x-kom hosting

Reset komputera, po wykryciu wirusa przez Avast

Mataj
utworzono
utworzono

Witam serdeczenie! mam taki problem. Siedziałem pewnego razu przy kompie i nagle pojawił się alarm Avasta o wirusie. Chwilę później komputer się zrestował, więc poczekałem chwilę i podczas procesu ładowania Windowsa XP komp znów się zresetował. I tak w kółko. Pojawia się tylko na chwilę niebieski ekran z jakimiś napisami. Na system udało mi się wejść przez jakiś tryb debguwania. Od razu zrobiłem skan i pousuwałem wszystkie zarażone pliki. Lecz to nic nie pomogło, nadal się resetuje przy normalnym włączaniu. Nie wiem teraz co zrobić, czy sformatować dysk i zainstalować system od nowa, czy może jest jakiś inny sposób na pozbycie się tego probelmu. Z góry dziękuję za pomoc!

Psycholandia
komentarz
komentarz

Daj loga z OTL: http://www.forumpc.pl/index.php?showtopic=104338

Mataj
komentarz
komentarz (edytowane)

[log]OTL logfile created on: 2009-10-21 19:34:01 - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = C:\Documents and Settings\Radzio\Pulpit
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 1,30 Gb Available Physical Memory | 65,07% Memory free
3,85 Gb Paging File | 2,94 Gb Available in Paging File | 76,51% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 40,00 Gb Total Space | 12,15 Gb Free Space | 30,36% Space Free | Partition Type: NTFS
Drive D: | 87,99 Gb Total Space | 54,83 Gb Free Space | 62,32% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 170,10 Gb Total Space | 135,62 Gb Free Space | 79,73% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
Drive I: | 3,82 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: RADEK
Current User Name: Radzio
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2009-10-21 19:32:53 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Radzio\Pulpit\OTL.exe
PRC - [2009-10-09 08:53:32 | 01,078,664 | ---- | M] (LogMeIn Inc.) -- D:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2009-09-15 12:56:48 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009-09-15 12:56:43 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009-09-15 12:56:28 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009-09-15 12:54:13 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009-09-15 12:49:40 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009-08-31 18:07:34 | 11,391,592 | ---- | M] (GG Network S.A.) -- C:\Program Files\Nowe Gadu-Gadu\gg.exe
PRC - [2009-08-31 16:56:26 | 00,077,824 | ---- | M] () -- C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
PRC - [2009-08-28 13:13:02 | 00,832,808 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2009-07-25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009-04-10 19:29:08 | 00,037,888 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
PRC - [2009-01-21 13:08:06 | 01,095,560 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsSvc.exe
PRC - [2009-01-07 12:40:56 | 00,348,752 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe
PRC - [2008-12-08 13:33:48 | 01,173,384 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsTray.exe
PRC - [2008-08-12 23:28:26 | 00,249,856 | ---- | M] (BL) -- C:\Program Files\lg_fwupdate\fwupdate.exe
PRC - [2008-01-29 17:38:31 | 00,583,048 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2008-01-04 00:26:00 | 00,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe
PRC - [2007-09-12 18:27:24 | 00,554,352 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
PRC - [2007-06-13 15:23:49 | 01,034,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2007-05-28 18:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2007-05-15 15:55:46 | 01,628,208 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
PRC - [2007-05-15 15:55:46 | 01,550,896 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
PRC - [2007-05-15 15:55:26 | 01,057,328 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\InCD\InCD.exe
PRC - [2007-04-19 13:35:46 | 00,075,304 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2007-04-19 13:26:52 | 00,484,904 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
PRC - [2007-03-21 16:49:20 | 16,126,464 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2007-03-11 22:34:40 | 00,049,152 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
PRC - [2007-02-12 14:50:40 | 00,020,480 | ---- | M] () -- C:\WINDOWS\FixCamera.exe
PRC - [2006-11-23 15:10:42 | 00,056,928 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2006-10-10 15:49:42 | 00,270,336 | ---- | M] () -- C:\WINDOWS\tsnp325.exe
PRC - [2006-10-10 14:11:08 | 00,827,392 | ---- | M] () -- C:\WINDOWS\vsnp325.exe
PRC - [2006-03-30 09:15:44 | 00,096,341 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2005-08-08 06:54:00 | 00,167,936 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe
PRC - [2005-04-06 16:03:28 | 00,110,592 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe

[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - File not found -- -- (LiveUpdate Notice Ex [Auto | Stopped])
SRV - File not found -- -- (ACDaemon [On_Demand | Stopped])
SRV - [2009-10-09 08:53:32 | 01,078,664 | ---- | M] (LogMeIn Inc.) -- D:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc [Auto | Running])
SRV - [2009-09-15 12:56:43 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009-09-15 12:56:28 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009-09-15 12:54:13 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2009-09-15 12:49:40 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2009-07-25 05:23:10 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2009-01-21 13:08:06 | 01,095,560 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService [Auto | Running])
SRV - [2009-01-07 12:40:56 | 00,348,752 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService [Auto | Running])
SRV - [2008-11-20 21:18:52 | 00,136,120 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2008-07-29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008-07-29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008-07-29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008-07-25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008-07-25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008-01-29 17:38:31 | 00,583,048 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -- (LiveUpdate Notice Service [Auto | Running])
SRV - [2008-01-04 00:26:00 | 00,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2007-10-25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
SRV - [2007-09-12 18:27:24 | 02,999,664 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate [On_Demand | Stopped])
SRV - [2007-09-12 18:27:24 | 00,554,352 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler [Auto | Running])
SRV - [2007-05-28 18:57:54 | 00,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE [Auto | Running])
SRV - [2007-05-15 15:55:46 | 01,550,896 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe -- (InCDsrv [Auto | Running])
SRV - [2007-05-08 19:47:22 | 00,271,920 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
SRV - [2007-04-19 13:35:46 | 00,075,304 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2007-04-13 21:09:56 | 00,792,112 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService [On_Demand | Stopped])
SRV - [2007-03-11 23:02:52 | 00,131,072 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc [Auto | Running])
SRV - [2007-03-11 22:24:50 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08 [On_Demand | Running])
SRV - [2006-11-08 17:35:38 | 00,053,248 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\HPZipm12.dll -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2006-11-08 17:35:36 | 00,043,520 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\System32\HPZinw12.dll -- (Net Driver HPZ12 [Auto | Running])
SRV - [2006-03-30 09:15:44 | 00,096,341 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8 [Auto | Running])
SRV - [2005-08-08 06:54:00 | 00,167,936 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe -- (RichVideo [Auto | Running])
SRV - [2005-04-06 16:03:28 | 00,110,592 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe -- (BlueSoleil Hid Service [Auto | Running])
SRV - [2004-08-04 00:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2003-07-28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2009-09-15 12:56:14 | 00,094,160 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
DRV - [2009-09-15 12:55:30 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009-09-15 12:55:19 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009-09-15 12:54:30 | 00,052,368 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2009-09-15 12:54:21 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
DRV - [2009-09-15 12:53:24 | 00,027,408 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
DRV - [2009-09-08 17:18:08 | 00,721,904 | ---- | M] (Duplex Secure Ltd.) -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Stopped])
DRV - [2009-04-24 22:47:40 | 00,033,824 | ---- | M] () -- C:\WINDOWS\System32\drivers\oreans32.sys -- (oreans32 [System | Running])
DRV - [2009-04-23 11:15:06 | 00,026,176 | -H-- | M] (LogMeIn, Inc.) -- C:\WINDOWS\System32\DRIVERS\hamachi.sys -- (hamachi [On_Demand | Running])
DRV - [2009-04-03 11:18:26 | 00,130,936 | ---- | M] (PC Tools) -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore [Boot | Running])
DRV - [2009-02-10 17:23:02 | 00,082,320 | ---- | M] (EZB Systems, Inc.) -- C:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive [System | Running])
