Sprawdzenie logów. Minimalne użycie procesora 50%


(Jonatandragon) #1

Bardzo proszę o sprawdzenie logów: http://www.wklejto.pl/42917

Od paru dni procesor jest ciągle(nawet w stanie spoczynku) używany w co najmniej 50%. Gry się zawieszają, i ogólnie komputer muli.

Nie wiem czy to na coś się przyda, ale tu trochę informacji o moim komputerze:

Windows XP Home + wszystkie aktualizacje

Mój sprzęt:

Core 2 Duo e8400 3ghz 6mbl,

Radeon hd 4850 512ddr3,

4gb ddr3 ramu

więc komputer mój rzadko się zatrzymuje na sekundę a co dopiero żeby mulił cały czas.

Dodatkowo sprawdzałem na linuxie(live CD) i tam mój komputer ma normalne użycie procesora.

Jest jeszcze możliwość że mój komputer ciągle "stawia" serwer ssh, bo dużo takich programów ostatnio instalowałem, ale raczej wszystkie usuwałem i w menadżerze zadań(procesy) nic nie widać. Jeszcze raz proszę o pomoc. Z góry dziękuję.


(jessica) #2

Log jest czyściutki jak łza, ale to niewiele znaczy, bo większość szkodników już dawno nauczyła się omijać Hijacka.

Prawdopodobnie nie masz żadnej infekcji, ale może jeszcze, tak na wszelki wypadek, daj log z OTL

jessi


(Daniel_1982) #3

Po mojemu najprościej bedzie zrobienie formata i bedzie po sprawie;)


(Jonatandragon) #4

Właśnie chcę uniknąć formata, bo za często go robię a tym razem mam za dużo danych.

Tutaj logi:

OTL logfile created on: 09-09-20 22:20:20 - Run 1

OTL by OldTimer - Version 3.0.14.0 Folder = D:\Downloads

Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yy-MM-dd


2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 100,00% Memory free

4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free

Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]


%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 244,14 Gb Total Space | 101,36 Gb Free Space | 41,52% Space Free | Partition Type: NTFS

Drive D: | 221,61 Gb Total Space | 106,03 Gb Free Space | 47,85% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded


Computer Name: DOMOWYSMOK

Current User Name: Smok

Logged in as Administrator.


Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Standard


[color=#E56717]========== Processes (SafeList) ==========[/color]


PRC - [2009-07-15 04:08:26 | 00,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe

PRC - [2009-02-16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe

PRC - [2009-07-15 04:08:26 | 00,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe

PRC - [2008-04-14 22:51:18 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE

PRC - [2009-08-17 17:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

PRC - [2009-08-17 18:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe

PRC - [2009-02-06 15:14:34 | 00,068,136 | ---- | M] () -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe

PRC - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe

PRC - [2007-02-10 15:29:54 | 29,178,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

PRC - [2007-02-10 05:29:56 | 00,089,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

PRC - [2009-08-17 18:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

PRC - [2009-08-17 18:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

PRC - [2008-04-14 22:51:52 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe

PRC - [2009-08-17 18:07:23 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe

PRC - [2009-02-16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

PRC - [2009-09-10 16:18:33 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe

PRC - [2009-02-06 12:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe

PRC - [2009-09-20 22:19:14 | 00,514,560 | ---- | M] (OldTimer Tools) -- D:\Downloads\OTL.exe


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]


SRV - [2008-07-25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])

SRV - [2009-08-17 17:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])

SRV - [2009-07-15 04:08:26 | 00,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])

SRV - [2009-07-14 21:05:00 | 00,593,920 | ---- | M] () -- C:\WINDOWS\System32\ati2sgag.exe -- (ATI Smart [Disabled | Stopped])

SRV - [2009-08-17 18:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])

SRV - [2009-08-17 18:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])

SRV - [2009-08-17 18:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])

SRV - [2008-07-25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])

SRV - [2008-07-29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])

SRV - [2009-02-06 15:14:34 | 00,068,136 | ---- | M] () -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service [Auto | Running])

SRV - [2009-08-07 12:43:04 | 00,045,816 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper [On_Demand | Stopped])

SRV - [2008-04-14 22:50:46 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])

SRV - [2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])

SRV - [2008-07-29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])

SRV - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])

SRV - [2006-10-27 00:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])

SRV - [2007-02-10 15:29:54 | 29,178,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS [Auto | Running])

SRV - [2005-10-14 12:50:19 | 00,045,272 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper [Disabled | Stopped])

SRV - [2008-02-18 16:29:12 | 00,877,864 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -- (Nero BackItUp Scheduler 3 [Disabled | Stopped])

SRV - [2008-07-29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])

SRV - [2008-02-28 17:07:48 | 00,529,704 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService [Disabled | Stopped])

SRV - [2008-06-15 15:34:20 | 00,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU [Disabled | Stopped])

SRV - [2006-10-26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])

SRV - [2006-10-26 13:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])

SRV - [2006-12-19 09:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\WINDOWS\System32\IoctlSvc.exe -- (PLFlash DeviceIoControl Service [Disabled | Stopped])

SRV - [2009-09-20 21:54:29 | 00,075,064 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrA.exe -- (PnkBstrA [Disabled | Stopped])

SRV - [2009-09-20 19:53:50 | 00,189,104 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.exe -- (PnkBstrB [Disabled | Stopped])

SRV - [2007-11-06 22:22:26 | 00,092,792 | ---- | M] (CACE Technologies) -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd [On_Demand | Stopped])

SRV - [2007-12-10 13:59:04 | 00,353,280 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [Disabled | Stopped])

SRV - [2007-02-10 15:29:47 | 00,242,544 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser [Disabled | Stopped])

SRV - [2007-02-10 05:29:56 | 00,089,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter [Auto | Running])

SRV - [2009-02-16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])

SRV - [2006-12-01 11:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

SRV - File not found -- -- (WUSB54GCSVC [Disabled | Stopped])


