
- Kod: Zaznacz wszystko
ComboFix 09-04-04.01 - HiVu 2009-04-06 20:34:54.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.2047.1619 [GMT 2:00]
Uruchomiony z: c:\documents and settings\HiVu\Moje dokumenty\Downloads\ComboFix.exe
FW: ActiveArmor Firewall *disabled*
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
.
((((((((((((((((((((((((( Pliki utworzone od 2009-03-06 do 2009-04-06 )))))))))))))))))))))))))))))))
.
2009-04-06 15:42 . 2009-04-06 15:42 98,304 --a------ c:\windows\system32\CmdLineExt.dll
2009-04-06 14:24 . 2009-04-06 15:14 <DIR> d-------- c:\program files\Kolekcja Klasyki
2009-04-06 12:51 . 2009-04-06 12:51 <DIR> d-------- C:\ProgramData
2009-04-06 12:51 . 2009-04-06 12:51 1,214 --a------ c:\windows\system32\ealregsnapshot1.reg
2009-04-06 12:41 . 2009-04-06 12:51 <DIR> d-------- c:\program files\Electronic Arts
2009-04-02 22:35 . 2009-04-02 22:35 <DIR> d-------- c:\documents and settings\NetworkService\Dane aplikacji\Xfire
2009-04-02 21:48 . 2009-04-05 21:30 <DIR> d-------- c:\program files\Xfire
2009-04-02 21:48 . 2009-04-05 15:02 <DIR> d-------- c:\documents and settings\HiVu\Dane aplikacji\Xfire
2009-03-31 21:48 . 2009-04-04 16:15 <DIR> d-------- c:\windows\system32\Adobe
2009-03-31 17:32 . 2009-03-31 17:32 <DIR> d-------- c:\windows\Sun
2009-03-31 17:00 . 2009-03-31 17:00 <DIR> d-------- c:\program files\Java
2009-03-31 17:00 . 2009-03-31 17:00 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-31 17:00 . 2009-03-31 17:00 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-30 19:34 . 2009-03-30 19:34 <DIR> d-------- c:\program files\Teamspeak2_RC2
2009-03-30 19:34 . 2009-03-30 19:34 <DIR> d-------- c:\documents and settings\HiVu\Dane aplikacji\teamspeak2
2009-03-30 19:34 . 2009-03-30 19:34 34,064 --a------ c:\windows\system32\lhacm.acm
2009-03-30 14:09 . 2009-03-30 14:10 <DIR> d---s---- c:\program files\HLSW
2009-03-30 14:09 . 2009-03-30 14:21 <DIR> d-------- c:\documents and settings\HiVu\Dane aplikacji\HLSW
2009-03-29 18:24 . 2009-03-29 18:24 <DIR> d-------- c:\windows\ServicePackFiles
2009-03-29 18:24 . 2008-04-14 22:51 294,912 -----c--- c:\windows\system32\dllcache\dlimport.exe
2009-03-29 18:22 . 2009-03-29 18:22 <DIR> d-------- c:\windows\EHome
2009-03-29 15:44 . 2009-03-29 15:44 <DIR> d-------- c:\windows\ERUNT
2009-03-29 15:44 . 2009-03-29 15:44 <DIR> d-------- C:\ERDNT
2009-03-29 15:33 . 2009-03-29 15:33 <DIR> d-------- c:\program files\HDCleaner
2009-03-29 14:46 . 2009-04-05 21:29 <DIR> d-------- c:\program files\Odkurzacz
2009-03-29 14:42 . 2009-03-29 14:42 <DIR> d-------- c:\program files\CCleaner
2009-03-29 13:45 . 2009-03-29 13:45 <DIR> d-------- c:\program files\Trend Micro
2009-03-29 11:15 . 2009-03-29 11:15 <DIR> d-------- c:\program files\AMD
2009-03-29 11:15 . 2009-03-29 11:15 <DIR> d-------- c:\documents and settings\HiVu\Dane aplikacji\InstallShield
2009-03-28 23:29 . 2009-03-28 23:29 <DIR> d-------- c:\program files\Radeon Omega Drivers
2009-03-28 23:29 . 2009-03-28 23:29 <DIR> d-------- c:\program files\MultiRes
2009-03-28 23:29 . 2009-03-28 23:29 472,576 --a------ c:\windows\Radeon Omega Drivers v4.8.442 Uninstall.exe
