• Ogłoszenie:

Nie jestem pewny czy mój pendrive is clean

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Nie jestem pewny czy mój pendrive is clean

Postprzez neeven 19 Lut 2009, 21:37

reklama
Cześć
Niby przeskanowałem avast'em pendrive'a ale nie wykrył nic.Więc podłączam go do laptopa koleżanki i anty wykrył ,że jakiś syf jest.... Dlatego proszę o sprawdzenie logów:


Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:31:19, on 2009-02-19
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ALLUpdate] "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'USŁUGA SIECIOWA')
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 4964 bytes





Kod: Zaznacz wszystko
"Silent Runners.vbs", revision 59, http://www.silentrunners.org/
Operating System: Windows Vista
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"ALLUpdate" = ""C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep"" [null data]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"NvCplDaemon" = "RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" [MS]
"NvMediaCenter" = "RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
  -> {HKLM...CLSID} = "avast"
                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShA64.dll" ["ALWIL Software"]
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
  -> {HKLM...CLSID} = "DesktopContext Class"
                   \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"]
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
  -> {HKLM...CLSID} = "NVIDIA CPL Extension"
                   \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"]

HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
  -> {HKLM...CLSID} = "avast"
                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShA64.dll" ["ALWIL Software"]
WinRAR\(Default) = "{B41DB860-64E4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files (x86)\WinRAR\rarext64.dll" [null data]

HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-64E4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files (x86)\WinRAR\rarext64.dll" [null data]

HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
  -> {HKLM...CLSID} = "avast"
                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShA64.dll" ["ALWIL Software"]
WinRAR\(Default) = "{B41DB860-64E4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files (x86)\WinRAR\rarext64.dll" [null data]


Default executables:
--------------------

HKLM\SOFTWARE\Classes\.hta\(Default) = "htafile"
<<!>> HKLM\SOFTWARE\Classes\htafile\shell\open\command\(Default) = "C:\Windows\SysWOW64\mshta.exe "%1" %*" [MS]


Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------

Note: detected settings may not have any effect.

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\

"DisableThumbnails" = (REG_DWORD) dword:0x00000001
{unrecognized setting}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\

"NoActiveDesktop" = (REG_DWORD) dword:0x00000001
{unrecognized setting}

"NoActiveDesktopChanges" = (REG_DWORD) dword:0x00000001
{unrecognized setting}

"ForceActiveDesktopOn" = (REG_DWORD) dword:0x00000000
{unrecognized setting}

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"DisableRegistryTools" = (REG_DWORD) dword:0x00000000
{User Configuration|Administrative Templates|System|
Prevent access to registry editing tools}

HKCU\Software\Policies\Microsoft\Windows\System\

"DisableCMD" = (REG_DWORD) dword:0x00000000
{User Configuration|Administrative Templates|System|
Prevent access to the command prompt}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\

"ConsentPromptBehaviorAdmin" = (REG_DWORD) dword:0x00000002
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Behavior Of The Elevation Prompt For Administrators In Admin Approval Mode}

"ConsentPromptBehaviorUser" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Behavior Of The Elevation Prompt For Standard Users}

"EnableInstallerDetection" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Detect Application Installations And Prompt For Elevation}

"EnableLUA" = (REG_DWORD) dword:0x00000000
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Run All Administrators In Admin Approval Mode}

"EnableSecureUIAPaths" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Only elevate UIAccess applications that are installed in secure locations}

"EnableVirtualization" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Virtualize file and registry write failures to per-user locations}

"PromptOnSecureDesktop" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Switch to the secure desktop when prompting for elevation}

"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}

"FilterAdministratorToken" = (REG_DWORD) dword:0x00000000
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
User Account Control: Admin Approval Mode for the Built-in Administrator Account}

"EnableUIADesktopToggle" = (REG_DWORD) dword:0x00000000
{unrecognized setting}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Users\Daniel\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\Windows\system32\logon.scr" [MS]


Windows Portable Device AutoPlay Handlers
-----------------------------------------

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\

AlcoholAutoPlayV2.BurnDisc\
"Provider" = "Alcohol 120%"
"InvokeProgID" = "AlcoholAutoPlayV2"
"InvokeVerb" = "BurnDisc"
HKLM\SOFTWARE\Classes\AlcoholAutoPlayV2\shell\BurnDisc\command\(Default) = ""C:\Program Files (x86)\Alcohol Soft\Alcohol 120\alcohol_.exe" %1" ["Alcohol Soft Development Team"]

AlcoholAutoPlayV2.ReadDisc\
"Provider" = "Alcohol 120%"
"InvokeProgID" = "AlcoholAutoPlayV2"
"InvokeVerb" = "BurnDisc"
HKLM\SOFTWARE\Classes\AlcoholAutoPlayV2\shell\BurnDisc\command\(Default) = ""C:\Program Files (x86)\Alcohol Soft\Alcohol 120\alcohol_.exe" %1" ["Alcohol Soft Development Team"]

MSPlayCDAudioOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.AudioCD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\WMP.AudioCD\shell\play\command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /device:AudioCD "%L"" [MS]

MSPlayDVDMovieOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.DVD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\WMP.DVD\shell\play\command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:DVD "%L"" [MS]

MSPlaySuperVideoCDMovieOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.VCD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L"" [MS]

MSPlayVideoCDMovieOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.VCD"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\WMP.VCD\shell\play\command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:4 /device:VCD "%L"" [MS]

MSRipCDAudioOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.RipCD"
"InvokeVerb" = "Rip"
HKLM\SOFTWARE\Classes\WMP.RipCD\shell\Rip\Command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /RipAudioCD "%L" " [MS]

MSWMPBurnCDOnArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.BurnCD"
"InvokeVerb" = "Burn"
HKLM\SOFTWARE\Classes\WMP.BurnCD\shell\Burn\Command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:CDWrite /Device:"%L" " [MS]

MSWMPBurnDataDVDArrival\
"Provider" = "@wmploc.dll,-6502"
"InvokeProgID" = "WMP.BurnDVD"
"InvokeVerb" = "Burn"
HKLM\SOFTWARE\Classes\WMP.BurnDVD\shell\Burn\Command\(Default) = ""C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:3 /Task:DVDWrite /Device:"%L" " [MS]

NeroAutoPlay7AudioToNeroDigital\
"Provider" = "Nero Burning ROM"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "AudioToNeroDigital_PlayCDAudioOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\AudioToNeroDigital_PlayCDAudioOnArrival\command\(Default) = "C:\Program Files (x86)\Nero\Nero 7\Core\nero.exe /Dialog:SaveTracks %L" ["Nero AG"]

NeroAutoPlay7CDAudio\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "CDAudio_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\CDAudio_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files (x86)\Nero\Nero 7\Core\nero.exe -w /New:AudioCD" ["Nero AG"]

NeroAutoPlay7CopyCD\
"Provider" = "Nero Burning ROM"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "CopyCD_PlayMusicFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\CopyCD_PlayMusicFilesOnArrival\command\(Default) = "C:\Program Files (x86)\Nero\Nero 7\Core\nero.exe /Dialog:DiscCopy %L" ["Nero AG"]

NeroAutoPlay7DataDisc\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "DataDisc_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\DataDisc_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files (x86)\Nero\Nero 7\Core\nero.exe -w /New:ISODisc" ["Nero AG"]

NeroAutoPlay7LaunchNeroStartSmart\
"Provider" = "Nero StartSmart"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "LaunchNeroStartSmart_HandleCDBurningOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\LaunchNeroStartSmart_HandleCDBurningOnArrival\command\(Default) = "C:\Program Files (x86)\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe /AutoPlay" ["Nero AG"]

NeroAutoPlay7PlayAudioCD\
"Provider" = "Nero ShowTime"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "PlayAudioCD_PlayMusicFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\PlayAudioCD_PlayMusicFilesOnArrival\command\(Default) = "C:\Program Files (x86)\Nero\Nero 7\Nero ShowTime\ShowTime.exe /Play %L" ["Nero AG"]

NeroAutoPlay7PlayDVD\
"Provider" = "Nero ShowTime"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "PlayDVD_PlayVideoFilesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\PlayDVD_PlayVideoFilesOnArrival\command\(Default) = "C:\Program Files (x86)\Nero\Nero 7\Nero ShowTime\ShowTime.exe /Play %L" ["Nero AG"]

NeroAutoPlay7RipCD\
"Provider" = "Nero Burning ROM"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "RipCD_PlayCDAudioOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\RipCD_PlayCDAudioOnArrival\command\(Default) = "C:\Program Files (x86)\Nero\Nero 7\Core\nero.exe /Dialog:SaveTracks %L" ["Nero AG"]

NeroAutoPlay7TranscodeVideo\
"Provider" = "Nero Recode"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "TranscodeVideo_PlayDVDMovieOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\TranscodeVideo_PlayDVDMovieOnArrival\command\(Default) = "C:\Program Files (x86)\Nero\Nero 7\Nero Recode\Recode.exe /New:CopyDVDVideo" ["Nero AG"]

NeroAutoPlay7VideoCapture\
"Provider" = "Nero Vision"
"ProgID" = "Shell.HWEventHandlerShellExecute"
"InitCmdLine" = ""C:\Program Files (x86)\Nero\Nero 7\Nero Vision\NeroVision.exe" /New:VideoCapture"
HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}"
  -> {HKLM...CLSID} = "Shell Execute Hardware Event Handler"
                   \LocalServer32\(Default) = "C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]

NeroAutoPlay7ViewPhotos\
"Provider" = "Nero PhotoSnap Viewer"
"InvokeProgID" = "Nero.AutoPlay7"
"InvokeVerb" = "ViewPhotos_ShowPicturesOnArrival"
HKLM\SOFTWARE\Classes\Nero.AutoPlay7\shell\ViewPhotos_ShowPicturesOnArrival\command\(Default) = "C:\Program Files (x86)\Nero\Nero 7\Nero PhotoSnap\PhotoSnapViewer.exe /" ["Nero AG"]


