088,502 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2010-10-17 20:58:21 | 000,269,115 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\translate.googleusercontent.com - translate_c.pdf

[2010-10-17 20:57:02 | 000,242,282 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\en.wikipedia.org - Battle_of_Arras_(1918).pdf

[2010-10-17 20:50:36 | 000,463,100 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\en.wikipedia.org - Battle_of_Arras_(1917).pdf

[2010-10-17 13:42:59 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\System Mechanic.lnk

[2010-10-17 13:13:20 | 000,000,406 | ---- | M] () -- C:\WINDOWS\System32\ioloBootDefrag.cfg

[2010-10-17 13:12:18 | 000,074,703 | ---- | M] () -- C:\WINDOWS\System32\mfc45.dll

[2010-10-15 15:50:54 | 000,271,784 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2010-10-13 17:33:32 | 000,076,523 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\main.aspx

[2010-10-12 21:34:34 | 000,080,212 | ---- | M] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\ofertapracy_01 (1).pdf

[2010-10-12 21:22:11 | 000,907,943 | ---- | M] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\ankieta.pdf

[2010-10-12 21:21:59 | 000,080,212 | ---- | M] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\ofertapracy_01.pdf

[2010-10-12 21:19:09 | 000,260,609 | ---- | M] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\Plansze_przewodnik_historia_g_v1.pdf

[2010-10-12 20:09:10 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Opera.lnk

[2010-10-12 12:55:54 | 000,087,688 | ---- | M] (iolo technologies, LLC) -- C:\WINDOWS\System32\IncContxMenu.dll

[2010-10-12 12:55:18 | 000,011,776 | ---- | M] (iolo technologies, LLC) -- C:\WINDOWS\System32\smrgdf.exe

[2010-10-12 12:55:10 | 000,029,696 | ---- | M] (iolo technologies, LLC) -- C:\WINDOWS\System32\iolobtdfg.exe

[2010-10-12 11:08:52 | 002,233,016 | ---- | M] (iolo technologies, LLC) -- C:\WINDOWS\System32\Incinerator.dll

[2010-10-04 16:46:35 | 000,001,564 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\Gimnazjum.lnk

[2010-10-04 13:52:05 | 000,000,698 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\Bullzip PDF Printer.lnk

[2010-10-04 13:51:12 | 004,532,364 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\BullzipPDFPrinter_7_1_0_1218.zip

[2010-09-28 21:54:13 | 000,055,337 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\Wymagania na poszczególne oceny.docx

[2010-09-27 15:28:06 | 000,196,096 | ---- | M] (Bullzip) -- C:\WINDOWS\System32\bzpdf.dll

[2010-09-27 15:27:58 | 000,135,168 | ---- | M] (Bullzip) -- C:\WINDOWS\System32\bzpdfc.dll

[2010-09-26 21:52:35 | 000,089,600 | ---- | M] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\Jak zdobywać informacje i jak z nich korzystać.doc

[2010-09-26 21:51:19 | 000,022,553 | ---- | M] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\Edukacja filozoficzna.docx


[color=#E56717]========== Files Created - No Company Name ==========[/color]


[2010-10-23 15:52:24 | 000,000,496 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\Skaner antywirusowy.lnk

[2010-10-23 15:18:24 | 1062,719,488 | -HS- | C] () -- C:\hiberfil.sys

[2010-10-20 21:21:34 | 000,449,398 | ---- | C] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\tom 2.pdf

[2010-10-20 21:21:22 | 000,745,683 | ---- | C] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\tom 1.pdf

[2010-10-20 17:33:47 | 000,001,036 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2010-10-17 20:57:02 | 000,242,282 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\en.wikipedia.org - Battle_of_Arras_(1918).pdf

[2010-10-17 20:53:50 | 000,269,115 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\translate.googleusercontent.com - translate_c.pdf

[2010-10-17 20:50:36 | 000,463,100 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\en.wikipedia.org - Battle_of_Arras_(1917).pdf

[2010-10-17 13:13:20 | 000,000,406 | ---- | C] () -- C:\WINDOWS\System32\ioloBootDefrag.cfg

[2010-10-17 13:12:41 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\System Mechanic.lnk

[2010-10-17 13:12:18 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll

[2010-10-13 17:33:32 | 000,076,523 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\main.aspx

[2010-10-12 21:34:33 | 000,080,212 | ---- | C] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\ofertapracy_01 (1).pdf

[2010-10-12 21:22:04 | 000,907,943 | ---- | C] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\ankieta.pdf

[2010-10-12 21:19:14 | 000,080,212 | ---- | C] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\ofertapracy_01.pdf

[2010-10-11 21:07:27 | 000,260,609 | ---- | C] () -- C:\Documents and Settings\Właściciel\Moje dokumenty\Plansze_przewodnik_historia_g_v1.pdf

[2010-10-04 16:46:35 | 000,001,564 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\Gimnazjum.lnk

[2010-10-04 13:52:05 | 000,000,698 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\Bullzip PDF Printer.lnk

[2010-10-04 13:51:11 | 004,532,364 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\BullzipPDFPrinter_7_1_0_1218.zip

[2010-09-29 14:12:11 | 000,160,217 | ---- | C] () -- C:\WINDOWS\System32\PowerToysLicense.rtf

[2010-09-28 21:54:11 | 000,055,337 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\Wymagania na poszczególne oceny.docx

[2010-08-25 17:07:29 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2010-08-21 18:43:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI

[2010-08-21 12:35:45 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini

[2010-07-22 19:45:12 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll

[2010-07-22 19:45:12 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll

[2010-07-22 19:45:12 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll

[2009-12-18 14:59:08 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\fusioncache.dat

[2009-09-26 16:49:25 | 000,000,241 | ---- | C] () -- C:\WINDOWS\SIERRA.INI

[2009-08-29 18:24:30 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2009-07-31 12:21:59 | 000,033,792 | ---- | C] () -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009-07-30 16:56:57 | 000,000,090 | ---- | C] () -- C:\WINDOWS\Route.INI

[2009-04-27 17:30:56 | 000,000,021 | ---- | C] () -- C:\WINDOWS\kit.ini

[2009-02-28 13:01:21 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\WLANUTL.dll

[2009-02-08 13:15:46 | 000,041,068 | ---- | C] () -- C:\WINDOWS\System32\ActPanel.dll

[2009-01-14 18:50:06 | 000,000,556 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2008-05-26 22:22:36 | 000,016,222 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini

[2008-05-26 22:22:34 | 000,021,728 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini

[2008-05-26 22:22:32 | 000,016,164 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini

[2008-04-14 22:21:10 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2008-04-14 20:42:47 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4864.dll

[2000-01-07 23:34:10 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\pagesync.dll


< End of report >

Witam !

1- W systemie może być zainstalowany tylko jeden antywirus. Z analizy loga widać, że była instalowana Panda Internet Security. Jeżeli de-instalacja nie została przeprowadzono do końca, pozostały zapisy od Panda Internet Security, praca i tryb aktualizacji MCAfee będą blokowane.

2- Proszę oczyścić całkowicie Rejestr z pozostałości po Panda Internet Security. Można do tego wykorzystać program jv16 Power Tools 1.3 \ Opcje rejestru \ Programy \ Narzędzia \ Wyszukiwanie w rejestrze \ ( w powstałe okienko wpisać Panda, w następnym - Wybierz które klucze mają być przeszukane - zaznaczyć wszystkie pozycje ).