• Ogłoszenie:

Brak tapety na pulpicie

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Brak tapety na pulpicie

Postprzez Mielcarek27 21 Paź 2008, 15:31

reklama
Witam,znikneła mi tapeta z pulpitu a mimo to we własciwościach ekranu figuruje jakby była;zmiana tapety na inną nic nie daje-dalej jest niebieskie tło.Nod32 nie wykazuje żadnych wirusów,porty w wwdc pozamykane
Proszę o sprawdzenie loga
Hijack:
Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:28:30, on 2008-10-21
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Acer\Empowering Technology\admtray.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\DOCUME~1\UKASZ~1\USTAWI~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\ŁUKASZ\Pulpit\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [INPROCOMMWireless] C:\Program Files\Atheros\Wireless\Utility\WlanUtil.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 4044 bytes


Silent Runners

Kod: Zaznacz wszystko
"Silent Runners.vbs", revision 58, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"INPROCOMMWireless" = "C:\Program Files\Atheros\Wireless\Utility\WlanUtil.exe" [file not found]
"egui" = ""C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice" ["ESET"]
"SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"" ["Sun Microsystems, Inc."]
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"AzMixerSel" = "C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" ["Realtek Semiconductor Corp."]
"RTHDCPL" = "RTHDCPL.EXE" ["Realtek Semiconductor Corp."]
"Alcmtr" = "ALCMTR.EXE" ["Realtek Semiconductor Corp."]
"NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]
"nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
"NvMediaCenter" = "RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit" [MS]
"ADMTray.exe" = ""C:\Acer\Empowering Technology\admtray.exe"" ["Avocent Inc."]
"eDataSecurity Loader" = "C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" ["HiTRUST"]
"ePower_DMC" = "C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" ["Acer Incorporated"]
"Acer ePower Management" = "C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot" ["Acer Value Labs, Taiwan"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "SSVHelper Class"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll" ["Sun Microsystems, Inc."]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
                   \InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "D:\Programy\WinRAR\rarext.dll" [null data]
"{B089FE88-FB52-11D3-BDF1-0050DA34150D}" = "Eset Smart Security - Context Menu Shell Extension"
  -> {HKLM...CLSID} = "Eset Smart Security - Context Menu Shell Extension"
                   \InProcServer32\(Default) = "C:\Program Files\ESET\ESET Smart Security\shellExt.dll" ["ESET"]
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
  -> {HKLM...CLSID} = "DesktopContext Class"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
  -> {HKLM...CLSID} = "NVIDIA CPL Extension"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
  -> {HKLM...CLSID} = "Desktop Explorer"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
  -> {HKLM...CLSID} = "nView Desktop Context Menu"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
"{2b45bd21-71f8-4c8c-a87a-7eeb25a1a3e0}" = "EPM-PO Shell Extension"
  -> {HKLM...CLSID} = "EPM-PO Shell Extensions"
                   \InProcServer32\(Default) = "epm-po.dll" ["Acer Labs USA"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
  -> {HKLM...CLSID} = "WPDShServiceObj Class"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]

HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
EDSshellExt\(Default) = "{29FF7AB0-BE34-4992-A30B-53A9D86EE239}"
  -> {HKLM...CLSID} = "eDSshlExt Class"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\eDSshellExt.dll" ["HiTRUST"]
Eset Smart Security - Context Menu Shell Extension\(Default) = "{B089FE88-FB52-11D3-BDF1-0050DA34150D}"
  -> {HKLM...CLSID} = "Eset Smart Security - Context Menu Shell Extension"
                   \InProcServer32\(Default) = "C:\Program Files\ESET\ESET Smart Security\shellExt.dll" ["ESET"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "D:\Programy\WinRAR\rarext.dll" [null data]

HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
EDSshellExt\(Default) = "{29FF7AB0-BE34-4992-A30B-53A9D86EE239}"
  -> {HKLM...CLSID} = "eDSshlExt Class"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\eDSshellExt.dll" ["HiTRUST"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "D:\Programy\WinRAR\rarext.dll" [null data]

HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
Eset Smart Security - Context Menu Shell Extension\(Default) = "{B089FE88-FB52-11D3-BDF1-0050DA34150D}"
  -> {HKLM...CLSID} = "Eset Smart Security - Context Menu Shell Extension"
                   \InProcServer32\(Default) = "C:\Program Files\ESET\ESET Smart Security\shellExt.dll" ["ESET"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "D:\Programy\WinRAR\rarext.dll" [null data]


Group Policies {policy setting}:
--------------------------------

Note: detected settings may not have any effect.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) dword:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\ŁUKASZ\Dane aplikacji\Opera\Opera\profile\skin\tapety-na-plochu-zahranicni-celebrity-cassie-lane-1.bmp"


Windows Portable Device AutoPlay Handlers
-----------------------------------------

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\

MSWPDShellNamespaceHandler\
"Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = " "
  -> {HKLM...CLSID} = "WPDShextAutoplay"
                   \LocalServer32\(Default) = "C:\WINDOWS\system32\WPDShextAutoplay.exe" [MS]

NeroAutoPlay2AudioToNeroDigital\
"Provider" = "Nero Burning ROM"
"InvokeProgID" = "Nero.AutoPlay2"
"InvokeVerb" = "PlayCDAudioOnArrival_AudioToNeroDigital"
HKLM\SOFTWARE\Classes\Nero.AutoPlay2\shell\PlayCDAudioOnArrival_AudioToNeroDigital\command\(Default) = "d:\Programy\Ahead\nero\nero.exe /Dialog:SaveTracksND  /Drive:%L" ["Ahead Software AG"]

NeroAutoPlay2CDAudio\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay2"
"InvokeVerb" = "HandleCDBurningOnArrival_CDAudio"
HKLM\SOFTWARE\Classes\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_CDAudio\command\(Default) = "d:\Programy\Ahead\nero\nero.exe /w /New:AudioCD /Drive:%L" ["Ahead Software AG"]

NeroAutoPlay2CopyCD\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay2"
"InvokeVerb" = "PlayCDAudioOnArrival_CopyCD"
HKLM\SOFTWARE\Classes\Nero.AutoPlay2\shell\PlayCDAudioOnArrival_CopyCD\command\(Default) = "d:\Programy\Ahead\nero\nero.exe /w /Dialog:DiscCopy /Drive:%L" ["Ahead Software AG"]

NeroAutoPlay2DataDisc\
"Provider" = "Nero Express"
"InvokeProgID" = "Nero.AutoPlay2"
"InvokeVerb" = "HandleCDBurningOnArrival_DataDisc"
HKLM\SOFTWARE\Classes\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_DataDisc\command\(Default) = "d:\Programy\Ahead\nero\nero.exe /w /New:ISODisc /Drive:%L" ["Ahead Software AG"]

NeroAutoPlay2LaunchNeroStartSmart\
"Provider" = "Nero StartSmart"
"InvokeProgID" = "Nero.AutoPlay2"
"InvokeVerb" = "HandleCDBurningOnArrival_LaunchNeroStartSmart"
HKLM\SOFTWARE\Classes\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_LaunchNeroStartSmart\command\(Default) = "d:\Programy\Ahead\Nero StartSmart\NeroStartSmart.exe /AutoPlay /Drive:%L" ["Ahead Software AG"]

NeroAutoPlay2RipCD\
"Provider" = "Nero Burning ROM"
"InvokeProgID" = "Nero.AutoPlay2"
"InvokeVerb" = "PlayCDAudioOnArrival_RipCD"
HKLM\SOFTWARE\Classes\Nero.AutoPlay2\shell\PlayCDAudioOnArrival_RipCD\command\(Default) = "d:\Programy\Ahead\nero\nero.exe /Dialog:SaveTracks  /Drive:%L" ["Ahead Software AG"]

VLCPlayCDAudioOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.CDAudio"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\VLC.CDAudio\shell\play\command\(Default) = "D:\Programy\VLC\vlc.exe cdda:%1" ["VideoLAN Team"]

VLCPlayDVDMovieOnArrival\
"Provider" = "VideoLAN VLC media player"
"InvokeProgID" = "VLC.DVDMovie"
"InvokeVerb" = "play"
HKLM\SOFTWARE\Classes\VLC.DVDMovie\shell\play\command\(Default) = "D:\Programy\VLC\vlc.exe dvd:%1" ["VideoLAN Team"]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
"{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}" = (no title provided)
  -> {HKLM...CLSID} = "Acer eDataSecurity Management"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\eDStoolbar.dll" ["HiTRUST"]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}"
  -> {HKCU...CLSID} = "Java Plug-in 1.6.0_07"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll" ["Sun Microsystems, Inc."]
  -> {HKLM...CLSID} = "Java Plug-in 1.6.0_07"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll" ["Sun Microsystems, Inc."]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

AdminWorks Agent X6, AWService, ""C:\Acer\Empowering Technology\admServ.exe"" ["Avocent Inc."]
Eset Service, ekrn, ""C:\Program Files\ESET\ESET Smart Security\ekrn.exe"" ["ESET"]
NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\system32\nvsvc32.exe" ["NVIDIA Corporation"]


---------- (launch time: 2008-10-21 15:28:50)
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
  took 10 seconds.
---------- (total run time: 41 seconds)
Ostatnio edytowany przez Mielcarek27, 21 Paź 2008, 15:38, edytowano w sumie 1 raz
Mielcarek27
~user
 
Posty: 22
Dołączenie: 21 Wrz 2008, 18:05



Brak tapety na pulpicie

Postprzez Magik 21 Paź 2008, 15:37

Witam

pierwsza rzecz wstaw logi w tagi 'code'

wstaw tez log z combofix'a

W Hijacku nic nie widac
Image Image
Awatar użytkownika
Magik
~user
 
Posty: 7956
Dołączenie: 08 Maj 2004, 09:17
Miejscowość: Głogów
Pochwały: 886



Brak tapety na pulpicie

Postprzez djarta 21 Paź 2008, 15:39

Silent - też czysto.

