

(jak wcisnę OK, to pokazuje się następny, tylko nazwa pliku się zmienia (tmp3D.tmp, tmp3E.tmp, tmp3F.tmp, tmp40.tmp, tmp41.tmp, itd.)
Zakażony plik najprawdopodobniej został ściągnięty przez torrenta, brat wyłączył Nortona, a ja tego nie zauważyłam. Komputer bardzo wolno działa, mam też wrażenie, że ubywa miejsca na dysku C. Przeskanowałam komputer SDFix'em w trybie awaryjnym, tutaj jest raport:
SDFix: Version 1.208
Run by User on 2008-07-26 at 03:17
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\Documents and Settings\User\Dane aplikacji\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.redtube.com\settings.sol - Deleted
Folder C:\Documents and Settings\User\Dane aplikacji\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.redtube.com - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-26 03:27:51
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s0"=dword:d4b484da
"s1"=dword:b965653c
"s2"=dword:bc1edf8f
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="D:\Programy\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:1f,90,16,ae,84,56,41,82,73,4a,31,90,60,39,4d,c9,33,02,14,28,95,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,c8,59,10,0c,79,5b,88,37,10,14,04,93,2c,a2,01,f8,8e,..
"khjeh"=hex:15,b8,d0,29,b4,c2,91,1e,bf,2d,c9,07,dc,81,00,f5,7f,1a,8f,5f,64,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:44,a7,2d,35,3b,e2,07,84,4e,9c,c1,18,ab,03,0c,d5,0e,3a,a8,92,72,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="D:\Programy\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:1f,90,16,ae,84,56,41,82,73,4a,31,90,60,39,4d,c9,33,02,14,28,95,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,c8,59,10,0c,79,5b,88,37,10,14,04,93,2c,a2,01,f8,8e,..
"khjeh"=hex:15,b8,d0,29,b4,c2,91,1e,bf,2d,c9,07,dc,81,00,f5,7f,1a,8f,5f,64,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:44,a7,2d,35,3b,e2,07,84,4e,9c,c1,18,ab,03,0c,d5,0e,3a,a8,92,72,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
scanning hidden files ...
C:\WINDOWS\temp\tmp4ED.tmp 914944 bytes
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"F:\\Program Files\\Orbit Downloader\\orbitdm.exe"="F:\\Program Files\\Orbit Downloader\\orbitdm.exe:*:Enabled:Orbit"
"F:\\Program Files\\Orbit Downloader\\orbitnet.exe"="F:\\Program Files\\Orbit Downloader\\orbitnet.exe:*:Enabled:Orbit"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"F:\\Program Files\\Konnekt\\konnekt.exe"="F:\\Program Files\\Konnekt\\konnekt.exe:*:Enabled:Konnekt - Core"
"F:\\Program Files\\VLC\\vlc.exe"="F:\\Program Files\\VLC\\vlc.exe:*:Enabled:VLC media player"
"F:\\Program Files\\Free Download Manager\\fdm.exe"="F:\\Program Files\\Free Download Manager\\fdm.exe:*:Enabled:Free Download Manager"
"E:\\eMule\\emule.exe"="E:\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"F:\\Program Files\\DAP\\DAP.exe"="F:\\Program Files\\DAP\\DAP.exe:*:Enabled:Download Accelerator Plus (DAP)"
"F:\\Program Files\\AQQ\\AQQ.exe"="F:\\Program Files\\AQQ\\AQQ.exe:*:Enabled:P2P AQQ"
"F:\\Program Files\\Tlen.pl\\tlen.exe"="F:\\Program Files\\Tlen.pl\\tlen.exe:*:Enabled:Komunikator Tlen.pl"
"F:\\Program Files\\Gadu-Gadu\\gg.exe"="F:\\Program Files\\Gadu-Gadu\\gg.exe:*:Enabled:Gadu-Gadu - program glowny"
"F:\\Program Files\\eMule\\emule.exe"="F:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
"F:\\Program Files\\uTorrent\\uTorrent.exe"="F:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
"F:\\Program Files\\Skype\\Phone\\Skype.exe"="F:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Mon 21 Jul 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 21 Jul 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 27 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\523d056929e13eacf8392044f602e53e\BIT3E.tmp"
Tue 24 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\abf37927fe96bc682b342849c5743771\BIT14.tmp"
Fri 27 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\afa5528a2269b5106016bdbc1ea3037f\BIT3A.tmp"
Tue 24 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\baf5873d097c20aedd3e06e2ff27a933\BITD.tmp"
Fri 27 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT34.tmp"
Finished!
