
Kilka dni temu na pewnej stronie (jest to znana mi stronka, która zawsze była czysta) Comodo zaczął szaleć. Wyskoczyła reklama jakiejś aplikacji od skanowania systemu on-line.
Wszystko zablokowałem, także Comodo nie powinien nic przepuścić, jednak od tego czasu komp zaczął zamulać. Przez ostatnie dwa dni, to nawet potrafi całkowicie się zawiesić - dysk mieli non stop.
Zerknijcie, czy nie ma czegoś w logach.
RIST:
- Kod: Zaznacz wszystko
Logfile of random's system information tool 1.06 (written by random/random)
Run by Mike at 2010-01-20 18:18:34
Microsoft® Windows Vista™ Ultimate Service Pack 1
System drive C: has 6 GB (15%) free of 41 GB
Total RAM: 2046 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:21:27, on 2010-01-20
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Comodo\COMODO Internet Security\cfp.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\MC-907 Mouse\ADOGMOU.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\AQQ\AQQ.exe
C:\Windows\ehome\ehtray.exe
G:\Edgecam85\Cam\edgecls.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Mike\Downloads\RSIT.exe
C:\Program Files\trend micro\Mike.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\Comodo\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [ADOGMOUSE] "C:\Program Files\MC-907 Mouse\ADOGMOU.exe"
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [AQQ] C:\PROGRA~1\AQQ\AQQ.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'USŁUGA SIECIOWA')
O4 - Global Startup: EdgeCLS10.75.lnk = G:\Edgecam85\Cam\edgecls.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O13 - Gopher Prefix:
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SolarWinds TFTP Server - SolarWinds - C:\Program Files\SolarWinds\TFTPServer\SolarWinds TFTP Server.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Windows\System32\nvSCPAPISvr.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
--
End of file - 5688 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-03-26 5369856]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-06-10 13785632]
"COMODO Internet Security"=C:\Program Files\Comodo\COMODO Internet Security\cfp.exe [2009-12-12 1800464]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"ADOGMOUSE"=C:\Program Files\MC-907 Mouse\ADOGMOU.exe [2006-11-15 475136]
"BrMfcWnd"=C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [2007-03-12 663552]
"ControlCenter3"=C:\Program Files\Brother\ControlCenter3\brctrcen.exe [2007-01-26 65536]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AQQ"=C:\PROGRA~1\AQQ\AQQ.exe [2009-11-17 6807552]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ABIT uGuruIII]
C:\Program Files\U-ABIT\uGuru\LaunchuGuru.exe [2007-02-09 22528]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files\Alcohol 52\axcmd.exe [2009-04-24 203416]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
C:\Windows\RaidTool\xInsIDE.exe [2007-03-20 36864]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
EdgeCLS10.75.lnk - G:\Edgecam85\Cam\edgecls.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=177
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25289084-6685-11de-93fd-806e6f6e6963}]
shell\AutoRun\command - H:\swlauncher.exe
======List of files/folders created in the last 1 months======
2010-01-20 18:18:40 ----D---- C:\Program Files\trend micro
2010-01-20 18:18:34 ----D---- C:\rsit
2010-01-19 21:30:38 ----D---- C:\Windows\Minidump
2010-01-16 12:17:42 ----D---- C:\Program Files\Adobe
2010-01-16 00:05:39 ----D---- C:\Program Files\Simpli Software
2010-01-11 20:37:12 ----D---- C:\Program Files\pdfsam
2010-01-11 10:13:53 ----R---- C:\Windows\system32\BrDctF2S.dll
