REKLAMA

Pulpit.rar

Jak usunąć wirusa szpiegowskiego rlvknlg.exe z systemu?

Wszystkie raporty w załączniku.


Pobierz plik - link do postu
  • Pulpit.rar
    • OTL.Txt
    • mbam-log-2010-03-23 (15-12-01).txt
    • Extras.Txt
    • DrWeb.csv


Pulpit.rar > OTL.Txt

OTL logfile created on: 2010-03-23 15:15:39 - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

511,00 Mb Total Physical Memory | 145,00 Mb Available Physical Memory | 28,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 64,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 28,50 Gb Total Space | 19,06 Gb Free Space | 66,90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SPEED2
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2010-03-23 14:28:46 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie\OTL.exe
PRC - [2010-03-23 10:38:38 | 000,035,346 | ---- | M] () -- C:\WINDOWS\system32\temp1.exe
PRC - [2010-02-21 12:59:19 | 001,217,872 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2010-01-16 04:18:19 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-12-22 00:29:54 | 001,815,168 | ---- | M] (TMRG, Inc.) -- C:\Program Files\RelevantKnowledge\rlvknlg.exe
PRC - [2009-10-28 13:44:08 | 011,539,048 | ---- | M] (GG Network S.A.) -- C:\Program Files\Nowe Gadu-Gadu\gg.exe
PRC - [2009-10-28 12:43:06 | 000,077,824 | ---- | M] () -- C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
PRC - [2008-07-22 14:25:05 | 001,528,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-07-20 07:24:30 | 000,395,716 | ---- | M] () -- C:\Program Files\Drive Space Indicator\DrvSpace.exe
PRC - [2008-07-10 03:03:34 | 000,036,352 | ---- | M] () -- C:\Program Files\winamp\winampa.exe
PRC - [2008-06-10 04:27:04 | 000,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
PRC - [2008-06-10 04:27:03 | 000,329,104 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
PRC - [2007-09-05 11:20:12 | 000,036,352 | ---- | M] (VisualTaskTips.com) -- C:\Program Files\Utilities\VisualTaskTips\VisualTaskTips.exe
PRC - [2007-05-11 02:09:48 | 001,050,120 | ---- | M] (O & O Software GmbH) -- C:\WINDOWS\system32\oodag.exe
PRC - [2007-05-11 02:08:54 | 002,512,392 | ---- | M] (O & O Software GmbH) -- C:\WINDOWS\system32\oodtray.exe
PRC - [2003-05-30 09:42:22 | 000,585,728 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
PRC - [2003-05-29 16:28:32 | 000,790,528 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
PRC - [2002-09-20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


[color=#E56717]========== Modules (SafeList) ==========[/color]

MOD - [2010-03-23 14:28:46 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie\OTL.exe
MOD - [2009-12-22 00:29:50 | 000,385,664 | ---- | M] (TMRG, Inc.) -- C:\Program Files\RelevantKnowledge\rlls.dll
MOD - [2008-04-14 21:50:40 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll
MOD - [2007-09-05 11:20:04 | 000,007,680 | ---- | M] () -- C:\Program Files\Utilities\VisualTaskTips\VttHooks.dll
MOD - [2007-03-16 22:10:44 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\RelevantKnowledge\MSVCP71.DLL
MOD - [2007-03-16 22:10:44 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\RelevantKnowledge\MSVCR71.DLL


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2007-05-11 02:09:48 | 001,050,120 | ---- | M] (O & O Software GmbH) [Auto | Running] -- C:\WINDOWS\system32\oodag.exe -- (O & O Defrag)
SRV - [2002-09-20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2008-07-07 08:40:49 | 000,056,108 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007-11-21 00:09:22 | 000,104,320 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2006-05-03 17:50:42 | 001,540,608 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2002-09-20 11:53:34 | 000,235,100 | ---- | M] (Analog Devices Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MidiSyn.sys -- (MidiSyn)
DRV - [2001-12-19 11:45:00 | 000,008,576 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Program Files\System\CPL Bonus\vcdrom.sys -- (vcdrom)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: " ProxyEnable " = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.startup.homepage: " www.wp.pl "
FF - prefs.js..extensions.enabledItems: support@predictad.com:1.11

