

Po odzyskaniu systemu Window stał się nie stabilny!


Proszę o sprawdzenie loga HijackThis i Combo, może tu widać jakiś problem.. Jeśli trzeba jakiś jeszcze proszę o odpowiedź.
Z góry DZIĘKUJĘ!

- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:15:04, on 2008-12-29
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\Messen.exe
C:\Program Files\SYSTMEM.EXE
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\PeerGuardian2\pg2.exe
D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\explorer.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Gadu-Gadu\gg.exe
D:\Program Files\Winamp\winamp.exe
E:\Program Files\hijackthis\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
F2 - REG:system.ini: Shell=Explorer.exe %PROGRAMFILES%\SYSTMEM.EXE
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SYSTMEM.EXE] C:\Program Files\\SYSTMEM.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATI Video Driver Control] Messen.exe
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunServices: [ATI Video Driver Control] Messen.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] D:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [ATI Video Driver Control] Messen.exe
O4 - HKCU\..\RunServices: [ATI Video Driver Control] Messen.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATI Video Driver Control] Messen.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [ATI Video Driver Control] Messen.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [ATI Video Driver Control] Messen.exe (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{812DB291-1A31-457C-B70E-A23B1C66735F}: NameServer = 217.116.100.65 217.116.100.66
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NET Runtime Optimization Service v2.1.41329_X86 - Unknown owner - C:\WINDOWS\Fonts\wmsncs.exe (file missing)
--
End of file - 4697 bytes
i Combo..
- Kod: Zaznacz wszystko
ComboFix 08-12-28.04 - Ogólny 2008-12-29 21:30:45.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.959.579 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Ogólny.RODZINNY-CWWHAP\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\setup.ini
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-28 do 2008-12-29 )))))))))))))))))))))))))))))))
.
2008-12-29 20:37 . 2008-12-29 20:37 <DIR> d-------- c:\program files\Java
2008-12-29 20:37 . 2008-12-29 20:37 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-29 20:37 . 2008-12-29 20:37 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-29 19:53 . 2008-12-29 19:53 <DIR> d-------- c:\program files\ZTE ZXDSL 852
2008-12-29 19:53 . 2008-12-29 19:54 3,255 --a------ c:\windows\stsetup.htm
2008-12-29 19:48 . 2008-12-29 19:48 <DIR> d-------- c:\windows\Provisioning
2008-12-29 19:48 . 2008-12-29 19:56 <DIR> d-------- c:\windows\PeerNet
2008-12-29 19:48 . 2008-12-29 19:57 <DIR> d-------- c:\windows\ehome
2008-12-29 19:37 . 2008-12-29 19:37 121 --a------ c:\windows\StmClean.Bat
2008-12-29 19:34 . 2004-07-27 16:18 36,864 --------- c:\windows\StmClean.exe
2008-12-29 19:19 . 2008-12-29 19:19 <DIR> d---s---- c:\windows\system32\Microsoft
2008-12-29 19:15 . 2004-08-04 13:00 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2008-12-29 19:14 . 2004-08-04 13:00 2,134,528 --a--c--- c:\windows\system32\dllcache\smtpsnap.dll
2008-12-29 19:12 . 2004-08-04 13:00 16,384 --a--c--- c:\windows\system32\dllcache\isignup.exe
2008-12-29 19:12 . 2004-08-04 13:00 8,192 --a--c--- c:\windows\system32\dllcache\bitsprx2.dll
2008-12-29 19:12 . 2004-08-04 13:00 8,192 --a------ c:\windows\system32\bitsprx2.dll