Logi z:
Hijack This
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58, on 2008-07-26
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\Emil Junior\Dragdiag.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
D:\Programy\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Orbit Downloader\orbitnet.exe
C:\Documents and Settings\User\Pulpit\WIRUS\HiJackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - F:\Program Files\Orbit Downloader\orbitcth.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - F:\Program Files\Real Player\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - F:\Program Files\Bit Comet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - F:\Program Files\Orbit Downloader\GrabPro.dll
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - F:\PROGRA~1\FRESHD~1\fdiebar.dll (file missing)
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "F:\Program Files\Emil Junior\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
O4 - HKLM\..\Run: [DAEMON Tools] "D:\Programy\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Komunikator] F:\Program Files\Tlen.pl\tlen.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://F:\Program Files\Bit Comet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://F:\Program Files\Bit Comet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://F:\Program Files\Bit Comet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://F:\Program Files\Bit Comet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: FreshDownload - {E94C521D-98A5-4449-95EB-0E180785AC13} - F:\Program Files\FreshDownload\fd.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0312336-BAD3-4A17-A16C-617E4B05A5A9}: NameServer = 80.244.140.241 80.244.128.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 8784 bytes
i
DSS (z Combofix'a nie mogę zrobić, kompa skanuje bez problemu, ale raport tworzył przez ponad 5 godzin i nic)
Deckard's System Scanner v20071014.68
Run by User on 2008-07-26 11:42:34
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
16: 2008-07-26 09:43:13 UTC - RP170 - Deckard's System Scanner Restore Point
15: 2008-07-25 21:30:45 UTC - RP169 - ComboFix created restore point
14: 2008-07-24 16:57:27 UTC - RP168 - Instalacja niepodpisanego sterownika
13: 2008-07-23 00:18:22 UTC - RP167 - Installed Ulead GIF Animator
12: 2008-07-22 22:27:53 UTC - RP166 - Operacja przywracania
-- First Restore Point --
1: 2008-07-12 07:47:18 UTC - RP155 - Installed PC Inspector File Recovery
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 0.58 GiB (less than 15%) free.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-07-26 11:45:24
Platform: Windows XP Dodatek Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
C:\Program Files\ESET\nod32krn.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVSCAN.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ESET\nod32kui.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
F:\Program Files\Emil Junior\dragdiag.exe
C:\WINDOWS\ZSSnp211.EXE
C:\WINDOWS\Domino.EXE
D:\Programy\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Orbit Downloader\orbitnet.exe
C:\Documents and Settings\User\Pulpit\dss.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - F:\Program Files\Orbit Downloader\orbitcth.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - F:\Program Files\Real Player\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - F:\Program Files\Bit Comet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - F:\Program Files\Orbit Downloader\GrabPro.dll
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - F:\PROGRA~1\FRESHD~1\fdiebar.dll (file missing)
