DDS (Ver_2012-11-07.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.9.2 Run by unknown at 18:49:52 on 2012-11-27 Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.1524.1092 [GMT 1:00] . . ============== Running Processes ================ . C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre7\bin\jqs.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\Launch Manager\QtZgAcer.EXE C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\igfxext.exe C:\DOCUME~1\unknown\USTAWI~1\Temp\RtkBtMnt.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k bthsvcs C:\WINDOWS\system32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.mks.com.pl/skaner/ BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [RTHDCPL] RTHDCPL.EXE mRun: [PLFSetL] c:\windows\PLFSetL.exe mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [AzMixerSel] c:\program files\realtek\audio\drivers\AzMixerSel.exe mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\unknown\menust~1\programy\autost~1\launch~1.lnk - c:\program files\launch manager\QtZgAcer.EXE uPolicies-Explorer: NoDriveTypeAutoRun = dword:323 uPolicies-Explorer: NoDriveAutoRun = dword:67108863 uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 mPolicies-Explorer: NoDriveTypeAutoRun = dword:323 mPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDriveTypeAutoRun = dword:323 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {68282C51-9459-467B-95BF-3C0E89627E55} - hxxp://www.mks.com.pl/skaner/SkanerOnline.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1353154761531 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab TCP: Interfaces\{4D8BC517-66EF-4234-8A82-4B76B39EBB9D} : NameServer = 195.130.130.3,195.130.131.3 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\unknown\dane aplikacji\mozilla\firefox\profiles\4tfhztq8.default\ FF - prefs.js: browser.search.selectedEngine - Allegro FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\documents and settings\unknown\dane aplikacji\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\unknown\dane aplikacji\mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\documents and settings\unknown\ustawienia lokalne\dane aplikacji\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_110.dll FF - plugin: c:\windows\system32\npDeployJava1.dll FF - plugin: c:\windows\system32\npptools.dll . ============= SERVICES / DRIVERS =============== . R1 oreans32;oreans32;c:\windows\system32\drivers\oreans32.sys [2012-1-31 33824] R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-6-25 35088] R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2009-4-9 96856] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 SkypeUpdate;Skype Updater;c:\daniel\progsy\programy portable\skype v3.5.0.239 pl - portable\skype\updater\Updater.exe [2012-11-9 160944] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-10-22 1691480] S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2009-12-18 11336] S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-7-23 13192] S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-7-23 8456] S3 PortTalk;PortTalk;c:\windows\system32\drivers\porttalk.sys [2011-11-5 3567] S3 PsSdk40;PsSdk40;c:\windows\system32\drivers\pssdk40.sys [2010-11-10 36928] S3 PsSdkLBF;PsSdkLBF;c:\windows\system32\drivers\pssdklbf.sys [2010-11-10 53312] S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys --> c:\windows\system32\drivers\rt2870.sys [?] S3 Sony PC Companion;Sony PC Companion;c:\program files\sony\sony pc companion\PCCService.exe [2011-10-16 155320] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-15 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2012-11-26 20:28:33 -------- d-----w- c:\windows\system32\wbem\repository\FS 2012-11-26 20:28:33 -------- d-----w- c:\windows\system32\wbem\Repository 2012-11-26 20:27:18 -------- d-----w- c:\program files\Handset WinDriver 2012-11-26 20:27:12 -------- d-----w- c:\program files\Convar 2012-11-26 20:27:12 -------- d-----w- c:\program files\Babylon 2012-11-26 20:27:11 -------- d-----w- c:\program files\DAEMON Tools Lite 2012-11-24 17:29:12 -------- d-----w- c:\documents and settings\unknown\dane aplikacji\Proxifier 2012-11-24 17:28:38 -------- d-----w- c:\program files\Proxifier 2012-11-20 18:39:33 -------- d-----w- c:\documents and settings\unknown\dane aplikacji\Process Hacker 2 2012-11-18 18:51:51 -------- d-----w- c:\windows\RegLooks 2012-11-18 18:41:14 -------- d-----w- c:\program files\trend micro 2012-11-18 09:01:41 275696 ----a-w- c:\windows\system32\mucltui.dll 2012-11-18 09:01:41 18160 ----a-w- c:\windows\system32\mucltui.dll.mui 2012-11-17 19:48:01 -------- d-----w- c:\documents and settings\unknown\ustawienia lokalne\dane aplikacji\Microsoft_Corporation 2012-11-17 16:46:24 -------- d-----w- c:\program files\common files\Borland Shared 2012-11-17 13:27:53 14048 ------w- c:\windows\system32\spmsg2.dll 2012-11-17 13:23:17 -------- d-----w- c:\documents and settings\unknown\dane aplikacji\Windows Search 2012-11-17 12:35:24 -------- d-----w- c:\windows\system32\winrm 2012-11-17 12:35:20 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$ 2012-11-17 12:34:19 -------- d-----w- c:\windows\system32\GroupPolicy 2012-11-17 12:34:19 -------- d-----w- c:\program files\Windows Desktop Search 2012-11-16 20:33:05 1866624 ----a-w- c:\windows\system32\win32k.sys 2012-11-16 20:11:06 -------- d-----w- c:\documents and settings\unknown\ustawienia lokalne\dane aplikacji\PCHealth . ==================== Find3M ==================== . 2012-11-21 18:43:11 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-11-21 18:43:11 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-11-17 21:02:12 7844 ----a-w- C:\kopia_reg.reg 2012-10-02 18:04:38 58368 ----a-w- c:\windows\system32\synceng.dll 2012-09-24 21:16:36 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2012-09-02 11:34:21 821736 ----a-w- c:\windows\system32\npDeployJava1.dll 2012-09-02 11:34:21 746984 ----a-w- c:\windows\system32\deployJava1.dll . ============= FINISH: 18:50:13,20 ===============