2008-12-29 19:12 . 2004-08-04 13:00 7,168 --a--c--- c:\windows\system32\dllcache\bitsprx3.dll
2008-12-29 19:12 . 2004-08-04 13:00 7,168 --a------ c:\windows\system32\bitsprx3.dll
2008-12-29 19:12 . 2008-12-29 19:12 749 -rah----- c:\windows\WindowsShell.Manifest
2008-12-29 19:12 . 2008-12-29 19:12 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2008-12-29 19:12 . 2008-12-29 19:12 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2008-12-29 19:12 . 2008-12-29 19:12 749 -rah----- c:\windows\system32\nwc.cpl.manifest
2008-12-29 19:12 . 2008-12-29 19:12 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2008-12-29 19:12 . 2008-12-29 19:12 488 -rah----- c:\windows\system32\logonui.exe.manifest
2008-12-29 19:11 . 2004-08-04 13:00 124,800 --a------ c:\windows\system32\drivers\fltMgr.sys
2008-12-29 19:11 . 2004-08-04 13:00 124,800 --a--c--- c:\windows\system32\dllcache\fltmgr.sys
2008-12-29 19:11 . 2004-08-04 13:00 22,528 --a------ c:\windows\system32\fltMc.exe
2008-12-29 19:11 . 2004-08-04 13:00 22,528 --a--c--- c:\windows\system32\dllcache\fltmc.exe
2008-12-29 19:11 . 2004-08-04 13:00 18,944 --a--c--- c:\windows\system32\dllcache\hscupd.exe
2008-12-29 19:11 . 2004-08-04 13:00 16,896 --a------ c:\windows\system32\fltlib.dll
2008-12-29 19:11 . 2004-08-04 13:00 16,896 --a--c--- c:\windows\system32\dllcache\fltlib.dll
2008-12-29 19:03 . 2003-07-01 21:42 27,904 --a------ c:\windows\system32\drivers\VIAAGP1.SYS
2008-12-29 19:00 . 2004-08-04 13:00 66,082 --a--c--- c:\windows\system32\dllcache\c_28603.nls
2008-12-29 19:00 . 2004-08-04 13:00 66,082 --a------ c:\windows\system32\c_28603.nls
2008-12-29 19:00 . 2004-08-04 13:00 24,661 --a------ c:\windows\system32\spxcoins.dll
2008-12-29 19:00 . 2004-08-04 13:00 13,312 --a------ c:\windows\system32\irclass.dll
2008-12-29 19:00 . 2004-08-04 13:00 13,312 --a--c--- c:\windows\system32\dllcache\irclass.dll
2008-12-28 20:39 . 2008-12-28 20:39 70 --a------ c:\windows\system32\ii
2008-12-28 20:16 . 2008-12-28 20:24 664,064 --a------ c:\windows\system32\hal.exe
2008-12-28 20:10 . 2008-12-28 20:10 664,064 -r-hs---- c:\program files\SYSTMEM.EXE
2008-12-28 19:42 . 2004-08-04 13:00 431,616 --a------ c:\windows\system32\wuapi.dll
2008-12-28 19:42 . 2004-08-04 13:00 184,320 --a------ c:\windows\system32\wuaueng1.dll
2008-12-28 19:42 . 2004-08-04 13:00 168,960 --a------ c:\windows\system32\wuauclt1.exe
2008-12-28 19:42 . 2004-08-04 13:00 163,328 --a------ c:\windows\system32\wuaucpl.cpl
2008-12-28 19:42 . 2004-08-04 13:00 120,320 --a------ c:\windows\system32\wuweb.dll
2008-12-28 19:42 . 2004-08-04 13:00 113,664 --a------ c:\windows\system32\wucltui.dll
2008-12-28 19:42 . 2004-08-04 13:00 36,864 --a------ c:\windows\system32\wups.dll
2008-12-28 17:45 . 2008-12-28 17:45 <DIR> d-------- c:\documents and settings\Ogólny.RODZINNY-CWWHAP\Dane aplikacji\Media Player Classic
2008-12-28 16:46 . 2008-12-29 19:13 316,640 --a------ c:\windows\WMSysPr9.prx
2008-12-28 16:42 . 2008-12-28 17:42 <DIR> d-------- c:\documents and settings\Ogólny.RODZINNY-CWWHAP\Dane aplikacji\Winamp
2008-12-27 20:48 . 2003-03-18 21:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2008-12-27 20:48 . 2003-03-18 20:14 499,712 --a------ c:\windows\system32\MSVCP71.dll
2008-12-27 20:48 . 2003-02-21 04:42 348,160 --a------ c:\windows\system32\MSVCR71.dll
2008-12-27 19:53 . 2008-12-27 19:53 <DIR> d-------- c:\windows\system32\CatRoot_bak
2008-12-27 19:29 . 2008-12-28 17:40 169 --a------ c:\windows\RtlRack.ini
2008-12-27 19:21 . 2008-12-27 19:21 <DIR> d-------- c:\documents and settings\Ogólny.RODZINNY-CWWHAP\Dane aplikacji\iolo
