Problem z pingiem oraz pakietami


(Korsky1) #1

Witam od ponad tygodnia mam problem z internetem, otoz mam wiecej pakietow wyslanych niz odebranych oraz skaczacy ping (http://www.bankfotek.pl/view/520790). Podam wam logi z Hijackthis, poniewaz sam nie wiem ktore nalezy usunac ktore nie i mysle ze mi pomozecie :wink:. Dodam jeszcze ze ping mam normalny od 15 do 16 i potem dopiero znow od 24 do rana i tak codziennie. A czasem bywa tak ze przez 3 minuty mam normalny ping, potem wysoki przez 15 min i potem normalny przez 10 min.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:24:30, on 2010-01-31

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\Program Files\Razer\DeathAdder\razerhid.exe

C:\Program Files\Search Settings\SearchSettings.exe

D:\Winamp\winampa.exe

C:\Program Files\Gadu-Gadu\gg.exe

C:\Program Files\Save\Save.exe

C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe

C:\Program Files\Application Updater\ApplicationUpdater.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\Program Files\Razer\DeathAdder\razertra.exe

C:\Program Files\Razer\DeathAdder\razerofa.exe

C:\WINDOWS\system32\wscntfy.exe

D:\Winamp\winamp.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\cmd.exe

C:\WINDOWS\system32\ping.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.myquickfinder.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=%s

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll

R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll

R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll

O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Automated Content Enhancer - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.1.0.5260\ACEIEAddOn.dll

O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll

O2 - BHO: Content Management Wizard - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - C:\Program Files\Content Management Wizard\1.1.0.1950\CMWIE.dll

O2 - BHO: Textual Content Provider - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - C:\Program Files\Textual Content Provider\1.1.0.1810\TCPIE.dll

O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll

O3 - Toolbar: Gameztar Toolbar - {D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2} - C:\Program Files\Gameztar Toolbar\2.1.3.6670\mvb0.dll

O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll

O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM..\Run: [GEST] m‘|\ü

O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"

O4 - HKLM..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe

O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM..\Run: [searchSettings] C:\Program Files\Search Settings\SearchSettings.exe

O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM..\Run: [WinampAgent] D:\Winamp\winampa.exe

O4 - HKCU..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray

O4 - HKCU..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep"

O4 - HKCU..\Run: [Octoshape Streaming Services] "C:\Documents and Settings\Intel\Dane aplikacji\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun

O4 - HKCU..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe

O4 - HKCU..\Run: [steam] "D:\stimek\Steam.exe" -silent

O4 - HKCU..\Run: [CPU_Control] C:\Program Files\CPU-Control\CPU_Control.exe

O4 - HKCU..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"

O4 - HKCU..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup

O4 - HKUS\S-1-5-19..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')

O4 - HKUS\S-1-5-20..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,wbsys.dll

O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe

O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--

End of file - 7122 bytes


(djkamil09061991) #2

wyczyść autostart ze zbędników, masz tam wiele niepotrzebnych rzeczy. Daj log z OTL otl-gmer-rsit-dds-inne-instrukcje-t370405.html


(Korsky1) #3

OTL logfile created on: 2010-01-31 14:20:54 - Run 1

OTL by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\Intel\Pulpit

Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 72,00% Memory free

4,00 Gb Paging File | 3,00 Gb Available in Paging File | 88,00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 74,70 Gb Total Space | 44,33 Gb Free Space | 59,34% Space Free | Partition Type: NTFS

Drive D: | 74,34 Gb Total Space | 71,65 Gb Free Space | 96,38% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: INTEL-7389F9D66

Current User Name: Intel

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: On

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Processes (SafeList) ==========

PRC - [2010-01-31 14:19:04 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Intel\Pulpit\OTL.exe

PRC - [2010-01-18 21:10:47 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe

PRC - [2010-01-08 01:36:58 | 000,974,848 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Search Settings\SearchSettings.exe

PRC - [2010-01-08 00:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe

PRC - 2010-01-06 15:33:06 | 002,335,952 | ---- | M -- C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe

PRC - 2009-12-18 01:31:52 | 001,551,712 | ---- | M -- D:\Winamp\winamp.exe

PRC - 2009-12-18 01:30:48 | 000,039,424 | ---- | M -- D:\Winamp\winampa.exe

PRC - 2009-09-24 11:00:30 | 000,075,064 | ---- | M -- C:\WINDOWS\system32\PnkBstrA.exe

PRC - [2008-08-02 05:20:00 | 000,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe

PRC - [2008-03-20 11:04:46 | 002,127,296 | ---- | M] (Gadu-Gadu S.A.) -- C:\Program Files\Gadu-Gadu\gg.exe

PRC - [2008-02-13 07:31:34 | 016,857,600 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe

PRC - 2007-09-07 14:54:54 | 000,159,744 | ---- | M -- C:\Program Files\Razer\DeathAdder\razerhid.exe

PRC - [2007-05-07 14:35:14 | 000,163,840 | ---- | M] (Razer Inc.) -- C:\Program Files\Razer\DeathAdder\razerofa.exe

PRC - 2006-11-24 14:24:16 | 000,143,360 | ---- | M -- C:\Program Files\Razer\DeathAdder\razertra.exe

PRC - [2006-08-25 14:45:12 | 000,803,184 | ---- | M] (WhenU.com, Inc.) -- C:\Program Files\Save\Save.exe

PRC - [2005-12-05 01:39:19 | 000,461,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliPoint\ipoint.exe

PRC - [2004-08-03 23:44:30 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe

PRC - [2004-08-03 23:44:26 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ping.exe

PRC - [2004-08-03 23:44:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2004-08-03 23:44:18 | 000,395,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe

========== Modules (SafeList) ==========

MOD - [2010-01-31 14:19:04 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Intel\Pulpit\OTL.exe

MOD - [2006-12-21 13:30:44 | 000,102,400 | ---- | M] (Gadu-Gadu S.A.) -- C:\Program Files\Gadu-Gadu\ggwhook.dll

MOD - [2004-08-03 23:42:34 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll

MOD - [2003-02-26 22:27:44 | 000,036,864 | ---- | M] (Stardock.Net, Inc) -- C:\WINDOWS\system32\wbsys.dll

MOD - [2003-02-26 22:24:32 | 000,028,740 | ---- | M] (Stardock.Net, Inc) -- C:\Program Files\AlienGUIse\wbhelp.dll

========== Win32 Services (SafeList) ==========

SRV - [2010-01-08 00:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)

SRV - 2009-09-24 11:00:30 | 000,075,064 | ---- | M [Auto | Running] -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA)

SRV - 2009-04-15 15:20:36 | 001,838,592 | ---- | M [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager)

SRV - [2008-08-02 05:20:00 | 000,163,908 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)

SRV - [2007-06-27 18:04:00 | 000,279,848 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)

========== Driver Services (SafeList) ==========

DRV - [2009-12-03 11:17:48 | 000,024,504 | ---- | M] (Turtle Entertainment GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ESLvnic.sys -- (ESLvnic1)

DRV - [2009-04-28 21:20:06 | 000,044,944 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)

DRV - [2008-12-21 21:52:16 | 000,016,608 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)

DRV - [2008-08-02 05:20:00 | 006,121,856 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)

DRV - [2008-02-14 10:04:06 | 004,676,096 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2008-01-03 15:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)

DRV - [2007-11-15 21:30:48 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\npf.sys -- (npf)

DRV - [2007-09-21 02:11:02 | 000,028,432 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt)

DRV - [2007-09-21 02:10:46 | 000,036,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)

DRV - [2007-09-21 02:10:40 | 000,035,088 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)

DRV - [2007-08-02 16:32:26 | 000,022,784 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dadder.sys -- (DAdderFltr)

DRV - [2005-12-02 00:57:56 | 000,021,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\point32.sys -- (Point32)

DRV - [2005-01-07 17:07:18 | 000,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)

DRV - [2004-08-03 23:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) Sterownik audio USB (WDM)

DRV - 2004-07-17 10:36:38 | 000,027,440 | ---- | M [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)

DRV - [2001-08-17 22:49:56 | 000,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKLM..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.myquickfinder.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)

IE - HKCU..\URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()

IE - HKCU..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll (Spigot, Inc.)