FF - HKLM\software\mozilla\Firefox\Extensions\\support@predictad.com: C:\Program Files\AutocompletePro\support@predictad.com [2010-03-21 17:27:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-03-09 22:13:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-02-11 19:07:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.14\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010-02-11 18:08:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.14\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2010-02-11 18:17:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Extensions
[2010-02-11 18:17:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\tngbrtfo.default\extensions
[2010-03-21 21:02:01 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010-01-16 02:08:36 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2010-01-16 02:08:36 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2010-01-16 02:08:36 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2010-01-16 02:08:36 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2010-01-16 02:08:36 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2010-01-16 02:08:36 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2001-08-23 13:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [DriveSpace] C:\Program Files\Drive Space Indicator\DrvSpace.exe ()
O4 - HKLM..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe (O & O Software GmbH)
O4 - HKLM..\Run: [RelevantKnowledge] C:\program files\relevantknowledge\rlvknlg.exe (TMRG, Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\winamp\winampa.exe ()
O4 - HKCU..\Run: [VisualTaskTips] C:\Program Files\Utilities\VisualTaskTips\VisualTaskTips.exe (VisualTaskTips.com)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\Administrator\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
F3 - HKCU WinNT: Load - (C:\WINDOWS\svchost.exe) - C:\WINDOWS\svchost.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O8 - Extra context menu item: E & ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Wyślij & do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.63 62.179.1.62
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-02-11 17:56:36 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006-05-10 00:36:18 | 000,000,034 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{6ee6fbe0-172f-11df-8953-806d6172696f}\Shell - " " = AutoRun
O33 - MountPoints2\{e890b639-1736-11df-97a2-001f1f2f5fbe}\Shell - " " = AutoRun
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O & O Software GmbH)
O35 - HKLM\..comfile [open] -- " %1 " %*
O35 - HKLM\..exefile [open] -- " %1 " %*
O37 - HKLM\...com [@ = comfile] -- " %1 " %*
O37 - HKLM\...exe [@ = exefile] -- " %1 " %*

