
Oto logi:
Combo:
- Kod: Zaznacz wszystko
ComboFix 09-04-27.02 - PooH 2009-04-27 20:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3326.2806 [GMT 2:00]
Uruchomiony z: c:\documents and settings\PooH\Pulpit\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *enabled*
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((( Pliki utworzone od 2009-05-27 do 2009-4-27 )))))))))))))))))))))))))))))))
.
2009-04-27 18:04 . 2009-04-27 18:04 -------- d-----w c:\windows\system32\xircom
2009-04-27 18:04 . 2009-04-27 18:04 -------- d-----w c:\program files\microsoft frontpage
2009-04-19 10:26 . 2009-04-19 12:38 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\AIMP
2009-04-19 10:24 . 2009-04-19 10:24 -------- d-----w c:\program files\AIMP2
2009-04-17 17:13 . 2008-04-10 09:52 4682 ----a-w c:\windows\system32\npptNT2.sys
2009-04-17 16:44 . 2009-04-17 18:08 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\Hamachi
2009-04-17 16:44 . 2009-04-17 16:44 25280 ----a-w c:\windows\system32\drivers\hamachi.sys
2009-04-17 16:44 . 2009-04-17 16:44 -------- d-----w c:\program files\Hamachi
2009-04-17 14:40 . 2009-04-17 14:40 -------- d-----w c:\program files\Common Files\INCA Shared
2009-04-17 10:29 . 2009-04-17 10:32 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\Horse
2009-04-17 10:17 . 2009-04-17 10:17 279712 ----a-w c:\windows\system32\drivers\atksgt.sys
2009-04-17 10:17 . 2009-04-17 10:17 25888 ----a-w c:\windows\system32\drivers\lirsgt.sys
2009-04-17 10:08 . 2009-04-17 10:08 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\DAEMON Tools
2009-04-17 10:08 . 2009-04-17 10:08 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\DAEMON Tools Pro
2009-04-17 10:07 . 2009-04-17 10:07 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\DAEMON Tools Lite
2009-04-17 10:07 . 2009-04-17 10:07 -------- d-----w c:\program files\DAEMON Tools Toolbar
2009-04-17 10:07 . 2009-04-17 17:03 -------- d-----w c:\program files\DAEMON Tools Lite
2009-04-17 10:05 . 2009-04-17 10:05 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-04-17 10:05 . 2009-04-17 10:09 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\DAEMON Tools Lite
2009-04-16 17:28 . 2009-04-16 17:28 -------- d-----w c:\program files\ivo
2009-04-16 17:28 . 2009-04-16 17:35 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\Expressivo
2009-04-16 06:55 . 2009-04-16 06:55 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1
2009-04-16 06:55 . 2009-04-16 06:55 -------- d-----w c:\program files\e-Deklaracje
2009-04-16 06:55 . 2009-04-16 06:55 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-04-15 19:16 . 2009-04-15 19:16 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\BESTplayer
2009-04-15 14:59 . 2009-04-15 14:59 43520 ----a-w c:\windows\system32\CmdLineExt03.dll
2009-04-09 15:11 . 2009-04-09 15:11 -------- d-----w c:\program files\ContextConvert Pro
2009-04-09 14:56 . 2009-04-09 14:56 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\ABBYY
2009-04-09 14:53 . 2009-04-09 14:58 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\ABBYY
2009-04-09 14:53 . 2009-04-09 14:58 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\ABBYY
2009-04-09 14:53 . 2009-04-09 14:56 -------- d-----w c:\program files\ABBYY FineReader 9.0
2009-04-09 14:52 . 2009-04-17 16:43 -------- d-----w C:\temp
2009-04-09 14:52 . 2009-04-09 14:52 -------- d-----w c:\temp\FR90PE
2009-04-09 14:28 . 2009-04-09 14:28 -------- d-----w c:\program files\MSSOAP
2009-04-09 14:28 . 2009-04-09 14:28 -------- d-----w c:\program files\Webroot
2009-04-09 14:25 . 2009-04-09 14:25 164 ----a-w c:\windows\install.dat
2009-04-09 14:24 . 2009-04-09 14:24 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\ESET
2009-04-09 14:15 . 2009-04-09 14:15 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\OpenOffice.org
2009-04-09 14:14 . 2009-04-09 14:14 -------- d-----w c:\program files\OpenOffice.org 3
2009-04-09 13:21 . 2009-04-09 13:21 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Brother
2009-04-09 07:11 . 2009-04-09 07:11 -------- d-----w c:\documents and settings\LocalService\Ustawienia lokalne\Dane aplikacji\ESET
2009-04-07 20:44 . 2009-04-14 21:56 398536 ----a-w c:\documents and settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat
2009-04-07 15:09 . 2009-04-07 15:09 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\BraCa_Soft
2009-04-07 15:09 . 2009-04-07 15:09 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\BraCa_Soft
2009-04-07 14:53 . 2009-04-07 15:02 -------- d-----w c:\windows\SxsCaPendDel
2009-04-07 09:29 . 2009-04-07 09:29 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\Gadu-Gadu
