Dandoo utworzono 25 sierpnia 2009 utworzono 25 sierpnia 2009 Witam Dzisiaj w nocy KASPERSKY ONLINE SCANNER 7.0 wykrył u mnie 3 wirusy... C:\Program Files\6-11-pre-r300_xp-2k_dd_ccc_wdm_38185\Driver\2KXP_INF\B_32846\ati3duag.dl_ Zagrożenie: Packed.Win32.Katusha.e C:\WINDOWS\system32\ati3duag.dll Zagrożenie: Packed.Win32.Katusha.e F:\Instalki\Dekodery\DivX\DivXPro502GAINBundle.exe Zagrożenie: not-a-virus:AdWare.Win32.Gator.3202 - to usunąłem ręcznie- cały folder, ponieważ była to tylko zwykła instalka ... Log do sprawdzenia OTL logfile created on: 2009-08-25 14:03:40 - Run 1OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Jędrzej\Pulpit Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 511,30 Mb Total Physical Memory | 292,78 Mb Available Physical Memory | 57,26% Memory free 1,32 Gb Paging File | 0,83 Gb Available in Paging File | 63,16% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 5,18 Gb Total Space | 0,39 Gb Free Space | 7,62% Space Free | Partition Type: NTFS Drive D: | 15,43 Gb Total Space | 1,18 Gb Free Space | 7,65% Space Free | Partition Type: NTFS Drive E: | 20,61 Gb Total Space | 5,22 Gb Free Space | 25,34% Space Free | Partition Type: NTFS Drive F: | 33,31 Gb Total Space | 3,31 Gb Free Space | 9,93% Space Free | Partition Type: NTFS Drive G: | 960,57 Mb Total Space | 26,02 Mb Free Space | 2,71% Space Free | Partition Type: FAT32 H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: JEDRZEJ Current User Name: Jędrzej Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2006-05-03 18:43:46 | 00,413,696 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe PRC - [2009-08-17 17:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Avast4\aswUpdSv.exe PRC - [2009-08-17 18:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Avast4\ashServ.exe PRC - [2006-05-03 18:43:46 | 00,413,696 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe PRC - [2004-08-04 01:44:20 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE PRC - [2005-06-14 12:36:40 | 00,077,824 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE PRC - [2009-08-17 18:07:23 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Avast4\ashDisp.exe PRC - [2003-09-04 11:45:08 | 00,135,214 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE PRC - [2004-08-04 01:44:26 | 01,667,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe PRC - [2008-12-13 19:26:28 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe PRC - [2005-01-28 14:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe PRC - [2009-08-24 10:06:51 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009-08-17 18:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Avast4\ashMaiSv.exe PRC - [2009-08-17 18:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Avast4\ashWebSv.exe PRC - [2009-08-25 14:02:05 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jędrzej\Pulpit\OTL.exe ========== Win32 Services (SafeList) ========== SRV - [2005-09-23 08:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) SRV - [2009-08-17 17:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running]) SRV - [2006-05-03 18:43:46 | 00,413,696 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running]) SRV - [2006-05-03 12:57:00 | 00,520,192 | ---- | M] () -- C:\WINDOWS\System32\ati2sgag.exe -- (ATI Smart [Auto | Stopped]) SRV - [2009-08-17 18:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running]) SRV - [2009-08-17 18:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running]) SRV - [2009-08-17 18:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running]) SRV - [2005-09-23 08:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) SRV - [2004-08-04 01:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running]) SRV - [2005-04-04 01:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped]) SRV - [2008-12-13 19:26:28 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running]) SRV - [2005-01-28 14:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running]) ========== Driver Services (SafeList) ========== DRV - [2009-08-17 18:03:21 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [system | Running]) DRV - [2001-10-26 01:40:02 | 00,031,776 | ---- | M] (Alfa Corporation) -- C:\WINDOWS\System32\Drivers\AFPAnsi.sys -- (AFPAnsi [boot | Running]) DRV - [2005-06-16 18:24:24 | 02,324,160 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running]) DRV - [2009-08-17 18:05:37 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running]) DRV - [2009-08-17 18:06:43 | 00,094,160 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running]) DRV - [2009-08-17 18:04:29 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running]) DRV - [2009-08-17 18:05:52 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [system | Running]) DRV - [2009-08-17 18:04:40 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [system | Running]) DRV - [2006-05-03 18:50:42 | 01,540,608 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running]) DRV - [2004-08-04 00:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running]) DRV - [2009-02-09 02:16:09 | 00,010,345 | ---- | M] (Applied Networking Inc.) -- C:\WINDOWS\System32\DRIVERS\hamachi.sys -- (hamachi [On_Demand | Stopped]) DRV - [2001-08-17 23:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\msmpu401.sys -- (ms_mpu401 [On_Demand | Running]) DRV - [2004-06-03 04:40:46 | 00,079,360 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nvatabus.sys -- (nvatabus [boot | Running]) DRV - [2004-07-28 09:15:36 | 00,033,024 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\NVENETFD.sys -- (NVENETFD [On_Demand | Running]) DRV - [2004-07-28 09:15:38 | 00,012,928 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nvnetbus.sys -- (nvnetbus [On_Demand | Running]) DRV - [2003-10-29 07:02:00 | 00,021,120 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys -- (nv_agp [boot | Running]) DRV - [2008-06-19 17:24:30 | 00,028,544 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot [boot | Running]) DRV - [2003-09-04 11:38:56 | 00,152,576 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\System32\DRIVERS\LV532AV.SYS -- (PID_0920 [On_Demand | Running]) DRV - [2001-08-17 23:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running]) DRV - [2007-03-08 01:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [boot | Running]) DRV - [2002-03-25 20:02:14 | 00,027,440 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped]) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2025429265-1957994488-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKU\S-1-5-21-2025429265-1957994488-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch IE - HKU\S-1-5-21-2025429265-1957994488-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome IE - HKU\S-1-5-21-2025429265-1957994488-839522115-1003\S-1-5-21-2025429265-1957994488-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Winamp Search" FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=" FF - prefs.js..browser.search.selectedEngine: "Wikipedia (pl)" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {a3b24d40-bac4-11dc-95ff-0800200c9a66}:0.2.2 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13 FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=" FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008-12-13 19:26:32 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-08-24 10:07:09 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-08-24 10:07:09 | 00,000,000 | ---D | M] [2008-12-14 22:33:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\mozilla\Extensions [2008-12-14 22:33:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009-08-25 10:22:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\mozilla\Firefox\Profiles\633amiy7.default\extensions [2009-07-03 02:20:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\mozilla\Firefox\Profiles\633amiy7.default\extensions\{a3b24d40-bac4-11dc-95ff-0800200c9a66} [2009-02-18 19:45:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\mozilla\Firefox\Profiles\633amiy7.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2008-12-13 18:59:08 | 00,001,196 | ---- | M] () -- C:\Documents and Settings\Jędrzej\Dane aplikacji\Mozilla\FireFox\Profiles\633amiy7.default\searchplugins\winamp-search.xml [2009-08-25 10:22:23 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009-08-24 10:07:09 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2008-12-13 19:27:11 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2009-08-24 10:06:44 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009-08-24 10:06:45 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2008-12-13 19:26:30 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll [2009-08-24 10:06:53 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2005-09-24 06:44:16 | 00,077,824 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2007-10-25 04:00:00 | 00,144,720 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2008-12-13 19:18:43 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2008-12-13 19:18:43 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2008-12-13 19:18:43 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2008-12-13 19:18:43 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2008-12-13 19:18:43 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2008-12-13 19:18:43 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2008-12-13 19:18:43 | 00,126,976 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2007-10-25 04:00:00 | 00,081,920 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll [2009-08-24 10:06:56 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2009-08-24 10:06:56 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2009-08-24 10:06:56 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009-08-24 10:06:56 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2009-08-24 10:06:56 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2009-08-24 10:06:56 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2009-08-24 10:06:56 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - E:\Niektore programy ktore nie zmiescily sie na dysku C\BitComet\tools\BitCometBHO_1.2.1.2.dll (BitComet) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\Jędrzej\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.) O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKU\S-1-5-21-2025429265-1957994488-839522115-1003\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [avast!] C:\Program Files\Avast4\ashDisp.exe (ALWIL Software) O4 - HKLM..\Run: [Hidder] C:\Program Files\SekretNIK\Hidder.exe (G DATA Software Sp. z o.o.) O4 - HKLM..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE (Logitech Inc.) O4 - HKLM..\Run: [RealTray] C:\Program Files\K-Lite Codec Pack\Real\mpclauncher.exe () O4 - HKLM..\Run: [soundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.) O4 - HKU\S-1-5-21-2025429265-1957994488-839522115-1003..