
Od kilku dni nurtują mnie dwie rzeczy, gdy uruchamiam komputer, po czym wchodze do gry jakiejkolwiek to nie ma w niej głosu, wychodzę i patrze w panel sterowania a tu sterowniki do głosu usnięte samoistnie, gdyż na początku gdy uruchamiam windows głos jest i wszystko ok. Po wyjściu z jakiejkolwiek gry zauważyłem ze zmienia się wygląd mojego windowsa, pasek menu na dole zmienia styl na windws98.
Prosze o sprawdzenie log
HijackThis:
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:37:23, on 2008-11-29
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Prime95\prime95.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Documents and Settings\Mój komputer\Pulpit\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ati.com/online/cccwelcome/drivers.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: D - {F51766C3-4635-3137-A458-E929397DE96B} - C:\WINDOWS\system32\xwr26220.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: (no name) - {37B85A29-692B-4205-9CAD-2626E4993404} - (no file)
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [Six Engine] "C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe" -r
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [QFan Help] "C:\Program Files\ASUS\AI Suite\QFan3\QFanHelp.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\Run: [IDMan] d:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Startup: Need for Speed™ Undercover Registration.lnk = D:\Program Files\EA GAMES\Need for Speed Undercover\Support\EAregister.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKfox000
O8 - Extra context menu item: Ściągnij przez IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Ściągnij wszystkie linki przez IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Ściągnij zawartość wideo FLV przez IDM - D:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1222236355343
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Prime95 Service - Unknown owner - C:\Program Files\Prime95\prime95.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 9702 bytes
ComboFix:
- Kod: Zaznacz wszystko
ComboFix 08-11-28.03 - Mój komputer 2008-11-29 19:38:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.2719 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Mój komputer\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mój komputer\Dane aplikacji\FunWebProducts
c:\documents and settings\Mój komputer\Dane aplikacji\FunWebProducts\Data\Mój komputer\wffavs.dat
c:\documents and settings\Mój komputer\Menu Start\Cheap Pharmacy Online.url
c:\documents and settings\Mój komputer\Menu Start\Search Online.url
c:\documents and settings\Mój komputer\Ulubione\Cheap Pharmacy Online.url
c:\documents and settings\Mój komputer\Ulubione\Search Online.url
c:\program files\FunWebProducts
c:\program files\FunWebProducts\ScreenSaver\Images\[u]0[/u]13B91A5.urr
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\FunWebProducts\Shared\Cache\WebfettiBtn-new.htmlx
c:\program files\FunWebProducts\Shared\Cache\WebfettiBtn.html
c:\program files\Gene6 FTP Server
c:\program files\Gene6 FTP Server\Accounts\Ble\settings.ini
c:\program files\Gene6 FTP Server\Accounts\Ble\users\Anonymous.ini
c:\program files\Gene6 FTP Server\Accounts\settings.ini
c:\program files\Gene6 FTP Server\Backup\Administrator.reg
c:\program files\Gene6 FTP Server\Backup\RemoteAdmin\Remote.ini
c:\program files\Gene6 FTP Server\languages.sib
c:\program files\Gene6 FTP Server\Log\Ble-2008-09.log
c:\program files\Gene6 FTP Server\RemoteAdmin\Log\Admin-08-09-24.log
c:\program files\Gene6 FTP Server\RemoteAdmin\Remote.ini
c:\program files\Gene6 FTP Server\RemoteAdmin\RemoteAdmin.crt
c:\program files\Gene6 FTP Server\RemoteAdmin\RemoteAdmin.key
c:\program files\Mozilla Firefox\plugins\NPMyGlSh.dll
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
c:\program files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
c:\program files\MyWebSearch\bar\1.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MSG.DLL
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSSVC.EXE
c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Cache\[u]0[/u]0012EBC
c:\program files\MyWebSearch\bar\Cache\[u]0[/u]05DF018
c:\program files\MyWebSearch\bar\Cache\[u]0[/u]0ECA348.bin
c:\program files\MyWebSearch\bar\Cache\[u]0[/u]139A4A9
c:\program files\MyWebSearch\bar\Cache\[u]0[/u]139A65F.bin
c:\program files\MyWebSearch\bar\Cache\[u]0[/u]139A9F9.bin
c:\program files\MyWebSearch\bar\Cache\[u]0[/u]139B68C.bin
c:\program files\MyWebSearch\bar\Cache\[u]0[/u]139B7B4.bin
c:\program files\MyWebSearch\bar\Cache\[u]0[/u]139B8ED.bin
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
c:\windows\system32\Dvbpws.dll
c:\windows\system32\f3PSSavr.scr
c:\windows\system32\NCTAudioInformation2.dll
c:\windows\system32\s.ico
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_MyWebSearchService
((((((((((((((((((((((((( Pliki utworzone od 2008-10-28 do 2008-11-29 )))))))))))))))))))))))))))))))
.
