
HijackThis
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:50:54, on 2008-11-04
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\program files\powerstrip\pstrip.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\user\Pulpit\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Przyspieszenie uruchomienia programu AutoCAD.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll/206 (file missing)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Usługa iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
--
End of file - 5600 bytes
oraz ComboFix
- Kod: Zaznacz wszystko
ComboFix 08-11-03.06 - user 2008-11-04 19:47:36.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1590 [GMT 1:00]
Uruchomiony z: c:\documents and settings\user\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
* Resident AV is active
.
((((((((((((((((((((((((( Pliki utworzone od 2008-10-04 do 2008-11-04 )))))))))))))))))))))))))))))))
.
2008-11-03 17:03 . 2008-11-03 17:03 <DIR> d-------- c:\program files\Microsoft SQL Server 2005 Mobile Edition
2008-11-03 17:03 . 2008-11-03 17:06 <DIR> d-------- c:\program files\Microsoft SQL Server
2008-11-03 17:03 . 2008-11-03 17:03 <DIR> d-------- c:\program files\Microsoft Device Emulator
2008-11-03 17:01 . 2008-11-03 17:01 175 --a------ c:\windows\ODBC.INI
2008-11-03 16:55 . 2008-11-03 16:55 <DIR> d-------- c:\windows\Symbols
2008-11-03 16:55 . 2008-11-03 16:59 <DIR> d-------- c:\program files\HTML Help Workshop
2008-11-03 16:55 . 2008-11-03 16:59 <DIR> d-------- c:\program files\Common Files\Merge Modules
2008-11-03 16:55 . 2008-11-03 16:56 <DIR> d-------- c:\program files\Common Files\Business Objects
2008-11-03 16:55 . 2008-11-03 16:55 <DIR> d-------- c:\program files\CE Remote Tools
2008-11-03 16:55 . 2008-11-03 16:55 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\PreEmptive Solutions
2008-10-31 00:58 . 2008-10-31 00:58 <DIR> d-------- c:\program files\Photodex Presenter
2008-10-31 00:58 . 2008-10-31 00:58 <DIR> d-------- c:\program files\Photodex
2008-10-31 00:58 . 2008-10-31 00:58 <DIR> d-------- c:\documents and settings\user\Dane aplikacji\Photodex
2008-10-31 00:58 . 2008-10-31 00:58 <DIR> d-------- c:\documents and settings\user\Dane aplikacji\Netscape
2008-10-29 10:48 . 2008-10-29 10:48 92 --a------ c:\windows\wininit.ini
2008-10-25 08:50 . 2008-07-12 07:18 3,851,784 --a------ c:\windows\system32\D3DX9_39.dll
2008-10-25 08:50 . 2008-07-12 07:18 1,493,528 --a------ c:\windows\system32\D3DCompiler_39.dll
2008-10-25 08:50 . 2008-07-31 09:40 509,448 --a------ c:\windows\system32\XAudio2_2.dll
2008-10-25 08:50 . 2008-05-30 13:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-10-25 08:50 . 2008-07-12 07:18 467,984 --a------ c:\windows\system32\d3dx10_39.dll
2008-10-25 08:50 . 2008-07-31 09:41 238,088 --a------ c:\windows\system32\xactengine3_2.dll
2008-10-25 08:50 . 2008-07-31 09:41 68,616 --a------ c:\windows\system32\XAPOFX1_1.dll
2008-10-25 08:50 . 2008-05-30 13:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-10-25 08:44 . 2008-10-25 08:44 <DIR> d-------- c:\windows\Logs
2008-10-23 23:34 . 2008-10-23 23:34 <DIR> d-------- c:\windows\system32\LogFiles
2008-10-21 01:20 . 2008-10-21 01:20 <DIR> d-------- c:\windows\system32\NtmsData
2008-10-19 21:14 . 2008-10-19 21:14 271,360 --a------ c:\windows\system32\drivers\atksgt.sys
2008-10-19 21:14 . 2008-10-19 21:14 18,048 --a------ c:\windows\system32\drivers\lirsgt.sys
2008-10-17 19:09 . 2008-11-04 15:29 103,514,832 --a------ C:\BackupRegistry(20081017).reg
2008-10-17 19:00 . 2008-10-17 19:00 <DIR> d-------- c:\program files\Yamicsoft
2008-10-17 19:00 . 2008-10-17 19:00 162,816 --a------ c:\windows\system32\fmod.dll
2008-10-09 22:12 . 2008-10-12 18:58 <DIR> d-------- c:\program files\PowerStrip
2008-10-09 00:23 . 2008-10-09 00:23 <DIR> d-------- c:\program files\NAPI-PROJEKT