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2010-03-23 14:30:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Dane aplikacji\Malwarebytes
[2010-03-23 14:30:11 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010-03-23 14:30:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
[2010-03-23 14:30:08 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010-03-23 14:30:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010-03-22 22:59:50 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
[2010-03-22 14:15:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Pulpit\Akcje CS avi
[2010-03-22 13:34:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Dane aplikacji\DivX
[2010-03-22 13:25:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Pulpit\CS DEMA
[2010-03-22 13:08:45 | 000,000,000 | ---D | C] -- C:\Program Files\RelevantKnowledge
[2010-03-22 13:07:33 | 000,000,000 | ---D | C] -- C:\Program Files\Mp3 Knife
[2010-03-22 12:55:07 | 000,000,000 | ---D | C] -- C:\Fraps
[2010-03-22 12:34:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Moje dokumenty\Downloads
[2010-03-21 18:33:43 | 000,000,000 | ---D | C] -- C:\Program Files\VirtualDub
[2010-03-21 17:36:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Dane aplikacji\Cool Record Edit Pro
[2010-03-21 17:27:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Dane aplikacji\Free Sound Recorder
[2010-03-21 17:27:15 | 000,000,000 | ---D | C] -- C:\Program Files\AutocompletePro
[2010-03-21 17:26:59 | 000,417,792 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTTextToAudio2.dll
[2010-03-21 17:26:59 | 000,348,160 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTWMAFile2.dll
[2010-03-21 17:26:58 | 001,986,560 | ---- | C] (NCT Company Ltd.) -- C:\WINDOWS\System32\NCTAudioFile2.dll
[2010-03-21 17:26:58 | 001,212,416 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioInformation2.dll
[2010-03-21 17:26:58 | 000,880,640 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioEditor2.dll
[2010-03-21 17:26:58 | 000,835,584 | ---- | C] (NCT) -- C:\WINDOWS\System32\NCTAudioCDGrabber2.dll
[2010-03-21 17:26:58 | 000,602,112 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioTransform2.dll
[2010-03-21 17:26:58 | 000,479,232 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioVisualization2.dll
[2010-03-21 17:26:58 | 000,458,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioRecord2.dll
[2010-03-21 17:26:58 | 000,458,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\WINDOWS\System32\NCTAudioPlayer2.dll
[2010-03-21 17:26:56 | 000,000,000 | ---D | C] -- C:\Program Files\Free Sound Recorder
[2010-03-21 15:54:39 | 000,729,088 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divxdec.ax
[2010-03-21 15:54:39 | 000,684,032 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divx.dll
[2010-03-21 15:54:39 | 000,524,288 | ---- | C] (DivX Inc.) -- C:\WINDOWS\System32\DivXsm.exe
[2010-03-21 15:54:39 | 000,233,984 | ---- | C] (CoreCodec) -- C:\WINDOWS\System32\coreavcdecoder.ax
[2010-03-21 15:54:39 | 000,081,920 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\dpl100.dll
[2010-03-21 15:54:39 | 000,000,000 | ---D | C] -- C:\Program Files\Codec
[2010-03-21 15:49:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Pulpit\train avi
[2010-03-21 15:40:09 | 000,000,000 | ---D | C] -- C:\Program Files\VideoMach-4.0.4
[2010-03-21 13:01:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\VideoMach
[2010-03-14 12:38:11 | 000,000,000 | ---D | C] -- C:\Program Files\directx
[2010-03-14 12:18:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Moje dokumenty\Notesy programu OneNote
[2010-03-14 00:11:01 | 000,000,000 | ---D | C] -- C:\Program Files\ID
[2010-03-11 19:46:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Pulpit\dyplom informatyka
[2010-03-10 21:54:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Pulpit\azer
[2010-03-07 14:56:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Pulpit\Postac na sell
[2010-03-04 10:26:04 | 000,086,016 | ---- | C] (Beepa P/L) -- C:\WINDOWS\System32\frapsvid.dll
[2010-03-03 09:09:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Moje dokumenty\Eidos
[2010-03-03 09:08:28 | 000,098,304 | ---- | C] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[2010-02-11 17:56:33 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft
[2010-02-11 17:56:33 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji\Microsoft
[2010-02-11 17:56:33 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft
[2010-02-11 17:56:33 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Microsoft
[1 C:\WINDOWS\System32\*.tmp files - & gt; C:\WINDOWS\System32\*.tmp - & gt; ]
[1 C:\WINDOWS\*.tmp files - & gt; C:\WINDOWS\*.tmp - & gt; ]
[1 C:\Documents and Settings\Administrator\*.tmp files - & gt; C:\Documents and Settings\Administrator\*.tmp - & gt; ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2010-03-23 14:30:13 | 000,000,714 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2010-03-23 10:38:38 | 000,035,346 | ---- | M] () -- C:\WINDOWS\System32\temp1.exe
[2010-03-23 10:38:38 | 000,002,085 | ---- | M] () -- C:\WINDOWS\System32\temp2.exe
[2010-03-23 10:38:13 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010-03-23 10:38:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-03-23 10:37:51 | 000,098,506 | ---- | M] () -- C:\WINDOWS\System32\oodbs.lor
[2010-03-22 23:00:02 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini
[2010-03-22 23:00:01 | 003,670,016 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
[2010-03-22 22:12:43 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010-03-22 13:07:34 | 000,000,640 | ---- | M] () -- C:\Documents and Settings\Administrator\Pulpit\Mp3 Knife.lnk
[2010-03-22 12:55:08 | 000,000,492 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Fraps.lnk
[2010-03-21 18:33:44 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\Administrator\Pulpit\VirtualDub.lnk
[2010-03-21 17:27:01 | 000,001,654 | ---- | M] () -- C:\Documents and Settings\Administrator\Pulpit\Cool Record Edit Pro.lnk
[2010-03-21 17:27:01 | 000,000,659 | ---- | M] () -- C:\Documents and Settings\Administrator\Pulpit\Free Sound Recorder.lnk
[2010-03-21 15:40:14 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\VideoMach.lnk
[2010-03-21 12:18:57 | 000,002,207 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Steam.lnk
[2010-03-21 12:16:51 | 004,804,946 | -H-- | M] () -- C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2010-03-16 15:25:34 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-03-14 12:38:11 | 000,001,588 | ---- | M] () -- C:\Documents and Settings\Administrator\Pulpit\Play to Quake III.lnk
[2010-03-14 12:38:11 | 000,001,588 | ---- | M] () -- C:\Documents and Settings\Administrator\Pulpit\Graj w Quake III.lnk
[2010-03-14 12:18:30 | 000,000,983 | ---- | M] () -- C:\Documents and Settings\Administrator\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
[2010-03-04 16:49:19 | 000,065,760 | ---- | M] () -- C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2010-03-04 10:26:04 | 000,086,016 | ---- | M] (Beepa P/L) -- C:\WINDOWS\System32\frapsvid.dll
[2010-03-03 09:08:28 | 000,098,304 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll
[1 C:\WINDOWS\System32\*.tmp files - & gt; C:\WINDOWS\System32\*.tmp - & gt; ]
[1 C:\WINDOWS\*.tmp files - & gt; C:\WINDOWS\*.tmp - & gt; ]
[1 C:\Documents and Settings\Administrator\*.tmp files - & gt; C:\Documents and Settings\Administrator\*.tmp - & gt; ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2010-03-23 14:30:13 | 000,000,714 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2010-03-22 13:07:34 | 000,000,640 | ---- | C] () -- C:\Documents and Settings\Administrator\Pulpit\Mp3 Knife.lnk
[2010-03-22 12:55:08 | 000,000,492 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Fraps.lnk
[2010-03-21 18:33:44 | 000,000,654 | ---- | C] () -- C:\Documents and Settings\Administrator\Pulpit\VirtualDub.lnk
[2010-03-21 17:27:01 | 000,001,654 | ---- | C] () -- C:\Documents and Settings\Administrator\Pulpit\Cool Record Edit Pro.lnk
[2010-03-21 17:27:01 | 000,000,659 | ---- | C] () -- C:\Documents and Settings\Administrator\Pulpit\Free Sound Recorder.lnk
[2010-03-21 17:26:59 | 000,113,486 | ---- | C] () -- C:\WINDOWS\System32\NCTWMAProfiles.prx
[2010-03-21 16:37:55 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010-03-21 15:54:40 | 000,838,656 | ---- | C] () -- C:\WINDOWS\System32\ac3filter.ax
[2010-03-21 15:54:40 | 000,617,984 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010-03-21 15:54:40 | 000,538,624 | ---- | C] () -- C:\WINDOWS\System32\ac3filter.acm
[2010-03-21 15:54:40 | 000,319,488 | ---- | C] () -- C:\WINDOWS\System32\coreaac.ax
[2010-03-21 15:54:40 | 000,178,688 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010-03-21 15:54:40 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\xvid.ax
[2010-03-21 15:54:39 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010-03-21 15:54:39 | 000,004,816 | ---- | C] () -- C:\WINDOWS\System32\divxsm.tlb
[2010-03-21 15:40:14 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\VideoMach.lnk
[2010-03-14 12:38:11 | 000,001,588 | ---- | C] () -- C:\Documents and Settings\Administrator\Pulpit\Play to Quake III.lnk
[2010-03-14 12:18:29 | 000,000,983 | ---- | C] () -- C:\Documents and Settings\Administrator\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
[2010-03-14 00:11:11 | 000,001,588 | ---- | C] () -- C:\Documents and Settings\Administrator\Pulpit\Graj w Quake III.lnk
[2010-02-11 17:48:40 | 000,394,752 | ---- | C] () -- C:\WINDOWS\System32\cygwinb19.dll
[2010-02-11 17:48:40 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 122 bytes - & gt; C:\Documents and Settings\All Users\Dane aplikacji\TEMP:05EE1EEF
& lt; End of report & gt;


