x-kom hosting

Proszę o sprawdzenie loga

ranshou
utworzono
utworzono
Może sobie działać, o ile Combofix się uruchomi. Jeśli nie to w trybie awaryjnym spróbuj.

ummm musiałam zrobić loga w trybie awaryjnym :

Log do sprawdzenia
ComboFix 09-04-25.01 - Basia 2009-04-26 10:19.1 - NTFSx86 NETWORK

Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.511.398 [GMT 2:00]

Uruchomiony z: c:\documents and settings\Basia\Pulpit\ComboFix.exe

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

.

((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Basia\Dane aplikacji\EurekaLog

c:\documents and settings\Basia\Dane aplikacji\EurekaLog\EurekaLog.ini

.

((((((((((((((((((((((((( Pliki utworzone od 2009-05-26 do 2009-4-26 )))))))))))))))))))))))))))))))

.

2009-04-25 19:07 . 2009-04-25 19:07 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\nView_Profiles

2009-04-25 19:04 . 2009-04-25 19:06 -------- d-----w c:\windows\nview

2009-04-25 19:04 . 2004-07-15 09:42 172032 ----a-w c:\windows\system32\nvudisp.exe

2009-04-25 19:04 . 2004-07-15 09:42 13474 ----a-w c:\windows\system32\nvdisp.nvu

2009-04-25 19:04 . 2009-04-25 19:04 -------- d-----w C:\NVIDIA

2009-04-25 17:44 . 2009-04-25 20:33 -------- d-----w c:\documents and settings\Basia\Dane aplikacji\X-Chat 2

2009-04-25 17:23 . 2008-08-20 17:58 129520 ------w c:\windows\system32\pxafs.dll

2009-04-25 17:23 . 2009-04-26 08:09 -------- d-----w c:\documents and settings\Basia\Dane aplikacji\winamp

2009-04-25 17:06 . 2005-01-28 15:48 2310272 ------w c:\windows\system32\drivers\alcxwdm.sys

2009-04-25 17:06 . 2005-01-24 18:22 9294336 ------w c:\windows\system32\RTLCPL.exe

2009-04-25 17:06 . 2005-01-20 18:04 77824 ------w c:\windows\soundman.exe

2009-04-25 17:06 . 2004-10-27 13:47 40960 ------w c:\windows\system32\ChCfg.exe

2009-04-25 17:06 . 2004-09-07 12:23 156672 ------w c:\windows\system32\RtlCPAPI.dll

2009-04-25 17:06 . 2002-02-05 11:54 141016 ------w c:\windows\system32\alsndmgr.wav

2009-04-25 17:06 . 2005-01-24 18:32 17592320 ------w c:\windows\system32\alsndmgr.cpl

2009-04-25 17:06 . 2004-11-05 14:29 208896 ------w c:\windows\alcupd.exe

2009-04-25 17:06 . 2004-09-01 18:04 139264 ------w c:\windows\alcrmv.exe

2009-04-25 10:08 . 2009-04-25 10:08 -------- d--h--w C:\$AVG8.VAULT$

2009-04-25 09:44 . 2009-04-25 09:43 73728 ----a-w c:\windows\system32\javacpl.cpl

2009-04-25 09:44 . 2009-04-25 09:43 410984 ----a-w c:\windows\system32\deploytk.dll

2009-04-25 09:38 . 2009-04-25 09:40 -------- d-----w c:\documents and settings\Basia\Dane aplikacji\gtk-2.0

2009-04-25 09:38 . 2009-04-25 09:38 -------- d-----w c:\documents and settings\Basia\.thumbnails

2009-04-24 18:10 . 2007-06-27 12:42 207488 ----a-r c:\windows\system32\drivers\vinyl97.sys

2009-04-24 18:10 . 2007-04-11 13:35 331184 ------w c:\windows\system32\difxapi.dll

2009-04-24 13:53 . 2009-04-24 13:53 -------- d-----w c:\documents and settings\Basia\Dane aplikacji\Samsung

2009-04-24 13:39 . 2006-05-03 20:53 174592 ----a-w c:\windows\system32\framedyn.dll

2009-04-24 13:39 . 2003-02-21 16:42 348160 ----a-w c:\windows\system32\msvcr71.dll

2009-04-24 13:38 . 2009-04-24 13:50 5632 ----a-w c:\windows\system32\drivers\StarOpen.sys

2009-04-24 13:37 . 2009-04-24 13:39 -------- d-----w c:\windows\system32\Samsung_USB_Drivers

2009-04-24 13:37 . 2005-08-30 15:59 94000 ----a-w c:\windows\system32\drivers\ss_mdm.sys

2009-04-24 13:37 . 2005-08-30 15:58 8304 ----a-w c:\windows\system32\drivers\ss_mdfl.sys

2009-04-24 13:37 . 2005-08-30 15:58 6144 ----a-w c:\windows\system32\drivers\ss_cmnt.sys

2009-04-24 13:37 . 2005-08-30 15:58 6144 ----a-w c:\windows\system32\drivers\ss_cm.sys

2009-04-24 13:37 . 2005-08-30 15:57 58320 ----a-w c:\windows\system32\drivers\ss_bus.sys

2009-04-24 13:37 . 2005-08-30 15:57 5808 ----a-w c:\windows\system32\drivers\ss_whnt.sys