2010-01-11 10:13:53 ----R---- C:\Windows\system32\BrDctF2L.dll
2010-01-11 10:13:53 ----R---- C:\Windows\system32\BrDctF2.dll
2010-01-11 10:13:49 ----N---- C:\Windows\system32\BroSNMP.dll
2010-01-11 10:13:32 ----D---- C:\Program Files\Brother
2010-01-11 10:13:32 ----D---- C:\Brother
2010-01-10 15:21:32 ----D---- C:\Users\Mike\AppData\Roaming\SolidWorksNewsReader
2010-01-10 15:19:34 ----D---- C:\Users\Mike\AppData\Roaming\SolidWorks
2010-01-10 15:14:40 ----D---- C:\Users\Mike\AppData\Roaming\DWGeditor
2010-01-10 15:13:55 ----D---- C:\Program Files\SolidWorks Installation Manager
2010-01-10 15:13:34 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2010-01-10 15:08:14 ----D---- C:\Program Files\Common Files\eDrawings2007
2010-01-09 13:34:33 ----N---- C:\Windows\system32\MSVCR70.DLL
2010-01-09 13:34:33 ----N---- C:\Windows\system32\MSVCP70.DLL
2010-01-09 13:34:33 ----N---- C:\Windows\system32\MSVCI70.DLL
2010-01-09 13:34:32 ----N---- C:\Windows\system32\MFC70.DLL
2010-01-09 13:34:32 ----N---- C:\Windows\system32\Atl70.dll
2010-01-09 13:34:20 ----A---- C:\Windows\system32\echelp.exe
2010-01-09 13:05:03 ----D---- C:\Program Files\DjVuZone
2010-01-09 12:40:57 ----D---- C:\Users\Mike\AppData\Roaming\XnView
2010-01-09 12:40:32 ----D---- C:\Program Files\XnView
2010-01-05 22:36:51 ----D---- C:\Users\Mike\AppData\Roaming\PhotoFiltre
2010-01-05 22:36:48 ----D---- C:\Program Files\PhotoFiltre
2010-01-03 23:37:16 ----H---- C:\Windows\system32\sdlshgb.dll
2010-01-03 23:37:16 ----H---- C:\Windows\system32\emh727q.dll
2010-01-03 23:37:14 ----H---- C:\Windows\system32\gjzlq9s.dll
2010-01-03 23:37:13 ----H---- C:\Windows\system32\kv52taf.dll
2010-01-03 23:37:11 ----H---- C:\Windows\system32\qpb68k8.dll
2010-01-03 23:37:10 ----H---- C:\Windows\system32\vzyqvfh.dll
2010-01-03 23:37:08 ----H---- C:\Windows\system32\qve7xvr.dll
2010-01-03 23:37:07 ----H---- C:\Windows\system32\m67s30d.dll
2010-01-03 23:37:06 ----H---- C:\Windows\system32\fhtjs5w.dll
2010-01-03 23:37:05 ----H---- C:\Windows\system32\w3jddga.dll
2010-01-03 23:37:05 ----H---- C:\Windows\system32\moicoqy.dll
2010-01-03 23:37:03 ----H---- C:\Windows\system32\r3504cn.dll
2010-01-03 23:37:01 ----H---- C:\Windows\system32\og2yv47.dll
2010-01-03 23:36:59 ----H---- C:\Windows\system32\qppohzo.dll
2010-01-03 23:36:58 ----H---- C:\Windows\system32\b0oarjz.dll
2010-01-03 23:36:56 ----H---- C:\Windows\system32\khspd1x.dll
2010-01-03 23:36:54 ----H---- C:\Windows\system32\sbwr5w6.dll
2010-01-03 23:36:53 ----H---- C:\Windows\system32\eqzz7q3.dll
2010-01-03 23:36:51 ----H---- C:\Windows\system32\r1z1qrc.dll
2010-01-03 23:36:50 ----H---- C:\Windows\system32\qi4kmbt.dll
2010-01-03 23:36:48 ----H---- C:\Windows\system32\o68o3jr.dll
2010-01-03 23:36:47 ----H---- C:\Windows\system32\qf47url.dll
2010-01-03 23:36:45 ----H---- C:\Windows\system32\teict2z.dll
2010-01-03 23:36:45 ----H---- C:\Windows\system32\b3luwtz.dll
2010-01-03 23:36:44 ----H---- C:\Windows\system32\ugsg9ee.dll
2010-01-03 23:36:42 ----H---- C:\Windows\system32\vj5ccqi.dll
2010-01-03 23:36:42 ----H---- C:\Windows\system32\unk0vr0.dll
2010-01-03 23:36:41 ----H---- C:\Windows\system32\we91eyj.dll
2010-01-03 23:36:40 ----H---- C:\Windows\system32\rm61sy8.dll
2010-01-03 23:36:39 ----H---- C:\Windows\system32\l6u303w.dll
2010-01-03 23:36:38 ----H---- C:\Windows\system32\dek2q0s.dll
2010-01-03 23:36:37 ----H---- C:\Windows\system32\btzwjoc.dll
2010-01-03 23:36:36 ----H---- C:\Windows\system32\u9nid94.dll
2010-01-03 23:36:35 ----H---- C:\Windows\system32\xzcqzxr.dll
2010-01-03 23:36:34 ----H---- C:\Windows\system32\hja4s58.dll
2010-01-03 23:36:33 ----H---- C:\Windows\system32\sm0vy36.dll
