
- Kod: Zaznacz wszystko
ComboFix 08-11-27.03 - Martini 2008-11-27 20:47:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.546 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Martini\Ustawienia lokalne\Dane aplikacji\Opera\Opera\profile\cache4\temporary_download\ComboFix.exe
* Utworzono nowy punkt przywracania
[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr1.dat
C:\resycled
c:\resycled\boot.com
c:\windows\system32\aacbmgkn.ini
c:\windows\system32\ahnwuhuo.dll
c:\windows\system32\autorun.ini
c:\windows\system32\awtqnkhe.dll
c:\windows\system32\awtuuTki.dll
c:\windows\system32\byXQGvuR.dll
c:\windows\system32\cbXNHAtt.dll
c:\windows\system32\cbXnopQj.dll
c:\windows\system32\cbXRLdcY.dll
c:\windows\system32\ddcDTjjG.dll
c:\windows\system32\ddcYrPhh.dll
c:\windows\system32\Desktop_.ini
c:\windows\system32\geBrrrqq.dll
c:\windows\system32\gmhpwfon.ini
c:\windows\system32\hgGvuVmK.dll
c:\windows\system32\hgGWoNGy.dll
c:\windows\system32\hgGyXqoo.dll
c:\windows\system32\iifcbyYO.dll
c:\windows\system32\ikTuutwa.ini
c:\windows\system32\ikTuutwa.ini2
c:\windows\system32\iqpdibws.dll
c:\windows\system32\jkkIYsTk.dll
c:\windows\system32\jkkllJYS.dll
c:\windows\system32\khfFwXPH.dll
c:\windows\system32\mlJBRHxu.dll
c:\windows\system32\nofwphmg.dll
c:\windows\system32\opnopQgg.dll
c:\windows\system32\osldgm.dll
c:\windows\system32\pmnkLEXO.dll
c:\windows\system32\pmnnNhIB.dll
c:\windows\system32\qoMeDSLf.dll
c:\windows\system32\sovhay.dll
c:\windows\system32\tuvSmnoP.dll
c:\windows\system32\urqNGVMc.dll
c:\windows\system32\urqOeDvu.dll
c:\windows\system32\urqQhhIY.dll
c:\windows\system32\urqQjhIb.dll
c:\windows\system32\vtUlIXPf.dll
c:\windows\system32\vtUoNDsQ.dll
c:\windows\system32\xxyAPgde.dll
c:\windows\system32\yayyARLD.dll
c:\windows\Tasks\myvnskwn.job
D:\resycled
d:\resycled\boot.com
----- BITS: Możliwe zainfekowane strony -----
hxxp://childhe.com
.
((((((((((((((((((((((((( Pliki utworzone od 2008-10-27 do 2008-11-27 )))))))))))))))))))))))))))))))
.
2008-11-27 20:37 . 2008-11-27 20:37 <DIR> d-------- c:\program files\Trend Micro
2008-11-22 17:53 . 2008-03-16 14:47 872,192 --a------ c:\windows\system32\drivers\mod7700.sys
2008-11-22 17:53 . 2008-03-17 11:56 103,168 --a------ c:\windows\system32\drivers\ewusbfake.sys
2008-11-22 17:53 . 2008-03-17 11:03 101,376 -ra------ c:\windows\system32\drivers\ewusbmdm.sys
2008-11-22 17:53 . 2008-01-22 15:09 100,992 --a------ c:\windows\system32\drivers\ewusbnet.sys
2008-11-22 17:53 . 2007-08-09 04:13 24,448 -ra------ c:\windows\system32\drivers\ewdcsc.sys
2008-11-19 18:20 . 2008-11-19 18:20 138,184 --a------ c:\windows\system32\drivers\PnkBstrK.sys
2008-11-19 18:20 . 2008-10-22 05:27 63,040 --a------ c:\windows\system32\PnkBstrA.exe
2008-11-19 18:19 . 2008-11-19 18:16 183,112 --a------ c:\windows\system32\PnkBstrB.exe
2008-11-19 18:12 . 2008-11-19 18:12 1,680 --a------ c:\windows\system32\ealregsnapshot1.reg
2008-11-19 18:11 . 2008-11-19 18:11 <DIR> d-------- c:\documents and settings\Martini\Dane aplikacji\Leadertech
2008-11-19 18:10 . 2008-11-19 18:10 <DIR> d-------- c:\windows\system32\LogFiles
2008-11-19 01:13 . 2008-11-19 01:52 <DIR> d-------- c:\documents and settings\Martini\.scorched3d
2008-11-18 23:00 . 2008-11-18 23:00 <DIR> d-------- c:\documents and settings\Martini\Dane aplikacji\teamspeak2
2008-11-18 22:49 . 2008-11-27 17:29 <DIR> d-------- c:\program files\Teamspeak2_RC2
2008-11-18 22:49 . 2008-11-18 22:49 34,064 --a------ c:\windows\system32\lhacm.acm
2008-11-16 10:23 . 2008-11-16 10:23 484 --a------ c:\windows\eReg.dat
2008-11-16 08:56 . 1998-10-07 12:54 327,168 --a------ c:\windows\IsUn0415.exe
2008-11-14 15:48 . 2008-11-14 15:48 <DIR> d-------- c:\documents and settings\Martini\Dane aplikacji\ArcSoft
2008-11-14 15:22 . 2008-04-14 21:51 221,184 --a------ c:\windows\system32\wmpns.dll
2008-11-14 15:20 . 2008-11-14 15:22 <DIR> d-------- c:\program files\Common Files\ArcSoft
2008-11-14 15:20 . 2008-11-14 15:20 <DIR> d-------- c:\program files\ArcSoft
2008-11-14 15:20 . 2006-01-24 10:20 1,645,320 --a------ c:\windows\system32\GdiPlus.dll
2008-11-14 15:20 . 2005-06-21 10:29 245,408 --a------ c:\windows\system32\unicows.dll
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-27 15:49 --------- d-----w c:\documents and settings\Martini\Dane aplikacji\IGN_DLM
2008-11-26 19:50 --------- d-----w c:\documents and settings\Martini\Dane aplikacji\Skype