2008-11-29 16:43 . 2007-11-14 08:18 553 -r------- c:\windows\USetup.iss
2008-11-28 20:36 . 2008-11-28 20:36 5,444,880 --a------ c:\windows\system32\xa4863343.exe
2008-11-28 20:36 . 2008-11-28 20:36 5,444,880 --a------ c:\windows\system32\xa4862984.exe
2008-11-28 20:31 . 2008-11-28 20:31 5,444,880 --a------ c:\windows\system32\xa4566984.exe
2008-11-28 20:31 . 2008-11-28 20:31 5,444,880 --a------ c:\windows\system32\xa4566593.exe
2008-11-28 20:29 . 2008-11-28 20:29 5,444,880 --a------ c:\windows\system32\xa4425437.exe
2008-11-28 20:29 . 2008-11-28 20:29 5,444,880 --a------ c:\windows\system32\xa4425015.exe
2008-11-28 20:24 . 2008-11-28 20:24 5,444,880 --a------ c:\windows\system32\xa4125500.exe
2008-11-28 20:24 . 2008-11-28 20:24 5,444,880 --a------ c:\windows\system32\xa4125140.exe
2008-11-28 20:22 . 2008-11-28 20:22 5,444,880 --a------ c:\windows\system32\xa4036000.exe
2008-11-28 20:22 . 2008-11-28 20:22 5,444,880 --a------ c:\windows\system32\xa4035468.exe
2008-11-28 20:21 . 2008-11-28 20:21 <DIR> d-------- c:\windows\system32\zone
2008-11-28 20:20 . 2008-10-09 21:47 348,928 --a------ c:\windows\system32\code_post_gfx.ff
2008-11-28 20:19 . 2008-11-28 20:19 5,444,880 --a------ c:\windows\system32\xa3831375.exe
2008-11-28 20:19 . 2008-11-28 20:19 5,444,880 --a------ c:\windows\system32\xa3831015.exe
2008-11-28 20:17 . 2008-11-28 20:17 5,444,880 --a------ c:\windows\system32\xa3739296.exe
2008-11-28 20:17 . 2008-11-28 20:17 5,444,880 --a------ c:\windows\system32\xa3738875.exe
2008-11-28 20:17 . 2008-11-28 20:17 176,128 --a------ c:\windows\system32\xwr26220.dll
2008-11-28 20:17 . 2008-11-28 20:17 176,128 --a------ c:\windows\system32\wr26220.dll
2008-11-28 18:48 . 2008-11-28 18:48 319,488 --a------ c:\windows\HideWin.exe
2008-11-24 21:59 . 2008-11-24 21:59 <DIR> d-------- c:\program files\Common Files\COWON
2008-11-24 21:59 . 2008-11-24 21:59 <DIR> d-------- c:\documents and settings\Mój komputer\Dane aplikacji\COWON
2008-11-24 21:59 . 2008-11-24 21:59 <DIR> d-------- c:\documents and settings\Mój komputer\Dane aplikacji\COWON
2008-11-24 21:59 . 2008-11-24 21:59 <DIR> d-------- c:\documents and settings\Mój komputer\Dane aplikacji\COWON
2008-11-24 20:16 . 2008-08-05 20:10 1,684,736 --a------ c:\windows\system32\drivers\Ambfilt.sys
2008-11-24 20:16 . 2006-01-04 15:41 1,389,056 --a------ c:\windows\system32\drivers\Monfilt.sys
2008-11-24 20:16 . 2008-11-10 15:35 34,816 --a------ c:\windows\system32\RtkCoInstXP.dll
2008-11-24 19:55 . 2008-11-24 19:55 <DIR> d-------- c:\program files\4U Computing
2008-11-24 19:55 . 2002-12-03 03:02 491,520 --a------ c:\windows\system32\NCTAudioFile.dll
2008-11-24 19:55 . 2002-01-05 07:37 344,064 --a------ c:\windows\system32\msvcr70.dll
2008-11-24 19:55 . 2003-03-25 15:08 286,720 --a------ c:\windows\system32\NCTWMAFile2.dll
2008-11-24 19:55 . 2002-12-03 03:07 168,448 --a------ c:\windows\system32\NCTAudioPlayer.dll
2008-11-24 19:55 . 2002-12-03 03:11 143,872 --a------ c:\windows\system32\NCTWMAFile.dll
2008-11-24 19:55 . 2002-03-19 07:18 120,832 --a------ c:\windows\system32\lame_enc.dll
2008-11-24 12:43 . 2008-11-24 12:43 <DIR> d-------- c:\program files\Common Files\Totem Shared
2008-11-24 12:43 . 2008-11-24 12:43 4 --a------ c:\windows\num41.jbd
2008-11-24 12:43 . 2008-11-24 12:43 4 --a------ c:\windows\info147.sys
2008-11-24 12:43 . 2008-11-24 12:43 4 --a------ c:\windows\data4711.bak
2008-11-23 13:31 . 2008-11-23 13:32 <DIR> d-------- c:\program files\Hamachi
2008-11-23 12:21 . 2008-11-23 12:21 <DIR> d-------- c:\program files\VID_0E8F&PID_0003
2008-11-15 10:45 . 2008-11-15 10:45 <DIR> d-------- c:\documents and settings\Mój komputer\Dane aplikacji\Sports Interactive
2008-11-15 10:45 . 2008-11-15 10:45 <DIR> d-------- c:\documents and settings\Mój komputer\Dane aplikacji\Sports Interactive