[color=#E56717]========== Driver Services (SafeList) ==========[/color]


DRV - [2009-08-17 18:03:21 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])

DRV - [2009-09-15 16:22:15 | 00,020,747 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\System32\DRIVERS\AegisP.sys -- (AegisP [Auto | Running])

DRV - [2009-08-17 18:05:37 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])

DRV - [2009-08-17 18:06:43 | 00,094,160 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])

DRV - [2009-08-17 18:04:29 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])

DRV - [2009-08-17 18:05:52 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])

DRV - [2009-08-17 18:04:40 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])

DRV - [2009-07-15 06:20:10 | 04,407,808 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])

DRV - [2008-05-21 01:53:36 | 00,093,696 | R--- | M] (ATI Research Inc.) -- C:\WINDOWS\System32\drivers\AtiHdmi.sys -- (AtiHdmiService [On_Demand | Running])

DRV - [2009-08-28 14:45:37 | 00,278,984 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\atksgt.sys -- (atksgt [Auto | Running])

DRV - [2004-10-25 21:02:00 | 00,021,664 | ---- | M] (EnTech Taiwan) -- C:\WINDOWS\System32\DRIVERS\ENTECH.sys -- (ENTECH [On_Demand | Stopped])

DRV - [2009-09-20 21:26:16 | 00,017,488 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\gdrv.sys -- (gdrv [On_Demand | Running])

DRV - [2003-09-25 22:15:32 | 00,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\GTNDIS5.SYS -- (GTNDIS5 [On_Demand | Stopped])

DRV - [2009-09-02 17:56:07 | 00,025,280 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\System32\DRIVERS\hamachi.sys -- (hamachi [On_Demand | Stopped])

DRV - [2008-04-15 14:00:00 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])

DRV - [2009-01-20 12:53:06 | 05,027,840 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])

DRV - [2009-08-28 14:45:37 | 00,025,416 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\lirsgt.sys -- (lirsgt [Auto | Running])

DRV - [2008-04-14 00:23:10 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\NMnt.sys -- (nm [On_Demand | Stopped])

DRV - [2007-02-22 10:15:56 | 00,137,216 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcd.sys -- (nmwcd [On_Demand | Stopped])

DRV - [2007-02-22 10:15:14 | 00,008,320 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdc.sys -- (nmwcdc [On_Demand | Stopped])

DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdcj.sys -- (nmwcdcj [On_Demand | Stopped])

DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdcm.sys -- (nmwcdcm [On_Demand | Stopped])

DRV - [2007-11-06 22:22:06 | 00,034,064 | ---- | M] (CACE Technologies) -- C:\WINDOWS\System32\drivers\npf.sys -- (NPF [On_Demand | Stopped])

DRV - [2009-09-08 16:52:00 | 00,038,976 | ---- | M] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\Drivers\pssdk42.sys -- (PSSDK42 [On_Demand | Stopped])

DRV - [2009-09-08 16:52:00 | 00,053,312 | ---- | M] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\Drivers\pssdklbf.sys -- (PSSDKLBF [On_Demand | Stopped])

DRV - [2006-03-02 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])

DRV - [2005-11-24 19:51:38 | 00,245,248 | ---- | M] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\DRIVERS\rt73.sys -- (RT73 [On_Demand | Running])

DRV - [2008-10-30 15:14:20 | 00,117,888 | R--- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys -- (RTLE8023xp [On_Demand | Stopped])

DRV - [2008-04-13 22:09:18 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])

DRV - [2009-09-02 17:49:45 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])

DRV - [2008-11-17 02:24:00 | 00,051,688 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\srescan.sys -- (srescan [Boot | Running])

DRV - [2009-02-16 00:10:26 | 00,353,672 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\vsdatant.sys -- (vsdatant [System | Running])


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]



[color=#E56717]========== Internet Explorer ==========[/color]


IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm



IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

IE - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\S-1-5-21-1202660629-1645522239-1801674531-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========[/color]


FF - prefs.js..browser.search.selectedEngine: "Wikipedia (pl)"

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1

FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3789

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14


FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-08-05 16:10:39 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-07-02 20:32:50 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-09-20 19:17:46 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-10 16:18:38 | 00,000,000 | ---D | M]


[2009-07-02 20:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\mozilla\Extensions

[2009-07-02 20:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2009-09-20 14:07:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\mozilla\Firefox\Profiles\9r6vl9lk.default\extensions

[2009-08-05 23:24:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\mozilla\Firefox\Profiles\9r6vl9lk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2009-09-20 21:55:40 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions

[2009-09-10 16:18:38 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009-09-02 17:49:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}

[2009-07-02 20:14:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

[2009-07-02 20:32:57 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

[2009-08-26 09:58:33 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

[2009-09-10 16:18:33 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll

[2009-09-10 16:18:33 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll

[2009-07-25 05:23:01 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll

[2009-09-10 16:18:33 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll

[2006-10-26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL

[2009-02-27 12:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll

[2009-09-02 17:17:46 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll

[2009-08-07 12:43:40 | 00,030,400 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\mozilla firefox\plugins\np_gp.dll

[2009-07-26 13:53:03 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml

[2009-07-11 10:48:26 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml

[2009-07-11 10:48:26 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml

[2009-07-11 10:48:26 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml

[2009-07-11 10:48:26 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml

[2009-07-11 10:48:26 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml

[2009-07-11 10:48:26 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml


O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)

O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = 

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = 

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255

O7 - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\wshbth.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1253474421625 (WUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)

O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 91.214.54.1

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: GinaDLL - (GTGina.dll) - C:\WINDOWS\System32\GTGina.dll (Gemtek)

O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)

O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009-06-30 21:58:25 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [NTFS]

O34 - HKLM BootExecute: (autocheck) - File not found

O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)

O34 - HKLM BootExecute: (*) - File not found


[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]


[8 C:\WINDOWS\*.tmp files]