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Winamp Search"

FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="

FF - prefs.js..browser.search.order.1: "Ask"

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034"

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..browser.startup.homepage: "http://home.myquickfinder.com/"

FF - prefs.js..extensions.enabledItems: {8141440E-08F0-4339-9959-5C31C6A69F23}:4.1.0.5260

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1

FF - prefs.js..extensions.enabledItems: {E889F097-B0BE-471B-89AD-B86B6F04B506}:4.1.0.1850

FF - prefs.js..extensions.enabledItems: dealio@mybrowserbar.com:4.0.2

FF - prefs.js..extensions.enabledItems: {40f1eb95-4de4-4f36-a826-054ee36bb905}:2.1.3.0

FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.736

FF - prefs.js..extensions.enabledItems: {F2DDDB92-1605-4260-9B25-45A4DAE87B50}:1.0

FF - prefs.js..extensions.enabledItems: searchsettings@spigot.com:1.2.3

FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3789

FF - prefs.js..extensions.enabledItems: {E63605FC-D583-4C81-867F-9457BDB3EA1B}:4.1.0.1990

FF - prefs.js..keyword.URL: "http://toolbar.ask.com/toolbarv/askRedirect?o=13757&gct=&gc=1&q="

FF - HKLM\software\mozilla\Firefox\Extensions\{40f1eb95-4de4-4f36-a826-054ee36bb905}: C:\Program Files\Gameztar Toolbar\2.1.3.6670\FFToolbar [2009-12-10 15:36:35 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\Extensions\{E63605FC-D583-4C81-867F-9457BDB3EA1B}: C:\Program Files\Web Search Operator\4.1.0.1990\FF [2009-12-10 15:36:42 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\Extensions\{8141440E-08F0-4339-9959-5C31C6A69F23}: C:\Program Files\Automated Content Enhancer\4.1.0.5260\FF [2009-12-10 15:36:46 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\Extensions\{E889F097-B0BE-471B-89AD-B86B6F04B506}: C:\Program Files\Customized Platform Advancer\4.1.0.1850\FF [2009-12-10 15:36:51 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\Components: C:\Program Files\Mozilla Firefox\components [2010-01-30 23:19:04 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-01-30 23:19:04 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Thunderbird\Extensions\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010-01-25 16:51:33 | 000,000,000 | ---D | M]

[2009-02-09 23:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Intel\Dane aplikacji\Mozilla\Extensions

[2010-01-30 14:25:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Intel\Dane aplikacji\Mozilla\Firefox\Profiles\y62i6at2.default\extensions

[2009-04-11 13:54:59 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Intel\Dane aplikacji\Mozilla\Firefox\Profiles\y62i6at2.default\extensions{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}

2009-06-02 19:27:00 | 000,000,681 | ---- | M -- C:\Documents and Settings\Intel\Dane aplikacji\Mozilla\Firefox\Profiles\y62i6at2.default\searchplugins\ask.xml

2009-09-17 13:23:14 | 000,001,196 | ---- | M -- C:\Documents and Settings\Intel\Dane aplikacji\Mozilla\Firefox\Profiles\y62i6at2.default\searchplugins\winamp-search.xml

[2010-01-31 13:45:32 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

2010-01-23 01:16:38 | 000,000,000 | ---D | M -- C:\Program Files\Mozilla Firefox\extensions{F2DDDB92-1605-4260-9B25-45A4DAE87B50}

[2010-01-25 15:04:58 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru

2009-12-18 01:31:54 | 000,063,488 | ---- | M -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

2010-01-18 21:10:54 | 000,002,767 | ---- | M -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml

2010-01-18 21:10:54 | 000,001,406 | ---- | M -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml

2010-01-18 21:10:54 | 000,000,917 | ---- | M -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml

2010-01-18 21:10:54 | 000,000,858 | ---- | M -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml

2009-12-10 16:12:55 | 000,002,405 | ---- | M -- C:\Program Files\Mozilla Firefox\searchplugins\questservice129.xml

2010-01-23 01:16:38 | 000,002,405 | ---- | M -- C:\Program Files\Mozilla Firefox\searchplugins\questservice137.xml

2010-01-18 21:10:54 | 000,001,183 | ---- | M -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml

2010-01-18 21:10:54 | 000,001,683 | ---- | M -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2009-09-07 20:09:51 | 000,000,776 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O1 - Hosts: 127.0.0.1 http://www.multihack.pl

O2 - BHO: (Dealio Toolbar) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll (Spigot, Inc.)

