
Moim problemem jest dobrze już znany tytułowy zlob.DNSchanger. Próbowałem prostych metod usuwania, ale oczywiście nadaremnie. Przeglądnąłem też kilka forów w poszukiwaniu sposobu, ale żaden z nich nie zadziałał.
Mój system to Windows Vista Home. W lokalnej sieci powinniśmy używać w Tcp/ipv4 automatycznego przydzielania DNS. Jednak kiedy pojawił się w sieci zlob.DNSchanger i przypisywał porty 85.255.112.36 i 85.255.112.41, co uniemożliwiało przeglądanie www, administratorzy podali nam zastępczy DNS 193.198.8.211. Przez kilka dni www chodziło na tym adresie, ale potem znowu padło. Innym użytkownikom działa, tylko nie mi i jeszcze paru osobom. Nie udało mi się, jak już wspomniałem, wyeliminować Zloba. Pomimo kilkukrotnego usuwania różnymi programami (także w trybie awaryjnym) zainfekowanych wpisów w rejestrze, problem pojawia się na nowo, a www dalej nie chodzi (mimo, że wpisany jest ręcznie inny adres DNS). Z góry dziękuję za pomoc.
Poniżej wklejam log RSITa:
- Kod: Zaznacz wszystko
Logfile of random's system information tool 1.05 (written by random/random)
Run by Paweł at 2009-01-28 17:23:32
Microsoft® Windows Vista™ Home Premium
System drive C: has 166 GB (85%) free of 195 GB
Total RAM: 3070 MB (64% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:23:33, on 2009-01-28
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16764)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\RtHDVCpl.exe
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\ProgramData\fsc-reg\fscreg.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
D:\paweł\Miranda IM\miranda32.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Windows\NOTEPAD.EXE
C:\Windows\helppane.exe
C:\Windows\system32\mstsc.exe
C:\Users\Paweł\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Paweł.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [recinfo642] c:\RecInfo\RecInfo.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [CafeNews] C:\Program Files\CafeNews\CN.exe /autostart
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe 20081227
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Subskrybuj w Cafe News - C:\Program Files\CafeNews\addFeed.htm
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0416E862-C9D6-43FF-8A8D-4168D8740C35}: NameServer = 193.198.8.211
O17 - HKLM\System\CS1\Services\Tcpip\..\{0416E862-C9D6-43FF-8A8D-4168D8740C35}: NameServer = 193.198.8.211
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
--
End of file - 7177 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Google Software Updater.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-09-23 1088296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-10-06 455960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-10 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-10-06 2055960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2009-01-18 657904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-10 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-10-06 2055960]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-04-10 4431872]
"recinfo642"=c:\RecInfo\RecInfo.exe [2007-10-23 2764800]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-02-26 153136]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-11-27 1261336]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-10 136600]
"CafeNews"=C:\Program Files\CafeNews\CN.exe [2008-07-22 1228800]
"TrojanScanner"=C:\Program Files\Trojan Remover\Trjscan.exe [2009-01-01 1231752]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"fsc-reg"=C:\ProgramData\fsc-reg\fscreg.exe [2007-11-16 234256]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
C:\Users\Paweł\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="G"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2009-01-28 17:19:30 ----D---- C:\rsit
2009-01-28 17:07:16 ----D---- C:\Windows\temp
2009-01-28 17:07:15 ----A---- C:\ComboFix.txt
2009-01-28 17:04:25 ----A---- C:\Windows\PSEXESVC.EXE
2009-01-28 17:03:03 ----D---- C:\Qoobox
2009-01-28 17:03:03 ----D---- C:\ComboFix