2009-04-24 13:37 . 2005-08-30 15:57 5808 ----a-w c:\windows\system32\drivers\ss_wh.sys

2009-04-24 13:37 . 2005-08-28 18:51 766 ----a-w c:\windows\system32\Uninstall.ico

2009-04-24 13:01 . 2009-04-24 13:01 -------- d-----w c:\documents and settings\Basia\Ustawienia lokalne\Dane aplikacji\Innovative Solutions

2009-04-23 19:23 . 2009-04-25 09:31 -------- d-----w c:\documents and settings\Basia\.gimp-2.6

2009-04-23 19:23 . 2009-04-23 19:23 -------- d-----w c:\documents and settings\Basia\.gegl-0.0

2009-04-23 19:18 . 2009-04-26 08:14 -------- d-----w c:\documents and settings\Basia\Dane aplikacji\WTablet

2009-04-23 19:17 . 2008-04-14 22:59 1532082 ------w c:\windows\system32\PenTablet.znc

2009-04-23 19:17 . 2008-05-01 22:31 3708200 ------w c:\windows\system32\PenTablet.cpl

2009-04-23 19:17 . 2007-02-16 00:11 11440 ----a-w c:\windows\system32\drivers\WacomVKHid.sys

2009-04-23 19:17 . 2008-01-15 20:11 13480 ----a-w c:\windows\system32\drivers\wacomvhid.sys

2009-04-23 19:17 . 2007-02-16 19:12 11312 ----a-w c:\windows\system32\drivers\wacommousefilter.sys

2009-04-23 19:17 . 2008-03-17 20:14 15144 ----a-w c:\windows\system32\drivers\wacmoumonitor.sys

2009-04-23 19:16 . 2009-04-23 19:16 -------- d-----w c:\windows\system32\WTablet

2009-04-23 19:16 . 2008-05-01 22:23 181544 ------w c:\windows\system32\Wintab32.dll

2009-04-23 19:16 . 2008-05-01 22:40 3032360 ------w c:\windows\system32\Pen_Tablet.exe

2009-04-23 19:16 . 2008-05-01 22:33 128296 ------w c:\windows\system32\Pen_Tablet.dll

2009-04-23 19:16 . 2001-10-26 14:57 12160 -c--a-w c:\windows\system32\dllcache\mouhid.sys

2009-04-23 19:16 . 2001-10-26 14:57 12160 ----a-w c:\windows\system32\drivers\mouhid.sys

2009-04-23 17:34 . 2009-04-23 17:36 -------- d-----w c:\documents and settings\Basia\Ustawienia lokalne\Dane aplikacji\Adobe

2009-04-23 17:28 . 2009-04-23 17:28 -------- d-----w c:\documents and settings\Basia\Dane aplikacji\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1

2009-04-23 13:30 . 2009-04-23 13:30 -------- d-----w c:\documents and settings\Basia\Ustawienia lokalne\Dane aplikacji\Identities

2009-04-23 13:15 . 2009-04-23 13:15 18480 ----a-w c:\documents and settings\Basia\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT

2009-04-23 13:14 . 2009-04-23 13:14 -------- d-----w c:\documents and settings\Basia\WapSter

2009-04-23 10:47 . 2009-04-23 10:47 -------- d-----w c:\documents and settings\Basia\Ustawienia lokalne\Dane aplikacji\Opera

2009-04-23 10:43 . 2009-04-23 10:43 -------- d-s---w c:\documents and settings\Basia\UserData

2009-04-22 19:17 . 1998-10-07 10:54 327168 ----a-w c:\windows\IsUn0415.exe

.

(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-04-25 17:06 . 2009-04-24 13:37 -------- d--h--w c:\program files\InstallShield Installation Information

2009-04-25 17:06 . 2009-04-24 13:36 -------- d-----w c:\program files\Common Files\InstallShield

2009-04-25 15:22 . 2009-04-20 08:48 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat

2009-04-25 09:43 . 2009-04-25 09:43 -------- d-----w c:\program files\Java

2009-04-25 08:44 . 2009-04-20 09:12 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\avg8

2009-04-24 18:11 . 2009-04-24 18:10 -------- d-----w c:\program files\VIA

2009-04-24 13:37 . 2009-04-24 13:37 -------- d-----w c:\program files\Samsung

2009-04-23 19:17 . 2009-04-23 19:16 -------- d-----w c:\program files\Tablet

2009-04-23 17:33 . 2009-04-23 17:33 -------- d-----w c:\program files\Common Files\Adobe

2009-04-23 17:28 . 2009-04-23 17:28 -------- d-----w c:\program files\Common Files\Adobe AIR

2009-04-23 10:43 . 2009-04-20 09:12 -------- d-----w c:\documents and settings\Basia\Dane aplikacji\AVGTOOLBAR

2009-04-20 09:16 . 2009-04-20 09:16 -------- d-----w c:\program files\Google

2009-04-20 09:12 . 2009-04-20 09:12 10520 ----a-w c:\windows\system32\avgrsstx.dll

2009-04-20 09:12 . 2009-04-20 09:12 107272 ----a-w c:\windows\system32\drivers\avgtdix.sys

2009-04-20 09:12 . 2009-04-20 09:12 325128 ----a-w c:\windows\system32\drivers\avgldx86.sys

2009-04-20 09:12 . 2009-04-20 09:12 -------- d-----w c:\program files\AVG

2009-04-20 08:57 . 2001-10-26 16:15 49492 ----a-w c:\windows\system32\perfc015.dat

2009-04-20 08:57 . 2001-10-26 16:15 355486 ----a-w c:\windows\system32\perfh015.dat

2009-04-20 08:50 . 2009-04-20 08:50 -------- d-----w c:\program files\microsoft frontpage

2009-04-20 08:46 . 2009-04-20 08:46 -------- d-----w c:\program files\Usługi online

2009-04-20 08:44 . 2009-04-20 08:44 21856 ----a-w c:\windows\system32\emptyregdb.dat

2009-04-08 21:25 . 2009-04-08 21:25 3366912 ----a-w c:\windows\system32\GPhotos.scr

.

