Próbowałam tego: http://forum.dobreprogramy.pl/brak-osta ... 16502.html ale to nic nie dało
Screeny:
P.S. Przepraszam za mój trochę chaotyczny post


| Pozdrawiam! AdaxLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:33:15, on 2009-07-30
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Launch Manager\WButton.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Launch Manager\OSD.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\Windows\VMSnap23.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nasza-klasa.pl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\Dom\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LMgrVolOSD] C:\Program Files\Launch Manager\OSD.exe
O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [BigDogPath323VMSnap] C:\Windows\VMSnap23.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKCU\..\Run: [StartCCC] c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1150595.exe -Update -1150595 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618; InfoPath.2; Creative ZENcast v2.00.13)" -"http://www.gry.pl/gra/Rally-Point.html"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - (no file)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - (no file)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E1F190C4-8F36-465B-A3BF-638BB252F6B4}: NameServer = 213.241.79.37 83.238.255.76
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs:
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
--
End of file - 8373 bytesComboFix 09-07-29.04 - Dom 2009-07-30 13:40.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1250.48.1045.18.1918.1128 [GMT 2:00]
Uruchomiony z: c:\users\Dom\Pulpit\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Zapora osobista *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
SP: ESET Smart Security 4.0 *disabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1295347312-942090187-475515473-1001
c:\$recycle.bin\S-1-5-21-1295347312-942090187-475515473-1002
c:\$recycle.bin\S-1-5-21-1295347312-942090187-475515473-1003
c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
c:\$recycle.bin\S-1-5-21-2368007090-1545034847-1956563946-500
c:\users\Dom\AppData\Roaming\inst.exe
c:\windows\system32\beddeeda3_d.dll
.
((((((((((((((((((((((((( Pliki utworzone od 2009-06-28 do 2009-07-30 )))))))))))))))))))))))))))))))
.
2009-07-30 11:50 . 2009-07-30 11:51 -------- d-----w- c:\users\Dom\AppData\Local\temp
2009-07-30 11:50 . 2009-07-30 11:50 -------- d-----w- c:\users\Ola\AppData\Local\temp
2009-07-30 11:26 . 2009-07-30 11:26 812344 ----a-w- c:\users\Dom\HJTInstall.exe
2009-07-15 13:10 . 2009-06-15 15:29 156160 ----a-w- c:\windows\system32\t2embed.dll
2009-07-15 13:10 . 2009-06-15 15:22 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-15 13:10 . 2009-06-15 15:23 24064 ----a-w- c:\windows\system32\lpk.dll
2009-07-15 13:10 . 2009-06-15 15:21 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-15 13:10 . 2009-06-15 15:20 34304 ----a-w- c:\windows\system32\atmlib.dll
2009-07-15 13:10 . 2009-06-15 13:03 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-14 17:19 . 2009-07-14 20:09 166640 ----a-w- c:\windows\system32\drivers\sfi.dat
2009-07-14 13:34 . 2009-07-14 13:33 74328 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-07-14 13:34 . 2009-07-28 16:59 -------- d-----w- c:\program files\COMODO
2009-07-05 19:20 . 2009-07-05 19:20 -------- d-----w- c:\users\Dom\AppData\Roaming\Desktopicon
2009-07-05 18:48 . 2005-04-11 14:40 73728 ----a-w- c:\windows\system32\FLKill.exe
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 13:49 . 2008-12-24 20:21 -------- d-----w- c:\programdata\Creative
2009-07-28 13:49 . 2008-12-24 20:19 -------- d-----w- c:\program files\Creative
2009-07-26 17:22 . 2008-06-12 15:28 -------- d-----w- c:\users\Dom\AppData\Roaming\Skype
2009-07-26 17:15 . 2008-01-02 20:07 -------- d-----w- c:\users\Dom\AppData\Roaming\skypePM
2009-07-25 18:09 . 2007-09-01 17:14 95356 ----a-w- c:\windows\system32\perfc015.dat
2009-07-25 18:09 . 2007-09-01 17:14 556746 ----a-w- c:\windows\system32\perfh015.dat