1) Daj log z SRENG

2) Daj log z ComboFixa.



================
K.
Pozdrawiam djarta. :)
djarta
~user
 
Posty: 684
Dołączenie: 31 Lip 2008, 10:49
Pochwały: 55



Brak tapety na pulpicie

Postprzez Mielcarek27 21 Paź 2008, 15:59

Gdy combofix robił loga,wyskoczyło okienko o zainfekowaniu i usunieciu czegos.Niestety mignęło tak szybko ze nie zauwazyłem co i jak
Oto logi:
Combofix:
Kod: Zaznacz wszystko
ComboFix 08-10-19.04 - ŁUKASZ 2008-10-21 15:52:37.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1250.48.1045.18.570 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\ŁUKASZ\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
* Resident AV is active


[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.

(((((((((((((((((((((((((   Pliki utworzone od 2008-09-21 do 2008-10-21  )))))))))))))))))))))))))))))))
.

2008-10-21 14:04 . 2006-01-20 15:56   225,350   --a------   C:\WINDOWS\system32\Epm-Po.dll
2008-10-21 14:02 . 2008-10-21 14:02   <DIR>   d--------   C:\WINDOWS\system32\URTTemp
2008-10-21 13:53 . 2008-10-21 14:10   <DIR>   d--------   C:\WINDOWS\SxsCaPendDel
2008-10-21 13:43 . 2008-10-21 13:43   95   --a------   C:\WINDOWS\AcerePrj.UNI
2008-10-21 13:38 . 2006-02-22 12:50   106,496   --a------   C:\WINDOWS\system32\eDStoolbar.dll
2008-10-21 13:38 . 2005-12-27 15:50   67,072   --a------   C:\WINDOWS\system32\HTCA_SelfExtract.bin
2008-10-21 13:38 . 2005-12-27 20:03   27,136   --a------   C:\WINDOWS\system32\eDSshellExt.dll
2008-10-21 13:37 . 2008-10-21 13:37   <DIR>   d--------   C:\Documents and Settings\ŁUKASZ\Dane aplikacji\Acer
2008-10-21 13:36 . 2008-10-21 13:36   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\Acer
2008-10-21 13:36 . 2008-10-21 13:36   <DIR>   d--------   C:\Acer
2008-10-21 13:36 . 2005-10-15 18:20   12,106   --a------   C:\WINDOWS\system32\drivers\OsaFsLoc.sys
2008-10-21 13:36 . 2005-06-30 16:58   7,296   --a------   C:\WINDOWS\system32\drivers\osaio.sys
2008-10-21 13:36 . 2005-09-13 15:34   4,392   --a------   C:\WINDOWS\system32\drivers\NdisFilt.sys
2008-10-21 13:36 . 2005-01-14 15:57   4,010   --a------   C:\WINDOWS\system32\drivers\osanbm.sys
2008-10-21 13:35 . 2005-01-10 16:48   147,456   --a------   C:\WINDOWS\UNINST32.EXE
2008-10-21 12:10 . 2008-10-21 12:10   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\nView_Profiles
2008-10-21 11:57 . 2008-10-21 11:57   <DIR>   d--------   C:\WINDOWS\nview
2008-10-20 19:24 . 2008-10-20 19:26   <DIR>   d--------   C:\Documents and Settings\ŁUKASZ\Dane aplikacji\BESTplayer
2008-10-20 18:55 . 2008-10-20 18:55   <DIR>   d--------   C:\Documents and Settings\ŁUKASZ\Dane aplikacji\Mozilla
2008-10-20 18:55 . 2008-10-20 18:55   0   --a------   C:\WINDOWS\nsreg.dat
2008-10-20 18:01 . 2008-10-20 18:01   <DIR>   d--------   C:\WINDOWS\system32\Lang
2008-10-20 18:01 . 2008-10-20 18:01   940,794   --a------   C:\WINDOWS\system32\LoopyMusic.wav
2008-10-20 18:01 . 2008-10-20 18:01   146,650   --a------   C:\WINDOWS\system32\BuzzingBee.wav
2008-10-20 17:56 . 2008-10-20 17:56   <DIR>   d--------   C:\Program Files\CONEXANT
2008-10-20 17:56 . 2004-08-03 23:08   60,288   --a------   C:\WINDOWS\system32\drivers\drmk.sys
2008-10-20 17:56 . 2004-08-03 23:08   60,288   --a--c---   C:\WINDOWS\system32\dllcache\drmk.sys
2008-10-20 17:53 . 2008-10-20 17:53   <DIR>   d--------   C:\Program Files\Realtek
2008-10-20 17:53 . 2007-01-13 07:54   520,192   --a------   C:\WINDOWS\RtlExUpd.dll
2008-10-20 17:53 . 2008-10-20 17:53   315,392   --a------   C:\WINDOWS\HideWin.exe
2008-10-20 17:09 . 2006-12-23 02:56   988,800   --a------   C:\WINDOWS\system32\drivers\HSF_DPV.sys
2008-10-20 17:09 . 2006-12-23 02:55   730,112   --a------   C:\WINDOWS\system32\drivers\HSF_CNXT.sys
2008-10-20 17:09 . 2006-12-23 02:56   209,664   --a------   C:\WINDOWS\system32\drivers\HSFHWAZL.sys
2008-10-20 17:09 . 2006-12-21 08:37   176,128   --a------   C:\WINDOWS\system32\UCI32M16.dll
2008-10-20 17:09 . 2006-12-23 06:04   144,201   --a------   C:\WINDOWS\system32\drivers\HSFProf.cty
2008-10-20 17:09 . 2006-06-20 05:26   94,208   --a------   C:\WINDOWS\system32\mdmxsdk.dll
2008-10-20 17:09 . 2006-06-20 05:26   12,672   --a------   C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-10-20 13:38 . 2008-10-20 14:19   <DIR>   d--------   C:\WINDOWS\system32\CatRoot_bak
2008-10-20 13:37 . 2008-06-14 20:01   273,024   ---------   C:\WINDOWS\system32\drivers\bthport.sys
2008-10-20 13:37 . 2008-06-14 20:01   273,024   -----c---   C:\WINDOWS\system32\dllcache\bthport.sys
2008-10-20 13:35 . 2008-08-14 15:46   2,181,632   -----c---   C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-20 13:35 . 2008-08-14 15:46   2,137,600   -----c---   C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-20 13:35 . 2008-08-14 15:46   2,059,008   -----c---   C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-20 13:35 . 2008-08-14 15:46   2,017,280   -----c---   C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-20 13:34 . 1999-09-10 12:06   45,056   --a------   C:\WINDOWS\system32\WNASPI32.DLL
2008-10-20 13:34 . 1999-09-10 12:06   25,244   --a------   C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-10-20 13:34 . 1999-09-10 12:06   5,600   --a------   C:\WINDOWS\system\WINASPI.DLL
2008-10-20 13:34 . 1999-09-10 12:06   4,672   --a------   C:\WINDOWS\system\WOWPOST.EXE
2008-10-20 13:29 . 2005-09-01 11:03   127,488   ---------   C:\WINDOWS\system32\drivers\imagesrv.sys
2008-10-20 13:29 . 2005-09-01 11:03   5,888   ---------   C:\WINDOWS\system32\drivers\imagedrv.sys
2008-10-20 13:28 . 2008-10-20 13:28   <DIR>   d--------   C:\Program Files\Common Files\Ahead
2008-10-20 13:28 . 2004-07-26 16:16   1,568,768   ---------   C:\WINDOWS\system32\ImagX7.dll
2008-10-20 13:28 . 2004-07-26 16:16   476,320   ---------   C:\WINDOWS\system32\ImagXpr7.dll
2008-10-20 13:28 . 2004-07-26 16:16   471,040   ---------   C:\WINDOWS\system32\ImagXRA7.dll
2008-10-20 13:28 . 2004-07-09 08:43   364,544   ---------   C:\WINDOWS\system32\TwnLib4.dll
2008-10-20 13:28 . 2004-07-26 16:16   262,144   ---------   C:\WINDOWS\system32\ImagXR7.dll
2008-10-20 13:28 . 2001-07-09 10:50   155,648   --a------   C:\WINDOWS\system32\NeroCheck.exe