2008-11-15 10:45 . 2008-11-15 10:45 <DIR> d-------- c:\documents and settings\Mój komputer\Dane aplikacji\Sports Interactive
2008-11-15 10:45 . 2008-11-15 10:45 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Sports Interactive
2008-11-12 18:53 . 2008-11-12 18:53 <DIR> d-------- c:\program files\Activision
2008-11-12 18:47 . 2008-11-12 18:47 <DIR> d--hs---- c:\windows\ftpcache
2008-11-11 11:01 . 2008-11-11 11:01 <DIR> d-------- c:\program files\HyperSnap-DX 5
2008-11-09 17:23 . 2008-11-09 17:23 <DIR> d-------- c:\program files\Common Files\DirectX
2008-11-09 17:21 . 2008-11-09 17:21 32 --a------ c:\windows\ZSAM.INI
2008-10-29 19:20 . 2008-10-29 19:38 <DIR> d-------- c:\program files\Prime95
2008-10-29 18:50 . 2008-10-29 18:50 <DIR> d-------- c:\program files\Tibia
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-29 18:41 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Hamachi
2008-11-29 18:41 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Hamachi
2008-11-29 18:41 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Hamachi
2008-11-29 18:41 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\DMCache
2008-11-29 18:41 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\DMCache
2008-11-29 18:41 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\DMCache
2008-11-29 18:30 138,184 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-28 19:17 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-23 12:31 25,280 ----a-w c:\windows\system32\drivers\hamachi.sys
2008-11-22 18:52 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\mIRC
2008-11-22 18:52 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\mIRC
2008-11-22 18:52 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\mIRC
2008-11-22 15:58 --------- d-----w c:\program files\mIRC
2008-11-22 10:49 4,000 ----a-w C:\ao.dat
2008-11-18 14:12 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Ahead
2008-11-18 14:12 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Ahead
2008-11-18 14:12 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Ahead
2008-11-13 18:48 --------- d---a-w c:\documents and settings\All Users\Dane aplikacji\TEMP
2008-11-12 18:04 22,328 ----a-w c:\documents and settings\Mój komputer\Dane aplikacji\PnkBstrK.sys
2008-11-12 18:04 22,328 ----a-w c:\documents and settings\Mój komputer\Dane aplikacji\PnkBstrK.sys
2008-11-12 18:04 22,328 ----a-w c:\documents and settings\Mój komputer\Dane aplikacji\PnkBstrK.sys
2008-10-29 18:29 --------- d-----w c:\program files\ASUS
2008-10-29 18:10 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Skype
2008-10-29 18:10 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Skype
2008-10-29 18:10 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Skype
2008-10-29 17:36 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\skypePM
2008-10-29 17:36 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\skypePM
2008-10-29 17:36 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\skypePM
2008-10-27 18:12 --------- d-----w c:\program files\FIFApatcher
2008-10-24 05:15 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Tibia
2008-10-24 05:15 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Tibia
2008-10-24 05:15 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Tibia
2008-10-23 17:35 --------- d-----w c:\program files\NAPI-PROJEKT
2008-10-21 17:04 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Ventrilo
2008-10-21 17:04 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Ventrilo
2008-10-21 17:04 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Ventrilo
2008-10-21 16:59 --------- d-----w c:\program files\Ventrilo
2008-10-21 16:59 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-21 13:09 --------- d-----w c:\program files\Asprate
