OTL.Txt

XP - w32/blaster.worm infekcja prosze o sprawdzenie logow otl - komputer firmowy

Bardzo serdecznie dziękuje, bardzo mi pan pomógł i uratował moją firmę. Niesamowita wiedza i precyzja sprawiła, że dzięki panu wszystko wróciło do normy. Poniżej przedstawiam log OTL, jeszcze raz dziękuje.


OTL logfile created on: 2013-04-20 23:56:07 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\mir-pol\Moje dokumenty\Pobieranie
Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

1,93 Gb Total Physical Memory | 1,29 Gb Available Physical Memory | 66,73% Memory free
3,78 Gb Paging File | 3,26 Gb Available in Paging File | 86,31% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 75,19 Gb Total Space | 0,79 Gb Free Space | 1,06% Space Free | Partition Type: NTFS
Drive E: | 73,85 Gb Total Space | 66,11 Gb Free Space | 89,53% Space Free | Partition Type: NTFS
Drive F: | 15,92 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: MIR-POL | User Name: mir-pol | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2013-04-20 23:49:57 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\mir-pol\Moje dokumenty\Pobieranie\OTL.exe
PRC - [2013-04-20 23:27:42 | 000,181,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2013-04-10 08:56:41 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010-11-25 23:42:22 | 003,294,528 | ---- | M] () -- C:\Program Files\iPlus\iPlusManager.exe
PRC - [2010-11-15 14:56:56 | 018,633,728 | ---- | M] (Redefine Sp z o.o.) -- C:\Program Files\ipla\ipla.exe
PRC - [2010-05-14 11:32:30 | 001,479,680 | ---- | M] (Nokia) -- C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
PRC - [2009-09-22 11:50:36 | 000,073,728 | ---- | M] (Software 2000 Limited) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE
PRC - [2009-05-11 10:45:18 | 000,024,576 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\HP UT\bin\hppusg.exe
PRC - [2008-12-13 06:23:30 | 000,882,176 | ---- | M] (Ares Development Group) -- C:\Program Files\Ares\Ares.exe
PRC - [2008-07-25 06:18:00 | 000,768,520 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe
PRC - [2008-04-15 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2003-08-19 17:09:30 | 000,057,344 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
PRC - [2003-08-19 17:00:40 | 000,053,248 | ---- | M] (Lexmark International, Inc.) -- C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2013-04-10 08:56:55 | 003,133,336 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2013-02-15 08:16:58 | 001,712,128 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\024c898ad1ccfde466d033c0a08d0564\Microsoft.VisualBasic.ni.dll
MOD - [2013-02-15 08:10:23 | 012,433,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ba12e418b906593b7c9c18f971f36bf9\System.Windows.Forms.ni.dll
MOD - [2013-02-15 08:08:06 | 000,303,104 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2013-01-11 09:32:24 | 000,311,296 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\07de14823c42ee36ffa303d9c89ded36\System.Runtime.Serialization.Formatters.Soap.ni.dll
MOD - [2013-01-11 09:31:13 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\96b7a0136e9e72e8f4eb0230c20766d2\System.Configuration.ni.dll
MOD - [2013-01-11 09:20:29 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\fe025743210c22bea2f009e1612c38bf\System.Xml.ni.dll
MOD - [2013-01-11 09:19:34 | 001,593,856 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\7782f356a838c403b4a8e9c80df5a577\System.Drawing.ni.dll
MOD - [2013-01-11 09:14:22 | 007,977,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aeac298c43c77d8860db8e7634d9f2eb\System.ni.dll
MOD - [2013-01-11 09:13:09 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a87868659979\mscorlib.ni.dll
MOD - [2010-11-25 23:42:22 | 003,294,528 | ---- | M] () -- C:\Program Files\iPlus\iPlusManager.exe
MOD - [2010-11-25 23:42:18 | 001,097,728 | ---- | M] () -- C:\Program Files\iPlus\NDISAPI.dll
MOD - [2010-11-15 14:50:08 | 000,267,264 | ---- | M] () -- C:\Program Files\ipla\MediaFileScanner.dll
MOD - [2010-11-15 14:48:44 | 000,386,560 | ---- | M] () -- C:\Program Files\ipla\jabberoo.dll
MOD - [2010-11-15 14:47:52 | 000,156,160 | ---- | M] () -- C:\Program Files\ipla\lua.dll
MOD - [2010-11-15 14:47:00 | 000,060,928 | ---- | M] () -- C:\Program Files\ipla\ziplib.dll
MOD - [2009-08-22 09:57:58 | 000,488,448 | ---- | M] () -- C:\WINDOWS\system32\apdfprintmon.dll
MOD - [2009-07-09 18:03:04 | 003,565,568 | ---- | M] () -- C:\Program Files\K-Lite Codec Pack\ffdshow\ffdshow.ax
MOD - [2008-08-12 12:16:16 | 002,023,424 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 7\QtCore4.dll
MOD - [2008-07-29 15:47:56 | 000,016,384 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 7\imageformats\qsvg4.dll
MOD - [2008-07-29 15:47:38 | 000,135,168 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 7\imageformats\qjpeg4.dll
MOD - [2008-07-29 15:11:18 | 000,253,952 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 7\QtSvg4.dll
MOD - [2008-07-29 15:01:12 | 007,331,840 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 7\QtGUI4.dll
MOD - [2008-07-29 14:50:26 | 000,364,544 | ---- | M] () -- C:\Program Files\Nokia\Nokia PC Suite 7\QtXml4.dll
MOD - [2008-04-15 14:00:00 | 000,070,656 | ---- | M] () -- C:\WINDOWS\system32\amstream.dll
MOD - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008-02-01 09:26:24 | 000,753,664 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
MOD - [2008-02-01 09:26:24 | 000,143,360 | ---- | M] () -- C:\WINDOWS\system32\preflib.dll
MOD - [2003-07-29 15:27:40 | 000,078,336 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBKPP5C.DLL
MOD - [2003-06-07 07:30:00 | 000,057,344 | ---- | M] () -- C:\Program Files\Launch Manager\PowerUtl.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2013-04-20 23:27:42 | 000,181,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013-04-10 08:56:49 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013-02-05 17:48:00 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe -- (McComponentHostService)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\rt73.sys -- (RT73)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2010-11-25 23:42:46 | 000,117,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2010-11-25 23:42:46 | 000,106,496 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010-11-25 23:42:46 | 000,072,832 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010-11-25 23:42:44 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010-02-26 15:32:58 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2010-02-26 15:32:46 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2010-02-26 15:32:44 | 000,022,528 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2010-02-26 15:32:44 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008-08-26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008-07-01 05:27:44 | 000,108,800 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2008-06-20 10:58:08 | 004,741,120 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2008-01-23 13:10:38 | 001,265,536 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2006-11-02 15:27:00 | 000,020,112 | ---- | M] (Dritek System Inc.) [Kernel | System | Running] -- C:\Program Files\Launch Manager\DPortIO.sys -- (DritekPortIO)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: " URL " = http://search.live.com/results.aspx?q={searchTerms} & src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: " URL " = http://www.google.com/search?q={searchTerms} & rls=com.microsoft:{language}:{referrer:source?} & ie={inputEncoding} & oe={outputEncoding} & sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ipko.pl/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://pl.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B4 9C 00 72 8E 1E CA 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: " URL " = http://www.bing.com/search?q={searchTerms} & FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: " URL " = http://www.bing.com/search?q={searchTerms} & FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: " ProxyEnable " = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.selectedEngine: " Google "
FF - prefs.js..browser.startup.homepage: " wyborcza.pl/0,0.html?p=030 "
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: bkmrksync@nokia.com:1.0.0.733
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010-11-18 11:33:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013-04-20 23:33:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013-04-20 23:32:59 | 000,000,000 | ---D | M]