2009-03-28 23:08 . 2009-03-28 23:08 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\ATI
2009-03-28 22:52 . 2009-03-28 22:52 <DIR> d-------- c:\documents and settings\HiVu\Dane aplikacji\Ventrilo
2009-03-28 22:48 . 2009-03-28 22:48 <DIR> d-------- c:\program files\Mumble
2009-03-28 22:48 . 2009-03-28 22:48 <DIR> d-------- c:\documents and settings\HiVu\Dane aplikacji\Mumble
2009-03-28 22:05 . 2009-04-06 19:46 <DIR> d-------- c:\program files\mIRC
2009-03-28 22:05 . 2009-04-06 19:50 <DIR> d-------- c:\documents and settings\HiVu\Dane aplikacji\mIRC
2009-03-28 22:01 . 2009-03-28 22:01 <DIR> d-------- c:\program files\Ventrilo
2009-03-28 22:01 . 2009-03-28 22:01 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-03-28 21:40 . 2009-03-28 23:34 <DIR> d-------- c:\program files\ATI
2009-03-28 21:38 . 2009-03-28 21:38 <DIR> d-------- C:\ATI
2009-03-28 17:56 . 2009-03-28 17:56 <DIR> d-------- c:\program files\Valve
2009-03-28 17:49 . 2009-03-28 17:49 <DIR> d-------- c:\documents and settings\HiVu\Dane aplikacji\ATI
2009-03-28 17:48 . 2009-03-28 17:48 0 --a------ c:\windows\ativpsrm.bin
2009-03-28 17:46 . 2009-03-28 17:50 <DIR> d-------- c:\documents and settings\HiVu\Dane aplikacji\Nowe Gadu-Gadu
2009-03-28 17:45 . 2009-03-28 17:45 <DIR> d-------- c:\program files\Nowe Gadu-Gadu
2009-03-28 17:43 . 2008-04-14 22:50 21,504 --a------ c:\windows\system32\hidserv.dll
2009-03-28 17:43 . 2001-08-17 23:59 3,072 --a------ c:\windows\system32\drivers\audstub.sys
2009-03-28 17:42 . 2009-03-28 17:47 <DIR> d-------- c:\program files\Common Files\ATI Technologies
2009-03-28 17:42 . 2008-04-14 22:50 77,312 --a------ c:\windows\system32\usbui.dll
2009-03-28 17:42 . 2008-04-14 21:35 58,880 --a------ c:\windows\system32\drivers\redbook.sys
2009-03-28 17:40 . 2009-03-28 17:40 <DIR> dr-h----- c:\documents and settings\Default User\Ustawienia lokalne
2009-03-28 17:40 . 2009-03-28 17:40 <DIR> d-------- c:\documents and settings\Default User\Ulubione
2009-03-28 17:40 . 2009-03-28 16:45 <DIR> d--h----- c:\documents and settings\Default User\Szablony
2009-03-28 17:40 . 2009-03-28 17:40 <DIR> d-------- c:\documents and settings\Default User\Pulpit
2009-03-28 17:40 . 2009-03-28 17:40 <DIR> d-------- c:\documents and settings\Default User\Moje dokumenty
2009-03-28 17:40 . 2009-03-28 17:40 <DIR> dr------- c:\documents and settings\Default User\Menu Start
2009-03-28 17:40 . 2009-03-28 17:40 <DIR> d-------- c:\documents and settings\All Users\Ulubione
2009-03-28 17:40 . 2009-03-28 17:40 <DIR> d--h----- c:\documents and settings\All Users\Szablony
2009-03-28 17:40 . 2009-04-06 15:14 <DIR> d-------- c:\documents and settings\All Users\Pulpit
2009-03-28 17:40 . 2009-03-29 18:25 <DIR> dr------- c:\documents and settings\All Users\Menu Start
2009-03-28 17:40 . 2009-03-28 16:46 <DIR> dr------- c:\documents and settings\All Users\Dokumenty
2009-03-28 17:39 . 2009-04-06 20:34 <DIR> d-------- c:\windows\system32\CatRoot2
2009-03-28 17:39 . 2009-03-29 18:26 <DIR> d-------- c:\windows\system32\CatRoot
2009-03-28 17:39 . 2009-03-28 17:40 <DIR> dr-h----- c:\documents and settings\Default User\Dane aplikacji
2009-03-28 17:39 . 2009-03-28 23:08 <DIR> dr-h----- c:\documents and settings\All Users\Dane aplikacji
