maniek099 utworzono 12 lutego 2010 utworzono 12 lutego 2010 (edytowane) Witam, otóż mój problem polega na tym, że jakoś nigdy nie miałem potrzeby otwierać rejestru a teraz gdy postanowiłem do niego zajrzeć nie mogę go uruchomić, ani po przez Start -> Uruchom... ani przez ikonę w folderze C:/Windows. Gdy klikam to na sekundę znikają wszystkie ikony i pasek zadań, zostaje tylko tło pulpitu (ale procesy się nie przerywają, bo np. muzyka cały czas leci) i po chwili wszystko wraca ale edytor rejestru się nie uruchamia. Mój system: Windows XP Professional Edycja Specjalna by SiMiLiOn Wersja 2002 Service Pack 3 (taki mi w sklepie zainstalowali).
naekana komentarz 12 lutego 2010 komentarz 12 lutego 2010 Prawdopodobnie infekcja. Zapoznaj się proszę z tymi tematami: http://www.forumpc.pl/index.php?showtopic=72102 http://www.forumpc.pl/index.php?showtopic=104338 http://www.forumpc.pl/index.php?showtopic=121124 i wklej logi.
maniek099 komentarz 13 lutego 2010 Autor komentarz 13 lutego 2010 Więc tak, z tego co podałeś to tak: -RSIT [log]Logfile of random's system information tool 1.06 (written by random/random) Run by mx at 2010-02-13 21:32:25 Microsoft Windows XP Professional Dodatek Service Pack 3 System drive C: has 18 GB (52%) free of 34 GB Total RAM: 2046 MB (67% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:32:49, on 2010-02-13 Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\G DATA TotalCare\AVK\AVKService.exe C:\Program Files\G DATA TotalCare\AVK\AVKWCtl.exe C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe C:\Program Files\G DATA TotalCare\Firewall\GDFwSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\Program Files\G DATA TotalCare\Firewall\GDFirewallTray.exe C:\Program Files\G DATA TotalCare\AVKTray\AVKTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DNA\btdna.exe F:\p3vwxx.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Winamp\winamp.exe F:\p3vwxx.exe C:\Documents and Settings\mx\Pulpit\RSIT.exe C:\Program Files\trend micro\mx.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL (file missing) O2 - BHO: G DATA WebFilter Class - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G DATA TotalCare\Webfilter\AvkWebIE.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing) O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (file missing) O3 - Toolbar: G DATA WebFilter - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G DATA TotalCare\Webfilter\AvkWebIE.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [GEST] = O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe" O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Dane aplikacji\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [GDFirewallTray] C:\Program Files\G DATA TotalCare\Firewall\GDFirewallTray.exe O4 - HKLM\..\Run: [AVKTray] "C:\Program Files\G DATA TotalCare\AVKTray\AVKTray.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [cdoosoft] C:\DOCUME~1\mx\USTAWI~1\Temp\herss.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA') O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA LOKALNA') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA') O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA SIECIOWA') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: G DATA Firewall Tray.lnk = ? O4 - Global Startup: scvhost.exe O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{4FD1FCA2-9AB9-4B8F-A8AB-84C7007A6C9C}: NameServer = 213.241.79.37 83.238.255.76 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: winmm.dll O20 - Winlogon Notify: crypt - crypts.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: G DATA AntiVirus Proxy (AVKProxy) - G DATA Software AG - C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe O23 - Service: G DATA Scheduler (AVKService) - G DATA Software AG - C:\Program Files\G DATA TotalCare\AVK\AVKService.exe O23 - Service: Strażnik AntiVirus (AVKWCtl) - G DATA Software AG - C:\Program Files\G DATA TotalCare\AVK\AVKWCtl.exe O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - F:\Inne\Common\Database\bin\fbserver.exe O23 - Service: G DATA Tuner Service - G DATA Software - C:\Program Files\G DATA TotalCare\AVKTuner\AVKTunerService.exe O23 - Service: G DATA Personal Firewall (GDFwSvc) - G DATA Software AG - C:\Program Files\G DATA TotalCare\Firewall\GDFwSvc.exe O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe -- End of file - 9158 bytes ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0124123D-61B4-456f-AF86-78C53A0790C5}] G DATA WebFilter - C:\Program Files\G DATA TotalCare\Webfilter\AvkWebIE.dll [2007-11-07 652872] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}] BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO.dll [2006-11-29 230976] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [] {0124123D-61B4-456f-AF86-78C53A0790C5} - G DATA WebFilter - C:\Program Files\G DATA TotalCare\Webfilter\AvkWebIE.dll [2007-11-07 652872] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-02-13 16857600] "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632] "GEST"== [] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-08-02 13570048] "nwiz"=nwiz.exe /install [] "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-08-02 86016] "amd_dc_opt"=C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe [2006-06-28 106496] "SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472] "PaperPort PTD"=C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [2007-01-29 30248] "IndexSearch"=C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [2007-01-29 46632] "PPort11reminder"=C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe [2007-02-01 255528] "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648] "SpeedTouch USB Diagnostics"=C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe [2004-03-23 888832] "PCSuiteTrayApplication"=C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE [2006-06-15 229376] "GDFirewallTray"=C:\Program Files\G DATA TotalCare\Firewall\GDFirewallTray.exe [2007-10-25 1189552] "AVKTray"=C:\Program Files\G DATA TotalCare\AVKTray\AVKTray.exe [2007-11-22 598016] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360] "ALLUpdate"=C:\Program Files\ALLPlayer\ALLUpdate.exe sleep [] "BitTorrent DNA"=C:\Program Files\DNA\btdna.exe [2009-11-13 323392] "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-10 216520] "cdoosoft"=C:\DOCUME~1\mx\USTAWI~1\Temp\herss.exe [2010-02-13 91648] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe G DATA Firewall Tray.lnk - C:\Program Files\G DATA TotalCare\Firewall\GDFirewallTray.exe scvhost.exe C:\Documents and Settings\mx\Menu Start\Programy\Autostart Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLS"="winmm.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt] crypts.