
- Kod: Zaznacz wszystko
Deckard's System Scanner v20071014.68
Run by Szymon on 2008-08-08 09:58:41
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
9: 2008-08-08 07:58:44 UTC - RP84 - Deckard's System Scanner Restore Point
8: 2008-08-07 02:04:01 UTC - RP83 - Usunięto WOS EURO Online
7: 2008-08-06 15:42:29 UTC - RP82 - Punkt kontrolny systemu
6: 2008-08-05 15:19:30 UTC - RP81 - Installed Samsung Master
5: 2008-08-05 15:19:13 UTC - RP80 - Installed Windows Media Format 9 Series Runtime Setup
-- First Restore Point --
1: 2008-08-05 09:22:23 UTC - RP76 - Punkt kontrolny systemu
Backed up registry hives.
Performed disk cleanup.
[color=red]Percentage of Memory in Use: 80% (more than 75%).[/color]
-- HijackThis (run as Szymon.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:59, on 2008-08-08
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\RUNDLL32.EXE
D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Nowe Gadu-Gadu\gg.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\nvsvc32.exe
d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
D:\Program Files\foobar2000\foobar2000.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Documents and Settings\Szymon\Pulpit\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Szymon.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VirtualCloneDrive] "D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "D:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Anno 1503 Zlota Edycja Drivers Auto Removal (pr2ajfae) (pr2ajfae) - Cenega Poland - C:\WINDOWS\system32\pr2ajfae.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 4564 bytes
-- File Associations -----------------------------------------------------------
[COLOR=red].cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*[/COLOR]
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - c:\windows\system32\drivers\sfvfs02.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 VClone - c:\windows\system32\drivers\vclone.sys <Not Verified; Elaborate Bytes AG; Virtual CloneDrive>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.2.0.3) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.2.0.3>
R3 EuMusDesignVirtualAudioCableWdm_s2x (Sound2x Audio Cable (WDM)) - c:\windows\system32\drivers\vacs2xkd.sys <Not Verified; Eugene V. Muzychenko; Sound2x Audio Cable>
S3 ASPI (Advanced SCSI Programming Interface Driver) - c:\windows\system32\drivers\aspi32.sys <Not Verified; Adaptec; Adaptec's ASPI Layer>
S3 DNINDIS5 (DNINDIS5 NDIS Protocol Driver) - c:\windows\system32\dnindis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S3 hwdatacard (Huawei DataCard USB Modem and USB Serial) - c:\windows\system32\drivers\ewusbmdm.sys (file missing)
S3 mcdbus (Driver for MagicISO SCSI Host Controller) - c:\windows\system32\drivers\mcdbus.sys (file missing)
S3 NPF (NetGroup Packet Filter Driver) - c:\windows\system32\drivers\npf.sys <Not Verified; CACE Technologies; WinPcap Netgroup Packet Filter Driver>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 AntiVirScheduler (AntiVir PersonalEdition Classic Scheduler) - "d:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; AntiVir Workstation>
R2 StarWindServiceAE (StarWind AE Service) - d:\program files\alcohol soft\alcohol 120\starwind\starwindserviceae.exe <Not Verified; Rocket Division Software; StarWind Alcohol Edition>
S3 rpcapd (Remote Packet Capture Protocol v.0 (experimental)) - "c:\program files\winpcap\rpcapd.exe" -d -f "c:\program files\winpcap\rpcapd.ini" <Not Verified; CACE Technologies; Remote Packet Capture Daemon>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Kontroler Ethernet
Device ID: PCI\VEN_10EC&DEV_8167&SUBSYS_816710EC&REV_10\4&1F2C41BC&0&2810
Manufacturer:
