
Parę dni temu NOD32 wykrył jakiegoś trojana o nazwie trojan.downloader... i oczywiście automatycznie go skasował ale od tego czasu komp zaczął strasznie mulić. Jest tak że, 30 sekund działa normalnie a później na 8-10 sekund się zawiesza i nic nie odpowiada. Po tym czasie znów działa normalnie, w ciągu pisania tego tekstu przyciął mi się 4 razy... Robiłem już 3 razy skany ComboFixem, za pierwszym razem wyciał tego trochę ale nic nie pomogło zamieszczam ostatni Log z combofixa i hijacka. Proszę o pomoc.
COMBOFIX
- Kod: Zaznacz wszystko
ComboFix 09-06-19.01 - Jacek 2009-06-20 16:02.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1033.18.1023.690 [GMT 2:00]
Uruchomiony z: c:\documents and settings\Jacek.DOMGORA\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
.
((((((((((((((((((((((((( Pliki utworzone od 2009-05-20 do 2009-06-20 )))))))))))))))))))))))))))))))
.
2009-06-19 20:01 . 2009-06-19 20:01 -------- d-----w- C:\ERDNT
2009-06-19 20:00 . 2009-06-19 20:00 -------- d-----w- C:\!FixIEDef
2009-06-19 17:57 . 2009-06-19 18:16 -------- d-----w- C:\!KillBox
2009-06-18 18:16 . 2009-06-17 18:58 3026777 ----a-r- C:\ComboFix.exe
2009-06-18 17:32 . 2009-06-19 20:01 -------- d-----w- c:\windows\ERUNT
2009-06-18 17:27 . 2009-06-18 18:13 -------- d-----w- C:\SDFix
2009-06-17 20:30 . 2009-06-17 20:30 -------- d-----w- c:\documents and settings\Jacek.DOMGORA\Local Settings\Application Data\ESET
2009-06-17 19:31 . 2009-06-17 19:31 -------- d-----w- c:\program files\ESET
2009-06-17 19:31 . 2009-06-17 19:31 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ESET
2009-06-17 18:44 . 2009-06-17 18:45 -------- d-----w- c:\program files\CCleaner
2009-06-17 18:34 . 2009-06-17 18:34 -------- d-----w- c:\program files\Trend Micro
2009-06-14 18:00 . 2009-06-14 18:00 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-14 18:00 . 2009-06-14 18:00 -------- d-----w- c:\program files\Real
2009-06-14 18:00 . 2009-06-14 18:00 -------- d-----w- c:\program files\Common Files\Real
2009-06-14 17:57 . 2009-06-14 17:57 -------- d-----w- c:\documents and settings\Jacek.DOMGORA\Application Data\Media Player Classic
2009-06-14 17:55 . 2004-08-04 00:56 25600 ----a-w- c:\documents and settings\LocalService.NT AUTHORITY\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-05-23 17:58 . 2009-05-23 17:58 -------- d-----w- c:\documents and settings\Jacek.DOMGORA\Phone Browser
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-20 13:59 . 2008-12-30 17:18 -------- d-----w- c:\documents and settings\Jacek.DOMGORA\Application Data\Skype
2009-06-20 13:56 . 2009-04-06 17:19 -------- d-----w- c:\documents and settings\Jacek.DOMGORA\Application Data\skypePM
2009-06-19 20:28 . 2009-05-13 18:21 -------- d-----w- c:\program files\Nokia
2009-06-19 20:28 . 2009-05-13 18:21 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Downloaded Installations
2009-06-19 20:28 . 2009-05-13 18:22 -------- d-----w- c:\program files\Common Files\PCSuite
2009-05-14 13:49 . 2009-05-14 13:49 94360 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2009-05-14 13:47 . 2009-05-14 13:47 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-05-14 13:41 . 2009-05-14 13:41 114472 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-05-13 18:25 . 2009-05-13 18:25 -------- d-----w- c:\documents and settings\Jacek.DOMGORA\Application Data\Nokia
2009-05-13 18:22 . 2009-05-13 18:22 -------- d-----w- c:\documents and settings\Jacek.DOMGORA\Application Data\PC Suite
2009-05-13 18:22 . 2009-05-13 18:22 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PC Suite
2009-04-27 15:57 . 2009-04-27 15:57 -------- d-----w- c:\documents and settings\Jacek.DOMGORA\Application Data\Ahead
2009-04-27 15:56 . 2009-04-27 15:56 -------- d-----w- c:\program files\Common Files\Ahead
2009-04-27 15:56 . 2009-04-27 15:56 -------- d-----w- c:\program files\Ahead
2009-04-06 17:19 . 2009-04-06 17:19 48 ---ha-w- c:\windows\system32\ezsidmv.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-06-17_19.23.01 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-08-23 14:00 . 2009-06-17 18:43 40836 c:\windows\system32\perfc009.dat
+ 2001-08-23 14:00 . 2009-06-20 13:59 40836 c:\windows\system32\perfc009.dat
+ 2009-06-17 19:33 . 2009-06-17 19:33 10134 c:\windows\Installer\{644CEC11-C3D3-4F8D-A935-74F1EEF38209}\callmsi.exe
+ 2009-06-18 17:32 . 2009-06-18 17:32 8192 c:\windows\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000002\UsrClass.dat
+ 2009-06-18 17:32 . 2009-06-18 17:32 8192 c:\windows\ERUNT\SDFIX\Users\[u]0[/u]0000002\UsrClass.dat
+ 2001-08-23 14:00 . 2009-06-20 13:59 314508 c:\windows\system32\perfh009.dat
- 2001-08-23 14:00 . 2009-06-17 18:43 314508 c:\windows\system32\perfh009.dat
+ 2009-06-17 19:33 . 2009-06-17 19:33 101480 c:\windows\Installer\{644CEC11-C3D3-4F8D-A935-74F1EEF38209}\egui.exe
+ 2009-06-18 17:32 . 2009-06-18 17:32 376832 c:\windows\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000001\NTUSER.DAT