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-05-02 133632] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\Gadu-Gadu\gg.exe"="C:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program główny" "F:\Gry\TmNationsForever\TmForever.exe"="F:\Gry\TmNationsForever\TmForever.exe:*:Disabled:TmForever" "F:\Gry\Rag Doll Kung Fu\rag_doll_kung_fu.exe"="F:\Gry\Rag Doll Kung Fu\rag_doll_kung_fu.exe:*:Enabled:rag_doll_kung_fu" "C:\Documents and Settings\mx\Moje dokumenty\Nowe Gadu-Gadu\gg.exe"="C:\Documents and Settings\mx\Moje dokumenty\Nowe Gadu-Gadu\gg.exe:*:Enabled:Nowe Gadu-Gadu" "C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA" "C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent" "F:\Gry\Metin\metin2.bin"="F:\Gry\Metin\metin2.bin:*:Enabled:metin2" "C:\Program Files\Tlen.pl\tlen.exe"="C:\Program Files\Tlen.pl\tlen.exe:*:Enabled:Komunikator Tlen.pl" "C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client" "C:\Documents and Settings\mx\Pulpit\Pablo Commander v14 pl(dobreprogramy.pl)\Commander.exe"="C:\Documents and Settings\mx\Pulpit\Pablo Commander v14 pl(dobreprogramy.pl)\Commander.exe:*:Enabled:Commander" "F:\Gry\MotoGP URT 3\motogp.exe"="F:\Gry\MotoGP URT 3\motogp.exe:*:Disabled:motogp" "F:\Gry\NFS Carbon\NFSC.exe"="F:\Gry\NFS Carbon\NFSC.exe:*:Enabled:NFSC" "F:\Gry\Comanche 4\c4.exe"="F:\Gry\Comanche 4\c4.exe:*:Disabled:c4" "F:\Gry\CS 1.6\hl.exe"="F:\Gry\CS 1.6\hl.exe:*:Enabled:Half-Life Launcher" "F:\Gry\CS 1.6\hltv.exe"="F:\Gry\CS 1.6\hltv.exe:*:Enabled:HLTV Launcher" "F:\Gry\CS 1.6\hlds.exe"="F:\Gry\CS 1.6\hlds.exe:*:Enabled:HLDS Launcher" "E:\SETUP\DATA\CODWAWMP.EXE"="E:\SETUP\DATA\CODWAWMP.EXE:*:Enabled:Call of Duty(R): World at War Multiplayer" "F:\Gry\Call of duty 5\CD\Setup\Data\CoDWaW.exe"="F:\Gry\Call of duty 5\CD\Setup\Data\CoDWaW.exe:*:Enabled:Call of Duty(R): World at War Campaign/Coop" "F:\Gry\Counter Strike\hl.exe"="F:\Gry\Counter Strike\hl.exe:*:Enabled:Half-Life Launcher" "C:\Program Files\Tlen7\tlen7.exe"="C:\Program Files\Tlen7\tlen7.exe:*:Enabled:tlen7" "F:\Gry\Rac driver GRID\GRID.exe"="F:\Gry\Rac driver GRID\GRID.exe:*:Enabled:GRID" "C:\Documents and Settings\mx\Ustawienia lokalne\Temp\stInstall.exe"="C:\Documents and Settings\mx\Ustawienia lokalne\Temp\stInstall.exe:*:Enabled:SpeedTouch Home Install Wizard" "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype" "F:\Gry\Test Drive\TestDriveUnlimited.exe"="F:\Gry\Test Drive\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited" "F:\Gry\Test Drive\Game\TestDriveUnlimited.exe"="F:\Gry\Test Drive\Game\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited" "F:\Gry\COD4\iw3mp.exe"="F:\Gry\COD4\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)" "C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA" "C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00bd9052-aa93-11de-9373-001fd09c7eea}] shell\AutoRun\command - G:\xmor.exe shell\open\command - G:\xmor.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{497d0fa4-cc6f-11de-8e19-000e50db705c}] shell\AutoRun\command - G:\v1cbvsmq.exe shell\open\command - G:\v1cbvsmq.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4efb71ab-ce00-11dd-8d52-001fd09c7eea}] shell\AutoRun\command - F:\p3vwxx.exe shell\open\command - F:\p3vwxx.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ba0b0332-d2c0-11de-8e2c-000e50db705c}] shell\AutoRun\command - G:\f.bat shell\explore\command - G:\f.bat shell\open\command - G:\f.bat [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cfd56184-e649-11de-8e90-000e50db705c}] shell\AutoRun\command - G:\xmor.exe shell\open\command - G:\xmor.exe ======File associations====== .reg - open - "regedit.exe" "%1" ======List of files/folders created in the last 1 months====== 2010-02-13 21:32:25 ----D---- C:\rsit 2010-02-13 21:32:25 ----D---- C:\Program Files\trend micro 2010-02-13 11:53:32 ----D---- C:\Documents and Settings\mx\Dane aplikacji\Juce VST Host 2010-02-13 11:53:21 ----D---- C:\Documents and Settings\mx\Dane aplikacji\Hardcore 2010-02-12 17:49:42 ----D---- C:\Program Files\CarReplacer 2010-02-12 17:01:59 ----D---- C:\Downloads 2010-02-11 17:11:06 ----RSH---- C:\p3vwxx.exe 2010-02-09 16:25:24 ----RSH---- C:\9qqigqwf.exe 2010-02-08 21:12:16 ----D---- C:\Program Files\ASIO4ALL v2 2010-02-08 21:12:01 ----A---- C:\WINDOWS\system32\rewire.dll 2010-02-08 21:11:42 ----D---- C:\Program Files\VstPlugins 2010-02-08 21:11:41 ----D---- C:\Program Files\Outsim 2010-02-08 21:11:41 ----D---- C:\Program Files\Image-Line 2010-02-08 16:47:28 ----D---- C:\Documents and Settings\mx\Dane aplikacji\id Software 2010-02-08 16:47:24 ----A---- C:\WINDOWS\system32\pbsvc.exe 2010-02-08 16:47:22 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\id Software 2010-02-05 20:25:29 ----D---- C:\Documents and Settings\mx\Dane aplikacji\EurekaLog 2010-02-05 19:49:59 ----D---- C:\Program Files\WapSter 2010-02-04 20:17:56 ----RSH---- C:\ws.exe 2010-02-04 12:36:15 ----RSH---- C:\bveijo.exe 2010-01-30 18:09:26 ----RSH---- C:\1hqup.exe 2010-01-30 11:25:20 ----RSH---- C:\mvmdh.exe 2010-01-27 12:02:52 ----D---- C:\Program Files\Smart MP3 Converter 2010-01-25 10:15:59 ----RSH---- C:\c2e.exe 2010-01-22 18:04:58 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\wanted 2010-01-22 18:02:49 ----A---- C:\WINDOWS\system32\D3DX9_40.dll 2010-01-22 18:02:49 ----A---- C:\WINDOWS\system32\d3dx10_40.dll 2010-01-22 18:02:49 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll 2010-01-22 18:02:48 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll 2010-01-22 18:02:47 ----A---- C:\WINDOWS\system32\XAudio2_3.dll 2010-01-22 18:02:47 ----A---- C:\WINDOWS\system32\xactengine3_3.dll 2010-01-22 18:02:46 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll 2010-01-21 14:08:47 ----RSH---- C:\qkm.exe 2010-01-20 09:45:56 ----RSH---- C:\9fo3ar0j.exe 2010-01-19 10:17:34 ----RSH---- C:\sywyrl0q.exe 2010-01-17 22:35:19 ----RSH---- C:\9xf8.exe ======List of files/folders modified in the last 1 months====== 2010-02-13 21:32:43 ----D---- C:\WINDOWS\Temp 2010-02-13 21:32:25 ----RD---- C:\Program Files 2010-02-13 21:32:19 ----D---- C:\WINDOWS\Prefetch 2010-02-13 21:23:52 ----D---- C:\Documents and Settings\mx\Dane aplikacji\DNA 2010-02-13 20:53:57 ----D---- C:\Program Files\Mozilla Firefox 2010-02-13 19:57:35 ----D---- C:\WINDOWS\system32 2010-02-13 19:57:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2010-02-13 19:53:42 ----D---- C:\Program Files\DNA 2010-02-13 18:32:01 ----A---- C:\WINDOWS\SchedLgU.Txt 2010-02-13 18:31:24 ----A---- C:\WINDOWS\NeroDigital.ini 2010-02-13 16:26:02 ----D---- C:\Documents and Settings\mx\Dane aplikacji\codeblocks 2010-02-13 11:22:14 ----D---- C:\WINDOWS\system32\CatRoot2 2010-02-12 17:49:56 ----D---- C:\WINDOWS 2010-02-12 17:49:38 ----N---- C:\WINDOWS\Setup1.exe 2010-02-12 17:38:43 ----AD---- C:\Documents and Settings\All Users\Dane aplikacji\TEMP 2010-02-12 14:22:56 ----A---- C:\WINDOWS\system32\PnkBstrB.exe 2010-02-09 16:23:27 ----SHD---- C:\WINDOWS\CSC 2010-02-08 21:11:56 ----HD---- C:\WINDOWS\inf 2010-02-08 16:47:34 ----SHD---- C:\WINDOWS\Installer 2010-02-08 16:47:34 ----SHD---- C:\Config.Msi 2010-02-08 16:47:24 ----A---- C:\WINDOWS\system32\PnkBstrA.exe 2010-02-06 22:01:00 ----D---- C:\Documents and Settings\mx\Dane aplikacji\Tlen.pl 2010-01-29 17:48:51 ----A---- C:\WINDOWS\win.ini 2010-01-23 10:06:50 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Codemasters 2010-01-22 18:03:55 ----D---- C:\Program Files\Common Files\Wise Installation Wizard 2010-01-22 18:03:48 ----D---- C:\Program Files\AGEIA Technologies 2010-01-22 18:02:52 ----D---- C:\WINDOWS\system32\DirectX 2010-01-22 18:02:10 ----RSD---- C:\WINDOWS\assembly 2010-01-22 18:01:19 ----D---- C:\Program Files\OpenAL 2010-01-22 17:54:20 ----HD---- C:\Program Files\InstallShield Installation Information 2010-01-22 11:56:20 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\TrackMania 2010-01-18 10:17:38 ----A---- C:\WINDOWS\system32\H@tKeysH@@k.DLL 2010-01-15 20:13:42 ----RSH---- C:\kmj.exe ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 intelppm;Sterownik procesora Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448] R1 kbdhid;Sterownik klawiatury HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720] R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2003-09-06 51744] R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-05-23 278984] R2 GDTdiInterceptor;GDTdiInterceptor; \??\C:\WINDOWS\system32\drivers\GDTdiIcpt.sys [] R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-02-08 18048] R3 alcan5wn;SpeedTouch USB ADSL PPP Networking Driver (NDISWAN); C:\WINDOWS\system32\DRIVERS\alcan5wn.sys [2003-12-08 53600] R3 alcaudsl;SpeedTouch ADSL Modem ATM Transport; C:\WINDOWS\system32\DRIVERS\alcaudsl.sys [2003-12-08 70688] R3 AmdTools;AMD Special Tools Driver; C:\WINDOWS\system32\DRIVERS\AmdTools.sys [2006-06-27 31744] R3 Arp1394;Protokół klienta 1394 ARP; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800] R3 GDMnIcpt;GDMnIcpt; \??