
Wykonałem speedtest.Wyniki były takie jakie powinny być dla neo 1 MB

podaje log HijackThis:
- Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 11:09:43, on 2009-03-26
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Nowe Gadu-Gadu\gg.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\hp\AppData\Local\Temp\Rar$EX00.275\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKCU\..\Run: [Gadwin PrintScreen] "C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" /nosplash
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Wyślij obraz do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Wyślij stronę do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Statystyki ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{34938EC6-9DDF-442F-83A8-4F8FC113F19E}: NameServer = 192.168.1.1,194.204.159.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{34938EC6-9DDF-442F-83A8-4F8FC113F19E}: NameServer = 192.168.1.1,194.204.159.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{34938EC6-9DDF-442F-83A8-4F8FC113F19E}: NameServer = 192.168.1.1,194.204.159.1
O17 - HKLM\System\CS3\Services\Tcpip\..\{34938EC6-9DDF-442F-83A8-4F8FC113F19E}: NameServer = 192.168.1.1,194.204.159.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
Combofix:
- Kod: Zaznacz wszystko
ComboFix 09-03-25.03 - hp 2009-03-26 11:55:47.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1045.18.2558.1281 [GMT 1:00]
Uruchomiony z: c:\users\hp\Downloads\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((( Pliki utworzone od 2009-02-26 do 2009-03-26 )))))))))))))))))))))))))))))))
.
2009-03-26 11:51 . 2009-03-26 11:51 318,976 --a------ c:\windows\System32\CF16913.exe
2009-03-25 23:49 . 2009-03-25 23:50 <DIR> d-------- c:\program files\Nowe Gadu-Gadu
2009-03-25 15:59 . 1999-04-23 22:22 151,552 --a------ c:\windows\System32\MSOSS.DLL
2009-03-15 17:24 . 2009-03-15 17:24 <DIR> d-------- c:\users\All Users\TVU Networks
2009-03-15 17:24 . 2009-03-15 17:24 <DIR> d-------- c:\programdata\TVU Networks
2009-03-15 12:44 . 2009-03-15 12:44 <DIR> d-------- c:\program files\Microsoft Silverlight
2009-03-11 13:42 . 2008-12-16 04:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 13:42 . 2009-02-09 04:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 13:42 . 2008-11-27 05:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-11 13:42 . 2008-12-16 06:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 13:42 . 2008-12-16 06:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 13:42 . 2008-12-16 06:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-09 14:40 . 2009-03-09 14:41 <DIR> d-------- c:\program files\Ganymede
2009-03-09 14:29 . 2009-03-09 15:32 <DIR> d-------- c:\users\hp\AppData\Roaming\GanymedeNet
2009-03-07 13:11 . 2009-03-07 13:11 <DIR> d-------- c:\users\hp\.gstreamer-0.10
2009-03-06 00:06 . 2009-03-06 00:07 <DIR> d-------- c:\program files\ivo
2009-02-27 22:37 . 2009-03-01 13:27 <DIR> d-------- C:\Downloads
2009-02-27 22:32 . 2009-02-27 22:32 <DIR> d-------- c:\users\hp\AppData\Roaming\FlashGet
2009-02-27 22:32 . 2009-02-27 22:32 <DIR> d-------- c:\program files\FlashGet
2009-02-27 20:10 . 2009-02-27 20:10 <DIR> d-------- c:\users\hp\AppData\Roaming\AdobeUM
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-26 10:55 655,392 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-26 10:55 524,288 --sha-w c:\users\Gość\ntuser.dat
2009-03-26 10:55 524,288 --sha-w c:\users\Gość\ntuser.dat
2009-03-26 10:54 7,035,424 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-26 10:54 58,140 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-26 10:53 4,368 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-26 08:47 --------- d-----w c:\programdata\Kaspersky Lab
2009-03-25 22:28 --------- d---a-w c:\programdata\TEMP
2009-03-25 22:01 --------- d-----w c:\users\hp\AppData\Roaming\Skype
2009-03-25 18:53 27,554 ----a-w c:\users\All Users\nvModes.dat
2009-03-25 18:53 27,554 ----a-w c:\programdata\nvModes.dat
2009-03-25 15:02 --------- d-----w c:\users\hp\AppData\Roaming\skypePM
2009-03-25 14:59 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-14 09:53 --------- d-----w c:\users\hp\AppData\Roaming\Teleca
2009-03-12 02:07 --------- d-----w c:\program files\Windows Mail