Non-disabled Scheduled Tasks:
-----------------------------

C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client
"AD RMS Rights Policy Template Management (Manual)" ->  launches: "{BF5CB148-7C77-4d8a-A53E-D81C70CF743C}"
  -> {HKLM...CLSID} = "AD RMS Rights Policy Template Management (Manual) Task Handler"
                   \InProcServer32\(Default) = "C:\Windows\system32\msdrm.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth
"UninstallDeviceTask" ->  launches: "BthUdTask.exe $(Arg0)" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient
"SystemTask" ->  launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
  -> {HKLM...CLSID} = "Certificate Services Client Task Handler"
                   \InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
"UserTask" ->  launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
  -> {HKLM...CLSID} = "Certificate Services Client Task Handler"
                   \InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
"UserTask-Roam" ->  launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
  -> {HKLM...CLSID} = "Certificate Services Client Task Handler"
                   \InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program
"Consolidator" ->  launches: "%SystemRoot%\System32\wsqmcons.exe" [MS]
"OptinNotification" ->  launches: "%SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Defrag
"ScheduledDefrag" ->  launches: "%windir%\system32\defrag.exe -c -i" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\DiskDiagnostic
"Microsoft-Windows-DiskDiagnosticDataCollector" -> (HIDDEN!) launches: "%windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Media Center
"ehDRMInit" ->  launches: "%SystemRoot%\ehome\ehPrivJob.exe /DRMInit" [MS]
"mcupdate" ->  launches: "%SystemRoot%\ehome\mcupdate $(Arg0) -gc" [MS]
"OCURActivate" ->  launches: "%SystemRoot%\ehome\ehPrivJob.exe /OCURActivate" [MS]
"OCURDiscovery" ->  launches: "%SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery" [MS]
"UpdateRecordPath" ->  launches: "%SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC
"HotStart" ->  launches: "{06DA0625-9701-43da-BFD7-FBEEA2180A1E}"
  -> {HKLM...CLSID} = "HotStart User Agent"
                   \InProcServer32\(Default) = "C:\Windows\System32\HotStartUserAgent.dll" [MS]
"TMM" ->  launches: "{35EF4182-F900-4632-B072-8639E4478A61}"
  -> {HKLM...CLSID} = "Transient Multi-Monitor Manager"
                   \InProcServer32\(Default) = "C:\Windows\System32\TMM.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\MUI
"LPRemove" ->  launches: "%windir%\system32\lpremove.exe" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia
"SystemSoundsService" ->  launches: "{2DEA658F-54C1-4227-AF9B-260AB5FC3543}"
  -> {HKLM...CLSID} = "Microsoft PlaySoundService Class"
                   \InProcServer32\(Default) = "C:\Windows\System32\PlaySndSrv.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\NetworkAccessProtection
"NAPStatus UI" ->  launches: "{f09878a1-4652-4292-aa63-8c7d4fd7648f}"
  -> {HKLM...CLSID} = "Nap ITask Handler Implementation"
                   \InProcServer32\(Default) = "C:\Windows\System32\QAgent.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\PLA\System
"ConvertLogEntries" -> (HIDDEN!) launches: "%windir%\system32\rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\RAC
"RACAgent" -> (HIDDEN!) launches: "%windir%\system32\RacAgent.exe" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance
"RemoteAssistanceTask" -> (HIDDEN!) launches: "%windir%\system32\RAServer.exe /offerraupdate" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Shell
"CrawlStartPages" ->  launches: "{51653423-e62d-4ff7-894a-dabb2b8e21e2}"
  -> {HKLM...CLSID} = "CrawlStartPages Task Handler"
                   \InProcServer32\(Default) = "C:\Windows\System32\srchadmin.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\SideShow
"GadgetManager" ->  launches: "{FF87090D-4A9A-4f47-879B-29A80C355D61}"
  -> {HKLM...CLSID} = "GadgetsManager Class"
                   \InProcServer32\(Default) = "C:\Windows\System32\AuxiliaryDisplayServices.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore
"SR" ->  launches: "%windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Tcpip
"IpAddressConflict1" ->  launches: "rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem" [MS]
"IpAddressConflict2" ->  launches: "rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework
"MsCtfMonitor" -> (HIDDEN!) launches: "{01575cfe-9a55-4003-a5e1-f38d1ebdcbe1}"
  -> {HKLM...CLSID} = "MsCtfMonitor task handler"
                   \InProcServer32\(Default) = "C:\Windows\system32\MsCtfMonitor.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\UPnP
"UPnPHostConfig" ->  launches: "sc.exe config upnphost start= auto" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\WDI
"ResolutionHost" -> (HIDDEN!) launches: "{900be39d-6be8-461a-bc4d-b0fa71f5ecb1}"
  -> {HKLM...CLSID} = "DiagnosticInfrastructureCustomHandler"
                   \InProcServer32\(Default) = "C:\Windows\System32\wdi.dll" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting
"QueueReporting" ->  launches: "%windir%\system32\wermgr.exe -queuereporting" [MS]

C:\Windows\System32\Tasks\Microsoft\Windows\Wired
"GatherWiredInfo" ->  launches: "%windir%\system32\gatherWiredInfo.vbs" [null data]

C:\Windows\System32\Tasks\Microsoft\Windows\Wireless
"GatherWirelessInfo" ->  launches: "%windir%\system32\gatherWirelessInfo.vbs" [null data]

C:\Windows\System32\Tasks\Microsoft\Windows Defender
"MP Scheduled Scan" -> (HIDDEN!) launches: "c:\program files\windows defender\MpCmdRun.exe Scan -RestrictPrivileges" [MS]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000005\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000006\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

Transport Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 10


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" ["ALWIL Software"]
avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" ["ALWIL Software"]
NVIDIA Display Driver Service, nvsvc, "C:\Windows\system32\nvvsvc.exe" ["NVIDIA Corporation"]
StarWind AE Service, StarWindServiceAE, "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe" ["Rocket Division Software"]
Usługa Protokół SSTP, SstpSvc, "C:\Windows\system32\svchost.exe -k LocalService" {"C:\Windows\system32\sstpsvc.dll" [MS]}
Windows Driver Foundation — User-mode Driver Framework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [MS]}
Windows Image Acquisition (WIA), stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [MS]}


