x-kom hosting

Log do sprawdzenia

kula1576
utworzono
utworzono (edytowane)

Jaki skrypt mam utworzyć do tego loga?

[log]
ComboFix 09-10-07.02 - PC 2009-10-08 14:29.7.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3326.2808 [GMT 2:00]
Uruchomiony z: g:\programy\ComboFix.exe
Użyto następujących komend :: d:\documents and settings\PC\Pulpit\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
.

((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\windows\AhnRpta.exe

.
((((((((((((((((((((((((( Pliki utworzone od 2009-09-08 do 2009-10-08 )))))))))))))))))))))))))))))))
.

2009-10-07 07:30 . 2009-10-07 07:30 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\0148
2009-10-06 11:37 . 2009-10-06 11:37 -------- d-----w- d:\documents and settings\PC\Ustawienia lokalne\Dane aplikacji\Symantec
2009-10-06 11:36 . 2005-05-13 17:50 91856 ----a-w- d:\windows\system32\S32EVNT1.DLL
2009-10-06 11:36 . 2005-05-13 17:50 123488 ----a-w- d:\windows\system32\drivers\SYMEVENT.SYS
2009-10-06 11:36 . 2009-10-06 11:36 -------- d-----w- d:\program files\Symantec
2009-10-06 11:36 . 2009-10-08 12:17 -------- d-----w- d:\program files\Symantec AntiVirus
2009-10-06 11:34 . 2009-10-06 11:34 -------- d-----w- d:\program files\antywirus
2009-10-04 16:05 . 2009-10-04 16:05 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\2K Sports
2009-09-30 19:55 . 2009-09-30 19:55 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Sports Interactive
2009-09-30 19:53 . 2009-09-30 19:53 -------- d--h--w- d:\program files\Zero G Registry
2009-09-30 19:52 . 2009-09-30 19:52 -------- d--h--w- d:\documents and settings\PC\InstallAnywhere

.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 10:51 . 2001-10-26 17:15 49712 ----a-w- d:\windows\system32\perfc015.dat
2009-10-08 10:51 . 2001-10-26 17:15 355830 ----a-w- d:\windows\system32\perfh015.dat
2009-10-06 12:37 . 2009-06-20 09:52 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\uTorrent
2009-10-06 12:11 . 2009-06-09 11:56 -------- d-----w- d:\program files\Common Files\Symantec Shared
2009-10-06 11:36 . 2009-06-09 12:01 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Symantec
2009-09-15 20:22 . 2009-06-09 14:36 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu
2009-09-08 16:55 . 2009-06-09 13:36 -------- d-----w- d:\program files\AGEIA Technologies
2009-09-05 21:05 . 2009-06-14 18:23 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\BESTplayer
2009-09-04 09:07 . 2009-06-09 14:36 -------- d-----w- d:\program files\Nowe Gadu-Gadu
2009-08-28 12:56 . 2009-08-28 12:56 -------- d-----w- d:\program files\Half-Life Model Viewer
2009-08-22 21:49 . 2009-06-09 13:03 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Test Drive Unlimited
2009-07-27 17:27 . 2009-06-09 11:58 107888 ----a-w- d:\windows\system32\CmdLineExt.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-10-06_11.31.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-08-17 22:30 . 2009-10-08 10:51 40128 d:\windows\system32\perfc009.dat
- 2001-08-17 22:30 . 2009-10-06 08:26 40128 d:\windows\system32\perfc009.dat
+ 2005-06-23 17:29 . 2005-06-23 17:29 71416 d:\windows\system32\pds.dll
+ 2005-06-23 17:29 . 2005-06-23 17:29 83704 d:\windows\system32\nts.dll
+ 2005-06-23 17:27 . 2005-06-23 17:27 43712 d:\windows\system32\NavLogon.dll
+ 2005-06-23 17:29 . 2005-06-23 17:29 46848 d:\windows\system32\msgsys.dll
+ 2005-06-23 17:29 . 2005-06-23 17:29 83648 d:\windows\system32\loc32vc0.dll
+ 2005-04-22 10:03 . 2005-04-22 10:03 17976 d:\windows\system32\drivers\symredrv.sys
+ 2005-04-22 10:02 . 2005-04-22 10:02 47192 d:\windows\system32\drivers\symndis.sys
+ 2005-04-22 10:02 . 2005-04-22 10:02 36984 d:\windows\system32\drivers\symids.sys
+ 2005-04-22 10:02 . 2005-04-22 10:02 11512 d:\windows\system32\drivers\symdns.sys
+ 2005-06-23 17:28 . 2005-06-23 17:28 34552 d:\windows\system32\cba.dll
+ 2003-03-18 18:05 . 2003-03-18 18:05 89088 d:\windows\system32\atl71.dll
+ 2009-10-06 11:37 . 2009-10-06 11:37 40960 d:\windows\Installer\{3248E093-5288-4CA9-B3AB-11A675FEA1F9}\NewShortcut1.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe
+ 2009-10-06 11:37 . 2009-10-06 11:37 25214 d:\windows\Installer\{3248E093-5288-4CA9-B3AB-11A675FEA1F9}\ARPPRODUCTICON.exe
+ 2005-04-22 10:03 . 2005-04-22 10:03 132824 d:\windows\system32\SymRedir.dll
+ 2005-04-22 10:03 . 2005-04-22 10:03 517848 d:\windows\system32\SymNeti.dll
- 2001-08-17 22:30 . 2009-10-06 08:26 311740 d:\windows\system32\perfh009.dat
+ 2001-08-17 22:30 . 2009-10-08 10:51 311740 d:\windows\system32\perfh009.dat
+ 2005-04-22 10:03 . 2005-04-22 10:03 267192 d:\windows\system32\drivers\symtdi.sys
+ 2005-04-22 10:02 . 2005-04-22 10:02 173208 d:\windows\system32\drivers\symfw.sys
+ 2003-03-18 20:12 . 2003-03-18 20:12 1047552 d:\windows\system32\mfc71u.dll
+ 2009-10-06 11:37 . 2009-10-06 11:37 5502464 d:\windows\Installer\4b351.msi
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"SunJavaUpdateSched"="d:\program files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 36975]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"ccApp"="d:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752]
"vptray"="d:\progra~1\SYMANT~1\VPTray.exe" [2005-06-23 85696]
"RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.exe [2008-05-14 16862720]
"nwiz"="nwiz.exe" - d:\windows\system32\nwiz.exe [2008-10-07 1630208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BD344AF4-67AB-4E19-A630-7435587D320B}"= "d:\windows\system32\ahndoor0.dll" [2008-04-14 63554]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Talisman.lnk]
path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Talisman.lnk
backup=d:\windows\pss\Talisman.lnkStartup

[HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Yahoo! Widget Engine.lnk]
path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Yahoo! Widget Engine.lnk
backup=d:\windows\pss\Yahoo! Widget Engine.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"g:\\Gry\\Test Drive Unlimited\\TestDriveUnlimited.exe"=
"d:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"g:\\Gry\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"d:\\Program Files\\Ares\\Ares.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"d:\\Program Files\\Ares\\chatServer.exe"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"g:\\Gry\\Stronghold 2\\Stronghold2.exe"=
"g:\\Gry\\PES09\\pes2009.exe"=
"g:\\Gry\\Q U A K E II\\r1q2.exe"=
"g:\\Gry\\Valve\\SteamApps\\kula_1576\\counter-strike\\hl.exe"=
"g:\\Gry\\Fotbal Menager 2008\\fm.exe"=

R0 sojubus;sojubus;d:\windows\system32\drivers\sojubus.sys [2003-10-05 123520]
R0 sojuscsi;sojuscsi;d:\windows\system32\drivers\sojuscsi.sys [2003-09-28 5504]
S2 gupdate1ca0016106c1b22;Usługa Google Update (gupdate1ca0016106c1b22);d:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 133104]
S3 SavRoam;SAVRoam;d:\program files\Symantec AntiVirus\SavRoam.exe [2005-06-23 124608]

--- Inne Usługi/Sterowniki w Pamięci ---

*Deregistered* - EraserUtilDrvI9
.
Zawartość folderu 'Zaplanowane zadania'

2009-10-08 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 21:50]

2009-10-08 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 21:50]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://search.bearshare.com/
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&ksport do programu Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\PC\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.pl
FF - plugin: d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu\_userdata\npgg.1.dll
FF - plugin: d:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-08 14:31
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ...

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ...