2009-02-20 13:02 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-20 13:02 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-20 13:02 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-20 12:31 --------- d-----w c:\program files\Kaspersky Lab
2009-02-19 14:29 --------- d-----w c:\programdata\Kaspersky Lab Setup Files
2009-02-19 13:41 --------- d-----w c:\program files\Mozilla Thunderbird
2009-02-16 20:53 --------- d-----w c:\program files\Your Uninstaller 2008
2009-02-16 20:50 --------- d-----w c:\users\hp\AppData\Roaming\URSoft
2009-02-10 22:59 --------- d-----w c:\program files\Opera
2009-02-04 10:51 --------- d-----w c:\program files\Brother
2009-02-04 10:48 --------- d-----w c:\users\hp\AppData\Roaming\InstallShield
2009-01-30 16:24 14,600 ----a-w c:\windows\Help\OEM\scripts\HC_InstallHPHC.exe
2009-01-30 16:14 --------- d-----w c:\users\hp\AppData\Roaming\Winamp
2009-01-26 13:49 --------- d-----w c:\users\hp\AppData\Roaming\Graphisoft
2009-01-26 13:15 --------- d-----r c:\users\hp\AppData\Roaming\Brother
2009-01-25 12:35 56 ---ha-w c:\users\All Users\ezsidmv.dat
2009-01-25 12:35 56 ---ha-w c:\programdata\ezsidmv.dat
2009-01-25 10:44 348,160 ----a-w c:\windows\System32\msvcr71.dll
2009-01-18 19:04 174 --sha-w c:\program files\desktop.ini
2009-01-18 18:14 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2009-01-18 18:13 82,432 ----a-w c:\windows\System32\axaltocm.dll
2009-01-18 17:23 47,560 ----a-w c:\windows\System32\SPReview.exe
2009-01-18 17:23 152,576 ----a-w c:\windows\System32\SPWizUI.dll
2009-01-18 11:24 269,312 ----a-w c:\windows\System32\es.dll
2009-01-18 10:34 61,440 ----a-w c:\windows\System32\winipsec.dll
2009-01-18 10:34 361,984 ----a-w c:\windows\System32\IPSECSVC.DLL
2009-01-18 10:34 28,672 ----a-w c:\windows\System32\FwRemoteSvr.dll
2009-01-18 10:34 272,896 ----a-w c:\windows\System32\polstore.dll
2009-01-18 10:33 94,720 ----a-w c:\windows\System32\PortableDeviceClassExtension.dll
2009-01-18 10:33 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2009-01-18 10:33 160,768 ----a-w c:\windows\System32\PortableDeviceTypes.dll
2009-01-18 10:22 296,960 ----a-w c:\windows\System32\gdi32.dll
2009-01-18 10:16 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2009-01-18 10:16 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2009-01-18 10:16 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2009-01-18 10:16 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2009-01-18 10:16 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2009-01-18 10:16 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2009-01-18 10:16 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2009-01-18 10:16 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2009-01-18 10:16 1,695,744 ----a-w c:\windows\System32\gameux.dll
2009-01-18 10:14 303,616 ----a-w c:\windows\System32\wmpeffects.dll
2009-01-18 10:12 2,048 ----a-w c:\windows\System32\msxml3r.dll
2009-01-18 10:12 1,191,936 ----a-w c:\windows\System32\msxml3.dll
2009-01-18 10:07 2,048 ----a-w c:\windows\System32\tzres.dll
2009-01-18 10:02 2,927,104 ----a-w c:\windows\explorer.exe
2009-01-18 09:56 181,760 ----a-w c:\windows\System32\fsquirt.exe
2009-01-18 09:55 988,216 ----a-w c:\windows\System32\winload.exe
2009-01-18 09:55 927,288 ----a-w c:\windows\System32\winresume.exe
2009-01-18 09:55 615,992 ----a-w c:\windows\System32\ci.dll
2009-01-18 09:55 6,656 ----a-w c:\windows\System32\kbd106n.dll
2009-01-18 09:55 46,592 ----a-w c:\windows\System32\setbcdlocale.dll
2009-01-18 09:55 40,960 ----a-w c:\windows\System32\srclient.dll
2009-01-18 09:55 378,368 ----a-w c:\windows\System32\srcore.dll
2009-01-18 09:55 318,464 ----a-w c:\windows\System32\rstrui.exe
2009-01-18 09:55 19,000 ----a-w c:\windows\System32\kd1394.dll
2009-01-18 09:55 14,848 ----a-w c:\windows\System32\srdelayed.exe
2009-01-18 09:52 712,704 ----a-w c:\windows\System32\WindowsCodecs.dll
2009-01-18 09:52 443,392 ----a-w c:\windows\System32\win32spl.dll
2009-01-18 09:52 425,472 ----a-w c:\windows\System32\PhotoMetadataHandler.dll
2009-01-18 09:52 37,888 ----a-w c:\windows\System32\printcom.dll
2009-01-18 09:52 347,136 ----a-w c:\windows\System32\WindowsCodecsExt.dll
2009-01-18 09:51 14,848 ----a-w c:\windows\System32\wshrm.dll
