Wirus google earth - pomocy


(Mankiet) #1

Witam ,tak jak w temacie, na laptopie przesladuje mnie ten wirus (byc moze) tez inny,ostatnio sporo rzeczy bylo sciaganr.Mam antywiurs McAfee ale o nie pomoga:

skrypt z OTL:

OTL logfile created on: 6/27/2011 2:01:17 PM - Run 1

OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Kamilka&Michas\Downloads

64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7600.16385)

Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3.80 Gb Total Physical Memory | 2.27 Gb Available Physical Memory | 59.62% Memory free

7.60 Gb Paging File | 5.68 Gb Available in Paging File | 74.74% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 101.00 Gb Total Space | 72.29 Gb Free Space | 71.57% Space Free | Partition Type: NTFS

Drive D: | 344.66 Gb Total Space | 316.74 Gb Free Space | 91.90% Space Free | Partition Type: NTFS

Drive F: | 2.53 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: KAMILKA-MICHAS | User Name: Kamilka&Michas | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/24 20:10:52 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\Kamilka&Michas\Downloads\OTL.exe

PRC - [2011/06/16 06:51:12 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

PRC - [2011/01/20 11:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe

PRC - [2010/06/08 09:39:00 | 000,847,360 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe

PRC - 2010/05/21 02:16:24 | 011,312,128 | ---- | M -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin

PRC - 2010/05/21 02:16:22 | 011,318,784 | ---- | M -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe

PRC - [2010/05/06 08:44:44 | 001,749,504 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe

PRC - [2010/02/10 16:29:52 | 000,719,360 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe

PRC - 2010/01/19 04:34:48 | 002,201,192 | ---- | M -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe

PRC - [2008/03/20 12:04:46 | 002,127,296 | ---- | M] (Gadu-Gadu S.A.) -- C:\Program Files (x86)\Gadu-Gadu\gg.exe

========== Modules (SafeList) ==========

MOD - [2011/06/24 20:10:52 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\Kamilka&Michas\Downloads\OTL.exe

MOD - [2011/04/08 16:56:28 | 000,018,176 | ---- | M] (McAfee, Inc.) -- c:\PROGRA~2\mcafee\SITEAD~1\saHook.dll

MOD - [2010/08/21 07:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\ comctl32.dll

========== Win32 Services (SafeList) ==========

SRV - [2011/02/16 15:49:08 | 000,101,048 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)

SRV - [2010/04/13 20:11:18 | 000,231,224 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe -- (MOBKbackup)

SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

========== Driver Services (SafeList) ==========

DRV - [2010/11/25 14:28:20 | 000,015,144 | ---- | M] (Windows ® 2003 DDK 3790 provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\rtport.sys -- (rtport)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://samsung.msn.com

IE - HKU.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-4141374535-311919606-3590139362-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://samsung.msn.com

IE - HKU\S-1-5-21-4141374535-311919606-3590139362-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://samsung.msn.com [binary data]

IE - HKU\S-1-5-21-4141374535-311919606-3590139362-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com

IE - HKU\S-1-5-21-4141374535-311919606-3590139362-1001..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)

IE - HKU\S-1-5-21-4141374535-311919606-3590139362-1001\Software\Microsoft\Windows\ CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.wp.pl/"

FF - HKLM\software\mozilla\Firefox\Extensions\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/06/05 18:05:47 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/24 19:17:47 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/19 13:22:06 | 000,000,000 | ---D | M]

[2011/06/24 19:18:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kamilka&Michas\AppData\Roaming\mozilla\Extensions

[2011/06/24 19:17:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions

[2011/01/24 11:49:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

[2011/01/25 11:24:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

[2011/03/09 15:29:31 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}

File not found (No name found) --

[2011/06/16 06:51:12 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll

[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll

[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll

2010/01/01 10:00:00 | 000,002,767 | ---- | M -- C:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml

2010/01/01 10:00:00 | 000,001,406 | ---- | M -- C:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml

2011/05/03 13:36:37 | 000,002,034 | ---- | M -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml

2010/01/01 10:00:00 | 000,000,917 | ---- | M -- C:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml

2010/01/01 10:00:00 | 000,000,858 | ---- | M -- C:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml

2010/01/01 10:00:00 | 000,001,183 | ---- | M -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml

2010/01/01 10:00:00 | 000,001,683 | ---- | M -- C:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()

O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110516231638.dll (McAfee, Inc.)

O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)

O3 - HKLM..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)

O3 - HKLM..\Toolbar: (no name) - Locked - No CLSID value found.

O3 - HKU\S-1-5-21-4141374535-311919606-3590139362-1001..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.