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------

[HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)

[HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a6,7d,1d,90,39,09,ad,46,99,fe,17,b8,16,6f,7f,0b,be,77,2e,c8,07,81,27,
3f,75,79,8f,5a,76,d4,12,5a,f4,0a,60,db,5a,2a,57,cc,ca,e9,89,35,11,a2,a6,72,\
"??"=hex:a0,87,12,9e,a4,06,2f,b5,52,62,2b,d2,0b,43,9d,7b

[HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:03,ca,b9,2d,48,91,81,3c,29,08,70,54,2c,bf,3a,61,4a,d0,87,92,99,
ed,7e,57,ba,05,a0,3b,26,14,09,29,be,d4,de,78,8d,b6,40,81,a7,af,1e,0e,ba,3e,\
"rkeysecu"=hex:94,94,3a,05,62,40,36,54,f0,6a,81,57,71,86,8d,50
.
Czas ukończenia: 2009-10-08 14:32
ComboFix-quarantined-files.txt 2009-10-08 12:31
ComboFix2.txt 2009-10-08 12:14
ComboFix3.txt 2009-10-08 11:59
ComboFix4.txt 2009-10-08 09:54
ComboFix5.txt 2009-10-08 12:28

Przed: 17 741 246 464 bajtów wolnych
Po: 17 734 914 048 bajtów wolnych

178
[/log]

Psycholandia
komentarz
komentarz

Daj loga z OTL: http://www.forumpc.pl/index.php?showtopic=104338
Logów z Combofixa nie dajemy od tak sobie, zapoznaj się z regulaminem działu bezpieczeństwo.

kula1576
komentarz
komentarz (edytowane)

Sorki ja nowicjusz oto log z OTL

[log]OTL logfile created on: 2009-10-08 15:00:41 - Run 1
OTL by OldTimer - Version 3.0.18.4 Folder = D:\Documents and Settings\PC\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 100,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 9,90 Gb Total Space | 1,28 Gb Free Space | 12,96% Space Free | Partition Type: FAT32
Drive D: | 29,29 Gb Total Space | 16,53 Gb Free Space | 56,41% Space Free | Partition Type: NTFS
Drive E: | 13,79 Gb Total Space | 3,41 Gb Free Space | 24,72% Space Free | Partition Type: FAT32
Drive F: | 13,55 Gb Total Space | 3,39 Gb Free Space | 25,05% Space Free | Partition Type: FAT32
Drive G: | 97,65 Gb Total Space | 18,08 Gb Free Space | 18,52% Space Free | Partition Type: NTFS
Drive H: | 171,13 Gb Total Space | 22,97 Gb Free Space | 13,42% Space Free | Partition Type: NTFS
Drive I: | 3,58 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive K: | 3,48 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: KUL
Current User Name: PC
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2005-06-02 09:21:46 | 00,161,392 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2005-06-02 09:21:40 | 00,185,968 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2008-05-14 03:50:46 | 16,862,720 | R--- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\RTHDCPL.EXE
PRC - [2005-06-02 09:21:38 | 00,048,752 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2005-06-23 19:27:36 | 00,085,696 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\VPTray.exe
PRC - [2005-06-23 19:27:18 | 00,019,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\DefWatch.exe
PRC - [2008-10-07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\nvsvc32.exe
PRC - [2009-06-11 15:57:29 | 00,075,064 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrA.exe
PRC - [2009-07-09 11:24:20 | 00,189,072 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrB.exe
PRC - [2005-06-23 19:27:28 | 01,715,904 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Rtvscan.exe
PRC - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wdfmgr.exe
PRC - [2008-04-14 22:51:18 | 01,035,264 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
PRC - [2009-09-10 16:13:00 | 00,307,704 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-10-08 15:00:24 | 00,520,704 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe

[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2005-06-02 09:21:40 | 00,185,968 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [Auto | Running])
SRV - [2005-06-02 09:21:46 | 00,083,568 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc [On_Demand | Stopped])
SRV - [2005-06-02 09:21:46 | 00,161,392 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running])
SRV - [2005-06-23 19:27:18 | 00,019,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running])
SRV - [2009-07-08 23:50:07 | 00,133,104 | ---- | M] (Google Inc.) -- D:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1ca0016106c1b22 [Auto | Stopped])
SRV - [2008-04-14 22:50:46 | 00,038,400 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2008-10-07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2003-07-28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2009-06-11 15:57:29 | 00,075,064 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
SRV - [2009-07-09 11:24:20 | 00,189,072 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrB.exe -- (PnkBstrB [Auto | Running])
SRV - [2005-06-23 19:27:30 | 00,124,608 | ---- | M] (symantec) -- D:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam [On_Demand | Stopped])
SRV - [2005-04-22 12:03:28 | 00,206,552 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [On_Demand | Stopped])
SRV - [2005-03-30 21:48:22 | 00,992,864 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc [On_Demand | Stopped])
SRV - [2005-06-23 19:27:28 | 01,715,904 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus [Auto | Running])
SRV - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])
SRV - [2004-08-04 02:44:16 | 00,006,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wuauserv.dll -- (wuauserv [Auto | Running])

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2006-07-01 23:32:26 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- D:\WINDOWS\System32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running])
DRV - File not found -- -- (catchme [On_Demand | Running])
DRV - [2009-09-17 08:53:46 | 00,371,248 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl [System | Running])
DRV - [2009-06-09 13:55:32 | 00,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- D:\WINDOWS\gdrv.sys -- (gdrv [On_Demand | Stopped])
DRV - [2008-04-13 22:06:06 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- D:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2008-05-15 02:03:12 | 04,742,144 | R--- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\System32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2009-09-17 08:53:46 | 00,084,912 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\VirusDefs\20091007.002\NAVENG.SYS -- (NAVENG [On_Demand | Running])
DRV - [2009-09-17 08:53:46 | 01,323,568 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\VirusDefs\20091007.002\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
DRV - [2003-04-02 09:54:16 | 00,020,648 | R--- | M] (Thomson Inc.) -- D:\WINDOWS\System32\DRIVERS\netrcacm.sys -- (netrcacm [On_Demand | Running])
DRV - [2008-10-07 13:33:00 | 06,133,856 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2008-04-14 00:26:08 | 00,088,320 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx [Auto | Running])
DRV - [2001-08-18 00:54:18 | 00,063,232 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnknb.sys -- (NwlnkNb [Auto | Running])
DRV - [2001-08-18 00:54:18 | 00,055,936 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx [Auto | Running])
DRV - [2008-04-14 00:04:14 | 00,163,584 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwrdr.sys -- (NWRDR [On_Demand | Stopped])
DRV - [2009-07-09 11:24:29 | 00,138,920 | ---- | M] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys -- (PnkBstrK [On_Demand | Stopped])
DRV - [2001-08-18 00:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- D:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008-01-04 08:10:16 | 00,105,856 | R--- | M] (Realtek Semiconductor Corporation ) -- D:\WINDOWS\System32\DRIVERS\Rtenicxp.sys -- (RTLE8023xp [On_Demand | Stopped])
DRV - [2005-02-04 20:14:30 | 00,324,232 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT [System | Running])
DRV - [2005-02-04 20:14:32 | 00,053,896 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL [System | Running])
DRV - [2008-04-13 22:09:18 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- D:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2003-10-05 10:41:14 | 00,123,520 | ---- | M] ( ) -- D:\WINDOWS\system32\DRIVERS\sojubus.sys -- (sojubus [Boot | Running])
DRV - [2003-09-28 10:57:52 | 00,005,504 | ---- | M] ( ) -- D:\WINDOWS\system32\DRIVERS\sojuscsi.sys -- (sojuscsi [Boot | Running])
DRV - [2005-03-30 21:48:20 | 00,372,832 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv [On_Demand | Stopped])
DRV - [2005-05-13 19:50:10 | 00,123,488 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
DRV - [2005-04-22 12:03:00 | 00,017,976 | ---- | M] (Symantec Corporation) -- D:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV [On_Demand | Running])
DRV - [2005-04-22 12:03:02 | 00,267,192 | ---- | M] (Symantec Corporation) -- D:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI [System | Running])

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.startup.homepage: "http://google.pl"
FF - prefs.js..extensions.enabledItems: anycolor.pavlos256@gmail.com:0.3.0
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.2
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:3.2.8
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2009-09-10 16:13:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2009-10-04 19:46:11 | 00,000,000 | ---D | M]