2009-01-18 09:49 996,352 ----a-w c:\windows\System32\WMNetMgr.dll
2009-01-18 09:49 98,816 ----a-w c:\windows\System32\mfps.dll
2009-01-18 09:49 94,720 ----a-w c:\windows\System32\logagent.exe
2009-01-18 09:49 53,248 ----a-w c:\windows\System32\rrinstaller.exe
2009-01-18 09:49 24,576 ----a-w c:\windows\System32\mfpmp.exe
2009-01-18 09:49 2,868,736 ----a-w c:\windows\System32\mf.dll
2009-01-18 09:49 2,048 ----a-w c:\windows\System32\mferror.dll
2009-01-18 09:46 84,480 ----a-w c:\windows\System32\INETRES.dll
2009-01-18 09:46 738,304 ----a-w c:\windows\System32\inetcomm.dll
2009-01-18 09:45 1,645,568 ----a-w c:\windows\System32\connect.dll
2009-01-18 09:44 1,314,816 ----a-w c:\windows\System32\quartz.dll
2009-01-17 07:14 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2009-01-17 07:14 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2009-01-17 07:14 2,048 ----a-w c:\windows\System32\msxml6r.dll
2009-01-17 07:14 1,334,272 ----a-w c:\windows\System32\msxml6.dll
2009-01-16 17:47 27,050 ----a-w c:\users\hp\AppData\Roaming\nvModes.dat
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2009-01-15 00:01 83,456 ----a-w c:\windows\System32\wudriver.dll
2009-01-15 00:01 561,688 ----a-w c:\windows\System32\wuapi.dll
2009-01-15 00:01 51,224 ----a-w c:\windows\System32\wuauclt.exe
2009-01-15 00:01 43,544 ----a-w c:\windows\System32\wups2.dll
2009-01-15 00:01 34,328 ----a-w c:\windows\System32\wups.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
"Nowe Gadu-Gadu"="c:\program files\Nowe Gadu-Gadu\gg.exe" [2008-06-27 8798816]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2008-12-09 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-04-23 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 50696]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 528384]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-20 201992]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-07 44128]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-12-20 719664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^UniSpiker-2.6.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\UniSpiker-2.6.lnk
backup=c:\windows\pss\UniSpiker-2.6.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-06 23:46 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2009-01-18 14:28 2356088 c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2008-12-13 05:23 882176 c:\program files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
--------- 2007-03-12 14:51 663552 c:\program files\Brother\Brmfcmon\BrMfcWnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
--------- 2007-01-26 15:58 65536 c:\program files\Brother\ControlCenter3\BrCtrCen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadwin PrintScreen]
--a------ 2008-12-09 12:08 495616 c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HEXelon MAX]
--a------ 2007-06-28 20:44 2816512 c:\program files\HEXelon MAX 6\hexelon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
--a------ 2007-01-29 21:10 46632 c:\program files\ScanSoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
--a------ 2008-06-09 10:16 2363392 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-12-04 02:42 13556256 c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-12-04 02:42 92704 c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2008-12-04 02:42 711200 c:\windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--a------ 2007-01-29 21:12 30248 c:\program files\ScanSoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPort11reminder]
--a------ 2007-02-01 13:46 255528 c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2009-01-24 15:29 155648 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2008-01-18 23:33 1233920 c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
--a------ 2006-10-09 21:43 729088 c:\program files\Motorola\SMSERIAL\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
--a------ 2006-10-25 09:03 210472 c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-01-02 20:21 77824 c:\program files\Java\jre1.6.0\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