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "F:\Program Files\Emil Junior\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
O4 - HKLM\..\Run: [DAEMON Tools] "D:\Programy\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Komunikator] F:\Program Files\Tlen.pl\tlen.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://F:\Program Files\Bit Comet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://F:\Program Files\Bit Comet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://F:\Program Files\Bit Comet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://F:\Program Files\Bit Comet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: FreshDownload - {E94C521D-98A5-4449-95EB-0E180785AC13} - F:\Program Files\FreshDownload\fd.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{C0312336-BAD3-4A17-A16C-617E4B05A5A9}: NameServer = 80.244.140.241 80.244.128.1
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPWDSVC.EXE
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\ESET\nod32krn.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVSCAN.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 9284 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 ZSMC211 (USB PC Camera (ZS0211)) - c:\windows\system32\drivers\zs211.sys <Not Verified; ZSMC Corporation; >
S3 autorun - c:\huadio.tmp <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
S3 catchme - c:\docume~1\user\ustawi~1\temp\catchme.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-07-25 21:07:37 542 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job
2008-06-24 19:54:47 410 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
-- Files created between 2008-06-26 and 2008-07-26 -----------------------------
2008-07-26 03:12:24 0 d-------- C:\WINDOWS\ERUNT
2008-07-25 23:50:24 53248 --a------ C:\WINDOWS\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-07-23 02:16:48 0 d-------- C:\WINDOWS\Noslip
2008-07-22 23:35:09 68096 --a------ C:\WINDOWS\zip.exe
2008-07-22 23:35:09 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-07-22 23:35:09 98816 --a------ C:\WINDOWS\sed.exe
2008-07-22 23:35:09 80412 --a------ C:\WINDOWS\grep.exe
2008-07-22 23:35:09 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-07-22 23:35:08 49152 --a------ C:\WINDOWS\VFind.exe
2008-07-22 23:35:07 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-07-22 23:35:07 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-07-22 00:18:47 0 d-------- C:\pprecorder
2008-07-20 10:04:12 0 d-------- C:\Program Files\Common Files\DirectX
2008-07-15 19:43:48 25088 --a------ C:\WINDOWS\system\vdsvrlnk.dll <Not Verified; ; VirtualDub>
2008-07-15 19:43:48 31232 --a------ C:\WINDOWS\system\vdremote.dll <Not Verified; ; VirtualDub>
2008-07-13 11:58:02 2560 --a------ C:\WINDOWS\system32\bitcometres.dll <Not Verified; BitComet; BitComet BCTP Helper>
2008-07-13 08:55:30 223128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys
2008-07-13 08:48:26 96256 --a------ C:\WINDOWS\system32\drivers\sptd4621.sys
2008-07-13 08:48:26 664064 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-12 21:44:41 0 d-------- C:\WINDOWS\EffectResources
2008-07-12 21:44:40 307200 --a------ C:\WINDOWS\vidcap32.Exe <Not Verified; Microsoft Corporation; Microsoft Windows>
2008-07-12 21:44:38 49152 --a------ C:\WINDOWS\Domino.EXE <Not Verified; ; Domino>
2008-07-12 21:44:38 172032 --a------ C:\WINDOWS\amcap.exe <Not Verified; Microsoft Corporation; DirectX 9.0 Sample>
2008-07-12 21:44:37 102400 --a------ C:\WINDOWS\ZS211Cap.exe <Not Verified; www.zsmc.com.cn; www.zsmc.com.cn StillCap>