Pulpit.rar > mbam-log-2010-03-23 (15-12-01).txt

Malwarebytes' Anti-Malware 1.44
Wersja bazy definicji: 3903
Windows 5.1.2600 Dodatek Service Pack 3
Internet Explorer 7.0.5730.13

2010-03-23 15:12:06
mbam-log-2010-03-23 (15-12-01).txt

Typ skanowania: Pe³ne skanowanie (C:\|)
Przeskanowane obiekty: 153536
Up³ynê³o: 37 minute(s), 0 second(s)

Zainfekowane procesy w pamiêci: 2
Zainfekowane modu³y pamiêci: 3
Zainfekowane klucze rejestru: 7
Zainfekowane wartoœci rejestru: 2
Zainfekowane pliki rejestru: 2
Zainfekowane foldery: 8
Zainfekowane pliki: 33

Zainfekowane procesy w pamiêci:
C:\WINDOWS\system32\temp1.exe (Trojan.Downloader) - & gt; No action taken.
C:\program files\relevantknowledge\rlvknlg.exe (Spyware.MarketScore) - & gt; No action taken.

Zainfekowane modu³y pamiêci:
C:\program files\relevantknowledge\MSVCP71.DLL (Spyware.MarketScore) - & gt; No action taken.
C:\program files\relevantknowledge\MSVCR71.DLL (Spyware.MarketScore) - & gt; No action taken.
C:\program files\relevantknowledge\rlls.dll (Spyware.MarketScore) - & gt; No action taken.

Zainfekowane klucze rejestru:
HKEY_CLASSES_ROOT\TypeLib\{01bcb858-2f62-4f06-a8f4-48f927c15333} (Adware.PredictAd) - & gt; No action taken.
HKEY_CLASSES_ROOT\Interface\{c9ae652b-8c99-4ac2-b556-8b501182874e} (Adware.PredictAd) - & gt; No action taken.
HKEY_CLASSES_ROOT\CLSID\{0fb6a909-6086-458f-bd92-1f8ee10042a0} (Adware.PredictAd) - & gt; No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0fb6a909-6086-458f-bd92-1f8ee10042a0} (Adware.PredictAd) - & gt; No action taken.
HKEY_CLASSES_ROOT\AppID\AutocompletePro.DLL (Adware.PredictAd) - & gt; No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutocompletePro2_is1 (Adware.PredictAd) - & gt; No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) - & gt; No action taken.

Zainfekowane wartoœci rejestru:
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\support@predictad.com (Adware.PredictAd) - & gt; No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Backdoor.Bot) - & gt; No action taken.