O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (Automated Content Enhancer) - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.1.0.5260\ACEIEAddOn.dll ()

O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)

O2 - BHO: (Content Management Wizard) - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - C:\Program Files\Content Management Wizard\1.1.0.1950\CMWIE.dll ()

O2 - BHO: (Textual Content Provider) - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - C:\Program Files\Textual Content Provider\1.1.0.1810\TCPIE.dll ()

O2 - BHO: (SearchSettings Class) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll (Spigot, Inc.)

O3 - HKLM..\Toolbar: (Dealio Toolbar) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll (Spigot, Inc.)

O3 - HKLM..\Toolbar: (Gameztar Toolbar) - {D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2} - C:\Program Files\Gameztar Toolbar\2.1.3.6670\mvb0.dll ()

O3 - HKLM..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)

O3 - HKCU..\Toolbar\WebBrowser: (Gameztar Toolbar) - {D45817B8-3EAD-4D1D-8FCA-EC63A8E35DE2} - C:\Program Files\Gameztar Toolbar\2.1.3.6670\mvb0.dll ()

O3 - HKCU..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)

O4 - HKLM..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe ()

O4 - HKLM..\Run: [GEST] File not found

O4 - HKLM..\Run: [intelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)

O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)

O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)

O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)

O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [searchSettings] C:\Program Files\Search Settings\SearchSettings.exe (Spigot, Inc.)

O4 - HKLM..\Run: [WinampAgent] D:\Winamp\winampa.exe (Nullsoft)

O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)

O4 - HKCU..\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe ()

O4 - HKCU..\Run: [CPU_Control] C:\Program Files\CPU-Control\CPU_Control.exe ()

O4 - HKCU..\Run: [Gadu-Gadu] C:\Program Files\Gadu-Gadu\gg.exe (Gadu-Gadu S.A.)

O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Documents and Settings\Intel\Dane aplikacji\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)

O4 - HKCU..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe (Franmo Software)

O4 - HKCU..\Run: [steam] D:\stimek\Steam.exe (Valve Corporation)

O4 - HKCU..\Run: [WhenUSave] C:\Program Files\Save\Save.exe (WhenU.com, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStrCmpLogical = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoTrayNotify = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()

O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\NPJPI150_05.dll (Sun Microsystems, Inc.)

O15 - HKLM..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKCU..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.100

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)

O20 - AppInit_DLLs: (wbsys.dll) - C:\WINDOWS\System32\wbsys.dll (Stardock.Net, Inc)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock)

O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\Intel\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Intel\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - 2008-12-21 21:44:09 | 000,000,000 | ---- | M - C:\AUTOEXEC.BAT -- [NTFS]

O33 - MountPoints2{5b345848-d065-11de-9794-001fd00ea4f4}\Shell\AutoRun\command - "" = F:\Launcher.exe -- File not found

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] -- "%1" %*

O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

File not found -- C:\Documents and Settings\Intel\Pulpit\notatka

File not found -- C:\Documents and Settings\Intel\Pulpit\Beyonce feat. Jay-Z - Deja Vu

[2010-01-31 14:18:59 | 000,548,864 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Intel\Pulpit\OTL.exe

[2010-01-31 12:10:45 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro

[2010-01-30 23:19:52 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_42.dll

[2010-01-30 23:19:51 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_32.dll

[2010-01-30 23:19:41 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_31.dll

[2010-01-30 23:19:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs

[2010-01-30 23:18:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Dane aplikacji\Winamp

[2010-01-30 22:59:24 | 000,000,000 | ---D | C] -- C:\Program Files\IObit

[2010-01-30 22:59:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Dane aplikacji\IObit

