logo elektroda
logo elektroda
X
logo elektroda
REKLAMA
REKLAMA
Adblock/uBlockOrigin/AdGuard mogą powodować znikanie niektórych postów z powodu nowej reguły.

Błąd NTVDM na Windows XP SP2 - analiza logów HijackThis i GMER

peace_maker 10 Kwi 2011 19:31 2561 9
REKLAMA
  • #1 9384387
    peace_maker
    Poziom 12  
    Posty: 103
    Ocena: 2
    Witam

    Na kompie wyskakuje mi problem:

    NTVDM napotkał na błąd systemu ... . Z tego co zdążyłem poczytać to może to wynikać z infekcji kompa. Poniżej przedstawiam log-i z hijackthis i z gmera (skopiowane z okna rootkit/malware). Z góry dzięki za pomoc


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:20:27, on 2011-04-10
    Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    D:\instalki\ROBOCZE\Avira\AntiVir Desktop\sched.exe
    D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avguard.exe
    D:\instalki\ROBOCZE\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avshadow.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avgnt.exe
    H:\instalki robocze\DAEMON Tools Lite\DTLite.exe
    D:\instalki\ROBOCZE\Gadu-Gadu\gg.exe
    D:\instalki\ROBOCZE\firefox\firefox.exe
    D:\instalki\ROBOCZE\firefox\plugin-container.exe
    D:\instalki\ROBOCZE\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://redirect.zonelabs.com/redirect/route?o...PL&date=-86400&link_id=8&dest=try_buy_product
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\instalki\ROBOCZE\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\instalki\ROBOCZE\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\instalki\ROBOCZE\adobereader\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\instalki\ROBOCZE\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [avgnt] "D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "H:\instalki robocze\DAEMON Tools Lite\DTLite.exe" -autorun
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://H:\INSTAL~1\MSOFFI~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\INSTAL~1\MSOFFI~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C6A616E9-DBAD-49F5-8DE3-65CD58360F63}: NameServer = 217.30.129.149,217.30.137.200
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\instalki\ROBOCZE\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\instalki\ROBOCZE\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\system32\wdfmgr.exe (file missing)

    --
    End of file - 4217 bytes



    GMER 1.0.15.15570 - http://www.gmer.net
    Rootkit quick scan 2011-04-10 19:27:23
    Windows 5.1.2600 Dodatek Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 ST360021A rev.3.19
    Running: gmer.exe; Driver: C:\DOCUME~1\as\USTAWI~1\Temp\axkyifog.sys


    ---- System - GMER 1.0.15 ----

    SSDT spda.sys ZwEnumerateKey [0xF7734DA4]
    SSDT spda.sys ZwEnumerateValueKey [0xF7735132]

    ---- Devices - GMER 1.0.15 ----

    Device \Driver\atapi \Device\Ide\IdePort0 867DC1F8
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 867DC1F8
    Device \Driver\atapi \Device\Ide\IdePort1 867DC1F8
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 867DC1F8
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 867DC1F8
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 867DC1F8
    Device \Driver\ac7uc2wu \Device\Scsi\ac7uc2wu1Port2Path0Target0Lun0 864B3500
    Device \Driver\ac7uc2wu \Device\Scsi\ac7uc2wu1 864B3500
    Device \FileSystem\Ntfs \Ntfs 867DB1F8
    Device \FileSystem\Fastfat \Fat 865811F8

    AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- EOF - GMER 1.0.15 ----
  • REKLAMA
  • #2 9384402
    DVDM14
    Poziom 35  
    Posty: 2949
    Pomógł: 315
    Ocena: 553
    Przeskanuj system cureit`em i usuń to, co wykryje. Następnie użyj OTL i wstaw tutaj log który utworzy.
  • REKLAMA
  • #3 9384423
    peace_maker
    Poziom 12  
    Posty: 103
    Ocena: 2
    LOG z OTL:

    z pliku Extras:

    OTL Extras logfile created on: 2011-04-10 20:27:16 - Run 1
    OTL by OldTimer - Version 3.2.22.3 Folder = D:\instalki\ANTYWIRY
    Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.2180)
    Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