2009-04-07 09:07 . 2009-04-07 12:50 -------- d-----w c:\documents and settings\PooH\Gadu-Gadu
2009-04-06 14:23 . 2009-04-06 14:23 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\Ahead
2009-04-06 14:22 . 2009-04-06 18:04 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\Ahead
2009-04-06 14:22 . 2009-04-06 14:22 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Ahead
2009-04-06 14:21 . 2009-04-06 14:21 -------- d-----w c:\program files\Nero
2009-04-06 14:21 . 2009-04-06 14:21 -------- d-----w c:\program files\Common Files\Ahead
2009-04-06 14:21 . 2009-04-06 14:21 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Nero
2009-04-03 22:22 . 2009-04-03 22:22 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\Identities
2009-04-03 08:01 . 2009-04-15 19:11 16504 ----a-w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-04-02 16:22 . 2009-04-17 17:05 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\Google
2009-04-02 16:21 . 2009-04-18 12:28 -------- d-----w c:\program files\Google
2009-04-02 16:21 . 2009-04-02 16:21 -------- d-----w c:\program files\IrfanView
2009-04-02 16:18 . 2009-04-03 13:31 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\ACD Systems
2009-04-02 16:18 . 2009-04-02 16:18 -------- d-----w c:\documents and settings\PooH\Dane aplikacji\ACD Systems
2009-04-02 16:15 . 2009-04-02 16:15 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\ACD Systems
2009-04-02 16:14 . 2009-04-02 16:15 -------- d-----w c:\program files\Common Files\ACD Systems
2009-04-02 16:14 . 2009-04-02 16:14 -------- d-----w c:\program files\ACD Systems
2009-04-02 16:12 . 2009-04-02 16:12 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\Downloaded Installations
2009-04-02 16:10 . 2009-04-02 16:10 -------- d-----w c:\program files\Ifran
2009-03-28 20:15 . 2009-03-28 20:15 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\TVU Networks
2009-03-28 20:15 . 2009-03-28 20:15 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\LocalLow
2009-03-28 20:15 . 2009-03-28 20:15 -------- d-----w c:\documents and settings\PooH\Ustawienia lokalne\Dane aplikacji\TVU Networks
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-27 17:49 . 2001-10-26 16:15 83864 ----a-w c:\windows\system32\perfc015.dat
2009-04-27 17:49 . 2001-10-26 16:15 490614 ----a-w c:\windows\system32\perfh015.dat
2009-04-17 17:07 . 2009-03-27 18:29 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-09 14:56 . 2009-03-27 19:57 -------- d-----w c:\program files\Common Files\Adobe
2009-04-09 13:38 . 2009-04-09 13:21 50 ----a-w c:\windows\system32\bridf07a.dat
2009-04-09 13:38 . 2009-04-09 13:21 -------- d-----w c:\program files\Brother
2009-04-06 18:04 . 2009-03-27 18:59 -------- d-----w c:\program files\NAPI-PROJEKT
2009-03-28 21:25 . 2009-03-27 18:17 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-28 20:18 . 2009-03-27 19:44 -------- d-----w c:\program files\SopCast
2009-03-28 15:26 . 2009-03-27 20:31 -------- d-----w c:\program files\uTorrent
2009-03-28 14:55 . 2009-03-27 18:57 -------- d-----w c:\program files\SubEdit-Player
2009-03-28 13:08 . 2009-03-28 12:53 -------- d-----w c:\program files\EVEREST Ultimate Edition v4.60.1500
2009-03-28 12:55 . 2009-03-27 18:26 16608 ----a-w c:\windows\gdrv.sys
2009-03-28 12:54 . 2009-03-27 18:29 -------- d-----w c:\program files\Gigabyte
2009-03-27 20:56 . 2009-03-27 20:32 -------- d-----w c:\program files\CM Rev Colours Changer 2
2009-03-27 20:03 . 2009-03-27 20:03 -------- d-----w c:\program files\MSBuild
2009-03-27 20:03 . 2009-03-27 20:03 -------- d-----w c:\program files\Reference Assemblies
2009-03-27 19:52 . 2009-03-27 19:50 -------- d--h--w c:\program files\Zero G Registry
2009-03-27 19:25 . 2009-03-27 19:25 -------- d-----w c:\program files\VideoLAN
2009-03-27 19:22 . 2009-03-27 19:22 -------- d-----w c:\program files\K-Lite Codec Pack
2009-03-27 19:07 . 2009-03-27 19:07 -------- d-----w c:\program files\AGEIA Technologies
2009-03-27 19:07 . 2009-03-27 19:07 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-27 18:53 . 2009-03-27 18:53 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-27 18:53 . 2009-03-27 18:53 -------- d-----w c:\program files\Java
2009-03-27 18:47 . 2009-03-27 18:47 0 ----a-w c:\windows\nsreg.dat
2009-03-27 18:38 . 2009-03-27 18:38 -------- d-----w c:\program files\ESET
2009-03-27 18:35 . 2009-03-27 18:35 -------- d-----w c:\program files\Thomson
2009-03-27 18:35 . 2009-03-27 18:29 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-27 18:33 . 2009-03-27 18:30 -------- d-----w c:\program files\Realtek
2009-03-27 18:30 . 2009-03-27 18:30 319488 ----a-w c:\windows\HideWin.exe
2009-03-27 18:30 . 2009-03-27 18:30 -------- d-----w c:\program files\AMD