O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)

O4 - HKU\S-1-5-19..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-20..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-4141374535-311919606-3590139362-1001..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)

O4 - HKU\S-1-5-21-4141374535-311919606-3590139362-1001..\Run: [Gadu-Gadu] C:\Program Files (x86)\Gadu-Gadu\gg.exe (Gadu-Gadu S.A.)

O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found

O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found

O4 - Startup: C:\Users\Kamilka&Michas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O13 - gopher Prefix: missing

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)

O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)

O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll (McAfee, Inc.)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - 2011/06/13 10:20:36 | 000,000,000 | ---- | M - C:\autoexec.bat -- [NTFS]

O32 - AutoRun File - 2010/08/16 14:57:50 | 000,000,154 | R--- | M - F:\autorun.cfg -- [UDF]

O32 - AutoRun File - [2010/10/05 16:53:16 | 000,214,344 | R--- | M] (Sports Interactive) - F:\autorun.exe -- [UDF]

O32 - AutoRun File - 2006/09/11 15:26:42 | 000,000,027 | R--- | M - F:\autorun.inf -- [UDF]

O33 - MountPoints2{eefc83c0-9693-11e0-8adb-806e6f6e6963}\Shell - "" = AutoRun

O33 - MountPoints2{eefc83c0-9693-11e0-8adb-806e6f6e6963}\Shell\AutoRun\command - "" = F:\autorun.exe -- [2010/10/05 16:53:16 | 000,214,344 | R--- | M] (Sports Interactive)

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM..comfile [open] -- "%1" %*

O35 - HKLM..exefile [open] -- "%1" %*

O37 - HKLM...com [@ = comfile] -- "%1" %*

O37 - HKLM...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/27 08:28:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

[2011/06/24 20:11:16 | 000,000,000 | ---D | C] -- C:_OTL

[2011/06/24 20:05:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\trend micro

[2011/06/24 20:05:36 | 000,000,000 | ---D | C] -- C:\rsit

[2011/06/24 19:17:55 | 000,000,000 | ---D | C] -- C:\Users\Kamilka&Michas\AppData\Roaming\Mozilla

[2011/06/19 17:23:05 | 000,000,000 | ---D | C] -- C:\Users\Kamilka&Michas\P5JavaClientSettings

[2011/06/19 13:21:50 | 000,000,000 | -HSD | C] -- C:\Config.Msi

[2011/06/18 11:12:03 | 000,000,000 | ---D | C] -- C:\Users\Kamilka&Michas\AppData\Roaming\Malwarebytes

[2011/06/18 11:07:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2011/06/18 10:43:49 | 000,000,000 | ---D | C] -- C:\Users\Kamilka&Michas\Desktop\Armin_Van_Buuren-Mirage__Remixes-WEB-2011-WAV

[2011/06/16 07:02:48 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll

[2011/06/16 07:02:46 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll

[2011/06/16 07:02:46 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll

[2011/06/16 07:02:46 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll

[2011/06/16 07:02:46 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll

[2011/06/16 07:02:45 | 000,386,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec

[2011/06/16 07:02:45 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe

[2011/06/16 07:02:19 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1core.dll

[2011/06/16 07:02:19 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1.dll

[2011/06/14 16:54:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Sports Interactive

[2011/06/14 16:54:17 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Sports Interactive

[2011/06/14 16:54:17 | 000,000,000 | ---D | C] -- C:\Users\Kamilka&Michas\Documents\Sports Interactive

[2011/06/14 16:54:14 | 000,000,000 | ---D | C] -- C:\Users\Kamilka&Michas\AppData\Roaming\Sports Interactive

[2011/06/14 16:54:14 | 000,000,000 | ---D | C] -- C:\Users\Kamilka&Michas\AppData\Local\Sports Interactive

[2011/06/14 16:48:33 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_41.dll

[2011/06/14 16:48:32 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_41.dll

[2011/06/14 16:48:32 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_41.dll

[2011/06/14 16:48:31 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_4.dll

[2011/06/14 16:48:31 | 000,069,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_3.dll

[2011/06/14 16:48:30 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_4.dll

[2011/06/14 16:48:30 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_6.dll

[2011/06/14 16:48:29 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_40.dll

[2011/06/14 16:48:29 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_40.dll

[2011/06/14 16:48:29 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_40.dll

[2011/06/14 16:48:28 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_3.dll

[2011/06/14 16:48:28 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_2.dll

[2011/06/14 16:48:27 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_3.dll

[2011/06/14 16:48:27 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_5.dll

[2011/06/14 16:48:26 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_2.dll

[2011/06/14 16:48:26 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_2.dll

[2011/06/14 16:48:26 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_1.dll

[2011/06/14 16:48:25 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_39.dll