Zainfekowane pliki rejestru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Dropper) - & gt; Data: c:\windows\svchost.exe - & gt; No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) - & gt; Bad: (1) Good: (0) - & gt; No action taken.

Zainfekowane foldery:
C:\Program Files\RelevantKnowledge (Spyware.MarketScore) - & gt; No action taken.
C:\Documents and Settings\All Users\Menu Start\Programy\RelevantKnowledge (Spyware.MarketScore) - & gt; No action taken.
C:\Program Files\AutocompletePro (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\chrome (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\chrome\content (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\defaults (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\defaults\preferences (Adware.PredictAd) - & gt; No action taken.

Zainfekowane pliki:
C:\WINDOWS\system32\temp1.exe (Trojan.Downloader) - & gt; No action taken.
C:\autorun.inf (Worm.Perlovga) - & gt; No action taken.
C:\copy.exe (Worm.Perlovga) - & gt; No action taken.
C:\host.exe (Trojan.Dropper) - & gt; No action taken.
C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\is-S1429.tmp\Bho_vcsoftwaresAcPro.exe (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\AutocompletePro.dll (Adware.PredictAd) - & gt; No action taken.
C:\WINDOWS\svchost.exe (Trojan.Dropper) - & gt; No action taken.
C:\WINDOWS\xcopy.exe (Worm.Perlovga) - & gt; No action taken.
C:\WINDOWS\system32\temp2.exe (Trojan.Downloader) - & gt; No action taken.
C:\Program Files\RelevantKnowledge\MSVCP71.DLL (Spyware.MarketScore) - & gt; No action taken.
C:\Program Files\RelevantKnowledge\MSVCR71.DLL (Spyware.MarketScore) - & gt; No action taken.
C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.MarketScore) - & gt; No action taken.
C:\Program Files\RelevantKnowledge\rlls64.dll (Spyware.MarketScore) - & gt; No action taken.
C:\Program Files\RelevantKnowledge\rloci.bin (Spyware.MarketScore) - & gt; No action taken.
C:\Program Files\RelevantKnowledge\rlservice.exe (Spyware.MarketScore) - & gt; No action taken.
C:\Program Files\RelevantKnowledge\rlvknlg.exe (Spyware.MarketScore) - & gt; No action taken.
C:\Program Files\RelevantKnowledge\rlvknlg64.exe (Spyware.MarketScore) - & gt; No action taken.
C:\Documents and Settings\All Users\Menu Start\Programy\RelevantKnowledge\About RelevantKnowledge.lnk (Spyware.MarketScore) - & gt; No action taken.
C:\Documents and Settings\All Users\Menu Start\Programy\RelevantKnowledge\Privacy Policy and User License Agreement.lnk (Spyware.MarketScore) - & gt; No action taken.
C:\Documents and Settings\All Users\Menu Start\Programy\RelevantKnowledge\Support.lnk (Spyware.MarketScore) - & gt; No action taken.
C:\Documents and Settings\All Users\Menu Start\Programy\RelevantKnowledge\Uninstall Instructions.lnk (Spyware.MarketScore) - & gt; No action taken.
C:\Program Files\AutocompletePro\AcRemoteUpdate.exe (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\InstTracker.exe (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\TaskScheduler.dll (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\unins000.dat (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\unins000.exe (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\chrome.manifest (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\install.rdf (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\chrome\content\browserOverlay.xul (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\chrome\content\options.js (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\chrome\content\options.xul (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\chrome\content\utils.js (Adware.PredictAd) - & gt; No action taken.
C:\Program Files\AutocompletePro\support@predictad.com\defaults\preferences\predictad.js (Adware.PredictAd) - & gt; No action taken.


Pulpit.rar > Extras.Txt

OTL Extras logfile created on: 2010-03-23 15:15:39 - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

511,00 Mb Total Physical Memory | 145,00 Mb Available Physical Memory | 28,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 64,00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 28,50 Gb Total Space | 19,06 Gb Free Space | 66,90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SPEED2
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ & lt; extension & gt; ]

