
Otoz mam problem z netem nieraz bardzo powoli chodzi a transfer 10,ale to jak jest to na jakis czas.Skanowalem kompa kasperskim i bylo pelno wirusow i chyba usunelo.Chcialbym sprawdzic czy juz wszystko ok.Oto logi
HijackThis
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:57, on 2008-12-06
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
E:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINDOWS\explorer.exe
E:\Programy Zainstalowane\Gamaa Adjuster\GammaAdjuster.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Winamp\winamp.exe
C:\Documents and Settings\cNx\Pulpit\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "E:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O9 - Extra button: Statystyki ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
--
End of file - 4651 bytes
ComboFix
- Kod: Zaznacz wszystko
ComboFix 08-12-06.03 - cNx 2008-12-06 21:40:33.4 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.241 [GMT 1:00]
Uruchomiony z: E:\INSTALKI\ComboFix.exe
* Utworzono nowy punkt przywracania
.
/wow section - STAGE 27
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\WINDOWS\system32\febefd_z.dll
C:\WINDOWS\system32\gasretyw0.dll
C:\WINDOWS\system32\kamsoft.exe
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-06 do 2008-12-06 )))))))))))))))))))))))))))))))
.
2008-12-06 19:33 . 2008-12-06 19:33 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-12-06 19:33 . 2008-12-06 19:33 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-12-06 19:33 . 2008-12-06 21:42 1,064,480 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-12-06 19:33 . 2008-12-06 21:42 122,912 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-12-06 19:33 . 2008-12-06 19:33 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-12-06 19:33 . 2008-12-06 19:33 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-12-06 19:33 . 2008-12-06 21:42 10,444 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-12-06 19:33 . 2008-12-06 21:42 2,548 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-12-06 19:32 . 2008-12-06 19:32 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-12-05 20:19 . 2008-12-05 20:19 <DIR> d-------- C:\Program Files\WMV9_VCM
2008-12-05 20:18 . 2008-12-05 20:18 <DIR> d-------- C:\Program Files\Avalon
2008-12-05 19:44 . 2008-12-05 19:45 <DIR> d-------- C:\WINDOWS\Logs
2008-12-05 19:44 . 2008-12-05 19:44 <DIR> d-------- C:\Program Files\directx9
2008-12-05 14:04 . 2008-12-05 14:04 <DIR> d-------- C:\Documents and Settings\cNx\Dane aplikacji\Media Player Classic
2008-12-05 13:51 . 2008-12-06 20:01 104,421 -r-hs---- C:\2u.com
2008-12-04 15:34 . 2008-12-04 15:35 <DIR> d-------- C:\Program Files\Odkurzacz
2008-12-03 17:13 . 2008-12-03 17:13 <DIR> d-------- C:\Documents and Settings\Nikola\Dane aplikacji\OpenOffice.ux.pl2
2008-12-02 21:45 . 2008-12-02 21:45 <DIR> d-------- C:\Documents and Settings\cNx\Dane aplikacji\vlc
2008-12-02 21:44 . 2008-12-02 21:44 <DIR> d-------- C:\Program Files\VideoLAN
2008-12-02 21:27 . 2008-12-02 21:27 23 --a------ C:\WINDOWS\system32\abcdf9_z.ocx
2008-12-02 21:08 . 2004-08-04 00:44 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-12-02 20:57 . 2008-12-02 20:57 <DIR> d-------- C:\Program Files\NAPI-PROJEKT
2008-12-02 20:53 . 2008-12-02 20:53 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-12-02 20:50 . 2008-12-02 20:50 <DIR> d-------- C:\Program Files\Skype
2008-12-02 20:50 . 2008-12-02 20:50 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-12-02 20:50 . 2008-12-02 20:50 <DIR> d-------- C:\Documents and Settings\cNx\Dane aplikacji\Skype
2008-12-02 20:50 . 2008-12-02 20:50 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-11-27 13:31 . 2008-11-27 13:31 <DIR> d-------- C:\Documents and Settings\Nikola\Dane aplikacji\Winamp
2008-11-25 19:29 . 2008-11-25 19:29 <DIR> d-------- C:\Documents and Settings\cNx\Dane aplikacji\OpenOffice.ux.pl2
2008-11-25 19:26 . 2008-11-25 19:26 <DIR> d-------- C:\Program Files\OpenOffice.ux.pl 2.1.0
2008-11-23 10:02 . 2008-11-23 10:02 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-11-23 10:02 . 2008-11-23 10:02 <DIR> d-------- C:\Documents and Settings\cNx\SystemRequirementsLab
2008-11-22 15:58 . 2008-11-27 19:23 502 --a------ C:\hpfr3420.xml
2008-11-22 15:56 . 2008-11-22 15:56 <DIR> d-------- C:\Program Files\hp deskjet 3420 series