[2010-01-30 22:41:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss

[2010-01-29 13:05:50 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Intel\IETldCache

[2010-01-29 12:52:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates

[2010-01-29 12:52:07 | 011,070,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll

[2010-01-29 12:52:07 | 001,985,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll

[2010-01-29 12:52:07 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll

[2010-01-29 12:52:07 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll

[2010-01-29 12:51:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM

[2010-01-29 12:50:53 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8

[2010-01-29 12:50:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\pl-PL

[2010-01-29 03:03:39 | 000,000,000 | ---D | C] -- C:\Program Files\Save

[2010-01-29 03:03:24 | 000,000,000 | ---D | C] -- C:\Program Files\Turbo Internet Booster

[2010-01-29 02:55:41 | 000,000,000 | ---D | C] -- C:\Program Files\PingPlotter Pro

[2010-01-27 11:59:12 | 000,000,000 | ---D | C] -- C:\Program Files\Szotgan Software

[2010-01-27 11:50:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Grisoft

[2010-01-26 18:46:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\KB905474

[2010-01-26 18:40:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles

[2010-01-26 18:40:02 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0

[2010-01-26 13:57:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak

[2010-01-26 13:04:27 | 000,273,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys

[2010-01-26 12:27:10 | 002,181,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe

[2010-01-26 12:27:10 | 002,137,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe

[2010-01-26 12:27:10 | 002,059,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe

[2010-01-26 12:27:09 | 002,017,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe

[2010-01-26 12:17:59 | 000,453,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys

[2010-01-26 03:00:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall

[2010-01-25 22:17:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Dane aplikacji\CPUControl

[2010-01-25 22:17:21 | 000,000,000 | ---D | C] -- C:\Program Files\CPU-Control

[2010-01-25 22:07:44 | 000,051,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\imagecfg.exe

[2010-01-25 18:26:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Pulpit\kojarze

[2010-01-25 15:56:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution

[2010-01-25 15:03:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab

[2010-01-25 14:21:37 | 000,000,000 | ---D | C] -- C:\Program Files\WinPcap

[2010-01-25 14:09:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\37061017

[2010-01-25 12:02:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Ustawienia lokalne\Dane aplikacji\ESET

[2010-01-25 12:01:58 | 000,000,000 | ---D | C] -- C:\Program Files\ESET

[2010-01-25 12:01:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\ESET

[2010-01-24 21:27:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Dane aplikacji\TS3Client

[2010-01-24 21:27:02 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client

[2010-01-21 18:20:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Blizzard Entertainment

[2010-01-20 15:31:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Blizzard

[2010-01-20 15:01:59 | 000,000,000 | ---D | C] -- C:\World of Warcraft

[2010-01-20 14:53:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Ustawienia lokalne\Dane aplikacji\Blizzard Entertainment

[2010-01-20 14:50:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment

[2010-01-19 15:15:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Moje dokumenty\Pobieranie

[2010-01-16 22:25:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Pulpit\gb5

[2010-01-16 22:25:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Pulpit\gb4

[2010-01-16 22:25:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Pulpit\gb3

[2010-01-16 22:25:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Pulpit\gb2

[2010-01-16 22:25:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Pulpit\gb

[2010-01-12 15:32:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Dane aplikacji\Search Settings

[2010-01-12 15:32:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Intel\Dane aplikacji\Dealio

[2010-01-12 15:30:26 | 000,000,000 | ---D | C] -- C:\Program Files\Dealio Toolbar

[2010-01-12 15:29:50 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater

[2010-01-01 18:01:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NSS

[2010-01-01 18:01:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NSS\0207000.034

[2009-02-23 22:06:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Apple

[2008-12-21 21:46:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft

[2008-12-21 21:46:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft

[2008-12-21 21:44:07 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji\Microsoft

[2008-12-21 21:44:07 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Microsoft

[1 C:\Program Files*.tmp files -> C:\Program Files*.tmp ->]

========== Files - Modified Within 30 Days ==========

File not found -- C:\Documents and Settings\Intel\Pulpit\notatka

File not found -- C:\Documents and Settings\Intel\Pulpit\Beyonce feat. Jay-Z - Deja Vu