DRV - [2008-09-17 15:14:00 | 00,027,672 | R--- | M] (EnTech Taiwan) -- C:\WINDOWS\System32\DRIVERS\ENTECH.sys -- (ENTECH [On_Demand | Stopped])
DRV - [2008-08-20 19:58:58 | 00,044,944 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2008-02-12 03:42:38 | 00,232,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Drivers\vmm.sys -- (vmm [System | Running])
DRV - [2008-02-05 01:50:44 | 00,059,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\VMNetSrv.sys -- (VPCNetS2 [On_Demand | Running])
DRV - [2008-01-04 00:26:00 | 07,077,344 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2007-11-13 12:25:55 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [Auto | Running])
DRV - [2007-05-15 15:55:36 | 00,118,576 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDFs.sys -- (InCDfs [Disabled | Running])
DRV - [2007-05-15 15:55:36 | 00,038,576 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDRm.sys -- (incdrm [System | Running])
DRV - [2007-05-15 15:55:36 | 00,037,040 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDPass.sys -- (InCDPass [System | Running])
DRV - [2007-04-03 13:55:26 | 10,251,904 | ---- | M] (Sonix Co. Ltd.) -- C:\WINDOWS\System32\DRIVERS\snp325.sys -- (SNP325 [On_Demand | Running])
DRV - [2007-03-26 21:21:06 | 04,395,008 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2007-03-24 13:20:24 | 00,046,208 | R--- | M] (JMicron Technology Corp.) -- C:\WINDOWS\system32\DRIVERS\jraid.sys -- (JRAID [Boot | Running])
DRV - [2007-03-15 16:12:02 | 00,038,656 | R--- | M] (Attansic Technology corporation.) -- C:\WINDOWS\System32\DRIVERS\atl01_xp.sys -- (AtcL001 [On_Demand | Running])
DRV - [2007-03-08 06:20:50 | 00,021,568 | R--- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys -- (HPZius12 [On_Demand | Stopped])
DRV - [2007-03-08 06:20:49 | 00,016,496 | R--- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
DRV - [2007-03-08 06:20:48 | 00,049,920 | R--- | M] (HP) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys -- (HPZid412 [On_Demand | Stopped])
DRV - [2006-07-16 16:06:16 | 00,023,040 | ---- | M] (IVT Corporation) -- C:\WINDOWS\System32\Drivers\btcusb.sys -- (Btcsrusb [On_Demand | Stopped])
DRV - [2006-06-23 16:00:26 | 00,031,488 | ---- | M] (IVT Corporation) -- C:\WINDOWS\System32\DRIVERS\blueletaudio.sys -- (BlueletAudio [On_Demand | Running])
DRV - [2006-06-14 19:12:13 | 00,078,184 | ---- | M] (Protection Technology (StarForce)) -- C:\WINDOWS\System32\drivers\sfvfs02.sys -- (sfvfs02 [Boot | Running])
DRV - [2006-06-14 18:00:34 | 00,059,264 | ---- | M] (Protection Technology (StarForce)) -- C:\WINDOWS\System32\drivers\sfsync04.sys -- (sfsync04 [Boot | Running])
DRV - [2006-06-14 17:10:38 | 00,058,232 | ---- | M] (Protection Technology (StarForce)) -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01 [Boot | Running])
DRV - [2006-06-14 16:56:56 | 00,013,680 | ---- | M] (Protection Technology (StarForce)) -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02 [Boot | Running])
DRV - [2006-04-14 09:14:12 | 00,014,312 | ---- | M] () -- C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys -- (BTNetFilter [On_Demand | Stopped])
DRV - [2006-02-28 16:57:22 | 00,084,836 | ---- | M] (IVT Corporation) -- C:\WINDOWS\System32\Drivers\VcommMgr.sys -- (VcommMgr [On_Demand | Running])
DRV - [2006-02-07 21:52:58 | 00,006,912 | R--- | M] (JMicron ) -- C:\WINDOWS\system32\DRIVERS\JGOGO.sys -- (JGOGO [Boot | Running])
DRV - [2006-01-19 13:31:34 | 00,010,068 | ---- | M] (IVT Corporation) -- C:\WINDOWS\System32\DRIVERS\btnetdrv.sys -- (BT [On_Demand | Stopped])
DRV - [2005-08-31 10:34:52 | 00,020,480 | ---- | M] (IVT Corporation) -- C:\WINDOWS\System32\DRIVERS\BlueletSCOAudio.sys -- (BlueletSCOAudio [On_Demand | Running])
DRV - [2005-07-30 07:21:32 | 00,011,988 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\vbtenum.sys -- (BTHidEnum [On_Demand | Running])
DRV - [2005-05-01 05:50:10 | 00,028,271 | ---- | M] (IVT Corporation) -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr [Boot | Running])
DRV - [2005-01-07 17:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2004-10-19 13:37:38 | 00,061,312 | ---- | M] (IVT Corporation) -- C:\WINDOWS\System32\DRIVERS\VComm.sys -- (VComm [On_Demand | Running])
DRV - [2004-08-13 20:56:20 | 00,005,810 | R--- | M] () -- C:\WINDOWS\System32\DRIVERS\ASACPI.sys -- (MTsensor [On_Demand | Running])
DRV - [2001-08-17 23:57:36 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Drivers\RootMdm.sys -- (ROOTMODEM [On_Demand | Running])
DRV - [2001-08-17 23:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2001-08-17 21:53:42 | 00,004,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\loop.sys -- (msloop [On_Demand | Stopped])