2008-12-27 19:21 . 2008-12-27 19:21 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dane aplikacji\iolo
2008-12-27 19:19 . 2008-12-27 19:19 <DIR> d-------- c:\documents and settings\Ogólny.RODZINNY-CWWHAP\Dane aplikacji\Gadu-Gadu
2008-12-27 19:18 . 2008-12-28 14:19 <DIR> d-------- c:\documents and settings\Ogólny.RODZINNY-CWWHAP\Gadu-Gadu
2008-12-27 19:18 . 2008-12-28 14:19 <DIR> d-------- c:\documents and settings\Ogólny.RODZINNY-CWWHAP\Gadu-Gadu
2008-12-27 18:56 . 2008-12-27 18:56 <DIR> d---s---- c:\documents and settings\Ogólny.RODZINNY-CWWHAP\UserData
2008-12-27 18:56 . 2008-12-27 18:56 <DIR> d---s---- c:\documents and settings\Ogólny.RODZINNY-CWWHAP\UserData
2008-12-27 18:55 . 2008-12-27 21:39 578,560 -rahs---- c:\windows\system32\Messen.exe
2008-12-27 18:55 . 2008-12-29 11:03 65 --a------ c:\windows\system32\o
2008-12-27 18:52 . 2008-12-27 18:52 150,234 --a------ c:\windows\system32\wmsoft75687.exe
2008-12-27 18:52 . 2008-12-27 18:52 112,640 --a------ c:\windows\system32\wmsoft30770.exe
2008-12-27 18:43 . 2008-12-27 18:43 0 --a------ c:\windows\nsreg.dat
2008-12-27 18:23 . 2008-12-27 18:23 <DIR> d-------- c:\program files\ToniArts
2008-12-27 18:12 . 2004-08-04 00:44 130,048 --a------ c:\windows\system32\ksproxy.ax
2008-12-27 18:12 . 2004-08-04 00:44 91,136 --a------ c:\windows\system32\kswdmcap.ax
2008-12-27 18:12 . 2004-08-03 23:10 85,376 --a------ c:\windows\system32\drivers\nabtsfec.sys
2008-12-27 18:12 . 2004-08-04 00:44 61,952 --a------ c:\windows\system32\kstvtune.ax
2008-12-27 18:12 . 2004-08-03 23:10 51,328 --a------ c:\windows\system32\drivers\msdv.sys
2008-12-27 18:12 . 2004-08-04 00:44 43,008 --a------ c:\windows\system32\ksxbar.ax
2008-12-27 18:12 . 2004-08-03 23:10 19,328 --a------ c:\windows\system32\drivers\wstcodec.sys
2008-12-27 18:12 . 2004-08-03 23:10 17,024 --a------ c:\windows\system32\drivers\ccdecode.sys
2008-12-27 18:12 . 2004-08-03 22:58 5,504 --a------ c:\windows\system32\drivers\mstee.sys
2008-12-27 18:12 . 2004-08-04 00:44 4,096 --a------ c:\windows\system32\ksuser.dll
2008-12-27 18:11 . 2008-12-27 18:11 <DIR> d-------- c:\windows\vnDrvBas
2008-12-27 18:11 . 2005-06-17 04:41 61,440 --a------ c:\windows\system32\vuins32.dll
2008-12-27 18:11 . 2006-03-15 03:51 43,008 --a------ c:\windows\system32\drivers\fetnd5bv.sys
2008-12-21 18:16 . 2008-12-21 18:16 <DIR> d-------- c:\documents and settings\Ogólny\Dane aplikacji\iolo
2008-12-21 18:08 . 2008-12-21 18:08 <DIR> d-------- c:\documents and settings\Ogólny\Dane aplikacji\Gadu-Gadu
2008-12-21 18:03 . 2008-12-21 18:03 <DIR> d-------- c:\documents and settings\Ogólny\Gadu-Gadu
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-27 17:23 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-27 16:57 --------- d-----w c:\program files\Realtek AC97
2008-12-27 16:57 --------- d-----w c:\program files\AvRack
2008-12-21 16:37 --------- d-----w c:\program files\Realtek Sound Manager
2008-12-21 16:15 --------- d-----w c:\program files\microsoft frontpage
2008-12-19 13:54 --------- d-----w c:\program files\Zuma deluxe
2008-11-24 14:32 57,344 ----a-w c:\windows\system32\ff_vfw.dll
2008-11-15 16:26 --------- d-----w c:\program files\Picasa2
2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-05-05 20:07 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-05-05 20:07 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-05-05 20:07 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-05-05 20:08 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-05-05 20:08 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( snapshot_2008-12-29_19.42.17,53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-07-07 14:02:26 65,536 ----a-r c:\windows\DSLTest.exe