2009-03-27 18:29 . 2009-03-27 18:29 -------- d-----w c:\program files\Browser Configuration Utility
2009-03-27 18:17 . 2001-07-21 22:36 67 --sha-w c:\windows\Fonts\desktop.ini
2009-03-27 18:17 . 2009-03-27 18:17 -------- d-----w c:\program files\Usługi online
2009-03-27 18:15 . 2009-03-27 18:15 21856 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-27 18:15 . 2009-03-27 18:15 -------- d-----w c:\program files\Windows Media Connect 2
2009-02-16 22:17 . 2009-03-27 19:07 453152 ----a-w c:\windows\system32\NVUNINST.EXE
2009-04-02 16:22 . 2009-04-02 16:22 135680 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
------- Sigcheck -------
[-] 2008-05-02 06:48 361344 8E036EEC565910417EA020CE0962AA24 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-08-26 16851456]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-03-01 124928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SharedAccess"=2 (0x2)
"idsvc"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"ERSvc"=2 (0x2)
"CiSvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ES lite Service"=2 (0x2)
"wscsvc"=2 (0x2)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
"NBService"=3 (0x3)
"UPS"=3 (0x3)
"WRConsumerService"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"f:\\Gry\\Football Manager 2009\\fm.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
R3 scsiprnt;Klasa drukarki rodzajowej Microsoft SCSI/1394;c:\windows\system32\DRIVERS\scsiprnt.sys [2001-08-17 11648]
R4 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\ESSVR.EXE [2008-11-24 68136]
S2 ABBYY.Licensing.FineReader.Professional.9.0;Usługa licencjonowania programu ABBYY FineReader 9.0;c:\program files\ABBYY FineReader 9.0\NetworkLicenseServer.exe [2007-09-24 566560]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
.
.
------- Skan uzupełniający -------
.
uStart Page = about:blank
TCP: {DDE9EAA5-CBCF-42B6-A9D6-D6B51A06E261} = 213.241.79.37 83.238.255.76
FF - ProfilePath - c:\documents and settings\PooH\Dane aplikacji\Mozilla\Firefox\Profiles\jp7j5fcs.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/
FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\PooH\Dane aplikacji\Mozilla\Firefox\Profiles\jp7j5fcs.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\documents and settings\PooH\Dane aplikacji\Mozilla\Firefox\Profiles\jp7j5fcs.default\extensions\SignPlugin@bph.pl\plugins\NPSignPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-27 20:04
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_USERS\S-1-5-21-1645522239-1563985344-725345543-1003\Software\G*e*n*i*e*"!\FM Genie Scout 2009 XE]
"GameDir"="c:\\Documents and Settings\\PooH\\Moje dokumenty\\Sports Interactive\\Football Manager 2009\\games"
"ShortlistDir"="c:\\Documents and Settings\\PooH\\Moje dokumenty\\Sports Interactive\\Football Manager 2009\\shortlists"
"ScreenshotsDir"="c:\\Documents and Settings\\PooH\\Moje dokumenty\\Sports Interactive\\Football Manager 2009"
"SaveDir"="c:\\Documents and Settings\\PooH\\Moje dokumenty\\Sports Interactive\\Football Manager 2009\\"
"HistoryDir"="c:\\Documents and Settings\\PooH\\Pulpit\\fm_genie_scout_2009_xe_209\\FM Genie Scout 2009 XE\\History Points"
"LangDB"="f:\\Gry\\Football Manager 2009\\data\\updates\\update-930\\db\\930\\lang_db.dat"
"LastSaveGame"="c:\\Documents and Settings\\PooH\\Moje dokumenty\\Sports Interactive\\Football Manager 2009\\games\\badalona.fm"
"Language"="English"
"LoadLangDB"=dword:00000001
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="Champions League"
"LastUpdateCheck"=dword:00000000
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000067
"UniqueID"="24-F555-2F93"
"Currency"=dword:00000056
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'explorer.exe'(3612)
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\Brother\Brmfcmon\BrMfcMon.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Czas ukończenia: 2009-04-27 20:05 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-04-27 18:05
Przed: 36 846 542 848 bajtów wolnych
Po: 37 576 380 416 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
254
HJ:
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:05:33, on 2009-04-27
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\PooH\Pulpit\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BrMfcWnd] "C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] "C:\Program Files\Brother\ControlCenter3\brctrcen.exe" /autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE9EAA5-CBCF-42B6-A9D6-D6B51A06E261}: NameServer = 213.241.79.37 83.238.255.76
O23 - Service: Usługa licencjonowania programu ABBYY FineReader 9.0 (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 4698 bytes