[HKEY_CURRENT_USER\SOFTWARE\Classes\ & lt; extension & gt; ]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ & lt; key & gt; \shell\[command]\command]
batfile [open] -- " %1 " %*
batfile [print] -- Reg Error: Key error.
cmdfile [open] -- " %1 " %*
cmdfile [print] -- Reg Error: Key error.
comfile [open] -- " %1 " %*
exefile [open] -- " %1 " %*
htmlfile [edit] -- " C:\Program Files\Microsoft Office\Office12\msohtmed.exe " %1 (Microsoft Corporation)
htmlfile [print] -- " C:\Program Files\Microsoft Office\Office12\msohtmed.exe " /p %1 (Microsoft Corporation)
inffile [print] -- Reg Error: Key error.
inifile [print] -- Reg Error: Key error.
InternetShortcut [print] -- Reg Error: Key error.
piffile [open] -- " %1 " %*
regfile [merge] -- Reg Error: Key error.
regfile [print] -- Reg Error: Key error.
scrfile [config] -- " %1 "
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- " %1 " /S
txtfile [edit] -- Reg Error: Key error.
txtfile [print] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with FastStone] -- " C:\Program Files\FastStone Image Viewer\FSViewer.exe " " %1 " ()
Directory [cmd] -- cmd.exe /k cd " %L " (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE " %L " (Microsoft Corporation)
Directory [openNew] -- explorer %1 (Microsoft Corporation)
Directory [Winamp.Bookmark] -- " C:\Program Files\winamp\winamp.exe " /BOOKMARK " %1 " (Nullsoft)
Directory [Winamp.Enqueue] -- " C:\Program Files\winamp\winamp.exe " /ADD " %1 " (Nullsoft)
Directory [Winamp.Play] -- " C:\Program Files\winamp\winamp.exe " " %1 " (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- Reg Error: Key error.
Drive [find] -- Reg Error: Key error.

[color=#E56717]========== Security Center Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
" EnableFirewall " = 0
" DoNotAllowExceptions " = 0
" DisableNotifications " = 0
" DisableUnicastResponsesToMulticastBroadcast " = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
" EnableFirewall " = 0
" DoNotAllowExceptions " = 0
" DisableNotifications " = 0
" DisableUnicastResponsesToMulticastBroadcast " = 0