2010-01-03 23:36:31 ----H---- C:\Windows\system32\i2u1rpp.dll
2010-01-03 23:36:30 ----H---- C:\Windows\system32\mbsr8x5.dll
2010-01-03 23:36:28 ----H---- C:\Windows\system32\lgnkaeh.dll
2010-01-03 23:36:27 ----H---- C:\Windows\system32\sgroq5m.dll
2010-01-03 23:36:25 ----H---- C:\Windows\system32\ny7pthn.dll
2010-01-03 23:36:22 ----H---- C:\Windows\system32\t3oikx3.dll
2010-01-03 23:36:22 ----H---- C:\Windows\system32\r3wnok3.dll
2010-01-03 23:36:21 ----H---- C:\Windows\system32\whrvi8j.dll
2010-01-03 23:36:19 ----H---- C:\Windows\system32\psu07oo.dll
2010-01-03 23:36:18 ----H---- C:\Windows\system32\gsg9rhw.dll
2010-01-03 23:36:17 ----H---- C:\Windows\system32\svgd18j.dll
2010-01-03 23:36:17 ----H---- C:\Windows\system32\d523tik.dll
2010-01-03 23:36:16 ----H---- C:\Windows\system32\d1ucoul.dll
2010-01-03 23:36:15 ----H---- C:\Windows\system32\qxifzao.dll
2010-01-03 23:36:14 ----H---- C:\Windows\system32\xkdp0he.dll
2010-01-03 23:36:13 ----H---- C:\Windows\system32\j82dy4z.dll
2010-01-03 23:36:12 ----H---- C:\Windows\system32\zfatp2b.dll
2010-01-03 23:36:11 ----H---- C:\Windows\system32\puebqjh.dll
2010-01-03 23:36:10 ----H---- C:\Windows\system32\p1gti3g.dll
2010-01-03 23:36:10 ----H---- C:\Windows\system32\ilexiq0.dll
2010-01-03 23:36:09 ----H---- C:\Windows\system32\yg51rnp.dll
2010-01-03 23:36:09 ----H---- C:\Windows\system32\rvxeh2g.dll
2010-01-03 23:36:08 ----H---- C:\Windows\system32\klu37si.dll
2010-01-03 23:36:07 ----H---- C:\Windows\system32\kevl7am.dll
2010-01-03 23:36:05 ----H---- C:\Windows\system32\yhdfh9b.dll
2010-01-03 23:36:05 ----H---- C:\Windows\system32\edau9f2.dll
2010-01-03 23:36:04 ----H---- C:\Windows\system32\gdb26uj.dll
2010-01-03 23:36:02 ----H---- C:\Windows\system32\mtf8ftp.dll
2010-01-03 23:36:02 ----H---- C:\Windows\system32\dicb9cc.dll
2010-01-03 23:35:59 ----H---- C:\Windows\system32\ycu9glx.dll
2010-01-03 23:35:59 ----H---- C:\Windows\system32\u16iw4k.dll
2010-01-03 23:35:56 ----H---- C:\Windows\system32\fmz6ipk.dll
2010-01-03 23:35:54 ----H---- C:\Windows\system32\wcgl2ka.dll
2010-01-03 23:35:52 ----H---- C:\Windows\system32\vkg44zc.dll
2010-01-03 23:35:51 ----H---- C:\Windows\system32\x6a6jd1.dll
2010-01-03 23:35:50 ----H---- C:\Windows\system32\am3ota9.dll
2010-01-03 23:35:49 ----H---- C:\Windows\system32\jg3uvk8.dll
2010-01-03 23:35:49 ----H---- C:\Windows\system32\daxyr8e.dll
2010-01-03 23:35:47 ----H---- C:\Windows\system32\cg8a9oj.dll
2010-01-03 23:35:46 ----H---- C:\Windows\system32\dntbhlb.dll
2010-01-03 23:35:42 ----H---- C:\Windows\system32\q8dghnn.dll
2010-01-03 23:35:42 ----A---- C:\Windows\system32\op1ofix.dll
2010-01-03 23:35:42 ----A---- C:\Windows\system32\fmivbcp.dll
2010-01-03 23:35:41 ----A---- C:\Windows\system32\ssprs.dll
2010-01-03 23:35:41 ----A---- C:\Windows\system32\prsgrc.dll
2010-01-03 23:35:41 ----A---- C:\Windows\system32\grcauth2.dll
2010-01-03 23:35:41 ----A---- C:\Windows\system32\grcauth1.dll
2010-01-03 23:35:41 ----A---- C:\Windows\system32\clauth2.dll
2010-01-03 23:35:41 ----A---- C:\Windows\system32\clauth1.dll
2010-01-03 23:35:38 ----H---- C:\Windows\system32\a8c741v.dll
2010-01-03 23:35:34 ----D---- C:\Users\Mike\AppData\Roaming\DassaultSystemes
2010-01-03 23:35:34 ----D---- C:\ProgramData\DassaultSystemes
2010-01-03 23:35:24 ----A---- C:\Windows\system32\hlvdd.dll
2010-01-03 23:35:24 ----A---- C:\Windows\system32\haspvdd.dll
2010-01-03 23:34:16 ----N---- C:\Windows\system32\gdiplus.dll
2010-01-03 20:07:26 ----D---- C:\Program Files\Common Files\Bcgsoft
======List of files/folders modified in the last 1 months======
2010-01-20 18:18:40 ----RD---- C:\Program Files
2010-01-20 18:05:43 ----D---- C:\Program Files\Mozilla Firefox