[2009-09-20 20:18:41 | 00,000,000 | ---D | C] -- C:\Program Files\freeSSHd

[2009-09-20 20:00:38 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Smok\Pulpit\HijackThis.lnk

[2009-09-20 20:00:38 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro

[2009-09-19 13:57:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Moje dokumenty\Downloads

[2009-09-19 10:56:57 | 00,160,217 | ---- | C] () -- C:\WINDOWS\System32\PowerToysLicense.rtf

[2009-09-18 22:01:33 | 00,000,000 | ---D | C] -- C:\Program Files\Bitvise WinSSHD

[2009-09-17 18:50:18 | 00,000,600 | ---- | C] () -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\PUTTY.RND

[2009-09-15 17:24:03 | 00,000,000 | ---D | C] -- C:\Program Files\Advanced IP Scanner

[2009-09-15 16:22:15 | 00,245,248 | ---- | C] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\rt73.sys

[2009-09-15 16:22:15 | 00,007,846 | ---- | C] () -- C:\WINDOWS\System32\rt73.cat

[2009-09-15 16:21:57 | 00,001,362 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI

[2009-09-12 21:34:57 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll

[2009-09-12 21:34:57 | 00,031,930 | ---- | C] () -- C:\WINDOWS\System32\GTNDIS3.VXD

[2009-09-12 21:34:57 | 00,015,872 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\GTNDIS5.sys

[2009-09-12 21:34:56 | 00,245,248 | ---- | C] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\drivers\rt73.sys

[2009-09-12 21:34:55 | 00,032,768 | ---- | C] (Gemtek) -- C:\WINDOWS\System32\GTGina.dll

[2009-09-12 21:34:46 | 00,000,000 | ---D | C] -- C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor

[2009-09-10 16:41:47 | 00,000,078 | ---- | C] () -- C:\Documents and Settings\Smok\Dane aplikacji\.ettercap_gtk

[2009-09-10 16:21:49 | 00,000,000 | ---D | C] -- C:\Program Files\WinPcap

[2009-09-10 16:18:25 | 00,000,000 | ---D | C] -- C:\Program Files\EttercapNG

[2009-09-08 17:45:29 | 00,000,000 | ---D | C] -- C:\Program Files\Advanced Port Scanner

[2009-09-08 16:52:00 | 00,053,312 | ---- | C] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\drivers\pssdklbf.sys

[2009-09-08 16:52:00 | 00,038,976 | ---- | C] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\drivers\pssdk42.sys

[2009-09-05 11:24:35 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss

[2009-09-04 22:26:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\cache

[2009-09-04 22:20:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Dane aplikacji\Nowe Gadu-Gadu

[2009-09-04 22:20:02 | 00,000,000 | ---D | C] -- C:\Program Files\Gadu-Gadu

[2009-09-04 21:53:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\ATI

[2009-09-02 17:56:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Dane aplikacji\Hamachi

[2009-09-02 17:56:07 | 00,025,280 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\drivers\hamachi.sys

[2009-09-02 17:56:06 | 00,000,000 | ---D | C] -- C:\Program Files\Hamachi

[2009-09-02 17:54:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite

[2009-09-02 17:54:45 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar

[2009-09-02 17:54:44 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite

[2009-09-02 17:49:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Dane aplikacji\DAEMON Tools Lite

[2009-09-02 17:49:24 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype

[2009-09-02 17:49:23 | 00,000,000 | R--D | C] -- C:\Program Files\Skype

[2009-09-02 17:17:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Dane aplikacji\Apple Computer

[2009-08-28 14:45:37 | 00,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys

[2009-08-28 14:45:37 | 00,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys

[2009-08-26 16:08:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Moje dokumenty\Tom Clancy's H.A.W.X

[2009-08-25 21:37:20 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2009-08-25 16:01:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Moje dokumenty\Nero Home

[2009-08-25 16:01:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\Nero

[2009-08-25 15:57:16 | 00,000,000 | ---D | C] -- C:\Program Files\NeroInstall.bak

[2009-08-25 15:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\Ahead

[2009-08-25 15:52:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Dane aplikacji\Nero

[2009-08-25 15:51:34 | 00,000,000 | ---D | C] -- C:\Program Files\Nero

[2009-08-25 15:51:34 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero

[2009-08-25 15:51:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Nero

[2009-08-23 22:35:48 | 00,000,000 | ---D | C] -- C:\Program Files\NOS

[2009-08-23 22:35:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\NOS

[2009-07-30 23:34:05 | 00,151,552 | ---- | C] () -- C:\WINDOWS\System32\nvRegDev.dll

[2009-07-23 18:43:04 | 00,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll

[2009-07-08 16:26:27 | 01,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll

[2009-07-02 21:50:21 | 00,139,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys

[2009-07-02 21:49:59 | 00,000,298 | ---- | C] () -- C:\WINDOWS\game.ini

[2009-07-02 20:17:57 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2009-06-30 17:06:40 | 00,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys

[2008-10-22 05:29:06 | 00,173,550 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat

[2008-07-05 12:14:48 | 00,456,192 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll

[2008-07-05 12:14:44 | 03,591,168 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll

[2008-07-05 12:13:16 | 00,708,096 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll

[2008-06-22 18:34:00 | 00,177,664 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll

[2008-06-13 12:39:38 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll

[2008-06-12 19:36:38 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2008-04-15 14:00:00 | 00,000,603 | ---- | C] () -- C:\WINDOWS\win.ini

[2008-04-15 14:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

[2007-11-06 22:19:28 | 00,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll

[2007-07-10 17:10:12 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest

[2007-03-29 22:00:40 | 00,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll

[2004-11-24 20:25:52 | 00,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll

[2004-10-03 18:50:54 | 00,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll


[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]


[3 C:\WINDOWS\System32\*.tmp files]

[8 C:\WINDOWS\*.tmp files]