2008-10-07 08:12 . 2008-11-04 13:28 519 --a------ C:\hpfr3420.xml
2008-10-06 22:09 . 2008-10-06 22:09 <DIR> d---s---- c:\documents and settings\user\UserData
2008-10-06 22:08 . 2003-04-07 07:21 233,528 -ra------ c:\windows\system32\HPZidr12.dll
2008-10-06 22:08 . 2003-04-07 07:21 167,936 -ra------ c:\windows\system32\HPZipr12.dll
2008-10-06 22:08 . 2003-04-07 07:21 94,208 -ra------ c:\windows\system32\HPZipt12.dll
2008-10-06 22:08 . 2003-04-07 07:21 65,795 -ra------ c:\windows\system32\HPZipm12.exe
2008-10-06 22:08 . 2003-04-07 07:21 61,699 -ra------ c:\windows\system32\HPZinw12.exe
2008-10-06 22:08 . 2003-04-07 07:21 57,344 -ra------ c:\windows\system32\HPZisn12.dll
2008-10-06 22:08 . 2003-04-07 07:21 51,024 -ra------ c:\windows\system32\drivers\hpzid412.sys
2008-10-06 22:08 . 2003-04-07 07:21 16,080 -ra------ c:\windows\system32\drivers\HPZipr12.sys
2008-10-06 22:07 . 2008-10-06 22:07 <DIR> d-------- c:\documents and settings\user\Dane aplikacji\Hewlett-Packard
2008-10-06 22:07 . 2008-10-06 22:07 82,380 --a------ c:\windows\system32\drivers\AFS2K.SYS
2008-10-06 22:07 . 2004-08-03 22:08 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys
2008-10-06 22:07 . 2004-08-03 22:08 31,616 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2008-10-06 22:07 . 2004-08-03 22:01 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-10-06 22:07 . 2004-08-03 22:01 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2008-10-06 22:07 . 2003-04-07 07:21 21,456 -ra------ c:\windows\system32\drivers\HPZius12.sys
2008-10-06 22:07 . 2004-08-03 21:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-10-06 22:07 . 2004-08-03 21:58 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2008-10-06 22:05 . 2008-10-06 22:05 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2008-10-06 22:04 . 2008-10-06 22:07 <DIR> d-------- c:\program files\Hewlett-Packard
2008-10-06 22:04 . 2008-10-06 22:07 20,458 --a------ c:\windows\hpoins01.dat
2008-10-06 22:04 . 2003-04-07 07:31 16,622 --------- c:\windows\hpomdl01.dat
2008-10-05 19:03 . 2008-10-29 18:52 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Test Drive Unlimited
2008-10-05 18:52 . 2008-10-05 18:52 <DIR> d-------- c:\program files\Atari
2008-10-04 00:26 . 2008-10-04 00:32 <DIR> d-------- c:\program files\ALLPlayer
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-04 18:22 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-04 14:27 --------- d-----w c:\program files\GRETECH
2008-11-04 14:23 --------- d---a-w c:\documents and settings\All Users\Dane aplikacji\TEMP
2008-11-03 21:52 --------- d-----w c:\program files\Steam
2008-11-03 16:05 --------- d-----w c:\program files\Microsoft.NET
2008-11-03 16:02 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2008-11-03 15:59 --------- d-----w c:\program files\MSBuild
2008-10-12 16:11 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\iolo
2008-10-02 18:12 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-09-24 17:27 --------- d-----w c:\documents and settings\user\Dane aplikacji\Autodesk
2008-09-24 17:26 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Autodesk
2008-09-24 17:25 --------- d-----w c:\program files\Common Files\Autodesk Shared
2008-09-24 17:25 --------- d-----w c:\program files\AutoCAD 2007
2008-09-24 17:25 --------- d-----w c:\program files\AnswerWorks 4.0
2008-09-24 17:19 --------- d-----w c:\program files\Autodesk
2008-09-22 21:09 --------- d-----w c:\program files\Gadu-Gadu
2008-09-21 22:10 409,600 ----a-w c:\windows\system32\wrap_oal.dll
2008-09-21 22:10 114,688 ----a-w c:\windows\system32\OpenAL32.dll
2008-09-21 22:09 --------- d-----w c:\program files\Common Files\Apple
2008-09-20 21:43 --------- d-----w c:\program files\Puzzle Quest
2008-09-20 21:41 --------- d-----w c:\program files\Common Files\Adobe
2008-09-20 21:26 --------- d-----w c:\documents and settings\user\Dane aplikacji\iolo