+ 2006-06-27 09:53:58 102,400 ----a-r c:\windows\stmtrace.exe
+ 2008-11-26 17:17:25 20,560 ----a-w c:\windows\system32\drivers\aswFsBlk.sys
+ 2003-08-12 11:51:00 60,255 ----a-r c:\windows\system32\drivers\stmatm.sys
+ 2006-07-05 12:50:52 683,791 ----a-r c:\windows\system32\drivers\torususb.sys
+ 2008-12-29 19:37:17 144,792 ----a-w c:\windows\system32\java.exe
+ 2008-12-29 19:37:17 144,792 ----a-w c:\windows\system32\javaw.exe
+ 2008-12-29 19:37:17 148,888 ----a-w c:\windows\system32\javaws.exe
+ 2006-06-02 15:38:00 425,984 ----a-r c:\windows\system32\stmcfg32.dll
+ 2004-07-27 15:18:00 36,864 ----a-r c:\windows\system32\stmclean.exe
+ 2006-06-02 08:01:34 151,552 ----a-r c:\windows\system32\stmctrl.dll
+ 2008-12-29 19:37:39 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_c7c.dat
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"PeerGuardian"="d:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
"ATI Video Driver Control"="Messen.exe" [2008-12-27 c:\windows\system32\Messen.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"ATI Video Driver Control"="Messen.exe" [2008-12-27 c:\windows\system32\Messen.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="d:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"SYSTMEM.EXE"="c:\program files\\SYSTMEM.EXE" [2008-12-28 664064]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-29 136600]
"VTTimer"="VTTimer.exe" [2005-03-07 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2006-07-10 c:\windows\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-03-02 c:\windows\soundman.exe]
"AdslTaskBar"="stmctrl.dll" [2006-06-02 c:\windows\system32\stmctrl.dll]
"ATI Video Driver Control"="Messen.exe" [2008-12-27 c:\windows\system32\Messen.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"ATI Video Driver Control"="Messen.exe" [2008-12-27 c:\windows\system32\Messen.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]
"ATI Video Driver Control"="Messen.exe" [2008-12-27 c:\windows\system32\Messen.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunServices]
"ATI Video Driver Control"="Messen.exe" [2008-12-27 c:\windows\system32\Messen.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2008-12-27 11264]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-27 111184]
R3 stmatm;ATM/ADSL miniport;c:\windows\system32\DRIVERS\stmatm.sys [2008-12-29 60255]
R3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\DRIVERS\torususb.sys [2008-12-29 683791]
S2 NET Runtime Optimization Service v2.1.41329_X86;NET Runtime Optimization Service v2.1.41329_X86;"c:\windows\Fonts\wmsncs.exe" []
S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\e:\program files\EVEREST Home Edition\kerneld.wnt [2008-01-06 7168]
*Newly Created Service* - JAVAQUICKSTARTERSERVICE
*Newly Created Service* - WMIAPSRV
.
.
------- Skan uzupełniający -------
.
TCP: {812DB291-1A31-457C-B70E-A23B1C66735F} = 217.116.100.65 217.116.100.66
.
**************************************************************************
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki:
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\e:\program files\EVEREST Home Edition\kerneld.wnt"
.
Czas ukończenia: 2008-12-29 21:32:59
ComboFix-quarantined-files.txt 2008-12-29 20:32:56
ComboFix2.txt 2008-12-28 12:14:16
Przed: 4 327 780 352 bajtów wolnych
Po: 4,326,387,712 bajtów wolnych
198