2008-10-20 13:28 . 2000-06-26 10:45   106,496   --a------   C:\WINDOWS\system32\TwnLib20.dll
2008-10-20 13:25 . 2008-10-21 13:44   <DIR>   d--h-----   C:\WINDOWS\$hf_mig$
2008-10-19 23:20 . 2008-10-19 23:20   <DIR>   d--------   C:\Documents and Settings\ŁUKASZ\Dane aplikacji\Macromedia
2008-10-19 23:20 . 2008-10-19 23:20   <DIR>   d--------   C:\Documents and Settings\ŁUKASZ\Dane aplikacji\Adobe
2008-10-19 23:15 . 2008-10-19 23:15   <DIR>   d--------   C:\Program Files\Codec Pack - All In 1
2008-10-19 23:15 . 2008-10-19 23:14   737,280   --a------   C:\WINDOWS\iun6002.exe
2008-10-19 23:14 . 2008-10-19 23:14   <DIR>   d--------   C:\Program Files\Windows Media Connect 2
2008-10-19 23:14 . 2008-10-19 23:14   <DIR>   d--------   C:\Program Files\Real Alternative
2008-10-19 23:14 . 2008-10-19 23:14   <DIR>   d--------   C:\Documents and Settings\ŁUKASZ\Dane aplikacji\Real
2008-10-19 23:14 . 2003-03-19 05:14   499,712   --a------   C:\WINDOWS\system32\msvcp71.dll
2008-10-19 23:14 . 2004-01-12 00:00   348,160   --a------   C:\WINDOWS\system32\msvcr71.dll
2008-10-19 23:14 . 2004-08-04 14:00   221,184   --a------   C:\WINDOWS\system32\wmpns.dll
2008-10-19 23:12 . 2008-10-19 23:12   <DIR>   d--------   C:\WINDOWS\system32\LogFiles
2008-10-19 23:12 . 2008-10-19 23:13   <DIR>   d--------   C:\WINDOWS\system32\drivers\UMDF
2008-10-19 23:12 . 2008-10-19 23:12   <DIR>   d--------   C:\Program Files\Java
2008-10-19 23:12 . 2008-06-10 02:32   73,728   --a------   C:\WINDOWS\system32\javacpl.cpl
2008-10-19 23:12 . 2006-09-25 17:58   23,856   --a------   C:\WINDOWS\system32\spupdsvc.exe
2008-10-19 23:10 . 2008-10-19 23:10   <DIR>   d--------   C:\Program Files\Common Files\Java
2008-10-19 23:10 . 2008-10-19 23:10   13,646   --a------   C:\WINDOWS\system32\wpa.bak
2008-10-19 23:07 . 2008-10-19 23:07   <DIR>   d--------   C:\Program Files\Opera
2008-10-19 23:07 . 2008-10-19 23:07   <DIR>   d--------   C:\Documents and Settings\ŁUKASZ\Dane aplikacji\Opera
2008-10-19 23:05 . 2008-10-19 23:05   <DIR>   d--------   C:\Documents and Settings\ŁUKASZ\Dane aplikacji\ESET
2008-10-19 23:05 . 2008-10-19 23:05   159,871   --a------   C:\WINDOWS\Marsu-Fix Uninstaller.exe
2008-10-19 23:04 . 2008-10-19 23:04   <DIR>   d--------   C:\Program Files\ESET
2008-10-19 23:04 . 2008-10-19 23:04   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\ESET
2008-10-19 22:59 . 2008-10-19 22:59   <DIR>   d--------   C:\Program Files\Atheros
2008-10-19 22:59 . 2006-11-15 08:00   528,096   --a------   C:\WINDOWS\system32\drivers\ar5211.sys
2008-10-19 22:59 . 2005-06-21 13:32   28,544   --a------   C:\WINDOWS\system32\drivers\callistx.sys
2008-10-19 22:30 . 2008-10-19 22:30   <DIR>   d--------   C:\Program Files\Intel
2008-10-19 22:30 . 2008-10-19 22:30   <DIR>   d--------   C:\Intel
2008-10-19 22:08 . 2004-08-04 00:58   5,504   --a------   C:\WINDOWS\system32\drivers\MSTEE.sys
2008-10-19 22:06 . 2004-08-04 02:44   130,048   --a------   C:\WINDOWS\system32\ksproxy.ax
2008-10-19 22:05 . 2004-08-04 02:44   77,312   --a------   C:\WINDOWS\system32\usbui.dll
2008-10-19 22:05 . 2004-08-04 01:07   8,832   --a------   C:\WINDOWS\system32\drivers\wmiacpi.sys
2008-10-19 22:03 . 2008-10-19 22:03   <DIR>   dr-h-----   C:\Documents and Settings\Default User\Ustawienia lokalne
2008-10-19 22:03 . 2008-10-19 22:03   <DIR>   d--------   C:\Documents and Settings\Default User\Ulubione
2008-10-19 22:03 . 2008-10-19 20:31   <DIR>   d--h-----   C:\Documents and Settings\Default User\Szablony
2008-10-19 22:03 . 2008-10-19 22:03   <DIR>   d--------   C:\Documents and Settings\Default User\Pulpit
2008-10-19 22:03 . 2008-10-19 22:03   <DIR>   d--------   C:\Documents and Settings\Default User\Moje dokumenty
2008-10-19 22:03 . 2008-10-19 22:03   <DIR>   dr-------   C:\Documents and Settings\Default User\Menu Start
2008-10-19 22:03 . 2008-10-19 22:03   <DIR>   d--------   C:\Documents and Settings\All Users\Ulubione
2008-10-19 22:03 . 2008-10-19 22:03   <DIR>   d--h-----   C:\Documents and Settings\All Users\Szablony
2008-10-19 22:03 . 2008-10-21 13:36   <DIR>   d--------   C:\Documents and Settings\All Users\Pulpit
2008-10-19 22:03 . 2008-10-19 23:10   <DIR>   dr-------   C:\Documents and Settings\All Users\Menu Start
2008-10-19 22:03 . 2008-10-19 23:14   <DIR>   dr-------   C:\Documents and Settings\All Users\Dokumenty
2008-10-19 22:03 . 2004-08-04 14:00   1,896,400   --a--c---   C:\WINDOWS\system32\dllcache\NT5.CAT
2008-10-19 22:02 . 2008-10-21 15:50   <DIR>   d--------   C:\WINDOWS\system32\CatRoot2
2008-10-19 22:02 . 2008-10-21 11:57   <DIR>   d--------   C:\WINDOWS\system32\CatRoot
2008-10-19 22:02 . 2008-10-19 22:03   <DIR>   dr-h-----   C:\Documents and Settings\Default User\Dane aplikacji
2008-10-19 22:02 . 2008-10-19 20:37   <DIR>   d--h-----   C:\Documents and Settings\Default User
2008-10-19 22:02 . 2008-10-21 13:36   <DIR>   dr-h-----   C:\Documents and Settings\All Users\Dane aplikacji
2008-10-19 22:02 . 2008-10-19 20:36   <DIR>   d--------   C:\Documents and Settings\All Users
2008-10-19 22:02 . 2008-10-19 20:43   <DIR>   d--------   C:\Documents and Settings
2008-10-19 22:02 . 2004-08-04 14:00   1,014,483   -ra------   C:\WINDOWS\SET3.tmp
2008-10-19 22:01 . 2008-10-19 20:40   261   --a------   C:\WINDOWS\system32\$winnt$.inf

.
((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-21 12:04   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
2008-10-21 11:36   ---------   d-----w   C:\Program Files\Common Files\InstallShield
2008-10-19 19:57   ---------   d-----w   C:\Documents and Settings\ŁUKASZ\Dane aplikacji\InstallShield
2008-10-19 18:37   ---------   d-----w   C:\Program Files\microsoft frontpage
2008-10-19 18:36   ---------   d-----w   C:\Program Files\Usługi online
2008-09-15 15:40   1,846,272   ----a-w   C:\WINDOWS\system32\win32k.sys
2008-08-28 10:04   333,056   ----a-w   C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:38   662,016   ----a-w   C:\WINDOWS\system32\wininet.dll
2008-08-14 13:46   2,137,600   ----a-w   C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:46   2,017,280   ----a-w   C:\WINDOWS\system32\ntkrnlpa.exe
.