[2009-08-18 09:04:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\mir-pol\Dane aplikacji\Mozilla\Extensions
[2013-04-19 07:55:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\mir-pol\Dane aplikacji\Mozilla\Firefox\Profiles\pmg1ao3m.default\extensions
[2011-03-04 10:07:23 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\mir-pol\Dane aplikacji\Mozilla\Firefox\Profiles\pmg1ao3m.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013-04-20 23:33:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013-04-10 08:57:39 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2004-11-13 05:36:20 | 000,005,120 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\mozilla firefox\plugins\NPAdbESD.dll
[2013-04-10 10:57:33 | 000,002,980 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2013-04-10 10:57:33 | 000,001,619 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2013-04-10 10:57:33 | 000,001,130 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2013-04-10 10:57:33 | 000,001,071 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2013-04-10 10:57:33 | 000,001,396 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2013-04-10 10:57:33 | 000,001,896 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2008-04-15 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [HPUsageTracking] C:\Program Files\HP\HP UT\bin\hppusg.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [iPlusManager] C:\Program Files\iPlus\iPlusChecker.exe ()
O4 - HKLM..\Run: [Lexmark X1100 Series] C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Nero AG)
O4 - HKCU..\Run: [ares] C:\Program Files\Ares\Ares.exe (Ares Development Group)
O4 - HKCU..\Run: [Internet Security] C:\Documents and Settings\All Users\Dane aplikacji\amsecure.exe File not found
O4 - HKCU..\Run: [IPLA!] C:\Program Files\ipla\ipla.exe (Redefine Sp z o.o.)
O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa & ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.2.96.53 212.2.96.54
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{431622F4-2DC8-416C-836F-881DD3183B11}: DhcpNameServer = 8.8.8.8 8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A11D60BF-1A42-4E8A-824E-F30588F8B178}: DhcpNameServer = 212.2.96.53 212.2.96.54
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\mir-pol\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\mir-pol\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-08-11 22:46:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010-12-16 15:03:48 | 000,143,360 | R--- | M] (Huawei Technologies Co., Ltd.) - F:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2010-12-16 15:04:42 | 000,000,045 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{1ac401ae-3781-11e1-927f-00242b62c95b}\Shell - " " = AutoRun
O33 - MountPoints2\{1ac401ae-3781-11e1-927f-00242b62c95b}\Shell\AutoRun\command - " " = F:\AutoRun.exe -- [2010-12-16 15:03:48 | 000,143,360 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{3749891c-c26c-11e0-91d2-00235a4ca856}\Shell - " " = AutoRun
O33 - MountPoints2\{3749891c-c26c-11e0-91d2-00235a4ca856}\Shell\AutoRun\command - " " = F:\AutoRun.exe -- [2010-12-16 15:03:48 | 000,143,360 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{37498920-c26c-11e0-91d2-00235a4ca856}\Shell - " " = AutoRun
O33 - MountPoints2\{37498920-c26c-11e0-91d2-00235a4ca856}\Shell\AutoRun\command - " " = F:\AutoRun.exe -- [2010-12-16 15:03:48 | 000,143,360 | R--- | M] (Huawei Technologies Co., Ltd.)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- " %1 " %*
O35 - HKLM\..exefile [open] -- " %1 " %*
O37 - HKLM\...com [@ = comfile] -- " %1 " %*
O37 - HKLM\...exe [@ = exefile] -- " %1 " %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2013-04-20 23:33:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Mozilla
[2013-04-20 23:33:14 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2013-04-20 23:28:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2013-04-20 23:28:21 | 000,866,720 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
[2013-04-20 23:28:21 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2013-04-20 23:28:10 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2013-04-20 23:28:10 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2013-04-20 23:28:10 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013-04-20 23:08:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\Foxit Software
[2013-04-20 23:07:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Foxit Reader