2008-07-12 21:44:37 57344 --a------ C:\WINDOWS\Sti211.exe <Not Verified; ZSMC; >
2008-07-12 21:44:36 49152 --a------ C:\WINDOWS\ZSSnp211.EXE <Not Verified; ZSMCSNAP; ZSMCSNAP>
2008-07-12 21:44:36 81920 --a------ C:\WINDOWS\system32\ZS211STI.dll <Not Verified; zsmc; >
2008-07-12 21:44:35 391836 --a------ C:\WINDOWS\system32\drivers\ZS211.sys <Not Verified; ZSMC Corporation; >
2008-07-12 21:44:35 0 d-------- C:\WINDOWS\CatRoot
2008-07-12 21:44:34 0 d-------- C:\Program Files\Vimicro
2008-07-12 18:48:10 0 d-------- C:\Program Files\Common Files\xing shared
2008-07-11 09:33:47 0 d-------- C:\WINDOWS\system32\appmgmt
2008-07-11 09:27:56 0 d-------- C:\Program Files\Sun
2008-07-09 17:43:57 0 d--h----- C:\WINDOWS\PIF
2008-07-09 05:45:59 0 d-------- C:\Program Files\Common Files\SWF Studio
2008-07-09 00:06:33 0 d-------- C:\Program Files\ICQToolbar
2008-07-08 15:14:38 0 d-------- C:\WINDOWS\Desktop
2008-07-04 11:13:50 0 d-------- C:\Program Files\Software Informer
2008-07-02 23:10:32 0 d-------- C:\WINDOWS\Applian FLV Player
2008-06-30 18:05:29 79872 --a------ C:\WINDOWS\system32\lex_psu.exe
2008-06-30 18:05:29 41472 --a------ C:\WINDOWS\system32\ldeei.dll <Not Verified; Lexmark International, Inc.; Lexmark LDEEI>
2008-06-30 18:04:50 163840 --a------ C:\WINDOWS\system32\ldepcl32.dll
2008-06-30 18:04:50 328704 --a------ C:\WINDOWS\system32\dosfnt32.dll
2008-06-30 18:03:46 298496 --a------ C:\WINDOWS\unin0415.exe
2008-06-29 01:29:32 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-06-29 01:28:13 0 d-------- C:\Program Files\Skype
2008-06-29 01:28:06 0 d-------- C:\Program Files\Common Files\Skype
2008-06-29 01:18:16 0 d-------- C:\Program Files\Yahoo!
2008-06-26 20:39:10 0 d-------- C:\WINDOWS\Sun
-- Find3M Report ---------------------------------------------------------------
2008-07-26 11:47:50 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-26 11:37:03 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Orbit
2008-07-26 00:30:48 0 d-------- C:\Program Files\Common Files
2008-07-23 02:21:17 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Ulead Systems
2008-07-23 02:18:23 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-13 11:58:42 0 d-------- C:\Documents and Settings\User\Dane aplikacji\uTorrent
2008-07-12 21:57:26 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Skype
2008-07-12 21:55:36 0 d-------- C:\Documents and Settings\User\Dane aplikacji\skypePM
2008-07-12 21:44:34 0 d-------- C:\Program Files\Common Files\InstallShield
2008-07-12 18:47:58 0 d-------- C:\Program Files\Common Files\Real
2008-07-11 09:27:30 0 d-------- C:\Program Files\Java
2008-07-09 10:55:05 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Tlen.pl
2008-07-09 02:38:33 0 d-------- C:\Documents and Settings\User\Dane aplikacji\ICQ
2008-07-09 00:21:34 0 d-------- C:\Documents and Settings\User\Dane aplikacji\ICQ Toolbar
2008-07-04 11:22:25 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Hide IP NG
2008-07-03 01:34:19 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Yahoo!
2008-06-30 05:16:12 494308 --a------ C:\WINDOWS\system32\perfh015.dat
2008-06-30 05:16:12 86968 --a------ C:\WINDOWS\system32\perfc015.dat
2008-06-29 01:31:37 0 d-------- C:\Documents and Settings\User\Dane aplikacji\TVU Networks
2008-06-29 01:17:07 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Real
2008-06-28 19:51:48 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Adobe
2008-06-28 00:43:46 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Thinstall
2008-06-25 10:32:43 0 d-------- C:\Documents and Settings\User\Dane aplikacji\GrabPro
