REKLAMA

OTL.Txt

Czy 9 procesów svchost.exe to wirus? Analiza logu z OTL

Zauważyłem u kuzyna 9 procesów svchost - dla mnie to jest wirus. Dołączam log z OTL, proszę o kod do fixa.


Pobierz plik - link do postu

OTL logfile created on: 2010-02-22 13:23:23 - Run 1
OTL by OldTimer - Version 3.1.30.1 Folder = C:\Documents and Settings\Xp\Moje dokumenty\Pobieranie
Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 70,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39,06 Gb Total Space | 20,92 Gb Free Space | 53,56% Space Free | Partition Type: NTFS
Drive D: | 193,82 Gb Total Space | 85,77 Gb Free Space | 44,25% Space Free | Partition Type: NTFS
Drive E: | 6,65 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: XP-F386BBD7F08F
Current User Name: Xp
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2010-02-22 13:23:11 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Xp\Moje dokumenty\Pobieranie\OTL.exe
PRC - [2010-02-20 08:46:22 | 001,217,872 | ---- | M] (Valve Corporation) -- D:\Gry\Kamil\steam\steam.exe
PRC - [2010-02-19 10:06:55 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010-02-15 19:24:23 | 000,189,184 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe
PRC - [2010-01-12 15:36:18 | 000,075,064 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe
PRC - [2009-11-19 14:49:16 | 000,971,408 | ---- | M] (Blizzard Entertainment, Inc.) -- D:\Gry\Kamil\WOW\World of Warcraft\Repair.exe
PRC - [2008-07-01 09:02:28 | 000,468,224 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2008-07-01 09:01:04 | 001,447,168 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007-11-28 09:45:31 | 000,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2007-03-11 21:34:40 | 000,049,152 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
PRC - [2007-03-11 21:32:42 | 000,151,552 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
PRC - [2007-03-11 21:26:24 | 000,210,520 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2006-12-18 14:34:36 | 000,868,352 | R--- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2006-09-11 19:59:28 | 000,172,032 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
PRC - [2006-09-11 19:56:02 | 000,135,227 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
PRC - [2006-09-11 19:55:42 | 000,065,599 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
PRC - [2006-04-13 16:14:26 | 000,020,543 | ---- | M] (Apache Software Foundation) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
PRC - [2006-03-29 16:12:06 | 000,364,544 | ---- | M] () -- C:\Program Files\TP-LINK\TWCU\TWCU.exe
PRC - [2005-12-30 08:15:16 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe


[color=#E56717]========== Modules (SafeList) ==========[/color]

MOD - [2010-02-22 13:23:11 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Xp\Moje dokumenty\Pobieranie\OTL.exe