[2013-04-20 23:06:43 | 000,000,000 | ---D | C] -- C:\Program Files\Foxit Software
[2013-04-20 23:06:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mir-pol\Dane aplikacji\Foxit Software
[2013-04-20 16:21:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mir-pol\Doctor Web
[2013-04-20 15:14:26 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2013-04-20 14:10:07 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2013-04-20 11:19:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Loaris Trojan Remover
[2013-04-20 11:19:29 | 000,000,000 | ---D | C] -- C:\Program Files\Loaris
[2013-04-20 09:07:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mir-pol\Ustawienia lokalne\Dane aplikacji\Norman Malware Cleaner
[3 C:\WINDOWS\*.tmp files - & gt; C:\WINDOWS\*.tmp - & gt; ]
[2 C:\WINDOWS\System32\*.tmp files - & gt; C:\WINDOWS\System32\*.tmp - & gt; ]
[1 C:\Program Files\*.tmp files - & gt; C:\Program Files\*.tmp - & gt; ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2013-04-20 23:41:52 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013-04-20 23:41:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013-04-20 23:33:18 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk
[2013-04-20 23:27:44 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013-04-20 23:27:40 | 000,263,584 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2013-04-20 23:27:40 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2013-04-20 23:27:40 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2013-04-20 23:27:40 | 000,144,896 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2013-04-20 23:27:39 | 000,866,720 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
[2013-04-20 23:27:38 | 000,788,896 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2013-04-20 23:23:59 | 000,541,310 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2013-04-20 23:23:59 | 000,483,030 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013-04-20 23:23:59 | 000,103,500 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2013-04-20 23:23:59 | 000,086,740 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013-04-20 23:07:04 | 000,001,703 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Foxit Reader.lnk
[2013-04-20 13:30:12 | 000,243,920 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013-04-20 11:06:33 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{741EFA13-1DAA-4AC7-9EBA-86ECB385FEA3}.job
[2013-04-19 08:54:54 | 000,106,408 | ---- | M] () -- C:\Documents and Settings\mir-pol\Pulpit\1.jpg
[2013-04-15 11:02:04 | 000,012,959 | ---- | M] () -- C:\Documents and Settings\mir-pol\Pulpit\Bez tytułu 1.odt
[2013-04-15 09:16:26 | 000,044,856 | ---- | M] () -- C:\Documents and Settings\mir-pol\Pulpit\1.pdf
[2013-04-13 07:41:38 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013-04-12 16:56:18 | 000,065,604 | ---- | M] () -- C:\Documents and Settings\mir-pol\Pulpit\2.jpg
[2013-04-11 08:42:32 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013-04-05 10:40:30 | 000,000,770 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Centrum urządzenia Lexmark X1100 Series All-In-One.lnk
[2013-04-05 10:40:07 | 000,000,258 | ---- | M] () -- C:\WINDOWS\lexstat.ini
[2013-03-28 15:46:03 | 000,740,512 | ---- | M] () -- C:\Documents and Settings\mir-pol\Pulpit\FRA - PRZEDSTAWICIEL BLAZEJ KEPA.jpg
[3 C:\WINDOWS\*.tmp files - & gt; C:\WINDOWS\*.tmp - & gt; ]
[2 C:\WINDOWS\System32\*.tmp files - & gt; C:\WINDOWS\System32\*.tmp - & gt; ]
[1 C:\Program Files\*.tmp files - & gt; C:\Program Files\*.tmp - & gt; ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2013-04-20 23:33:18 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk
[2013-04-20 23:33:18 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk
[2013-04-20 23:07:04 | 000,001,703 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Foxit Reader.lnk
[2013-04-15 11:02:04 | 000,012,959 | ---- | C] () -- C:\Documents and Settings\mir-pol\Pulpit\Bez tytułu 1.odt
[2013-03-28 15:46:02 | 000,740,512 | ---- | C] () -- C:\Documents and Settings\mir-pol\Pulpit\FRA - PRZEDSTAWICIEL BLAZEJ KEPA.jpg
[2012-02-16 14:44:07 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2010-05-13 11:45:42 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\mir-pol\Dane aplikacji\dm.ini
[2009-09-20 08:20:13 | 000,054,784 | ---- | C] () -- C:\Documents and Settings\mir-pol\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-09-17 08:25:39 | 000,008,627 | ---- | C] () -- C:\Documents and Settings\mir-pol\PAV_FOG.OPC