    1 023,00 Mb Total Physical Memory | 596,00 Mb Available Physical Memory | 58,00% Memory free
    2,00 Gb Paging File | 2,00 Gb Available in Paging File | 86,00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 5,86 Gb Total Space | 1,87 Gb Free Space | 31,91% Space Free | Partition Type: NTFS
    Drive D: | 27,86 Gb Total Space | 3,69 Gb Free Space | 13,23% Space Free | Partition Type: FAT32
    Drive E: | 22,15 Gb Total Space | 1,14 Gb Free Space | 5,14% Space Free | Partition Type: FAT32
    Drive F: | 19,38 Gb Total Space | 3,12 Gb Free Space | 16,10% Space Free | Partition Type: NTFS
    Drive G: | 64,84 Gb Total Space | 2,06 Gb Free Space | 3,18% Space Free | Partition Type: NTFS
    Drive H: | 64,82 Gb Total Space | 4,44 Gb Free Space | 6,85% Space Free | Partition Type: NTFS
    Drive L: | 3,74 Gb Total Space | 2,02 Gb Free Space | 54,07% Space Free | Partition Type: FAT32

    Computer Name: RUCKTION-C14C8C | User Name: maciek | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- D:\instalki\ROBOCZE\firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    exefile [open] -- "%1" %*
    htmlfile [edit] -- "H:\instalki robocze\ms office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
    InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "D:\instalki\ROBOCZE\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "D:\instalki\ROBOCZE\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Directory [Winamp.Bookmark] -- "H:\instalki robocze\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
    Directory [Winamp.Enqueue] -- "H:\instalki robocze\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
    Directory [Winamp.Play] -- "H:\instalki robocze\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
    "65533:TCP" = 65533:TCP:*:Enabled:Services
    "52344:TCP" = 52344:TCP:*:Enabled:Services
    "6923:TCP" = 6923:TCP:*:Enabled:Services
    "8467:TCP" = 8467:TCP:*:Enabled:Services
    "5321:TCP" = 5321:TCP:*:Enabled:Services
    "5063:TCP" = 5063:TCP:*:Enabled:Services
    "1578:TCP" = 1578:TCP:*:Enabled:Services
    "8755:TCP" = 8755:TCP:*:Enabled:Services
    "6843:TCP" = 6843:TCP:*:Enabled:Services
    "2129:TCP" = 2129:TCP:*:Enabled:Services
    "2480:TCP" = 2480:TCP:*:Enabled:Services
    "8245:TCP" = 8245:TCP:*:Enabled:Services
    "9747:TCP" = 9747:TCP:*:Enabled:Services
    "1959:TCP" = 1959:TCP:*:Enabled:Services
    "4936:TCP" = 4936:TCP:*:Enabled:Services
    "2617:TCP" = 2617:TCP:*:Enabled:Services

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
    "65533:TCP" = 65533:TCP:*:Enabled:Services
    "52344:TCP" = 52344:TCP:*:Enabled:Services
    "6923:TCP" = 6923:TCP:*:Enabled:Services
    "8467:TCP" = 8467:TCP:*:Enabled:Services
    "5321:TCP" = 5321:TCP:*:Enabled:Services
    "5063:TCP" = 5063:TCP:*:Enabled:Services
    "1578:TCP" = 1578:TCP:*:Enabled:Services
    "8755:TCP" = 8755:TCP:*:Enabled:Services
    "6843:TCP" = 6843:TCP:*:Enabled:Services
    "2129:TCP" = 2129:TCP:*:Enabled:Services
    "2480:TCP" = 2480:TCP:*:Enabled:Services
    "8245:TCP" = 8245:TCP:*:Enabled:Services
    "9747:TCP" = 9747:TCP:*:Enabled:Services
    "1959:TCP" = 1959:TCP:*:Enabled:Services
    "4936:TCP" = 4936:TCP:*:Enabled:Services
    "2617:TCP" = 2617:TCP:*:Enabled:Services