2009-03-28 17:39 . 2004-08-04 14:00 1,014,483 --a--c--- c:\windows\system32\dllcache\SP2.CAT
2009-03-28 17:39 . 2004-08-04 14:00 808,524 --a--c--- c:\windows\system32\dllcache\NT5IIS.CAT
2009-03-28 17:39 . 2004-08-04 14:00 399,670 --a--c--- c:\windows\system32\dllcache\MAPIMIG.CAT
2009-03-28 17:39 . 2004-08-04 14:00 37,509 --a--c--- c:\windows\system32\dllcache\MW770.CAT
2009-03-28 17:39 . 2004-08-04 14:00 13,497 --a--c--- c:\windows\system32\dllcache\HPCRDP.CAT
2009-03-28 17:39 . 2004-08-04 14:00 8,599 --a--c--- c:\windows\system32\dllcache\IASNT4.CAT
2009-03-28 17:39 . 2004-08-04 14:00 7,407 --a--c--- c:\windows\system32\dllcache\OEMBIOS.CAT
2009-03-28 17:39 . 2004-08-04 14:00 7,334 --a--c--- c:\windows\system32\dllcache\wmerrenu.cat
2009-03-28 17:38 . 2009-03-29 18:29 <DIR> d--h----- c:\documents and settings\Default User
2009-03-28 17:38 . 2009-03-28 16:48 <DIR> d-------- c:\documents and settings\All Users
2009-03-28 17:38 . 2009-03-28 16:51 <DIR> d-------- C:\Documents and Settings
2009-03-28 17:38 . 2008-05-21 01:53 93,696 -ra------ c:\windows\system32\drivers\AtiHdmi.sys
2009-03-28 17:37 . 2009-03-28 21:40 <DIR> d-------- c:\program files\ATI Technologies
2009-03-28 17:37 . 2008-07-04 04:48 3,107,788 -ra------ c:\windows\system32\ativvaxx.dat
2009-03-28 17:37 . 2008-07-04 04:48 3,107,788 -ra------ c:\windows\system32\ativva5x.dat
2009-03-28 17:37 . 2008-07-04 04:48 887,724 -ra------ c:\windows\system32\ativva6x.dat
2009-03-28 17:37 . 2009-02-25 16:15 593,920 --------- c:\windows\system32\ati2sgag.exe
2009-03-28 17:37 . 2009-02-25 23:42 442,368 --a------ c:\windows\system32\ATIDEMGX.dll
2009-03-28 17:37 . 2009-02-25 23:09 307,200 --a------ c:\windows\system32\atiiiexx.dll
2009-03-28 17:37 . 2009-01-26 19:55 182,995 --a------ c:\windows\system32\atiicdxx.dat
2009-03-28 17:37 . 2008-12-29 21:35 15,485 --a------ c:\windows\atiogl.xml
2009-03-28 17:37 . 2007-08-31 15:20 7,167 -ra------ c:\windows\system32\atifglpf.xml
2009-03-28 17:33 . 2008-04-14 00:15 172,416 --a------ c:\windows\system32\drivers\kmixer.sys
2009-03-28 17:33 . 2008-04-13 22:09 142,592 --a------ c:\windows\system32\drivers\aec.sys
2009-03-28 17:33 . 2008-04-14 00:47 83,072 --a------ c:\windows\system32\drivers\wdmaud.sys
2009-03-28 17:33 . 2008-04-14 00:45 60,800 --a------ c:\windows\system32\drivers\sysaudio.sys
2009-03-28 17:33 . 2008-04-14 00:15 56,576 --a------ c:\windows\system32\drivers\swmidi.sys
2009-03-28 17:33 . 2008-04-14 00:15 52,864 --a------ c:\windows\system32\drivers\dmusic.sys
2009-03-28 17:33 . 2008-04-14 00:09 7,552 --a------ c:\windows\system32\drivers\mskssrv.sys
2009-03-28 17:33 . 2008-04-14 00:15 6,272 --a------ c:\windows\system32\drivers\splitter.sys
2009-03-28 17:33 . 2008-04-14 00:09 5,376 --a------ c:\windows\system32\drivers\mspclock.sys
2009-03-28 17:33 . 2008-04-14 00:09 4,992 --a------ c:\windows\system32\drivers\mspqm.sys
2009-03-28 17:33 . 2008-04-14 00:15 2,944 --a------ c:\windows\system32\drivers\drmkaud.sys
2009-03-28 17:32 . 2009-03-28 17:32 <DIR> d-------- c:\program files\Analog Devices
2009-03-28 17:32 . 2006-03-17 11:18 392,960 -ra------ c:\windows\system32\drivers\senfilt.sys