2010-01-20 18:04:57 ----D---- C:\Windows\System32
2010-01-20 18:04:57 ----D---- C:\Windows\inf
2010-01-20 18:04:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-20 17:57:54 ----D---- C:\Windows\Temp
2010-01-20 17:57:42 ----D---- C:\ProgramData\VMware
2010-01-20 17:57:40 ----D---- C:\ProgramData\NVIDIA
2010-01-20 17:10:59 ----D---- C:\Program Files\Mozilla Thunderbird
2010-01-20 16:45:55 ----D---- C:\Windows\Prefetch
2010-01-19 21:30:38 ----D---- C:\Windows
2010-01-19 12:55:13 ----D---- C:\Windows\system32\catroot2
2010-01-19 12:55:12 ----SHD---- C:\System Volume Information
2010-01-16 12:19:03 ----D---- C:\ProgramData\Adobe
2010-01-16 12:18:18 ----SHD---- C:\Windows\Installer
2010-01-16 12:17:53 ----D---- C:\Program Files\Common Files\Adobe
2010-01-16 00:28:32 ----D---- C:\Users\Mike\AppData\Roaming\uTorrent
2010-01-15 23:52:37 ----D---- C:\Program Files\Reader 9.0
2010-01-15 17:11:58 ----D---- C:\Users\Mike\AppData\Roaming\foobar2000
2010-01-13 23:58:46 ----D---- C:\Users\Mike\AppData\Roaming\FileZilla
2010-01-12 23:57:34 ----D---- C:\Users\Mike\AppData\Roaming\Thunderbird
2010-01-11 10:16:06 ----A---- C:\Windows\BRWMARK.INI
2010-01-11 10:16:06 ----A---- C:\Windows\BRPP2KA.INI
2010-01-11 10:14:39 ----D---- C:\Windows\system32\catroot
2010-01-11 10:13:31 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-10 15:15:25 ----D---- C:\Program Files\Common Files\SolidWorks Shared
2010-01-10 15:13:59 ----SD---- C:\Users\Mike\AppData\Roaming\Microsoft
2010-01-10 15:08:40 ----D---- C:\Windows\winsxs
2010-01-10 15:08:15 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-10 15:08:14 ----D---- C:\Program Files\Common Files
2010-01-10 15:08:10 ----D---- C:\Program Files\Microsoft Office
2010-01-10 15:06:44 ----RSD---- C:\Windows\Fonts
2010-01-10 15:06:13 ----HD---- C:\Windows\system32\GroupPolicy
2010-01-09 16:41:11 ----HD---- C:\ProgramData
2010-01-09 16:35:42 ----D---- C:\Users\Mike\AppData\Roaming\VMware
2010-01-09 13:32:04 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-04 09:49:29 ----D---- C:\Users\Mike\AppData\Roaming\BESTplayer
2010-01-03 23:35:24 ----D---- C:\Windows\system32\drivers
2010-01-01 11:10:34 ----D---- C:\Windows\system32\WDI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2009-12-12 128376]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2009-12-12 29520]
R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-01-21 350720]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2009-12-12 74328]
R1 UGURU;UGURU; C:\Windows\system32\drivers\uGuru.sys [2006-10-02 21048]
R2 Hardlock;Hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [2004-11-05 670208]
R2 Haspnt;Haspnt; \??\C:\Windows\system32\drivers\Haspnt.sys [2010-01-03 47616]
R2 hcmon;VMware hcmon; \??\C:\Windows\system32\drivers\hcmon.sys [2009-10-22 32304]
R2 vmci;VMware vmci; \??\C:\Windows\system32\Drivers\vmci.sys [2009-10-22 70704]
R2 VMnetBridge;VMware Bridge Protocol; C:\Windows\system32\DRIVERS\vmnetbridge.sys [2009-10-22 36400]
R2 VMnetuserif;VMware Network Application Interface; \??\C:\Windows\system32\drivers\vmnetuserif.sys [2009-10-22 26288]
R2 vmx86;VMware vmx86; \??\C:\Windows\system32\Drivers\vmx86.sys [2009-10-22 853936]
R2 vstor2-ws60;Vstor2 WS60 Virtual Storage Driver; \??\C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys [2009-10-12 22448]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-03-26 2103512]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-06-10 9899296]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-06-16 122368]
R3 vmkbd;VMware kbd; \??\C:\Windows\system32\drivers\VMkbd.sys [2009-10-22 23216]