[2009-06-09 13:31:44 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Extensions
[2009-06-09 13:31:44 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-10-08 13:27:48 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions
[2009-07-09 00:36:32 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009-07-09 14:14:16 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2009-07-08 23:26:05 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2009-08-14 13:06:23 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-06-27 12:52:28 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{eaf8a4ef-d221-45ca-9deb-d0934b45fa34}
[2009-07-08 23:33:43 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2009-07-08 23:20:28 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\anycolor.pavlos256@gmail.com
[2009-06-20 12:32:59 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions
[2009-09-10 16:13:00 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-09-10 16:13:00 | 00,023,032 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-09-10 16:13:00 | 00,134,648 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007-04-30 16:29:22 | 00,049,152 | ---- | M] (Adobe Systems, Inc.) -- D:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2009-09-10 16:13:02 | 00,065,528 | ---- | M] (mozilla.org) -- D:\Program Files\mozilla firefox\plugins\npnul32.dll
[2003-07-15 06:56:52 | 00,013,888 | ---- | M] (Microsoft Corporation) -- D:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2009-07-25 21:28:08 | 00,002,767 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2009-06-13 11:07:49 | 00,001,406 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2009-06-13 11:07:49 | 00,001,706 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-06-13 11:07:49 | 00,000,917 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2009-06-13 11:07:49 | 00,000,858 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2009-06-13 11:07:49 | 00,001,183 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2009-06-13 11:07:49 | 00,001,683 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: (27 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - @!22BF9-DF26-493f-B0DA-6D2FC5E6429E} - No CLSID value found.
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - D:\Documents and Settings\PC\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.)
O2 - BHO: (no name) - Ř?!ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (no name) - X@!C7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - D:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare)
O3 - HKCU\..\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - D:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare)
O4 - HKLM..\Run: [ccApp] D:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [RTHDCPL] D:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_02\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [vptray] D:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Java Plug-in 1.5.0_02)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.172.224.160 89.228.6.21
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - D:\WINDOWS\system32\NavLogon.dll - D:\WINDOWS\System32\NavLogon.dll (Symantec Corporation)
O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - CLSID or File not found.
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O28 - HKLM ShellExecuteHooks: {BD344AF4-67AB-4E19-A630-7435587D320B} - D:\WINDOWS\System32\ahndoor0.dll ()
O30 - LSA: Authentication Packages - (nwprovau) - D:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-11-11 11:04:46 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2008-10-24 14:30:24 | 00,837,392 | R--- | M] () - I:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2007-01-25 11:51:25 | 00,000,172 | R--- | M] () - I:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:41 | 03,460,608 | R--- | M] () - K:\autorun.dat -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:22 | 00,000,139 | R--- | M] () - K:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - D:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[6 D:\WINDOWS\*.tmp files]
[2009-10-07 09:30:00 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\0148
[2009-10-04 18:05:26 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Dane aplikacji\2K Sports
[2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Dane aplikacji\Sports Interactive
[2009-10-06 13:37:14 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Symantec
[2009-10-06 13:34:59 | 00,000,000 | ---D | C] -- D:\Program Files\antywirus
[2009-10-06 13:36:32 | 00,000,000 | ---D | C] -- D:\Program Files\Symantec
[2009-10-06 13:36:24 | 00,000,000 | ---D | C] -- D:\Program Files\Symantec AntiVirus
[2009-10-08 14:48:22 | 00,000,000 | ---D | C] -- D:\Program Files\trend micro
[2009-09-30 21:53:26 | 00,000,000 | -H-D | C] -- D:\Program Files\Zero G Registry
[2009-10-08 15:00:19 | 00,520,704 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe
[2009-10-08 14:48:22 | 00,000,000 | ---D | C] -- D:\rsit
[2009-10-08 14:43:20 | 00,000,000 | -HSD | C] -- D:\RECYCLER
[2009-10-08 14:32:04 | 00,000,000 | ---D | C] -- D:\WINDOWS\temp
[2009-10-08 14:28:43 | 00,000,000 | ---D | C] -- D:\ComboFix
[2009-10-06 13:36:36 | 00,123,488 | ---- | C] (Symantec Corporation) -- D:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009-10-06 13:36:36 | 00,091,856 | ---- | C] (Symantec Corporation) -- D:\WINDOWS\System32\S32EVNT1.DLL
[2009-10-06 13:25:41 | 00,000,000 | ---D | C] -- D:\Qoobox
[2009-10-05 11:59:07 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Pulpit\xxx
[2009-10-04 19:51:37 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\NBA LIVE 08
[2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\Sports Interactive
[2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dokumenty\Sports Interactive
[2009-09-29 20:42:42 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\NBA LIVE 06
[2009-09-12 10:13:47 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Pulpit\kwie
[2003-10-05 10:41:14 | 00,123,520 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\sojubus.sys
[2003-09-28 10:57:52 | 00,005,504 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\sojuscsi.sys

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[5 D:\WINDOWS\System32\*.tmp files]
[6 D:\WINDOWS\*.tmp files]
[2009-10-08 15:00:24 | 00,520,704 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe
[2009-10-08 14:47:50 | 00,781,909 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\RSIT.exe
[2009-10-08 14:32:02 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2009-10-08 14:31:24 | 00,000,246 | ---- | M] () -- D:\WINDOWS\system.ini
[2009-10-08 14:17:21 | 00,195,356 | ---- | M] () -- D:\WINDOWS\System32\nvapps.xml
[2009-10-08 14:17:20 | 00,001,032 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009-10-08 14:17:16 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2009-10-08 14:16:07 | 04,314,060 | -H-- | M] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-10-08 14:07:00 | 00,001,036 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009-10-08 13:46:37 | 00,002,596 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT
[2009-10-08 12:51:16 | 00,763,990 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI
[2009-10-08 12:51:16 | 00,355,830 | ---- | M] () -- D:\WINDOWS\System32\perfh015.dat
[2009-10-08 12:51:16 | 00,311,740 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2009-10-08 12:51:16 | 00,049,712 | ---- | M] () -- D:\WINDOWS\System32\perfc015.dat
[2009-10-08 12:51:16 | 00,040,128 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2009-10-08 12:02:44 | 00,000,000 | ---- | M] () -- D:\WINDOWS\VPC32.INI
[2009-10-06 20:17:39 | 00,000,591 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\NBA LIVE 06.lnk
[2009-10-06 14:38:11 | 00,000,573 | ---- | M] () -- D:\WINDOWS\win.ini
[2009-10-06 13:31:15 | 00,000,027 | ---- | M] () -- D:\WINDOWS\System32\drivers\etc\hosts
[2009-10-04 19:55:28 | 00,011,264 | ---- | M] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-10-04 19:50:12 | 00,001,471 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\EA SPORTS™ NBA LIVE 08.lnk
[2009-10-04 18:26:10 | 00,000,510 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\NBA 2K9.exe.lnk
[2009-10-04 18:02:49 | 26,271,866 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\spolszczenie_2k9.rar
[2009-10-04 18:01:40 | 00,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2009-10-02 19:39:08 | 07,524,224 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\Inna - Deja vu(1).mp3
[2009-09-30 21:54:20 | 00,000,556 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Football Manager 2008.lnk
[2009-09-24 16:22:25 | 03,122,605 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\rihanna - push up on me.mp31253803802_[mp3.teledyski.info].mp3
[2009-09-14 02:12:36 | 00,229,888 | ---- | M] () -- D:\WINDOWS\PEV.exe