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
" {048298C9-A4D3-490B-9FF9-AB023A9238F3} " = Steam
" {0BEDBD4E-2D34-47B5-9973-57E62B29307C} " = ATI Control Panel
" {1FF7993C-23B1-4C91-B1F6-09D13C57A06A}_is1 " = VirtualDub 1.9.6 US
" {3248F0A8-6813-11D6-A77B-00B0D0160070} " = Java(TM) 6 Update 7
" {38171128-662E-4CE0-A2C8-23B3FCBA73B3} " = Conflict Global Storm
" {53480330-E1D1-41CA-B8F8-7F78644F7F50} " = O & O Defrag Professional Edition
" {5AF71003-1797-4D93-9F37-4F2125CBF539} " = Microsoft .NET Framework 2.0 Language Pack - PLK
" {64CB2553-C109-4132-AA51-1F421B515FD1} " = Microsoft .NET Framework 1.1 Polish Language Pack
" {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} " = Microsoft .NET Framework 2.0
" {789289CA-F73A-4A16-A331-54D498CE069F} " = Ventrilo
" {837b34e3-7c30-493c-8f6a-2b0f04e2912c} " = Microsoft Visual C++ 2005 Redistributable
" {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} " = Microsoft Silverlight
" {8C5FAD77-F678-4758-A296-C12F08D179E0} " = Microsoft IntelliPoint 6.2
" {90120000-0010-0415-0000-0000000FF1CE} " = Microsoft Software Update for Web Folders (Polish) 12
" {90120000-0015-0415-0000-0000000FF1CE} " = Microsoft Office Access MUI (Polish) 2007
" {90120000-0016-0415-0000-0000000FF1CE} " = Microsoft Office Excel MUI (Polish) 2007
" {90120000-0018-0415-0000-0000000FF1CE} " = Microsoft Office PowerPoint MUI (Polish) 2007
" {90120000-0019-0415-0000-0000000FF1CE} " = Microsoft Office Publisher MUI (Polish) 2007
" {90120000-001A-0415-0000-0000000FF1CE} " = Microsoft Office Outlook MUI (Polish) 2007
" {90120000-001B-0415-0000-0000000FF1CE} " = Microsoft Office Word MUI (Polish) 2007
" {90120000-001F-0407-0000-0000000FF1CE} " = Microsoft Office Proof (German) 2007
" {90120000-001F-0409-0000-0000000FF1CE} " = Microsoft Office Proof (English) 2007
" {90120000-001F-0415-0000-0000000FF1CE} " = Microsoft Office Proof (Polish) 2007
" {90120000-002C-0415-0000-0000000FF1CE} " = Microsoft Office Proofing (Polish) 2007
" {90120000-0030-0000-0000-0000000FF1CE} " = Microsoft Office Enterprise 2007
" {90120000-0044-0415-0000-0000000FF1CE} " = Microsoft Office InfoPath MUI (Polish) 2007
" {90120000-006E-0415-0000-0000000FF1CE} " = Microsoft Office Shared MUI (Polish) 2007
" {90120000-00A1-0415-0000-0000000FF1CE} " = Microsoft Office OneNote MUI (Polish) 2007
" {90120000-00BA-0415-0000-0000000FF1CE} " = Microsoft Office Groove MUI (Polish) 2007
" {95120000-00B9-0409-0000-0000000FF1CE} " = Microsoft Application Error Reporting
" {AC76BA86-7AD7-1033-7B44-A90000000001} " = Adobe Reader 9 Lite
" {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} " = Microsoft .NET Framework 1.1
" {d08d9f98-1c78-4704-87e6-368b0023d831} " = RelevantKnowledge
" {F0A37341-D692-11D4-A984-009027EC0A9C} " = SoundMAX
" Adobe Flash Player ActiveX " = Adobe Flash Player ActiveX
" Adobe Flash Player Plugin " = Adobe Flash Player 10 Plugin
" Adobe Shockwave Player " = Adobe Shockwave Player 11
" ATI Display Driver " = ATI Display Driver
" Audacity_is1 " = Audacity 1.2.6
" AutocompletePro2_is1 " = AutocompletePro
" Codec_is1 " = Codec 8.3i
" CPLBonus " = Kels' CPL Bonus Pack!
" Driver Magician_is1 " = Driver Magician 3.28
" Driver Sweeper " = Driver Sweeper 0.9 (Remove Only)
" DriveSpace " = Drive Space Indicator
" ENTERPRISE " = Microsoft Office Enterprise 2007
" FastStone Image Viewer " = FastStone Image Viewer 3.5
" Fraps " = Fraps (remove only)
" Free Sound Recorder_is1 " = Free Sound Recorder 2010 v8.2.1
" GMailFS " = GMail Drive Shell Extension
" HFSLIPTotalSlipstream " = HFSLIP Total Slipstream (v2.0.0pre-alpha, build 80630a)
" MakeISO right click extensions " = MakeISO right click extensions
" Malwarebytes' Anti-Malware_is1 " = Malwarebytes' Anti-Malware
" Microsoft .NET Framework 1.1 (1033) " = Microsoft .NET Framework 1.1
" Microsoft .NET Framework 2.0 " = Microsoft .NET Framework 2.0
" Microsoft .NET Framework 2.0 Language Pack - PLK " = Microsoft .NET Framework 2.0 — pakiet języka polskiego
" mIRC " = mIRC
" Mozilla Firefox (3.6) " = Mozilla Firefox (3.6)
" Mozilla Thunderbird (2.0.0.14) " = Mozilla Thunderbird (2.0.0.14)
" Mp3 Knife_is1 " = Mp3 Knife 3.2
" Nero8Lite_is1 " = Nero 8 Micro 8.3.2.1b
" Notepad++ " = Notepad++
" Nowe Gadu-Gadu " = Nowe Gadu-Gadu
" PowerISO " = PowerISO
" Quake III " = Quake III
" ShellExtension " = FirmTools 2.0 build 313
" Steam App 10 " = Counter-Strike
" Tibia_is1 " = Tibia
" Unlocker " = Unlocker 1.8.7
" VideoMach " = VideoMach
" VideoMach 4.0.4 " = VideoMach 4.0.4
" VisualTaskTips " = Visual Task Tips 2.3
" Winamp " = Winamp 5.54 addon by jeetu
" Windows Media Format Runtime " = Windows Media Format 11 runtime
" Windows Media Player " = Windows Media Player 11
" WinRAR archiver " = Archiwizator WinRAR
" Your Uninstaller! 2008_is1 " = Your Uninstaller! 2008 Version 6.0

[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
" uTorrent " = µTorrent

[color=#E56717]========== Last 10 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2010-02-11 13:02:34 | Computer Name = SPEED2 | Source = .NET Runtime Optimization Service | ID = 1111
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Service reached limit of transient errors. Will shut down. Last error returned
from Service Manager: 0x800736b1.

Error - 2010-03-16 12:48:39 | Computer Name = SPEED2 | Source = Microsoft Office 12 | ID = 2001
Description = Rejected Safe Mode action : Microsoft Office Outlook.

Error - 2010-03-16 12:48:40 | Computer Name = SPEED2 | Source = Microsoft Office 12 | ID = 1000
Description = Faulting application outlook.exe, version 12.0.4518.1014, stamp 4542840f,
faulting module loadperf.dll, version 5.1.2600.5512, stamp 48038ff0, debug? 0,
fault address 0x0000adb8.

Error - 2010-03-16 12:49:04 | Computer Name = SPEED2 | Source = Microsoft Office 12 | ID = 2001
Description = Rejected Safe Mode action : Microsoft Office Outlook.

Error - 2010-03-16 12:49:06 | Computer Name = SPEED2 | Source = Microsoft Office 12 | ID = 1000
Description = Faulting application outlook.exe, version 12.0.4518.1014, stamp 4542840f,
faulting module loadperf.dll, version 5.1.2600.5512, stamp 48038ff0, debug? 0,
fault address 0x0000adb8.