((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

"AQQ"="d:\ranshou\inne\WAPSTE~1\AQQ.exe" [2009-02-25 4879360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-20 1601304]

"Adobe Reader Speed Launcher"="d:\ranshou\inne\adobe rader\Reader\Reader_sl.exe" [2008-01-11 39792]

"AudioDeck"="c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe" [2007-08-09 528384]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-25 148888]

"WinampAgent"="d:\winamp\winampa.exe" [2009-04-22 37888]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-15 4112384]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-07-15 81920]

"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-01-20 77824]

"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-07-15 843776]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\All Users\Menu Start\Programy\Autostart\

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-04-20 09:12 10520 ----a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

"d:\\RANSHOU\\inne\\WapSter AQQ\\AQQ.exe"=

"d:\\Xchat\\xchat.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-20 325128]

R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-04-20 903960]

R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-20 298264]

R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-05-01 3032360]

R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2008-03-17 15144]

S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-20 107272]

.

.

------- Skan uzupełniający -------

.

uStart Page = hxxp://google.pl/

uDefault_Search_URL = hxxp://www.google.com/ie

uInternet Settings,ProxyServer = 10.0.0.50:80

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

TCP: {7970B1F7-5102-4746-986B-BA57EC793D51} = 213.172.186.4,213.172.186.5

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-04-26 10:22

Windows 5.1.2600 Dodatek Service Pack 2 NTFS

skanowanie ukrytych procesów ...

skanowanie ukrytych wpisów autostartu ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

AudioDeck = c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe 1????????????????????????????????????????????????

skanowanie ukrytych plików ...

skanowanie pomyślnie ukończone

ukryte pliki: 0

**************************************************************************

.

Czas ukończenia: 2009-04-26 10:23

ComboFix-quarantined-files.txt 2009-04-26 08:23

Przed: 3 949 187 072 bajtów wolnych

Po: 4 039 000 064 bajtów wolnych

WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

172

i jeszcze mi zniknął po skanie pasek narzędzi i ikony (potem się nie pojawiły) :blink: nie wiem czy to normalne... aczkolwiek informuję na zapas jakby coś...(podzczas skanowania też zniknął.... a potem się pojawił)

http://support.microsoft.com/kb/293078/pl

Zainstaluj jakieś inne niż obecnie sterowniki do karty graficznej.

Wcześniej odinstaluj je tym programem: http://dobreprogramy.pl/index.php?dz=2&amp...ver+Cleaner+3.3

Jeśli masz z płyty to zainstaluj jakieś z sieci, jeśli z sieci to z płyty.

zainstalowałam z neta.... narazie nie było blue-screena :)

Panel sterowania --> Dźwięki i urządzenia audio

Kolejno zakładki: Głośność, ustaw na max, siła głośników na dole - na maxa, Zaawansowane (w głośność urządzenia) - na maxa, Zaawansowane (ustawienia głośników) - tu ustaw sobie swoje głośniki, np. 5.1 kiedy masz 5.1

ale ja własnie tak robiłam i nic nie działa... <_< "

a w utawieniach głośników próbowałam wszystkich mozliwości Y_Y"

//Proponowałbym przenieść się z logiem do działu Logi do sprawdzenia

//Michał Paluch

//Przenoszę do działu Bezpieczeństwo

//Andziorka

//Daje tagi

//MarekM25

Gość
komentarz
komentarz

W logu nic nie ma.

1. Usuń ręcznie folder C:\Qoobox.

2. Z folderu "System Volume Information" usuniesz poprzez chwilowe wyłączenie "Przywracania Systemu":

>Panel Sterowania>System>Przywracanie Systemu>>zaznacz w okienku przy "Wyłącz przywracanie na wszystkich dyskach">Zastosuj>OK.

Potem możesz powrócić do poprzedniego ustawienia (czyli usunąć zaznaczenie z okienka).

3. Wykonaj optymalizację systemu

4.Przeskanuj obszar mojego komputera http://www.kaspersky.pl/virusscanner.html (uruchom przez IE) Daj raport z niego na forum.

.

ranshou
komentarz
komentarz

niestety nie moge przeprowadzić skanowania kasperskym o albo podczas skanowania komputera się wyłącza przeglądarka , albo pokazuje mi się coś takiego http://ifotos.pl/?page=2ℑ=109058.jpg :wsciekly:

poprzednie 3 rzeczy zrobiłam <_<"

Psycholandia
komentarz
komentarz

Musisz w Internet Explorer uruchomić skaner.