2008-10-20 17:43 --------- d-----w c:\program files\Akademicki
2008-10-20 12:10 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\TibiaTestserver
2008-10-20 12:10 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\TibiaTestserver
2008-10-20 12:10 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\TibiaTestserver
2008-10-20 12:08 --------- d-----w c:\program files\Eloth
2008-10-18 15:08 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\KONAMI
2008-10-18 13:15 --------- d-----w c:\program files\WypasOT Client 8.31
2008-10-17 13:10 --------- d-----w c:\program files\Tibia Auto
2008-10-15 15:10 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Lavasoft
2008-10-15 15:08 --------- d-----w c:\program files\Lavasoft
2008-10-15 14:47 --------- d-----w c:\program files\Trend Micro
2008-10-14 10:09 --------- d-----w c:\program files\Nero
2008-10-14 10:09 --------- d-----w c:\program files\Common Files\Ahead
2008-10-14 10:09 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Nero
2008-10-14 09:10 --------- d-----w c:\program files\Winamp
2008-10-14 09:10 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Winamp
2008-10-14 09:10 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Winamp
2008-10-14 09:10 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Winamp
2008-10-12 18:06 --------- d-----w c:\program files\BearShare
2008-10-11 14:07 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Samsung
2008-10-11 14:07 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Samsung
2008-10-11 14:07 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Samsung
2008-10-11 13:25 --------- d-----w c:\program files\Samsung
2008-10-10 17:51 --------- d--h--r c:\documents and settings\Mój komputer\Dane aplikacji\SecuROM
2008-10-10 17:51 --------- d--h--r c:\documents and settings\Mój komputer\Dane aplikacji\SecuROM
2008-10-10 17:51 --------- d--h--r c:\documents and settings\Mój komputer\Dane aplikacji\SecuROM
2008-10-10 17:42 --------- d-----w c:\program files\AGEIA Technologies
2008-10-09 18:35 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\OpenOffice.ux.pl2
2008-10-09 18:35 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\OpenOffice.ux.pl2
2008-10-09 18:35 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\OpenOffice.ux.pl2
2008-10-05 08:48 --------- d-----w c:\program files\KONAMI
2008-10-03 14:27 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Leadertech
2008-10-03 14:27 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Leadertech
2008-10-03 14:27 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\Leadertech
2008-10-03 14:15 --------- d-----w c:\program files\EA SPORTS
2008-10-01 19:10 --------- d-----w c:\program files\Skype
2008-10-01 19:10 --------- d-----w c:\program files\Common Files\Skype
2008-10-01 19:10 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Skype
2008-09-30 15:42 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\IDM
2008-09-30 15:42 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\IDM
2008-09-30 15:42 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\IDM
2008-09-28 18:18 --------- d-----w c:\program files\Teamspeak2_RC2
2008-09-28 18:18 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\teamspeak2
2008-09-28 18:18 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\teamspeak2
2008-09-28 18:18 --------- d-----w c:\documents and settings\Mój komputer\Dane aplikacji\teamspeak2
2008-09-28 14:02 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\ArcSoft
2008-09-27 15:17 7,060 ----a-w c:\documents and settings\Mój komputer\FMCodec.dat
2008-09-27 15:17 7,060 ----a-w c:\documents and settings\Mój komputer\FMCodec.dat
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F51766C3-4635-3137-A458-E929397DE96B}]