[2009-09-20 21:54:29 | 00,075,064 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrA.exe

[2009-09-20 21:26:16 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009-09-20 21:26:15 | 00,350,192 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml

[2009-09-20 21:26:12 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009-09-20 21:20:45 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009-09-20 20:59:04 | 00,000,603 | ---- | M] () -- C:\WINDOWS\win.ini

[2009-09-20 20:59:04 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini

[2009-09-20 20:59:04 | 00,000,211 | -HS- | M] () -- C:\boot.ini

[2009-09-20 20:24:05 | 00,000,600 | ---- | M] () -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\PUTTY.RND

[2009-09-20 20:00:38 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Smok\Pulpit\HijackThis.lnk

[2009-09-20 19:53:50 | 00,189,104 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr

[2009-09-20 19:53:50 | 00,189,104 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.exe

[2009-09-20 19:45:40 | 00,000,078 | ---- | M] () -- C:\Documents and Settings\Smok\Dane aplikacji\.ettercap_gtk

[2009-09-19 13:58:11 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2009-09-19 11:03:54 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2009-09-15 16:21:57 | 00,001,362 | ---- | M] () -- C:\WINDOWS\System32\WLAN.INI

[2009-09-10 20:48:47 | 00,015,872 | ---- | M] () -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009-09-08 16:52:00 | 00,053,312 | ---- | M] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\drivers\pssdklbf.sys

[2009-09-08 16:52:00 | 00,038,976 | ---- | M] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\drivers\pssdk42.sys

[2009-09-05 16:12:31 | 00,139,584 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys

[2009-09-02 17:56:07 | 00,025,280 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\System32\drivers\hamachi.sys

[2009-09-02 17:49:45 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2009-09-01 14:43:02 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2009-08-28 14:45:37 | 00,278,984 | ---- | M] () -- C:\WINDOWS\System32\drivers\atksgt.sys

[2009-08-28 14:45:37 | 00,025,416 | ---- | M] () -- C:\WINDOWS\System32\drivers\lirsgt.sys

[2009-08-26 23:00:34 | 00,004,096 | ---- | M] () -- C:\WINDOWS\System32\crash

[2009-08-26 22:21:38 | 01,573,970 | -H-- | M] () -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\IconCache.db

[2009-08-26 15:25:01 | 00,001,247 | ---- | M] () -- C:\Documents and Settings\Smok\Pulpit\Downloads.lnk

[2009-08-25 16:02:08 | 00,002,645 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT


[color=#E56717]========== LOP Check ==========[/color]


[2009-09-04 22:24:50 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji

[2009-07-27 15:59:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Activision

[2009-07-23 18:50:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Age of Empires 3

[2009-09-04 21:53:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ATI

[2009-07-27 17:46:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Codemasters

[2009-09-02 17:54:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite

[2009-07-07 10:15:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations

[2009-07-07 10:18:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite

[2009-08-05 14:27:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP

[2009-06-30 23:50:39 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Dane aplikacji

[2009-06-30 22:00:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji

[2009-09-08 19:54:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji

[2009-09-10 17:19:57 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Smok\Dane aplikacji

[2009-07-27 15:59:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Activision

[2009-07-02 19:26:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\ATI

[2009-09-09 21:20:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\BESTplayer

[2009-07-06 11:12:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Canneverbe_Limited

[2009-07-27 17:17:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Capcom

[2009-08-03 20:17:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Command & Conquer 3 Tiberium Wars

[2009-09-02 17:55:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\DAEMON Tools

[2009-09-02 17:55:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\DAEMON Tools Lite

[2009-09-18 21:52:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\DC++

[2009-07-02 20:12:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Gadu-Gadu

[2009-09-04 17:01:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Hamachi

[2009-07-26 20:04:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Leadertech

[2009-07-07 10:18:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Nokia

[2009-09-04 22:30:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Nowe Gadu-Gadu

[2009-07-07 10:18:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\PC Suite

[2009-08-06 16:43:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Red Alert 3

[2009-07-04 12:11:57 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\SecuROM

[2009-09-19 14:30:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\uTorrent

[2009-09-01 14:43:02 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

[2008-04-15 14:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini

[2009-09-20 21:26:16 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT


[color=#E56717]========== Purity Check ==========[/color]




[color=#E56717]========== Alternate Data Streams ==========[/color]


@Alternate Data Stream - 487 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:05EE1EEF

@Alternate Data Stream - 12 bytes -> C:\WINDOWS\system32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD}

< End of report >

Jakieś sugestie?


(jessica) #5

Nie podoba mi się ten strumień, bo jest podpięty pod folder, a nie pod plik.

Prawidłowe strumienie nigdy nie podpinają się pod folder "system32, ja przynajmniej nie słyszałam o takim przypadku.

Może użyj ComboFixa

(Nowsza instrukcja obsługi ComboFixa >http://www.bleepingcomputer.com/combofix/pl/instrukcja-uzycia-combofix)

ComboFix często samoczynnie usuwa takie strumienie, może i tym razem będzie potrafił usunąć?

Pokaż log z tego ComboFixa - zobaczymy, czy usunął.

EDIT:

Możesz też, zamiast ComboFixa, zrobić to:

Uruchom OTL i w oknie Custom Scans/Fixes wklej to:

:OTL

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

@Alternate Data Stream - 12 bytes -> C:\WINDOWS\system32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD}


:Commands

[emptytemp]

[start explorer]

[Reboot]

Kliknij w Run Fix. Zatwierdź restart komputera.

Następnie uruchom OTL ponownie, tym razem wywołaj opcję Run Scan.

Pokaż nowy log OTL.txt oraz log z czyszczenia.

jessi


(Jonatandragon) #6

Dzięki za tak szybkie odpowiedzi i w ogóle za pomoc.

Log z czyszczenia:

All processes killed

========== OTL ==========

No active process named explorer.exe was found!