2009-03-28 17:32 . 2007-01-16 03:09 293,888 -ra------ c:\windows\system32\drivers\ADIHdAud.sys
2009-03-28 17:32 . 2008-04-14 00:49 146,048 --a------ c:\windows\system32\drivers\portcls.sys
2009-03-28 17:32 . 2008-04-14 22:51 129,536 --a------ c:\windows\system32\ksproxy.ax
2009-03-28 17:32 . 2006-08-07 00:57 93,952 -ra------ c:\windows\system32\drivers\aeaudio.sys
2009-03-28 17:32 . 2003-08-19 12:36 65,536 --a--c--- c:\windows\system32\dllcache\a3d.dll
2009-03-28 17:32 . 2003-08-19 12:36 65,536 -ra------ c:\windows\system32\a3d.dll
2009-03-28 17:32 . 2008-04-14 00:15 60,160 --a------ c:\windows\system32\drivers\drmk.sys
2009-03-28 17:32 . 2006-06-30 09:00 28,160 -ra------ c:\windows\system32\PostProc.dll
2009-03-28 17:32 . 2007-08-10 20:53 26,488 --a------ c:\windows\system32\spupdsvc.exe
2009-03-28 17:32 . 2008-04-14 22:50 4,096 --a------ c:\windows\system32\ksuser.dll
2009-03-28 17:24 . 2009-04-05 21:26 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-03-28 17:24 . 2009-03-28 17:24 <DIR> d-------- c:\program files\DIFX
2009-03-28 17:24 . 2006-06-19 00:51 43,520 --a------ c:\windows\system32\drivers\AmdK8.sys
2009-03-28 17:16 . 2009-04-06 15:14 <DIR> d--h----- c:\program files\InstallShield Installation Information
2009-03-28 17:15 . 2009-03-28 17:15 1,024 --a------ C:\.rnd
2009-03-28 17:14 . 2009-03-28 17:14 22 --a------ c:\windows\FileName
2009-03-28 17:13 . 2009-03-28 17:13 <DIR> d-------- c:\program files\NVIDIA Corporation
2009-03-28 17:12 . 2009-03-28 17:12 <DIR> d-------- c:\windows\ASUSInstAll
2009-03-28 17:12 . 2006-08-29 17:29 446,464 --a------ c:\windows\system32\CapabilityTable.exe
2009-03-28 17:12 . 2006-08-07 08:07 208,896 --------- c:\windows\system32\nvuide.exe
2009-03-28 17:12 . 2006-06-01 09:32 1,570 --------- c:\windows\system32\nvide.nvu
2009-03-28 17:11 . 2006-08-14 08:51 363,008 -ra------ c:\windows\system32\idecoiins.dll
2009-03-28 17:11 . 2006-08-14 08:51 363,008 -ra------ c:\windows\system32\idecoi.dll
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-28 14:52 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2009-03-28 14:49 --------- d-----w c:\program files\microsoft frontpage
2009-03-28 14:47 --------- d-----w c:\program files\Usługi online
2009-03-20 22:26 41,808 ----a-w c:\windows\system32\xfcodec.dll
2009-03-19 15:08 499,712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-19 15:08 348,160 ----a-w c:\windows\system32\msvcr71.dll
2009-02-25 22:58 3,565,568 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2009-02-25 21:41 325,120 ----a-w c:\windows\system32\ati2dvag.dll
2009-02-25 21:30 204,800 ----a-w c:\windows\system32\atipdlxx.dll
2009-02-25 21:30 11,841,536 ----a-w c:\windows\system32\atioglxx.dll
2009-02-25 21:29 43,520 ----a-w c:\windows\system32\ati2edxx.dll
2009-02-25 21:29 26,112 ----a-w c:\windows\system32\Ati2mdxx.exe
2009-02-25 21:29 155,648 ----a-w c:\windows\system32\Oemdspif.dll
2009-02-25 21:29 155,648 ----a-w c:\windows\system32\ati2evxx.dll
2009-02-25 21:27 602,112 ----a-w c:\windows\system32\ati2evxx.exe
2009-02-25 21:26 53,248 ----a-w c:\windows\system32\ATIDDC.DLL