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "D:\instalki\ROBOCZE\Gadu-Gadu\gg.exe" = D:\instalki\ROBOCZE\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program główny -- (Gadu-Gadu S.A.)
    "H:\instalki robocze\utorrent\uTorrent.exe" = H:\instalki robocze\utorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
    "D:\instalki\ROBOCZE\Java\jre6\bin\javaw.exe" = D:\instalki\ROBOCZE\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    ""SubEditCodecPack"" = "SubEditCodecPack"
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 15
    "{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
    "{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
    "{90110415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{A0B0BCE9-2994-36F2-BE66-D23C884372E8}" = Visual C++ 9.0 OpenMP (x86) WinSXS MSM
    "{AA2EBBCC-4E3B-3442-865E-7BB3E9F45F0C}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
    "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
    "{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
    "{EB5BA578-FF7F-3863-8E53-7A003222B7FC}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
    "{EB6C11E5-449C-3BA3-9086-80B18BCFF947}" = Visual C++ 9.0 OpenMP (x86) WinSXS MSM
    "{FFFF6D5C-E2F1-4B40-BC89-8923312E89EB}}_is1" = ACE Mega CoDecS Pack
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "ALLPlayer V2.X" = ALLPlayer V2.X
    "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
    "Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
    "dumeter3_is1" = DU Meter
    "Gadu-Gadu" = Gadu-Gadu 7.6
    "GameDesire-Pool & Snooker" = GameDesire-Pool & Snooker
    "HijackThis" = HijackThis 2.0.2
    "JDownloader" = JDownloader
    "Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
    "MoorHunt_is1" = MoorHunt 0.6.7.2
    "Mozilla Firefox 4.0 (x86 pl)" = Mozilla Firefox 4.0 (x86 pl)
    "NAPIPROJEKT_is1" = NAPIPROJEKT 1.0.6.2
    "Nero - Burning Rom!UninstallKey" = Nero OEM
    "NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
    "PDF Password Remover v3.1_is1" = PDF Password Remover v3.1
    "PENTAX Digital Camera Utility" = PENTAX Digital Camera Utility
    "Profesor Henry 5.0 - Słownictwo - poziom 1 & 2_is1" = Profesor Henry 5.0 - Słownictwo - poziom 1 & 2
    "Profesor Henry 5.0 - Słownictwo - poziom 3 & 4_is1" = Profesor Henry 5.0 - Słownictwo - poziom 3 & 4
    "RealAlt_is1" = Real Alternative 1.45 Beta 1
    "SlowView" = SlowView
    "SubEdit-Player_is1" = SubEdit-Player
    "SubtitleWorkshop" = Subtitle Workshop 2.51
    "SuperMemo UX - Angielski. No problem!+ 3" = SuperMemo UX - Angielski. No problem!+ 3
    "VLC media player" = VLC media player 0.9.9
    "Winamp" = Winamp
    "WinPcapInst" = WinPcap 4.1.1
    "WinRAR archiver" = WinRAR archiver

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "uTorrent" = µTorrent
    "Winamp Detect" = Winamp Detector Plug-in

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 2011-03-16 14:41:37 | Computer Name = RUCKTION-C14C8C | Source = Application Hang | ID = 1002
    Description = Aplikacja zawieszająca MoorHunt.exe, wersja 0.6.7.2, moduł zawieszenia
    hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

    Error - 2011-03-17 12:22:44 | Computer Name = RUCKTION-C14C8C | Source = ESENT | ID = 490
    Description = svchost (1064) Próba otwarcia pliku "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
    w trybie odczytu lub zapisu zakończyła się niepomyślnie z błędem systemowym 32
    (0x00000020): "Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany
    przez inny proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032
    (0xfffffbf8).

    Error - 2011-03-21 15:06:46 | Computer Name = RUCKTION-C14C8C | Source = ESENT | ID = 490
    Description = svchost (1064) Próba otwarcia pliku "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
    w trybie odczytu lub zapisu zakończyła się niepomyślnie z błędem systemowym 32
    (0x00000020): "Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany
    przez inny proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032
    (0xfffffbf8).

    Error - 2011-03-22 14:07:07 | Computer Name = RUCKTION-C14C8C | Source = Application Error | ID = 1000
    Description = Aplikacja powodująca błąd bestplayer.exe, wersja 2.1.0.263, moduł
    powodujący błąd ffdshow.ax, wersja 0.0.0.0, adres błędu 0x00145674.

    Error - 2011-03-22 15:24:15 | Computer Name = RUCKTION-C14C8C | Source = Application Error | ID = 1000
    Description = Aplikacja powodująca błąd bestplayer.exe, wersja 2.1.0.263, moduł
    powodujący błąd ffdshow.ax, wersja 0.0.0.0, adres błędu 0x00145674.

