. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_29 Run by jacek at 8:10:42 on 2012-07-18 Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.2047.1492 [GMT 2:00] . AV: Kaspersky Anti-Virus *Disabled/Outdated* {2C4D4BC6-0793-4956-A9F9-E252435469C0} . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\Ati2evxx.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe C:\Program Files\EaseUS\Todo Backup\bin\GuardAgent.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe C:\WINDOWS\V0230Mon.exe C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe C:\Program Files\Portrait Displays\forteManager\DTHtml.exe C:\Program Files\A4Tech\Mouse\Amoumain.exe C:\PROGRA~1\Wanadoo\TaskbarIcon.exe C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\Portrait Displays\Pivot Software\floater.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\WINDOWS\system32\wscntfy.exe C:\TC PowerPack\totalcmd.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\NOTEPAD.EXE . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.fr uInternet Settings,ProxyOverride = *.local uURLSearchHooks: BrotherSoft Extreme Toolbar: {51a86bb3-6602-4c85-92a5-130ee4864f13} - c:\program files\brothersoft_extreme\prxtbBro0.dll uURLSearchHooks: Ashampoo PO Toolbar: {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - c:\program files\ashampoo_po\prxtbAsha.dll mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - BHO: BrotherSoft Extreme Toolbar: {51a86bb3-6602-4c85-92a5-130ee4864f13} - c:\program files\brothersoft_extreme\prxtbBro0.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2011\ievkbd.dll BHO: Ashampoo PO Toolbar: {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - c:\program files\ashampoo_po\prxtbAsha.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: BrotherSoft Extreme Toolbar: {51a86bb3-6602-4c85-92a5-130ee4864f13} - c:\program files\brothersoft_extreme\prxtbBro0.dll TB: Ashampoo PO Toolbar: {d43723ae-1ae1-4a25-a6a4-bf0929273cab} - c:\program files\ashampoo_po\prxtbAsha.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [Gadu-Gadu 10] "c:\program files\gadu-gadu 10\gg.exe" uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe" mRun: [V0230Mon.exe] c:\windows\V0230Mon.exe mRun: [RemoteControl9] "c:\program files\cyberlink\powerdvd9\PDVD9Serv.exe" mRun: [PDVD9LanguageShortcut] "c:\program files\cyberlink\powerdvd9\language\Language.exe" mRun: [PivotSoftware] "c:\program files\portrait displays\pivot software\wpctrl.exe" mRun: [DT LGE] c:\program files\common files\portrait displays\shared\DT_startup.exe -LGE mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin mRun: [WheelMouse] c:\program files\a4tech\mouse\Amoumain.exe mRun: [WOOWATCH] c:\progra~1\wanadoo\Watch.exe mRun: [WOOTASKBARICON] c:\progra~1\wanadoo\TaskbarIcon.exe mRun: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar mRun: [InstantAccess] c:\program files\scanneru\tbridge\bin\InstantAccess.exe /h mRun: [RegisterDropHandler] c:\program files\scanneru\tbridge\bin\RegisterDropHandler.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [EaseUs Watch] "c:\program files\easeus\todo backup\bin\EuWatch.exe" mRun: [EaseUs Tray] "c:\program files\easeus\todo backup\bin\TrayNotify.exe" mRun: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2011\avp.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE IE: E&ksport do programu Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{284FF4D2-2F21-4F0D-8D01-87FB6EFCB84C} : NameServer = 192.168.1.1 TCP: Interfaces\{811F400C-1FC8-4E69-B686-4AB6128AB99D} : DhcpNameServer = 192.168.1.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: klogon - c:\windows\system32\klogon.dll LSA: Authentication Packages = msv1_0 nwprovau . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\jacek\dane aplikacji\mozilla\firefox\profiles\yg3fzps3.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2776682&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ FF - plugin: c:\documents and settings\all users\dane aplikacji\gadu-gadu 10\_userdata\npgg.3.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll . ============= SERVICES / DRIVERS =============== . R0 EUBAKUP;EUBAKUP;c:\windows\system32\drivers\eubakup.sys [2012-5-3 50312] R0 EUBKMON;EUBKMON;c:\windows\system32\drivers\EUBKMON.sys [2012-5-3 43784] R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2009-12-1 40368] R0 KL1;kl1;c:\windows\system32\drivers\kl1.sys [2010-6-9 132184] R1 EUDSKACS;EUDSKACS;c:\windows\system32\drivers\eudskacs.sys [2012-5-3 16008] R1 EUFDDISK;EUFDDISK;c:\windows\system32\drivers\EuFdDisk.sys [2012-5-3 185864] R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352] R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2011-1-19 475736] R2 AVP;Usługa Kaspersky Anti-Virus;c:\program files\kaspersky lab\kaspersky internet security 2011\avp.exe [2010-7-1 352976] R2 EaseUS Agent;EaseUS Agent;c:\program files\easeus\todo backup\bin\Agent.exe [2012-5-3 61064] R2 Guard Agent;Guard Agent;c:\program files\easeus\todo backup\bin\GuardAgent.exe [2012-5-3 23176] R2 Wybór systemu operacyjnego;Aktywator programu Acronis OS Selector;c:\program files\acronis\diskdirector\oss\reinstall_svc.exe [2010-7-5 2155736] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2010-5-7 32856] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19472] R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2011-1-2 27632] R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [2011-5-25 60533] S2 BulkUsb;Plustek USB Scanner;c:\windows\system32\drivers\usbscan.sys [2011-6-13 15104] S2 gupdate;Usługa Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-8 135664] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-7 250056] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2011-1-2 13224] S3 gupdatem;Usługa Google Update (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-5-8 135664] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-16 113120] S3 prwntdrv;prwntdrv;c:\windows\system32\prwntdrv.sys [2012-5-9 13064] S3 TaurusUsb;Siemens ADSL Modem USB Service;c:\windows\system32\drivers\torususb.sys [2011-5-25 688864] S3 V0230Vfx;V0230Vfx;c:\windows\system32\drivers\V0230Vfx.sys [2009-11-26 6272] S3 V0230VID;Live! Cam Video IM Pro;c:\windows\system32\drivers\V0230VID.sys [2009-11-26 500608] S4 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] . =============== Created Last 30 ================ . 2012-07-18 05:35:14 -------- d-sha-r- C:\cmdcons 2012-07-17 15:55:00 -------- d-----w- c:\program files\trend micro 2012-07-17 14:00:46 98816 ----a-w- c:\windows\sed.exe 2012-07-17 14:00:46 518144 ----a-w- c:\windows\SWREG.exe 2012-07-17 14:00:46 256000 ----a-w- c:\windows\PEV.exe 2012-07-17 14:00:46 208896 ----a-w- c:\windows\MBR.exe 2012-07-17 06:42:51 421200 ----a-w- c:\program files\mozilla firefox\msvcp100.dll 2012-07-17 06:42:50 770384 ----a-w- c:\program files\mozilla firefox\msvcr100.dll . ==================== Find3M ==================== . 2012-07-14 06:48:32 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-07-14 06:48:31 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-05-09 22:01:48 170080 ----a-w- c:\windows\system32\drivers\snapman.sys 2012-05-03 14:56:05 400896 --sha-w- C:\EUMONBMP.SYS . ============= FINISH: 8:11:38,23 ===============