Name: Kontroler Ethernet
PNP Device ID: PCI\VEN_10EC&DEV_8167&SUBSYS_816710EC&REV_10\4&1F2C41BC&0&2810
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Kontroler Ethernet
Device ID: PCI\VEN_10B9&DEV_5263&SUBSYS_52631849&REV_40\3&267A616A&0&68
Manufacturer:
Name: Kontroler Ethernet
PNP Device ID: PCI\VEN_10B9&DEV_5263&SUBSYS_52631849&REV_40\3&267A616A&0&68
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Kontroler magazynu masowego
Device ID: PCI\VEN_10B9&DEV_5289&SUBSYS_52891849&REV_10\3&267A616A&0&71
Manufacturer:
Name: Kontroler magazynu masowego
PNP Device ID: PCI\VEN_10B9&DEV_5289&SUBSYS_52891849&REV_10\3&267A616A&0&71
Service:
-- Files created between 2008-07-08 and 2008-08-08 -----------------------------
2008-08-07 04:04:04 0 d-------- C:\WINDOWS\System32\appmgmt
2008-08-07 02:58:21 416304 --a------ C:\WINDOWS\System32\MPG4C32.DLL <Not Verified; Microsoft Corporation; Microsoft MPEG-4 Video Codec>
2008-08-05 17:19:54 8704 --a------ C:\WINDOWS\System32\vidccleaner.exe <Not Verified; ; vidccleaner Application>
2008-08-05 17:19:35 217088 --a------ C:\WINDOWS\System32\skjpeg40.dll <Not Verified; STOIK Software; STOIK Software skjpeg>
2008-08-05 17:19:35 83968 --a------ C:\WINDOWS\System32\Skbase40.dll <Not Verified; STOIK Software Ltd.; STOIK Software Ltd. skbase>
2008-08-05 17:19:32 0 d-------- C:\Program Files\Samsung
2008-08-05 17:19:20 997888 --a------ C:\WINDOWS\System32\wmvdmoe2.dll <Not Verified; Microsoft Corporation; Microsoft® Windows Media Services>
2008-08-05 17:19:20 892416 --a------ C:\WINDOWS\System32\wmspdmoe.dll <Not Verified; Microsoft Corporation; Microsoft® Windows Media Services>
2008-08-05 17:19:20 1111040 --a------ C:\WINDOWS\System32\wmsdmoe2.dll <Not Verified; Microsoft Corporation; Microsoft® Windows Media Services>
2008-08-05 11:30:56 68096 --a------ C:\WINDOWS\zip.exe
2008-08-05 11:30:56 49152 --a------ C:\WINDOWS\VFind.exe
2008-08-05 11:30:56 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-08-05 11:30:56 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-08-05 11:30:56 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-08-05 11:30:56 98816 --a------ C:\WINDOWS\sed.exe
2008-08-05 11:30:56 80412 --a------ C:\WINDOWS\grep.exe
2008-08-05 11:30:56 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-08-05 11:11:25 0 d-------- C:\Program Files\Trend Micro
2008-08-05 10:49:21 21840 --a------ C:\WINDOWS\System32\SIntfNT.dll
2008-08-05 10:49:21 17212 --a------ C:\WINDOWS\System32\SIntf32.dll
2008-08-05 10:49:21 12067 --a------ C:\WINDOWS\System32\SIntf16.dll
2008-08-05 10:47:41 151552 --a------ C:\WINDOWS\System32\MSOSS.DLL <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(R) Operating System>
2008-08-05 07:22:56 0 d-------- C:\Program Files\KONAMI
2008-08-05 06:59:01 0 d-------- C:\Gry
2008-08-01 23:29:08 0 d-------- C:\Program Files\AVD Graphic Studio 6.7 TRIAL
2008-07-21 19:12:47 0 d-------- C:\Program Files\Common Files\Adobe
2008-07-13 00:10:46 685816 --a------ C:\WINDOWS\System32\drivers\sptd.sys
2008-07-12 23:50:16 765952 --a------ C:\WINDOWS\System32\xvidcore.dll
2008-07-12 23:50:15 180224 --a------ C:\WINDOWS\System32\xvidvfw.dll
2008-07-12 23:50:15 0 d-------- C:\Program Files\Xvid
2008-07-11 14:29:34 0 d-------- C:\Program Files\Diablo Mod PL
2008-07-11 14:24:21 61440 --a------ C:\WINDOWS\diabunin.exe
2008-07-11 14:24:21 86528 --a------ C:\WINDOWS\bnetunin.exe
2008-07-11 13:15:57 60416 --a------ C:\WINDOWS\ALCFDRTM.EXE <Not Verified; Realtek Semiconductor Corp.; Realtek ALCFDRTM>
2008-07-11 13:15:49 0 d-------- C:\WINDOWS\System32\Lang
-- Find3M Report ---------------------------------------------------------------
2008-08-07 23:14:00 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\foobar2000