[color=#E56717]========== Files - No Company Name ==========[/color]
[2009-10-08 14:47:39 | 00,781,909 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\RSIT.exe
[2009-10-08 12:02:44 | 00,000,000 | ---- | C] () -- D:\WINDOWS\VPC32.INI
[2009-10-04 19:50:12 | 00,001,471 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\EA SPORTS™ NBA LIVE 08.lnk
[2009-10-04 18:26:10 | 00,000,510 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\NBA 2K9.exe.lnk
[2009-10-04 17:48:20 | 26,271,866 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\spolszczenie_2k9.rar
[2009-10-02 19:39:33 | 07,524,224 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\Inna - Deja vu(1).mp3
[2009-09-30 21:54:20 | 00,000,556 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\Football Manager 2008.lnk
[2009-09-29 20:32:37 | 00,000,591 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\NBA LIVE 06.lnk
[2009-09-24 16:30:37 | 03,122,605 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\rihanna - push up on me.mp31253803802_[mp3.teledyski.info].mp3
[2009-07-09 22:42:17 | 04,314,060 | -H-- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-06-24 00:05:28 | 00,168,448 | ---- | C] () -- D:\WINDOWS\System32\unrar.dll
[2009-06-20 15:01:29 | 00,354,816 | ---- | C] () -- D:\WINDOWS\System32\psisdecd.dll
[2009-06-19 14:07:50 | 00,076,407 | ---- | C] () -- D:\Documents and Settings\PC\Dane aplikacji\Smiley.ico
[2009-06-13 14:34:41 | 00,000,421 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2009-06-11 15:57:43 | 00,138,920 | ---- | C] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009-06-09 22:10:06 | 00,000,298 | ---- | C] () -- D:\WINDOWS\game.ini
[2009-06-09 14:49:10 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
[2009-06-09 13:27:41 | 00,011,264 | ---- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-06-09 13:25:04 | 00,042,944 | ---- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2009-06-09 13:03:24 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\PC\Dane aplikacji\desktop.ini
[2008-06-25 21:57:00 | 01,703,936 | ---- | C] () -- D:\WINDOWS\System32\nvwdmcpl.dll
[2008-06-25 21:57:00 | 01,486,848 | ---- | C] () -- D:\WINDOWS\System32\nview.dll
[2008-06-25 21:57:00 | 01,019,904 | ---- | C] () -- D:\WINDOWS\System32\nvwimg.dll
[2008-06-25 21:57:00 | 00,466,944 | ---- | C] () -- D:\WINDOWS\System32\nvshell.dll
[2008-06-25 21:57:00 | 00,286,720 | ---- | C] () -- D:\WINDOWS\System32\nvnt4cpl.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSwedish.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSpanish.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelPortugese.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelKorean.dll
[2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelJapanese.dll
[2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelGerman.dll
[2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelFrench.dll
[2008-06-05 08:58:26 | 00,197,912 | ---- | C] () -- D:\WINDOWS\System32\physxcudart_20.dll
[2004-09-01 17:49:17 | 03,375,104 | ---- | C] () -- D:\WINDOWS\System32\qt-mt331.dll
[2004-08-04 02:44:20 | 00,063,554 | ---- | C] () -- D:\WINDOWS\System32\ahndoor0.dll
[2003-04-08 11:40:22 | 00,005,679 | ---- | C] () -- D:\WINDOWS\System32\OUTLPERF.INI
[2001-07-22 01:16:20 | 00,000,573 | ---- | C] () -- D:\WINDOWS\win.ini
[2001-07-22 01:15:52 | 00,000,246 | ---- | C] () -- D:\WINDOWS\system.ini
< End of report >[/log]

Psycholandia
komentarz
komentarz

Loga nie ma, wklej jeszcze raz :)

kula1576
komentarz
komentarz (edytowane)

Dałem bez spacji ale już poprawiłem :]

Psycholandia
komentarz
komentarz

W okienko OTL wklej poniższy skrypt i klik na Run Fix:

[code]:Processes
explorer.exe

:OTL
O2 - BHO: (no name) - @!22BF9-DF26-493f-B0DA-6D2FC5E6429E} - No CLSID value found.
O2 - BHO: (no name) - Ř?!ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (no name) - X@!C7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - D:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare)
O3 - HKCU\..\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - D:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare)
O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - CLSID or File not found.
O32 - AutoRun File - [2008-10-24 14:30:24 | 00,837,392 | R--- | M] () - I:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2007-01-25 11:51:25 | 00,000,172 | R--- | M] () - I:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:41 | 03,460,608 | R--- | M] () - K:\autorun.dat -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:22 | 00,000,139 | R--- | M] () - K:\autorun.inf -- [ CDFS ]

:Files
D:\Program Files\BearShare Applications\BearShare MediaBar
D:\RECYCLER
D:\Qoobox
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
D:\WINDOWS\PEV.exe
D:\WINDOWS\System32\unrar.dll

:Commands
[emptytemp]
[start explorer]
[Reboot][/code]

Otwórz notatnik tekstowy i wklej do niego poniższy tekst: [code]Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
[/code]
Zapisz jako->Wybierz [b]Wszystkie pliki[/b]->wpisz [b]Fix.reg[/b]->Następnie kliknij na zapisany plik i uruchom komputer ponownie.

Przeskanuj komputer tym: [url="http://www.programosy.pl/program,malwarebytes-anti-malware.html"]Malware[/url] usuń wszystko co znajdzie i daj loga po kasowaniu (loga z Malware)

kula1576
komentarz
komentarz

Trwa pełne skanowanie tym Malware a chciałem spytać przy okazji o ten wpis który się pokazał w tym pierwszym logu z Combofixa: d:\windows\AhnRpta.exe
Cały czas mam to uruchomione w menadżerze zadań..

Psycholandia
komentarz
komentarz

Po skanowaniu Malware usuniesz wszystko co znajdzie + dasz loga po usuwaniu + nowego loga z OTL

kula1576
komentarz
komentarz

Log po skanowaniu i usuwaniu z Malware:
[log]
Malwarebytes' Anti-Malware 1.41
Wersja bazy definicji: 2775
Windows 5.1.2600 Dodatek Service Pack 3

2009-10-08 16:27:23
mbam-log-2009-10-08 (16-27-23).txt

Typ skanowania: Pełne skanowanie (C:\|D:\|E:\|F:\|G:\|H:\|)
Przeskanowane obiekty: 298210
Upłynęło: 47 minute(s), 41 second(s)

Zainfekowane procesy w pamięci: 1
Zainfekowane moduły pamięci: 0
Zainfekowane klucze rejestru: 0
Zainfekowane wartości rejestru: 0
Zainfekowane pliki rejestru: 1
Zainfekowane foldery: 0
Zainfekowane pliki: 1

Zainfekowane procesy w pamięci:
D:\WINDOWS\AhnRpta.exe (Trojan.Backdoor) -> Unloaded process successfully.

Zainfekowane moduły pamięci:
(Nie wykryto groźnych plików)

Zainfekowane klucze rejestru:
(Nie wykryto groźnych plików)

Zainfekowane wartości rejestru:
(Nie wykryto groźnych plików)

Zainfekowane pliki rejestru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Zainfekowane foldery:
(Nie wykryto groźnych plików)

Zainfekowane pliki:
D:\WINDOWS\AhnRpta.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
[/log]

Log po ponownym skanowaniu OTL:

[log]
OTL logfile created on: 2009-10-08 16:30:22 - Run 2
OTL by OldTimer - Version 3.0.18.4 Folder = D:\Documents and Settings\PC\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 100,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 9,90 Gb Total Space | 1,28 Gb Free Space | 12,96% Space Free | Partition Type: FAT32
Drive D: | 29,29 Gb Total Space | 16,51 Gb Free Space | 56,38% Space Free | Partition Type: NTFS
Drive E: | 13,79 Gb Total Space | 3,41 Gb Free Space | 24,72% Space Free | Partition Type: FAT32
Drive F: | 13,55 Gb Total Space | 3,39 Gb Free Space | 25,05% Space Free | Partition Type: FAT32
Drive G: | 97,65 Gb Total Space | 18,08 Gb Free Space | 18,52% Space Free | Partition Type: NTFS
Drive H: | 171,13 Gb Total Space | 22,97 Gb Free Space | 13,42% Space Free | Partition Type: NTFS
Drive I: | 3,58 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive K: | 3,48 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: KUL
Current User Name: PC
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2005-06-02 09:21:46 | 00,161,392 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2005-06-02 09:21:40 | 00,185,968 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2008-04-14 22:51:18 | 01,035,264 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Explorer.EXE
PRC - [2008-05-14 03:50:46 | 16,862,720 | R--- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\RTHDCPL.EXE
PRC - [2005-06-02 09:21:38 | 00,048,752 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2005-06-23 19:27:36 | 00,085,696 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\VPTray.exe
PRC - [2005-06-23 19:27:18 | 00,019,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\DefWatch.exe
PRC - [2008-10-07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\nvsvc32.exe
PRC - [2009-06-11 15:57:29 | 00,075,064 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrA.exe
PRC - [2009-07-09 11:24:20 | 00,189,072 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrB.exe
PRC - [2008-04-14 22:51:32 | 00,070,144 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\AhnRpta.exe
PRC - [2009-07-08 23:50:07 | 00,133,104 | ---- | M] (Google Inc.) -- D:\Program Files\Google\Update\GoogleUpdate.exe
PRC - [2005-06-23 19:27:28 | 01,715,904 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Rtvscan.exe
PRC - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wdfmgr.exe
PRC - [2008-04-14 22:51:52 | 00,013,824 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wscntfy.exe
PRC - [2009-10-08 15:00:24 | 00,520,704 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe

[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2005-06-02 09:21:40 | 00,185,968 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [Auto | Running])
SRV - [2005-06-02 09:21:46 | 00,083,568 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc [On_Demand | Stopped])
SRV - [2005-06-02 09:21:46 | 00,161,392 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running])
SRV - [2005-06-23 19:27:18 | 00,019,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running])
SRV - [2009-07-08 23:50:07 | 00,133,104 | ---- | M] (Google Inc.) -- D:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1ca0016106c1b22 [Auto | Stopped])
SRV - [2008-04-14 22:50:46 | 00,038,400 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2008-10-07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2003-07-28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2009-06-11 15:57:29 | 00,075,064 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
SRV - [2009-07-09 11:24:20 | 00,189,072 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrB.exe -- (PnkBstrB [Auto | Running])
SRV - [2005-06-23 19:27:30 | 00,124,608 | ---- | M] (symantec) -- D:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam [On_Demand | Stopped])
SRV - [2005-04-22 12:03:28 | 00,206,552 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [On_Demand | Stopped])
SRV - [2005-03-30 21:48:22 | 00,992,864 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc [On_Demand | Stopped])
SRV - [2005-06-23 19:27:28 | 01,715,904 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus [Auto | Running])
SRV - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])
SRV - [2004-08-04 02:44:16 | 00,006,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wuauserv.dll -- (wuauserv [Auto | Running])