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2010-02-15 19:24:23 | 000,189,184 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PnkBstrB.exe -- (PnkBstrB)
SRV - [2010-01-12 15:36:18 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA)
SRV - [2009-04-06 17:35:00 | 002,743,325 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2008-07-01 09:08:00 | 000,019,200 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2008-07-01 09:02:28 | 000,468,224 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2007-11-28 09:45:31 | 000,155,716 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - [2007-06-04 22:14:50 | 000,217,088 | ---- | M] (Hewlett-Packard Co.) [On_Demand | Running] -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08)
SRV - [2007-06-04 22:14:50 | 000,131,072 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc)
SRV - [2006-11-08 16:35:38 | 000,053,248 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.dll -- (Pml Driver HPZ12)
SRV - [2006-11-08 16:35:36 | 000,043,520 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\WINDOWS\system32\HPZinw12.dll -- (Net Driver HPZ12)
SRV - [2006-09-11 19:59:28 | 000,172,032 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2006-09-11 19:56:02 | 000,135,227 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe -- (nSvcIp)
SRV - [2006-09-11 19:55:42 | 000,065,599 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe -- (nSvcLog)
SRV - [2006-04-13 16:14:26 | 000,020,543 | ---- | M] (Apache Software Foundation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe -- (ForcewareWebInterface)
SRV - [2005-12-30 08:15:16 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2010-01-11 12:13:01 | 000,021,275 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP) AEGIS Protocol (IEEE 802.1x)
DRV - [2009-04-28 21:20:06 | 000,044,944 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)
DRV - [2008-07-01 09:04:40 | 000,034,312 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2008-07-01 08:57:14 | 000,053,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\easdrv.sys -- (easdrv)
DRV - [2008-07-01 08:56:22 | 000,039,944 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2008-04-13 22:09:18 | 000,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2008-04-13 22:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007-11-28 09:45:31 | 007,429,088 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2007-03-08 05:20:50 | 000,021,568 | R--- | M] (HP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HPZius12.sys -- (HPZius12)
DRV - [2007-03-08 05:20:49 | 000,016,496 | R--- | M] (HP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HPZipr12.sys -- (HPZipr12)
DRV - [2007-03-08 05:20:48 | 000,049,920 | R--- | M] (HP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HPZid412.sys -- (HPZid412)
DRV - [2007-01-16 02:09:06 | 000,293,888 | R--- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV - [2006-09-11 12:45:38 | 000,019,968 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006-09-11 12:45:36 | 000,057,856 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006-09-11 12:45:26 | 000,110,592 | R--- | M] (NVIDIA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\nvtcp.sys -- (NVTCP)
DRV - [2006-08-21 11:24:28 | 000,105,344 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2006-08-06 23:57:30 | 000,093,952 | R--- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (AEAudio)
DRV - [2006-06-18 23:51:32 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006-03-17 10:18:58 | 000,392,960 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2006-03-02 13:00:00 | 000,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
DRV - [2005-12-21 10:16:34 | 000,470,048 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2005-02-01 16:30:00 | 000,141,246 | ---- | M] (NVIDIA Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\NVCAP.SYS -- (nvcap) nVidia WDM Video Capture (universal)
DRV - [2005-02-01 16:30:00 | 000,016,176 | ---- | M] (NVIDIA Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\NVXBAR.SYS -- (NVXBAR)
DRV - [2004-08-13 03:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKCU\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: " ProxyEnable " = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultenginename: " Winamp Search "
FF - prefs.js..browser.search.defaulturl: " http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685 & invocationType=tb50ffwinampie7 & query= "
FF - prefs.js..browser.search.selectedEngine: " Google "
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: " http://www.google.pl/ "
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.736
FF - prefs.js..extensions.enabledItems: maps@ovi.com:2.3.37.6
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
FF - prefs.js..keyword.URL: " http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685 & invocationType=tb50ffwinampab & query= "


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-02-19 21:01:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-02-19 20:09:53 | 000,000,000 | ---D | M]

[2010-01-12 13:22:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Xp\Dane aplikacji\Mozilla\Extensions
[2010-02-22 07:55:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Xp\Dane aplikacji\Mozilla\Firefox\Profiles\vj0ohcw7.default\extensions
[2010-02-19 20:09:49 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Xp\Dane aplikacji\Mozilla\Firefox\Profiles\vj0ohcw7.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010-02-16 15:02:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Xp\Dane aplikacji\Mozilla\Firefox\Profiles\vj0ohcw7.default\extensions\maps@ovi.com
[2010-02-19 20:17:27 | 000,001,250 | ---- | M] () -- C:\Documents and Settings\Xp\Dane aplikacji\Mozilla\Firefox\Profiles\vj0ohcw7.default\searchplugins\winamp-search.xml
[2010-02-22 07:55:12 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010-01-12 19:59:57 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
[2010-01-13 23:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2009-12-22 04:48:34 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2009-12-22 04:48:34 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2009-12-22 04:48:34 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2009-12-22 04:48:34 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2009-12-22 04:48:34 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2009-12-22 04:48:34 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2006-03-02 13:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\Xp\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll (GG Network S.A.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [Gainward] C:\Program Files\VDOTool\TBPanel.exe File not found
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TWCU] C:\Program Files\TP-LINK\TWCU\TWCU.exe ()
O4 - HKCU..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.)
O4 - HKCU..\Run: [Steam] d:\gry\kamil\steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: & Winamp Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O9 - Extra Button: Kolekcja wycinków HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Zaznaczanie HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Xp\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Xp\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-01-11 19:20:01 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009-10-07 22:41:59 | 000,000,024 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{77c856d0-fea2-11de-992a-806d6172696f}\Shell - " " = AutoRun
O33 - MountPoints2\{77c856d0-fea2-11de-992a-806d6172696f}\Shell\AutoRun\command - " " = F:\Setup.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- " %1 " %*
O35 - exefile [open] -- " %1 " %*