+ 2009-06-18 17:32 . 2008-08-07 13:27 163328 c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2009-06-18 17:32 . 2009-06-18 17:32 376832 c:\windows\ERUNT\SDFIX\Users\[u]0[/u]0000001\NTUSER.DAT
+ 2009-06-18 17:32 . 2008-08-07 13:27 163328 c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2008-12-25 03:47 . 2005-10-20 16:00 157696 c:\windows\ERUNT\ERUNT.EXE
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-16 24264488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-14 198160]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-10-30 16269312]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-05-14 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-05-14 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-05-14 731840]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
.
.
------- Skan uzupełniający -------
.
FF - ProfilePath - c:\documents and settings\Jacek.DOMGORA\Application Data\Mozilla\Firefox\Profiles\7cwpsna1.default\
FF - prefs.js: browser.startup.homepage - www.onet.pl
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\id Software\QuakeLive\npquakezero.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-20 16:09
Windows 5.1.2600 Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
c:\windows\TEMP\4vjg21qd.TMP 616448 bytes
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'explorer.exe'(2052)
c:\windows\system32\msi.dll
.
Czas ukończenia: 2009-06-20 16:12
ComboFix-quarantined-files.txt 2009-06-20 14:11
ComboFix2.txt 2009-06-19 17:49
ComboFix3.txt 2009-06-18 18:33
ComboFix4.txt 2009-06-17 19:27
Przed: 8 527 413 248 bytes free
Po: 8 517 996 544 bytes free
124
HIJACKTHIS
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:29:06, on 2009-06-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\CF4753.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 4047 bytes
- Kod: Zaznacz wszystko
OTL logfile created on: 2009-06-20 17:40:55 - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Jacek.DOMGORA\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd
1023,23 Mb Total Physical Memory | 530,96 Mb Available Physical Memory | 51,89% Memory free
2,40 Gb Paging File | 2,10 Gb Available in Paging File | 87,36% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 7,98 Gb Free Space | 40,84% Space Free | Partition Type: NTFS
Drive D: | 64,60 Gb Total Space | 55,75 Gb Free Space | 86,30% Space Free | Partition Type: NTFS
Drive E: | 64,91 Gb Total Space | 62,52 Gb Free Space | 96,31% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 15,06 Gb Total Space | 13,76 Gb Free Space | 91,37% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Computer Name: DOMGORA
Current User Name: Jacek
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
[color=orange]========== Processes (SafeList) ==========[/color]
PRC - [2006-10-30 13:49:54 | 16,269,312 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2005-07-19 18:32:18 | 00,221,184 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\LVCOMSX.EXE
PRC - [2007-10-25 17:33:22 | 00,563,984 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2007-10-25 17:37:32 | 02,178,832 | ---- | M] () -- C:\Program Files\Logitech\QuickCam\Quickcam.exe
PRC - [2009-06-14 20:00:37 | 00,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009-05-14 15:47:08 | 02,029,640 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2009-05-14 15:47:54 | 00,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2007-10-19 14:17:28 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2004-02-05 00:54:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2008-10-07 14:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2007-10-19 14:17:28 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2009-02-28 13:05:24 | 00,070,968 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe
PRC - [2005-01-28 14:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe
PRC - [2004-08-04 02:56:58 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
PRC - [2007-10-25 17:32:58 | 00,407,824 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
PRC - File not found -- C:\WINDOWS\system32\CF4753.exe
PRC - [2004-08-04 02:56:50 | 01,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2009-06-13 19:45:51 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-06-20 17:39:15 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\OTL.exe
[color=orange]========== Win32 Services (SafeList) ==========[/color]
SRV - [2009-05-14 15:54:22 | 00,020,680 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv [On_Demand | Stopped])
SRV - [2009-05-14 15:47:54 | 00,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn [Auto | Running])
SRV - [2004-08-04 02:56:46 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2004-08-04 02:56:44 | 00,027,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\irmon.dll -- (Irmon [Auto | Running])
SRV - [2007-10-19 14:17:28 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer [Auto | Running])