---------- (launch time: 2009-02-19 20:27:39)
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
  took 24 seconds.
---------- (total run time: 47 seconds)
Awatar użytkownika
neeven
~user
 
Posty: 299
Dołączenie: 20 Paź 2006, 01:12
Pochwały: 3



Re: nie jestem pewny czy mój pendrive is clean

Postprzez Lukesh 19 Lut 2009, 21:48

Odpal combofixa z podłączonym pendrivem - wszystko nam zaraz pokaże.
][_, ([]) ][_, xD

Niedaleko od Krakowa leży miasto Częstochowa,
dzieją się tam różne rzeczy, zakonnice mają dzieci
I kup sobie chamie medalik na szyje,
nic Ci się nie stanie i tramwaj nie zabije,
I kup sobie chamie obrączkę na rączkę,
nie będziesz chorował na kiłe i rzeżączkę.
Medalikarz mądra głowa, niech nam żyje Częstochowa,
czy za dyche, czy za piątkę kupisz chamie tu pamiątkę,
a pamiątka z Częstochowy to karabin maszynowy !
Awatar użytkownika
Lukesh
*mod
 
Posty: 7838
Dołączenie: 11 Lis 2005, 21:45
Miejscowość: Częstochowa / Kraków
Pochwały: 852



Re: nie jestem pewny czy mój pendrive is clean

Postprzez neeven 20 Lut 2009, 16:21

Zawsze combofix mi odpalał,a teraz gdy próbuje go użyć wyskakuje:
Image
I co teraz? :?
Awatar użytkownika
neeven
~user
 
Posty: 299
Dołączenie: 20 Paź 2006, 01:12
Pochwały: 3



Nie jestem pewny czy mój pendrive is clean

Postprzez wojtas 20 Lut 2009, 16:23

Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Re: nie jestem pewny czy mój pendrive is clean

Postprzez neeven 20 Lut 2009, 21:32

Ok dzięki a jeśli chciałbym sprawdzić cały komputer?I dać loga z combofix'a?Którego nie mogę odpalić.To co muszę zrobić aby dać log z combo?Błąd pokazałem w drugim poście.

Edit:
Dorzucam log z RSIT'a: I proszę o jego sprawdzenie.



Kod: Zaznacz wszystko
Logfile of random's system information tool 1.05 (written by random/random)
Run by Daniel at 2009-02-20 21:25:51
Microsoft® Windows Vista™ Ultimate  Service Pack 1
System drive C: has 9 GB (26%) free of 36 GB
Total RAM: 3071 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:25:52, on 2009-02-20
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\SysWOW64\conime.exe
C:\Users\Daniel\Desktop\RSIT.exe
C:\Program Files (x86)\Trend Micro\HijackThis\Daniel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'USŁUGA SIECIOWA')
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 4938 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"DisableThumbnails"=1
"NoDriveAutoRun"=FFFFFFFF
"NoDriveTypeAutoRun"=36

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"NoActiveDesktopChanges"=
"ForceActiveDesktopOn"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8fd627fa-f782-11dd-8c10-806e6f6e6963}]
shell\AutoRun\command - G:\Autorun.exe