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1123561945-706699826-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1123561945-706699826-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-1123561945-706699826-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1123561945-706699826-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKU\S-1-5-21-1123561945-706699826-725345543-1003\..\URLSearchHook: {34ea1c70-42cc-42c5-aa29-ec58b95a343e} - C:\Program Files\myBabylon\tbmyB0.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1123561945-706699826-725345543-1003\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKU\S-1-5-21-1123561945-706699826-725345543-1003\S-1-5-21-1123561945-706699826-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.0.4
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14

FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-09-03 10:21:54 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008-11-27 23:03:51 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-09-18 18:16:50 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-18 18:16:50 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: G:\Program Files\Mozilla Firefox\components [2009-08-11 16:19:22 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: G:\Program Files\Mozilla Firefox\plugins [2009-08-28 13:20:13 | 00,000,000 | ---D | M]

[2009-08-11 16:19:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\mozilla\Extensions
[2009-08-11 16:19:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-10-18 00:33:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\mozilla\Firefox\Profiles\x6brljz9.default\extensions
[2009-09-18 23:09:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\mozilla\Firefox\Profiles\x6brljz9.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2009-09-03 17:58:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\mozilla\Firefox\Profiles\x6brljz9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009-08-11 16:30:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\mozilla\Firefox\Profiles\x6brljz9.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2009-08-30 22:01:39 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-09-18 18:16:43 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-09-18 18:16:43 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-09-18 18:16:43 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-09-18 18:16:44 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009-09-03 18:06:35 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2009-09-03 18:06:35 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2009-09-03 18:06:35 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-09-03 18:06:35 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2009-09-03 18:06:35 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2009-09-03 18:06:35 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2009-09-03 18:06:35 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - No CLSID value found.
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (myBabylon English Toolbar) - {34ea1c70-42cc-42c5-aa29-ec58b95a343e} - C:\Program Files\myBabylon\tbmyB0.dll (Conduit Ltd.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\Radzio\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.)
O3 - HKLM\..\Toolbar: (myBabylon English Toolbar) - {34ea1c70-42cc-42c5-aa29-ec58b95a343e} - C:\Program Files\myBabylon\tbmyB0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKU\S-1-5-21-1123561945-706699826-725345543-1003\..\Toolbar\WebBrowser: (myBabylon English Toolbar) - {34EA1C70-42CC-42C5-AA29-EC58B95A343E} - C:\Program Files\myBabylon\tbmyB0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1123561945-706699826-725345543-1003\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: [36X Raid Configurer] C:\WINDOWS\System32\xRaidSetup.exe (JMicron Technology Corp.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe ()
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [LGODDFU] C:\Program Files\lg_fwupdate\fwupdate.exe (BL)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Onet.pl AutoUpdate] C:\Program Files\Common Files\Onet.pl\NewAutoUpdate.exe File not found
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [snp325] C:\WINDOWS\vsnp325.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [tsnp325] C:\WINDOWS\tsnp325.exe ()
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKU\S-1-5-21-1123561945-706699826-725345543-1003..\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe ()
O4 - HKU\S-1-5-21-1123561945-706699826-725345543-1003..\Run: [AQQ] G:\PROGRA~1\WapSter\WAPSTE~1\AQQ.exe File not found
O4 - HKU\S-1-5-21-1123561945-706699826-725345543-1003..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe File not found
O4 - HKU\S-1-5-21-1123561945-706699826-725345543-1003..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
O4 - HKU\S-1-5-21-1123561945-706699826-725345543-1003..\Run: [MsnMsgr] C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1123561945-706699826-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Kolekcja wycinków HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Zaznaczanie HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\PrxerNsp.dll ( )
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\PrxerDrv.dll (Initex Software)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\ESPI11.dll (DYWT)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\ESPI11.dll (DYWT)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\PrxerDrv.dll (Initex Software)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1123561945-706699826-725345543-1003\..Trusted Domains: ([]msn in Mój komputer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} http://download.gamedesire.com/g_bin/pl/billard8_2_0_0_35.cab (GameDesire Pool 8)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 192.168.108.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-08-01 22:08:52 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[3 C:\WINDOWS\*.tmp files]
[2009-10-21 11:24:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Tools
[2009-10-03 12:22:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Radzio\Dane aplikacji\BITS
[2009-10-21 11:24:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Radzio\Dane aplikacji\PC Tools
[2009-10-07 17:52:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Radzio\Ustawienia lokalne\Dane aplikacji\LogMeIn Hamachi
[2009-10-21 11:24:37 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2009-10-21 11:24:30 | 00,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2009-10-21 19:32:48 | 00,521,216 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Radzio\Pulpit\OTL.exe
[2009-10-21 11:25:06 | 00,159,600 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctgntdi.sys
[2009-10-21 11:24:43 | 00,130,936 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTCore.sys
[2009-10-21 11:24:43 | 00,073,840 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2009-10-21 11:24:37 | 00,064,392 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\pctplsg.sys
[2009-10-20 20:32:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009-10-12 09:41:34 | 00,026,176 | -H-- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\hamachi.sys
[2009-10-04 14:03:19 | 00,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\loop.sys
[2009-10-04 14:03:19 | 00,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\loop.sys
[2009-08-11 23:23:22 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\PrxerNsp.dll
[2008-08-18 15:11:02 | 00,147,456 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp325.dll
[2008-08-18 15:11:02 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpx32.dll
[2008-08-18 15:07:42 | 00,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnp325.dll
[2008-08-18 15:07:42 | 00,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp325.dll