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2006-07-01 23:32:26 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- D:\WINDOWS\System32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running])
DRV - [2009-09-17 08:53:46 | 00,371,248 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl [System | Running])
DRV - [2009-06-09 13:55:32 | 00,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- D:\WINDOWS\gdrv.sys -- (gdrv [On_Demand | Stopped])
DRV - [2008-04-13 22:06:06 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- D:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2008-05-15 02:03:12 | 04,742,144 | R--- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\System32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2009-09-17 08:53:46 | 00,084,912 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\VirusDefs\20091007.002\NAVENG.SYS -- (NAVENG [On_Demand | Running])
DRV - [2009-09-17 08:53:46 | 01,323,568 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\VirusDefs\20091007.002\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
DRV - [2003-04-02 09:54:16 | 00,020,648 | R--- | M] (Thomson Inc.) -- D:\WINDOWS\System32\DRIVERS\netrcacm.sys -- (netrcacm [On_Demand | Running])
DRV - [2008-10-07 13:33:00 | 06,133,856 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2008-04-14 00:26:08 | 00,088,320 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx [Auto | Running])
DRV - [2001-08-18 00:54:18 | 00,063,232 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnknb.sys -- (NwlnkNb [Auto | Running])
DRV - [2001-08-18 00:54:18 | 00,055,936 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx [Auto | Running])
DRV - [2008-04-14 00:04:14 | 00,163,584 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwrdr.sys -- (NWRDR [On_Demand | Stopped])
DRV - [2009-07-09 11:24:29 | 00,138,920 | ---- | M] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys -- (PnkBstrK [On_Demand | Stopped])
DRV - [2001-08-18 00:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- D:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008-01-04 08:10:16 | 00,105,856 | R--- | M] (Realtek Semiconductor Corporation ) -- D:\WINDOWS\System32\DRIVERS\Rtenicxp.sys -- (RTLE8023xp [On_Demand | Stopped])
DRV - [2005-02-04 20:14:30 | 00,324,232 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT [System | Running])
DRV - [2005-02-04 20:14:32 | 00,053,896 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL [System | Running])
DRV - [2008-04-13 22:09:18 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- D:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2003-10-05 10:41:14 | 00,123,520 | ---- | M] ( ) -- D:\WINDOWS\system32\DRIVERS\sojubus.sys -- (sojubus [Boot | Running])
DRV - [2003-09-28 10:57:52 | 00,005,504 | ---- | M] ( ) -- D:\WINDOWS\system32\DRIVERS\sojuscsi.sys -- (sojuscsi [Boot | Running])
DRV - [2005-03-30 21:48:20 | 00,372,832 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv [On_Demand | Stopped])
DRV - [2005-05-13 19:50:10 | 00,123,488 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
DRV - [2005-04-22 12:03:00 | 00,017,976 | ---- | M] (Symantec Corporation) -- D:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV [On_Demand | Running])
DRV - [2005-04-22 12:03:02 | 00,267,192 | ---- | M] (Symantec Corporation) -- D:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI [System | Running])

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.startup.homepage: "http://google.pl"
FF - prefs.js..extensions.enabledItems: anycolor.pavlos256@gmail.com:0.3.0
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.2
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:3.2.8
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2009-09-10 16:13:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2009-10-04 19:46:11 | 00,000,000 | ---D | M]

[2009-06-09 13:31:44 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Extensions
[2009-06-09 13:31:44 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-10-08 13:27:48 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions
[2009-07-09 00:36:32 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009-07-09 14:14:16 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2009-07-08 23:26:05 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2009-08-14 13:06:23 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-06-27 12:52:28 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{eaf8a4ef-d221-45ca-9deb-d0934b45fa34}
[2009-07-08 23:33:43 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2009-07-08 23:20:28 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\anycolor.pavlos256@gmail.com
[2009-06-20 12:32:59 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions
[2009-09-10 16:13:00 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-09-10 16:13:00 | 00,023,032 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-09-10 16:13:00 | 00,134,648 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007-04-30 16:29:22 | 00,049,152 | ---- | M] (Adobe Systems, Inc.) -- D:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2009-09-10 16:13:02 | 00,065,528 | ---- | M] (mozilla.org) -- D:\Program Files\mozilla firefox\plugins\npnul32.dll
[2003-07-15 06:56:52 | 00,013,888 | ---- | M] (Microsoft Corporation) -- D:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2009-07-25 21:28:08 | 00,002,767 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2009-06-13 11:07:49 | 00,001,406 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2009-06-13 11:07:49 | 00,001,706 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-06-13 11:07:49 | 00,000,917 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2009-06-13 11:07:49 | 00,000,858 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2009-06-13 11:07:49 | 00,001,183 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2009-06-13 11:07:49 | 00,001,683 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: (27 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - D:\Documents and Settings\PC\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.)
O4 - HKLM..\Run: [ccApp] D:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [RTHDCPL] D:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_02\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [vptray] D:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Java Plug-in 1.5.0_02)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.172.224.160 89.228.6.21
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - D:\WINDOWS\system32\NavLogon.dll - D:\WINDOWS\System32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O28 - HKLM ShellExecuteHooks: {BD344AF4-67AB-4E19-A630-7435587D320B} - D:\WINDOWS\System32\ahndoor0.dll ()
O30 - LSA: Authentication Packages - (nwprovau) - D:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-11-11 11:04:46 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2008-10-24 14:30:24 | 00,837,392 | R--- | M] () - I:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2007-01-25 11:51:25 | 00,000,172 | R--- | M] () - I:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:41 | 03,460,608 | R--- | M] () - K:\autorun.dat -- [ CDFS ]
O32 - AutoRun File - [2007-08-18 04:49:22 | 00,000,139 | R--- | M] () - K:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - D:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2009-10-07 09:30:00 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\0148
[2009-10-08 15:38:09 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
[2009-10-04 18:05:26 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Dane aplikacji\2K Sports
[2009-10-08 15:38:14 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Dane aplikacji\Malwarebytes
[2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Dane aplikacji\Sports Interactive
[2009-10-06 13:37:14 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Symantec
[2009-10-06 13:34:59 | 00,000,000 | ---D | C] -- D:\Program Files\antywirus
[2009-10-08 15:38:09 | 00,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware
[2009-10-06 13:36:32 | 00,000,000 | ---D | C] -- D:\Program Files\Symantec
[2009-10-06 13:36:24 | 00,000,000 | ---D | C] -- D:\Program Files\Symantec AntiVirus
[2009-10-08 14:48:22 | 00,000,000 | ---D | C] -- D:\Program Files\trend micro
[2009-09-30 21:53:26 | 00,000,000 | -H-D | C] -- D:\Program Files\Zero G Registry
[2009-10-08 16:29:06 | 00,070,144 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\AhnRpta.exe
[2009-10-08 15:38:10 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-10-08 15:38:09 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys
[2009-10-08 15:37:04 | 04,045,528 | ---- | C] (Malwarebytes Corporation ) -- D:\Documents and Settings\PC\Pulpit\mbam-setup.exe
[2009-10-08 15:22:38 | 00,000,000 | -HSD | C] -- D:\RECYCLER
[2009-10-08 15:22:33 | 00,000,000 | ---D | C] -- D:\_OTL
[2009-10-08 15:00:19 | 00,520,704 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe
[2009-10-08 14:48:22 | 00,000,000 | ---D | C] -- D:\rsit
[2009-10-08 14:32:04 | 00,000,000 | ---D | C] -- D:\WINDOWS\temp
[2009-10-08 14:28:43 | 00,000,000 | ---D | C] -- D:\ComboFix
[2009-10-06 13:36:36 | 00,123,488 | ---- | C] (Symantec Corporation) -- D:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009-10-06 13:36:36 | 00,091,856 | ---- | C] (Symantec Corporation) -- D:\WINDOWS\System32\S32EVNT1.DLL
[2009-10-05 11:59:07 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Pulpit\xxx
[2009-10-04 19:51:37 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\NBA LIVE 08
[2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\Sports Interactive
[2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dokumenty\Sports Interactive
[2009-09-29 20:42:42 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\NBA LIVE 06
[2009-09-12 10:13:47 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Pulpit\kwie
[2003-10-05 10:41:14 | 00,123,520 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\sojubus.sys
[2003-09-28 10:57:52 | 00,005,504 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\sojuscsi.sys