ADS C:\WINDOWS\system32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD} deleted successfully.

========== COMMANDS ==========


[EMPTYTEMP]


User: All Users


User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes


User: LocalService

File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temp\Cookies\index.dat scheduled to be deleted on reboot.

->Temp folder emptied: 82513 bytes

File delete failed. C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

->Temporary Internet Files folder emptied: 33170 bytes


User: NetworkService

->Temp folder emptied: 98304 bytes

File delete failed. C:\Documents and Settings\NetworkService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

->Temporary Internet Files folder emptied: 33170 bytes


User: Smok

File delete failed. C:\Documents and Settings\Smok\Ustawienia lokalne\Temp\~DF189E.tmp scheduled to be deleted on reboot.

->Temp folder emptied: 218906420 bytes

->Temporary Internet Files folder emptied: 3343146 bytes

->Java cache emptied: 16876246 bytes

->FireFox cache emptied: 62957907 bytes


%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 4500748 bytes

%systemroot%\System32 .tmp files removed: 1613396 bytes

File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.

File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_780.dat scheduled to be deleted on reboot.

File delete failed. C:\WINDOWS\temp\ZLT00914.TMP scheduled to be deleted on reboot.

Windows Temp folder emptied: 1220202 bytes

RecycleBin emptied: 0 bytes


Total Files Cleaned = 295,32 mb



OTL by OldTimer - Version 3.0.14.0 log created on 09212009_080906


Files\Folders moved on Reboot...

C:\Documents and Settings\Smok\Ustawienia lokalne\Temp\~DF189E.tmp moved successfully.

File\Folder C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!

File\Folder C:\WINDOWS\temp\Perflib_Perfdata_780.dat not found!

File\Folder C:\WINDOWS\temp\ZLT00914.TMP not found!


Registry entries deleted on Reboot...

Log aktualny:

OTL logfile created on: 09-09-21 08:16:19 - Run 2

OTL by OldTimer - Version 3.0.14.0 Folder = D:\Downloads

Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yy-MM-dd


2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 100,00% Memory free

4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free

Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]


%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 244,14 Gb Total Space | 101,62 Gb Free Space | 41,62% Space Free | Partition Type: NTFS

Drive D: | 221,61 Gb Total Space | 106,03 Gb Free Space | 47,85% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded


Computer Name: DOMOWYSMOK

Current User Name: Smok

Logged in as Administrator.


Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Standard


[color=#E56717]========== Processes (SafeList) ==========[/color]


PRC - [2009-07-15 04:08:26 | 00,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe

PRC - [2009-07-15 04:08:26 | 00,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe

PRC - [2009-02-16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe

PRC - [2008-04-14 22:51:18 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE

PRC - [2009-08-17 17:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

PRC - [2009-08-17 18:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe

PRC - [2009-02-06 15:14:34 | 00,068,136 | ---- | M] () -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe

PRC - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe

PRC - [2007-02-10 15:29:54 | 29,178,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

PRC - [2007-02-10 05:29:56 | 00,089,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

PRC - [2009-08-17 18:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

PRC - [2009-08-17 18:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

PRC - [2008-04-14 22:51:52 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe

PRC - [2009-08-17 18:07:23 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe

PRC - [2009-02-16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

PRC - [2009-09-10 16:18:33 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe

PRC - [2006-10-27 15:23:04 | 00,347,432 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\WINWORD.EXE

PRC - [2009-09-20 22:19:14 | 00,514,560 | ---- | M] (OldTimer Tools) -- D:\Downloads\OTL.exe

PRC - [2009-07-15 13:07:18 | 00,238,888 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]


SRV - [2008-07-25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])

SRV - [2009-08-17 17:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])

SRV - [2009-07-15 04:08:26 | 00,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])

SRV - [2009-07-14 21:05:00 | 00,593,920 | ---- | M] () -- C:\WINDOWS\System32\ati2sgag.exe -- (ATI Smart [Disabled | Stopped])

SRV - [2009-08-17 18:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])

SRV - [2009-08-17 18:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])

SRV - [2009-08-17 18:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])

SRV - [2008-07-25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])

SRV - [2008-07-29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])

SRV - [2009-02-06 15:14:34 | 00,068,136 | ---- | M] () -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service [Auto | Running])

SRV - [2009-08-07 12:43:04 | 00,045,816 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper [On_Demand | Stopped])

SRV - [2008-04-14 22:50:46 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])

SRV - [2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])

SRV - [2008-07-29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])

SRV - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])

SRV - [2006-10-27 00:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])

SRV - [2007-02-10 15:29:54 | 29,178,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS [Auto | Running])

SRV - [2005-10-14 12:50:19 | 00,045,272 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper [Disabled | Stopped])

SRV - [2008-02-18 16:29:12 | 00,877,864 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -- (Nero BackItUp Scheduler 3 [Disabled | Stopped])

SRV - [2008-07-29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])

SRV - [2008-02-28 17:07:48 | 00,529,704 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService [Disabled | Stopped])

SRV - [2008-06-15 15:34:20 | 00,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccessU [Disabled | Stopped])

SRV - [2006-10-26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])

SRV - [2006-10-26 13:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])

SRV - [2006-12-19 09:30:26 | 00,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\WINDOWS\System32\IoctlSvc.exe -- (PLFlash DeviceIoControl Service [Disabled | Stopped])

SRV - [2009-09-20 21:54:29 | 00,075,064 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrA.exe -- (PnkBstrA [Disabled | Stopped])

SRV - [2009-09-20 19:53:50 | 00,189,104 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.exe -- (PnkBstrB [Disabled | Stopped])

SRV - [2007-11-06 22:22:26 | 00,092,792 | ---- | M] (CACE Technologies) -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd [On_Demand | Stopped])

SRV - [2007-12-10 13:59:04 | 00,353,280 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [Disabled | Stopped])

SRV - [2007-02-10 15:29:47 | 00,242,544 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser [Disabled | Stopped])