======File associations======

.inf - open - %SystemRoot%\SysWow64\NOTEPAD.EXE %1

======List of files/folders created in the last 1 months======

2009-02-20 21:25:51 ----D---- C:\rsit
2009-02-20 20:47:04 ----RASHD---- C:\autorun.inf
2009-02-20 15:20:31 ----A---- C:\Bug.txt
2009-02-20 15:13:08 ----D---- C:\ComboFix
2009-02-20 15:13:07 ----A---- C:\Windows\system32\CF31733.exe
2009-02-20 15:12:44 ----D---- C:\32788R22FWJFW
2009-02-19 22:17:18 ----A---- C:\Windows\system32\CF29343.exe
2009-02-19 22:16:39 ----A---- C:\Windows\system32\CF29209.exe
2009-02-19 22:16:17 ----A---- C:\Windows\system32\swsc.exe
2009-02-19 22:16:17 ----A---- C:\Windows\system32\CF29141.exe
2009-02-19 22:03:57 ----A---- C:\Windows\system32\CF26741.exe
2009-02-19 22:03:40 ----A---- C:\Windows\system32\CF26669.exe
2009-02-19 21:58:13 ----A---- C:\Windows\system32\CF25617.exe
2009-02-19 21:57:48 ----A---- C:\Windows\system32\CF25516.exe
2009-02-19 21:57:17 ----D---- C:\combo
2009-02-18 20:49:45 ----D---- C:\Program Files (x86)\Elecard
2009-02-18 20:49:45 ----D---- C:\Program Files (x86)\Common Files\Elecard
2009-02-18 20:08:15 ----A---- C:\Windows\NeroDigital.ini
2009-02-18 20:07:51 ----D---- C:\Program Files (x86)\NAPI-PROJEKT
2009-02-18 20:07:48 ----D---- C:\Program Files (x86)\ALLPlayer
2009-02-18 16:04:16 ----D---- C:\Program Files (x86)\Nvidia Omega Drivers
2009-02-18 16:04:16 ----A---- C:\Windows\Nvidia Omega Drivers v1.169.25 Uninstall.exe
2009-02-17 15:24:52 ----D---- C:\Program Files (x86)\Sunrise Vista 64 Konfigurator
2009-02-17 15:17:03 ----D---- C:\Program Files (x86)\Lavalys
2009-02-16 15:30:44 ----D---- C:\Users\Daniel\AppData\Roaming\Ashampoo
2009-02-16 15:21:29 ----D---- C:\ProgramData\ashampoo
2009-02-16 15:21:22 ----D---- C:\Program Files (x86)\Ashampoo
2009-02-15 22:07:27 ----D---- C:\Program Files (x86)\CCleaner
2009-02-15 22:05:08 ----D---- C:\Program Files (x86)\Microsoft Bootvis
2009-02-15 22:03:57 ----A---- C:\Windows\system32\CF12076.exe
2009-02-15 22:02:56 ----A---- C:\Windows\system32\cmd.execf
2009-02-15 21:58:02 ----D---- C:\Program Files (x86)\Odkurzacz
2009-02-15 21:47:04 ----D---- C:\Program Files (x86)\Trend Micro
2009-02-15 21:36:44 ----A---- C:\wwdc.exe
2009-02-15 18:55:52 ----D---- C:\Program Files (x86)\MSXML 4.0
2009-02-15 11:00:01 ----D---- C:\Users\Daniel\AppData\Roaming\Ahead
2009-02-15 10:59:45 ----D---- C:\ProgramData\Ahead
2009-02-15 10:58:52 ----D---- C:\ProgramData\Nero
2009-02-15 10:58:52 ----D---- C:\Program Files (x86)\Nero
2009-02-15 10:58:52 ----D---- C:\Program Files (x86)\Common Files\Ahead
2009-02-14 12:17:50 ----A---- C:\Windows\system32\CmdLineExt_x64.dll
2009-02-12 16:55:02 ----RA---- C:\Windows\system32\vp6vfw.dll
2009-02-12 16:22:38 ----D---- C:\Program Files (x86)\Alcohol Soft
2009-02-12 15:57:53 ----A---- C:\Windows\ÄAxType.ini
2009-02-12 15:55:18 ----D---- C:\Program Files (x86)\WinRAR
2009-02-11 20:23:19 ----D---- C:\Users\Daniel\AppData\Roaming\Nowe Gadu-Gadu
2009-02-11 20:21:25 ----D---- C:\Program Files (x86)\Nowe Gadu-Gadu
2009-02-10 22:01:03 ----D---- C:\Users\Daniel\AppData\Roaming\Foxit
2009-02-10 21:48:49 ----D---- C:\Program Files (x86)\PROnetworks
2009-02-10 21:48:28 ----SHD---- C:\Windows\Installer
2009-02-10 21:21:20 ----D---- C:\Users\Daniel\AppData\Roaming\foobar2000
2009-02-10 21:21:16 ----D---- C:\Program Files (x86)\foobar2000
2009-02-10 21:14:43 ----D---- C:\Users\Daniel\AppData\Roaming\Mozilla
2009-02-10 21:14:38 ----D---- C:\Program Files (x86)\Mozilla Firefox
2009-02-10 20:54:57 ----A---- C:\Windows\system32\gpprefcl.dll
2009-02-10 20:52:18 ----D---- C:\ProgramData\NVIDIA
2009-02-10 20:19:04 ----D---- C:\Users\Daniel\AppData\Roaming\Macromedia
2009-02-10 20:19:04 ----D---- C:\Users\Daniel\AppData\Roaming\Adobe
2009-02-10 20:19:03 ----D---- C:\Windows\system32\Macromed
2009-02-10 20:17:57 ----A---- C:\Windows\system32\msshooks.dll
2009-02-10 20:17:57 ----A---- C:\Windows\system32\msscb.dll
2009-02-10 20:17:57 ----A---- C:\Windows\system32\mimefilt.dll
2009-02-10 20:17:56 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-02-10 20:17:56 ----A---- C:\Windows\system32\propdefs.dll
2009-02-10 20:17:56 ----A---- C:\Windows\system32\msstrc.dll
2009-02-10 20:17:56 ----A---- C:\Windows\system32\mssitlb.dll
2009-02-10 20:17:56 ----A---- C:\Windows\system32\chsbrkr.dll
2009-02-10 20:17:55 ----A---- C:\Windows\system32\thawbrkr.dll
2009-02-10 20:17:55 ----A---- C:\Windows\system32\rtffilt.dll
2009-02-10 20:17:55 ----A---- C:\Windows\system32\propsys.dll
2009-02-10 20:17:55 ----A---- C:\Windows\system32\offfilt.dll
2009-02-10 20:17:55 ----A---- C:\Windows\system32\nlhtml.dll
2009-02-10 20:17:55 ----A---- C:\Windows\system32\mssprxy.dll
2009-02-10 20:17:55 ----A---- C:\Windows\system32\msshsq.dll
2009-02-10 20:17:55 ----A---- C:\Windows\system32\korwbrkr.dll
2009-02-10 20:17:54 ----A---- C:\Windows\system32\xmlfilter.dll
2009-02-10 20:17:54 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-02-10 20:17:54 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-02-10 20:17:54 ----A---- C:\Windows\system32\mssvp.dll