2008-11-26 18:15 --------- d-----w c:\documents and settings\Martini\Dane aplikacji\skypePM
2008-11-25 15:25 --------- d-----w c:\program files\Money Manager Ex
2008-11-19 20:48 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-19 17:11 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-15 17:15 --------- d-----w c:\documents and settings\Martini\Dane aplikacji\Winamp
2008-11-14 14:44 --------- d-----w c:\program files\Common Files\Adobe
2008-11-12 19:24 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2008-11-03 05:08 --------- d-----w c:\program files\Opera
2008-10-28 06:19 --------- d-----w c:\program files\Gadu-Gadu
2008-10-27 18:50 2,516 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-10-23 17:05 --------- d-----w c:\program files\FDRLab
2008-10-22 04:21 --------- d-----w c:\program files\Java
2008-10-21 21:14 --------- d-----w c:\program files\ePortfel
2008-10-21 15:11 --------- d-----w c:\program files\Common Files\Java
2008-10-19 17:32 --------- d-----w c:\documents and settings\Martini\Dane aplikacji\Media Player Classic
2008-10-18 08:16 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\comodo
2008-10-18 07:47 87,056 ----a-w c:\windows\system32\drivers\cmdguard.sys
2008-10-18 07:47 24,208 ----a-w c:\windows\system32\drivers\cmdhlp.sys
2008-10-18 07:47 143,104 ----a-w c:\windows\system32\guard32.dll
2008-10-18 07:47 --------- d-----w c:\program files\Comodo
2008-10-18 07:47 --------- d-----w c:\documents and settings\Martini\Dane aplikacji\Comodo
2008-10-15 20:25 --------- d-----w c:\program files\FLV Player
2008-10-15 19:23 --------- d-----w c:\program files\ABC Lock
2008-10-15 18:51 --------- d-----w c:\program files\Folder Hider 2.0
2008-10-13 19:19 --------- d-----w c:\documents and settings\Martini\Dane aplikacji\U3
2008-10-13 16:27 --------- d-----w c:\program files\Kalendarz XP
2008-10-11 22:32 --------- d-----w c:\program files\Corel Paint Shop Pro Photo X2
2008-10-11 22:32 --------- d-----w c:\documents and settings\Martini\Dane aplikacji\Corel
2008-10-11 22:32 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Corel
2008-10-11 22:31 --------- d-----w c:\program files\Common Files\Corel
2008-10-09 19:35 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-07 10:33 --------- d-----w c:\program files\7-Zip
2008-10-06 05:43 --------- d-----w c:\program files\Common Files\INCA Shared
2008-10-05 22:20 --------- d-----w c:\program files\Download Manager
2008-10-05 21:19 278,984 ----a-w c:\windows\system32\drivers\atksgt.sys
2008-10-05 21:19 25,416 ----a-w c:\windows\system32\drivers\lirsgt.sys
2008-10-05 21:16 --------- d-----w c:\program files\WIDCOMM
2008-10-05 14:27 --------- d-----w c:\program files\Launch Manager
2008-10-05 11:24 --------- d-----w c:\program files\MSBuild
2008-10-05 11:24 --------- d-----w c:\program files\Microsoft Works
2008-10-05 11:22 --------- d-----w c:\program files\Microsoft.NET
2008-10-05 11:16 --------- d-----w c:\program files\Microsoft Visual Studio 8
2008-10-05 08:55 --------- d-----w c:\program files\Common Files\Ahead
2008-10-05 08:55 --------- d-----w c:\program files\Ahead
2008-10-04 21:03 --------- d-----w c:\program files\DAEMON Tools Lite
2008-10-04 21:00 716,272 ----a-w c:\windows\system32\drivers\sptd.sys
2008-10-04 21:00 --------- d-----w c:\documents and settings\Martini\Dane aplikacji\DAEMON Tools
2008-10-04 20:52 --------- d-----w c:\program files\Winamp
2008-10-04 20:31 --------- d-----w c:\documents and settings\Martini\Dane aplikacji\Gadu-Gadu
2008-10-04 20:15 32 ----a-w c:\documents and settings\All Users\Dane aplikacji\ezsid.dat
2008-10-04 20:14 --------- d-----w c:\program files\Skype
2008-10-04 20:14 --------- d-----w c:\program files\Common Files\Skype
2008-10-04 20:14 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Skype
2008-10-04 20:13 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-10-04 20:13 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-10-04 20:13 --------- d-----w c:\program files\Common Files\xing shared
2008-10-04 20:13 --------- d-----w c:\program files\Common Files\Real
2008-10-04 20:11 --------- d-----w c:\program files\K-Lite Codec Pack
2008-10-04 20:10 --------- d-----w c:\program files\ALLPlayer
2008-09-28 13:02 --------- d-----w c:\program files\Kaspersky Lab
2008-09-28 13:01 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-09-28 12:41 --------- d-----w c:\program files\Acer Inc