2008-06-25 02:26:34 0 d-------- C:\Documents and Settings\User\Dane aplikacji\vlc
2008-06-24 22:02:02 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-24 21:13:45 0 d-------- C:\Documents and Settings\User\Dane aplikacji\WinRAR
2008-06-24 20:43:09 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Macromedia
2008-06-24 20:36:39 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Mozilla
2008-06-24 19:46:18 0 d-------- C:\Program Files\Norton Internet Security
2008-06-24 19:45:58 0 d-------- C:\Program Files\Symantec
2008-06-24 19:42:08 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Symantec
2008-06-24 12:42:10 0 d-------- C:\Program Files\Messenger
2008-06-24 12:14:05 0 d-------- C:\Documents and Settings\User\Dane aplikacji\CyberLink
2008-06-24 11:54:47 892928 --a------ C:\WINDOWS\system32\iconv.dll <Not Verified; Free Software Foundation; libiconv: character set conversion library>
2008-06-24 11:54:31 404992 --a------ C:\WINDOWS\system32\libmplayer.dll
2008-06-24 11:54:29 126976 --a------ C:\WINDOWS\system32\libmpeg2_ff.dll
2008-06-24 11:54:28 3142656 --a------ C:\WINDOWS\system32\libavcodec.dll
2008-06-24 11:54:16 23552 --a------ C:\WINDOWS\system32\ff_wmv9.dll
2008-06-24 11:54:15 56832 --a------ C:\WINDOWS\system32\ff_unrar.dll
2008-06-24 11:54:14 102912 --a------ C:\WINDOWS\system32\ff_tremor.dll
2008-06-24 11:54:13 135168 --a------ C:\WINDOWS\system32\ff_samplerate.dll
2008-06-24 11:54:12 118784 --a------ C:\WINDOWS\system32\ff_realaac.dll
2008-06-24 11:54:11 143360 --a------ C:\WINDOWS\system32\ff_libmad.dll
2008-06-24 11:54:10 397312 --a------ C:\WINDOWS\system32\ff_libfaad2.dll
2008-06-24 11:54:08 172032 --a------ C:\WINDOWS\system32\ff_libdts.dll
2008-06-24 11:54:07 51712 --a------ C:\WINDOWS\system32\ff_liba52.dll
2008-06-24 11:54:06 237568 --a------ C:\WINDOWS\system32\OggDS.dll <Not Verified; ; Ogg DirectShow(tm) Filter Collection>
2008-06-24 11:54:05 921600 --a------ C:\WINDOWS\system32\vorbisenc.dll
2008-06-24 11:54:01 188416 --a------ C:\WINDOWS\system32\vorbis.dll
2008-06-24 11:54:00 45056 --a------ C:\WINDOWS\system32\ogg.dll
2008-06-24 11:53:58 1415680 --a------ C:\WINDOWS\system32\WMV9VCM.dll <Not Verified; Microsoft Corporation; Windows Media Video 9 VCM>
2008-06-24 11:53:48 245760 --a------ C:\WINDOWS\system32\mplvpx.dll <Not Verified; Ligos Corporation; MPL Video Library>
2008-06-24 11:53:46 9216 --a------ C:\WINDOWS\system32\cpuinf32.dll
2008-06-24 11:53:30 755027 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-06-24 11:53:24 108032 --a------ C:\WINDOWS\system32\avi.dll
2008-06-24 11:53:23 141312 --a------ C:\WINDOWS\system32\mp4.dll
2008-06-24 11:53:22 148992 --a------ C:\WINDOWS\system32\mkx.dll
2008-06-24 11:53:21 159744 --a------ C:\WINDOWS\system32\mmfinfo.dll
2008-06-24 11:53:20 0 d-------- C:\Program Files\Real Alternative
2008-06-24 11:53:19 120832 --a------ C:\WINDOWS\system32\ogm.dll
2008-06-24 11:53:18 163840 --a------ C:\WINDOWS\system32\ts.dll
2008-06-24 11:53:16 79360 --a------ C:\WINDOWS\system32\mkzlib.dll
2008-06-24 11:53:15 23552 --a------ C:\WINDOWS\system32\mkunicode.dll
2008-06-24 11:53:00 0 d-------- C:\Program Files\QT Lite
2008-06-24 11:35:25 0 d-------- C:\Program Files\SiSLan
2008-06-24 11:22:35 0 d-------- C:\Program Files\Malicious Software Removal Tool
2008-06-24 11:17:50 0 d-------- C:\Program Files\Common Files\Java
2008-06-24 11:17:30 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Sun
2008-06-24 11:17:25 0 d-------- C:\Program Files\MSXML 4.0
2008-06-24 11:16:49 0 d-------- C:\Program Files\MSXML 6.0