SRV - [2007-10-19 14:19:22 | 00,141,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv [Auto | Stopped])
SRV - [2007-10-19 14:21:16 | 00,141,848 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher [Auto | Stopped])
SRV - [2004-02-05 00:54:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
SRV - [2008-10-07 14:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2003-07-28 21:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2009-02-28 13:05:24 | 00,070,968 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA [Auto | Running])
SRV - [2006-06-05 13:59:18 | 00,174,080 | ---- | M] (Nokia.) -- C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe -- (ServiceLayer [Disabled | Stopped])
SRV - [2005-01-28 14:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running])
[color=orange]========== Driver Services (SafeList) ==========[/color]
DRV - File not found -- -- (catchme [On_Demand | Running])
DRV - [2008-01-03 23:50:32 | 00,041,984 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\WINDOWS\system32\Drivers\DgiVecp.sys -- (DgiVecp [Auto | Running])
DRV - [2009-05-14 15:41:10 | 00,114,472 | ---- | M] (ESET) -- C:\WINDOWS\system32\DRIVERS\eamon.sys -- (eamon [Auto | Running])
DRV - [2009-05-14 15:47:14 | 00,107,256 | ---- | M] (ESET) -- C:\WINDOWS\system32\DRIVERS\ehdrv.sys -- (ehdrv [System | Running])
DRV - [2009-05-14 15:49:32 | 00,094,360 | ---- | M] (ESET) -- C:\WINDOWS\system32\DRIVERS\epfwtdir.sys -- (epfwtdir [System | Running])
DRV - [2005-01-07 18:07:18 | 00,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2006-11-03 03:32:30 | 04,394,496 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2001-08-17 15:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\irsir.sys -- (irsir [On_Demand | Running])
DRV - [2007-10-19 14:16:30 | 02,109,976 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\LVcKap.sys -- (LVcKap [On_Demand | Running])
DRV - [2007-10-11 19:59:02 | 02,142,488 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys -- (LVMVDrv [On_Demand | Running])
DRV - [2007-10-11 19:59:24 | 00,025,624 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys -- (LVPr2Mon [On_Demand | Running])
DRV - [2007-10-12 04:00:42 | 00,041,752 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta [On_Demand | Running])
DRV - [2008-10-07 14:33:00 | 06,133,856 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2007-03-06 06:27:28 | 00,058,752 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
DRV - [2007-03-06 06:27:32 | 00,019,968 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
DRV - [2007-02-16 02:50:32 | 00,012,032 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nvsmu.sys -- (nvsmu [On_Demand | Running])
DRV - [2007-10-12 03:55:58 | 00,013,848 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\lv302af.sys -- (pepifilter [On_Demand | Running])
DRV - [2007-10-12 03:55:58 | 01,279,000 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\LV302V32.SYS -- (PID_PEPI [On_Demand | Running])
DRV - [2001-08-23 16:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2004-07-17 13:36:38 | 00,027,440 | ---- | M] () -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2004-08-04 00:07:56 | 00,059,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Running])
[color=orange]========== Standard Registry (SafeList) ==========[/color]
[color=orange]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1547161642-261478967-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1547161642-261478967-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1547161642-261478967-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKU\S-1-5-21-1547161642-261478967-682003330-1003\S-1-5-21-1547161642-261478967-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=orange]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "www.onet.pl"
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2009-06-14 20:00:46 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009-06-14 20:00:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009-06-14 20:00:48 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\MOZILLA THUNDERBIRD [2009-06-17 21:31:25 | 00,000,000 | ---D | M]
[2008-12-29 22:59:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\mozilla\Extensions
[2008-12-29 22:59:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008-12-29 22:59:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\mozilla\Firefox\Profiles\7cwpsna1.default\extensions
[2008-12-29 22:59:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-06-13 19:45:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-06-13 19:45:51 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-06-13 19:45:51 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2006-06-03 18:43:22 | 00,000,896 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2008-04-03 19:19:08 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2008-04-16 06:08:20 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2007-03-31 19:11:54 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2006-06-03 18:43:22 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2008-03-28 23:36:04 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2007-01-05 13:40:56 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice (ESET)