2009-01-28 13:42:52 ----A---- C:\Windows\system32\ztvunace26.dll
2009-01-28 13:42:51 ----A---- C:\Windows\system32\ztvunrar36.dll
2009-01-28 13:42:51 ----A---- C:\Windows\system32\ztvcabinet.dll
2009-01-28 13:42:51 ----A---- C:\Windows\system32\UNRAR3.dll
2009-01-28 13:42:50 ----D---- C:\Users\Paweł\AppData\Roaming\Simply Super Software
2009-01-28 13:42:50 ----D---- C:\ProgramData\Simply Super Software
2009-01-28 13:42:50 ----D---- C:\Program Files\Trojan Remover
2009-01-28 12:13:21 ----A---- C:\Windows\ntbtlog.txt
2009-01-28 12:11:15 ----D---- C:\Users\Paweł\AppData\Roaming\Malwarebytes
2009-01-28 12:11:09 ----D---- C:\ProgramData\Malwarebytes
2009-01-28 12:11:09 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-27 14:08:54 ----D---- C:\Program Files\CCleaner
2009-01-27 13:57:28 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2009-01-27 13:57:21 ----D---- C:\Users\Paweł\AppData\Roaming\SUPERAntiSpyware.com
2009-01-27 13:57:21 ----D---- C:\Program Files\SUPERAntiSpyware
2009-01-27 13:56:54 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-01-27 13:47:31 ----D---- C:\fixwareout
2009-01-21 16:40:28 ----D---- C:\Users\Paweł\AppData\Roaming\Ashampoo
2009-01-21 16:40:22 ----D---- C:\ProgramData\ashampoo
2009-01-21 16:39:59 ----D---- C:\Program Files\Ashampoo
2009-01-21 02:22:59 ----A---- C:\Windows\zip.exe
2009-01-21 02:22:59 ----A---- C:\Windows\VFIND.exe
2009-01-21 02:22:59 ----A---- C:\Windows\SWXCACLS.exe
2009-01-21 02:22:59 ----A---- C:\Windows\SWSC.exe
2009-01-21 02:22:59 ----A---- C:\Windows\SWREG.exe
2009-01-21 02:22:59 ----A---- C:\Windows\sed.exe
2009-01-21 02:22:59 ----A---- C:\Windows\NIRCMD.exe
2009-01-21 02:22:59 ----A---- C:\Windows\grep.exe
2009-01-21 02:22:59 ----A---- C:\Windows\fdsv.exe
2009-01-21 02:22:50 ----D---- C:\Windows\ERDNT
2009-01-21 02:11:51 ----D---- C:\Program Files\Trend Micro
2009-01-18 23:17:49 ----D---- C:\Users\Paweł\AppData\Roaming\VoipCheapCom
2009-01-18 23:16:01 ----D---- C:\Program Files\VoipCheapCom
2009-01-18 17:59:50 ----D---- C:\ProgramData\Google Updater
2009-01-18 17:10:46 ----D---- C:\Program Files\Macromedia
2009-01-18 00:59:29 ----D---- C:\Program Files\a-squared Free
2009-01-18 00:47:08 ----AD---- C:\ProgramData\TEMP
2009-01-18 00:06:41 ----D---- C:\ProgramData\Spybot - Search & Destroy
2009-01-18 00:06:41 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-12-30 11:45:36 ----D---- C:\Program Files\Blaze Media Pro
2008-12-30 11:45:09 ----HDC---- C:\ProgramData\{DE097E60-7F86-4350-B083-1F09B6906C92}
2008-12-30 11:32:31 ----D---- C:\Program Files\Windows Media Components
2008-12-30 11:32:31 ----A---- C:\Windows\system32\wmrmcmp.exe
2008-12-30 10:33:59 ----A---- C:\Windows\system32\AudPlayer.dll
2008-12-30 10:33:59 ----A---- C:\Windows\system32\AudioVisu.dll
2008-12-30 10:33:59 ----A---- C:\Windows\system32\AudioRecord.dll
2008-12-30 10:33:59 ----A---- C:\Windows\system32\AudioInfos.dll
2008-12-30 10:33:59 ----A---- C:\Windows\system32\AudFile.dll
2008-12-30 10:33:59 ----A---- C:\Windows\system32\AudDisplay.dll
2008-12-30 10:33:59 ----A---- C:\Windows\system32\AudDesign.dll
2008-12-30 10:33:58 ----A---- C:\Windows\system32\VB6FR.DLL
2008-12-30 10:33:58 ----A---- C:\Windows\system32\TABCTFR.DLL
2008-12-30 10:33:58 ----A---- C:\Windows\system32\MSCMCFR.DLL
2008-12-30 10:33:58 ----A---- C:\Windows\system32\Mscc2fr.dll
2008-12-30 10:33:58 ----A---- C:\Windows\system32\inetfr.DLL
2008-12-30 10:33:58 ----A---- C:\Windows\system32\CMDLGFR.DLL
======List of files/folders modified in the last 1 months======
2009-01-28 17:22:11 ----D---- C:\Windows\System32
2009-01-28 17:22:11 ----D---- C:\Windows\inf
2009-01-28 17:22:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-01-28 17:07:16 ----D---- C:\Windows
2009-01-28 17:04:29 ----A---- C:\Windows\system.ini
2009-01-28 17:04:01 ----D---- C:\Windows\Prefetch
2009-01-28 17:03:02 ----D---- C:\Windows\system32\drivers
2009-01-28 14:20:10 ----D---- C:\Windows\Tasks
2009-01-28 14:13:19 ----D---- C:\Users\Paweł\AppData\Roaming\OpenOffice.org2