\C:\WINDOWS\system32\drivers\MiniIcpt.sys [] R3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys [] R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664] R3 HDAudBus;Sterownik magistrali Microsoft UAA dla High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384] R3 HidUsb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368] R3 HookCentre;HookCentre; \??\C:\WINDOWS\system32\drivers\HookCentre.sys [] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-02-14 4676096] R3 NIC1394;Sterownik sieci 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-08-02 6121856] R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-01-03 105856] R3 usbccgp;Rodzajowy sterownik nadrzędny USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128] R3 usbehci;Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208] R3 usbhub;Koncentrator z obsługą USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520] R3 usbuhci;Sterownik Miniport uniwersalnego kontrolera hosta USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608] S3 at6lz51z;at6lz51z; C:\WINDOWS\system32\drivers\at6lz51z.sys [] S3 Nokia USB Generic;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2006-05-29 8704] S3 Nokia USB Modem;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2006-05-29 13312] S3 Nokia USB Phone Parent;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2006-05-29 127488] S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\WINDOWS\system32\DRIVERS\s916bus.sys [2007-11-02 83496] S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016] S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s916mdm.sys [2007-11-02 109992] S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s916mgmt.sys [2007-11-02 103976] S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s916obex.sys [2007-11-02 100008] S3 SONYPVU1;Sterownik filtru USB Sony (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552] S3 usbprint;Klasa PRINTER USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856] S3 USBSTOR;Sterownik magazynu masowego USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368] S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-05-02 77568] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-05-02 82944] S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys [] S4 WS2IFSL;Środowisko wspomagające dostawcę usług innych niż IFS - Windows Socket 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-17 12032] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AVKProxy;G DATA AntiVirus Proxy; C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe [2007-11-08 722504] R2 AVKService;G DATA Scheduler; C:\Program Files\G DATA TotalCare\AVK\AVKService.exe [2007-11-14 423496] R2 AVKWCtl;Strażnik AntiVirus; C:\Program Files\G DATA TotalCare\AVK\AVKWCtl.exe [2007-11-14 1074760] R2 GEST Service;GEST Service for program management.; C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [2008-07-18 80392] R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120] R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-08-02 163908] R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-02-08 75064] R3 GDFwSvc;G DATA Personal Firewall; C:\Program Files\G DATA TotalCare\Firewall\GDFwSvc.exe [2007-10-24 1496648] S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-02-25 72704] S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240] S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance; F:\Inne\Common\Database\bin\fbserver.exe [2005-11-17 1527900] S3 G DATA Tuner Service;G DATA Tuner Service; C:\Program Files\G DATA TotalCare\AVKTuner\AVKTunerService.exe [2007-11-07 779848] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] S3 ServiceLayer;ServiceLayer; C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe [2006-06-05 174080] S3 WMPNetworkSvc;Usługa udostępniania w sieci programu Windows Media Player; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-12-01 918016] S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336] -----------------EOF-----------------[/log] -OTL [log]OTL logfile created on: 2010-02-13 21:35:38 - Run 1 OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\mx\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 67,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 88,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 33,20 Gb Total Space | 17,19 Gb Free Space | 51,78% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded Drive F: | 115,85 Gb Total Space | 45,02 Gb Free Space | 38,86% Space Free | Partition Type: NTFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: SPECIAL-XP Current User Name: mx Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard [color=#E56717]========== Processes (All) ==========[/color] PRC - [2010-02-13 21:34:30 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\mx\Pulpit\OTL.exe PRC - [2010-02-13 19:54:28 | 000,091,648 | RHS- | M] () -- F:\p3vwxx.exe PRC - [2010-02-13 19:54:28 | 000,091,648 | RHS- | M] () -- C:\p3vwxx.exe PRC - [2010-02-08 16:47:24 | 000,075,064 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe PRC - [2009-12-22 18:49:58 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009-11-13 09:52:49 | 000,323,392 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\DNA\btdna.exe PRC - [2009-03-09 16:50:48 | 001,433,952 | ---- | M] (Nullsoft) -- C:\Program Files\Winamp\winamp.exe PRC - [2008-08-02 12:20:00 | 000,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe PRC - [2008-07-18 11:45:10 | 000,080,392 | ---- | M] () -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe PRC - [2008-04-14 21:51:50 | 000,510,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winlogon.exe PRC - [2008-04-14 21:51:44 | 000,057,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spoolsv.exe PRC - [2008-04-14 21:51:44 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\smss.exe PRC - [2008-04-14 21:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [RPCSS] PRC - [2008-04-14 21:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETWORKSERVICE] PRC - [2008-04-14 21:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETSVCS] PRC - [2008-04-14 21:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [LOCALSERVICE] PRC - [2008-04-14 21:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [DCOMLAUNCH] PRC - [2008-04-14 21:51:40 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\services.exe PRC - [2008-04-14 21:51:40 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe PRC - [2008-04-14 21:51:24 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\lsass.exe PRC - [2008-04-14 21:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2008-04-14 21:51:12 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ctfmon.exe PRC - [2008-04-14 21:51:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\csrss.exe PRC - [2008-04-14 21:51:04 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\alg.exe PRC - [2008-02-13 07:31:34 | 016,857,600 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe PRC - [2007-11-22 12:36:32 | 000,598,016 | ---- | M] (G DATA Software) -- C:\Program Files\G DATA TotalCare\AVKTray\AVKTray.exe PRC - [2007-11-14 10:53:42 | 001,074,760 | ---- | M] (G DATA Software AG) -- C:\Program Files\G DATA TotalCare\AVK\AVKWCtl.exe PRC - [2007-11-14 03:24:36 | 000,423,496 | ---- | M] (G DATA Software AG) -- C:\Program Files\G DATA TotalCare\AVK\AVKService.exe PRC - [2007-11-08 03:22:04 | 000,722,504 | ---- | M] (G DATA Software AG) -- C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe PRC - [2007-10-25 11:09:54 | 001,189,552 | ---- | M] (G DATA Software