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[5 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009-10-21 19:32:53 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Radzio\Pulpit\OTL.exe
[2009-10-21 18:23:12 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2009-10-21 18:22:53 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-10-21 18:22:45 | 00,000,359 | ---- | M] () -- C:\WINDOWS\lgfwup.ini
[2009-10-21 18:22:42 | 00,160,503 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009-10-21 18:22:32 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-10-21 17:41:48 | 00,002,259 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2009-10-21 17:34:41 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-10-21 12:10:17 | 00,002,539 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\Microsoft Office Word 2003.lnk
[2009-10-21 11:24:40 | 00,001,655 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Spyware Doctor.lnk
[2009-10-20 12:49:52 | 02,642,830 | -H-- | M] () -- C:\Documents and Settings\Radzio\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-10-19 21:08:37 | 00,001,030 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-10-17 17:00:30 | 00,049,664 | ---- | M] () -- C:\Documents and Settings\Radzio\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-10-17 12:53:00 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009-10-17 00:46:05 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-10-16 22:25:16 | 00,230,424 | ---- | M] () -- C:\img2-001.raw
[2009-10-16 19:29:13 | 00,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-10-16 19:27:47 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2009-10-16 19:27:47 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2009-10-16 14:27:06 | 00,387,072 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\Wstęp do prawoznawstwa.doc
[2009-10-16 14:26:06 | 00,365,568 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\Wstep_do_nauki_o_panstwie_i_prawie.doc
[2009-10-15 18:39:49 | 03,724,884 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\sean kingston - fire burning on the dance floor.mp31255624519_[mp3.teledyski.info].mp3
[2009-10-15 17:38:59 | 01,055,718 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-10-15 17:38:59 | 00,495,520 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2009-10-15 17:38:59 | 00,436,070 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-10-15 17:38:59 | 00,085,852 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2009-10-15 17:38:59 | 00,068,966 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-10-14 18:30:10 | 03,491,245 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\stahu stah - jestes moja kokain.mp31255537631_[mp3.teledyski.info].mp3
[2009-10-11 15:58:22 | 03,366,274 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\tinchy stryder feat. n-dubz - number 1.mp31255269251_[mp3.teledyski.info].mp3
[2009-10-03 11:36:44 | 00,160,408 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\Art-024-Virus_by_JavierZhX.jpg
[2009-10-02 20:01:57 | 25,198,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009-10-01 23:00:38 | 03,866,154 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\ewa farna - dmuchawce, latawce, wiatr.mp31254432496_[mp3.teledyski.info].mp3
[2009-09-27 18:12:06 | 03,628,335 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\beyonce - single ladies (dave aude radio edit).mp31254067670_[mp3.teledyski.info].mp3
[2009-09-27 18:08:07 | 03,337,435 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\kristina debarge - goodbye.mp31254067914_[mp3.teledyski.info].mp3
[2009-09-27 18:07:13 | 04,833,311 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\green day - 21 guns.mp31254067789_[mp3.teledyski.info].mp3
[2009-09-27 18:03:29 | 03,897,083 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\david guetta ft akon - sexy bitch.mp31254067055_[mp3.teledyski.info].mp3
[2009-09-27 18:02:38 | 03,268,053 | ---- | M] () -- C:\Documents and Settings\Radzio\Pulpit\pink - funhouse.mp31254068938_[mp3.teledyski.info].mp3
[2009-09-25 19:48:13 | 00,002,645 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009-09-25 07:58:06 | 00,664,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wininet.dll
[2009-09-25 07:58:06 | 00,664,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
[2009-09-25 07:58:06 | 00,625,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\urlmon.dll
[2009-09-25 07:58:06 | 00,625,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll
[2009-09-25 07:58:06 | 00,473,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\shlwapi.dll
[2009-09-25 07:58:06 | 00,473,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shlwapi.dll
[2009-09-25 07:58:05 | 01,506,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\shdocvw.dll
[2009-09-25 07:58:05 | 01,506,304 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shdocvw.dll
[2009-09-25 07:58:05 | 00,532,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mstime.dll
[2009-09-25 07:58:05 | 00,532,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
[2009-09-25 07:58:05 | 00,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msrating.dll
[2009-09-25 07:58:05 | 00,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msrating.dll
[2009-09-25 07:58:05 | 00,039,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\pngfilt.dll
[2009-09-25 07:58:05 | 00,039,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009-09-25 07:58:04 | 03,084,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll
[2009-09-25 07:58:04 | 03,084,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2009-09-25 07:58:04 | 00,449,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtmled.dll
[2009-09-25 07:58:04 | 00,449,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009-09-25 07:58:03 | 01,055,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\danim.dll
[2009-09-25 07:58:03 | 01,055,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\danim.dll
[2009-09-25 07:58:03 | 00,357,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dxtmsft.dll
[2009-09-25 07:58:03 | 00,357,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009-09-25 07:58:03 | 00,251,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iepeers.dll
[2009-09-25 07:58:03 | 00,251,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll
[2009-09-25 07:58:03 | 00,205,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dxtrans.dll
[2009-09-25 07:58:03 | 00,205,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009-09-25 07:58:03 | 00,096,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inseng.dll
[2009-09-25 07:58:03 | 00,096,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inseng.dll
[2009-09-25 07:58:03 | 00,081,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieencode.dll
[2009-09-25 07:58:03 | 00,081,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieencode.dll
[2009-09-25 07:58:03 | 00,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\extmgr.dll
[2009-09-25 07:58:03 | 00,055,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\extmgr.dll
[2009-09-25 07:58:03 | 00,016,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll
[2009-09-25 07:58:03 | 00,016,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009-09-25 07:58:02 | 01,023,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\browseui.dll
[2009-09-25 07:58:02 | 01,023,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\browseui.dll
[2009-09-25 07:58:02 | 00,151,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cdfview.dll
[2009-09-25 07:58:02 | 00,151,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\cdfview.dll
[2009-09-25 07:45:02 | 00,370,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\html.iec
[2009-09-23 10:41:58 | 00,026,176 | -H-- | M] (LogMeIn, Inc.) -- C:\WINDOWS\System32\hamachi.sys