SRV - [2007-02-10 05:29:56 | 00,089,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter [Auto | Running])

SRV - [2009-02-16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])

SRV - [2006-12-01 11:46:28 | 00,918,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

SRV - File not found -- -- (WUSB54GCSVC [Disabled | Stopped])


[color=#E56717]========== Driver Services (SafeList) ==========[/color]


DRV - [2009-08-17 18:03:21 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])

DRV - [2009-09-15 16:22:15 | 00,020,747 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\System32\DRIVERS\AegisP.sys -- (AegisP [Auto | Running])

DRV - [2009-08-17 18:05:37 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])

DRV - [2009-08-17 18:06:43 | 00,094,160 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])

DRV - [2009-08-17 18:04:29 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])

DRV - [2009-08-17 18:05:52 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])

DRV - [2009-08-17 18:04:40 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])

DRV - [2009-07-15 06:20:10 | 04,407,808 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])

DRV - [2008-05-21 01:53:36 | 00,093,696 | R--- | M] (ATI Research Inc.) -- C:\WINDOWS\System32\drivers\AtiHdmi.sys -- (AtiHdmiService [On_Demand | Running])

DRV - [2009-08-28 14:45:37 | 00,278,984 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\atksgt.sys -- (atksgt [Auto | Running])

DRV - [2004-10-25 21:02:00 | 00,021,664 | ---- | M] (EnTech Taiwan) -- C:\WINDOWS\System32\DRIVERS\ENTECH.sys -- (ENTECH [On_Demand | Stopped])

DRV - [2009-09-21 08:10:27 | 00,017,488 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\gdrv.sys -- (gdrv [On_Demand | Running])

DRV - [2003-09-25 22:15:32 | 00,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\GTNDIS5.SYS -- (GTNDIS5 [On_Demand | Stopped])

DRV - [2009-09-02 17:56:07 | 00,025,280 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\System32\DRIVERS\hamachi.sys -- (hamachi [On_Demand | Stopped])

DRV - [2008-04-15 14:00:00 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])

DRV - [2009-01-20 12:53:06 | 05,027,840 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])

DRV - [2009-08-28 14:45:37 | 00,025,416 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\lirsgt.sys -- (lirsgt [Auto | Running])

DRV - [2008-04-14 00:23:10 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\NMnt.sys -- (nm [On_Demand | Stopped])

DRV - [2007-02-22 10:15:56 | 00,137,216 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcd.sys -- (nmwcd [On_Demand | Stopped])

DRV - [2007-02-22 10:15:14 | 00,008,320 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdc.sys -- (nmwcdc [On_Demand | Stopped])

DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdcj.sys -- (nmwcdcj [On_Demand | Stopped])

DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\System32\drivers\nmwcdcm.sys -- (nmwcdcm [On_Demand | Stopped])

DRV - [2007-11-06 22:22:06 | 00,034,064 | ---- | M] (CACE Technologies) -- C:\WINDOWS\System32\drivers\npf.sys -- (NPF [On_Demand | Stopped])

DRV - [2009-09-08 16:52:00 | 00,038,976 | ---- | M] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\Drivers\pssdk42.sys -- (PSSDK42 [On_Demand | Stopped])

DRV - [2009-09-08 16:52:00 | 00,053,312 | ---- | M] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\Drivers\pssdklbf.sys -- (PSSDKLBF [On_Demand | Stopped])

DRV - [2006-03-02 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])

DRV - [2005-11-24 19:51:38 | 00,245,248 | ---- | M] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\DRIVERS\rt73.sys -- (RT73 [On_Demand | Running])

DRV - [2008-10-30 15:14:20 | 00,117,888 | R--- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys -- (RTLE8023xp [On_Demand | Stopped])

DRV - [2008-04-13 22:09:18 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])

DRV - [2009-09-02 17:49:45 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])

DRV - [2008-11-17 02:24:00 | 00,051,688 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\srescan.sys -- (srescan [Boot | Running])

DRV - [2009-02-16 00:10:26 | 00,353,672 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\vsdatant.sys -- (vsdatant [System | Running])


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]



[color=#E56717]========== Internet Explorer ==========[/color]


IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm



IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

IE - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

IE - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

IE - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\S-1-5-21-1202660629-1645522239-1801674531-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========[/color]


FF - prefs.js..browser.search.selectedEngine: "Wikipedia (pl)"

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1

FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3789

FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14


FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-08-05 16:10:39 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-07-02 20:32:50 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-09-20 19:17:46 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-10 16:18:38 | 00,000,000 | ---D | M]


[2009-07-02 20:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\mozilla\Extensions

[2009-07-02 20:26:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}

[2009-09-20 14:07:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\mozilla\Firefox\Profiles\9r6vl9lk.default\extensions

[2009-08-05 23:24:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\mozilla\Firefox\Profiles\9r6vl9lk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2009-09-21 08:12:10 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions

[2009-09-10 16:18:38 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2009-09-02 17:49:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}

[2009-07-02 20:14:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

[2009-07-02 20:32:57 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

[2009-08-26 09:58:33 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

[2009-09-10 16:18:33 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll

[2009-09-10 16:18:33 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll

[2009-07-25 05:23:01 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll

[2009-09-10 16:18:33 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll

[2006-10-26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL

[2009-02-27 12:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll

[2009-09-02 17:17:46 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll

[2009-09-02 17:17:47 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll

[2009-08-07 12:43:40 | 00,030,400 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\mozilla firefox\plugins\np_gp.dll

[2009-07-26 13:53:03 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml

[2009-07-11 10:48:26 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml

[2009-07-11 10:48:26 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml

[2009-07-11 10:48:26 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml

[2009-07-11 10:48:26 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml

[2009-07-11 10:48:26 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml

[2009-07-11 10:48:26 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml


O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts

O1 - Hosts: 127.0.0.1 localhost

O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)