(((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-07-01 1447168]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-12 53248]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-02-22 13508608]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-02-22 86016]
"ADMTray.exe"="C:\Acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 69632]
"ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-04-14 344064]
"Acer ePower Management"="C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe" [2006-01-20 3080192]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-29 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-02-22 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"D:\\Programy\\BearShare\\BearShare.exe"=
"C:\\Program Files\\Opera\\opera.exe"=
"C:\\Program Files\\ESET\\ESET Smart Security\\egui.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Documents and Settings\\ŁUKASZ\\Pulpit\\BESTplayer.exe"=

R1 OsaFsLoc;OsaFsLoc;C:\WINDOWS\system32\drivers\OsaFsLoc.sys [2005-10-15 12106]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 7296]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 4010]
R3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys [2005-09-13 4392]

*Newly Created Service* - PROCEXP90
.
- - - - USUNIĘTO PUSTE WPISY - - - -

HKLM-Run-INPROCOMMWireless - C:\Program Files\Atheros\Wireless\Utility\WlanUtil.exe


.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\ŁUKASZ\Dane aplikacji\Mozilla\Firefox\Profiles\hzpeezoz.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.onet.pl
FF -: plugin - C:\Program Files\Opera\program\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-21 15:54:58
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

skanowanie ukrytych procesów ...

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ...

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************
.
Czas ukończenia: 2008-10-21 15:55:30
ComboFix-quarantined-files.txt  2008-10-21 13:55:28

Przed: 3 870 081 024 bajtów wolnych
Po: 3,872,899,072 bajtów wolnych

191   --- E O F ---   2008-10-21 11:44:43


SRENG

Kod: Zaznacz wszystko

2008-10-21,15:51:02

System Repair Engineer 2.7.0.1210
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Dodatek Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been selected:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Running Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File
    Process Privileges Scan
    Scheduled Tasks
    API HOOK
    Hidden Process


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <INPROCOMMWireless><C:\Program Files\Atheros\Wireless\Utility\WlanUtil.exe>  [File is missing]
    <egui><"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice>  [(Verified)"ESET, spol. s r.o."]
    <SunJavaUpdateSched><"C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe">  [(Verified)"Sun Microsystems, Inc."]
    <NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <AzMixerSel><C:\Program Files\Realtek\InstallShield\AzMixerSel.exe>  [Realtek Semiconductor Corp.]
    <RTHDCPL><RTHDCPL.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <Alcmtr><ALCMTR.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><nwiz.exe /install>  []
    <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <ADMTray.exe><"C:\Acer\Empowering Technology\admtray.exe">  [Avocent Inc.]
    <eDataSecurity Loader><C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe>  [HiTRUST]
    <ePower_DMC><C:\Acer\Empowering Technology\ePower\ePower_DMC.exe>  [Acer Incorporated]
    <Acer ePower Management><C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot>  [File is missing]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
    <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Windows Publisher]
    <SysTray><C:\WINDOWS\system32\stobject.dll>  [(Verified)Microsoft Windows Publisher]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    <Dostosowywanie przeglądarki><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <Książka adresowa 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Aktualizacja pulpitu Windows><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Publisher]

==================================
Startup Folders
N/A

==================================
Services
[Zarządzanie aplikacjami / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  <C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe><(File is missing)>
[AdminWorks Agent X6 / AWService][Running/Auto Start]
  <"C:\Acer\Empowering Technology\admServ.exe"><Avocent Inc.>
[Eset HTTP Server / EhttpSrv][Stopped/Manual Start]
  <"C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe"><ESET>
[Eset Service / ekrn][Running/Auto Start]
  <"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"><ESET>
[Dostęp do urządzeń interfejsu HID / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>

==================================
Drivers
[Atheros Wireless Network Adapter Service / AR5211][Running/Manual Start]
  <system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
[Broadcom NetXtreme Gigabit Ethernet / b57w2k][Running/Manual Start]
  <system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[eamon / eamon][Running/Auto Start]
  <system32\DRIVERS\eamon.sys><ESET>
[easdrv / easdrv][Running/System Start]
  <system32\DRIVERS\easdrv.sys><ESET>
[epfw / epfw][Running/Auto Start]
  <system32\DRIVERS\epfw.sys><ESET>
[Eset Personal Firewall / Epfwndis][Running/Manual Start]
  <system32\DRIVERS\Epfwndis.sys><ESET>
[epfwtdi / epfwtdi][Running/System Start]
  <system32\DRIVERS\epfwtdi.sys><ESET>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
  <system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
  <system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[OSA NdisFilter Protocol / NdisFilt][Running/Manual Start]
  <System32\Drivers\NdisFilt.sys><OSA Technologies>
[Acer NetMonitor Protocol / NETMNT][Stopped/Manual Start]
  <system32\DRIVERS\NETMNT.sys><N/A>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[OsaFsLoc / OsaFsLoc][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\OsaFsLoc.sys><OSA Technologies>
[osaio / osaio][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\osaio.sys><OSA Technologies, An Avocent Company>
[osanbm / osanbm][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\osanbm.sys><Windows (R) 2000 DDK provider>
[Sterownik bezpośredniego połączenia kablowego / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[rimmptsk / rimmptsk][Running/Auto Start]
  <system32\DRIVERS\rimmptsk.sys><REDC>
[rimsptsk / rimsptsk][Running/Auto Start]
  <system32\DRIVERS\rimsptsk.sys><REDC>
[Ricoh xD-Picture Card Driver / rismxdp][Running/Auto Start]
  <system32\DRIVERS\rixdptsk.sys><REDC>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
  <system32\DRIVERS\UIUSYS.SYS><N/A>
[winachsf / winachsf][Running/Manual Start]
  <system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>

==================================
Browser Add-ons
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_07]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, (Signed) Microsoft Corporation>
[Acer eDataSecurity Management]
  {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} <C:\WINDOWS\system32\eDStoolbar.dll, HiTRUST>
[Java Plug-in 1.6.0_07]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_07]
  {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_07]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll, (Signed) Sun Microsystems, Inc.>
[]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <, >
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[]
  {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} <, >
[]
  {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >

==================================
Running Processes
[PID: 604 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1096 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1128 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1172 / SYSTEM][C:\WINDOWS\system32\services.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 1184 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1344 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1412 / USŁUGA SIECIOWA][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1448 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1580 / USŁUGA SIECIOWA][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1616 / USŁUGA LOKALNA][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1932 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2040 / SYSTEM][C:\Acer\Empowering Technology\admServ.exe]  [Avocent Inc., 1.5.28.78]
    [C:\Acer\Empowering Technology\OsaFsLoc.dll]  [OSA Technologies Inc. Taiwan Branch, 2, 0, 0, 1]
    [C:\Acer\Empowering Technology\osaiodll.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 1, 2, 16]
    [C:\Acer\Empowering Technology\IpmiTrans.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 3, 14]
    [C:\Acer\Empowering Technology\SYSAPI.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 5, 17]
    [C:\Acer\Empowering Technology\SMBIOSAPI.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 6, 7]
    [C:\Acer\Empowering Technology\cpuid_dll.dll]  [ OSA Technologies, Inc., 1, 0, 6, 13]
    [C:\Acer\Empowering Technology\NBAPI.dll]  [Avocent Inc., 1, 0, 2, 3]
    [C:\Acer\Empowering Technology\NetMonitor.dll]  [N/A, ]
    [C:\Acer\Empowering Technology\s_lm85m.dll]  [OSA Technologies, An Avocent Company, 1, 2, 2, 5]
    [C:\Acer\Empowering Technology\s_smsc47m1.dll]  [OSA Technologies, An Avocent Company, 1, 2, 4, 9]
    [C:\Acer\Empowering Technology\s_it87.dll]  [OSA Technologies, An Avocent Company, 1, 2, 2, 3]
[PID: 160 / SYSTEM][C:\Program Files\ESET\ESET Smart Security\ekrn.exe]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnScan.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnAmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnEmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnEpfw.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnSmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnUpdate.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\updater.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnMailPlugins.dll]  [ESET, 3.0.669 ]
[PID: 324 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\nvapi.dll]  [NVIDIA Corporation, 6.14.11.7431]
[PID: 504 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 692 / ŁUKASZ][C:\WINDOWS\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\nvcpl.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\NVRSPL.DLL]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\nvapi.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\nvshell.dll]  [, ]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [D:\Programy\WinRAR\rarext.dll]  [N/A, ]
    [C:\WINDOWS\system32\eDSshellExt.dll]  [HiTRUST, 1, 20, 0, 0]
    [C:\WINDOWS\system32\ATL71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\ESET\ESET Smart Security\shellExt.dll]  [ESET, 3.0.669 ]
[PID: 1060 / ŁUKASZ][C:\Program Files\ESET\ESET Smart Security\egui.exe]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiScan.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiAmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiEmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiEpfw.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiSmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiUpdate.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiMailPlugins.dll]  [ESET, 3.0.669 ]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 1080 / ŁUKASZ][C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe]  [Sun Microsystems, Inc., 6.0.70.6]
[PID: 1368 / ŁUKASZ][C:\WINDOWS\RTHDCPL.EXE]  [Realtek Semiconductor Corp., 2.1.3.7]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 1716 / ŁUKASZ][C:\WINDOWS\system32\RUNDLL32.EXE]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\NvMcTray.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\nvapi.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\NVRSPL.DLL]  [NVIDIA Corporation, 6.14.11.7431]
[PID: 1724 / ŁUKASZ][C:\Acer\Empowering Technology\admtray.exe]  [Avocent Inc., 1.6.23.36]
    [C:\Acer\Empowering Technology\ServiceControl.dll]  [N/A, ]
    [C:\Acer\Empowering Technology\OsaFsLoc.dll]  [OSA Technologies Inc. Taiwan Branch, 2, 0, 0, 1]
    [C:\Acer\Empowering Technology\InstallNdis.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 1, 3]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 1736 / ŁUKASZ][C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe]  [HiTRUST, 1, 20, 0, 0]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 1752 / ŁUKASZ][C:\Acer\Empowering Technology\ePower\ePower_DMC.exe]  [Acer Incorporated, 0.62]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_bbd236fd\mscorlib.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_b74d2ee3\system.dll]  [N/A, ]
    [c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_eed92856\system.drawing.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\system32\NvCpl.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\NVRSPL.DLL]  [NVIDIA Corporation, 6.14.11.7431]
    [c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_9d7831eb\system.windows.forms.dll]  [N/A, ]
    [c:\acer\empowering technology\epower\classlib_notifyiconex.dll]  [ , 1.0.2110.23044]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [C:\Acer\Empowering Technology\ePower\DialogDLL.dll]  [, 1, 0, 0, 1]
[PID: 416 / USŁUGA LOKALNA][C:\WINDOWS\System32\alg.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2068 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2076 / ŁUKASZ][C:\DOCUME~1\UKASZ~1\USTAWI~1\Temp\RtkBtMnt.exe]  [Realtek Semiconductor Corp., 1.0.0.7]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 2172 / ŁUKASZ][C:\WINDOWS\system32\wbem\unsecapp.exe]  [(Verified) Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 2204 / USŁUGA SIECIOWA][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2684 / ŁUKASZ][C:\Program Files\Opera\opera.exe]  [Opera Software, 10081]
    [C:\Program Files\Opera\Opera.dll]  [Opera Software, 10081]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [C:\Program Files\Opera\Program\Plugins\NPSWF32.dll]  [, ]
[PID: 4092 / ŁUKASZ][C:\Documents and Settings\ŁUKASZ\Pulpit\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
[PID: 1228 / ŁUKASZ][C:\Documents and Settings\ŁUKASZ\Pulpit\sreng2\SREea081c86.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [C:\Documents and Settings\ŁUKASZ\Pulpit\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1       localhost

==================================
Process Privileges Scan
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2040, C:\ACER\EMPOWERING TECHNOLOGY\ADMSERV.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 1724, C:\ACER\EMPOWERING TECHNOLOGY\ADMTRAY.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 1736, C:\ACER\EMPOWERING TECHNOLOGY\EDATASECURITY\EDSLOADER.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 1752, C:\ACER\EMPOWERING TECHNOLOGY\EPOWER\EPOWER_DMC.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2076, C:\DOCUME~1\UKASZ~1\USTAWI~1\TEMP\RTKBTMNT.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2684, C:\PROGRAM FILES\OPERA\OPERA.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 4092, C:\DOCUMENTS AND SETTINGS\ŁUKASZ\PULPIT\SRENG2\SRENGLDR.EXE]

==================================
Scheduled Tasks
N/A

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================




@edit
Tapeta się pojawiła po zmianie na windowsowska,tamta z neta znikneła z własciwosci.Mimo to prosze sprzwdzic co to za ustrojstwo sie przypałetało
Mielcarek27
~user
 
Posty: 22
Dołączenie: 21 Wrz 2008, 18:05



Brak tapety na pulpicie

Postprzez djarta 21 Paź 2008, 16:09

ComboFix - czysto. :)

SRENG - są wpisy niepotrzebne. ;)

Uruchom System Repair Engineer zakładka System Repair >> Browser Add-ons >> odszukaj i usuń.
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}
{FB5F1910-F110-11D2-BB9E-00C04F795683}

Potem nowy log z SRENGa.

Wykonaj to co jest podane w tym temacie (jeśli wykonałeś/łaś to wcześniej to nie rób tego).

Usuń ręcznie folder C:\Qoobox,

Usuń instalkę ComboFix z dysku.

Wykonaj optymalizację autostartu

Przeczyść komputer ATF-Cleaner

Wyłącz i włącz przywracanie systemu na wszystkich dyskach.Instrukcja

Przeskanuj obszar mojego komputera http://www.kaspersky.pl/virusscanner.html (uruchom przez IE) Daj raport z niego na forum.

i tym:

FixIEDef.


=====================
K.
Pozdrawiam djarta. :)
djarta
~user
 
Posty: 684
Dołączenie: 31 Lip 2008, 10:49
Pochwały: 55



Brak tapety na pulpicie

Postprzez Mielcarek27 21 Paź 2008, 16:35

Wykonano zalecenia.To świezy system wiec wiele w autostarcie nie ma,wwdc porty pozamykane.Oto logi:
SRENG
Kod: Zaznacz wszystko

2008-10-21,16:15:57

System Repair Engineer 2.7.0.1210
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Dodatek Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been selected:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Running Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File
    Process Privileges Scan
    Scheduled Tasks
    API HOOK
    Hidden Process


Boot Items
Registry
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <egui><"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice>  [(Verified)"ESET, spol. s r.o."]
    <SunJavaUpdateSched><"C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe">  [(Verified)"Sun Microsystems, Inc."]
    <NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <AzMixerSel><C:\Program Files\Realtek\InstallShield\AzMixerSel.exe>  [Realtek Semiconductor Corp.]
    <RTHDCPL><RTHDCPL.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><nwiz.exe /install>  []
    <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <ADMTray.exe><"C:\Acer\Empowering Technology\admtray.exe">  [Avocent Inc.]
    <eDataSecurity Loader><C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe>  [HiTRUST]
    <ePower_DMC><C:\Acer\Empowering Technology\ePower\ePower_DMC.exe>  [Acer Incorporated]
    <Acer ePower Management><C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot>  [File is missing]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
    <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Windows Publisher]
    <SysTray><%systemroot%\system32\stobject.dll>  [(Verified)Microsoft Windows Publisher]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    <Dostosowywanie przeglądarki><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <Książka adresowa 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Aktualizacja pulpitu Windows><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Publisher]

==================================
Startup Folders
N/A

==================================
Services
[Zarządzanie aplikacjami / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  <C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe><(File is missing)>
[AdminWorks Agent X6 / AWService][Running/Auto Start]
  <"C:\Acer\Empowering Technology\admServ.exe"><Avocent Inc.>
[Eset HTTP Server / EhttpSrv][Stopped/Manual Start]
  <"C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe"><ESET>
[Eset Service / ekrn][Running/Auto Start]
  <"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"><ESET>
[Dostęp do urządzeń interfejsu HID / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>