[2011/06/14 16:48:25 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_39.dll

[2011/06/14 16:48:24 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_39.dll

[2011/06/14 16:48:23 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_1.dll

[2011/06/14 16:48:23 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_1.dll

[2011/06/14 16:48:23 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAPOFX1_0.dll

[2011/06/14 16:48:22 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_38.dll

[2011/06/14 16:48:22 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_38.dll

[2011/06/14 16:48:22 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_4.dll

[2011/06/14 16:48:21 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_38.dll

[2011/06/14 16:48:20 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XAudio2_0.dll

[2011/06/14 16:48:20 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine3_0.dll

[2011/06/14 16:48:20 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_3.dll

[2011/06/14 16:48:19 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_37.dll

[2011/06/14 16:48:19 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_37.dll

[2011/06/14 16:48:18 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_37.dll

[2011/06/14 16:48:18 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_10.dll

[2011/06/14 16:48:16 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_36.dll

[2011/06/14 16:48:16 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_36.dll

[2011/06/14 16:48:16 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_36.dll

[2011/06/14 16:48:15 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_9.dll

[2011/06/14 16:48:14 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_35.dll

[2011/06/14 16:48:14 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_35.dll

[2011/06/14 16:48:14 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_35.dll

[2011/06/14 16:48:13 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_8.dll

[2011/06/14 16:48:13 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\X3DAudio1_2.dll

[2011/06/14 16:48:12 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_34.dll

[2011/06/14 16:48:12 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_34.dll

[2011/06/14 16:48:12 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_34.dll

[2011/06/14 16:48:12 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_3.dll

[2011/06/14 16:48:11 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_33.dll

[2011/06/14 16:48:11 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_7.dll

[2011/06/14 16:48:10 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_33.dll

[2011/06/14 16:48:10 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_33.dll

[2011/06/14 16:48:09 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_6.dll

[2011/06/14 16:48:09 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_5.dll

[2011/06/14 16:48:08 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10.dll

[2011/06/14 16:48:07 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_4.dll

[2011/06/14 16:48:07 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_1.dll

[2011/06/14 16:48:06 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_31.dll

[2011/06/14 16:48:06 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_3.dll

[2011/06/14 16:48:05 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_2.dll

[2011/06/14 16:48:05 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_2.dll

[2011/06/14 16:48:04 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_1.dll

[2011/06/14 16:48:04 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xinput1_1.dll

[2011/06/14 16:47:58 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll

[2011/06/14 16:47:57 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xactengine2_0.dll

[2011/06/14 16:47:57 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\x3daudio1_0.dll

[2011/06/14 16:47:55 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_29.dll

[2011/06/14 16:47:55 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_28.dll

[2011/06/14 16:47:54 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_27.dll

[2011/06/14 16:47:54 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_26.dll

[2011/06/14 16:47:53 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_25.dll

[2011/06/14 16:47:52 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_24.dll

[2011/06/14 16:44:59 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Zero G Registry

[2011/06/14 16:43:50 | 000,000,000 | -H-D | C] -- C:\Users\Kamilka&Michas\InstallAnywhere

[2011/06/14 16:36:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Toolbar

[2011/06/14 16:36:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite

[2011/06/14 16:36:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite

[2011/06/14 16:35:52 | 000,000,000 | ---D | C] -- C:\Users\Kamilka&Michas\AppData\Roaming\DAEMON Tools Lite

[2011/06/14 16:35:52 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite

[2011/06/14 16:30:04 | 000,000,000 | ---D | C] -- C:\Users\Kamilka&Michas\Documents\Alcohol 120%

[2011/06/14 16:27:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Alcohol Soft

[2011/06/13 10:45:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy

[2011/06/13 10:45:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy

[2011/06/13 10:20:25 | 000,000,000 | ---D | C] -- C:\sh4ldr

[2011/06/13 10:20:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard

[2011/06/13 10:10:39 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

[2011/06/10 12:02:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Absolute Uninstaller

[2011/06/10 11:35:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Grisoft

[2011/06/07 18:49:21 | 000,000,000 | ---D | C] -- C:\Users\Kamilka&Michas\AppData\Local\Google

========== Files - Modified Within 30 Days ==========

2011/06/27 14:02:34 | 001,835,008 | -HS- | M -- C:\Users\Kamilka&Michas\NTUSER.DAT

2011/06/27 13:54:00 | 000,001,064 | ---- | M -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

2011/06/27 08:28:00 | 000,001,060 | ---- | M -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