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-2025429265-1957994488-839522115-1003..\Run: [Nowe Gadu-Gadu] C:\Program Files\Nowe Gadu-Gadu\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-21-2025429265-1957994488-839522115-1003..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2025429265-1957994488-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &D&ownload &with BitComet - E:\Niektore programy ktore nie zmiescily sie na dysku C\BitComet\BitComet.exe (www.BitComet.com) O8 - Extra context menu item: &D&ownload all video with BitComet - E:\Niektore programy ktore nie zmiescily sie na dysku C\BitComet\BitComet.exe (www.BitComet.com) O8 - Extra context menu item: &D&ownload all with BitComet - E:\Niektore programy ktore nie zmiescily sie na dysku C\BitComet\BitComet.exe (www.BitComet.com) O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.05\AMVConverter\grab.html () O8 - Extra context menu item: E&ksport do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.05\MediaManager\grab.html () O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - E:\Niektore programy ktore nie zmiescily sie na dysku C\BitComet\tools\BitCometBHO_1.2.1.2.dll (BitComet) O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 88.156.63.9 82.139.8.7 88.156.96.61 O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-12-13 16:07:50 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2008-01-14 13:33:33 | 00,000,000 | ---D | M] - D:\Automap -- [ NTFS ] O33 - MountPoints2\{16da49ff-ce0f-11dd-a36f-0015f23f617f}\Shell\AutoRun\command - "" = I:\2ifetri.cmd -- File not found O33 - MountPoints2\{16da49ff-ce0f-11dd-a36f-0015f23f617f}\Shell\explore\Command - "" = I:\2ifetri.cmd -- File not found O33 - MountPoints2\{16da49ff-ce0f-11dd-a36f-0015f23f617f}\Shell\open\Command - "" = I:\2ifetri.cmd -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found ========== Files/Folders - Created Within 30 Days ========== [2009-08-25 14:02:02 | 00,514,048 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jędrzej\Pulpit\OTL.exe [2009-08-25 13:45:56 | 00,003,520 | ---- | C] () -- C:\Documents and Settings\Jędrzej\Pulpit\Raport.html [2009-08-25 03:23:03 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy [2009-08-25 03:23:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy [2009-08-25 03:21:12 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Jędrzej\Pulpit\spybotsd162.exe [2009-08-24 17:36:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jędrzej\Pulpit\Majka____quot_buju_buju_glupi_chuju__quot____ [2009-08-24 17:35:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jędrzej\Pulpit\PD__wlosy [2009-08-24 17:31:42 | 01,379,080 | ---- | C] () -- C:\Documents and Settings\Jędrzej\Pulpit\Majka____quot_buju_buju_glupi_chuju__quot____.zip [2009-08-24 17:31:24 | 00,534,664 | ---- | C] () -- C:\Documents and Settings\Jędrzej\Pulpit\PD__wlosy.zip [2009-08-23 03:15:28 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\pavboot.sys [2009-08-23 03:14:55 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security [2009-06-25 22:31:43 | 00,002,516 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys [2009-06-25 22:31:43 | 00,000,008 | RHS- | C] () -- C:\WINDOWS\System32\93D52D34D9.sys [2009-06-24 18:24:53 | 00,000,008 | ---- | C] () -- C:\WINDOWS\System32\lssexp3.dll [2009-06-07 14:27:58 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI [2009-04-01 23:30:51 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009-01-18 20:47:54 | 00,015,387 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini [2009-01-18 20:47:14 | 00,000,544 | ---- | C] () -- C:\WINDOWS\_delis32.ini [2009-01-07 04:48:36 | 00,000,226 | ---- | C] () -- C:\WINDOWS\AWS.ini [2009-01-03 14:11:41 | 00,000,427 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2009-01-03 13:32:57 | 00,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini [2009-01-03 13:31:09 | 00,000,026 | ---- | C] () -- C:\WINDOWS\CDE DX4000.ini [2008-12-20 00:24:54 | 00,593,938 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll [2008-12-17 17:53:12 | 00,000,190 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini [2008-12-13 18:38:05 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll [2008-12-13 17:51:50 | 00,000,538 | ---- | C] () -- C:\WINDOWS\wincmd.ini [2008-12-13 17:44:25 | 00,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2008-12-13 17:44:22 | 00,856,064 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2008-12-13 17:44:22 | 00,217,088 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2008-12-13 17:44:21 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2008-12-13 17:44:20 | 00,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2008-12-13 17:44:20 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2008-12-13 17:01:59 | 00,156,672 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll [2008-12-13 16:43:50 | 00,001,023 | ---- | C] () -- C:\WINDOWS\ATICIM.INI [2008-12-13 16:33:44 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2008-12-13 16:18:35 | 00,004,589 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini [2008-12-13 16:18:33 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2006-03-06 10:41:02 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\AMV_DecDLL.dll [2004-09-16 13:26:40 | 00,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS [2004-09-16 13:26:40 | 00,012,634 | ---- | C] () -- C:\WINDOWS\ADFUUD.SYS [2002-03-25 20:02:14 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys [2002-03-21 13:51:52 | 00,503,808 | R--- | C] () -- C:\WINDOWS\System32\lt_xtrans.dll [2002-03-21 13:51:52 | 00,286,720 | R--- | C] () -- C:\WINDOWS\System32\MrSIDD.dll [2002-03-21 13:51:52 | 00,163,840 | R--- | C] () -- C:\WINDOWS\System32\lt_common.dll [2002-03-21 13:51:52 | 00,126,976 | R--- | C] () -- C:\WINDOWS\System32\lt_trans.dll [2002-03-21 13:51:52 | 00,069,632 | R--- | C] () -- C:\WINDOWS\System32\lt_meta.dll [2002-03-21 13:51:52 | 00,053,248 | R--- | C] () -- C:\WINDOWS\System32\lt_encrypt.dll [2002-03-21 13:51:52 | 00,020,480 | R--- | C] () -- C:\WINDOWS\System32\lt_messagetext.dll [2002-03-20 22:01:06 | 00,006,688 | R--- | C] () -- C:\WINDOWS\System32\Digita.sys [2002-03-20 22:00:20 | 00,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportUSB.dll [2002-03-20 22:00:20 | 00,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportSerial.dll [2002-03-20 22:00:20 | 00,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportIrDA.dll [2002-03-20 22:00:20 | 00,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportIrCOMM.dll [2001-07-22 00:16:20 | 00,000,583 | ---- | C] () -- C:\WINDOWS\win.ini [2001-07-22 00:15:52 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini [1999-08-10 18:02:20 | 00,116,736 | ---- | C] () -- C:\WINDOWS\System32\LFKODAK.DLL [1999-08-10 18:02:16 | 00,343,040 | ---- | C] () -- C:\WINDOWS\System32\lffpx7.dll [1999-01-27 14:39:06 | 00,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll [1997-06-13 08:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll ========== Files - Modified Within 30 Days ========== [1 C:\WINDOWS\System32\*.tmp files] [3 C:\WINDOWS\*.tmp files] [2009-08-25 14:02:05 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jędrzej\Pulpit\OTL.exe [2009-08-25 13:45:56 | 00,003,520 | ---- | M] () -- C:\Documents and Settings\Jędrzej\Pulpit\Raport.html [2009-08-25 03:21:46 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Jędrzej\Pulpit\spybotsd162.exe [2009-08-25 00:48:58 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn [2009-08-24 17:31:52 | 01,379,080 | ---- | M] () -- C:\Documents and Settings\Jędrzej\Pulpit\Majka____quot_buju_buju_glupi_chuju__quot____.zip [2009-08-24 17:31:30 | 00,534,664 | ---- | M] () -- C:\Documents and Settings\Jędrzej\Pulpit\PD__wlosy.zip [2009-08-24 10:06:01 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009-08-24 10:05:57 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009-08-24 10:05:56 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009-08-23 01:14:02 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2009-08-22 20:22:20 | 00,002,636 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2009-08-17 18:10:20 | 01,279,456 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe [2009-08-17 18:06:54 | 00,093,392 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2009-08-17 18:06:43 | 00,094,160 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2009-08-17 18:05:52 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2009-08-17 18:05:37 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2009-08-17 18:04:40 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2009-08-17 18:04:29 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2009-08-17 18:03:21 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2009-08-17 18:02:50 | 00,097,480 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\AVASTSS.scr ========== LOP Check ========== [2009-08-25 03:23:03 | 00,000,000 | R--D | M] -- C:\Documents and Settings\All Users\Dane aplikacji [2009-03-06 17:32:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ACD Systems [2008-12-13 18:58:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OrbNetworks [2009-05-16 21:58:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2009-01-03 13:36:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\UDL [2008-12-13 15:57:35 | 00,000,000 | R--D | M] -- C:\Documents and Settings\Default User\Dane aplikacji [2009-07-04 20:29:57 | 00,000,000 | R--D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji [2009-03-06 17:33:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\ACD Systems [2008-12-13 17:45:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\Ashampoo Photo Commander 4 [2009-07-04 23:40:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\BESTplayer [2009-01-03 14:18:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\EPSON [2009-08-23 01:27:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\Nowe Gadu-Gadu [2009-03-14 17:19:25 | 00,000,000 | R--D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\SecuROM [2009-08-24 10:26:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jędrzej\Dane aplikacji\teamspeak2 [2008-12-13 16:15:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji [2008-12-13 16:15:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji [2009-08-23 01:14:02 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job [2001-07-22 00:17:50 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini [2009-08-24 10:06:01 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 487 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:05EE1EEF < End of report > Proszę o pomoc Pozdrawiam
Gość komentarz 25 sierpnia 2009 komentarz 25 sierpnia 2009 Log jest czysty. Kaspersky wykrył same False Alarm - nie martw się o to. .
Dandoo komentarz 25 sierpnia 2009 Autor komentarz 25 sierpnia 2009 OK, to bardzo dziękuje Od razu lepiej
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.