    Error - 2011-03-28 09:03:28 | Computer Name = RUCKTION-C14C8C | Source = ESENT | ID = 490
    Description = svchost (1064) Próba otwarcia pliku "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
    w trybie odczytu lub zapisu zakończyła się niepomyślnie z błędem systemowym 32
    (0x00000020): "Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany
    przez inny proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032
    (0xfffffbf8).

    Error - 2011-03-31 04:14:20 | Computer Name = RUCKTION-C14C8C | Source = ESENT | ID = 490
    Description = svchost (1064) Próba otwarcia pliku "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
    w trybie odczytu lub zapisu zakończyła się niepomyślnie z błędem systemowym 32
    (0x00000020): "Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany
    przez inny proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032
    (0xfffffbf8).

    Error - 2011-04-03 12:55:03 | Computer Name = RUCKTION-C14C8C | Source = Application Hang | ID = 1002
    Description = Aplikacja zawieszająca firefox.exe, wersja 1.9.2.4095, moduł zawieszenia
    hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

    Error - 2011-04-08 02:31:39 | Computer Name = RUCKTION-C14C8C | Source = Avira AntiVir | ID = 4112
    Description = An error occurred during a resource request to the Windows NT system.
    The resource <avgntflt> has not been allocated. This could be due to an out-of-memory
    error or any other system failure. Returned error code: 0x2

    Error - 2011-04-08 02:33:24 | Computer Name = RUCKTION-C14C8C | Source = Avira AntiVir | ID = 4112
    Description = An error occurred during a resource request to the Windows NT system.
    The resource <avgntflt> has not been allocated. This could be due to an out-of-memory
    error or any other system failure. Returned error code: 0x2

    [ System Events ]
    Error - 2011-04-08 11:11:37 | Computer Name = RUCKTION-C14C8C | Source = Service Control Manager | ID = 7000
    Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu
    następującego błędu: %%2

    Error - 2011-04-08 12:26:17 | Computer Name = RUCKTION-C14C8C | Source = Service Control Manager | ID = 7000
    Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu
    następującego błędu: %%2

    Error - 2011-04-09 04:18:00 | Computer Name = RUCKTION-C14C8C | Source = Service Control Manager | ID = 7000
    Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu
    następującego błędu: %%2

    Error - 2011-04-09 08:39:53 | Computer Name = RUCKTION-C14C8C | Source = Service Control Manager | ID = 7000
    Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu
    następującego błędu: %%2

    Error - 2011-04-10 04:12:41 | Computer Name = RUCKTION-C14C8C | Source = Service Control Manager | ID = 7000
    Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu
    następującego błędu: %%2

    Error - 2011-04-10 08:58:16 | Computer Name = RUCKTION-C14C8C | Source = Service Control Manager | ID = 7000
    Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu
    następującego błędu: %%2

    Error - 2011-04-10 11:27:28 | Computer Name = RUCKTION-C14C8C | Source = Service Control Manager | ID = 7000
    Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu
    następującego błędu: %%2

    Error - 2011-04-10 12:31:31 | Computer Name = RUCKTION-C14C8C | Source = Service Control Manager | ID = 7000
    Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu
    następującego błędu: %%2

    Error - 2011-04-10 13:04:03 | Computer Name = RUCKTION-C14C8C | Source = Service Control Manager | ID = 7000
    Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu
    następującego błędu: %%2

    Error - 2011-04-10 14:24:22 | Computer Name = RUCKTION-C14C8C | Source = Service Control Manager | ID = 7000
    Description = Nie można uruchomić usługi Windows User Mode Driver Framework z powodu
    następującego błędu: %%2


    < End of report >


    Z pliku OTL:

    OTL logfile created on: 2011-04-10 20:27:16 - Run 1
    OTL by OldTimer - Version 3.2.22.3 Folder = D:\instalki\ANTYWIRY
    Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 6.0.2900.2180)
    Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