O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = 

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = 

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255

O7 - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKU\S-1-5-21-1202660629-1645522239-1801674531-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\wshbth.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)

O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1253474421625 (WUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)

O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 91.214.54.1

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp - No CLSID value found

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp - No CLSID value found

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: GinaDLL - (GTGina.dll) - C:\WINDOWS\System32\GTGina.dll (Gemtek)

O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)

O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O31 - SafeBoot: AlternateShell - cmd.exe

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009-06-30 21:58:25 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [NTFS]

O34 - HKLM BootExecute: (autocheck) - File not found

O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)

O34 - HKLM BootExecute: (*) - File not found


[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]


[2009-09-20 20:18:41 | 00,000,000 | ---D | C] -- C:\Program Files\freeSSHd

[2009-09-20 20:00:38 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Smok\Pulpit\HijackThis.lnk

[2009-09-20 20:00:38 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro

[2009-09-19 13:57:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Moje dokumenty\Downloads

[2009-09-19 10:56:57 | 00,160,217 | ---- | C] () -- C:\WINDOWS\System32\PowerToysLicense.rtf

[2009-09-18 22:01:33 | 00,000,000 | ---D | C] -- C:\Program Files\Bitvise WinSSHD

[2009-09-17 18:50:18 | 00,000,600 | ---- | C] () -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\PUTTY.RND

[2009-09-15 17:24:03 | 00,000,000 | ---D | C] -- C:\Program Files\Advanced IP Scanner

[2009-09-15 16:22:15 | 00,245,248 | ---- | C] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\rt73.sys

[2009-09-15 16:22:15 | 00,007,846 | ---- | C] () -- C:\WINDOWS\System32\rt73.cat

[2009-09-15 16:21:57 | 00,001,362 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI

[2009-09-14 20:52:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Moje dokumenty\Jonatan

[2009-09-12 21:34:57 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll

[2009-09-12 21:34:57 | 00,031,930 | ---- | C] () -- C:\WINDOWS\System32\GTNDIS3.VXD

[2009-09-12 21:34:57 | 00,015,872 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\GTNDIS5.sys

[2009-09-12 21:34:56 | 00,245,248 | ---- | C] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\drivers\rt73.sys

[2009-09-12 21:34:55 | 00,032,768 | ---- | C] (Gemtek) -- C:\WINDOWS\System32\GTGina.dll

[2009-09-12 21:34:46 | 00,000,000 | ---D | C] -- C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor

[2009-09-10 16:41:47 | 00,000,078 | ---- | C] () -- C:\Documents and Settings\Smok\Dane aplikacji\.ettercap_gtk

[2009-09-10 16:21:49 | 00,000,000 | ---D | C] -- C:\Program Files\WinPcap

[2009-09-10 16:18:25 | 00,000,000 | ---D | C] -- C:\Program Files\EttercapNG

[2009-09-08 17:45:29 | 00,000,000 | ---D | C] -- C:\Program Files\Advanced Port Scanner

[2009-09-08 16:52:00 | 00,053,312 | ---- | C] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\drivers\pssdklbf.sys

[2009-09-08 16:52:00 | 00,038,976 | ---- | C] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\drivers\pssdk42.sys

[2009-09-05 11:24:35 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss

[2009-09-04 22:26:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\cache

[2009-09-04 22:20:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Dane aplikacji\Nowe Gadu-Gadu

[2009-09-04 22:20:02 | 00,000,000 | ---D | C] -- C:\Program Files\Gadu-Gadu

[2009-09-04 21:53:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\ATI

[2009-09-02 17:56:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Dane aplikacji\Hamachi

[2009-09-02 17:56:07 | 00,025,280 | ---- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\drivers\hamachi.sys

[2009-09-02 17:56:06 | 00,000,000 | ---D | C] -- C:\Program Files\Hamachi

[2009-09-02 17:54:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite

[2009-09-02 17:54:45 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar

[2009-09-02 17:54:44 | 00,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite

[2009-09-02 17:49:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Dane aplikacji\DAEMON Tools Lite

[2009-09-02 17:49:24 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype

[2009-09-02 17:49:23 | 00,000,000 | R--D | C] -- C:\Program Files\Skype

[2009-09-02 17:17:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Dane aplikacji\Apple Computer

[2009-08-28 14:45:37 | 00,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys

[2009-08-28 14:45:37 | 00,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys

[2009-08-26 16:08:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Moje dokumenty\Tom Clancy's H.A.W.X

[2009-08-25 21:37:20 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2009-08-25 16:01:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Moje dokumenty\Nero Home

[2009-08-25 16:01:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\Nero

[2009-08-25 15:57:16 | 00,000,000 | ---D | C] -- C:\Program Files\NeroInstall.bak

[2009-08-25 15:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\Ahead

[2009-08-25 15:52:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Smok\Dane aplikacji\Nero

[2009-08-25 15:51:34 | 00,000,000 | ---D | C] -- C:\Program Files\Nero

[2009-08-25 15:51:34 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero

[2009-08-25 15:51:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Nero

[2009-08-23 22:35:48 | 00,000,000 | ---D | C] -- C:\Program Files\NOS

[2009-08-23 22:35:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\NOS

[2009-07-30 23:34:05 | 00,151,552 | ---- | C] () -- C:\WINDOWS\System32\nvRegDev.dll

[2009-07-23 18:43:04 | 00,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll

[2009-07-08 16:26:27 | 01,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll

[2009-07-02 21:50:21 | 00,139,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys

[2009-07-02 21:49:59 | 00,000,298 | ---- | C] () -- C:\WINDOWS\game.ini

[2009-07-02 20:17:57 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2009-06-30 17:06:40 | 00,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys

[2008-10-22 05:29:06 | 00,173,550 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat

[2008-07-05 12:14:48 | 00,456,192 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll

[2008-07-05 12:14:44 | 03,591,168 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll

[2008-07-05 12:13:16 | 00,708,096 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll

[2008-06-22 18:34:00 | 00,177,664 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll

[2008-06-13 12:39:38 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll

[2008-06-12 19:36:38 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2008-04-15 14:00:00 | 00,000,603 | ---- | C] () -- C:\WINDOWS\win.ini

[2008-04-15 14:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

[2007-11-06 22:19:28 | 00,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll

[2007-07-10 17:10:12 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest

[2007-03-29 22:00:40 | 00,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll

[2004-11-24 20:25:52 | 00,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll

[2004-10-03 18:50:54 | 00,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll


[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]


[2009-09-21 08:10:26 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009-09-21 08:10:25 | 00,350,192 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml

[2009-09-21 08:10:22 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009-09-20 21:54:29 | 00,075,064 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrA.exe

[2009-09-20 21:20:45 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009-09-20 20:59:04 | 00,000,603 | ---- | M] () -- C:\WINDOWS\win.ini

[2009-09-20 20:59:04 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini

[2009-09-20 20:59:04 | 00,000,211 | -HS- | M] () -- C:\boot.ini

[2009-09-20 20:24:05 | 00,000,600 | ---- | M] () -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\PUTTY.RND

[2009-09-20 20:00:38 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Smok\Pulpit\HijackThis.lnk

[2009-09-20 19:53:50 | 00,189,104 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr

[2009-09-20 19:53:50 | 00,189,104 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.exe

[2009-09-20 19:45:40 | 00,000,078 | ---- | M] () -- C:\Documents and Settings\Smok\Dane aplikacji\.ettercap_gtk

[2009-09-19 13:58:11 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2009-09-19 11:03:54 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2009-09-15 16:21:57 | 00,001,362 | ---- | M] () -- C:\WINDOWS\System32\WLAN.INI

[2009-09-10 20:48:47 | 00,015,872 | ---- | M] () -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009-09-08 16:52:00 | 00,053,312 | ---- | M] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\drivers\pssdklbf.sys

[2009-09-08 16:52:00 | 00,038,976 | ---- | M] (microOLAP Technologies LTD) -- C:\WINDOWS\System32\drivers\pssdk42.sys

[2009-09-05 16:12:31 | 00,139,584 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys

[2009-09-02 17:56:07 | 00,025,280 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\System32\drivers\hamachi.sys

[2009-09-02 17:49:45 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2009-09-01 14:43:02 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2009-08-28 14:45:37 | 00,278,984 | ---- | M] () -- C:\WINDOWS\System32\drivers\atksgt.sys

[2009-08-28 14:45:37 | 00,025,416 | ---- | M] () -- C:\WINDOWS\System32\drivers\lirsgt.sys

[2009-08-26 23:00:34 | 00,004,096 | ---- | M] () -- C:\WINDOWS\System32\crash

[2009-08-26 22:21:38 | 01,573,970 | -H-- | M] () -- C:\Documents and Settings\Smok\Ustawienia lokalne\Dane aplikacji\IconCache.db

[2009-08-26 15:25:01 | 00,001,247 | ---- | M] () -- C:\Documents and Settings\Smok\Pulpit\Downloads.lnk

[2009-08-25 16:02:08 | 00,002,645 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT


[color=#E56717]========== LOP Check ==========[/color]


[2009-09-04 22:24:50 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji

[2009-07-27 15:59:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Activision

[2009-07-23 18:50:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Age of Empires 3

[2009-09-04 21:53:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ATI

[2009-07-27 17:46:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Codemasters

[2009-09-02 17:54:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite

[2009-07-07 10:15:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations

[2009-07-07 10:18:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite

[2009-08-05 14:27:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP

[2009-06-30 23:50:39 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Dane aplikacji

[2009-06-30 22:00:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji

[2009-09-08 19:54:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji

[2009-09-10 17:19:57 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Smok\Dane aplikacji

[2009-07-27 15:59:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Activision

[2009-07-02 19:26:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\ATI

[2009-09-09 21:20:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\BESTplayer

[2009-07-06 11:12:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Canneverbe_Limited

[2009-07-27 17:17:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Capcom

[2009-08-03 20:17:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Command & Conquer 3 Tiberium Wars

[2009-09-02 17:55:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\DAEMON Tools

[2009-09-02 17:55:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\DAEMON Tools Lite

[2009-09-18 21:52:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\DC++

[2009-07-02 20:12:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Gadu-Gadu

[2009-09-04 17:01:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Hamachi

[2009-07-26 20:04:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Leadertech

[2009-07-07 10:18:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Nokia

[2009-09-04 22:30:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Nowe Gadu-Gadu

[2009-07-07 10:18:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\PC Suite

[2009-08-06 16:43:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\Red Alert 3

[2009-07-04 12:11:57 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\SecuROM

[2009-09-19 14:30:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Smok\Dane aplikacji\uTorrent

[2009-09-01 14:43:02 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

[2008-04-15 14:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini

[2009-09-21 08:10:26 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT


[color=#E56717]========== Purity Check ==========[/color]




[color=#E56717]========== Alternate Data Streams ==========[/color]


@Alternate Data Stream - 487 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:05EE1EEF

< End of report >

Niestety problem ciągle ten sam, coraz bardziej boje się formata :frowning:


(jessica) #7

Nic tu więcej szkodliwego nie widzę.

Jeśli zdecydujesz się na format, to przedtem możesz usunąć także ten drugi strumień:

Uruchom OTL i w oknie Custom Scans/Fixes wklej to:

:OTL

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

@Alternate Data Stream - 487 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:05EE1EEF


:Commands

[emptytemp]

[start explorer]

[Reboot]

Kliknij w Run Fix. Zatwierdź restart komputera.

Nie sądzę, by to poprawiło sytuację, ale spróbować możesz...

jessi


(Jonatandragon) #8

Format zrobiony, mimo wszystko dzięki bardzo za pomoc.