O4 - HKLM..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide ()
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SkyTel] SkyTel.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1547161642-261478967-682003330-1003..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-261478967-682003330-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-261478967-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1547161642-261478967-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1547161642-261478967-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1547161642-261478967-682003330-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-06-09 13:03:16 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009-03-03 18:50:47 | 00,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-03-03 18:50:47 | 00,000,000 | ---D | M] - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009-03-03 18:50:47 | 00,000,000 | ---D | M] - E:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009-06-19 22:25:13 | 00,000,000 | ---D | M]
[color=orange]========== Files/Folders - Created Within 30 Days ==========[/color]
[3 C:\WINDOWS\*.tmp files]
[2009-06-20 17:38:34 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\OTL.exe
[2009-06-20 16:12:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009-06-20 16:12:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jacek.DOMGORA\Local Settings\temp
[2009-06-20 16:01:02 | 00,000,000 | --SD | C] -- C:\ComboFix
[2009-06-19 22:20:19 | 00,051,232 | ---- | C] (gkweb) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\wwdc_141_(dobreprogramy.pl).exe
[2009-06-19 22:14:59 | 00,038,899 | ---- | C] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\SeconfigXP.zip
[2009-06-19 22:01:39 | 00,000,000 | ---D | C] -- C:\ERDNT
[2009-06-19 22:00:55 | 00,000,000 | ---D | C] -- C:\!FixIEDef
[2009-06-19 21:59:53 | 01,130,036 | ---- | C] (Malwareteks.com) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\FixIEDef.exe
[2009-06-19 19:57:24 | 00,000,000 | ---D | C] -- C:\!KillBox
[2009-06-19 18:56:18 | 00,000,000 | ---- | C] () -- C:\WINDOWS\bestplayer.bbt
[2009-06-19 18:56:10 | 00,001,103 | ---- | C] () -- C:\WINDOWS\bestplayer.ini
[2009-06-19 18:56:07 | 00,000,000 | ---- | C] () -- C:\WINDOWS\bestplayer.bpp
[2009-06-18 20:16:48 | 03,026,777 | R--- | C] () -- C:\ComboFix.exe
[2009-06-18 20:09:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\WinRAR
[2009-06-18 19:32:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2009-06-18 19:28:04 | 00,132,597 | ---- | C] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\Flash_Disinfector.exe
[2009-06-18 19:27:22 | 00,000,000 | ---D | C] -- C:\SDFix
[2009-06-18 19:26:12 | 01,529,241 | ---- | C] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\SDFix.exe
[2009-06-17 21:34:42 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009-06-17 21:31:23 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
[2009-06-17 21:31:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\ESET
[2009-06-17 21:02:16 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009-06-17 21:02:16 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009-06-17 21:02:16 | 00,155,136 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009-06-17 21:02:16 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009-06-17 21:02:16 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009-06-17 21:02:16 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009-06-17 21:02:16 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009-06-17 21:02:16 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009-06-17 21:01:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009-06-17 21:01:32 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009-06-17 20:58:04 | 03,028,868 | R--- | C] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\ComboFix.exe
[2009-06-17 20:52:02 | 31,218,688 | ---- | C] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\eav_nt32_plk.msi
[2009-06-17 20:45:11 | 00,001,548 | ---- | C] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\CCleaner.lnk
[2009-06-17 20:44:58 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2009-06-17 20:43:44 | 03,247,736 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\ccsetup220.exe
[2009-06-17 20:34:03 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\HijackThis.lnk
[2009-06-17 20:34:03 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009-06-17 20:33:18 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\HJTInstall.exe