2009-02-10 20:17:54 ----A---- C:\Windows\system32\mssrch.dll
2009-02-10 20:17:54 ----A---- C:\Windows\system32\mssphtb.dll
2009-02-10 20:17:54 ----A---- C:\Windows\system32\mssph.dll
2009-02-10 20:17:54 ----A---- C:\Windows\system32\msscntrs.dll
2009-02-10 20:17:54 ----A---- C:\Windows\system32\chtbrkr.dll
2009-02-10 20:17:53 ----A---- C:\Windows\system32\tquery.dll
2009-02-10 20:10:59 ----A---- C:\Windows\system32\tzres.dll
2009-02-10 20:04:19 ----A---- C:\Windows\system32\EncDec.dll
2009-02-10 20:04:17 ----A---- C:\Windows\system32\psisdecd.dll
2009-02-10 20:03:37 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-02-10 20:03:35 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-02-10 20:03:16 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-02-10 20:01:53 ----A---- C:\Windows\system32\mshtml.dll
2009-02-10 20:01:52 ----A---- C:\Windows\system32\ieframe.dll
2009-02-10 20:01:51 ----A---- C:\Windows\system32\wininet.dll
2009-02-10 20:01:51 ----A---- C:\Windows\system32\urlmon.dll
2009-02-10 20:01:50 ----A---- C:\Windows\system32\mstime.dll
2009-02-10 20:01:50 ----A---- C:\Windows\system32\msfeeds.dll
2009-02-10 20:01:50 ----A---- C:\Windows\system32\jsproxy.dll
2009-02-10 20:01:50 ----A---- C:\Windows\system32\iertutil.dll
2009-02-10 20:01:04 ----A---- C:\Windows\system32\shell32.dll
2009-02-10 20:01:00 ----A---- C:\Windows\system32\mf.dll
2009-02-10 20:00:58 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-02-10 20:00:57 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-02-10 20:00:57 ----A---- C:\Windows\system32\logagent.exe
2009-02-10 20:00:38 ----A---- C:\Windows\system32\srclient.dll
2009-02-10 20:00:38 ----A---- C:\Windows\system32\kbd106n.dll
2009-02-10 20:00:10 ----A---- C:\Windows\system32\explorer.exe
2009-02-10 20:00:10 ----A---- C:\Windows\explorer.exe
2009-02-10 20:00:07 ----A---- C:\Windows\system32\wshqos.dll
2009-02-10 20:00:07 ----A---- C:\Windows\system32\traffic.dll
2009-02-10 20:00:07 ----A---- C:\Windows\system32\rpcrt4.dll
2009-02-10 20:00:07 ----A---- C:\Windows\system32\pacerprf.dll
2009-02-10 20:00:02 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-02-10 20:00:01 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-02-10 20:00:01 ----A---- C:\Windows\system32\gameux.dll
2009-02-10 19:59:59 ----A---- C:\Windows\system32\gdi32.dll
2009-02-10 19:59:58 ----A---- C:\Windows\system32\Faultrep.dll
2009-02-10 19:59:56 ----A---- C:\Windows\system32\msxml6.dll
2009-02-10 19:59:54 ----A---- C:\Windows\system32\msxml3.dll
2009-02-10 19:59:53 ----A---- C:\Windows\system32\win32spl.dll
2009-02-10 19:59:49 ----A---- C:\Windows\system32\dataclen.dll
2009-02-10 19:59:12 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-02-10 19:59:10 ----A---- C:\Windows\system32\inetcomm.dll
2009-02-10 19:59:08 ----A---- C:\Windows\system32\wshext.dll
2009-02-10 19:59:08 ----A---- C:\Windows\system32\wscript.exe
2009-02-10 19:59:08 ----A---- C:\Windows\system32\vbscript.dll
2009-02-10 19:59:08 ----A---- C:\Windows\system32\scrrun.dll
2009-02-10 19:59:08 ----A---- C:\Windows\system32\scrobj.dll
2009-02-10 19:59:08 ----A---- C:\Windows\system32\jscript.dll
2009-02-10 19:59:08 ----A---- C:\Windows\system32\cscript.exe
2009-02-10 19:59:06 ----A---- C:\Windows\system32\winipsec.dll
2009-02-10 19:59:06 ----A---- C:\Windows\system32\polstore.dll
2009-02-10 19:59:06 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2009-02-10 19:59:04 ----A---- C:\Windows\system32\es.dll
2009-02-10 19:59:03 ----A---- C:\Windows\system32\connect.dll
2009-02-10 19:58:13 ----A---- C:\Windows\system32\wmpeffects.dll
2009-02-10 19:58:12 ----A---- C:\Windows\system32\wshrm.dll
2009-02-10 19:57:14 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-02-10 19:57:14 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-02-10 19:57:13 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-02-10 19:56:37 ----A---- C:\Windows\system32\quartz.dll
2009-02-10 19:55:09 ----A---- C:\Windows\system32\netapi32.dll
2009-02-10 19:49:08 ----A---- C:\Windows\system32\wups.dll
2009-02-10 19:49:08 ----A---- C:\Windows\system32\wudriver.dll
2009-02-10 19:49:08 ----A---- C:\Windows\system32\wuapi.dll
2009-02-10 19:49:01 ----A---- C:\Windows\system32\wuwebv.dll
2009-02-10 19:49:01 ----A---- C:\Windows\system32\wuapp.exe
2009-02-10 19:47:20 ----D---- C:\Program Files (x86)\xp-AntiSpy
2009-02-10 19:40:21 ----D---- C:\Program Files (x86)\Vtune
2009-02-10 19:33:20 ----A---- C:\Windows\system32\MSVCR71.dll
2009-02-10 19:33:20 ----A---- C:\Windows\system32\MSVCP71.dll
2009-02-10 19:33:20 ----A---- C:\Windows\system32\MFC71.dll
2009-02-10 19:33:20 ----A---- C:\Windows\system32\aswBoot.exe
2009-02-10 19:26:33 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-02-10 19:26:33 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-02-10 19:26:33 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-02-10 19:26:32 ----A---- C:\Windows\system32\d3dx10_39.dll
2009-02-10 19:26:32 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2009-02-10 19:26:31 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-02-10 19:26:30 ----A---- C:\Windows\system32\XAudio2_1.dll