2008-09-20 21:21 --------- d-----w c:\documents and settings\LocalService\Dane aplikacji\iolo
2008-09-20 21:14 74,703 ----a-w c:\windows\system32\mfc45.dll
2008-09-20 16:40 --------- d-----w c:\documents and settings\user\Dane aplikacji\Apple Computer
2008-09-20 10:02 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-09-20 10:02 --------- d--h--r c:\documents and settings\user\Dane aplikacji\SecuROM
2008-09-19 19:14 --------- d-----w c:\program files\QuickTime
2008-09-19 19:14 --------- d-----w c:\program files\iTunes
2008-09-19 19:14 --------- d-----w c:\program files\iPod
2008-09-19 19:14 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Apple Computer
2008-09-19 19:14 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-19 19:13 --------- d-----w c:\program files\Apple Software Update
2008-09-19 19:13 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Apple
2008-09-06 12:19 --------- d-----w c:\program files\Common Files\NSV
2008-08-25 17:29 315,392 ----a-w c:\windows\HideWin.exe
2008-08-05 21:58 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-04 149040]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-11 13520896]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-02-20 1443072]
"PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2008-04-03 727288]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Przyspieszenie uruchomienia programu AutoCAD.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-03-05 11000]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^hp psc 1000 series.lnk]
backup=c:\windows\pss\hp psc 1000 series.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^hpoddt01.exe.lnk]
backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 01:44 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-26 23:47 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-09-10 16:40 289576 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-05-04 09:59 161328 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerStrip]
--a------ 2008-04-03 20:30 727288 c:\program files\PowerStrip\PStrip.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-07-07 08:34 167936 c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-10-09 21:13 1410296 c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-03-11 09:25 1626112 c:\windows\system32\nwiz.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Gry\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"=
"e:\\Gry\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9206:TCP"= 9206:TCP:BitComet 9206 TCP
"9206:UDP"= 9206:UDP:BitComet 9206 UDP
"17473:TCP"= 17473:TCP:BitComet 17473 TCP
"17473:UDP"= 17473:UDP:BitComet 17473 UDP
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [2006-07-05 63352]
R2 PStrip;PSTRIP;c:\windows\system32\drivers\pstrip.sys [2007-07-15 27992]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2001-10-26 3584]
S3 ddsxeiservice;ddsxeiservice2;c:\program files\sXe Injected\ddsxei.sys [2008-08-20 43392]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;e:\programy\visualstdio2005\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Zawartość folderu 'Zaplanowane zadania'
2008-10-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-10-06 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1223327293.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - c:\documents and settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\wjsbz8vh.default\
FF -: plugin - c:\documents and settings\user\Dane aplikacji\Mozilla\plugins\npPxPlay.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
.
.
------- Skojarzenia plików -------
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-04 19:48:42
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-11-04 19:49:10
ComboFix-quarantined-files.txt 2008-11-04 18:49:08
ComboFix2.txt 2008-10-17 17:53:36
Przed: 3 819 094 016 bajtów wolnych
Po: 3,818,770,432 bajtów wolnych
210