2008-11-22 15:56 . 2002-11-03 21:02 184,386 --a------ C:\WINDOWS\system32\hpzsnt07.dll
2008-11-22 15:56 . 2008-11-22 15:56 704 --a------ C:\WINDOWS\hpinfo.lnk
2008-11-22 15:55 . 2008-11-22 15:55 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-11-18 17:48 . 2008-11-18 17:48 <DIR> d-------- C:\Documents and Settings\cNx\Dane aplikacji\InstallShield
2008-11-12 17:45 . 2008-12-04 16:00 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-11-12 17:34 . 2008-11-12 17:34 <DIR> d-------- C:\Documents and Settings\Nikola\Dane aplikacji\Gadu-Gadu
2008-11-12 17:25 . 2008-11-12 17:25 <DIR> d-------- C:\Documents and Settings\Nikola\Gadu-Gadu
2008-11-12 17:21 . 2008-11-12 17:21 <DIR> d-------- C:\Documents and Settings\Nikola\Dane aplikacji\Nero
2008-11-12 15:08 . 2008-09-04 17:46 1,106,944 --------- C:\WINDOWS\system32\dllcache\msxml3.dll
2008-11-12 07:52 . 2008-10-24 12:10 453,632 --------- C:\WINDOWS\system32\dllcache\mrxsmb.sys
2008-11-11 20:42 . 2008-11-11 20:42 <DIR> d-------- C:\Documents and Settings\cNx\Dane aplikacji\Nero
2008-11-11 20:37 . 2008-11-11 20:37 <DIR> d-------- C:\Program Files\Nero
2008-11-11 20:37 . 2008-11-11 20:37 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-11-11 20:37 . 2008-11-11 20:37 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Nero
2008-11-11 20:12 . 2008-11-11 20:12 422 --a------ C:\log.udt
2008-11-11 08:15 . 2003-02-28 18:26 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2008-11-11 08:15 . 2003-02-28 18:26 46,352 --a------ C:\WINDOWS\setdebug.exe
2008-11-11 08:15 . 2003-02-28 16:54 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2008-11-11 08:15 . 2003-02-28 16:35 6,550 --a------ C:\WINDOWS\jautoexp.dat
2008-11-11 08:15 . 2003-02-28 16:38 113 --a------ C:\WINDOWS\system32\zonedon.reg
2008-11-11 08:15 . 2003-02-28 16:38 113 --a------ C:\WINDOWS\system32\zonedoff.reg
2008-11-09 18:58 . 2001-08-17 21:52 18,688 --a------ C:\WINDOWS\system32\dllcache\cdaudio.sys
2008-11-07 19:19 . 2008-11-07 19:19 <DIR> d-------- C:\Program Files\Realtek AC97
2008-11-07 19:19 . 2006-12-08 15:20 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe
2008-11-07 19:19 . 2006-10-18 02:53 147,456 --a------ C:\WINDOWS\system32\RtlCPAPI.dll
2008-11-07 19:19 . 2006-08-01 15:02 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-11-07 15:47 . 2008-11-07 15:47 <DIR> d-------- C:\WINDOWS\ERUNT
2008-11-07 15:47 . 2008-11-07 15:47 <DIR> d-------- C:\ERDNT
2008-11-07 15:47 . 2008-11-07 15:47 <DIR> d-------- C:\!FixIEDef
2008-11-07 15:45 . 2008-11-07 15:45 <DIR> d-------- C:\WINDOWS\Sun
2008-11-07 15:15 . 2008-11-07 15:15 <DIR> d--hs---- C:\Recycled
2008-11-06 08:09 . 2008-09-15 16:40 1,846,272 --------- C:\WINDOWS\system32\dllcache\win32k.sys
2008-11-06 08:09 . 2008-11-06 08:09 0 --a------ C:\WINDOWS\nsreg.dat
2008-11-06 07:57 . 2008-08-28 11:04 333,056 --------- C:\WINDOWS\system32\dllcache\srv.sys
2008-11-06 07:55 . 2008-11-06 07:55 <DIR> d-------- C:\Program Files\Sun
2008-11-06 07:53 . 2008-11-10 05:43 410,984 --a------ C:\WINDOWS\system32\deploytk.dll
2008-11-06 07:53 . 2008-11-10 03:39 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-11-06 07:52 . 2008-11-06 07:52 <DIR> d-------- C:\Program Files\Java
2008-11-06 07:51 . 2008-06-14 19:01 273,024 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-11-06 07:48 . 2008-08-14 10:51 138,368 --------- C:\WINDOWS\system32\dllcache\afd.sys
2008-11-06 07:28 . 2008-04-11 19:51 683,520 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-11-06 07:28 . 2008-05-01 15:33 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-11-06 07:21 . 2008-10-15 18:00 332,800 --------- C:\WINDOWS\system32\dllcache\netapi32.dll
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-05 16:34 --------- d-----w C:\Program Files\AvRack
2008-11-05 16:31 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\nView_Profiles
2008-11-05 16:24 --------- d-----w C:\Documents and Settings\cNx\Dane aplikacji\Gadu-Gadu
2008-11-05 15:42 --------- d-----w C:\Program Files\Winamp
2008-11-05 15:42 --------- d-----w C:\Documents and Settings\cNx\Dane aplikacji\Winamp
2008-11-05 15:35 --------- d-----w C:\Program Files\Opera
2008-11-05 15:33 21,275 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-11-05 15:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-11-05 15:32 --------- d-----w C:\Program Files\RALINK