AG) -- C:\Program Files\G DATA TotalCare\Firewall\GDFirewallTray.exe PRC - [2007-10-24 14:26:38 | 001,496,648 | ---- | M] (G DATA Software AG) -- C:\Program Files\G DATA TotalCare\Firewall\GDFwSvc.exe PRC - [2007-01-29 21:12:14 | 000,030,248 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe PRC - [2004-03-23 12:06:12 | 000,888,832 | ---- | M] (THOMSON Telecom Belgium) -- C:\Program Files\Thomson\SpeedTouch USB\dragdiag.exe PRC - [2003-06-19 22:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [color=#E56717]========== Modules (All) ==========[/color] MOD - [2010-02-13 21:34:30 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\mx\Pulpit\OTL.exe MOD - [2010-02-13 19:54:28 | 000,090,624 | RHS- | M] () -- C:\Documents and Settings\mx\Ustawienia lokalne\Temp\cvasds1.dll MOD - [2008-05-02 07:48:16 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\uxtheme.dll MOD - [2008-05-02 07:47:50 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\normaliz.dll MOD - [2008-04-14 21:51:58 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winspool.drv MOD - [2008-04-14 21:51:00 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ws2_32.dll MOD - [2008-04-14 21:51:00 | 000,019,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ws2help.dll MOD - [2008-04-14 21:50:58 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\user32.dll MOD - [2008-04-14 21:50:58 | 000,178,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winmm.dll MOD - [2008-04-14 21:50:58 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wldap32.dll MOD - [2008-04-14 21:50:58 | 000,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\srclient.dll MOD - [2008-04-14 21:50:58 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\version.dll MOD - [2008-04-14 21:50:48 | 008,489,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shell32.dll MOD - [2008-04-14 21:50:48 | 000,997,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\setupapi.dll MOD - [2008-04-14 21:50:48 | 000,474,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shlwapi.dll MOD - [2008-04-14 21:50:46 | 001,287,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ole32.dll MOD - [2008-04-14 21:50:46 | 000,584,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rpcrt4.dll MOD - [2008-04-14 21:50:46 | 000,551,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oleaut32.dll MOD - [2008-04-14 21:50:46 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\olepro32.dll MOD - [2008-04-14 21:50:46 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\samlib.dll MOD - [2008-04-14 21:50:46 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\secur32.dll MOD - [2008-04-14 21:50:46 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\psapi.dll MOD - [2008-04-14 21:50:42 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntmarta.dll MOD - [2008-04-14 21:50:40 | 000,343,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcrt.dll MOD - [2008-04-14 21:50:38 | 000,297,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MSCTF.dll MOD - [2008-04-14 21:50:36 | 001,018,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\kernel32.dll MOD - [2008-04-14 21:50:34 | 000,110,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\imm32.dll MOD - [2008-04-14 21:50:32 | 000,285,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\gdi32.dll MOD - [2008-04-14 21:50:32 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll MOD - [2008-04-14 21:50:14 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comdlg32.dll MOD - [2008-04-14 21:50:00 | 000,686,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\advapi32.dll MOD - [2008-04-14 21:49:16 | 000,714,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntdll.dll MOD - [2008-04-14 21:43:00 | 000,177,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MSCTFIME.IME MOD - [2008-04-14 21:29:10 | 001,054,208 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll MOD - [2008-03-01 15:02:29 | 000,826,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wininet.dll MOD - [2008-03-01 15:02:26 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iertutil.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2010-02-08 16:47:24 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA) SRV - [2009-02-25 19:39:48 | 000,072,704 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service) SRV - [2008-08-02 12:20:00 | 000,163,908 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc) SRV - [2008-07-18 11:45:10 | 000,080,392 | ---- | M] () [Auto | Running] -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service) SRV - [2007-11-14 10:53:42 | 001,074,760 | ---- | M] (G DATA Software AG) [Auto | Running] -- C:\Program Files\G DATA TotalCare\AVK\AVKWCtl.exe -- (AVKWCtl) SRV - [2007-11-14 03:24:36 | 000,423,496 | ---- | M] (G DATA Software AG) [Auto | Running] -- C:\Program Files\G DATA TotalCare\AVK\AVKService.exe -- (AVKService) SRV - [2007-11-08 03:22:04 | 000,722,504 | ---- | M] (G DATA Software AG) [Auto | Running] -- C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe -- (AVKProxy) SRV - [2007-11-07 10:54:24 | 000,779,848 | ---- | M] (G DATA Software) [On_Demand | Stopped] -- C:\Program Files\G DATA TotalCare\AVKTuner\AVKTunerService.exe -- (G DATA Tuner Service) SRV - [2007-10-24 14:26:38 | 001,496,648 | ---- | M] (G DATA Software AG) [On_Demand | Running] -- C:\Program Files\G DATA TotalCare\Firewall\GDFwSvc.exe -- (GDFwSvc) SRV - [2006-06-05 12:59:18 | 000,174,080 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe -- (ServiceLayer) SRV - [2005-11-17 14:18:52 | 001,527,900 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- F:\Inne\Common\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) SRV - [2004-10-22 03:24:18 | 000,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT) SRV - [2003-07-28 19:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2010-02-13 19:53:28 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\gdrv.sys -- (gdrv) DRV - [2009-11-29 15:08:55 | 000,045,768 | ---- | M] (G DATA Software AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MiniIcpt.sys -- (GDMnIcpt) DRV - [2009-11-29 15:08:54 | 000,032,072 | ---- | M] (G DATA Software AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HookCentre.sys -- (HookCentre) DRV - [2009-11-29 15:07:31 | 000,019,328 | ---- | M] (G DATA Software AG) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\GDNdisIc.sys -- (GDNdisIc) DRV - [2009-11-29 15:07:30 | 000,041,928 | ---- | M] (G DATA Software AG) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\GDTdiIcpt.sys -- (GDTdiInterceptor) DRV - [2009-05-23 09:28:43 | 000,278,984 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt) DRV - [2009-02-08 09:50:58 | 000,018,048 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt) DRV - [2008-12-22 14:41:54 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd) DRV - [2008-08-20 18:58:58 | 000,044,944 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20) DRV - [2008-08-02 12:20:00 | 006,121,856 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv) DRV - [2008-05-02 07:48:55 | 000,062,208 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\si3112.sys -- (Si3112) DRV - [2008-04-13 21:09:18 | 000,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv) DRV - [2008-04-13 21:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus) DRV - [2008-02-14 10:04:06 | 004,676,096 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2008-01-03 15:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2007-11-02 11:47:38 | 000,109,992 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s916mdm.sys -- (s916mdm) DRV - [2007-11-02 11:47:38 | 000,103,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s916mgmt.sys -- (s916mgmt) Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM) DRV - [2007-11-02 11:47:38 | 000,100,008 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s916obex.sys -- (s916obex) DRV - [2007-11-02 11:47:38 | 000,083,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s916bus.sys -- (s916bus) Sony Ericsson Device 916 driver (WDM) DRV - [2007-11-02 11:47:38 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s916mdfl.sys -- (s916mdfl) DRV - [2006-09-19 14:44:04 | 000,015,664 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV - [2006-06-27 14:24:16 | 000,031,744 | ---- | M] (AMD, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AmdTools.sys -- (AmdTools) DRV - [2006-05-29 07:26:38 | 000,127,488 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (Nokia USB Phone Parent) DRV - [2006-05-29 07:26:36 | 000,013,312 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (Nokia USB Modem) DRV - [2006-05-29 07:26:36 | 000,008,704 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (Nokia USB Generic) DRV - [2003-12-08 11:53:48 | 000,053,600 | ---- | M] (THOMSON) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcan5wn.sys -- (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) DRV - [2003-12-08 11:53:46 | 000,070,688 | ---- | M] (THOMSON) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcaudsl.sys -- (alcaudsl) DRV - [2003-09-06 14:37:22 | 000,062,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\prohlp02.sys -- (prohlp02) DRV - [2003-09-06 13:27:06 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp01.sys -- (sfhlp01) DRV - [2003-09-06 13:25:52 | 000,051,744 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\prodrv06.sys -- (prodrv06) DRV - [2003-09-06 13:22:08 | 000,006,944 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\prosync1.sys -- (prosync1) DRV - [2001-08-17 22:49:56 | 000,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink) DRV - [2001-08-17 21:56:16 | 000,007,552 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS -- (SONYPVU1) Sterownik filtru USB Sony (SONYPVU1) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-1659004503-602162358-1801674531-1003\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll (DeviceVM Inc.) IE - HKU\S-1-5-21-1659004503-602162358-1801674531-1003\..\URLSearchHook: {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL File not found IE - HKU\S-1-5-21-1659004503-602162358-1801674531-1003\S-1-5-21-1659004503-602162358-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "Ask" FF - prefs.js..browser.search.order.1: "Ask" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.onet.pl/" FF - prefs.js..keyword.URL: "http://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q=" FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-01-23 17:05:30 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-01-17 14:25:26 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009-04-21 14:22:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Mozilla\Extensions [2009-11-29 15:13:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Mozilla\Firefox\Profiles\gllsco3g.default\extensions [2009-04-01 09:14:00 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\mx\Dane aplikacji\Mozilla\Firefox\Profiles\gllsco3g.default\searchplugins\ask.xml [2008-12-21 20:33:13 | 000,001,670 | ---- | M] () -- C:\Documents and Settings\mx\Dane aplikacji\Mozilla\Firefox\Profiles\gllsco3g.default\searchplugins\dobreprogramy.xml [2009-02-08 16:10:53 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\mx\Dane aplikacji\Mozilla\Firefox\Profiles\gllsco3g.default\searchplugins\wrzuta.xml [2009-11-29 15:47:42 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2005-11-10 19:21:00 | 001,499,136 | ---- | M] (LizardTech) -- C:\Program Files\Mozilla Firefox\plugins\npdjvu.dll [2009-12-22 04:48:34 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml [2009-12-22 04:48:34 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml [2009-12-22 04:48:34 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml [2009-12-22 04:48:34 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml [2009-12-22 04:48:34 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml [2009-12-22 04:48:34 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2001-10-26 16:45:16 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (G DATA WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G DATA TotalCare\Webfilter\AvkWebIE.dll () O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll (BitComet) O3 - HKLM\..\Toolbar: (G DATA WebFilter) - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G DATA TotalCare\Webfilter\AvkWebIE.dll () O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found O3 - HKU\S-1-5-21-1659004503-602162358-1801674531-1003\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll File not found O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe () O4 - HKLM..\Run: [AVKTray] C:\Program Files\G DATA TotalCare\AVKTray\AVKTray.exe (G DATA Software) O4 - HKLM..\Run: [GDFirewallTray] C:\Program Files\G DATA TotalCare\Firewall\GDFirewallTray.exe (G DATA Software AG) O4 - HKLM..\Run: [GEST] File not found O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe (Nokia) O4 - HKLM..\Run: [PPort11reminder] C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [SpeedTouch USB Diagnostics] C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe (THOMSON Telecom Belgium) O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.) O4 - HKU\S-1-5-21-1659004503-602162358-1801674531-1003..\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe File not found O4 - HKU\S-1-5-21-1659004503-602162358-1801674531-1003..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.) O4 - HKU\S-1-5-21-1659004503-602162358-1801674531-1003..\Run: [cdoosoft] C:\Documents and Settings\mx\Ustawienia lokalne\Temp\herss.exe () O4 - HKU\S-1-5-21-1659004503-602162358-1801674531-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd) O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] File not found O4 - HKU\.DEFAULT..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.dll (Microsoft Corporation) O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-18..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.dll (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-19..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-20..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.dll (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\G DATA Firewall Tray.lnk = C:\Program Files\G DATA TotalCare\Firewall\GDFirewallTray.exe (G DATA Software AG) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\scvhost.exe () O4 - Startup: C:\Documents and Settings\mx\Menu Start\Programy\Autostart\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1659004503-602162358-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Download all links using BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O8 - Extra context menu item: Download all videos using BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O8 - Extra context menu item: Download link using &BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl/jinstall-1_4_0_03-win.cab (Java Plug-in 1.4.0_03) O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-1_4_0_03-win.cab (Java Plug-in 1.4.0_03) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-0326653716-8864680984-721376329-0658\winmap32.exe) - C:\RECYCLER\S-1-5-21-0326653716-8864680984-721376329-0658\winmap32.exe () O20 - Winlogon\Notify\crypt: DllName - crypts.dll - File not found O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\mx\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\mx\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O29 - HKLM SecurityProviders - (digeste.dll) - C:\WINDOWS\System32\digeste.dll () O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010-02-13 