    1 023,00 Mb Total Physical Memory | 596,00 Mb Available Physical Memory | 58,00% Memory free
    2,00 Gb Paging File | 2,00 Gb Available in Paging File | 86,00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 5,86 Gb Total Space | 1,87 Gb Free Space | 31,91% Space Free | Partition Type: NTFS
    Drive D: | 27,86 Gb Total Space | 3,69 Gb Free Space | 13,23% Space Free | Partition Type: FAT32
    Drive E: | 22,15 Gb Total Space | 1,14 Gb Free Space | 5,14% Space Free | Partition Type: FAT32
    Drive F: | 19,38 Gb Total Space | 3,12 Gb Free Space | 16,10% Space Free | Partition Type: NTFS
    Drive G: | 64,84 Gb Total Space | 2,06 Gb Free Space | 3,18% Space Free | Partition Type: NTFS
    Drive H: | 64,82 Gb Total Space | 4,44 Gb Free Space | 6,85% Space Free | Partition Type: NTFS
    Drive L: | 3,74 Gb Total Space | 2,02 Gb Free Space | 54,07% Space Free | Partition Type: FAT32

    Computer Name: RUCKTION-C14C8C | User Name: maciek | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2011-04-10 20:26:58 | 000,580,608 | ---- | M] (OldTimer Tools) -- D:\instalki\ANTYWIRY\OTL.exe
    PRC - [2011-04-08 13:15:56 | 000,016,856 | ---- | M] (Mozilla Corporation) -- D:\instalki\ROBOCZE\firefox\plugin-container.exe
    PRC - [2011-04-08 13:15:50 | 000,924,632 | ---- | M] (Mozilla Corporation) -- D:\instalki\ROBOCZE\firefox\firefox.exe
    PRC - [2011-03-04 14:36:54 | 000,269,480 | ---- | M] (Avira GmbH) -- D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avguard.exe
    PRC - [2010-08-02 16:10:02 | 000,135,336 | ---- | M] (Avira GmbH) -- D:\instalki\ROBOCZE\Avira\AntiVir Desktop\sched.exe
    PRC - [2010-08-02 16:09:56 | 000,281,768 | ---- | M] (Avira GmbH) -- D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2010-04-01 11:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- H:\instalki robocze\DAEMON Tools Lite\DTLite.exe
    PRC - [2010-01-14 22:11:02 | 000,076,968 | ---- | M] (Avira GmbH) -- D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avshadow.exe
    PRC - [2008-01-11 22:16:38 | 000,039,792 | ---- | M] (Adobe Systems Incorporated) -- D:\instalki\ROBOCZE\adobereader\Reader\reader_sl.exe
    PRC - [2007-01-30 16:58:28 | 001,716,224 | ---- | M] (Gadu-Gadu S.A.) -- D:\instalki\ROBOCZE\Gadu-Gadu\gg.exe
    PRC - [2004-08-04 00:44:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


    ========== Modules (SafeList) ==========

    MOD - [2011-04-10 20:26:58 | 000,580,608 | ---- | M] (OldTimer Tools) -- D:\instalki\ANTYWIRY\OTL.exe
    MOD - [2006-12-21 14:30:44 | 000,102,400 | ---- | M] (Gadu-Gadu S.A.) -- D:\instalki\ROBOCZE\Gadu-Gadu\ggwhook.dll
    MOD - [2004-08-04 00:42:34 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [Auto | Stopped] -- -- (UMWdf)
    SRV - File not found [Disabled | Stopped] -- -- (HidServ)
    SRV - [2011-03-04 14:36:54 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2010-08-02 16:10:02 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- D:\instalki\ROBOCZE\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)


    ========== Driver Services (SafeList) ==========

    DRV - [2011-03-04 16:11:12 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
    DRV - [2011-03-04 14:37:13 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
    DRV - [2010-08-24 15:36:04 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
    DRV - [2010-06-17 15:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
    DRV - [2010-06-17 15:27:14 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avgio.sys -- (avgio)
    DRV - [2010-01-27 04:09:02 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\npf.sys -- (npf)
    DRV - [2009-06-24 16:10:29 | 000,004,261 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rtport.sys -- (rtport)
    DRV - [2004-08-04 01:08:22 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
    DRV - [2002-01-07 19:56:00 | 000,043,648 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viaudio.sys -- (VIAudio) VIA AC'97 Enhanced Audio Controller (WDM)
    DRV - [2001-08-18 00:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
    IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
    IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..browser.search.selectedEngine: "Google"
    FF - prefs.js..browser.search.update: false
    FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"
    FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2
    FF - prefs.js..extensions.enabledItems: jqs(_at_)sun.com:1.0
    FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
    FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.0&q="

    FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: D:\instalki\ROBOCZE\firefox\components [2009-06-24 16:54:02 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: D:\instalki\ROBOCZE\firefox\plugins [2009-06-24 16:54:02 | 000,000,000 | ---D | M]

    [2009-06-24 16:54:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\maciek\Dane aplikacji\Mozilla\Extensions
    [2011-04-10 19:02:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\maciek\Dane aplikacji\Mozilla\Firefox\Profiles\b89nou8g.default\extensions
    [2010-11-11 16:16:02 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\maciek\Dane aplikacji\Mozilla\Firefox\Profiles\b89nou8g.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
    [2010-02-21 11:48:17 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\maciek\Dane aplikacji\Mozilla\Firefox\Profiles\b89nou8g.default\searchplugins\icqplugin-1.xml
    [2010-03-28 10:10:57 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\maciek\Dane aplikacji\Mozilla\Firefox\Profiles\b89nou8g.default\searchplugins\icqplugin-2.xml
    [2010-10-31 17:40:10 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\maciek\Dane aplikacji\Mozilla\Firefox\Profiles\b89nou8g.default\searchplugins\icqplugin-3.xml
    [2011-03-26 16:22:53 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\maciek\Dane aplikacji\Mozilla\Firefox\Profiles\b89nou8g.default\searchplugins\icqplugin-4.xml
    [2011-03-27 12:29:52 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\maciek\Dane aplikacji\Mozilla\Firefox\Profiles\b89nou8g.default\searchplugins\icqplugin-5.xml
    [2008-07-10 14:07:28 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\maciek\Dane aplikacji\Mozilla\Firefox\Profiles\b89nou8g.default\searchplugins\icqplugin.xml
    File not found (No name found) --
    [2009-06-25 09:56:16 | 000,000,000 | ---D | M] (Java Console) -- D:\INSTALKI\ROBOCZE\FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
    [2009-08-27 17:44:24 | 000,000,000 | ---D | M] (Java Console) -- D:\INSTALKI\ROBOCZE\FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    [2009-06-25 09:56:04 | 000,000,000 | ---D | M] (Java Quick Starter) -- D:\INSTALKI\ROBOCZE\JAVA\JRE6\LIB\DEPLOY\JQS\FF