  • 2 tygodnie później...
ranshou
komentarz
komentarz (edytowane)

Próbowałam chyba 4 razy ale to nic nie daje :< ciągle ten sam błąd wyskakuje (w IE)

  • 4 miesiące później...
ranshou
komentarz
komentarz

Miałam format kompa i nadal wyskakiwał błąd ... kolega powiedział żebym wyjęła kość ramu i... zadziałało! XD
niestety chyba mam zwalony slot bo wkładałam inne karty ramu (takiej samej częstotliwości btw.) i nadal wyskakiwał b-skriny :(

no cóż.. zostaje mi działać na tej jednej bo kupowanie nowych kości sdRAM sie raczej nie opłaca :<

mimo wszystko dzięki ^^

uważam ,że temat do zamknięcia ;)

Psycholandia
komentarz
komentarz

A smarowałaś sloty pamięci alkoholem? Przeczyściłaś je?

  • 2 tygodnie później...
ranshou
komentarz
komentarz

hmm rozumiem że nie chodzi o zwykły alkohol tylko izopropylowy ? ale jak go nałożyć? poprostu wylać pare kropel czy co :huh: ? gdzie moge go kupić? w jakim stężeniu (wybaczcie , ale w sprawach technicznych jestem początkująca :niepewny: )

Tak poza tym to BSOD'y znowu zaczęły sie pojawiać , na początku nie były zbyt często (np. raz na jakieś 2 tygodnie ) wiec sie tym nie przejmowałam zbytnio bo mogłam normalnie na nim pracować , ale teraz jak nie walnie raz dziennie to cud <_<

znowu wyskakuje mi błąd "IRQL_NOT_LESS_OR_EQUAL"

przepraszam ,jestem strasznie problemowa Y_____Y

Psycholandia
komentarz
komentarz

Wykonaj jeszcze raz: http://www.forumpc.pl/index.php?showtopic=16074
Może być spirytus, albo wódka, wystarczy kilka kropelek na ściereczkę i nią przesmarować.

ranshou
komentarz
komentarz

Proszę bardzo ^^; o to chodziło?

[log]Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\Minidump\Mini100309-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_rtm.040803-2158
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055ab20
Debug session time: Sat Oct 3 09:18:25.037 2009 (GMT+2)
System Uptime: 0 days 0:22:06.621
Loading Kernel Symbols
...............................................................
..........................................................
Loading User Symbols
Loading unloaded module list
...............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000000A, {4, 2, 1, 804dc903}
[/log]

Nie mam niestety spirytusu w domu (ani wódki) wiec zaraz pewnie skocze po niego do sklepu :)

mam nadzieje ,że nie spale domu czy coś~? :D

Psycholandia
komentarz
komentarz

Hm, nie ma tak czegoś w stylu? [b]Probably caused by : xxx[/b] ?
Daj loga z OTL: http://www.forumpc.pl/index.php?showtopic=104338
Komputer na czas smarowania wyłączasz, więc domu nie spalisz ;>

ranshou
komentarz
komentarz

Log z OTL

[log]OTL logfile created on: 2009-10-03 14:02:10 - Run 1
OTL by OldTimer - Version 3.0.18.0 Folder = C:\Documents and Settings\Ranran\Pulpit\OTL
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

255,48 Mb Total Physical Memory | 73,61 Mb Available Physical Memory | 28,81% Memory free
1001,75 Mb Paging File | 673,25 Mb Available in Paging File | 67,21% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 6,84 Gb Total Space | 2,56 Gb Free Space | 37,45% Space Free | Partition Type: NTFS
Drive D: | 31,32 Gb Total Space | 15,11 Gb Free Space | 48,24% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RANSHOU
Current User Name: Ranran
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2004-08-04 00:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2009-05-13 16:48:22 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2009-08-04 23:11:14 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009-03-02 13:08:47 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2007-04-05 14:57:52 | 03,251,800 | ---- | M] () -- D:\Ashampoo FireWall\FireWall.exe
PRC - [2009-01-17 16:48:08 | 05,853,672 | ---- | M] (o2.pl Sp. z o.o.) -- D:\Tlen.pl\tlen.exe
PRC - [2008-05-20 13:39:50 | 01,008,864 | ---- | M] (Pointstone Software, LLC) -- C:\Program Files\Pointstone\Internet Accelerator\InternetAccelerator.exe
PRC - [2009-07-21 14:34:33 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [1999-12-13 09:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\CTsvcCDA.exe
PRC - [2007-04-02 14:15:40 | 00,061,440 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTDevSrv.exe
PRC - [2009-08-04 23:11:14 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2002-07-16 12:16:00 | 00,061,440 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe
PRC - [2007-04-30 19:43:54 | 03,450,608 | ---- | M] (Stardock) -- D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
PRC - [2008-05-02 00:40:44 | 03,032,360 | ---- | M] (Wacom Technology, Corp.) -- C:\WINDOWS\System32\Pen_Tablet.exe
PRC - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe
PRC - [2008-05-02 00:40:44 | 03,032,360 | ---- | M] (Wacom Technology, Corp.) -- C:\WINDOWS\System32\Pen_Tablet.exe
PRC - [2004-08-04 00:44:30 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe
PRC - [2009-08-28 13:13:02 | 00,832,808 | ---- | M] (Opera Software) -- D:\OPERA ^^\opera.exe
PRC - [2009-10-03 14:00:25 | 00,519,168 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Ranran\Pulpit\OTL\OTL.exe