2008-06-24 10:39:29 0 d-------- C:\Program Files\Windows Media Connect 2
2008-06-24 09:57:52 0 d-------- C:\Program Files\MSBuild
2008-06-24 09:50:14 0 d-------- C:\Program Files\Reference Assemblies
2008-06-24 09:19:21 0 d-------- C:\Program Files\HighMAT CD Writing Wizard
2008-06-24 09:06:49 0 d-------- C:\Program Files\Common Files\Adobe
2008-06-24 09:01:51 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Ahead
2008-06-24 09:00:55 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Gadu-Gadu
2008-06-24 08:59:23 0 d-------- C:\Program Files\MarBit
2008-06-24 08:58:50 0 d-------- C:\Program Files\Winamp
2008-06-24 08:22:43 0 d-------- C:\Program Files\Microsoft.NET
2008-06-24 08:20:32 0 d-------- C:\Program Files\Microsoft Works
2008-06-24 08:10:07 0 d-------- C:\Program Files\CyberLink
2008-06-24 08:10:00 0 d-------- C:\Program Files\CyberLink DVD Solution
2008-06-24 07:48:22 0 d-------- C:\Program Files\Ahead
2008-06-24 07:48:08 0 d-------- C:\Program Files\Common Files\Ahead
2008-06-24 07:33:30 0 d-------- C:\Program Files\C-Media 3D Audio
2008-06-24 07:31:54 298104 --a------ C:\WINDOWS\system32\imon.dll <Not Verified; Eset; NOD32 Antivirus System>
2008-06-24 07:30:00 0 d-------- C:\Documents and Settings\User\Dane aplikacji\Identities
2008-06-24 01:11:33 0 d-------- C:\Program Files\Common Files\ODBC
2008-06-24 01:11:28 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-06-24 01:10:49 62 --ahs---- C:\Documents and Settings\User\Dane aplikacji\desktop.ini
2008-06-23 23:29:33 0 d-------- C:\Program Files\microsoft frontpage
2008-06-23 23:28:34 0 -rahs---- C:\MSDOS.SYS
2008-06-23 23:28:34 0 -rahs---- C:\IO.SYS
2008-06-23 23:28:34 0 --a------ C:\CONFIG.SYS
2008-06-23 23:28:34 0 --a------ C:\AUTOEXEC.BAT
2008-06-23 23:25:14 0 d--h----- C:\Program Files\WindowsUpdate
2008-06-23 23:25:07 0 d-------- C:\Program Files\Usługi online
2008-06-23 23:23:55 0 d-------- C:\Program Files\Common Files\MSSoap
2008-06-23 23:23:44 0 d-------- C:\Program Files\Movie Maker
2008-06-23 23:22:23 21856 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-06-23 23:21:25 0 d-------- C:\Program Files\MSN Gaming Zone
2008-06-23 23:21:11 0 d-------- C:\Program Files\Windows NT
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C55BBCD6-41AD-48AD-9953-3609C48EACC7}"= F:\Program Files\Orbit Downloader\GrabPro.dll [2008-06-10 10:47 457848]
[-HKEY_CLASSES_ROOT\CLSID\{C55BBCD6-41AD-48AD-9953-3609C48EACC7}]
[HKEY_CLASSES_ROOT\GrabPro.FindBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{8091D09E-B01D-4D32-AC66-BBF8916BB1CF}]
[HKEY_CLASSES_ROOT\GrabPro.FindBar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-06-24 07:31]
"Cmaudio"="cmicnfg.cpl" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 18:15]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-12-21 12:54]
"URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [2003-09-06 22:36]
"SpeedTouch USB Diagnostics"="F:\Program Files\Emil Junior\Dragdiag.exe" [2004-03-23 12:06]
"ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2006-08-19 11:37]
"Domino"="C:\WINDOWS\Domino.exe" [2006-08-18 16:58]
"DAEMON Tools"="D:\Programy\DAEMON Tools\daemon.exe" [2005-11-09 00:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44]
"fsm"="" []
"Komunikator"="F:\Program Files\Tlen.pl\tlen.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
Bardzo proszę o pomoc.
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
"disableregistrytools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
@="Service"
-- End of Deckard's System Scanner: finished at 2008-07-26 11:53:26 ------------