==================================
Drivers
[Atheros Wireless Network Adapter Service / AR5211][Running/Manual Start]
  <system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
[Broadcom NetXtreme Gigabit Ethernet / b57w2k][Running/Manual Start]
  <system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[catchme / catchme][Stopped/Manual Start]
  <\??\C:\ComboFix\catchme.sys><N/A>
[eamon / eamon][Running/Auto Start]
  <system32\DRIVERS\eamon.sys><ESET>
[easdrv / easdrv][Running/System Start]
  <system32\DRIVERS\easdrv.sys><ESET>
[epfw / epfw][Running/Auto Start]
  <system32\DRIVERS\epfw.sys><ESET>
[Eset Personal Firewall / Epfwndis][Running/Manual Start]
  <system32\DRIVERS\Epfwndis.sys><ESET>
[epfwtdi / epfwtdi][Running/System Start]
  <system32\DRIVERS\epfwtdi.sys><ESET>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
  <system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
  <system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[OSA NdisFilter Protocol / NdisFilt][Running/Manual Start]
  <System32\Drivers\NdisFilt.sys><OSA Technologies>
[Acer NetMonitor Protocol / NETMNT][Stopped/Manual Start]
  <system32\DRIVERS\NETMNT.sys><N/A>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[OsaFsLoc / OsaFsLoc][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\OsaFsLoc.sys><OSA Technologies>
[osaio / osaio][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\osaio.sys><OSA Technologies, An Avocent Company>
[osanbm / osanbm][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\osanbm.sys><Windows (R) 2000 DDK provider>
[Sterownik bezpośredniego połączenia kablowego / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[rimmptsk / rimmptsk][Running/Auto Start]
  <system32\DRIVERS\rimmptsk.sys><REDC>
[rimsptsk / rimsptsk][Running/Auto Start]
  <system32\DRIVERS\rimsptsk.sys><REDC>
[Ricoh xD-Picture Card Driver / rismxdp][Running/Auto Start]
  <system32\DRIVERS\rixdptsk.sys><REDC>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
  <system32\DRIVERS\UIUSYS.SYS><N/A>
[winachsf / winachsf][Running/Manual Start]
  <system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>

==================================
Browser Add-ons
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Acer eDataSecurity Management]
  {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} <C:\WINDOWS\system32\eDStoolbar.dll, HiTRUST>
[Java Plug-in 1.6.0_07]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_07]
  {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_07]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll, (Signed) Sun Microsystems, Inc.>
[]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <, >
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[]
  {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >

==================================
Running Processes
[PID: 604 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1100 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1132 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1176 / SYSTEM][C:\WINDOWS\system32\services.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 1188 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1340 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1424 / USŁUGA SIECIOWA][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1456 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1592 / USŁUGA SIECIOWA][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1624 / USŁUGA LOKALNA][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1896 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2028 / SYSTEM][C:\Acer\Empowering Technology\admServ.exe]  [Avocent Inc., 1.5.28.78]
    [C:\Acer\Empowering Technology\OsaFsLoc.dll]  [OSA Technologies Inc. Taiwan Branch, 2, 0, 0, 1]
    [C:\Acer\Empowering Technology\osaiodll.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 1, 2, 16]
    [C:\Acer\Empowering Technology\IpmiTrans.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 3, 14]
    [C:\Acer\Empowering Technology\SYSAPI.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 5, 17]
    [C:\Acer\Empowering Technology\SMBIOSAPI.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 6, 7]
    [C:\Acer\Empowering Technology\cpuid_dll.dll]  [ OSA Technologies, Inc., 1, 0, 6, 13]
    [C:\Acer\Empowering Technology\NBAPI.dll]  [Avocent Inc., 1, 0, 2, 3]
    [C:\Acer\Empowering Technology\NetMonitor.dll]  [N/A, ]
    [C:\Acer\Empowering Technology\s_lm85m.dll]  [OSA Technologies, An Avocent Company, 1, 2, 2, 5]
    [C:\Acer\Empowering Technology\s_smsc47m1.dll]  [OSA Technologies, An Avocent Company, 1, 2, 4, 9]
    [C:\Acer\Empowering Technology\s_it87.dll]  [OSA Technologies, An Avocent Company, 1, 2, 2, 3]
[PID: 156 / SYSTEM][C:\Program Files\ESET\ESET Smart Security\ekrn.exe]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnScan.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnAmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnEmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnEpfw.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnSmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnUpdate.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\updater.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnMailPlugins.dll]  [ESET, 3.0.669 ]
[PID: 464 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\nvapi.dll]  [NVIDIA Corporation, 6.14.11.7431]
[PID: 496 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 288 / ŁUKASZ][C:\WINDOWS\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
[PID: 1520 / USŁUGA LOKALNA][C:\WINDOWS\System32\alg.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1696 / ŁUKASZ][C:\Program Files\ESET\ESET Smart Security\egui.exe]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiScan.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiAmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiEmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiEpfw.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiSmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiUpdate.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiMailPlugins.dll]  [ESET, 3.0.669 ]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 260 / ŁUKASZ][C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe]  [Sun Microsystems, Inc., 6.0.70.6]
[PID: 1552 / ŁUKASZ][C:\WINDOWS\RTHDCPL.EXE]  [Realtek Semiconductor Corp., 2.1.3.7]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 660 / ŁUKASZ][C:\WINDOWS\system32\RUNDLL32.EXE]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\NvMcTray.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\nvapi.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\NVRSPL.DLL]  [NVIDIA Corporation, 6.14.11.7431]
[PID: 668 / ŁUKASZ][C:\Acer\Empowering Technology\admtray.exe]  [Avocent Inc., 1.6.23.36]
    [C:\Acer\Empowering Technology\ServiceControl.dll]  [N/A, ]
    [C:\Acer\Empowering Technology\OsaFsLoc.dll]  [OSA Technologies Inc. Taiwan Branch, 2, 0, 0, 1]
    [C:\Acer\Empowering Technology\InstallNdis.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 1, 3]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 680 / ŁUKASZ][C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe]  [HiTRUST, 1, 20, 0, 0]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 492 / ŁUKASZ][C:\Acer\Empowering Technology\ePower\ePower_DMC.exe]  [Acer Incorporated, 0.62]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_bbd236fd\mscorlib.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_b74d2ee3\system.dll]  [N/A, ]
    [c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_eed92856\system.drawing.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\system32\NvCpl.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\NVRSPL.DLL]  [NVIDIA Corporation, 6.14.11.7431]
    [c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_9d7831eb\system.windows.forms.dll]  [N/A, ]
    [c:\acer\empowering technology\epower\classlib_notifyiconex.dll]  [ , 1.0.2110.23044]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [C:\Acer\Empowering Technology\ePower\DialogDLL.dll]  [, 1, 0, 0, 1]
[PID: 868 / ŁUKASZ][C:\DOCUME~1\UKASZ~1\USTAWI~1\Temp\RtkBtMnt.exe]  [Realtek Semiconductor Corp., 1.0.0.7]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 932 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 996 / ŁUKASZ][C:\WINDOWS\system32\wbem\unsecapp.exe]  [(Verified) Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 1936 / USŁUGA SIECIOWA][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2056 / ŁUKASZ][C:\Program Files\Opera\opera.exe]  [Opera Software, 10081]
    [C:\Program Files\Opera\Opera.dll]  [Opera Software, 10081]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [C:\Program Files\Opera\Program\Plugins\NPSWF32.dll]  [, ]
[PID: 2460 / SYSTEM][C:\WINDOWS\system32\wuauclt.exe]  [(Verified) Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)]
[PID: 320 / ŁUKASZ][C:\Documents and Settings\ŁUKASZ\Pulpit\DIAGNOSTYKA-NIE UZYWAĆ!!!!!!!!\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
[PID: 2700 / ŁUKASZ][C:\Documents and Settings\ŁUKASZ\Pulpit\DIAGNOSTYKA-NIE UZYWAĆ!!!!!!!!\sreng2\SREea081c86.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [C:\Documents and Settings\ŁUKASZ\Pulpit\DIAGNOSTYKA-NIE UZYWAĆ!!!!!!!!\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1       localhost

==================================
Process Privileges Scan
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2028, C:\ACER\EMPOWERING TECHNOLOGY\ADMSERV.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 668, C:\ACER\EMPOWERING TECHNOLOGY\ADMTRAY.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 680, C:\ACER\EMPOWERING TECHNOLOGY\EDATASECURITY\EDSLOADER.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 492, C:\ACER\EMPOWERING TECHNOLOGY\EPOWER\EPOWER_DMC.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 868, C:\DOCUME~1\UKASZ~1\USTAWI~1\TEMP\RTKBTMNT.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2056, C:\PROGRAM FILES\OPERA\OPERA.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 320, C:\DOCUMENTS AND SETTINGS\ŁUKASZ\PULPIT\DIAGNOSTYKA-NIE UZYWAĆ!!!!!!!!\SRENG2\SRENGLDR.EXE]

==================================
Scheduled Tasks
N/A

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================




FixIEDef

Kod: Zaznacz wszystko
********************************************************************************
*                                                                              *
*                                 FixIEDef Log                                 *
*                              Version 1.6.10.6697                             *
*                                                                              *
********************************************************************************

Created at 16:20:42 on Tuesday, October 21, 2008

Time Zone            :

Logged On User       : ŁUKASZ

Operating System     : Microsoft Windows XP Home Edition Dodatek Service Pack 2
OS Version           : 5.1.2600
System Langauge      : Polish
Keyboard Layout      : Polish
Processor            : X86 Intel(R) Pentium(R) Dual  CPU  T2310  @ 1.46GHz

System Drive         : C:\
Windows Directory    : C:\WINDOWS
System Directory     : C:\WINDOWS\system32

System Drive Type    : Fixed
System Drive Status  : READY
System Drive Label   : WINDOWS
System Drive Size    : 10 GB
System Drive Free    : 3.73 GB

Total Physical Memory: 1022 MB
Free Physical Memory : 681 MB
Total Page File      : 1022 MB
Free Page File       : 2216 MB
Total Virtual Memory : 2048 MB
Free Virtual Memory  : 1968 MB

Boot State           : Normal boot

--------------------------------------------------------------------------------

!!! Files that have been deleted !!!