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2009-10-08 16:29:00 | 00,195,356 | ---- | M] () -- D:\WINDOWS\System32\nvapps.xml
[2009-10-08 16:28:58 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2009-10-08 16:28:56 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2009-10-08 15:38:13 | 00,000,700 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2009-10-08 15:37:45 | 04,045,528 | ---- | M] (Malwarebytes Corporation ) -- D:\Documents and Settings\PC\Pulpit\mbam-setup.exe
[2009-10-08 15:34:09 | 00,000,126 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\Fix.reg
[2009-10-08 15:00:24 | 00,520,704 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe
[2009-10-08 14:47:50 | 00,781,909 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\RSIT.exe
[2009-10-08 14:31:24 | 00,000,246 | ---- | M] () -- D:\WINDOWS\system.ini
[2009-10-08 14:16:07 | 04,314,060 | -H-- | M] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-10-08 13:46:37 | 00,002,596 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT
[2009-10-08 12:51:16 | 00,763,990 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI
[2009-10-08 12:51:16 | 00,355,830 | ---- | M] () -- D:\WINDOWS\System32\perfh015.dat
[2009-10-08 12:51:16 | 00,311,740 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2009-10-08 12:51:16 | 00,049,712 | ---- | M] () -- D:\WINDOWS\System32\perfc015.dat
[2009-10-08 12:51:16 | 00,040,128 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2009-10-08 12:02:44 | 00,000,000 | ---- | M] () -- D:\WINDOWS\VPC32.INI
[2009-10-06 20:17:39 | 00,000,591 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\NBA LIVE 06.lnk
[2009-10-06 14:38:11 | 00,000,573 | ---- | M] () -- D:\WINDOWS\win.ini
[2009-10-06 13:31:15 | 00,000,027 | ---- | M] () -- D:\WINDOWS\System32\drivers\etc\hosts
[2009-10-04 19:55:28 | 00,011,264 | ---- | M] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-10-04 19:50:12 | 00,001,471 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\EA SPORTS™ NBA LIVE 08.lnk
[2009-10-04 18:26:10 | 00,000,510 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\NBA 2K9.exe.lnk
[2009-10-04 18:02:49 | 26,271,866 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\spolszczenie_2k9.rar
[2009-10-04 18:01:40 | 00,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2009-10-02 19:39:08 | 07,524,224 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\Inna - Deja vu(1).mp3
[2009-09-30 21:54:20 | 00,000,556 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Football Manager 2008.lnk
[2009-09-24 16:22:25 | 03,122,605 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\rihanna - push up on me.mp31253803802_[mp3.teledyski.info].mp3
[2009-09-10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-09-10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys

[color=#E56717]========== Files - No Company Name ==========[/color]
[2009-10-08 15:38:13 | 00,000,700 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2009-10-08 15:34:09 | 00,000,126 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\Fix.reg
[2009-10-08 14:47:39 | 00,781,909 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\RSIT.exe
[2009-10-08 12:02:44 | 00,000,000 | ---- | C] () -- D:\WINDOWS\VPC32.INI
[2009-10-04 19:50:12 | 00,001,471 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\EA SPORTS™ NBA LIVE 08.lnk
[2009-10-04 18:26:10 | 00,000,510 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\NBA 2K9.exe.lnk
[2009-10-04 17:48:20 | 26,271,866 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\spolszczenie_2k9.rar
[2009-10-02 19:39:33 | 07,524,224 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\Inna - Deja vu(1).mp3
[2009-09-30 21:54:20 | 00,000,556 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\Football Manager 2008.lnk
[2009-09-29 20:32:37 | 00,000,591 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\NBA LIVE 06.lnk
[2009-09-24 16:30:37 | 03,122,605 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\rihanna - push up on me.mp31253803802_[mp3.teledyski.info].mp3
[2009-07-09 22:42:17 | 04,314,060 | -H-- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-06-20 15:01:29 | 00,354,816 | ---- | C] () -- D:\WINDOWS\System32\psisdecd.dll
[2009-06-19 14:07:50 | 00,076,407 | ---- | C] () -- D:\Documents and Settings\PC\Dane aplikacji\Smiley.ico
[2009-06-13 14:34:41 | 00,000,421 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2009-06-11 15:57:43 | 00,138,920 | ---- | C] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009-06-09 22:10:06 | 00,000,298 | ---- | C] () -- D:\WINDOWS\game.ini
[2009-06-09 14:49:10 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
[2009-06-09 13:27:41 | 00,011,264 | ---- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-06-09 13:25:04 | 00,042,944 | ---- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2009-06-09 13:03:24 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\PC\Dane aplikacji\desktop.ini
[2008-06-25 21:57:00 | 01,703,936 | ---- | C] () -- D:\WINDOWS\System32\nvwdmcpl.dll
[2008-06-25 21:57:00 | 01,486,848 | ---- | C] () -- D:\WINDOWS\System32\nview.dll
[2008-06-25 21:57:00 | 01,019,904 | ---- | C] () -- D:\WINDOWS\System32\nvwimg.dll
[2008-06-25 21:57:00 | 00,466,944 | ---- | C] () -- D:\WINDOWS\System32\nvshell.dll
[2008-06-25 21:57:00 | 00,286,720 | ---- | C] () -- D:\WINDOWS\System32\nvnt4cpl.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSwedish.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSpanish.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelPortugese.dll
[2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelKorean.dll
[2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelJapanese.dll
[2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelGerman.dll
[2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelFrench.dll
[2008-06-05 08:58:26 | 00,197,912 | ---- | C] () -- D:\WINDOWS\System32\physxcudart_20.dll
[2004-09-01 17:49:17 | 03,375,104 | ---- | C] () -- D:\WINDOWS\System32\qt-mt331.dll
[2004-08-04 02:44:20 | 00,063,554 | ---- | C] () -- D:\WINDOWS\System32\ahndoor0.dll
[2003-04-08 11:40:22 | 00,005,679 | ---- | C] () -- D:\WINDOWS\System32\OUTLPERF.INI
[2001-07-22 01:16:20 | 00,000,573 | ---- | C] () -- D:\WINDOWS\win.ini
[2001-07-22 01:15:52 | 00,000,246 | ---- | C] () -- D:\WINDOWS\system.ini
< End of report >
[/log]

Psycholandia
komentarz
komentarz

W okienko OTL wklej poniższy skrypt i klik na Run Fix:

[code]:Processes
explorer.exe

:Files
D:\WINDOWS\AhnRpta.exe

:Commands
[emptytemp]
[start explorer]
[Reboot][/code]
I dajesz nowego loga z OTL.

kula1576
komentarz
komentarz

nowy Log OTL

[log]
All processes killed
========== PROCESSES ==========
Process explorer.exe killed successfully!
========== FILES ==========
D:\WINDOWS\AhnRpta.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. D:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33075 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: PC
->Temp folder emptied: 915400 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Java cache emptied: 0 bytes
File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\XUL.mfl scheduled to be deleted on reboot.
->FireFox cache emptied: 33225897 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 32,62 mb


OTL by OldTimer - Version 3.0.18.4 log created on 10082009_164132

Files\Folders moved on Reboot...
D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_001_ moved successfully.
D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_002_ moved successfully.
D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_003_ moved successfully.
D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_MAP_ moved successfully.
D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\urlclassifier3.sqlite moved successfully.
D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\XUL.mfl moved successfully.

Registry entries deleted on Reboot...
[/log]

Psycholandia
komentarz
komentarz

Uruchamiasz OTL i klikasz na CleanUp. Czysto.

kula1576
komentarz
komentarz

Zrobiłem wszystko ale dalej mam ten proces uruchomiony w menadżerze zadań..

Psycholandia
komentarz
komentarz

Pobierz Avengera: http://swandog46.geekstogo.com/avenger.zip
Wklej w okienko poniższy skrypt:

[code]Files to delete:

D:\WINDOWS\AhnRpta.exe[/code]
I klik na [b]Execute[/b]
Dajesz loga powstałego po usuwaniu i sprawdzasz czy proces nadal jest

kula1576
komentarz
komentarz

Log po Avanger:

[log]
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at D:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "D:\WINDOWS\AhnRpta.exe" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
[/log]

Niestety po restarcie proces się pokazał ponownie

Psycholandia
komentarz
komentarz

Pobierz Combofixa: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Otwierasz notatnik i wklejasz w nim:
[code]File::
D:\WINDOWS\AhnRpta.exe[/code]
następnie: plik -> zapisz jako ----> [b]CFScript.txt[/b]- przeciągasz i upuszczasz CFScript.txt na ikonkę Combofix.exe. Tak jak niżej.
[URL=http://img5.imagebanana.com/][IMG]http://img5.imagebanana.com/img/8jtunobk/combofix_cfscript.gif[/IMG][/URL]
Dajesz loga powstałego po usuwaniu + sprawdzasz czy proces istnieje.

kula1576
komentarz
komentarz (edytowane)

Log z Combofixa:

[log]
ComboFix 09-10-07.05 - PC 2009-10-08 17:07.8.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3326.2683 [GMT 2:00]
Uruchomiony z: d:\documents and settings\PC\Pulpit\ComboFix.exe
Użyto następujących komend :: d:\documents and settings\PC\Pulpit\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!