2010-01-31 14:22:29 | 000,763,904 | ---- | M -- C:\WINDOWS\System32\drivers\agubwhz.sys

[2010-01-31 14:19:04 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Intel\Pulpit\OTL.exe

2010-01-31 12:31:29 | 000,000,625 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\World of Warcraft.lnk

2010-01-31 12:20:22 | 000,079,026 | ---- | M -- C:\Documents and Settings\Intel\Pulpit\bez tytułu.JPG

2010-01-31 12:10:45 | 000,001,740 | ---- | M -- C:\Documents and Settings\Intel\Pulpit\HijackThis.lnk

2010-01-31 12:04:32 | 000,000,260 | ---- | M -- C:\WINDOWS\tasks\WGASetup.job

2010-01-31 12:04:12 | 000,203,347 | ---- | M -- C:\WINDOWS\System32\nvapps.xml

2010-01-31 12:04:07 | 000,000,006 | -H-- | M -- C:\WINDOWS\tasks\SA.DAT

2010-01-31 12:04:04 | 000,002,048 | --S- | M -- C:\WINDOWS\bootstat.dat

2010-01-31 03:32:12 | 010,747,904 | ---- | M -- C:\Documents and Settings\Intel\NTUSER.DAT

2010-01-31 03:31:59 | 006,409,000 | -H-- | M -- C:\Documents and Settings\Intel\Ustawienia lokalne\Dane aplikacji\IconCache.db

2010-01-30 23:20:01 | 000,000,440 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\Winamp.lnk

2010-01-30 23:19:01 | 000,000,286 | ---- | M -- C:\Documents and Settings\Intel\Pulpit\50 FREE MP3s +1 Free Audiobook!.lnk

2010-01-30 23:14:03 | 000,002,163 | ---- | M -- C:\Documents and Settings\Intel\Pulpit\Ventrilo.lnk

2010-01-30 23:01:46 | 000,000,188 | -HS- | M -- C:\Documents and Settings\Intel\ntuser.ini

2010-01-30 22:43:04 | 000,000,477 | ---- | M -- C:\WINDOWS\win.ini

2010-01-30 22:43:04 | 000,000,227 | ---- | M -- C:\WINDOWS\system.ini

2010-01-30 22:43:04 | 000,000,211 | -HS- | M -- C:\boot.ini

2010-01-30 22:14:36 | 000,002,033 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\Steam.lnk

2010-01-30 14:27:01 | 000,000,558 | ---- | M -- C:\WINDOWS\tasks\Norton Security Scan for Intel.job

2010-01-29 12:52:58 | 000,001,374 | ---- | M -- C:\WINDOWS\imsins.BAK

2010-01-28 12:10:52 | 000,490,628 | ---- | M -- C:\WINDOWS\System32\perfh015.dat

2010-01-28 12:10:52 | 000,432,492 | ---- | M -- C:\WINDOWS\System32\perfh009.dat

2010-01-28 12:10:52 | 000,083,880 | ---- | M -- C:\WINDOWS\System32\perfc015.dat

2010-01-28 12:10:51 | 000,067,448 | ---- | M -- C:\WINDOWS\System32\perfc009.dat

2010-01-28 12:10:49 | 001,087,636 | ---- | M -- C:\WINDOWS\System32\PerfStringBackup.INI

2010-01-27 18:44:00 | 000,000,284 | ---- | M -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

2010-01-27 12:06:06 | 065,109,832 | ---- | M -- C:\Documents and Settings\Intel\Pulpit\przywrocane chybaaaaaa.reg

2010-01-27 11:59:15 | 000,000,877 | ---- | M -- C:\Documents and Settings\Intel\Pulpit\RegSweeper.lnk

2010-01-27 01:20:41 | 000,016,896 | ---- | M -- C:\Documents and Settings\Intel\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT

2010-01-27 01:19:08 | 000,114,968 | ---- | M -- C:\WINDOWS\System32\FNTCACHE.DAT

2010-01-26 20:20:36 | 000,000,069 | ---- | M -- C:\WINDOWS\NeroDigital.ini

2010-01-25 22:07:11 | 000,024,539 | ---- | M -- C:\WINDOWS\System32\Imagecfg.zip

2010-01-25 22:04:04 | 000,012,288 | ---- | M -- C:\Documents and Settings\Intel\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

2010-01-25 18:40:46 | 000,000,597 | ---- | M -- C:\Documents and Settings\Intel\Pulpit\Counter-Strike.lnk

2010-01-25 15:19:09 | 000,041,890 | ---- | M -- C:\Documents and Settings\Intel\Menu Start.rar

2010-01-24 21:27:06 | 000,000,843 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\TeamSpeak 3 Client.lnk

2010-01-24 11:34:35 | 000,002,206 | ---- | M -- C:\WINDOWS\System32\wpa.dbl

2010-01-24 00:06:19 | 000,000,289 | ---- | M -- C:\Documents and Settings\Intel\Pulpit\aequitas.ini

2010-01-22 20:40:27 | 000,000,655 | ---- | M -- C:\Documents and Settings\All Users\Pulpit\ESL Wire.lnk

2010-01-21 14:11:26 | 000,000,888 | ---- | M -- C:\Documents and Settings\Intel\Pulpit\World of Warcraft Installer.lnk

2010-01-12 19:33:40 | 000,010,911 | ---- | M -- C:\Documents and Settings\Intel\Pulpit\l.JPG

2010-01-08 20:00:34 | 000,002,760 | ---- | M -- C:\WINDOWS\wincmd.ini

2010-01-08 19:39:44 | 000,000,301 | ---- | M -- C:\WINDOWS\wcx_ftp.ini

2010-01-01 18:01:22 | 000,000,172 | ---- | M -- C:\WINDOWS\System32\drivers\NSS\0207000.034\isolate.ini

[1 C:\Program Files*.tmp files -> C:\Program Files*.tmp ->]

========== Files Created - No Company Name ==========

2010-01-31 12:10:45 | 000,001,740 | ---- | C -- C:\Documents and Settings\Intel\Pulpit\HijackThis.lnk

2010-01-30 23:19:01 | 000,000,286 | ---- | C -- C:\Documents and Settings\Intel\Pulpit\50 FREE MP3s +1 Free Audiobook!.lnk

2010-01-27 12:06:02 | 065,109,832 | ---- | C -- C:\Documents and Settings\Intel\Pulpit\przywrocane chybaaaaaa.reg

2010-01-27 11:59:15 | 000,000,877 | ---- | C -- C:\Documents and Settings\Intel\Pulpit\RegSweeper.lnk

2010-01-26 18:46:16 | 000,000,260 | ---- | C -- C:\WINDOWS\tasks\WGASetup.job

2010-01-25 22:07:10 | 000,024,539 | ---- | C -- C:\WINDOWS\System32\Imagecfg.zip

2010-01-25 18:40:46 | 000,000,597 | ---- | C -- C:\Documents and Settings\Intel\Pulpit\Counter-Strike.lnk

2010-01-25 18:31:21 | 000,002,033 | ---- | C -- C:\Documents and Settings\All Users\Pulpit\Steam.lnk

2010-01-25 11:34:18 | 000,000,016 | ---- | C -- C:\Documents and Settings\Intel\Dane aplikacji\wiaserva.log

2010-01-24 21:27:06 | 000,000,843 | ---- | C -- C:\Documents and Settings\All Users\Pulpit\TeamSpeak 3 Client.lnk

2010-01-24 11:36:12 | 000,763,904 | ---- | C -- C:\WINDOWS\System32\drivers\agubwhz.sys

2010-01-20 15:31:51 | 000,000,888 | ---- | C -- C:\Documents and Settings\Intel\Pulpit\World of Warcraft Installer.lnk

2010-01-20 15:01:59 | 000,000,625 | ---- | C -- C:\Documents and Settings\All Users\Pulpit\World of Warcraft.lnk

2010-01-17 11:29:47 | 000,079,026 | ---- | C -- C:\Documents and Settings\Intel\Pulpit\bez tytułu.JPG