R3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys [2009-10-22 16560]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S2 Sentinel;Sentinel; C:\Windows\System32\Drivers\SENTINEL.SYS [2008-04-02 76288]
S3 ax6ngqrt;ax6ngqrt; C:\Windows\system32\drivers\ax6ngqrt.sys []
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\Windows\system32\DRIVERS\bridge.sys [2008-01-21 93696]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2008-01-21 93696]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Sterownik funkcji Microsoft 1.1 UAA dla usługi standardu High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 Memctl;Memctl; \??\C:\Program Files\U-ABIT\FlashMenu\Memctl.sys [2006-04-18 4047]
S3 MSKSSRV;Serwer proxy usługi Microsoft Streaming; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Serwer proxy zegara Microsoft Streaming; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Serwer proxy menedżera jakości Microsoft Streaming; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konwerter strumieni Tee/Sink-to-Sink Microsoft Streaming; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 pgfilter;pgfilter; \??\C:\Program Files\PeerGuardian2\pgfilter.sys [2007-06-02 8192]
S3 RTL8023xp;Sterownik Realtek 10/100 NIC Family NDIS x86; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2006-11-02 47104]
S3 Ser2pl;Prolific Serial port driver; C:\Windows\system32\DRIVERS\ser2pl.sys [2007-07-31 76800]
S3 usb_rndisx;Karta USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2008-01-21 15872]
S3 usbscan;Sterownik skanera USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 vmusb;VMware USB Client Driver; C:\Windows\System32\Drivers\vmusb.sys [2009-10-22 31280]
S3 Winflash;WINFLASH; \??\C:\Program Files\U-ABIT\FlashMenu\WinFlash.sys [2006-04-18 3548]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe [2009-12-12 723632]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MSSQL$ECSQLEXPRESS;SQL Server (ECSQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2007-02-10 29178224]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-10-20 71096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-06-10 211488]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 SQLBrowser;SQLBrowser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2007-02-10 242544]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2007-02-10 89968]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol 52\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Windows\System32\nvSCPAPISvr.exe [2009-06-10 232960]
R2 VMAuthdService;VMware Authorization Service; C:\Program Files\VMware\VMware Workstation\vmware-authd.exe [2009-10-22 113200]
R2 VMnetDHCP;VMware DHCP Service; C:\Windows\system32\vmnetdhcp.exe [2009-10-22 334384]
R2 VMUSBArbService;VMware USB Arbitration Service; C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2009-10-22 563760]
R2 VMware NAT Service;VMware NAT Service; C:\Windows\system32\vmnat.exe [2009-10-22 395824]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-01-21 523776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SolarWinds TFTP Server;SolarWinds TFTP Server; C:\Program Files\SolarWinds\TFTPServer\SolarWinds TFTP Server.exe [2009-10-20 54272]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2010-01-10 72704]
S3 ufad-ws60;VMware Agent Service; C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe [2009-10-12 191024]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-01-21 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2008-01-21 917504]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 45272]
-----------------EOF-----------------
OTL:
http://wklej.org/hash/fec1fa1c70e/
http://wklej.org/hash/fc2ba3bfe75/