--a------ 2008-01-29 17:38 583048 c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2009-01-25 11:44 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-08-04 00:02 36352 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-18 23:38 1008184 c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-18 23:33 202240 c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
--a------ 2008-01-18 23:36 2153472 c:\windows\System32\oobefldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{38374DB1-0739-4DE0-9EF3-F53B33488064}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{9ABAC2EA-953E-4942-8EDE-F6BA0630E6DB}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{95ED3C44-3C80-4D3D-B6DD-5B8C1ADF5364}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{8AE77A11-7C42-480A-9CDC-736BD7F27D6B}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{E2F06E55-8668-4461-BE09-FE5B2A35C977}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{43ABBCA2-9A6D-4C13-8D6E-BEBCA6945DC8}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{C7CB7DB4-E752-4937-BE1C-F3156681479D}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D14DB3F9-E1D4-4DF2-AD64-0855F76D3DE9}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{A7B2DBC9-3C28-4DC8-A0AE-186EC898E777}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{074EDE3A-0A71-4B7B-BB6C-42D3D9FA9893}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{06E4AE80-A839-4DFA-AAFB-CF6139EDA74E}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{91B4FACA-E4A0-42BE-8990-47AF3705F1CB}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{6E39D32F-55DC-4C4B-8C12-AD6F12A2178C}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{387124FA-B4DC-4C63-A4C1-09A9DE1A20BA}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{DBEE9B97-AD12-43DB-80A0-D96BE3688915}c:\\program files\\nowe gadu-gadu\\gg.exe"= UDP:c:\program files\nowe gadu-gadu\gg.exe:Nowe Gadu-Gadu beta
"UDP Query User{49CD4C65-E166-427A-9FC5-C20171328FD8}c:\\program files\\nowe gadu-gadu\\gg.exe"= TCP:c:\program files\nowe gadu-gadu\gg.exe:Nowe Gadu-Gadu beta
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [2008-01-29 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [2008-03-26 20496]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [2008-11-17 3668480]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e8baac4-e978-11dd-b72b-001e37657e5c}]
\shell\AutoRun\command - G:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e8baac5-e978-11dd-b72b-001e37657e5c}]
\shell\AutoRun\command - H:\Launcher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e8baac6-e978-11dd-b72b-001e37657e5c}]
\shell\AutoRun\command - I:\AUTORUN.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a5cf464-f3a8-11dd-ad19-001b2477b1fd}]
\shell\AutoRun\command - K:\m0vnonh.bat
\shell\open\Command - K:\m0vnonh.bat
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Zawartość folderu 'Zaplanowane zadania'
2009-03-25 c:\windows\Tasks\NeroLiveEpgUpdate-hp-PC_hp.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe [2008-10-27 09:59]
2009-03-25 c:\windows\Tasks\User_Feed_Synchronization-{36B00FC4-22B2-4097-A31C-10BEB01A3574}.job
- c:\windows\system32\msfeedssync.exe [2008-01-18 23:33]
.
.
------- Skan uzupełniający -------
.
uInternet Settings,ProxyOverride = *.local
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Wyślij obraz do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Wyślij stronę do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: {34938EC6-9DDF-442F-83A8-4F8FC113F19E} = 192.168.1.1,194.204.159.1
FF - ProfilePath - c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\jc7p5mw2.default\
FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npganymedenet.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMAKAOV2.dll
FF - plugin: c:\program files\Opera\program\plugins\npganymedenet.dll
FF - plugin: c:\users\hp\AppData\Roaming\Mozilla\Firefox\Profiles\jc7p5mw2.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-26 12:02:49
Windows 6.0.6001 Service Pack 1 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'Explorer.exe'(7148)
c:\windows\system32\btncopy.dll
.
Czas ukończenia: 2009-03-26 12:07:06
ComboFix-quarantined-files.txt 2009-03-26 11:06:52
Przed: 34,145,972,224 bajtów wolnych
Po: 35,894,087,680 bajtów wolnych
Current=1 Default=1 Failed=0 LastKnownGood=3 Sets=1,2,3,5
325 --- E O F --- 2009-03-24 06:12:06
Pomocy