[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2009-05-13 16:48:22 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService [Auto | Running])
SRV - [2009-07-21 14:34:33 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService [Auto | Running])
SRV - [2005-09-23 07:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2005-09-23 07:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [1999-12-13 09:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\CTsvcCDA.exe -- (Creative Service for CDROM Access [Auto | Running])
SRV - [2007-04-02 14:15:40 | 00,061,440 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTDevSrv.exe -- (CTDevice_Srv [Auto | Running])
SRV - [2004-08-04 00:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2009-08-04 23:11:14 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2002-07-16 12:16:00 | 00,061,440 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2003-07-28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2004-08-04 00:44:18 | 00,395,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\cmd.exe -- (PEVSystemStart [Auto | Stopped])
SRV - [2007-05-28 18:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) -- D:\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE [Auto | Stopped])
SRV - [2008-05-02 00:40:44 | 03,032,360 | ---- | M] (Wacom Technology, Corp.) -- C:\WINDOWS\System32\Pen_Tablet.exe -- (TabletServicePen [Auto | Running])
SRV - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2009-10-03 09:20:14 | 00,004,096 | ---- | M] () -- C:\Documents and Settings\Ranran\Ustawienia lokalne\temp\ASFWHide -- (ASFWHide [On_Demand | Running])
DRV - [2009-02-13 12:35:05 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio [System | Running])
DRV - [2009-07-28 16:33:56 | 00,055,656 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\avgntflt.sys -- (avgntflt [Auto | Running])
DRV - [2009-03-30 10:33:07 | 00,096,104 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\avipbb.sys -- (avipbb [System | Running])
DRV - [2004-08-04 00:32:26 | 00,048,640 | ---- | M] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\DRIVERS\cwrwdm.sys -- (cwrwdm [On_Demand | Running])
DRV - [2004-08-04 01:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running])
DRV - [2001-08-18 00:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\msmpu401.sys -- (ms_mpu401 [On_Demand | Running])
DRV - [2002-07-16 12:16:00 | 00,981,466 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2001-08-17 23:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008-08-20 19:58:58 | 00,044,944 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2004-08-04 00:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Running])
DRV - [2004-07-17 11:36:38 | 00,027,440 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2009-08-07 17:31:46 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2009-05-11 10:12:24 | 00,028,520 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running])
DRV - [2005-08-30 17:57:18 | 00,058,320 | ---- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\ss_bus.sys -- (ss_bus [On_Demand | Stopped])
DRV - [2005-08-30 17:58:56 | 00,008,304 | ---- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\ss_mdfl.sys -- (ss_mdfl [On_Demand | Stopped])
DRV - [2005-08-30 17:59:00 | 00,094,000 | ---- | M] (MCCI) -- C:\WINDOWS\System32\DRIVERS\ss_mdm.sys -- (ss_mdm [On_Demand | Stopped])
DRV - [2006-07-24 16:05:00 | 00,005,632 | ---- | M] () -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen [System | Running])
DRV - [2008-03-17 22:14:52 | 00,015,144 | ---- | M] (Wacom Technology) -- C:\WINDOWS\System32\DRIVERS\wacmoumonitor.sys -- (wacmoumonitor [On_Demand | Stopped])
DRV - [2007-02-16 21:12:36 | 00,011,312 | ---- | M] (Wacom Technology) -- C:\WINDOWS\System32\DRIVERS\wacommousefilter.sys -- (wacommousefilter [On_Demand | Running])
DRV - [2008-01-15 22:11:46 | 00,013,480 | ---- | M] (Wacom Technology) -- C:\WINDOWS\System32\DRIVERS\wacomvhid.sys -- (wacomvhid [On_Demand | Running])
DRV - [2007-02-16 02:11:28 | 00,011,440 | ---- | M] (Wacom Technology) -- C:\WINDOWS\System32\DRIVERS\WacomVKHid.sys -- (WacomVKHid [On_Demand | Running])

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003\S-1-5-21-1757981266-1957994488-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003\S-1-5-21-1757981266-1957994488-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.0.0.50:80

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009-08-04 23:11:16 | 00,000,000 | ---D | M]

[2009-07-06 15:35:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\mozilla\Extensions
[2009-07-06 15:35:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-08-08 21:29:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\mozilla\Firefox\Profiles\f3xot81f.default\extensions