2011/06/27 08:27:55 | 000,000,318 | -HS- | M -- C:\Windows\tasks\Hcldwx.job

2011/06/27 08:27:54 | 000,000,006 | -H-- | M -- C:\Windows\tasks\SA.DAT

2011/06/27 08:27:52 | 000,067,584 | --S- | M -- C:\Windows\bootstat.dat

2011/06/27 08:27:47 | 4081,635,328 | -HS- | M -- C:\hiberfil.sys

2011/06/26 22:47:08 | 002,947,474 | -H-- | M -- C:\Users\Kamilka&Michas\AppData\Local\IconCache.db

2011/06/24 19:04:30 | 000,127,994 | ---- | M -- C:\Users\Kamilka&Michas\Desktop\przelewogloszenie.xps

2011/06/24 18:52:52 | 000,089,381 | ---- | M -- C:\Users\Kamilka&Michas\Desktop\bookmarks.html

2011/06/14 16:36:11 | 000,001,950 | ---- | M -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk

2011/06/14 16:32:34 | 000,000,245 | ---- | M -- C:\Users\Kamilka&Michas\Documents\ax_files.xml

2011/06/13 11:09:52 | 000,000,725 | ---- | M -- C:\Windows\wininit.ini

2011/06/13 10:20:36 | 000,000,000 | ---- | M -- C:\autoexec.bat

[2011/06/13 10:10:39 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2011/06/10 11:27:44 | 000,086,528 | RHS- | M -- C:\Windows\SysWow64\EncDecv.dll

2011/06/01 20:53:48 | 000,001,490 | ---- | M -- C:\Windows\win.ini

========== Files Created - No Company Name ==========

2011/06/24 19:17:49 | 000,001,146 | ---- | C -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk

2011/06/24 19:04:27 | 000,127,994 | ---- | C -- C:\Users\Kamilka&Michas\Desktop\przelewogloszenie.xps

2011/06/24 18:52:51 | 000,089,381 | ---- | C -- C:\Users\Kamilka&Michas\Desktop\bookmarks.html

2011/06/14 16:36:11 | 000,001,950 | ---- | C -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk

2011/06/14 16:30:55 | 000,000,245 | ---- | C -- C:\Users\Kamilka&Michas\Documents\ax_files.xml

2011/06/13 11:09:51 | 000,000,725 | ---- | C -- C:\Windows\wininit.ini

2011/06/13 10:20:36 | 000,000,000 | ---- | C -- C:\autoexec.bat

2011/06/10 11:27:44 | 000,086,528 | RHS- | C -- C:\Windows\SysWow64\EncDecv.dll

2011/06/10 11:27:44 | 000,000,318 | -HS- | C -- C:\Windows\tasks\Hcldwx.job

2011/06/07 18:49:31 | 000,001,064 | ---- | C -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

2011/06/07 18:49:31 | 000,001,060 | ---- | C -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

2011/05/17 21:12:39 | 000,003,584 | ---- | C -- C:\Users\Kamilka&Michas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF. ini

2011/01/20 17:28:47 | 002,947,474 | -H-- | C -- C:\Users\Kamilka&Michas\AppData\Local\IconCache.db

2011/01/20 16:31:14 | 000,062,952 | ---- | C -- C:\Users\Kamilka&Michas\AppData\Local\GDIPFONTCACHEV1.DAT

2011/01/20 16:24:08 | 000,131,368 | ---- | C -- C:\ProgramData\FullRemove.exe

2010/08/06 01:58:57 | 000,870,560 | ---- | C -- C:\Windows\SysWow64\igkrng575.bin

2010/08/06 01:58:57 | 000,208,896 | ---- | C -- C:\Windows\SysWow64\iglhsip32.dll

2010/08/06 01:58:57 | 000,143,360 | ---- | C -- C:\Windows\SysWow64\iglhcp32.dll

2010/08/06 01:58:55 | 000,104,636 | ---- | C -- C:\Windows\SysWow64\igfcg575m.bin

2010/08/06 01:58:54 | 000,127,868 | ---- | C -- C:\Windows\SysWow64\igcompkrng575.bin

2010/08/05 10:44:59 | 000,307,200 | ---- | C -- C:\Windows\SetDisplayResolution.exe

2010/08/05 09:51:56 | 000,001,960 | ---- | C -- C:\Windows\HotFixList.ini

2010/01/20 20:19:16 | 000,155,648 | ---- | C -- C:\Windows\SysWow64\msmicko-d.dll