[color=#E56717]========== Files - No Company Name ==========[/color]
[2009-10-21 11:24:40 | 00,001,655 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Spyware Doctor.lnk
[2009-10-17 21:51:21 | 03,700,223 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\Afromental - Radio Song.mp3
[2009-10-16 19:27:47 | 00,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2009-10-16 19:27:47 | 00,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2009-10-16 14:27:04 | 00,387,072 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\Wstęp do prawoznawstwa.doc
[2009-10-16 14:26:05 | 00,365,568 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\Wstep_do_nauki_o_panstwie_i_prawie.doc
[2009-10-15 18:36:44 | 03,724,884 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\sean kingston - fire burning on the dance floor.mp31255624519_[mp3.teledyski.info].mp3
[2009-10-14 18:27:18 | 03,491,245 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\stahu stah - jestes moja kokain.mp31255537631_[mp3.teledyski.info].mp3
[2009-10-11 15:55:35 | 03,366,274 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\tinchy stryder feat. n-dubz - number 1.mp31255269251_[mp3.teledyski.info].mp3
[2009-10-04 21:07:43 | 01,073,152 | ---- | C] () -- C:\WINDOWS\System32\libmysql_c.dll
[2009-10-03 11:36:44 | 00,160,408 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\Art-024-Virus_by_JavierZhX.jpg
[2009-10-01 22:57:21 | 03,866,154 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\ewa farna - dmuchawce, latawce, wiatr.mp31254432496_[mp3.teledyski.info].mp3
[2009-09-27 18:09:06 | 03,628,335 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\beyonce - single ladies (dave aude radio edit).mp31254067670_[mp3.teledyski.info].mp3
[2009-09-27 18:05:17 | 03,337,435 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\kristina debarge - goodbye.mp31254067914_[mp3.teledyski.info].mp3
[2009-09-27 18:03:13 | 04,833,311 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\green day - 21 guns.mp31254067789_[mp3.teledyski.info].mp3
[2009-09-27 17:59:55 | 03,897,083 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\david guetta ft akon - sexy bitch.mp31254067055_[mp3.teledyski.info].mp3
[2009-09-27 17:59:11 | 03,268,053 | ---- | C] () -- C:\Documents and Settings\Radzio\Pulpit\pink - funhouse.mp31254068938_[mp3.teledyski.info].mp3
[2009-09-20 00:32:57 | 00,000,203 | ---- | C] () -- C:\WINDOWS\GSdx9 sse2.INI
[2009-09-19 18:07:27 | 00,001,563 | ---- | C] () -- C:\WINDOWS\kaillera.ini
[2009-08-11 23:23:24 | 00,000,723 | ---- | C] () -- C:\Documents and Settings\Radzio\Dane aplikacji\Current.prx
[2009-08-07 22:13:23 | 01,052,928 | ---- | C] () -- C:\WINDOWS\System32\drivers\CAMTHWDM.sys
[2009-06-19 17:44:31 | 00,000,148 | ---- | C] () -- C:\WINDOWS\w5win.ini
[2009-05-13 17:31:15 | 01,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll
[2009-04-24 22:47:40 | 00,033,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\oreans32.sys
[2009-01-19 21:29:27 | 00,001,233 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log
[2008-12-06 21:21:48 | 00,000,016 | RH-- | C] () -- C:\Documents and Settings\Radzio\Ustawienia lokalne\Dane aplikacji\3C1BB30.ini
[2008-10-17 19:34:05 | 00,002,516 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2008-10-17 19:34:05 | 00,000,008 | RHS- | C] () -- C:\WINDOWS\System32\7B6AF19C02.sys
[2008-09-08 16:56:09 | 00,000,020 | ---- | C] () -- C:\WINDOWS\naglos.INI
[2008-09-08 16:39:51 | 00,000,025 | ---- | C] () -- C:\WINDOWS\OverlayXP.ini
[2008-08-18 15:11:03 | 00,015,498 | ---- | C] () -- C:\WINDOWS\snp325.ini
[2008-08-12 20:49:04 | 00,008,316 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\LUUnInstall.LiveUpdate
[2008-08-07 19:12:17 | 00,000,192 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008-08-05 19:36:54 | 00,000,528 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-08-02 19:13:11 | 00,049,664 | ---- | C] () -- C:\Documents and Settings\Radzio\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008-08-02 12:02:51 | 00,015,435 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2008-08-02 11:43:51 | 00,000,359 | ---- | C] () -- C:\WINDOWS\lgfwup.ini
[2008-08-02 00:04:33 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
[2008-08-01 23:50:17 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-08-01 22:51:30 | 00,013,263 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008-08-01 22:51:30 | 00,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2008-08-01 22:51:21 | 00,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008-08-01 22:49:53 | 00,051,112 | ---- | C] () -- C:\Documents and Settings\Radzio\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2008-08-01 22:48:29 | 02,642,830 | -H-- | C] () -- C:\Documents and Settings\Radzio\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2008-08-01 22:13:24 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Radzio\Dane aplikacji\desktop.ini
[2008-01-04 23:58:50 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008-01-04 23:57:22 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008-01-04 23:57:22 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008-01-04 23:56:24 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008-01-04 00:26:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008-01-04 00:26:00 | 01,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008-01-04 00:26:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008-01-04 00:26:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008-01-04 00:26:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007-07-23 09:03:32 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007-07-23 09:03:32 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007-07-23 09:03:32 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2007-07-23 09:03:30 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2006-04-14 09:14:12 | 00,014,312 | ---- | C] () -- C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2005-07-30 07:21:32 | 00,011,988 | ---- | C] () -- C:\WINDOWS\System32\drivers\vbtenum.sys
[2003-04-08 11:40:22 | 00,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001-07-22 00:16:20 | 00,001,030 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 00:15:52 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini

[color=#E56717]========== LOP Check ==========[/color]