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2010-02-22 11:18:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Xp\Moje dokumenty\Aspyr
[2010-02-22 11:17:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010-02-22 10:56:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Xp\Recent
[2010-02-22 10:33:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Xp\Ustawienia lokalne\Dane aplikacji\Aspyr
[2010-02-22 08:20:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\EA Games
[2010-02-22 08:14:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Xp\Moje dokumenty\EA Games
[2010-02-19 21:02:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Xp\Ustawienia lokalne\Dane aplikacji\Winamp Toolbar
[2010-02-19 20:09:53 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp Detect
[2010-02-19 20:09:43 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp Toolbar
[2010-02-19 20:09:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar
[2010-02-19 20:08:17 | 001,858,032 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxsfs.dll
[2010-02-19 20:08:17 | 000,670,192 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\px.dll
[2010-02-19 20:08:17 | 000,551,408 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxdrv.dll
[2010-02-19 20:08:17 | 000,436,720 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxwave.dll
[2010-02-19 20:08:17 | 000,219,632 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxmas.dll
[2010-02-19 20:08:17 | 000,129,520 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxafs.dll
[2010-02-19 20:08:17 | 000,096,752 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\vxblock.dll
[2010-02-19 20:08:17 | 000,072,176 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxhpinst.exe
[2010-02-19 20:08:17 | 000,066,544 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxcpya64.exe
[2010-02-19 20:08:17 | 000,066,032 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxinsa64.exe
[2010-02-19 20:08:17 | 000,044,944 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\PxHelp20.sys
[2010-02-19 20:08:17 | 000,009,200 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdralw2k.sys
[2010-02-19 20:08:17 | 000,009,072 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys
[2010-02-19 19:33:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment
[2010-02-19 19:21:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Blizzard
[2010-02-16 15:41:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Nokia
[2010-02-16 15:39:28 | 000,091,136 | ---- | C] (Nokia) -- C:\WINDOWS\System32\nmwcdcls.dll
[2010-02-16 15:39:16 | 000,000,000 | ---D | C] -- C:\Program Files\Nokia
[2010-02-16 15:39:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nokia
[2010-02-16 15:39:10 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
[2010-02-16 15:38:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations
[2010-02-16 15:02:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Xp\Dane aplikacji\Nokia
[2010-02-16 13:55:10 | 000,014,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg2.dll
[2010-02-16 13:53:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2010-02-16 13:53:46 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2010-02-16 13:53:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2010-02-16 13:53:42 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2010-02-16 13:53:22 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2010-02-16 13:53:22 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010-02-16 13:53:22 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010-02-16 13:53:22 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010-02-16 13:53:22 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2010-02-16 13:53:22 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010-02-08 16:36:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Xp\Moje dokumenty\ORDER OF WAR
[2010-02-08 13:59:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\AGEIA
[2010-02-08 13:59:32 | 000,000,000 | ---D | C] -- C:\Program Files\AGEIA Technologies
[2010-02-08 13:59:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010-02-06 15:19:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Xp\Ustawienia lokalne\Dane aplikacji\Activision
[2010-02-04 18:31:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Xp\Moje dokumenty\METIN2
[2010-02-02 17:29:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Xp\Ustawienia lokalne\Dane aplikacji\Identities
[2010-01-30 16:05:16 | 002,743,325 | ---- | C] (INCA Internet Co., Ltd.) -- C:\WINDOWS\System32\GameMon.des
[2010-01-30 16:03:40 | 000,004,682 | ---- | C] (INCA Internet Co., Ltd.) -- C:\WINDOWS\System32\npptNT2.sys
[2010-01-30 16:03:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\INCA Shared
[2010-01-30 14:22:38 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2010-01-27 15:21:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Xp\Dane aplikacji\Media Player Classic
[2010-01-16 13:11:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\ESET
[2010-01-11 14:12:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft
[2010-01-11 11:51:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft
[2010-01-11 11:48:55 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji\Microsoft
[2010-01-11 11:48:55 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Microsoft
[5 C:\WINDOWS\*.tmp files - & gt; C:\WINDOWS\*.tmp - & gt; ]
[1 C:\WINDOWS\System32\*.tmp files - & gt; C:\WINDOWS\System32\*.tmp - & gt; ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2010-02-22 08:20:35 | 000,000,868 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\The Sims™ 2 Cztery pory roku.lnk
[2010-02-22 08:14:58 | 000,000,700 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\The Sims 2.lnk
[2010-02-22 07:38:45 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010-02-22 07:38:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-02-21 21:22:10 | 003,932,160 | -H-- | M] () -- C:\Documents and Settings\Xp\NTUSER.DAT