2009/07/14 07:38:36 | 000,067,584 | --S- | C -- C:\Windows\bootstat.dat

2009/07/14 04:35:51 | 000,000,741 | ---- | C -- C:\Windows\SysWow64\NOISE.DAT

2009/07/14 04:35:42 | 000,001,405 | ---- | C -- C:\Windows\msdfmap.ini

2009/07/14 04:34:57 | 000,001,490 | ---- | C -- C:\Windows\win.ini

2009/07/14 04:34:57 | 000,000,219 | ---- | C -- C:\Windows\system.ini

2009/07/14 04:34:42 | 000,215,943 | ---- | C -- C:\Windows\SysWow64\dssec.dat

2009/07/14 02:10:29 | 000,043,131 | ---- | C -- C:\Windows\mib.bin

2009/07/14 01:42:10 | 000,064,000 | ---- | C -- C:\Windows\SysWow64\BWContextHandler.dll

2009/07/13 23:59:36 | 000,982,196 | ---- | C -- C:\Windows\SysWow64\igkrng500.bin

2009/07/13 23:59:36 | 000,139,824 | ---- | C -- C:\Windows\SysWow64\igfcg500.bin

2009/07/13 23:59:36 | 000,097,448 | ---- | C -- C:\Windows\SysWow64\igfcg500m.bin

2009/07/13 23:59:35 | 000,417,344 | ---- | C -- C:\Windows\SysWow64\igcompkrng500.bin

2009/07/13 23:03:59 | 000,364,544 | ---- | C -- C:\Windows\SysWow64\msjetoledb40.dll

2009/06/20 17:49:08 | 000,009,849 | ---- | C -- C:\Windows\SysWow64\mswinko-e.dll

2009/06/10 23:26:10 | 000,673,088 | ---- | C -- C:\Windows\SysWow64\mlang.dat

2005/10/14 11:56:50 | 003,596,288 | ---- | C -- C:\Windows\SysWow64\qt-dx331.dll

2005/10/14 11:56:50 | 000,921,600 | ---- | C -- C:\Windows\SysWow64\VorbisEnc.dll

2005/10/14 11:56:50 | 000,778,240 | ---- | C -- C:\Windows\SysWow64\DivXsm.exe

2005/10/14 11:56:50 | 000,761,856 | ---- | C -- C:\Windows\SysWow64\xvidcore.dll

2005/10/14 11:56:50 | 000,344,064 | ---- | C -- C:\Windows\SysWow64\xvid.dll

2005/10/14 11:56:50 | 000,237,568 | ---- | C -- C:\Windows\SysWow64\OggDS.dll

2005/10/14 11:56:50 | 000,188,416 | ---- | C -- C:\Windows\SysWow64\vorbis.dll

2005/10/14 11:56:50 | 000,045,056 | ---- | C -- C:\Windows\SysWow64\ogg.dll

========== LOP Check ==========

[2011/06/14 16:43:04 | 000,000,000 | ---D | M] -- C:\Users\Kamilka&Michas\AppData\Roaming\DAEMON Tools Lite

[2011/03/15 21:13:07 | 000,000,000 | ---D | M] -- C:\Users\Kamilka&Michas\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46. 1

[2011/01/20 20:54:16 | 000,000,000 | ---D | M] -- C:\Users\Kamilka&Michas\AppData\Roaming\Gadu-Gadu

[2011/05/27 15:23:38 | 000,000,000 | ---D | M] -- C:\Users\Kamilka&Michas\AppData\Roaming\GlarySoft

[2011/01/20 18:22:31 | 000,000,000 | ---D | M] -- C:\Users\Kamilka&Michas\AppData\Roaming\HEXelon

[2011/01/25 11:34:07 | 000,000,000 | ---D | M] -- C:\Users\Kamilka&Michas\AppData\Roaming\IrfanView

[2011/04/17 07:44:18 | 000,000,000 | ---D | M] -- C:\Users\Kamilka&Michas\AppData\Roaming\Microgaming

[2011/02/02 11:58:29 | 000,000,000 | ---D | M] -- C:\Users\Kamilka&Michas\AppData\Roaming\OpenOffice.org

[2011/06/14 16:54:14 | 000,000,000 | ---D | M] -- C:\Users\Kamilka&Michas\AppData\Roaming\Sports Interactive

2011/06/27 08:27:55 | 000,000,318 | -HS- | M -- C:\Windows\Tasks\Hcldwx.job

2011/04/28 20:09:20 | 000,032,522 | ---- | M -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 215 bytes -> C:\ProgramData\Temp:8927A071

@Alternate Data Stream - 117 bytes -> C:\ProgramData\Temp:E7BA7168

< End of report >

i Extras:

OTL Extras logfile created on: 6/27/2011 2:01:17 PM - Run 1

OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Kamilka&Michas\Downloads

64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7600.16385)

Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

3.80 Gb Total Physical Memory | 2.27 Gb Available Physical Memory | 59.62% Memory free

7.60 Gb Paging File | 5.68 Gb Available in Paging File | 74.74% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 101.00 Gb Total Space | 72.29 Gb Free Space | 71.57% Space Free | Partition Type: NTFS

Drive D: | 344.66 Gb Total Space | 316.74 Gb Free Space | 91.90% Space Free | Partition Type: NTFS

Drive F: | 2.53 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: KAMILKA-MICHAS | User Name: Kamilka&Michas | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes]

.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-4141374535-311919606-3590139362-1001\SOFTWARE\Classes]

.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\shell[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

htafile [open] -- "%1" %*

htmlfile [edit] -- Reg Error: Key error.

htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\DomainProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\PublicProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

========== Authorized Applications List ==========

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam

"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 4

"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager

"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Narzędzie do przekazywania usługi Windows Live

"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT

"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24

"{27C467F8-F8EF-4f68-BD72-D63632B2096C}" = McAfee Online Backup

"{2DDC70C1-C77A-4D08-89D2-9AB648504533}" = Easy Content Share

"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform

"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology

"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4A331D24-A9E8-484F-835E-1BA7B139689C}" = EasyBatteryManager

"{4D5219EC-BFF8-4B7F-AB92-6D827BB37CB0}" = Windows Live Messenger

"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin

"{74A579FB-EB06-497D-B194-01590D6FE51A}" = BatteryLifeExtender

"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113128447}" = Daycare Nightmare

"{8727531E-6C58-4852-A90B-39CF45E269A9}" = OpenOffice.org 3.2

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update

"{9AB614A6-719C-4A6E-A63E-831E0A35F62A}" = Windows Live Writer

"{A05BE20E-6510-44BC-95ED-6E6D730407D3}" = Vplayer

"{AA7B0DE4-E3CA-443F-B1CF-418431664C63}" = Windows Live Movie Maker

"{AC76BA86-7AD7-1045-7B44-A94000000001}" = Adobe Reader 9.4.5 - Polish

"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide

"{C35FE07E-24B5-410F-85B7-122087A0C7DD}" = Poczta usługi Windows Live

"{C4582EED-A3FB-4358-8F3F-8C994460DF28}" = EasyFileShare

"{C5096D00-8B9C-41DB-8472-9D721E982DF0}" = Podstawowe programy Windows Live

"{D1434266-0486-4469-B338-A60082CC04E1}" = Atheros Client Installation Program

"{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}" = Samsung Update Plus

"{E39C185F-1240-4BA7-A03B-4FD99805D63E}" = Galeria fotografii usługi Windows Live

"{E580DFEA-3F1D-4B56-9115-984217032FF5}" = Windows Live Sync

"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager

"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard

"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F687E657-F636-44DF-8125-9FEEA2C362F5}" = Samsung Support Center

"{F9557866-B4C8-4CE5-8508-0E386BDC20B2}" = Easy Network Manager

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0

"DAEMON Tools Lite" = DAEMON Tools Lite

"Football Manager 2011" = Football Manager 2011

"Gadu-Gadu" = Gadu-Gadu 7.7

"HEXelon MAX_is1" = HEXelon MAX 6.07

"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam

"IrfanView" = IrfanView (remove only)

"Mozilla Firefox 5.0 (x86 pl)" = Mozilla Firefox 5.0 (x86 pl)

"MSC" = McAfee Total Protection

"WinLiveSuite_Wave3" = Podstawowe programy Windows Live

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-4141374535-311919606-3590139362-1001\SOFTWARE\Microsoft\Windows\ CurrentVersion\Uninstall]

"BankBrowser" = BankBrowser

========== Last 10 Event Log Errors ==========

[Application Events]

Error - 6/10/2011 6:10:56 AM | Computer Name = Kamilka-Michas | Source = SideBySide | ID = 16842785

Description = Nie można wygenerować kontekstu aktywacji dla "C:\Users\KAMILK~1\AppData\Local\Temp\RarSFX0\MFC80U.DLL" .

Nie

można odnaleźć zestawu zależnego Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b" ,type="win32",version="8.0.50608.0".

Użyj

narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.

Error - 6/10/2011 6:10:56 AM | Computer Name = Kamilka-Michas | Source = SideBySide | ID = 16842785

Description = Nie można wygenerować kontekstu aktywacji dla "C:\Users\KAMILK~1\AppData\Local\Temp\RarSFX0\MFC80U.DLL" .

Nie

można odnaleźć zestawu zależnego Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b" ,type="win32",version="8.0.50608.0".

Użyj

narzędzia sxstrace.exe, aby uzyskać szczegółową diagnozę.