2009-02-25 21:16 3,817,984 ----a-w c:\windows\system32\ati3duag.dll
2009-02-25 20:59 2,670,080 ----a-w c:\windows\system32\ativvaxx.dll
2009-02-25 20:44 49,664 ----a-w c:\windows\system32\amdpcom32.dll
2009-02-25 20:40 475,136 ----a-w c:\windows\system32\atikvmag.dll
2009-02-25 20:38 17,408 ----a-w c:\windows\system32\atitvo32.dll
2009-02-25 20:38 126,976 ----a-w c:\windows\system32\atiadlxx.dll
2009-02-25 20:37 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2009-02-25 20:35 290,816 ----a-w c:\windows\system32\atiok3x2.dll
2009-02-25 20:32 626,688 ----a-w c:\windows\system32\ati2cqag.dll
2009-02-25 20:32 45,056 ----a-w c:\windows\system32\aticalrt.dll
2009-02-25 20:32 45,056 ----a-w c:\windows\system32\aticalcl.dll
2009-02-25 20:30 3,227,648 ----a-w c:\windows\system32\aticaldd.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Nowe Gadu-Gadu"="c:\program files\Nowe Gadu-Gadu\gg.exe" [2009-02-27 9339496]
"Steam"="c:\program files\valve\steam\steam.exe" [2009-03-29 1410296]
"Odkurzacz-MCD"="c:\program files\Odkurzacz\odk_mcd.exe" [2008-08-16 264704]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-07-21 2752512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-06 849280]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2009-03-28 17:36 133104 c:\documents and settings\HiVu\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2009-03-31 17:04 148888 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HLSW\\hlsw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\doluse\\counter-strike\\hl.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-03-28 93696]
R4 ps6ajfae;Anno 1503 Zlota Edycja Synchronization Driver (ps6ajfae);c:\windows\system32\drivers\ps6ajfae.sys --> c:\windows\system32\drivers\ps6ajfae.sys [?]
S3 gsplittm;gsplittm;\??\c:\docume~1\HiVu\USTAWI~1\Temp\gsplittm.sys --> c:\docume~1\HiVu\USTAWI~1\Temp\gsplittm.sys [?]
--- Inne Usługi/Sterowniki w Pamięci ---
*Deregistered* - pe3ajfae
.
Zawartość folderu 'Zaplanowane zadania'
2009-04-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-299502267-725345543-1004.job
- c:\documents and settings\HiVu\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2009-03-28 17:36]
.
.
------- Skan uzupełniający -------
.
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-06 20:35:32
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(640)
c:\windows\system32\Ati2evxx.dll
.
Czas ukończenia: 2009-04-06 20:36:02
ComboFix-quarantined-files.txt 2009-04-06 18:36:00
Przed: 92 502 446 080 bajtów wolnych
Po: 92,494,704,640 bajtów wolnych
234
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:34:15, on 2009-04-06
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Documents and Settings\HiVu\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HiVu\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HiVu\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HiVu\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HiVu\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
--
End of file - 5398 bytes
Już mnie szlak trafia , cały czas coś się zawiesza zainstalowałem antywirusa + IS było źle odinstalowałem ( wtedy to już nic prawie nie chodziło )jeszcze gorzej....