No malicious files found

--------------------------------------------------------------------------------

!!! Directories that have been removed !!!

No malicious directories to be removed

--------------------------------------------------------------------------------

!!! Registry entries that have been removed !!!

No malicious Registry entries found

================================================================================

All Done :)

ShadowPuterDude

Safe Surfing!!!

Kasprzak jeszcze pobiera jakies aktualizacje baz danych (dopiero 33%).Mysle że to potrwa troche :/
Mielcarek27
~user
 
Posty: 22
Dołączenie: 21 Wrz 2008, 18:05



Brak tapety na pulpicie

Postprzez djarta 21 Paź 2008, 16:41

Uruchom System Repair Engineer zakładka System Repair >> Browser Add-ons >> odszukaj i usuń.
{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}
{FB5F1910-F110-11D2-BB9E-00C04F795683}


FixIEDef - nic nie wykrył. ;)


===============
K.

Autor postu otrzymał pochwałę
Pozdrawiam djarta. :)
djarta
~user
 
Posty: 684
Dołączenie: 31 Lip 2008, 10:49
Pochwały: 55



Brak tapety na pulpicie

Postprzez Mielcarek27 21 Paź 2008, 16:46

Pierwszego wpisu -> {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} nie było
nowy log:
SRENG
Kod: Zaznacz wszystko

2008-10-21,16:44:43

System Repair Engineer 2.7.0.1210
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Dodatek Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been selected:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Running Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File
    Process Privileges Scan
    Scheduled Tasks
    API HOOK
    Hidden Process


Boot Items
Registry
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <egui><"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice>  [(Verified)"ESET, spol. s r.o."]
    <SunJavaUpdateSched><"C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe">  [(Verified)"Sun Microsystems, Inc."]
    <NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe>  [Ahead Software Gmbh]
    <AzMixerSel><C:\Program Files\Realtek\InstallShield\AzMixerSel.exe>  [Realtek Semiconductor Corp.]
    <RTHDCPL><RTHDCPL.EXE>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <nwiz><nwiz.exe /install>  []
    <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit>  [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <ADMTray.exe><"C:\Acer\Empowering Technology\admtray.exe">  [Avocent Inc.]
    <eDataSecurity Loader><C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe>  [HiTRUST]
    <ePower_DMC><C:\Acer\Empowering Technology\ePower\ePower_DMC.exe>  [Acer Incorporated]
    <Acer ePower Management><C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot>  [File is missing]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Publisher]
    <WebCheck><%SystemRoot%\system32\webcheck.dll>  [(Verified)Microsoft Windows Publisher]
    <SysTray><%systemroot%\system32\stobject.dll>  [(Verified)Microsoft Windows Publisher]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Microsoft Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
    <Dostosowywanie przeglądarki><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <Książka adresowa 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Aktualizacja pulpitu Windows><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer 6><%SystemRoot%\system32\ie4uinit.exe>  [(Verified)Microsoft Windows Publisher]

==================================
Startup Folders
N/A

==================================
Services
[Zarządzanie aplikacjami / AppMgmt][Stopped/Manual Start]
  <C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  <C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe><(File is missing)>
[AdminWorks Agent X6 / AWService][Running/Auto Start]
  <"C:\Acer\Empowering Technology\admServ.exe"><Avocent Inc.>
[Eset HTTP Server / EhttpSrv][Stopped/Manual Start]
  <"C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe"><ESET>
[Eset Service / ekrn][Running/Auto Start]
  <"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"><ESET>
[Dostęp do urządzeń interfejsu HID / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[NVIDIA Display Driver Service / NVSvc][Running/Auto Start]
  <C:\WINDOWS\system32\nvsvc32.exe><NVIDIA Corporation>

==================================
Drivers
[Atheros Wireless Network Adapter Service / AR5211][Running/Manual Start]
  <system32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
[Broadcom NetXtreme Gigabit Ethernet / b57w2k][Running/Manual Start]
  <system32\DRIVERS\b57xp32.sys><Broadcom Corporation>
[catchme / catchme][Stopped/Manual Start]
  <\??\C:\ComboFix\catchme.sys><N/A>
[eamon / eamon][Running/Auto Start]
  <system32\DRIVERS\eamon.sys><ESET>
[easdrv / easdrv][Running/System Start]
  <system32\DRIVERS\easdrv.sys><ESET>
[epfw / epfw][Running/Auto Start]
  <system32\DRIVERS\epfw.sys><ESET>
[Eset Personal Firewall / Epfwndis][Running/Manual Start]
  <system32\DRIVERS\Epfwndis.sys><ESET>
[epfwtdi / epfwtdi][Running/System Start]
  <system32\DRIVERS\epfwtdi.sys><ESET>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
  <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSFHWAZL / HSFHWAZL][Running/Manual Start]
  <system32\DRIVERS\HSFHWAZL.sys><Conexant Systems, Inc.>
[HSF_DPV / HSF_DPV][Running/Manual Start]
  <system32\DRIVERS\HSF_DPV.sys><Conexant Systems, Inc.>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
  <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[mdmxsdk / mdmxsdk][Running/Auto Start]
  <system32\DRIVERS\mdmxsdk.sys><Conexant>
[OSA NdisFilter Protocol / NdisFilt][Running/Manual Start]
  <System32\Drivers\NdisFilt.sys><OSA Technologies>
[Acer NetMonitor Protocol / NETMNT][Stopped/Manual Start]
  <system32\DRIVERS\NETMNT.sys><N/A>
[nv / nv][Running/Manual Start]
  <system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[OsaFsLoc / OsaFsLoc][Running/System Start]
  <\??\C:\WINDOWS\system32\drivers\OsaFsLoc.sys><OSA Technologies>
[osaio / osaio][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\osaio.sys><OSA Technologies, An Avocent Company>
[osanbm / osanbm][Running/Auto Start]
  <\??\C:\WINDOWS\system32\drivers\osanbm.sys><Windows (R) 2000 DDK provider>
[Sterownik bezpośredniego połączenia kablowego / Ptilink][Running/Manual Start]
  <system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[rimmptsk / rimmptsk][Running/Auto Start]
  <system32\DRIVERS\rimmptsk.sys><REDC>
[rimsptsk / rimsptsk][Running/Auto Start]
  <system32\DRIVERS\rimsptsk.sys><REDC>
[Ricoh xD-Picture Card Driver / rismxdp][Running/Auto Start]
  <system32\DRIVERS\rixdptsk.sys><REDC>
[Secdrv / Secdrv][Stopped/Manual Start]
  <system32\DRIVERS\secdrv.sys><N/A>
[Conexant Setup API / UIUSys][Stopped/Manual Start]
  <system32\DRIVERS\UIUSYS.SYS><N/A>
[winachsf / winachsf][Running/Manual Start]
  <system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>

==================================
Browser Add-ons
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Acer eDataSecurity Management]
  {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} <C:\WINDOWS\system32\eDStoolbar.dll, HiTRUST>
[CKAVWebScan Object]
  {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} <C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll, Kaspersky Lab>
[Java Plug-in 1.6.0_07]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_07]
  {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_07]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll, (Signed) Sun Microsystems, Inc.>
[]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <, >
[CKAVWebScan Object]
  {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} <C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll, Kaspersky Lab>
[Acer eDataSecurity Management]
  {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} <C:\WINDOWS\system32\eDStoolbar.dll, HiTRUST>
[CKAVReportCtrl Object]
  {6117669B-8C2D-41FA-A6D9-9E484B999CF0} <C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll, Kaspersky Lab>
[SSVHelper Class]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll, (Signed) Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash6.ocx, (Signed) Macromedia, Inc.>