[2010-02-21 21:22:10 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\Xp\ntuser.ini
[2010-02-21 21:22:01 | 001,576,778 | -H-- | M] () -- C:\Documents and Settings\Xp\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2010-02-19 20:09:53 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Winamp.lnk
[2010-02-19 11:42:46 | 000,312,825 | ---- | M] () -- C:\AnalysisLog.sr0
[2010-02-18 19:36:21 | 001,298,980 | ---- | M] () -- C:\Documents and Settings\Xp\Moje dokumenty\Star Wars The Force Unleashed v1.0 Trainer.rar
[2010-02-18 18:22:46 | 000,013,104 | ---- | M] () -- C:\Documents and Settings\Xp\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2010-02-18 08:01:25 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-02-16 15:39:21 | 000,001,855 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Nokia Software Updater.lnk
[2010-02-16 14:07:53 | 000,098,256 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-02-16 13:54:13 | 001,082,590 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010-02-16 13:54:13 | 000,490,284 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2010-02-16 13:54:13 | 000,432,356 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010-02-16 13:54:13 | 000,083,660 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2010-02-16 13:54:13 | 000,067,312 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010-02-16 13:53:36 | 000,000,212 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2010-02-15 19:24:23 | 000,189,184 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr
[2010-02-15 19:24:23 | 000,189,184 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2010-02-15 18:24:58 | 000,138,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010-02-14 14:10:19 | 000,005,120 | ---- | M] () -- C:\Documents and Settings\Xp\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-02-09 08:34:55 | 001,036,742 | ---- | M] () -- C:\ohydny.wav
[2010-02-06 15:17:41 | 000,022,328 | ---- | M] () -- C:\Documents and Settings\Xp\Dane aplikacji\PnkBstrK.sys
[2010-02-06 15:17:21 | 000,682,280 | ---- | M] () -- C:\WINDOWS\System32\pbsvc.exe
[2010-01-30 14:08:15 | 000,000,924 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Kangurek Kao - Runda 2.lnk
[2010-01-26 15:43:27 | 000,000,155 | ---- | M] () -- C:\WINDOWS\winamp.ini
[5 C:\WINDOWS\*.tmp files - & gt; C:\WINDOWS\*.tmp - & gt; ]
[1 C:\WINDOWS\System32\*.tmp files - & gt; C:\WINDOWS\System32\*.tmp - & gt; ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2010-02-22 08:20:35 | 000,000,868 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\The Sims™ 2 Cztery pory roku.lnk
[2010-02-22 08:14:58 | 000,000,700 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\The Sims 2.lnk
[2010-02-19 20:09:53 | 000,000,654 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Winamp.lnk
[2010-02-18 19:35:40 | 001,298,980 | ---- | C] () -- C:\Documents and Settings\Xp\Moje dokumenty\Star Wars The Force Unleashed v1.0 Trainer.rar
[2010-02-16 15:39:21 | 000,001,855 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Nokia Software Updater.lnk
[2010-02-16 13:54:06 | 000,158,272 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat
[2010-02-16 13:53:36 | 000,000,212 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2010-02-06 13:09:38 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Xp\Dane aplikacji\PnkBstrK.sys
[2010-02-06 13:09:06 | 000,682,280 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2010-01-30 16:03:39 | 000,005,174 | ---- | C] () -- C:\WINDOWS\System32\nppt9x.vxd
[2010-01-30 14:44:43 | 001,036,742 | ---- | C] () -- C:\ohydny.wav
[2010-01-30 14:20:17 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\Xp\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-01-30 14:08:15 | 000,000,924 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Kangurek Kao - Runda 2.lnk
[2010-01-12 15:36:42 | 000,138,064 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010-01-11 14:39:41 | 000,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010-01-11 14:39:40 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010-01-11 14:39:40 | 000,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010-01-11 14:39:40 | 000,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010-01-11 14:39:39 | 000,067,584 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010-01-11 14:39:39 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010-01-11 14:38:41 | 000,000,155 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2010-01-11 12:18:48 | 000,000,795 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log
[2010-01-11 12:14:48 | 000,000,558 | ---- | C] () -- C:\WINDOWS\DFC.INI
[2010-01-11 12:13:01 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\wgapi.dll
[2010-01-11 11:56:12 | 000,000,804 | R--- | C] () -- C:\WINDOWS\System32\AsusSetup.ini
[2010-01-11 11:56:12 | 000,000,396 | R--- | C] () -- C:\WINDOWS\System32\raidmgmt.ini
[2010-01-11 11:55:44 | 000,032,834 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010-01-11 11:55:42 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2010-01-11 11:55:34 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008-10-07 09:13:30 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008-10-07 09:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008-10-07 09:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008-07-01 09:04:40 | 000,034,312 | ---- | C] () -- C:\WINDOWS\System32\drivers\epfwtdir.sys
[2007-11-28 09:45:31 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007-11-28 09:45:31 | 001,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007-11-28 09:45:31 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007-11-28 09:45:31 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007-11-28 09:45:31 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
& lt; End of report & gt;