2008-11-28 20:17 176128 --a------ c:\windows\system32\xwr26220.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2007-11-14 2131392]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-07-22 2772992]
"IDMan"="d:\program files\Internet Download Manager\IDMan.exe" [2008-09-12 2606512]
"WinFast Schedule"="c:\program files\WinFast\WFDTV\WFWIZ.exe" [2008-06-20 2887680]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"Six Engine"="c:\program files\ASUS\EPU-4 Engine\FourEngine.exe" [2008-06-25 5625344]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"WinFastDTV"="c:\program files\WinFast\WFDTV\DTVSchdl.exe" [2008-07-11 90112]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-11-20 178688]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2008-05-26 1423360]
"QFan Help"="c:\program files\ASUS\AI Suite\QFan3\QFanHelp.exe" [2008-05-06 594432]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"RTHDCPL"="RTHDCPL.EXE" [2008-06-13 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\M˘j komputer\Menu Start\Programy\Autostart\
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2008-11-23 625952]
Need for Speedt Undercover Registration.lnk - d:\program files\EA GAMES\Need for Speed Undercover\Support\EAregister.exe [2008-10-22 4369408]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Mój komputer^Menu Start^Programy^Autostart^hamachi.lnk]
path=c:\documents and settings\Mój komputer\Menu Start\Programy\Autostart\hamachi.lnk
backup=c:\windows\pss\hamachi.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Mój komputer^Menu Start^Programy^Autostart^OpenOffice.ux.pl 2.3.1.lnk]
path=c:\documents and settings\Mój komputer\Menu Start\Programy\Autostart\OpenOffice.ux.pl 2.3.1.lnk
backup=c:\windows\pss\OpenOffice.ux.pl 2.3.1.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-09 17:53 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-09-29 16:57 21755688 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-08-04 00:02 36352 c:\program files\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"d:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"d:\\Program Files\\Pro Evolution Soccer 2008\\PES2008.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"d:\\Program Files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Program Files\\Ubisoft\\Gearbox Software\\Brothers in Arms - Hell's Highway\\Binaries\\biahh.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Mój komputer\\Pulpit\\vty-0213\\pes2009.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"d:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Documents and Settings\\Mój komputer\\Pulpit\\rld-pro9\\pes2009.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-09-24 78416]
R2 ACDaemon;ArcSoft Connect Daemon;c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-09-27 109056]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-09-24 20560]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-09-23 93696]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\l1e51x86.sys [2008-09-23 36864]
S3 WFIOCTL;WFIOCTL;\??\c:\program files\WinFast\WFDTV\WFIOCTL.SYS []
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
.
------- Skan uzupełniający -------
.
FireFox -: Profile - c:\documents and settings\Mój komputer\Dane aplikacji\Mozilla\Firefox\Profiles\g7uiga9p.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.pl
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-29 19:41:03
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(804)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\dumprep.exe
c:\program files\Prime95\Prime95.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Czas ukończenia: 2008-11-29 19:42:35 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-11-29 18:42:33
Przed: 6 934 142 976 bajtów wolnych
Po: 7,213,387,776 bajtów wolnych
394
PROSZE O SZYBKA POMOC!