2008-08-07 04:03:34 355486 --a------ C:\WINDOWS\System32\perfh015.dat
2008-08-07 04:03:34 49492 --a------ C:\WINDOWS\System32\perfc015.dat
2008-08-07 04:03:30 0 d-------- C:\Program Files\Usługi online
2008-08-07 02:57:20 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-08-05 13:30:03 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\Ford Street Racing
2008-08-05 11:33:07 0 d-------- C:\Program Files\Common Files
2008-08-05 11:12:25 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\MegauploadToolbar
2008-07-26 22:04:09 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\Nowe Gadu-Gadu
2008-07-24 02:26:41 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\Adobe
2008-07-21 18:56:18 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\InstallShield
2008-07-13 03:33:20 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\DeepBurner
2008-07-05 02:09:23 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\Mozilla
2008-07-04 02:13:59 0 d-------- C:\Program Files\Google
2008-06-28 20:45:38 0 d-------- C:\Program Files\Common Files\EasyInfo
2008-06-23 08:39:35 0 d-------- C:\Program Files\directx
2008-06-21 19:31:28 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\Talkback
2008-06-19 01:42:13 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\Media Player Classic
2008-06-19 01:41:59 0 d-------- C:\Program Files\Real Alternative
2008-06-19 01:41:53 0 d-------- C:\Documents and Settings\Szymon\Dane aplikacji\Real
2008-06-17 07:20:09 0 d-------- C:\Program Files\7-Zip
2008-06-13 04:46:03 711 --a------ C:\WINDOWS\eReg.dat
2008-06-13 04:35:51 0 d-------- C:\Program Files\Maxis
2008-06-11 01:56:50 0 d-------- C:\Program Files\%systemdir%
2008-06-02 05:43:24 286720 --a------ C:\WINDOWS\iun506.exe <Not Verified; Indigo Rose Corporation; Setup Factory 5.0 Uninstaller>
2008-06-02 02:10:06 58 --a------ C:\WINDOWS\winvidni.sys
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-22 12:22]
"nwiz"="nwiz.exe" [2006-10-22 12:22 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-10-22 12:22]
"VirtualCloneDrive"="D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 15:21]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 C:\WINDOWS\soundman.exe]
"avgnt"="D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 20:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-29 00:00]
"Nowe Gadu-Gadu"="D:\Program Files\Nowe Gadu-Gadu\gg.exe" [2008-06-27 10:28]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 14:44:06]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
-- End of Deckard's System Scanner: finished at 2008-08-08 09:59:53 ------------
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:53, on 2008-08-07
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\RUNDLL32.EXE
D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Program Files\foobar2000\foobar2000.exe
C:\Program Files\Last.fm\LastFM.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\nvsvc32.exe
d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\wuauclt.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VirtualCloneDrive] "D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "D:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Anno 1503 Zlota Edycja Drivers Auto Removal (pr2ajfae) (pr2ajfae) - Cenega Poland - C:\WINDOWS\system32\pr2ajfae.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 4489 bytes
Złapałem z tego co zauważyłem dwa wirusy. Jednego którego nazwy nie znam i on zablokował tapetę, managera zadań, spowolnił maksymalnie komputer oraz "sprowadził" Antyvirusa Xp 2008. Odpaliłem Combofixa i po restarcie systemu wszystko wyglądało ok lecz jednak wolę wstawić logi gdyż mimo wszystko coś mi tu nie pasuje.