Error - 6/10/2011 6:40:29 AM | Computer Name = Kamilka-Michas | Source = VSS | ID = 8194

Description =

Error - 6/11/2011 5:41:39 AM | Computer Name = Kamilka-Michas | Source = SideBySide | ID = 16842787

Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files (x86)\windows

live\photo gallery\MovieMaker.Exe". Błąd w pliku manifestu lub w pliku zasad "c:\program

files (x86)\windows live\photo gallery\WLMFDS.DLL" w wierszu 8. Tożsamość składnika

znaleziona w manifeście nie odpowiada tożsamości składnika żądanego. Odwołanie to

WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definicja to

WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Użyj narzędzia

sxstrace.exe, aby uzyskać szczegółową diagnozę.

Error - 6/13/2011 4:12:18 AM | Computer Name = Kamilka-Michas | Source = VSS | ID = 8194

Description =

Error - 6/13/2011 5:14:29 AM | Computer Name = Kamilka-Michas | Source = VSS | ID = 8194

Description =

Error - 6/13/2011 5:47:25 AM | Computer Name = Kamilka-Michas | Source = SideBySide | ID = 16842787

Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files (x86)\windows

live\photo gallery\MovieMaker.Exe". Błąd w pliku manifestu lub w pliku zasad "c:\program

files (x86)\windows live\photo gallery\WLMFDS.DLL" w wierszu 8. Tożsamość składnika

znaleziona w manifeście nie odpowiada tożsamości składnika żądanego. Odwołanie to

WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definicja to

WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Użyj narzędzia

sxstrace.exe, aby uzyskać szczegółową diagnozę.

Error - 6/13/2011 5:47:41 AM | Computer Name = Kamilka-Michas | Source = SideBySide | ID = 16842815

Description = Nie można wygenerować kontekstu aktywacji dla "c:\program files (x86)\spybot

  • search & destroy\DelZip179.dll". Błąd w pliku manifestu lub w pliku zasad "c:\program

files (x86)\spybot - search & destroy\DelZip179.dll" w wierszu 8. Wartość "*" atrybutu

"language" elementu "assemblyIdentity" jest nieprawidłowa.

Error - 6/14/2011 10:27:56 AM | Computer Name = Kamilka-Michas | Source = VSS | ID = 8194

Description =

Error - 6/14/2011 10:40:47 AM | Computer Name = Kamilka-Michas | Source = Application Error | ID = 1000

Description = Nazwa aplikacji powodującej błąd: firefox.exe, wersja: 2.0.1.4120,

sygnatura czasowa: 0x4da6a9fb Nazwa modułu powodującego błąd: DTToolbarFF4.dll,

wersja: 1.1.7.190, sygnatura czasowa: 0x4db0292c Kod wyjątku: 0xc000000d Przesunięcie

błędu: 0x0009f66b Identyfikator procesu powodującego błąd: 0xd2c Godzina uruchomienia

aplikacji powodującej błąd: 0x01cc2aa0d597b56b Ścieżka aplikacji powodującej błąd:

C:\Program Files (x86)\Mozilla Firefox\firefox.exe Ścieżka modułu powodującego błąd:

C:\Users\Kamilka&Michas\AppData\Roaming\Mozilla\Firefox\Profiles\ siffosq0.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF4.dll

Identyfikator

raportu: 4a16e9d3-9694-11e0-8adb-002454fed9e5

[System Events]

Error - 6/16/2011 11:19:00 AM | Computer Name = Kamilka-Michas | Source = Service Control Manager | ID = 7001

Description = Usługa SBSD Security Center Service zależy od usługi Centrum zabezpieczeń,

której nie można uruchomić z powodu następującego błędu: %%1058

Error - 6/16/2011 11:21:13 AM | Computer Name = Kamilka-Michas | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Usługa Google Update (gupdate) z powodu

następującego błędu: %%2

Error - 6/17/2011 2:03:58 AM | Computer Name = Kamilka-Michas | Source = Service Control Manager | ID = 7001

Description = Usługa SBSD Security Center Service zależy od usługi Centrum zabezpieczeń,

której nie można uruchomić z powodu następującego błędu: %%1058

Error - 6/17/2011 2:06:10 AM | Computer Name = Kamilka-Michas | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Usługa Google Update (gupdate) z powodu

następującego błędu: %%2

Error - 6/17/2011 8:13:10 PM | Computer Name = Kamilka-Michas | Source = Service Control Manager | ID = 7001