2010-01-01 18:01:21 | 000,000,172 | ---- | C -- C:\WINDOWS\System32\drivers\NSS\0207000.034\isolate.ini

2009-11-01 21:11:06 | 000,000,056 | ---- | C -- C:\WINDOWS\wb.ini

2009-09-24 11:46:40 | 000,138,944 | ---- | C -- C:\WINDOWS\System32\drivers\PnkBstrK.sys

2009-06-22 16:31:32 | 000,000,760 | ---- | C -- C:\Documents and Settings\Intel\Dane aplikacji\setup_ldm.iss

2009-01-06 16:16:23 | 000,000,327 | ---- | C -- C:\WINDOWS\RefreshLock.ini

2009-01-02 20:02:09 | 000,000,301 | ---- | C -- C:\WINDOWS\wcx_ftp.ini

2009-01-02 19:58:37 | 000,002,760 | ---- | C -- C:\WINDOWS\wincmd.ini

2008-12-24 12:46:14 | 000,000,069 | ---- | C -- C:\WINDOWS\NeroDigital.ini

2008-12-24 12:46:13 | 000,012,288 | ---- | C -- C:\Documents and Settings\Intel\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

2008-12-22 18:16:19 | 000,001,125 | ---- | C -- C:\WINDOWS\winamp.ini

2008-08-02 05:20:00 | 001,724,416 | ---- | C -- C:\WINDOWS\System32\nvwdmcpl.dll

2008-08-02 05:20:00 | 001,499,136 | ---- | C -- C:\WINDOWS\System32\nview.dll

2008-08-02 05:20:00 | 001,101,824 | ---- | C -- C:\WINDOWS\System32\nvwimg.dll

2008-08-02 05:20:00 | 000,466,944 | ---- | C -- C:\WINDOWS\System32\nvshell.dll

2008-08-02 05:20:00 | 000,286,720 | ---- | C -- C:\WINDOWS\System32\nvnt4cpl.dll

2006-04-23 00:00:10 | 000,053,299 | ---- | C -- C:\WINDOWS\System32\pthreadVC.dll

2004-07-17 10:36:38 | 000,027,440 | ---- | C -- C:\WINDOWS\System32\drivers\secdrv.sys

2002-10-06 19:42:58 | 000,237,568 | ---- | C -- C:\WINDOWS\System32\OggDS.dll

2002-10-05 00:04:26 | 000,921,600 | ---- | C -- C:\WINDOWS\System32\vorbisenc.dll

2002-10-05 00:04:26 | 000,188,416 | ---- | C -- C:\WINDOWS\System32\vorbis.dll

2002-10-05 00:04:18 | 000,045,056 | ---- | C -- C:\WINDOWS\System32\ogg.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 500 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:05EE1EEF

< End of report >


(bibut) #4

napraw łącze programem XP TCP/IP repair 2.0


(Gutek) #5

Zastosuj się do tego Tematu i zmień tytuł tematu na konkretny.

Pozdrawiam Gutek

Zmiana zasad wklejania logów na forum - viewtopic.php?f=16&t=253052

Uruchom OTL i w oknie Custom Scans/Fixes wklej to:

Kliknij w Run Fix. Zatwierdź restart komputera.

Następnie uruchom OTL ponownie, tym razem wywołaj opcję Run Scan.

Pokaż nowy log OTL.txt oraz log z czyszczenia.


(Korsky1) #6

Tutaj jest ten log utworzony po restarcie komputera http://www.wklej.eu/index.php?id=8953b21d0a

a tutaj OTL.txt http://www.wklej.eu/index.php?id=cb91702d25


(Gutek) #7

Uruchom OTL i w oknie Custom Scans/Fixes wklej to:

Kliknij w Run Fix. Zatwierdź restart komputera.

Następnie uruchom OTL ponownie, w OTL kliknij na przycisk CleanUp.

Pobierz GMER

W GMER nic nie zmieniasz-> wciskasz Szukaj (odczekaj swoje) -> po skanie Kopiuj.

>>>> otl-gmer-rsit-dds-inne-instrukcje-t370405.html


(Korsky1) #8

i to wszystko ??


(Gutek) #9

Log z Gmera - masz link wyżej.