Rezultaty skanowania Farbar Recovery Scan Tool (FRST) (x86) Wersja:23-09-2015 Uruchomiony przez Tomal2 (administrator) UNSEEN-66B25762 (23-09-2015 15:19:17) Uruchomiony z C:\Documents and Settings\Tomal2\Moje dokumenty\scan Załadowane profile: Tomal2 (Dostępne profile: Tomal2 & Administrator) Platform: Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) Język: Polski Internet Explorer Wersja 8 (Domyślna przeglądarka: FF) Tryb startu: Normal Instrukcja obsługi Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Procesy (filtrowane) ================= (Załączenie wejścia w fixlist spowoduje zamknięcie procesu. Powiązany plik nie zostanie przeniesiony.) (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Antivirus Pro 2010\WebProxy.exe (ATI Technologies Inc.) C:\WINDOWS\system32\ati2evxx.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Antivirus Pro 2010\PsCtrlS.exe (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Antivirus Pro 2010\PavFnSvr.exe (Panda Security, S.L.) C:\Program Files\Common Files\Panda Security\PavShld\PavPrSrv.exe (Panda Security S.L.) C:\Program Files\Panda Security\Panda Antivirus Pro 2010\PsImSvc.exe (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Antivirus Pro 2010\psksvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Antivirus Pro 2010\PAVSRV51.EXE (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Antivirus Pro 2010\AVENGINE.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Antivirus Pro 2010\ApVxdWin.exe (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe (Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe (Microsoft Corporation) C:\Program Files\Messenger\msmsgs.exe (Gadwin Systems, Inc) C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Panda Security S.L.) C:\Program Files\Panda Security\Panda Antivirus Pro 2010\avciman.exe (Panda Security, S.L.) C:\Program Files\Panda Security\Panda Antivirus Pro 2010\Upgrader.exe (Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe ==================== Rejestr (filtrowane) =========================== (Załączenie wejścia w fixlist spowoduje usunięcie obiektu z rejestru lub przywrócenie jego domyślnej postaci. Powiązany plik nie zostanie przeniesiony.) HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [18791456 2010-02-22] (Realtek Semiconductor Corp.) HKLM\...\Run: [APVXDWIN] => C:\Program Files\Panda Security\Panda Antivirus Pro 2010\APVXDWIN.EXE [906496 2009-09-25] (Panda Security, S.L.) HKLM\...\Run: [SCANINICIO] => C:\Program Files\Panda Security\Panda Antivirus Pro 2010\Inicio.exe [56064 2009-08-12] (Panda Security, S.L.) HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2010-03-17] (Apple Inc.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2010-02-10] (Advanced Micro Devices, Inc.) HKLM\...\Run: [MSConfig] => C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [171520 2008-04-14] (Microsoft Corporation) Winlogon\Notify\AtiExtEvent: C:\WINDOWS\SYSTEM32\Ati2evxx.dll [2010-02-11] (ATI Technologies Inc.) Winlogon\Notify\avldr: C:\WINDOWS\SYSTEM32\avldr.dll [2008-03-18] (Panda Security, S.L.) HKU\S-1-5-21-606747145-1677128483-1417001333-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd) HKU\S-1-5-21-606747145-1677128483-1417001333-1003\...\Run: [MSMSGS] => C:\Program Files\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKU\S-1-5-21-606747145-1677128483-1417001333-1003\...\Run: [Gadwin PrintScreen] => C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe [495616 2008-12-09] (Gadwin Systems, Inc) HKU\S-1-5-21-606747145-1677128483-1417001333-1003\...\MountPoints2: {0c121681-f053-11e2-9b3b-001d60f81eb8} - F:\wubi.exe HKU\S-1-5-21-606747145-1677128483-1417001333-1003\...\MountPoints2: {c64795d6-0646-11e2-97fb-001d60f81eb8} - F:\RunClubSanDisk.exe ShellIconOverlayIdentifiers: [SmartFTP Drop] -> {EA5A76F7-8138-4B53-B0F5-ADCC730CAFBD} => C:\Program Files\SmartFTP Client\sfShellTools.dll [2011-09-29] (SmartSoft Ltd.) Startup: C:\Documents and Settings\Tomal2\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk [2013-09-23] ShortcutTarget: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <======= UWAGA ==================== Internet (filtrowane) ==================== (Załączenie wejścia w fixlist, w przypadku gdy jest to obiekt rejestru, spowoduje usunięcie go z rejestru lub przywrócenie jego domyślnej postaci.) Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [94208 2006-02-28] (Apple Computer, Inc.) Hosts: W pliku Hosts jest więcej niż jedno wejście. Sprawdź sekcję Hosts w Addition.txt Tcpip\Parameters: [DhcpNameServer] 89.238.0.5 8.8.8.8 Tcpip\..\Interfaces\{0FAF8BF6-2719-413F-864C-3CC5954EBE68}: [DhcpNameServer] 89.238.0.5 8.8.8.8 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\S-1-5-21-606747145-1677128483-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-606747145-1677128483-1417001333-1003 -> {5F970FDE-702B-4ef9-920C-5F2848A5AF26} URL = hxxp://www.astroburn-search.com/search/web?q={searchTerms} BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll [2013-02-05] (McAfee, Inc.) BHO: DivX Plus Web Player HTML5