==================================
Running Processes
[PID: 604 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1100 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1132 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1176 / SYSTEM][C:\WINDOWS\system32\services.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\AppPatch\AcAdProc.dll]  [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 1188 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1340 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1424 / USŁUGA SIECIOWA][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1456 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1592 / USŁUGA SIECIOWA][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1624 / USŁUGA LOKALNA][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1896 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2028 / SYSTEM][C:\Acer\Empowering Technology\admServ.exe]  [Avocent Inc., 1.5.28.78]
    [C:\Acer\Empowering Technology\OsaFsLoc.dll]  [OSA Technologies Inc. Taiwan Branch, 2, 0, 0, 1]
    [C:\Acer\Empowering Technology\osaiodll.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 1, 2, 16]
    [C:\Acer\Empowering Technology\IpmiTrans.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 3, 14]
    [C:\Acer\Empowering Technology\SYSAPI.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 5, 17]
    [C:\Acer\Empowering Technology\SMBIOSAPI.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 6, 7]
    [C:\Acer\Empowering Technology\cpuid_dll.dll]  [ OSA Technologies, Inc., 1, 0, 6, 13]
    [C:\Acer\Empowering Technology\NBAPI.dll]  [Avocent Inc., 1, 0, 2, 3]
    [C:\Acer\Empowering Technology\NetMonitor.dll]  [N/A, ]
    [C:\Acer\Empowering Technology\s_lm85m.dll]  [OSA Technologies, An Avocent Company, 1, 2, 2, 5]
    [C:\Acer\Empowering Technology\s_smsc47m1.dll]  [OSA Technologies, An Avocent Company, 1, 2, 4, 9]
    [C:\Acer\Empowering Technology\s_it87.dll]  [OSA Technologies, An Avocent Company, 1, 2, 2, 3]
[PID: 156 / SYSTEM][C:\Program Files\ESET\ESET Smart Security\ekrn.exe]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnScan.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnAmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnEmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnEpfw.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnSmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnUpdate.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\updater.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnMailPlugins.dll]  [ESET, 3.0.669 ]
[PID: 464 / SYSTEM][C:\WINDOWS\system32\nvsvc32.exe]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\nvapi.dll]  [NVIDIA Corporation, 6.14.11.7431]
[PID: 496 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1520 / USŁUGA LOKALNA][C:\WINDOWS\System32\alg.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1696 / ŁUKASZ][C:\Program Files\ESET\ESET Smart Security\egui.exe]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiScan.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiAmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiEmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiEpfw.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiSmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiUpdate.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiMailPlugins.dll]  [ESET, 3.0.669 ]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 260 / ŁUKASZ][C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe]  [Sun Microsystems, Inc., 6.0.70.6]
[PID: 1552 / ŁUKASZ][C:\WINDOWS\RTHDCPL.EXE]  [Realtek Semiconductor Corp., 2.1.3.7]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 660 / ŁUKASZ][C:\WINDOWS\system32\RUNDLL32.EXE]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\NvMcTray.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\nvapi.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\NVRSPL.DLL]  [NVIDIA Corporation, 6.14.11.7431]
[PID: 668 / ŁUKASZ][C:\Acer\Empowering Technology\admtray.exe]  [Avocent Inc., 1.6.23.36]
    [C:\Acer\Empowering Technology\ServiceControl.dll]  [N/A, ]
    [C:\Acer\Empowering Technology\OsaFsLoc.dll]  [OSA Technologies Inc. Taiwan Branch, 2, 0, 0, 1]
    [C:\Acer\Empowering Technology\InstallNdis.dll]  [OSA Technologies Inc. Taiwan Branch, 1, 0, 1, 3]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 680 / ŁUKASZ][C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe]  [HiTRUST, 1, 20, 0, 0]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 492 / ŁUKASZ][C:\Acer\Empowering Technology\ePower\ePower_DMC.exe]  [Acer Incorporated, 0.62]
    [C:\WINDOWS\system32\mscoree.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\microsoft.net\framework\v1.1.4322\mscorlib.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_bbd236fd\mscorlib.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_b74d2ee3\system.dll]  [N/A, ]
    [c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_eed92856\system.drawing.dll]  [N/A, ]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MSCORJIT.DLL]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\system32\NvCpl.dll]  [NVIDIA Corporation, 6.14.11.7431]
    [C:\WINDOWS\system32\NVRSPL.DLL]  [NVIDIA Corporation, 6.14.11.7431]
    [c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll]  [Microsoft Corporation, 1.1.4322.573]
    [c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_9d7831eb\system.windows.forms.dll]  [N/A, ]
    [c:\acer\empowering technology\epower\classlib_notifyiconex.dll]  [ , 1.0.2110.23044]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [C:\Acer\Empowering Technology\ePower\DialogDLL.dll]  [, 1, 0, 0, 1]
[PID: 868 / ŁUKASZ][C:\DOCUME~1\UKASZ~1\USTAWI~1\Temp\RtkBtMnt.exe]  [Realtek Semiconductor Corp., 1.0.0.7]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 932 / SYSTEM][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 996 / ŁUKASZ][C:\WINDOWS\system32\wbem\unsecapp.exe]  [(Verified) Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
[PID: 1936 / USŁUGA SIECIOWA][C:\WINDOWS\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 264 / ŁUKASZ][C:\WINDOWS\explorer.exe]  [(Verified) Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [D:\Programy\WinRAR\rarext.dll]  [N/A, ]
[PID: 676 / ŁUKASZ][C:\Program Files\Opera\opera.exe]  [Opera Software, 10081]
    [C:\Program Files\Opera\Opera.dll]  [Opera Software, 10081]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [C:\Program Files\Opera\Program\Plugins\NPSWF32.dll]  [, ]
    [C:\Program Files\Java\jre1.6.0_07\bin\client\jvm.dll]  [Sun Microsystems, Inc., 10.0.0.23]
    [C:\Program Files\Java\jre1.6.0_07\bin\hpi.dll]  [Sun Microsystems, Inc., 6.0.70.6]
    [C:\Program Files\Java\jre1.6.0_07\bin\verify.dll]  [Sun Microsystems, Inc., 6.0.70.6]
    [C:\Program Files\Java\jre1.6.0_07\bin\java.dll]  [Sun Microsystems, Inc., 6.0.70.6]
    [C:\Program Files\Java\jre1.6.0_07\bin\zip.dll]  [Sun Microsystems, Inc., 6.0.70.6]
    [C:\Program Files\Java\jre1.6.0_07\bin\awt.dll]  [Sun Microsystems, Inc., 6.0.70.6]
    [C:\Program Files\Java\jre1.6.0_07\bin\fontmanager.dll]  [Sun Microsystems, Inc., 6.0.70.6]
    [C:\WINDOWS\system32\msdmo.dll]  [, ]
    [C:\WINDOWS\system32\ac3filter.ax]  [, 1.01a]
    [C:\WINDOWS\system32\DVobSub.ax]  [Gabest, 1, 0, 0, 9]
[PID: 2676 / ŁUKASZ][C:\Program Files\internet explorer\iexplore.exe]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll]  [Sun Microsystems, Inc., 6.0.70.6]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [C:\WINDOWS\system32\Macromed\Flash\Flash6.ocx]  [Macromedia, Inc., 6,0,88,0]
    [C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll]  [Kaspersky Lab, 5.0.98.1]
    [C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll]  [Kaspersky Lab., 4, 0, 2, 28]
[PID: 3776 / ŁUKASZ][C:\Documents and Settings\ŁUKASZ\Pulpit\DIAGNOSTYKA-NIE UZYWAĆ!!!!!!!!\sreng2\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
[PID: 2476 / ŁUKASZ][C:\Documents and Settings\ŁUKASZ\Pulpit\DIAGNOSTYKA-NIE UZYWAĆ!!!!!!!!\sreng2\SREea081c86.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\WINDOWS\system32\MSNChatHook.dll]  [, 1, 0, 0, 1]
    [C:\WINDOWS\system32\sysenv.dll]  [HiTRUST, 1, 20, 0, 1]
    [C:\WINDOWS\system32\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\WINDOWS\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Acer\Empowering Technology\ePower\SysHook.dll]  [, 0, 9, 7, 3]
    [C:\Documents and Settings\ŁUKASZ\Pulpit\DIAGNOSTYKA-NIE UZYWAĆ!!!!!!!!\sreng2\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1       localhost

==================================
Process Privileges Scan
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2028, C:\ACER\EMPOWERING TECHNOLOGY\ADMSERV.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 668, C:\ACER\EMPOWERING TECHNOLOGY\ADMTRAY.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 680, C:\ACER\EMPOWERING TECHNOLOGY\EDATASECURITY\EDSLOADER.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 492, C:\ACER\EMPOWERING TECHNOLOGY\EPOWER\EPOWER_DMC.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 868, C:\DOCUME~1\UKASZ~1\USTAWI~1\TEMP\RTKBTMNT.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 676, C:\PROGRAM FILES\OPERA\OPERA.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 3776, C:\DOCUMENTS AND SETTINGS\ŁUKASZ\PULPIT\DIAGNOSTYKA-NIE UZYWAĆ!!!!!!!!\SRENG2\SRENGLDR.EXE]

==================================
Scheduled Tasks
N/A

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================


Mielcarek27
~user
 
Posty: 22
Dołączenie: 21 Wrz 2008, 18:05




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 30 gości