Description = Usługa SBSD Security Center Service zależy od usługi Centrum zabezpieczeń,

której nie można uruchomić z powodu następującego błędu: %%1058

Error - 6/17/2011 8:15:19 PM | Computer Name = Kamilka-Michas | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Usługa Google Update (gupdate) z powodu

następującego błędu: %%2

Error - 6/18/2011 5:03:40 AM | Computer Name = Kamilka-Michas | Source = Service Control Manager | ID = 7001

Description = Usługa SBSD Security Center Service zależy od usługi Centrum zabezpieczeń,

której nie można uruchomić z powodu następującego błędu: %%1058

Error - 6/18/2011 5:05:48 AM | Computer Name = Kamilka-Michas | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Usługa Google Update (gupdate) z powodu

następującego błędu: %%2

Error - 6/18/2011 6:32:03 AM | Computer Name = Kamilka-Michas | Source = Service Control Manager | ID = 7001

Description = Usługa SBSD Security Center Service zależy od usługi Centrum zabezpieczeń,

której nie można uruchomić z powodu następującego błędu: %%1058

Error - 6/18/2011 6:34:27 AM | Computer Name = Kamilka-Michas | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Usługa Google Update (gupdate) z powodu

następującego błędu: %%2

< End of report >

Z gory dziekuje za pomoc,pozdrawiam


(Spandau) #2

Odinstaluj C:\Program Files (x86)\ DAEMON Tools Toolbar

W okno Własne opcje skanowania / skrypt w OTL wklej:

Klikasz na Wykonaj skrypt. Zgadzasz się na restart komputera. Log z usuwania na forum

Następnie ponownie uruchamiasz OTL klikasz raz jeszcze Skanuj i dajesz nowy log na forum Czyli dwa logi jeden z usuwania drugi z nowego skanowania po usuwaniu. Logi wklej na http://www.wklej.org a w poście podaj linka do wklejki


(Mankiet) #3

skrypt po resecie:

http://www.wklej.org/id/553512/

i pozniejszy po skanowaniu:

http://www.wklej.org/id/553514/

prosze zobaczyc czy wszystko ok.

dziekuje.


(Spandau) #4

To co chciałem zostało usunięte

Uruchom OTL klikasz Sprzątanie

Wykonaj pełny skan Malwarebytes http://www.dobreprogramy.pl/Malwarebyte ... 13117.html Jak program coś znajdzie podaj raport na forum Po tym przejdziemy do aktualizacji systemu i oprogramowania


(Mankiet) #5

uruchomilem w OTL sprzatanie potem skan

i wynik:

Malwarebytes' Anti-Malware 1.51.0.1200

www.malwarebytes.org

Wersja bazy: 6959

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

2011-06-27 17:46:34

mbam-log-2011-06-27 (17-46-34).txt

Typ skanowania: Pełne skanowanie (C:\|D:\|)

Przeskanowano obiektów: 249461

Upłynęło: 35 minut(y), 38 sekund(y)

Zainfekowanych procesów w pamięci: 0

Zainfekowanych modułów w pamięci: 0

Zainfekowanych kluczy rejestru: 0

Zainfekowanych wartości rejestru: 0

Zainfekowane informacje rejestru systemowego: 0

Zainfekowanych folderów: 0

Zainfekowanych plików: 0

Zainfekowanych procesów w pamięci:

(Nie znaleziono zagrożeń)

Zainfekowanych modułów w pamięci:

(Nie znaleziono zagrożeń)

Zainfekowanych kluczy rejestru:

(Nie znaleziono zagrożeń)

Zainfekowanych wartości rejestru:

(Nie znaleziono zagrożeń)

Zainfekowane informacje rejestru systemowego:

(Nie znaleziono zagrożeń)

Zainfekowanych folderów:

(Nie znaleziono zagrożeń)

Zainfekowanych plików:

(Nie znaleziono zagrożeń)

czekam na kolejne kroki,jesli sa potrzebne,pozdrawiam


(Spandau) #6

Tak są po pierwsze aktualizacja systemu Mamy już SP1 dla windows7 oraz IE9

SP1 Windows 7 64bity Internet Explorer 9

Java 6 Update 26 OpenOffice.org 3.3

No i ta staroć

Gadu-Gadu 10.5


(Mankiet) #7

hej,jave windowsa zaktualizowalem...gg zostawilem-przyzwyczailem sie do tej wersji...dziekuje za poprowadzenie krok po kroku.Jesli mam zainstalowanego McAfee to skasowac Malwarebytes' Anti-Malware? Czy to juz wszystko?


(Spandau) #8

Nie zostaw go sobie możesz nim skanować od czasu do czasu. Będzie on dobrym uzupełnieniem do antywirusa. Tak to już wszystko


(Mankiet) #9

nalezy Ci sie piwko w realu za pomoc . DZIEKUJE