O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Free Download Manager\iefdm2.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\adobe 9\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ashampoo FireWall] D:\Ashampoo FireWall\FireWall.exe ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003..\Run: [AlcoholAutomount] D:\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003..\Run: [Google Update] C:\Documents and Settings\Ranran\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003..\Run: [Internet Accelerator] C:\Program Files\Pointstone\Internet Accelerator\InternetAccelerator.exe (Pointstone Software, LLC)
O4 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003..\Run: [Komunikator] D:\Tlen.pl\tlen.exe (o2.pl Sp. z o.o.)
O4 - Startup: C:\Documents and Settings\Ranran\Menu Start\Programy\Autostart\Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - D:\Microsoft Office 2003\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Pobierz plik wideo we Free Download Manager - D:\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Pobierz w Free Download Manager - D:\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Pobierz wszystkie pliki w Free Download Manager - D:\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Pobierz zaznaczone w Free Download Manager - D:\Free Download Manager\dlselected.htm ()
O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Microsoft Office 2003\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - D:\Ashampoo FireWall\spi.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - D:\Ashampoo FireWall\spi.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - D:\Ashampoo FireWall\spi.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\Ashampoo FireWall\spi.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\Ashampoo FireWall\spi.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - D:\Ashampoo FireWall\spi.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.76.32.1 212.76.33.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-6722801334-9896425077-753053655-5028\sysdate.exe) - C:\RECYCLER\S-1-5-21-6722801334-9896425077-753053655-5028\sysdate.exe File not found
O20 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003 Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003 Winlogon: Shell - (C:\RECYCLER\S-1-5-21-6722801334-9896425077-753053655-5028\sysdate.exe) - C:\RECYCLER\S-1-5-21-6722801334-9896425077-753053655-5028\sysdate.exe File not found
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-24 12:11:07 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009-09-23 16:23:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ranran\Ustawienia lokalne\Dane aplikacji\Ashampoo
[2009-10-03 13:15:36 | 00,000,000 | ---D | C] -- C:\Program Files\Debugging Tools for Windows (x86)
[2009-10-03 14:01:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ranran\Pulpit\OTL
[2009-10-03 13:20:34 | 00,000,000 | ---D | C] -- C:\symbols
[2009-09-27 21:09:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ranran\Pulpit\Chobits Fan Book
[2009-09-26 15:32:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Ranran\Pulpit\yyyyyyyyy
[2009-09-24 18:46:42 | 00,000,000 | ---D | C] -- C:\WTablet
[2009-09-23 17:16:38 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2009-09-22 20:23:49 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009-09-19 17:43:46 | 00,000,000 | ---D | C] -- C:\Ram Cleaner
[2009-09-12 13:32:37 | 00,000,000 | ---D | C] -- C:\WINDOWS\osu!

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009-10-03 13:48:30 | 00,001,136 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1957994488-1708537768-1003UA.job
[2009-10-03 13:48:05 | 00,001,084 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1957994488-1708537768-1003Core.job
[2009-10-03 12:22:24 | 00,006,132 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\ehhhu userbar.png
[2009-10-03 12:19:42 | 00,016,773 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\ehhhu userbar -.- .xcf
[2009-10-03 11:38:02 | 00,002,488 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\hei-nyan.png
[2009-10-03 11:33:38 | 00,084,305 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\hei.png
[2009-10-03 11:08:36 | 00,032,093 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\41BUvOj7J1L.jpg
[2009-10-03 10:56:51 | 00,200,396 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\userbartut7ql.gif
[2009-10-03 09:19:59 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-10-03 09:19:54 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-10-03 09:19:50 | 26,796,4416 | -HS- | M] () -- C:\hiberfil.sys
[2009-10-03 09:16:13 | 00,231,100 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\g_szcz_3.png
[2009-10-02 22:50:44 | 00,090,112 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\obrona.doc
[2009-10-02 18:21:40 | 07,653,796 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\Hungry_Heart_Wild_Striker_-_Watashi_no_Taiyou.mp3
[2009-10-02 18:21:31 | 05,863,552 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\Phantom_Requiem_for_the_Phantom_-_Transparent.mp3
[2009-10-02 18:20:51 | 05,218,432 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\Itazura_na_Kiss_-_Jikan_yo_Tomare.mp3
[2009-10-02 18:20:02 | 06,066,304 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\Love_Get_Chu_-_Cry_A_Little.mp3
[2009-10-02 18:20:00 | 05,742,720 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\xxxHOLiC_Kei_-_Honey_Honey.mp3
[2009-10-02 18:19:39 | 04,714,624 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\Naruto_Shippuuden_-_My_Answer.mp3
[2009-10-02 18:18:47 | 05,650,560 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\Bakemonogatari_-_Staple_Stable.mp3
[2009-10-02 18:18:23 | 07,028,864 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\Bakemonogatari_-_Kimi_no_Shiranai_Monogatari.mp3
[2009-10-02 16:26:18 | 01,206,808 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\From_sunrise_to_sunset___PL_by_Aomori.jpg
[2009-10-01 19:46:09 | 05,039,365 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\kokia - tomoni.mp3
[2009-09-30 22:24:09 | 06,916,136 | -H-- | M] () -- C:\Documents and Settings\Ranran\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-09-30 20:24:47 | 03,646,306 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\thousand foot krutch - wish you well.mp3
[2009-09-30 20:01:58 | 03,439,836 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\thousand foot krutch- falls apart.mp3
[2009-09-30 20:01:06 | 03,758,738 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\thousand foot krutch - broken wing.mp3
[2009-09-29 20:34:01 | 03,977,749 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\kokia - arigatou.mp3
[2009-09-29 20:28:20 | 03,699,774 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\kokia - daiji na mono wa mabuta no ura.mp3
[2009-09-29 20:18:23 | 04,620,987 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\kokia - dandelion.mp3
[2009-09-29 17:26:43 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-09-28 17:18:52 | 02,883,584 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\Yoko .sai
[2009-09-28 15:52:25 | 00,033,280 | ---- | M] () -- C:\Documents and Settings\Ranran\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-09-27 18:37:15 | 02,445,312 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\Yoko - lineart.sai
[2009-09-26 20:59:36 | 02,174,976 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\New Canvas.sai
[2009-09-17 19:10:02 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2009-09-17 19:07:16 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\LauncherAccess.dt
[2009-09-05 19:35:56 | 06,327,158 | ---- | M] () -- C:\Documents and Settings\Ranran\Pulpit\collab3a.psd