[2009-06-14 20:00:47 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2009-06-14 20:00:46 | 00,001,601 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Free Games & Music.lnk
[2009-06-14 20:00:46 | 00,000,897 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\RealPlayer.lnk
[2009-06-14 20:00:38 | 00,278,528 | ---- | C] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2009-06-14 20:00:38 | 00,000,000 | ---D | C] -- C:\Program Files\Real
[2009-06-14 20:00:37 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Real
[2009-06-14 20:00:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Real
[2009-06-14 19:57:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Media Player Classic
[2009-06-14 19:57:20 | 02,045,127 | ---- | C] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\mplayerc_[www.programosy.pl].zip
[2009-06-14 19:48:23 | 00,000,046 | ---- | C] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\ant81_12.ram
[2009-06-13 19:45:17 | 00,000,083 | ---- | C] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\np_hq.ram
[2009-05-26 15:59:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\tabor
[2009-02-28 12:44:47 | 00,138,784 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009-01-28 11:49:16 | 00,000,412 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009-01-04 16:43:14 | 00,059,500 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2008-12-29 22:48:28 | 00,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008-12-29 22:48:28 | 00,004,445 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008-10-07 14:33:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008-10-07 14:33:00 | 01,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008-10-07 14:33:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008-10-07 14:33:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008-10-07 14:33:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008-09-24 18:06:21 | 00,022,723 | ---- | C] () -- C:\WINDOWS\System32\sse1ml3.dll
[2008-01-03 23:07:12 | 00,087,040 | ---- | C] () -- C:\WINDOWS\System32\WIASTIIO.dll
[2008-01-03 23:07:10 | 00,139,776 | ---- | C] () -- C:\WINDOWS\System32\WIAEH.dll
[2008-01-03 23:07:10 | 00,116,736 | ---- | C] () -- C:\WINDOWS\System32\WIAIPH.dll
[2008-01-03 23:07:08 | 00,265,216 | ---- | C] () -- C:\WINDOWS\System32\Sswiadrv.dll
[2008-01-03 23:07:08 | 00,138,240 | ---- | C] () -- C:\WINDOWS\System32\Ssuiext.dll
[2007-10-11 19:59:24 | 00,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2004-08-04 02:56:50 | 00,078,848 | ---- | C] () -- C:\WINDOWS\System32\e8main1.dll
[2004-08-04 02:56:44 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004-07-17 13:36:38 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2003-04-08 12:40:22 | 00,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001-08-23 16:00:00 | 00,000,461 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-08-23 16:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[color=orange]========== Files - Modified Within 30 Days ==========[/color]
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009-06-20 17:39:15 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\OTL.exe
[2009-06-20 16:12:55 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-06-20 16:09:29 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-06-20 15:59:54 | 00,360,124 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-06-20 15:59:54 | 00,314,508 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-06-20 15:59:54 | 00,040,836 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-06-20 15:59:49 | 03,028,868 | R--- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\ComboFix.exe
[2009-06-20 15:55:41 | 00,200,819 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009-06-20 15:55:33 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Local Settings\desktop.ini
[2009-06-20 15:55:31 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-06-19 22:20:35 | 00,051,232 | ---- | M] (gkweb) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\wwdc_141_(dobreprogramy.pl).exe
[2009-06-19 22:15:00 | 00,038,899 | ---- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\SeconfigXP.zip
[2009-06-19 22:00:39 | 01,130,036 | ---- | M] (Malwareteks.com) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\FixIEDef.exe
[2009-06-19 18:56:18 | 00,001,103 | ---- | M] () -- C:\WINDOWS\bestplayer.ini
[2009-06-19 18:56:18 | 00,000,000 | ---- | M] () -- C:\WINDOWS\bestplayer.bbt
[2009-06-19 18:56:07 | 00,000,000 | ---- | M] () -- C:\WINDOWS\bestplayer.bpp
[2009-06-18 19:34:33 | 00,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2009-06-18 19:28:04 | 00,132,597 | ---- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\Flash_Disinfector.exe
[2009-06-18 19:27:15 | 01,529,241 | ---- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\SDFix.exe
[2009-06-17 21:01:04 | 31,218,688 | ---- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\eav_nt32_plk.msi