FILE ::
"d:\windows\AhnRpta.exe"
.

((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\windows\AhnRpta.exe

.
((((((((((((((((((((((((( Pliki utworzone od 2009-09-08 do 2009-10-08 )))))))))))))))))))))))))))))))
.

2009-10-08 13:38 . 2009-10-08 13:38 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Malwarebytes
2009-10-08 13:38 . 2009-09-10 12:54 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2009-10-08 13:38 . 2009-10-08 13:38 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2009-10-08 13:38 . 2009-10-08 13:38 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Malwarebytes
2009-10-08 13:38 . 2009-09-10 12:53 19160 ----a-w- d:\windows\system32\drivers\mbam.sys
2009-10-08 12:48 . 2009-10-08 12:48 -------- d-----w- d:\program files\trend micro
2009-10-07 07:30 . 2009-10-07 07:30 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\0148
2009-10-06 11:37 . 2009-10-06 11:37 -------- d-----w- d:\documents and settings\PC\Ustawienia lokalne\Dane aplikacji\Symantec
2009-10-06 11:36 . 2005-05-13 17:50 91856 ----a-w- d:\windows\system32\S32EVNT1.DLL
2009-10-06 11:36 . 2005-05-13 17:50 123488 ----a-w- d:\windows\system32\drivers\SYMEVENT.SYS
2009-10-06 11:36 . 2009-10-06 11:36 -------- d-----w- d:\program files\Symantec
2009-10-06 11:36 . 2009-10-08 14:57 -------- d-----w- d:\program files\Symantec AntiVirus
2009-10-06 11:34 . 2009-10-06 11:34 -------- d-----w- d:\program files\antywirus
2009-10-04 16:05 . 2009-10-04 16:05 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\2K Sports
2009-09-30 19:55 . 2009-09-30 19:55 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Sports Interactive
2009-09-30 19:53 . 2009-09-30 19:53 -------- d--h--w- d:\program files\Zero G Registry
2009-09-30 19:52 . 2009-09-30 19:52 -------- d--h--w- d:\documents and settings\PC\InstallAnywhere

.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 13:22 . 2009-06-19 12:07 -------- d-----w- d:\program files\BearShare Applications
2009-10-08 10:51 . 2001-10-26 17:15 49712 ----a-w- d:\windows\system32\perfc015.dat
2009-10-08 10:51 . 2001-10-26 17:15 355830 ----a-w- d:\windows\system32\perfh015.dat
2009-10-06 12:37 . 2009-06-20 09:52 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\uTorrent
2009-10-06 12:11 . 2009-06-09 11:56 -------- d-----w- d:\program files\Common Files\Symantec Shared
2009-10-06 11:36 . 2009-06-09 12:01 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Symantec
2009-09-15 20:22 . 2009-06-09 14:36 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu
2009-09-08 16:55 . 2009-06-09 13:36 -------- d-----w- d:\program files\AGEIA Technologies
2009-09-05 21:05 . 2009-06-14 18:23 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\BESTplayer
2009-09-04 09:07 . 2009-06-09 14:36 -------- d-----w- d:\program files\Nowe Gadu-Gadu
2009-08-28 12:56 . 2009-08-28 12:56 -------- d-----w- d:\program files\Half-Life Model Viewer
2009-08-22 21:49 . 2009-06-09 13:03 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Test Drive Unlimited
2009-07-27 17:27 . 2009-06-09 11:58 107888 ----a-w- d:\windows\system32\CmdLineExt.dll
.

((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"SunJavaUpdateSched"="d:\program files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 36975]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"ccApp"="d:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752]
"vptray"="d:\progra~1\SYMANT~1\VPTray.exe" [2005-06-23 85696]
"Malwarebytes Anti-Malware (reboot)"="d:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.exe [2008-05-14 16862720]
"nwiz"="nwiz.exe" - d:\windows\system32\nwiz.exe [2008-10-07 1630208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BD344AF4-67AB-4E19-A630-7435587D320B}"= "d:\windows\system32\ahndoor0.dll" [2008-04-14 63554]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Talisman.lnk]
path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Talisman.lnk
backup=d:\windows\pss\Talisman.lnkStartup

[HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Yahoo! Widget Engine.lnk]
path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Yahoo! Widget Engine.lnk
backup=d:\windows\pss\Yahoo! Widget Engine.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"g:\\Gry\\Test Drive Unlimited\\TestDriveUnlimited.exe"=
"d:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"g:\\Gry\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"d:\\Program Files\\Ares\\Ares.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"d:\\Program Files\\Ares\\chatServer.exe"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"g:\\Gry\\Stronghold 2\\Stronghold2.exe"=
"g:\\Gry\\PES09\\pes2009.exe"=
"g:\\Gry\\Q U A K E II\\r1q2.exe"=
"g:\\Gry\\Valve\\SteamApps\\kula_1576\\counter-strike\\hl.exe"=
"g:\\Gry\\Fotbal Menager 2008\\fm.exe"=

R0 sojubus;sojubus;d:\windows\system32\drivers\sojubus.sys [2003-10-05 123520]
R0 sojuscsi;sojuscsi;d:\windows\system32\drivers\sojuscsi.sys [2003-09-28 5504]
S2 gupdate1ca0016106c1b22;Usługa Google Update (gupdate1ca0016106c1b22);d:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 133104]
S3 SavRoam;SAVRoam;d:\program files\Symantec AntiVirus\SavRoam.exe [2005-06-23 124608]

--- Inne Usługi/Sterowniki w Pamięci ---

*Deregistered* - EraserUtilDrvI9
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://search.bearshare.com/
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&ksport do programu Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\PC\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.pl
FF - plugin: d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu\_userdata\npgg.1.dll
FF - plugin: d:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
.
- - - - USUNIĘTO PUSTE WPISY - - - -

AddRemove-BearShare MediaBar - d:\program files\BearShare Applications\BearShare MediaBar\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-08 17:09
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ...

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ...

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------

[HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)

[HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a6,7d,1d,90,39,09,ad,46,99,fe,17,b8,16,6f,7f,0b,be,77,2e,c8,07,81,27,
3f,75,79,8f,5a,76,d4,12,5a,f4,0a,60,db,5a,2a,57,cc,ca,e9,89,35,11,a2,a6,72,\
"??"=hex:a0,87,12,9e,a4,06,2f,b5,52,62,2b,d2,0b,43,9d,7b

[HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:03,ca,b9,2d,48,91,81,3c,29,08,70,54,2c,bf,3a,61,4a,d0,87,92,99,
ed,7e,57,ba,05,a0,3b,26,14,09,29,be,d4,de,78,8d,b6,40,81,a7,af,1e,0e,ba,3e,\
"rkeysecu"=hex:94,94,3a,05,62,40,36,54,f0,6a,81,57,71,86,8d,50
.
Czas ukończenia: 2009-10-08 17:10
ComboFix-quarantined-files.txt 2009-10-08 15:10

Przed: 17 784 393 728 bajtów wolnych
Po: 17 768 587 264 bajtów wolnych

154
[/log]

Niestety po restarcie znów się to pokazało.
Nic się już więcej nie da zrobić? Nie da się tego usunąć?
Ta cisza oznacza już brak możliwości? Kurka nie wieże od 9 rano z tym walczę...w każdym bądź razie bardzo dziękuje za pomoc!