2008-11-05 15:32 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-11-05 14:56 558,142 ----a-w C:\WINDOWS\java\Packages\1NZHN93D.ZIP
2008-11-05 14:56 155,995 ----a-w C:\WINDOWS\java\Packages\UUJ17N73.ZIP
2008-11-05 14:56 --------- d-----w C:\Program Files\microsoft frontpage
2008-11-05 14:53 --------- d-----w C:\Program Files\Usługi online
2008-10-27 09:04 70,992 ----a-w C:\WINDOWS\system32\XAPOFX1_2.dll
2008-10-27 09:04 514,384 ----a-w C:\WINDOWS\system32\XAudio2_3.dll
2008-10-27 09:04 235,856 ----a-w C:\WINDOWS\system32\xactengine3_3.dll
2008-10-27 09:04 23,376 ----a-w C:\WINDOWS\system32\X3DAudio1_5.dll
2008-10-24 11:10 453,632 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-10-16 13:13 202,776 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-10-16 13:09 92,696 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w C:\WINDOWS\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w C:\WINDOWS\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w C:\WINDOWS\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-10-10 03:52 452,440 ----a-w C:\WINDOWS\system32\d3dx10_40.dll
2008-10-10 03:52 4,379,984 ----a-w C:\WINDOWS\system32\D3DX9_40.dll
2008-10-10 03:52 2,036,576 ----a-w C:\WINDOWS\system32\D3DCompiler_40.dll
2008-09-30 15:43 1,286,152 ----a-w C:\WINDOWS\system32\msxml4.dll
2008-09-15 15:40 1,846,272 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 00:44 1667584]
"Odkurzacz-MCD"="C:\Program Files\Odkurzacz\odk_mcd.exe" [2008-08-16 16:01 264704]
"Gadu-Gadu"="E:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 11:04 2127296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-05-14 06:41 3784704]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-11-03 21:02 188416]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-05-14 06:41 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-11-10 05:43 136600]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 20:20 206088]
"nwiz"="nwiz.exe" [2004-05-14 06:41 831488 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:44 15360]
C:\Documents and Settings\Nikola\Menu Start\Programy\Autostart\
OpenOffice.ux.pl 2.1.0.lnk - C:\Program Files\OpenOffice.ux.pl 2.1.0\program\quickstart.exe [2006-12-30 04:32:40 17408]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Ralink Wireless Utility.lnk - C:\Program Files\RALINK\Common\RaUI.exe [2008-11-05 16:33:35 614400]
[HKLM\~\startupfolder\C:^Documents and Settings^cNx^Menu Start^Programy^Autostart^OpenOffice.ux.pl 2.1.0.lnk]
path=C:\Documents and Settings\cNx\Menu Start\Programy\Autostart\OpenOffice.ux.pl 2.1.0.lnk
backup=C:\WINDOWS\pss\OpenOffice.ux.pl 2.1.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2007-05-04 01:32 961024 E:\Program Files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
--a------ 2008-07-29 20:20 206088 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2008-06-24 16:06 1840424 C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2008-06-08 09:31 2221352 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2008-06-19 09:53 570664 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-11-18 16:31 21633320 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-11-08 12:52 1410296 D:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Polish\\setup.exe"=
"D:\\Program Files\\Valve\\hl.exe"=
"C:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"E:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 18:29:38 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 18:06:48 24592]
S3 AVPsys;AVPsys;\??\C:\WINDOWS\system32\drivers\cdaudio.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{077770a8-ae76-11dd-8029-000e2e4965d4}]
\Shell\AutoRun\command - G:\sq.com
\Shell\explore\Command - G:\sq.com
\Shell\open\Command - G:\sq.com
.
- - - - USUNIĘTO PUSTE WPISY - - - -
MSConfigStartUp-Gadu-Gadu - E:\Programy Zainstalowane\Gadu-Gadu\gg.exe
.
------- Skan uzupełniający -------
.
O16 -: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
FireFox -: Profile - C:\Documents and Settings\cNx\Dane aplikacji\Mozilla\Firefox\Profiles\sha3vqod.default\
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-06 21:44:10
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
skanowanie ukrytych procesów ...
edit by Magik
http://forum.programosy.pl/przeczytaj-zanim-wstawisz-logi-na-forum-vt93842.html
po cos ktos to pisal




Chyba już dobrze ? prosze o sprawdzenie