[2009-10-21 11:24:30 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji
[2008-08-01 23:06:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ahead
[2009-08-04 22:17:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ArcSoft
[2009-07-07 13:07:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Bluetooth
[2009-08-17 18:39:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CyberLink
[2009-05-29 19:37:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Electronic Arts
[2009-06-19 23:28:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla
[2008-08-02 13:39:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\LightScribe
[2008-08-02 13:40:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\MSN6
[2009-09-11 23:19:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2009-04-26 18:41:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PMB Files
[2009-10-21 18:35:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
[2009-03-28 19:58:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Trymedia
[2009-02-07 13:18:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ubisoft
[2008-09-08 16:41:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\webcamXP5
[2009-10-20 12:13:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ZoomBrowser
[2008-08-02 00:04:33 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Dane aplikacji
[2008-08-01 22:12:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji
[2008-08-01 22:12:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji
[2009-10-21 11:24:30 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji
[2008-08-17 10:35:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Ahead
[2009-07-15 21:17:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\ArcSoft
[2008-08-20 12:27:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\AutoUpdate
[2009-10-03 12:26:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\BITS
[2009-08-04 21:55:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\CamTrack
[2008-08-21 21:24:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Canon
[2008-12-01 23:20:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\com.adobe.example.desktopLara.38AD268D554B48E1BFABC2A9B9EEB21BBAA89D0F.1
[2009-08-17 18:39:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\CyberLink
[2008-09-04 21:01:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\DAEMON Tools
[2008-08-12 20:58:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Gadu-Gadu
[2008-08-12 22:22:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\GanymedeNet
[2008-09-09 21:26:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Gizmoz
[2009-08-25 18:09:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\gtk-2.0
[2009-09-12 13:16:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\ImgBurn
[2009-08-04 22:05:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\ipla
[2008-08-20 12:27:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Kamerzysta
[2009-06-03 20:50:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Leadertech
[2008-08-16 16:14:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\LimeWire
[2008-08-06 16:14:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Lionhead Studios
[2008-12-06 14:17:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\MilkShape 3D 1.x.x
[2008-09-14 16:29:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\MSN6
[2009-08-23 22:36:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Nowe Gadu-Gadu
[2008-08-22 20:47:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\ooVoo Details
[2009-07-15 22:16:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\OpenFM
[2008-08-12 21:06:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Opera
[2009-01-31 22:32:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\SecondLife
[2008-10-12 21:09:30 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\SecuROM
[2009-08-07 22:13:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Webcammax
[2008-08-13 21:30:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\Wings3D
[2009-10-20 12:13:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Radzio\Dane aplikacji\ZoomBrowser EX
[2009-10-17 12:53:00 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001-07-22 00:17:50 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009-10-21 18:22:53 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009-10-21 18:23:12 | 00,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 498 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:05EE1EEF
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:0CE7F3C9
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2
< End of report >[/code]

to jest cały tekst z pliku OTL.txt[quote][/log]

Psycholandia
komentarz
komentarz

W okienko OTL wklej poniższy skrypt i klik na Run Fix:

[code]:Processes
explorer.exe

:Files
C:\WINDOWS\System32\7B6AF19C02.sys

:Commands
[emptytemp]
[start explorer]
[Reboot][/code]

Przeskanuj komputer tym: [url="http://www.programosy.pl/program,malwarebytes-anti-malware.html"]Malware[/url] usuń wszystko co znajdzie i daj loga po kasowaniu (loga z Malware)

Mataj
komentarz
komentarz (edytowane)

[log]Malwarebytes' Anti-Malware 1.41
Wersja bazy definicji: 2775
Windows 5.1.2600 Dodatek Service Pack 2

2009-10-21 20:41:04
mbam-log-2009-10-21 (20-41-04).txt

Typ skanowania: Pełne skanowanie (C:\|D:\|G:\|)
Przeskanowane obiekty: 204549
Upłynęło: 39 minute(s), 7 second(s)

Zainfekowane procesy w pamięci: 0
Zainfekowane moduły pamięci: 0
Zainfekowane klucze rejestru: 0
Zainfekowane wartości rejestru: 0
Zainfekowane pliki rejestru: 0
Zainfekowane foldery: 0
Zainfekowane pliki: 1

Zainfekowane procesy w pamięci:
(Nie wykryto groźnych plików)

Zainfekowane moduły pamięci:
(Nie wykryto groźnych plików)

Zainfekowane klucze rejestru:
(Nie wykryto groźnych plików)

Zainfekowane wartości rejestru:
(Nie wykryto groźnych plików)

Zainfekowane pliki rejestru:
(Nie wykryto groźnych plików)

Zainfekowane foldery:
(Nie wykryto groźnych plików)

Zainfekowane pliki:
G:\FIFA09_party\fifa 09 PL\FIFA_09.DVD5.PL.4HT_Tomin_www.Download24.li_M5G\FIFA 09.DVD5.PL.4HT\FIFA 09.DVD5.PL.4HT\Crack\rld-fi9k.exe (Malware.Packer) -> Quarantined and deleted successfully.
[/log]