Gość
komentarz
komentarz (edytowane)

Wklej do [b]Notatnika[/b] tekst który jest na tej stronie:
http://wklej.org/id/169690/

[b]>>Plik>>Zapisz jako... >>>[/b] [b]CFScript[/b]
Przeciągnij i upuść plik [b]CFScript.txt[/b] na plik [b]ComboFix.exe[/b]
[color="blue"]-->[/color][url="http://imageshack.us"][img]http://img228.imageshack.us/img228/5796/cfscriptb5b4me3.gif[/img][/url]
Ma się rozpocząć usuwanie. (i powstanie log).Daj ten log, który powstanie w trakcie usuwania.
Jeśli pójdzie dobrze, to: [b]Po restarcie[/b] usuń ręcznie folder [b]C:\[/b][b]Qoobox.[/b]


.

kula1576
komentarz
komentarz (edytowane)

Zrobiłem tak jak w instrukcji wyżej i oto nowy log z Combofixa:

[log]
ComboFix 09-10-10.02 - PC 2009-10-11 11:18.12.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3326.2832 [GMT 2:00]
Uruchomiony z: d:\documents and settings\PC\Pulpit\ComboFix.exe
Użyto następujących komend :: d:\documents and settings\PC\Pulpit\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

FILE ::
"d:\windows\system32\ahndoor0.dll"
"d:\windows\system32\ahndoor1.dll"
"d:\windows\system32\ahndoor2.dll"
"d:\windows\system32\ahndoor3.dll"
.

((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\vlvtdflx.exe
d:\docume~1\PC\USTAWI~1\Temp\cvasds0.dll
d:\docume~1\PC\USTAWI~1\Temp\cvasds1.dll
D:\vlvtdflx.exe
d:\windows\AhnRpta.exe
d:\windows\system32\ahndoor0.dll
E:\vlvtdflx.exe
F:\vlvtdflx.exe
G:\vlvtdflx.exe
H:\vlvtdflx.exe

.
((((((((((((((((((((((((( Pliki utworzone od 2009-09-11 do 2009-10-11 )))))))))))))))))))))))))))))))
.

2009-10-08 13:38 . 2009-10-08 13:38 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Malwarebytes
2009-10-08 13:38 . 2009-10-08 13:38 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Malwarebytes
2009-10-08 12:48 . 2009-10-08 12:48 -------- d-----w- d:\program files\trend micro
2009-10-07 07:30 . 2009-10-07 07:30 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\0148
2009-10-06 11:37 . 2009-10-06 11:37 -------- d-----w- d:\documents and settings\PC\Ustawienia lokalne\Dane aplikacji\Symantec
2009-10-06 11:36 . 2005-05-13 17:50 91856 ----a-w- d:\windows\system32\S32EVNT1.DLL
2009-10-06 11:36 . 2005-05-13 17:50 123488 ----a-w- d:\windows\system32\drivers\SYMEVENT.SYS
2009-10-06 11:36 . 2009-10-06 11:36 -------- d-----w- d:\program files\Symantec
2009-10-06 11:36 . 2009-10-11 09:20 -------- d-----w- d:\program files\Symantec AntiVirus
2009-10-06 11:34 . 2009-10-06 11:34 -------- d-----w- d:\program files\antywirus
2009-10-04 16:05 . 2009-10-04 16:05 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\2K Sports
2009-09-30 19:55 . 2009-09-30 19:55 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Sports Interactive
2009-09-30 19:53 . 2009-09-30 19:53 -------- d--h--w- d:\program files\Zero G Registry
2009-09-30 19:52 . 2009-09-30 19:52 -------- d--h--w- d:\documents and settings\PC\InstallAnywhere

.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 13:22 . 2009-06-19 12:07 -------- d-----w- d:\program files\BearShare Applications
2009-10-08 10:51 . 2001-10-26 17:15 49712 ----a-w- d:\windows\system32\perfc015.dat
2009-10-08 10:51 . 2001-10-26 17:15 355830 ----a-w- d:\windows\system32\perfh015.dat
2009-10-06 12:37 . 2009-06-20 09:52 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\uTorrent
2009-10-06 12:11 . 2009-06-09 11:56 -------- d-----w- d:\program files\Common Files\Symantec Shared
2009-10-06 11:36 . 2009-06-09 12:01 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Symantec
2009-09-15 20:22 . 2009-06-09 14:36 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu
2009-09-08 16:55 . 2009-06-09 13:36 -------- d-----w- d:\program files\AGEIA Technologies
2009-09-05 21:05 . 2009-06-14 18:23 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\BESTplayer
2009-09-04 09:07 . 2009-06-09 14:36 -------- d-----w- d:\program files\Nowe Gadu-Gadu
2009-08-28 12:56 . 2009-08-28 12:56 -------- d-----w- d:\program files\Half-Life Model Viewer
2009-08-22 21:49 . 2009-06-09 13:03 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Test Drive Unlimited
2009-07-27 17:27 . 2009-06-09 11:58 107888 ----a-w- d:\windows\system32\CmdLineExt.dll
.

((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"SunJavaUpdateSched"="d:\program files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 36975]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"ccApp"="d:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752]
"vptray"="d:\progra~1\SYMANT~1\VPTray.exe" [2005-06-23 85696]
"RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.exe [2008-05-14 16862720]
"nwiz"="nwiz.exe" - d:\windows\system32\nwiz.exe [2008-10-07 1630208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Talisman.lnk]
path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Talisman.lnk
backup=d:\windows\pss\Talisman.lnkStartup

[HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Yahoo! Widget Engine.lnk]
path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Yahoo! Widget Engine.lnk
backup=d:\windows\pss\Yahoo! Widget Engine.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"g:\\Gry\\Test Drive Unlimited\\TestDriveUnlimited.exe"=
"d:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"g:\\Gry\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"d:\\Program Files\\Ares\\Ares.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"d:\\Program Files\\Ares\\chatServer.exe"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"g:\\Gry\\Stronghold 2\\Stronghold2.exe"=
"g:\\Gry\\PES09\\pes2009.exe"=
"g:\\Gry\\Q U A K E II\\r1q2.exe"=
"g:\\Gry\\Valve\\SteamApps\\kula_1576\\counter-strike\\hl.exe"=
"g:\\Gry\\Fotbal Menager 2008\\fm.exe"=

R0 sojubus;sojubus;d:\windows\system32\drivers\sojubus.sys [2003-10-05 123520]
R0 sojuscsi;sojuscsi;d:\windows\system32\drivers\sojuscsi.sys [2003-09-28 5504]
S2 gupdate1ca0016106c1b22;Usługa Google Update (gupdate1ca0016106c1b22);d:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 133104]
S3 SavRoam;SAVRoam;d:\program files\Symantec AntiVirus\SavRoam.exe [2005-06-23 124608]

--- Inne Usługi/Sterowniki w Pamięci ---

*Deregistered* - EraserUtilDrvI9
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://search.bearshare.com/
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&ksport do programu Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\PC\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.pl
FF - plugin: d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu\_userdata\npgg.1.dll
FF - plugin: d:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-11 11:21
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ...

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ...

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------

[HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)

[HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a6,7d,1d,90,39,09,ad,46,99,fe,17,b8,16,6f,7f,0b,be,77,2e,c8,07,81,27,
3f,75,79,8f,5a,76,d4,12,5a,f4,0a,60,db,5a,2a,57,cc,ca,e9,89,35,11,a2,a6,72,\
"??"=hex:a0,87,12,9e,a4,06,2f,b5,52,62,2b,d2,0b,43,9d,7b

[HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:03,ca,b9,2d,48,91,81,3c,29,08,70,54,2c,bf,3a,61,4a,d0,87,92,99,
ed,7e,57,ba,05,a0,3b,26,14,09,29,be,d4,de,78,8d,b6,40,81,a7,af,1e,0e,ba,3e,\
"rkeysecu"=hex:94,94,3a,05,62,40,36,54,f0,6a,81,57,71,86,8d,50
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
d:\program files\Common Files\Symantec Shared\ccSetMgr.exe
d:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
d:\program files\Symantec AntiVirus\DefWatch.exe
d:\windows\system32\nvsvc32.exe
d:\windows\system32\PnkBstrA.exe
d:\windows\system32\rundll32.exe
d:\windows\system32\PnkBstrB.exe
d:\program files\Symantec AntiVirus\Rtvscan.exe
d:\windows\system32\wdfmgr.exe
d:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Czas ukończenia: 2009-10-11 11:23 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-10-11 09:22
ComboFix2.txt 2009-10-09 07:41

Przed: 17 485 537 280 bajtów wolnych
Po: 17 444 581 376 bajtów wolnych

173
[/log]

Po dodatkowym restarcie systemu zauważyłem ze proces w menadżerze który mnie tak nękał już się nie pojawił AhnRpta.exe :D wielkie dzięki za POMOC ! Jakby coś jeszcze w tym logu się znalazło to proszę o podpowiedź.

Gość
komentarz
komentarz

Jak na moje tureckie oko - jest OK.

Do poczytania/wykonania: http://www.forumpc.pl/index.php?showtopic=99378&st=0&p=695208&fromsearch=1&#entry695208


.

kula1576
komentarz
komentarz

Wielkie DZIĘKI za POMOC !:D Pozdrawiam

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.