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009-08-16 17:02:22 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
" " = %SystemRoot%\system32\shdocvw.dll -- [2008-04-15 14:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation)
" ThreadingModel " = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
" " = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009-02-09 12:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation)
" ThreadingModel " = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
" " = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-15 14:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
" ThreadingModel " = Both

[color=#E56717]========== LOP Check ==========[/color]

[2011-04-12 11:05:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\A-PDF
[2009-08-13 13:08:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ashampoo
[2011-03-08 20:14:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\BVRP Software
[2012-07-14 11:01:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DatacardService
[2010-11-21 09:12:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10
[2010-10-21 13:19:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\InsERT
[2010-11-18 11:31:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations
[2010-11-21 09:17:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla
[2010-11-26 20:02:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2009-08-13 14:23:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Panda Security
[2012-06-13 17:03:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Panda Software
[2010-11-18 11:33:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite
[2013-04-20 23:02:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
[2009-09-27 21:07:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\Ashampoo
[2013-04-20 23:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\Foxit Software
[2010-11-21 09:12:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\Gadu-Gadu 10
[2011-05-10 06:51:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\InsERT GT
[2013-04-20 23:42:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\ipla
[2011-08-09 11:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\iPlus
[2010-11-18 11:33:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\Nokia
[2009-08-22 19:56:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\Nowe Gadu-Gadu
[2010-02-06 08:32:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\OpenFM
[2009-08-18 11:26:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\OpenOffice.org
[2010-11-18 11:34:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\PC Suite
[2010-11-21 09:16:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mir-pol\Dane aplikacji\RDRM

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 126 bytes - & gt; C:\Documents and Settings\All Users\Dane aplikacji\TEMP:A9662AE0

& lt; End of report & gt;


Pobierz plik - link do postu