2009-02-10 19:26:30 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2009-02-10 19:26:30 ----A---- C:\Windows\system32\xactengine3_1.dll
2009-02-10 19:26:29 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2009-02-10 19:26:29 ----A---- C:\Windows\system32\d3dx10_38.dll
2009-02-10 19:26:29 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2009-02-10 19:26:28 ----A---- C:\Windows\system32\XAudio2_0.dll
2009-02-10 19:26:28 ----A---- C:\Windows\system32\xactengine3_0.dll
2009-02-10 19:26:28 ----A---- C:\Windows\system32\D3DX9_38.dll
2009-02-10 19:26:27 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2009-02-10 19:26:26 ----A---- C:\Windows\system32\d3dx10_37.dll
2009-02-10 19:26:26 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2009-02-10 19:26:25 ----A---- C:\Windows\system32\xactengine2_10.dll
2009-02-10 19:26:25 ----A---- C:\Windows\system32\D3DX9_37.dll
2009-02-10 19:26:24 ----A---- C:\Windows\system32\d3dx10_36.dll
2009-02-10 19:26:24 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2009-02-10 19:26:23 ----A---- C:\Windows\system32\d3dx9_36.dll
2009-02-10 19:26:22 ----A---- C:\Windows\system32\xactengine2_9.dll
2009-02-10 19:26:21 ----A---- C:\Windows\system32\d3dx10_35.dll
2009-02-10 19:26:21 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2009-02-10 19:26:20 ----A---- C:\Windows\system32\d3dx9_35.dll
2009-02-10 19:26:19 ----A---- C:\Windows\system32\xactengine2_8.dll
2009-02-10 19:26:19 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2009-02-10 19:26:19 ----A---- C:\Windows\system32\d3dx10_34.dll
2009-02-10 19:26:19 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2009-02-10 19:26:18 ----A---- C:\Windows\system32\xinput1_3.dll
2009-02-10 19:26:18 ----A---- C:\Windows\system32\d3dx9_34.dll
2009-02-10 19:26:17 ----A---- C:\Windows\system32\xactengine2_7.dll
2009-02-10 19:26:17 ----A---- C:\Windows\system32\d3dx10_33.dll
2009-02-10 19:26:17 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2009-02-10 19:26:16 ----A---- C:\Windows\system32\xactengine2_6.dll
2009-02-10 19:26:16 ----A---- C:\Windows\system32\d3dx9_33.dll
2009-02-10 19:26:15 ----A---- C:\Windows\system32\xactengine2_5.dll
2009-02-10 19:26:15 ----A---- C:\Windows\system32\d3dx10.dll
2009-02-10 19:26:14 ----A---- C:\Windows\system32\xactengine2_4.dll
2009-02-10 19:26:14 ----A---- C:\Windows\system32\x3daudio1_1.dll
2009-02-10 19:26:14 ----A---- C:\Windows\system32\d3dx9_32.dll
2009-02-10 19:26:13 ----A---- C:\Windows\system32\xactengine2_3.dll
2009-02-10 19:26:13 ----A---- C:\Windows\system32\d3dx9_31.dll
2009-02-10 19:26:12 ----A---- C:\Windows\system32\xinput1_2.dll
2009-02-10 19:26:12 ----A---- C:\Windows\system32\xinput1_1.dll
2009-02-10 19:26:12 ----A---- C:\Windows\system32\xactengine2_2.dll
2009-02-10 19:26:11 ----A---- C:\Windows\system32\xactengine2_1.dll
2009-02-10 19:26:08 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-02-10 19:26:07 ----A---- C:\Windows\system32\xactengine2_0.dll
2009-02-10 19:26:07 ----A---- C:\Windows\system32\x3daudio1_0.dll
2009-02-10 19:26:07 ----A---- C:\Windows\system32\d3dx9_29.dll
2009-02-10 19:26:06 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-02-10 19:26:06 ----A---- C:\Windows\system32\d3dx9_27.dll
2009-02-10 19:26:05 ----A---- C:\Windows\system32\d3dx9_26.dll
2009-02-10 19:26:04 ----A---- C:\Windows\system32\d3dx9_25.dll
2009-02-10 19:26:03 ----A---- C:\Windows\system32\d3dx9_24.dll
2009-02-10 19:13:30 ----A---- C:\Windows\RTKAUDIOSERVICE.EXE
2009-02-10 19:13:20 ----D---- C:\Windows\system32\RTCOM
2009-02-10 19:12:58 ----A---- C:\Windows\DIFxAPI.dll
2009-02-10 19:12:55 ----A---- C:\Windows\SkyTel.exe
2009-02-10 19:12:55 ----A---- C:\Windows\RtlUpd64.exe
2009-02-10 19:12:51 ----D---- C:\Program Files (x86)\Realtek
2009-02-10 19:12:51 ----A---- C:\Windows\RAVCpl64.exe
2009-02-10 19:12:50 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2009-02-10 19:12:49 ----R---- C:\Windows\RtlExUpd.dll
2009-02-10 19:12:49 ----A---- C:\Windows\HideWin.exe
2009-02-10 19:12:44 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2009-02-10 17:15:59 ----D---- C:\Program Files (x86)\Intel
2009-02-10 16:45:45 ----A---- C:\Windows\GSetup.ini
2009-02-10 16:41:32 ----D---- C:\Users\Daniel\AppData\Roaming\Identities
2009-02-10 16:41:26 ----SD---- C:\Users\Daniel\AppData\Roaming\Microsoft
2009-02-10 16:41:26 ----D---- C:\Users\Daniel\AppData\Roaming\Media Center Programs
2009-02-10 16:27:32 ----SHD---- C:\ProgramData\Ulubione
2009-02-10 16:27:32 ----SHD---- C:\ProgramData\Szablony
2009-02-10 16:27:32 ----SHD---- C:\ProgramData\Pulpit
2009-02-10 16:27:32 ----SHD---- C:\ProgramData\Menu Start
2009-02-10 16:27:32 ----SHD---- C:\ProgramData\Dokumenty
2009-02-10 16:27:32 ----SHD---- C:\ProgramData\Dane aplikacji
2009-02-10 16:27:08 ----D---- C:\Windows\Debug
2009-02-10 15:57:11 ----D---- C:\Windows\SoftwareDistribution
2009-02-10 15:55:26 ----D---- C:\Windows\CSC
2009-02-10 15:53:31 ----D---- C:\Windows\Prefetch
2009-02-10 15:52:26 ----D---- C:\Windows\Panther
2009-02-10 15:35:59 ----D---- C:\Windows.old