    O1 HOSTS File: ([2011-04-07 21:53:27 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
    O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
    O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\instalki\ROBOCZE\adobereader\Reader\Reader_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [avgnt] D:\instalki\ROBOCZE\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
    O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
    O4 - HKLM..\Run: [NvCplDaemon] File not found
    O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
    O4 - HKCU..\Run: [DAEMON Tools Lite] H:\instalki robocze\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: E&ksport do programu Microsoft Excel - H:\instalki robocze\ms office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
    O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\instalki robocze\ms office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
    O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
    O24 - Desktop WallPaper: C:\Documents and Settings\maciek\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\maciek\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009-06-24 15:49:55 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2011-04-10 19:39:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\maciek\DoctorWeb
    [2011-04-10 19:02:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\maciek\Dane aplikacji\Avira
    [2011-04-10 19:02:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Avira
    [2011-04-10 18:44:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\maciek\Pulpit\Nowy folder (2)
    [2011-04-08 10:15:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Mozilla
    [2011-04-08 10:15:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\Mozilla
    [2011-04-08 08:46:29 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
    [2011-04-08 08:46:28 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
    [2011-04-08 08:46:28 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
    [2011-04-08 08:46:28 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
    [2011-04-08 08:46:28 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
    [2011-04-08 08:46:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Avira
    [2011-04-08 08:29:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\maciek\WINDOWS
    [2011-04-08 08:29:21 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2011-04-07 21:46:30 | 000,000,000 | --SD | C] -- C:\ComboFix(2)
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2011-04-10 20:24:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2011-04-10 19:17:59 | 000,001,008 | ---- | M] () -- C:\WINDOWS\_delis43.ini
    [2011-04-10 19:16:59 | 000,002,675 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
    [2011-04-10 19:16:32 | 000,001,974 | ---- | M] () -- C:\WINDOWS\System32\AUTOEXEC.NT
    [2011-04-10 18:26:20 | 000,028,672 | ---- | M] () -- C:\Documents and Settings\maciek\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011-04-08 17:17:40 | 000,001,891 | ---- | M] () -- C:\WINDOWS\imsins.BAK
    [2011-04-08 08:46:43 | 000,000,759 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Avira AntiVir Control Center.lnk
    [2011-04-07 21:53:27 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2011-03-31 22:12:51 | 000,448,348 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
    [2011-03-31 22:12:51 | 000,392,432 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2011-03-31 22:12:51 | 000,074,450 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
    [2011-03-31 22:12:51 | 000,058,732 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2011-03-31 10:20:30 | 000,000,049 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
    [2011-03-23 19:25:25 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2011-04-10 18:33:12 | 000,001,008 | ---- | C] () -- C:\WINDOWS\_delis43.ini
    [2011-04-08 13:16:10 | 000,000,530 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Mozilla Firefox.lnk
    [2011-04-08 08:46:43 | 000,000,759 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Avira AntiVir Control Center.lnk
    [2010-04-05 18:04:14 | 000,013,116 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
    [2010-01-30 11:12:04 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010-01-27 04:09:02 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
    [2010-01-23 14:02:20 | 000,000,168 | ---- | C] () -- C:\WINDOWS\usdthank.ini
    [2010-01-23 14:02:20 | 000,000,031 | ---- | C] () -- C:\WINDOWS\idc.ini
    [2009-12-02 17:19:40 | 000,000,635 | ---- | C] () -- C:\WINDOWS\Rtcw.INI
    [2009-07-18 22:13:51 | 000,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2009-07-18 08:41:32 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2009-07-18 08:41:32 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2009-07-18 08:41:32 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2009-07-18 08:41:32 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2009-06-27 12:30:06 | 000,001,305 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2009-06-24 17:39:44 | 000,004,722 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2009-06-24 17:38:31 | 000,114,176 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2009-06-24 17:08:14 | 000,028,672 | ---- | C] () -- C:\Documents and Settings\maciek\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2009-06-24 16:54:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
    [2009-06-24 16:20:03 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
    [2009-06-24 16:10:26 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\Autorun.exe
    [2009-06-24 16:10:24 | 000,000,017 | ---- | C] () -- C:\WINDOWS\System32\auto.ini
    [2009-06-24 15:53:12 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
    [2009-06-24 15:46:15 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
    [2004-08-04 00:56:48 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
    [2004-08-04 00:44:00 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
    [2004-08-02 14:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
    [2004-07-17 11:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
    [2004-06-05 12:56:16 | 000,679,936 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
    [2003-03-25 06:49:02 | 000,152,064 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
    [2001-10-26 18:15:16 | 000,448,348 | ---- | C] () -- C:\WINDOWS\System32\perfh015.dat
    [2001-10-26 18:15:16 | 000,313,828 | ---- | C] () -- C:\WINDOWS\System32\perfi015.dat
    [2001-10-26 18:15:16 | 000,074,450 | ---- | C] () -- C:\WINDOWS\System32\perfc015.dat
    [2001-10-26 18:15:16 | 000,034,990 | ---- | C] () -- C:\WINDOWS\System32\perfd015.dat
    [2001-09-17 13:20:02 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
    [2001-08-23 15:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
    [2001-08-23 15:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
    [2001-08-17 23:30:24 | 000,392,432 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
    [2001-08-17 23:30:24 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
    [2001-08-17 23:30:24 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
    [2001-08-17 23:30:22 | 000,058,732 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
    [2001-08-17 23:15:38 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
    [2001-07-22 00:36:48 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
    [2001-07-22 00:36:04 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
    [2001-07-22 00:24:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

    < End of report >


    Proszę poprawić posty - logi wstawiamy w załączniku. Mod.
  • #4 9385262
    Kolobos
    Spec od komputerów
    Posty: 85176
    Pomógł: 17170
    Ocena: 10453
    Twoj problem nie ma zwiazku z tematyka tego dzialu.

    Zrob skan przy pomocy mbam oraz cureit.