[2009-06-17 20:58:24 | 03,026,777 | R--- | M] () -- C:\ComboFix.exe
[2009-06-17 20:45:12 | 00,001,548 | ---- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\CCleaner.lnk
[2009-06-17 20:44:09 | 03,247,736 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\ccsetup220.exe
[2009-06-17 20:34:03 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\HijackThis.lnk
[2009-06-17 20:33:19 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\HJTInstall.exe
[2009-06-17 19:06:02 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-06-14 20:03:54 | 00,000,046 | ---- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\ant81_12.ram
[2009-06-14 20:00:46 | 00,001,601 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Free Games & Music.lnk
[2009-06-14 20:00:46 | 00,000,897 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\RealPlayer.lnk
[2009-06-14 20:00:38 | 00,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2009-06-14 19:57:25 | 02,045,127 | ---- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\mplayerc_[www.programosy.pl].zip
[2009-06-14 19:55:05 | 00,000,375 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009-06-13 19:45:17 | 00,000,083 | ---- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\np_hq.ram
[2009-06-08 08:10:10 | 00,155,136 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009-06-05 20:40:33 | 04,058,715 | ---- | M] () -- C:\Documents and Settings\Jacek.DOMGORA\Desktop\shufutinskij_mihail-palma_de_majorka.mp3
[color=orange]========== LOP Check ==========[/color]
[2008-12-29 02:27:13 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Administrator.DOMGORA\Application Data
[2009-06-18 19:31:28 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Administrator.DOMGORA\Application Data\Microsoft
[2009-06-17 21:37:17 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data
[2009-03-13 19:55:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
[2009-06-19 22:28:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Downloaded Installations
[2009-06-17 21:31:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\ESET
[2009-02-28 12:44:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\id Software
[2009-01-28 19:37:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
[2009-01-04 16:47:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Logishrd
[2009-01-04 16:42:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Logitech
[2009-01-28 11:49:28 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
[2009-01-28 11:45:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
[2009-05-13 20:22:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
[2009-04-06 19:19:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype
[2008-12-29 02:27:13 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User.WINDOWS\Application Data
[2008-12-29 22:42:45 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Default User.WINDOWS\Application Data\Microsoft
[2009-06-18 20:09:56 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data
[2009-03-13 19:55:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Adobe
[2009-04-27 17:57:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Ahead
[2009-02-28 12:46:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\id Software
[2008-12-29 22:47:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Identities
[2008-12-29 22:50:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\InstallShield
[2008-12-29 22:57:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Macromedia
[2009-06-14 19:57:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Media Player Classic
[2009-05-23 19:03:04 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Microsoft
[2008-12-29 22:59:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Mozilla
[2009-05-13 20:25:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Nokia
[2009-01-08 20:17:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Nowe Gadu-Gadu
[2009-05-13 20:22:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\PC Suite
[2009-06-14 20:01:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Real
[2009-06-20 15:59:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Skype
[2009-06-20 15:56:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\skypePM
[2009-03-07 15:55:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\Winamp
[2009-06-18 20:09:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Jacek.DOMGORA\Application Data\WinRAR
[2008-12-29 22:46:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data
[2008-12-29 22:42:45 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\Microsoft
[2008-12-29 22:46:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data
[2008-12-29 22:42:45 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\Microsoft
[2001-08-23 16:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009-06-20 16:12:55 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[color=orange]========== Purity Check ==========[/color]
< End of report >