[ OSession Events ]
Error - 2010-03-16 12:48:28 | Computer Name = SPEED2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 9
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2010-03-16 12:48:39 | Computer Name = SPEED2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2010-03-16 12:49:05 | Computer Name = SPEED2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 2010-03-22 07:07:42 | Computer Name = SPEED2 | Source = NetBT | ID = 4321
Description = Nie można zarejestrować nazwy „SPEED2 :20” w interfejsie o
adresie IP 192.168.1.101. Komputer o adresie IP 192.168.1.100 nie zezwolił na przejęcie
tej nazwy przez ten komputer.

Error - 2010-03-22 09:48:46 | Computer Name = SPEED2 | Source = Server | ID = 2505
Description = Serwer nie mógł utworzyć powiązania do transportu \Device\NetBT_Tcpip_{48621D86-CE92-473C-B11E-402D93DC86F1},
ponieważ inny komputer w sieci ma tę samą nazwę. Nie można uruchomić serwera.

Error - 2010-03-22 09:48:51 | Computer Name = SPEED2 | Source = NetBT | ID = 4321
Description = Nie można zarejestrować nazwy „SPEED2 :0” w interfejsie o
adresie IP 192.168.1.101. Komputer o adresie IP 192.168.1.100 nie zezwolił na przejęcie
tej nazwy przez ten komputer.

Error - 2010-03-22 09:48:51 | Computer Name = SPEED2 | Source = NetBT | ID = 4321
Description = Nie można zarejestrować nazwy „SPEED2 :20” w interfejsie o
adresie IP 192.168.1.101. Komputer o adresie IP 192.168.1.100 nie zezwolił na przejęcie
tej nazwy przez ten komputer.

Error - 2010-03-22 09:52:36 | Computer Name = SPEED2 | Source = Dhcp | ID = 1002
Description = Adres IP połączenia 192.168.1.101 dla karty sieciowej o adresie 001F1F2F5FBE
został zabroniony przez serwer DHCP 0.0.0.0 (Serwer DHCP wysłał komunikat DHCPNACK).

Error - 2010-03-22 09:52:40 | Computer Name = SPEED2 | Source = Server | ID = 2505
Description = Serwer nie mógł utworzyć powiązania do transportu \Device\NetBT_Tcpip_{48621D86-CE92-473C-B11E-402D93DC86F1},
ponieważ inny komputer w sieci ma tę samą nazwę. Nie można uruchomić serwera.

Error - 2010-03-22 09:52:40 | Computer Name = SPEED2 | Source = NetBT | ID = 4321
Description = Nie można zarejestrować nazwy „SPEED2 :0” w interfejsie o
adresie IP 192.168.1.101. Komputer o adresie IP 192.168.1.100 nie zezwolił na przejęcie
tej nazwy przez ten komputer.

Error - 2010-03-22 09:52:40 | Computer Name = SPEED2 | Source = NetBT | ID = 4321
Description = Nie można zarejestrować nazwy „SPEED2 :20” w interfejsie o
adresie IP 192.168.1.101. Komputer o adresie IP 192.168.1.100 nie zezwolił na przejęcie
tej nazwy przez ten komputer.

Error - 2010-03-23 05:38:20 | Computer Name = SPEED2 | Source = Server | ID = 2505
Description = Serwer nie mógł utworzyć powiązania do transportu \Device\NetBT_Tcpip_{48621D86-CE92-473C-B11E-402D93DC86F1},
ponieważ inny komputer w sieci ma tę samą nazwę. Nie można uruchomić serwera.

Error - 2010-03-23 05:38:24 | Computer Name = SPEED2 | Source = NetBT | ID = 4321
Description = Nie można zarejestrować nazwy „SPEED2 :0” w interfejsie o
adresie IP 192.168.1.101. Komputer o adresie IP 192.168.1.100 nie zezwolił na przejęcie
tej nazwy przez ten komputer.


& lt; End of report & gt;


Pulpit.rar > DrWeb.csv

autorun.inf;C:\;Trojan.Copyself;Usuniêty.;
copy.exe;C:\;Trojan.Copyself.94;;
host.exe;C:\;Trojan.MulDrop.4181;Usuniêty.;
copy.exe;c:\;Trojan.Copyself.94;;
svchost.exe;c:\windows;Trojan.MulDrop.4181;Usuniêty.;
temp1.exe;C:\WINDOWS\system32;Trojan.Copyself.85;;
temp2.exe;C:\WINDOWS\system32;Trojan.DownLoader.10355;Usuniêty.;
temp1.exe;c:\windows\system32;Trojan.Copyself.85;;