2008-09-28 12:32 --------- d-----w c:\program files\Broadcom
2008-09-28 12:32 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Broadcom
2008-09-25 18:54 315,392 ----a-w c:\windows\HideWin.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Kalendarz XP.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Kalendarz XP.lnk
backup=c:\windows\pss\Kalendarz XP.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^TeamSpeak 2 Server.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\TeamSpeak 2 Server.lnk
backup=c:\windows\pss\TeamSpeak 2 Server.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
--a------ 2007-07-17 13:05 64000 c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
-r-hs---- 2008-11-17 15:38 73216 c:\recycler\S-1-5-21-0242434524-7652987055-424476126-0140\hdav.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]
--a------ 2008-10-18 08:47 1655552 c:\program files\Comodo\Firewall\cfp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-14 21:51 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-02-14 00:09 486856 c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
--a------ 2006-10-26 18:48 434528 c:\progra~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
--a------ 2008-03-20 11:04 2127296 c:\program files\Gadu-Gadu\gg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
-ra------ 2007-06-13 05:55 162584 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
--a------ 2007-06-13 13:21 850704 c:\progra~1\LAUNCH~1\LManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
-ra------ 2007-06-13 05:55 138008 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2005-12-16 09:32 761945 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-04 21:13 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinGuard Pro]
--a------ 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 11:43 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"d:\\Gry\\Scorched3D\\scorcheds.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2008-10-18 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2008-10-18 24208]
S3 flash;flash;\??\c:\windows\system32\drivers\flash.sys [2008-09-28 8064]
S3 npkycryp;npkycryp;\??\d:\gry\Lineage II\system\npkycryp.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{221421e4-b879-11dd-9e45-001e334d5232}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2e74bc2c-a698-11dd-9e30-001e334d5232}]
\Shell\AutoRun\command - F:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59105f61-a061-11dd-9e20-001e334d5232}]
\Shell\AutoRun\command - xyw9tmdj.com
\Shell\explore\Command - xyw9tmdj.com
\Shell\open\Command - xyw9tmdj.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{af2d0e63-a1ba-11dd-9e24-001e334d5232}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL explore.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6de506b-9241-11dd-9df2-001e4c274594}]
\Shell\AutoRun\command - setup.exe
.
- - - - USUNIĘTO PUSTE WPISY - - - -
BHO-{1368c4e5-a83f-4538-a3d3-4d43e1984916} - c:\windows\system32\osldgm.dll
BHO-{4E007A5F-299F-44FC-8B6B-F06B61867A2E} - c:\windows\system32\cbXRLdcY.dll
BHO-{89805667-2D15-4AE5-8DF2-E707D48B6684} - c:\windows\system32\awtuuTki.dll
ShellExecuteHooks-{4E007A5F-299F-44FC-8B6B-F06B61867A2E} - c:\windows\system32\cbXRLdcY.dll
MSConfigStartUp-4c70f2ba - c:\windows\system32\nofwphmg.dll
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-27 20:52:15
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Comodo\Firewall\cmdagent.exe
c:\windows\system32\PSIService.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Czas ukończenia: 2008-11-27 20:53:27 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-11-27 19:53:23
Przed: 27 333 779 456 bajtów wolnych
Po: 27,304,988,672 bajtów wolnych
268
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:37:13, on 2008-11-27
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O1 - Hosts: 78.46.45.81 L2authd.lineage2.com
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Wyślij do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{43070E4F-6C25-43DF-89BB-9132A76F5AAC}: NameServer = 85.255.112.210;85.255.112.62
O17 - HKLM\System\CS1\Services\Tcpip\..\{43070E4F-6C25-43DF-89BB-9132A76F5AAC}: NameServer = 85.255.112.210;85.255.112.62
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll osldgm.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
--
End of file - 4859 bytes