[color=#E56717]========== Files - No Company Name ==========[/color]
[2009-10-03 12:22:23 | 00,006,132 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\ehhhu userbar.png
[2009-10-03 12:19:42 | 00,016,773 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\ehhhu userbar -.- .xcf
[2009-10-03 11:38:02 | 00,002,488 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\hei-nyan.png
[2009-10-03 11:33:36 | 00,084,305 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\hei.png
[2009-10-03 11:08:36 | 00,032,093 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\41BUvOj7J1L.jpg
[2009-10-03 10:56:50 | 00,200,396 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\userbartut7ql.gif
[2009-10-03 09:16:13 | 00,231,100 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\g_szcz_3.png
[2009-10-02 20:50:32 | 00,090,112 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\obrona.doc
[2009-10-02 18:20:05 | 05,863,552 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\Phantom_Requiem_for_the_Phantom_-_Transparent.mp3
[2009-10-02 18:19:58 | 07,653,796 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\Hungry_Heart_Wild_Striker_-_Watashi_no_Taiyou.mp3
[2009-10-02 18:19:30 | 05,218,432 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\Itazura_na_Kiss_-_Jikan_yo_Tomare.mp3
[2009-10-02 18:18:28 | 05,742,720 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\xxxHOLiC_Kei_-_Honey_Honey.mp3
[2009-10-02 18:18:16 | 06,066,304 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\Love_Get_Chu_-_Cry_A_Little.mp3
[2009-10-02 18:18:05 | 04,714,624 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\Naruto_Shippuuden_-_My_Answer.mp3
[2009-10-02 18:17:27 | 05,650,560 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\Bakemonogatari_-_Staple_Stable.mp3
[2009-10-02 18:17:19 | 07,028,864 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\Bakemonogatari_-_Kimi_no_Shiranai_Monogatari.mp3
[2009-10-02 16:26:17 | 01,206,808 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\From_sunrise_to_sunset___PL_by_Aomori.jpg
[2009-10-01 19:42:38 | 05,039,365 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\kokia - tomoni.mp3
[2009-09-30 20:21:44 | 03,646,306 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\thousand foot krutch - wish you well.mp3
[2009-09-30 19:59:05 | 03,439,836 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\thousand foot krutch- falls apart.mp3
[2009-09-30 19:46:58 | 03,758,738 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\thousand foot krutch - broken wing.mp3
[2009-09-29 20:30:41 | 03,977,749 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\kokia - arigatou.mp3
[2009-09-29 20:25:14 | 03,699,774 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\kokia - daiji na mono wa mabuta no ura.mp3
[2009-09-29 20:14:31 | 04,620,987 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\kokia - dandelion.mp3
[2009-09-27 18:37:57 | 02,883,584 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\Yoko .sai
[2009-09-26 20:48:55 | 02,445,312 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\Yoko - lineart.sai
[2009-09-26 14:07:48 | 02,174,976 | ---- | C] () -- C:\Documents and Settings\Ranran\Pulpit\New Canvas.sai
[2009-09-22 22:13:19 | 06,916,136 | -H-- | C] () -- C:\Documents and Settings\Ranran\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-08-07 17:31:43 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009-07-10 14:17:38 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\LauncherAccess.dt
[2009-07-10 14:13:41 | 00,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2009-07-03 12:14:39 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009-06-29 21:10:56 | 00,033,280 | ---- | C] () -- C:\Documents and Settings\Ranran\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-06-24 13:49:26 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
[2009-06-24 13:04:15 | 00,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009-06-24 12:26:47 | 00,032,840 | ---- | C] () -- C:\Documents and Settings\Ranran\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2009-06-24 12:22:07 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Ranran\Dane aplikacji\desktop.ini
[2004-08-04 00:44:00 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004-07-17 11:36:38 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2001-10-26 17:45:34 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\NSREG.DLL
[2001-07-22 00:16:20 | 00,000,477 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 00:15:52 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

[color=#E56717]========== LOP Check ==========[/color]

[2009-08-25 18:31:23 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji
[2009-08-08 21:29:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\FreeDownloadManager.ORG
[2009-07-03 15:14:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SYSTEMAX Software Development
[2009-06-24 19:53:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Tlen.pl
[2009-06-24 13:49:25 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Dane aplikacji
[2009-06-24 12:17:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji
[2009-06-24 12:17:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji
[2009-09-30 16:45:09 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji
[2009-08-27 21:23:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\ChomikBox
[2009-07-13 22:35:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\ConvertTemp
[2009-10-03 14:01:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\foobar2000
[2009-10-03 13:13:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\Free Download Manager
[2009-10-03 12:22:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\gtk-2.0
[2009-09-21 18:02:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\iLibrary Reader
[2009-08-25 17:35:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\Opera
[2009-08-22 21:49:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\Publish Providers
[2009-07-10 14:18:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\Samsung
[2009-08-22 21:48:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\Sony
[2009-08-22 21:27:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\Sony Setup
[2009-07-03 15:14:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\SYSTEMAX Software Development
[2009-08-06 18:54:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\Temporary
[2009-10-03 09:50:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\Tlen.pl
[2009-09-17 19:08:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\TransRender
[2009-10-03 09:21:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\WTablet
[2009-10-03 13:14:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Ranran\Dane aplikacji\X-Chat 2
[2001-07-22 00:17:50 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009-10-03 13:48:05 | 00,001,084 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1957994488-1708537768-1003Core.job
[2009-10-03 13:48:30 | 00,001,136 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1957994488-1708537768-1003UA.job
[2009-10-03 09:19:59 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT

[color=#E56717]========== Purity Check ==========[/color]


< End of report >
[/log]

khu khu~ okazało się że moja rodzicielka wybyła z domu i nie moge jej nigdzie złapać wiec zabawa alkoholem narazie odpada gdyż niepełnoletnia jestem jeszcze :D

[quote name='Andziorka' date='03 październik 2009 - 13:32 ' timestamp='1254569564' post='873140']
Hm, nie ma tak czegoś w stylu? [b]Probably caused by : xxx[/b] ? [/quote]

a-ale gdzie to powinno być? :niepewny:
Skopiowałam wszystko to co mi sie wyświetliło...

Psycholandia
komentarz
komentarz

[quote]Skopiowałam wszystko to co mi sie wyświetliło... [/quote]
Skoro wszystko to znaczy, że nie ma ^^

W okienko OTL wklej poniższy skrypt i klik na Run Fix:

[code]:Processes
explorer.exe

:OTL
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O20 - HKU\S-1-5-21-1757981266-1957994488-1708537768-1003 Winlogon: Shell - (C:\RECYCLER\S-1-5-21-6722801334-9896425077-753053655-5028\sysdate.exe) - C:\RECYCLER\S-1-5-21-6722801334-9896425077-753053655-5028\sysdate.exe File not found
O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-6722801334-9896425077-753053655-5028\sysdate.exe) - C:\RECYCLER\S-1-5-21-6722801334-9896425077-753053655-5028\sysdate.exe File not found

:Files
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1957994488-1708537768-1003UA. job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1957994488-1708537768-1003Core. job

:Commands
[emptytemp]
[start explorer]
[Reboot][/code]
Uruchom ponownie OTL i klik na CleanUP

Przeskanuj komputer tym: [url="http://www.programosy.pl/program,malwarebytes-anti-malware.html"]Malware[/url] usuń wszystko co znajdzie i daj loga po kasowaniu (loga z Malware)

P/S
[quote]Chobits Fan Book[/quote] ooo, Chobits widzę, lubię. :D

ranshou
komentarz
komentarz

okku~ zrobiłam wszystko co miałam ,znalazło 4 trojany :blink:
[log]Malwarebytes' Anti-Malware 1.41
Wersja bazy definicji: 2899
Windows 5.1.2600 Dodatek Service Pack 2

2009-10-03 14:49:10
mbam-log-2009-10-03 (14-49-10).txt

Typ skanowania: Szybkie skanowanie
Przeskanowane obiekty: 87768
Upłynęło: 5 minute(s), 35 second(s)

Zainfekowane procesy w pamięci: 0
Zainfekowane moduły pamięci: 0
Zainfekowane klucze rejestru: 1
Zainfekowane wartości rejestru: 1
Zainfekowane pliki rejestru: 2
Zainfekowane foldery: 0
Zainfekowane pliki: 0

Zainfekowane procesy w pamięci:
(Nie wykryto groźnych plików)

Zainfekowane moduły pamięci:
(Nie wykryto groźnych plików)

Zainfekowane klucze rejestru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\notepad.exe (Security.Hijack) -> Quarantined and deleted successfully.

Zainfekowane wartości rejestru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.

Zainfekowane pliki rejestru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Zainfekowane foldery:
(Nie wykryto groźnych plików)

Zainfekowane pliki:
(Nie wykryto groźnych plików)
[/log]

toto w firewallu to też były trojany? O_____o'

PS.ahu~ Chobits ma jedną z najładniejszych kresek jakie widziałam :D

Psycholandia
komentarz
komentarz

[quote]toto w firewallu to też były trojany? O_____o'[/quote]
Nie, nie. Miałaś wyłączonego Firewalla i dlatego pokazał.
Już jest czysto, uruchom OTL i klik na CleanUP.
Zobaczymy czy teraz Bsody nadal będą wyskakiwać.

ranshou
komentarz
komentarz

okku~ zrobione
jak sie BSOD pojawi to dam znać ^^;

musiałam jeszcze raz sciągnąć OTL bo wsiąkł <_<

czy mogę usunąć ukryty plik z pulpitu o nazwie "thumbs.db" czy coś sie stanie ? ^^;

MarekM25
komentarz
komentarz

otl ginie po opcji CleanUp ;)

w zasadzie możesz usunąć i możesz zostawić ;) poczytaj na necie o jego zastosowaniach to będziesz wiedział czy jest Ci potrzebny

Psycholandia
komentarz
komentarz

Wejdź w jakiś dysk, narzędzia, opcje folderów, widok, zaznacz: nie pokazuj ukrytych plików i folderów
wtedy nie będziesz widziała tych pliczków, które automatycznie się odkrywają po skanie OTL.

ranshou
komentarz
komentarz

Znowu sie pojawił BSOD T_______T ... i znowu z komunikatem "IRQL_NOT_LESS_OR_EQUAL"


A dostępu do spirytusu narazie nimam ... nadal ...

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.