    Wykonaj skrypt w OTL:

    :OTL
    IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
    IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
    FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.0&q="
    O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
    [2009-06-24 16:10:26 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\Autorun.exe

    :Commands
    [emptytemp]


    Zainstaluj aktualizacje do programow wskazanych przez: http://screen317.spywareinfoforum.org/SecurityCheck.exe
  • #5 9387258
    peace_maker
    Poziom 12  
    Posty: 103
    Ocena: 2
    Kolobos napisał:
    Twoj problem nie ma zwiazku z tematyka tego dzialu.

    Zrob skan przy pomocy mbam oraz cureit.

    Wykonaj skrypt w OTL:

    :OTL
    IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
    IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
    FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.0&q="
    O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
    [2009-06-24 16:10:26 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\Autorun.exe

    :Commands
    [emptytemp]


    Zainstaluj aktualizacje do programow wskazanych przez: http://screen317.spywareinfoforum.org/SecurityCheck.exe


    skan cureit-em zrobiłem już wcześniej i znalazł jeden niby wir na partycji nie systemowej.

    Wykonaj skrypt w OTL - o co kaman ?? i co to za aktualizacje, które podałeś ??
  • REKLAMA
  • #6 9387388
    Acorus 20
    Poziom 43  
    Posty: 10541
    Pomógł: 3247
    Ocena: 1063
    Ten program wskazuje co należy aktualizować (out of date).
    Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:

    :OTL
    IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
    IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
    FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.0&q="
    O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
    [2009-06-24 16:10:26 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\Autorun.exe

    :Commands
    [emptytemp]

    Kliknij Wykonaj skrypt.
  • REKLAMA
  • #7 9392366
    peace_maker
    Poziom 12  
    Posty: 103
    Ocena: 2
    Acorus 20 napisał:
    Ten program wskazuje co należy aktualizować (out of date).
    Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:

    :OTL
    IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
    IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
    FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.0&q="
    O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
    [2009-06-24 16:10:26 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\Autorun.exe

    :Commands
    [emptytemp]

    Kliknij Wykonaj skrypt.


    czemu to ma służyć jeżeli mogę spytać, chodzi mi o OTL ??

    problem jeżeli chodzi o NTVDM jakoś się rozwiązał po którymś tam skanowaniu cureit-em, choć nie do końca jestem przekonany, że akurat to pomogło. Reperowałem też pliki zalecane w necie więc sam już nie wiem na którym etapie to wróciło do stanu pierwotnego.
  • #8 9392391
    Kolobos
    Spec od komputerów
    Posty: 85176
    Pomógł: 17170
    Ocena: 10453
    OTL usunie podane zbedne wpisy + plik.
  • #9 9400388
    peace_maker
    Poziom 12  
    Posty: 103
    Ocena: 2
    Acorus 20 napisał:
    Ten program wskazuje co należy aktualizować (out of date).
    Uruchom OTL i w okno (Własne opcje skanowania/Script)wklej:

    :OTL
    IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
    IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - Reg Error: Key error. File not found
    FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.0&q="
    O3 - HKLM\..\Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No CLSID value found.
    [2009-06-24 16:10:26 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\Autorun.exe

    :Commands
    [emptytemp]

    Kliknij Wykonaj skrypt.


    ok wykonałem skrypt. przybyło po tym ok 150 MB na dysku C.
  • #10 9401000
    Acorus 20
    Poziom 43  
    Posty: 10541
    Pomógł: 3247
    Ocena: 1063
    W OTL użyj opcji Sprzątanie.Przeskanuj progr.Malwarebytes Anti-Malware.

Podsumowanie tematu

✨ Użytkownik zgłosił problem z błędem NTVDM na systemie Windows XP SP2, sugerując, że może to być spowodowane infekcją. W odpowiedzi na prośbę o pomoc, użytkownicy zalecili skanowanie systemu za pomocą narzędzi CureIt oraz OTL, a także Malwarebytes Anti-Malware. Użytkownik dostarczył logi z HijackThis i OTL, które zawierały informacje o zainstalowanych procesach i potencjalnych zagrożeniach. Po wykonaniu skanowania i zastosowaniu skryptu w OTL, problem z NTVDM częściowo się rozwiązał, a użytkownik zauważył zwolnienie miejsca na dysku. Wskazano również na konieczność aktualizacji oprogramowania.
Podsumowanie AI na podstawie dyskusji. Może zawierać błędy.
REKLAMA