To jest log po przeskanowaniu Malware. Wykryło tylko to. Podczas skanowania uruchomił się alarm Avast. Wykryło jakieś wirusa w C:\windows\system 32\ spool\prtprocs\w32x86\FE.tmp (zostawiłem go w kwarantannie)
Dzisiaj mój kolega skasował wszystkie pliki, które były w kwarantannie w Avaście. Nie wiem czy dobrze zrobił. Jednym z tych plików był GHOST_~.exe

Nadal jest ten sam problem przy włączaniu komputera

Psycholandia
komentarz
komentarz

A komunikaty o wirusach nadal są wyświetlane?
Ważne co jest napisane na niebieskim ekranie, przepisz.
Wykonaj też to: http://www.forumpc.pl/index.php?showtopic=16074

Mataj
komentarz
komentarz

Nie, komunikaty nie są już wyświetlane. Zaraz napiszę to , co jest na niebieskim ekranie.

Psycholandia
komentarz
komentarz

Napisz co na niebieskim ekranie i wykonaj polecenia z linka.

Mataj
komentarz
komentarz (edytowane)

Minidump :
[log]*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000007E, {c0000005, 88e8101a, bacf6ecc, bacf6bc8}

Probably caused by : atapi.sys ( atapi!AtapiTaskRegisterSnapshot+48 )

Followup: MachineOwner
---------[/log]




Tekst z niebieskiego :
na poczatku jest "Pojawienie się prolemuu blablbla.." to już chyba wiesz potem jest

IRQL_NOT_LESS_OR_EQUAL

Potem coś znów jest napisane o pomocy itp.

apotem :

"Dane techniczne"
***STOP : 0x0000000A (0x00000000, 0x0000001c, 0x00000001, 0x804FAF04)

Psycholandia
komentarz
komentarz

-włóż płytę z Windowsem do napędu, uruchom konsolę odzyskiwania i kolejno wpisz:
wpisać polecenie [b]cd i386[/b]
wprowadzić polecenie: [b]expand ntfs.sy_ C:\Windows\System32\ntfs.sys[/b]
gdzie [b]C[/b] to litera dysku, na którym zainstalowany jest system
-Spróbuj też wyłączyć antywirusa i zobacz czy BSOD także występuje.
-Ściągnij najnowsze sterowniki do grafiki, sieci, chipsetu..
-Podkręcałeś komputer?
-ściągnij program Memtest86+ wypal na płytę, zresetuj komputer, kliknij F11 i niech się uruchomi program na noc, przetestuje pamięć ram
- start --> uruchom --> wpisz: [b]chkdsk /f[/b]
- Ntfs.sys, jest to plik sterownika, ktory pozwala systemowi na odczyty i zapisy na dyskach NTFS. Tak więc problemem może być dysk twardy. Sprawdź go programem HDTune, a logi ze smart wklej tu: http://www.forumpc.pl/index.php?showforum=144
- do poczytania: http://support.microsoft.com/kb/314063/pl

Mataj
komentarz
komentarz

Kurcze, trochę to skomplikowane... a jakbym przeinstalował system to to by coś dało?

Psycholandia
komentarz
komentarz

To jest o wiele mniej roboty niż format, a może pomóc. Jeśli wykonasz formata to pół na pół. Może pomóc, a może i nie pomóc. Jak wolisz. :)

Mataj
komentarz
komentarz (edytowane)

Aaa, ok, jutro się za to zabiorę, dzisiaj nie mam głowy do tego ;d. Dzięki ogromne za pomoc!!!

Aha i jak bym cały czas wchodził przez ten tryb debugowania to coś by się stało z kompem?

Sory za double posta, ale ten sposób nie działa.-włóż płytę z Windowsem do napędu, uruchom konsolę odzyskiwania i kolejno wpisz:
wpisać polecenie cd i386
wprowadzić polecenie: expand ntfs.sy_ C:\Windows\System32\ntfs.sys
gdzie C to litera dysku, na którym zainstalowany jest system"
mam sp 2, może dlatego?

Psycholandia
komentarz
komentarz

Możesz zainstalować SP3
wpisujesz tylko: [b]expand ntfs.sy_ C:\Windows\System32\ntfs.sys[/b]

Mataj
komentarz
komentarz

Czyli jak mam sp2 to wpisać tylko expand ntfs.sy_ C:\Windows\System32\ntfs.sys?

Psycholandia
komentarz
komentarz

obojętnie jaki masz SP masz wpisywać tylko
[b]expand ntfs.sy_ C:\Windows\System32\ntfs.sys[/b]

Mataj
komentarz
komentarz

Niestety to nie działa. Pojawia się jakiś błąd jak chce wpisac komende ;/ Więc pozostaje format tylko... :(

Sorki Andziorka, że napisałem na PW. Więc tutaj napisze to samo.
Więc wszedłem do konsoli odzyskiawnia, wpisałem komendę i 0pojawił się błąd "Odmowa dostępu"
O konsoli czytałem w internecie i piszą, że powinien pojawić się komunikat, gdzie trzeba wybrać system 1. Potem trzeba zalogować sie itp.

U mnie właśnie tego nie ma, pojawia się od razu "C:>"

Czyli pozostaje mi tylko format, czy jest jakieś wyjście jeszcze?

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.