======List of files/folders modified in the last 1 months======

2009-02-20 21:25:35 ----D---- C:\Windows\Temp
2009-02-20 20:21:02 ----D---- C:\Windows\System32
2009-02-20 20:21:02 ----D---- C:\Windows\inf
2009-02-20 15:20:29 ----D---- C:\Windows\SysWOW64
2009-02-20 15:14:11 ----SHD---- C:\System Volume Information
2009-02-20 15:13:07 ----D---- C:\Windows\system32\en-US
2009-02-18 20:49:45 ----RD---- C:\Program Files (x86)
2009-02-18 20:49:45 ----D---- C:\Program Files (x86)\Common Files
2009-02-18 20:08:15 ----D---- C:\Windows
2009-02-16 15:21:29 ----HD---- C:\ProgramData
2009-02-15 18:56:10 ----D---- C:\Windows\winsxs
2009-02-15 10:59:26 ----D---- C:\Windows\ehome
2009-02-11 20:25:10 ----D---- C:\Windows\rescache
2009-02-11 20:21:31 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2009-02-10 21:56:04 ----SD---- C:\ProgramData\Microsoft
2009-02-10 21:12:30 ----D---- C:\Windows\system32\drivers
2009-02-10 20:58:44 ----D---- C:\Windows\Microsoft.NET
2009-02-10 20:58:35 ----RSD---- C:\Windows\assembly
2009-02-10 20:44:10 ----D---- C:\Windows\system32\pl-PL
2009-02-10 20:44:09 ----D---- C:\Windows\PolicyDefinitions
2009-02-10 20:44:06 ----D---- C:\Windows\AppPatch
2009-02-10 20:44:05 ----D---- C:\Windows\system32\migration
2009-02-10 20:44:02 ----D---- C:\Program Files (x86)\Windows Mail
2009-02-10 20:19:04 ----SD---- C:\Windows\Downloaded Program Files
2009-02-10 20:08:43 ----D---- C:\Windows\Help
2009-02-10 19:53:08 ----D---- C:\Windows\Logs
2009-02-10 19:33:19 ----RD---- C:\Program Files
2009-02-10 16:41:45 ----SHD---- C:\$Recycle.Bin
2009-02-10 16:41:26 ----RD---- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys []
R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys []
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys []
R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys []
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys []
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 ksthunk;Kernel Streaming Thunks; C:\Windows\system32\drivers\ksthunk.sys []
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys []
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys []
S2 TBPanel;TBPanel; C:\Windows\system32\drivers\TBPanel.sys []
S3 a61hu2iu;a61hu2iu; C:\Windows\system32\drivers\a61hu2iu.sys []
S3 Cardex;Cardex; \??\C:\Windows\SysWOW64\drivers\TBPANELX64.SYS [2007-03-16 15648]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-02-10 18752]
S3 HdAudAddService;Sterownik funkcji Microsoft 1.1 UAA dla usługi standardu High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys []
S3 MSKSSRV;Serwer proxy usługi Microsoft Streaming; C:\Windows\system32\drivers\MSKSSRV.sys []
S3 MSPCLOCK;Serwer proxy zegara Microsoft Streaming; C:\Windows\system32\drivers\MSPCLOCK.sys []
S3 MSPQM;Serwer proxy menedżera jakości Microsoft Streaming; C:\Windows\system32\drivers\MSPQM.sys []
S3 MSTEE;Konwerter strumieni Tee/Sink-to-Sink Microsoft Streaming; C:\Windows\system32\drivers\MSTEE.sys []
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys []
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys []
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys []
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe []
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2008-01-21 93696]
S3 NBService;NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-21 19968]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-01-21 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe []
S4 Fax;Faks; C:\Windows\system32\fxssvc.exe []

-----------------EOF-----------------
Awatar użytkownika
neeven
~user
 
Posty: 299
Dołączenie: 20 Paź 2006, 01:12
Pochwały: 3



Nie jestem pewny czy mój pendrive is clean

Postprzez djarta 21 Lut 2009, 11:29

Czysto.


================
K.

Autor postu otrzymał pochwałę
Pozdrawiam djarta. :)
djarta
~user
 
Posty: 684
Dołączenie: 31 Lip 2008, 10:49
Pochwały: 55




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 18 gości

cron