21:35:45 | 000,000,059 | RHS- | M] () - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2010-02-13 21:35:45 | 000,000,059 | RHS- | M] () - F:\autorun.inf -- [ NTFS ] O33 - MountPoints2\{00bd9052-aa93-11de-9373-001fd09c7eea}\Shell\AutoRun\command - "" = G:\xmor.exe -- File not found O33 - MountPoints2\{00bd9052-aa93-11de-9373-001fd09c7eea}\Shell\open\Command - "" = G:\xmor.exe -- File not found O33 - MountPoints2\{497d0fa4-cc6f-11de-8e19-000e50db705c}\Shell\AutoRun\command - "" = G:\v1cbvsmq.exe -- File not found O33 - MountPoints2\{497d0fa4-cc6f-11de-8e19-000e50db705c}\Shell\open\Command - "" = G:\v1cbvsmq.exe -- File not found O33 - MountPoints2\{4efb71ab-ce00-11dd-8d52-001fd09c7eea}\Shell\AutoRun\command - "" = F:\p3vwxx.exe -- [2010-02-13 19:54:28 | 000,091,648 | RHS- | M] () O33 - MountPoints2\{4efb71ab-ce00-11dd-8d52-001fd09c7eea}\Shell\open\Command - "" = F:\p3vwxx.exe -- [2010-02-13 19:54:28 | 000,091,648 | RHS- | M] () O33 - MountPoints2\{7b0a872a-cdff-11dd-865d-806d6172696f}\Shell\AutoRun\command - "" = C:\p3vwxx.exe -- [2010-02-13 19:54:28 | 000,091,648 | RHS- | M] () O33 - MountPoints2\{7b0a872a-cdff-11dd-865d-806d6172696f}\Shell\open\Command - "" = C:\p3vwxx.exe -- [2010-02-13 19:54:28 | 000,091,648 | RHS- | M] () O33 - MountPoints2\{ba0b0332-d2c0-11de-8e2c-000e50db705c}\Shell\AutoRun\command - "" = G:\f.bat -- File not found O33 - MountPoints2\{ba0b0332-d2c0-11de-8e2c-000e50db705c}\Shell\explore\Command - "" = G:\f.bat -- File not found O33 - MountPoints2\{ba0b0332-d2c0-11de-8e2c-000e50db705c}\Shell\open\Command - "" = G:\f.bat -- File not found O33 - MountPoints2\{cfd56184-e649-11de-8e90-000e50db705c}\Shell\AutoRun\command - "" = G:\xmor.exe -- File not found O33 - MountPoints2\{cfd56184-e649-11de-8e90-000e50db705c}\Shell\open\Command - "" = G:\xmor.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - comfile [open] -- "%1" %* O35 - exefile [open] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: Ias - C:\WINDOWS\system32\ias [2008-12-19 19:17:35 | 000,000,000 | ---D | M] NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2010-02-13 21:34:18 | 000,549,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\mx\Pulpit\OTL.exe [2010-02-13 21:32:25 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro [2010-02-13 21:32:25 | 000,000,000 | ---D | C] -- C:\rsit [2010-02-13 20:56:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Pulpit\upstreammod [2010-02-13 11:53:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Dane aplikacji\Juce VST Host [2010-02-13 11:53:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Dane aplikacji\Hardcore [2010-02-12 17:49:42 | 000,000,000 | ---D | C] -- C:\Program Files\CarReplacer [2010-02-12 17:49:38 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\temp.001 [2010-02-12 17:47:29 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\temp.000 [2010-02-12 17:01:59 | 000,000,000 | ---D | C] -- C:\Downloads [2010-02-09 18:00:01 | 000,376,320 | ---- | C] (Image-Line) -- C:\Documents and Settings\mx\Pulpit\FL.exe [2010-02-08 21:12:16 | 000,000,000 | ---D | C] -- C:\Program Files\ASIO4ALL v2 [2010-02-08 21:12:01 | 000,225,280 | ---- | C] (Propellerhead Software AB) -- C:\WINDOWS\System32\rewire.dll [2010-02-08 21:11:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Moje dokumenty\Image-Line [2010-02-08 21:11:42 | 000,000,000 | ---D | C] -- C:\Program Files\VstPlugins [2010-02-08 21:11:41 | 000,000,000 | ---D | C] -- C:\Program Files\Outsim [2010-02-08 21:11:41 | 000,000,000 | ---D | C] -- C:\Program Files\Image-Line [2010-02-08 17:31:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Ustawienia lokalne\Dane aplikacji\PunkBuster [2010-02-08 16:47:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Dane aplikacji\id Software [2010-02-08 16:47:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\id Software [2010-02-05 20:25:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Dane aplikacji\EurekaLog [2010-02-05 19:50:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\WapSter [2010-02-05 19:49:59 | 000,000,000 | ---D | C] -- C:\Program Files\WapSter [2010-01-27 12:02:52 | 000,000,000 | ---D | C] -- C:\Program Files\Smart MP3 Converter [2010-01-22 18:04:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Ustawienia lokalne\Dane aplikacji\wanted [2010-01-22 18:04:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\wanted [2010-01-22 18:03:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Pulpit\Spolszczenie.WantedWeapons.Of.Fate [2010-01-22 18:02:49 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_40.dll [2010-01-22 18:02:49 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_40.dll [2010-01-22 18:02:49 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_40.dll [2010-01-22 18:02:48 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAPOFX1_2.dll [2010-01-22 18:02:47 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_3.dll [2010-01-22 18:02:47 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_3.dll [2010-01-22 18:02:46 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_5.dll [2010-01-18 15:04:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Pulpit\peugeot allegro [2010-01-18 14:29:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mx\Pulpit\peugeot 206 sw [2009-05-22 20:00:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\ESET [2008-12-19 19:17:55 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft [2008-12-19 19:17:55 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji\Microsoft [2008-12-19 19:17:55 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft [2008-12-19 19:17:55 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Microsoft [7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2010-02-13 21:37:00 | 000,000,059 | RHS- | M] () -- C:\autorun.inf [2010-02-13 21:34:30 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\mx\Pulpit\OTL.exe [2010-02-13 21:33:45 | 010,485,760 | -H-- | M] () -- C:\Documents and Settings\mx\NTUSER.DAT [2010-02-13 21:31:49 | 000,781,909 | ---- | M] () -- C:\Documents and Settings\mx\Pulpit\RSIT.exe [2010-02-13 20:55:32 | 002,401,709 | ---- | M] () -- C:\Documents and Settings\mx\Pulpit\upstreammod.zip [2010-02-13 19:57:35 | 001,162,720 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2010-02-13 19:57:35 | 000,865,120 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010-02-13 19:57:35 | 000,480,878 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2010-02-13 19:57:35 | 000,432,834 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2010-02-13 19:57:35 | 000,329,214 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010-02-13 19:54:28 | 000,091,648 | RHS- | M] () -- C:\p3vwxx.exe [2010-02-13 19:53:41 | 000,198,612 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2010-02-13 19:53:28 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\gdrv.sys [2010-02-13 19:53:28 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010-02-13 19:53:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010-02-13 18:31:24 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2010-02-13 12:06:17 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\mx\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-02-13 10:58:18 | 000,031,174 | ---- | M] () -- C:\Documents and Settings\mx\Pulpit\kkk.torrent [2010-02-12 21:46:35 | 006,686,106 | ---- | M] () -- C:\Documents and Settings\mx\Pulpit\LieroLWSr2.exe [2010-02-12 17:49:38 | 000,253,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Setup1.exe [2010-02-12 17:49:38 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\temp.001 [2010-02-12 17:47:30 | 000,001,700 | ---- | M] () -- C:\WINDOWS\ST6UNST.000 [2010-02-12 17:47:29 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\temp.000 [2010-02-12 14:23:05 | 000,138,504 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2010-02-12 14:22:56 | 000,214,488 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr [2010-02-12 14:22:56 | 000,214,488 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.exe [2010-02-11 11:28:51 | 000,096,356 | ---- | M] () -- C:\Documents and Settings\mx\Pulpit\Mp3.m3u [2010-02-10 17:44:51 | 000,091,648 | RHS- | M] () -- C:\9qqigqwf.exe [2010-02-08 16:47:24 | 002,373,712 | ---- | M] () -- C:\WINDOWS\System32\pbsvc.exe [2010-02-08 16:47:24 | 000,075,064 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrA.exe [2010-02-08 16:21:05 | 000,091,648 | RHS- | M] () -- C:\ws.exe [2010-02-08 15:47:06 | 004,292,160 | -H-- | M] () -- C:\Documents and Settings\mx\Ustawienia lokalne\Dane aplikacji\IconCache.db [2010-02-06 11:42:19 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010-02-04 12:35:49 | 000,094,208 | RHS- | M] () -- C:\bveijo.exe [2010-01-31 16:16:44 | 000,090,624 | RHS- | M] () -- C:\1hqup.exe [2010-01-30 23:01:21 | 000,357,376 | ---- | M] () -- C:\Documents and Settings\mx\Pulpit\Nowy Dokument programu Microsoft Word.doc [2010-01-30 11:24:54 | 000,097,280 | RHS- | M] () -- C:\mvmdh.exe [2010-01-29 17:48:51 | 000,000,603 | ---- | M] () -- C:\WINDOWS\win.ini [2010-01-27 12:02:52 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\mx\Pulpit\SmartMP3Converter.lnk [2010-01-25 17:40:50 | 000,097,792 | RHS- | M] () -- C:\c2e.exe [2010-01-22 19:34:36 | 000,096,768 | RHS- | M] () -- C:\qkm.exe [2010-01-22 18:01:17 | 000,000,591 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Wanted - Weapons of Fate.lnk [2010-01-20 18:55:28 | 000,118,272 | RHS- | M] () -- C:\9fo3ar0j.exe [2010-01-20 13:22:53 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\mx\ntuser.ini [2010-01-19 10:17:07 | 000,123,392 | RHS- | M] () -- C:\sywyrl0q.exe [2010-01-18 10:17:38 | 000,020,480 | ---- | M] () -- C:\WINDOWS\System32\H@tKeysH@@k.DLL [2010-01-17 22:34:53 | 000,115,712 | RHS- | M] () -- C:\9xf8.exe [2010-01-17 14:28:56 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\mx\Pulpit\Mozilla firefox.lnk [2010-01-15 20:13:42 | 000,120,320 | RHS- | M] () -- C:\kmj.exe [7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2010-02-13 21:31:36 | 000,781,909 | ---- | C] () -- C:\Documents and Settings\mx\Pulpit\RSIT.exe [2010-02-13 20:54:55 | 002,401,709 | ---- | C] () -- C:\Documents and Settings\mx\Pulpit\upstreammod.zip [2010-02-13 10:58:17 | 000,031,174 | ---- | C] () -- C:\Documents and Settings\mx\Pulpit\kkk.torrent [2010-02-12 21:44:44 | 006,686,106 | ---- | C] () -- C:\Documents and Settings\mx\Pulpit\LieroLWSr2.exe [2010-02-12 17:47:29 | 000,001,700 | ---- | C] () -- C:\WINDOWS\ST6UNST.000 [2010-02-11 17:11:06 | 000,091,648 | RHS- | C] () -- C:\p3vwxx.exe [2010-02-09 16:25:24 | 000,091,648 | RHS- | C] () -- C:\9qqigqwf.exe [2010-02-08 18:54:10 | 000,214,488 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.xtr [2010-02-08 16:47:24 | 002,373,712 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe [2010-02-04 20:17:56 | 000,091,648 | RHS- | C] () -- C:\ws.exe [2010-02-04 12:36:15 | 000,094,208 | RHS- | C] () -- C:\bveijo.exe [2010-01-30 22:41:43 | 000,357,376 | ---- | C] () -- C:\Documents and Settings\mx\Pulpit\Nowy Dokument programu Microsoft Word.doc [2010-01-30 18:09:26 | 000,090,624 | RHS- | C] () -- C:\1hqup.exe [2010-01-30 11:25:20 | 000,097,280 | RHS- | C] () -- C:\mvmdh.exe [2010-01-27 12:02:52 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\mx\Pulpit\SmartMP3Converter.lnk [2010-01-25 10:15:59 | 000,097,792 | RHS- | C] () -- C:\c2e.exe [2010-01-22 18:01:17 | 000,000,591 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Wanted - Weapons of Fate.lnk [2010-01-21 14:08:47 | 000,096,768 | RHS- | C] () -- C:\qkm.exe [2010-01-20 09:45:56 | 000,118,272 | RHS- | C] () -- C:\9fo3ar0j.exe [2010-01-19 10:17:34 | 000,123,392 | RHS- | C] () -- C:\sywyrl0q.exe [2010-01-17 22:35:19 | 000,115,712 | RHS- | C] () -- C:\9xf8.exe [2010-01-17 14:28:56 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\mx\Pulpit\Mozilla firefox.lnk [2010-01-02 16:15:05 | 001,032,582 | ---- | C] () -- C:\WINDOWS\System32\alleg42.dll [2009-12-17 14:58:06 | 000,000,271 | ---- | C] () -- C:\WINDOWS\game.ini [2009-11-30 20:41:03 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\H@tKeysH@@k.DLL [2009-11-29 15:12:20 | 000,000,103 | ---- | C] () -- C:\WINDOWS\Backup.INI [2009-11-29 15:10:25 | 000,002,596 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Config.nt.bak [2009-11-29 15:10:25 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Autoexec.nt.bak [2009-11-29 15:10:25 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\hosts.bak [2009-11-11 16:12:22 | 008,676,883 | ---- | C] () -- C:\WINDOWS\System32\NCMedia2.dll [2009-11-07 19:00:21 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MusicMaker.INI [2009-11-07 18:29:28 | 000,000,310 | ---- | C] () -- C:\WINDOWS\BeatBox.INI [2009-11-07 17:41:50 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\mgxasio2.dll [2009-11-07 17:39:58 | 000,005,817 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini [2009-09-25 14:45:13 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\mx\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2009-07-06 19:22:40 | 000,000,541 | ---- | C] () -- C:\WINDOWS\BZII.INI [2009-03-20 18:54:37 | 000,026,038 | ---- | C] () -- C:\WINDOWS\System32\digeste.dll [2009-03-20 15:09:41 | 000,000,016 | ---- | C] () -- C:\Documents and Settings\mx\Dane aplikacji\wiaserva.log [2009-03-16 15:56:57 | 000,383,238 | ---- | C] () -- C:\WINDOWS\System32\libmp3lame-0.dll [2009-03-14 12:44:32 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll [2009-03-14 12:44:32 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll [2009-03-14 12:44:32 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll [2009-02-08 09:50:58 | 000,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys [2009-02-08 09:50:58 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys [2009-02-07 15:59:27 | 000,000,023 | ---- | C] () -- C:\WINDOWS\clofghls.dll [2009-02-07 15:43:20 | 000,000,082 | ---- | C] () -- C:\WINDOWS\mafosav.INI [2009-01-24 20:13:14 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2009-01-24 20:13:14 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini [2009-01-24 20:13:07 | 002,283,027 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll [2009-01-24 20:13:06 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2009-01-24 20:13:06 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009-01-24 20:13:06 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2009-01-24 20:13:00 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2009-01-24 20:13:00 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2009-01-03 15:25:21 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2008-12-25 19:33:15 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2008-12-25 19:33:14 | 000,036,352 | ---- | C] () -- C:\Documents and Settings\mx\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008-12-22 15:07:02 | 000,138,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2008-12-22 14:41:54 | 000,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys [2008-12-21 21:25:57 | 000,040,960 | ---- | C] () -- C:\Program Files\Uninstall_CDS.exe [2008-12-21 21:05:58 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll [2008-12-21 21:04:34 | 000,031,567 | ---- | C] () -- C:\WINDOWS\maxlink.ini [2008-12-21 21:02:38 | 000,000,404 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI [2008-12-21 21:02:38 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI [2008-12-21 19:15:20 | 000,005,606 | ---- | C] () -- C:\WINDOWS\System32\stci.dll [2008-12-21 19:14:45 | 000,041,068 | ---- | C] () -- C:\WINDOWS\System32\ActPanel.dll [2008-10-07 09:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll [2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll [2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll [2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll [2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll [2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll [2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll [2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll [2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll [2008-08-02 12:20:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2008-08-02 12:20:00 | 001,499,136 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2008-08-02 12:20:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2008-08-02 12:20:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll [2008-08-02 12:20:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll [2008-06-05 08:58:26 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll [2008-05-03 08:24:01 | 000,000,082 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini [2005-12-07 12:31:00 | 000,202,752 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll [2003-04-08 10:40:22 | 000,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI [color=#E56717]========== LOP Check ==========[/color] [2010-01-23 10:06:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Codemasters [2008-12-22 14:46:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2009-11-29 10:02:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Downloaded Installations [2009-05-19 17:18:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ESET [2009-12-05 16:08:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\G DATA [2010-02-08 16:47:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\id Software [2009-11-07 22:12:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Keronsoft [2009-11-29 15:07:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Log [2009-11-07 17:42:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\MAGIX [2009-04-14 17:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite [2008-12-21 21:04:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ScanSoft [2010-02-12 17:38:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2009-12-07 15:23:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Test Drive Unlimited [2009-04-22 18:30:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Tlen.pl [2010-01-22 11:56:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TrackMania [2010-01-22 18:04:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\wanted [2009-06-21 17:51:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\BESTplayer [2008-12-22 14:46:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\DAEMON Tools [2008-12-22 14:47:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\DAEMON Tools Lite [2008-12-22 14:46:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\DAEMON Tools Pro [2009-04-14 17:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Datalayer [2009-12-30 17:24:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Dev-Cpp [2010-02-13 21:33:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\DNA [2009-05-19 17:19:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\ESET [2010-02-05 20:25:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\EurekaLog [2008-12-21 20:57:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Gadu-Gadu [2010-02-13 11:53:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Hardcore [2010-02-08 16:47:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\id Software [2010-02-13 11:54:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Juce VST Host [2008-12-22 14:55:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Leadertech [2009-09-04 09:26:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Nokia [2009-12-12 22:38:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Nokia Multimedia Player [2009-04-24 18:13:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Nowe Gadu-Gadu [2009-02-25 19:43:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Opera [2009-04-14 17:44:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\PC Suite [2009-01-03 16:00:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\ScanSoft [2010-02-06 22:01:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mx\Dane aplikacji\Tlen.pl [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< %systemdrive%\*.* >[/color] [2009-11-19 14:43:56 | 000,114,071 | RHS- | M] () -- C:\0qw6vege.exe [2010-01-31 16:16:44 | 000,090,624 | RHS- | M] () -- C:\1hqup.exe [2010-01-11 16:02:58 | 000,122,368 | RHS- | M] () -- C:\8xcrbho6.exe [2009-11-02 15:08:11 | 000,115,127 | RHS- | M] () -- C:\9b9w3.exe [2010-01-20 18:55:28 | 000,118,272 | RHS- | M] () -- C:\9fo3ar0j.exe [2009-11-18 09:43:21 | 000,114,180 | RHS- | M] () -- C:\9g86.exe [2010-02-10 17:44:51 | 000,091,648 | RHS- | M] () -- C:\9qqigqwf.exe [2010-01-17 22:34:53 | 000,115,712 | RHS- | M] () -- C:\9xf8.exe [2009-10-30 17:18:26 | 000,113,614 | RHS- | M] () -- C:\a2g21.exe [2010-02-13 21:37:00 | 000,000,059 | RHS- | M] () -- C:\autorun.inf [2008-12-19 20:10:03 | 000,000,223 | RHS- | M] () -- C:\boot.ini [2001-07-21 23:13:54 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin [2010-02-04 12:35:49 | 000,094,208 | RHS- | M] () -- C:\bveijo.exe [2010-01-25 17:40:50 | 000,097,792 | RHS- | M] () -- C:\c2e.exe [2009-11-26 17:49:58 | 000,114,928 | RHS- | M] () -- C:\cs6phv6d.exe [2010-01-06 18:46:47 | 000,118,784 | RHS- | M] () -- C:\e9naq.exe [2009-11-10 22:37:25 | 000,112,695 | RHS- | M] () -- C:\g12g.exe [2010-01-04 11:42:27 | 000,120,320 | RHS- | M] () -- C:\h0.exe [2009-12-28 12:25:21 | 000,106,496 | RHS- | M] () -- C:\imghyva6.exe [2008-12-19 19:17:59 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2009-12-05 21:59:19 | 000,115,688 | RHS- | M] () -- C:\k8jc.exe [2010-01-15 20:13:42 | 000,120,320 | RHS- | M] () -- C:\kmj.exe [2009-12-01 16:54:04 | 000,115,905 | RHS- | M] () -- C:\mbdm.exe [2009-12-03 21:15:49 | 000,113,792 | RHS- | M] () -- C:\mbvd.exe [2008-12-19 19:17:59 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2010-01-30 11:24:54 | 000,097,280 | RHS- | M] () -- C:\mvmdh.exe [2008-04-13 21:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2008-04-13 23:02:00 | 000,251,152 | RHS- | M] () -- C:\ntldr [2010-01-12 17:18:14 | 000,121,856 | RHS- | M] () -- C:\olu392qj.exe [2009-11-15 16:41:07 | 000,116,522 | RHS- | M] () -- C:\opdux.exe [2010-02-13 19:54:28 | 000,091,648 | RHS- | M] () -- C:\p3vwxx.exe [2010-02-13 19:53:18 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys [2009-11-12 17:29:12 | 000,113,817 | RHS- | M] () -- C:\pbudsara.exe [2009-11-30 14:45:25 | 000,115,856 | RHS- | M] () -- C:\q3kku.exe [2009-11-21 20:04:46 | 000,116,030 | RHS- | M] () -- C:\q93fi6kf.exe [2010-01-22 19:34:36 | 000,096,768 | RHS- | M] () -- C:\qkm.exe [2010-02-13 21:32:50 | 000,000,180 | ---- | M] () -- C:\service.log [2009-11-04 15:46:28 | 000,114,304 | RHS- | M] () -- C:\srgo.exe [2010-01-19 10:17:07 | 000,123,392 | RHS- | M] () -- C:\sywyrl0q.exe [2009-11-07 11:22:23 | 000,115,973 | RHS- | M] () -- C:\v1cbvsmq.exe [2009-11-16 17:12:59 | 000,115,097 | RHS- | M] () -- C:\wglb9q.exe [2009-12-29 09:54:31 | 000,098,816 | RHS- | M] () -- C:\wisf1.exe [2010-02-08 16:21:05 | 000,091,648 | RHS- | M] () -- C:\ws.exe [2009-11-24 16:53:14 | 000,113,508 | RHS- | M] () -- C:\wu1n.exe [2009-12-08 13:48:30 | 000,118,048 | RHS- | M] () -- C:\xmor.exe [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 514 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:05EE1EEF @Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:8CE646EE < End of report >[/log]
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.