2009-01-28 13:42:50 ----RD---- C:\Program Files
2009-01-28 13:42:50 ----HD---- C:\ProgramData
2009-01-28 13:10:35 ----D---- C:\Windows\system32\pl-PL
2009-01-28 12:49:37 ----D---- C:\Program Files\Mozilla Firefox
2009-01-28 08:58:21 ----D---- C:\Users\Paweł\AppData\Roaming\foobar2000
2009-01-28 08:01:57 ----SHD---- C:\System Volume Information
2009-01-27 20:26:25 ----D---- C:\Users\Paweł\AppData\Roaming\Skype
2009-01-27 18:41:20 ----D---- C:\Windows\AppPatch
2009-01-27 18:41:20 ----D---- C:\Program Files\Common Files
2009-01-27 17:28:28 ----D---- C:\Users\Paweł\AppData\Roaming\skypePM
2009-01-27 16:01:10 ----D---- C:\Windows\system32\Tasks
2009-01-27 14:33:01 ----SD---- C:\ProgramData\Microsoft
2009-01-27 14:11:03 ----D---- C:\Windows\Minidump
2009-01-27 14:11:03 ----D---- C:\Windows\Debug
2009-01-27 13:57:26 ----SHD---- C:\Windows\Installer
2009-01-26 20:54:50 ----D---- C:\Windows\system32\catroot2
2009-01-21 18:54:32 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-21 18:53:51 ----D---- C:\ProgramData\Google
2009-01-21 18:53:51 ----D---- C:\Program Files\Google
2009-01-21 18:40:25 ----D---- C:\Program Files\foobar2000
2009-01-21 16:31:14 ----D---- C:\Program Files\ACD Systems
2009-01-21 16:31:13 ----D---- C:\Program Files\Common Files\ACD Systems
2009-01-18 17:12:49 ----D---- C:\Users\Paweł\AppData\Roaming\Macromedia
2009-01-17 19:22:43 ----HD---- C:\$AVG8.VAULT$
2009-01-15 03:02:28 ----D---- C:\Windows\winsxs
2009-01-14 09:43:53 ----D---- C:\Windows\system32\catroot
2009-01-12 23:16:50 ----D---- C:\Program Files\SubEdit-Player
2009-01-10 02:35:28 ----A---- C:\Windows\system32\mrt.exe
2009-01-01 19:21:55 ----D---- C:\Windows\ModemLogs
2009-01-01 19:21:53 ----SD---- C:\Users\Paweł\AppData\Roaming\Microsoft
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2008-10-06 97928]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2008-10-06 26824]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [2009-01-15 55024]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2007-10-11 3155456]
R3 AvgWfpX;AVG8 Firewall Driver x86; C:\Windows\System32\Drivers\avgwfpx.sys [2008-10-06 69128]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2007-11-04 14208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-04-10 1764960]
R3 itecir;ITECIR Infrared Receiver; C:\Windows\system32\DRIVERS\itecir.sys [2007-04-04 46592]
R3 NETw4v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-02-25 2216448]
R3 pfc;Padus ASPI Shell; C:\Windows\system32\drivers\pfc.sys [2008-09-28 10368]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-02-16 70144]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-22 982272]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2007-11-04 11264]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2007-11-04 82688]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
S3 usbvideo;Urządzenie wideo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2007-11-04 132864]
S4 JRAID;JRAID; C:\Windows\system32\drivers\jraid.sys [2007-06-13 48256]
S4 nvrd32;NVIDIA nForce RAID Driver; C:\Windows\system32\drivers\nvrd32.sys [2007-07-02 131616]
S4 nvstor32;nvstor32; C:\Windows\system32\drivers\nvstor32.sys [2007-07-02 110112]
S4 viamraid;viamraid; C:\Windows\system32\drivers\viamraid.sys [2006-11-08 102912]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2008-12-17 419448]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2007-10-11 610304]
R2 avg8emc;AVG8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-10-06 875288]
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-06 231704]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2006-07-20 262247]
R2 TestHandler;Fujitsu Siemens Computers Diagnostic Testhandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [2006-12-08 204800]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-18 182768]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-02-26 267824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Usługa Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF-----------------