2009-07-22 21:06 . 2008-03-12 09:46 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-21 21:52 . 2009-07-28 17:30 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-28 17:30 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-28 17:30 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-28 17:30 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-15 13:17 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-15 13:17 . 2008-01-16 14:00 -------- d-----w- c:\programdata\Microsoft Help
2009-07-12 14:46 . 2009-04-11 12:43 -------- d-----w- c:\program files\English Translator 3
2009-07-10 17:57 . 2007-09-01 17:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-10 17:55 . 2008-12-25 16:31 -------- d-----w- c:\programdata\Electronic Arts
2009-07-06 12:27 . 2008-08-12 18:21 -------- d-----w- c:\users\Dom\AppData\Roaming\uTorrent
2009-07-06 11:19 . 2008-02-06 21:57 -------- d-----w- c:\users\Dom\AppData\Roaming\BitTorrent
2009-06-27 20:53 . 2008-09-09 06:32 -------- d-----w- c:\program files\Deutsch Translator 2
2009-06-21 20:03 . 2007-12-02 20:52 120520 ----a-w- c:\users\Dom\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-20 17:52 . 2008-06-04 12:55 -------- d-----w- c:\program files\ICQ6
2009-06-10 12:13 . 2009-06-10 12:13 -------- d-----w- c:\users\Dom\AppData\Roaming\OpenFM
2009-06-02 16:09 . 2009-06-02 16:09 10134 ----a-r- c:\users\Dom\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-02 16:09 . 2009-06-02 16:09 -------- d-----w- c:\program files\Microsoft WSE
2009-06-01 19:32 . 2009-06-01 19:32 -------- d-----w- c:\users\Dom\AppData\Roaming\DivX
2009-06-01 16:59 . 2009-01-16 18:12 -------- d-----w- c:\users\Dom\AppData\Roaming\DAEMON Tools Lite
2009-06-01 13:19 . 2008-08-13 11:42 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-05-28 09:23 . 2009-05-28 09:23 42088 ----a-w- c:\users\Dom\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll
2009-05-08 14:58 . 2009-05-08 14:23 47360 ----a-w- c:\users\Dom\AppData\Roaming\pcouffin.sys
2009-05-08 14:58 . 2009-05-08 14:23 47360 ----a-w- c:\users\Dom\AppData\Roaming\pcouffin.sys
2009-05-08 14:23 . 2009-05-08 14:23 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2007-01-25 02:52 . 2007-01-25 02:52 65536 ----a-w- c:\program files\Common Files\NMSAccessU.exe.vir
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-10 1232896]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-11-09 86016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 153136]
"LMgrVolOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224]
"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2006-08-29 241664]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2006-12-14 192512]
"CTCheck"="c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312]
"BigDogPath323VMSnap"="c:\windows\VMSnap23.exe" [2006-09-19 212992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-03-19 2029640]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-12-29 4317184]
c:\users\Dom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-9 113664]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-9 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoFileAssociate"= 0 (0x0)
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{55962861-3FA2-4508-B7DE-5E3D624FBD87}c:\\program files\\intervideo\\dvd8\\windvd.exe"= UDP:c:\program files\intervideo\dvd8\windvd.exe:WinDVD
"UDP Query User{10487523-9BA2-4200-8288-0C241CD58B47}c:\\program files\\intervideo\\dvd8\\windvd.exe"= TCP:c:\program files\intervideo\dvd8\windvd.exe:WinDVD
"TCP Query User{7414271A-DA47-444B-8032-673B4F06DC34}c:\\program files\\gadu-gadu\\gg.exe"= UDP:c:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program główny
"UDP Query User{471E9A70-9483-4E9F-A262-F371670886F9}c:\\program files\\gadu-gadu\\gg.exe"= TCP:c:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program główny
"TCP Query User{88E776A6-BDD9-481A-9EB9-35DCED092F47}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{698CBC31-1687-4E56-B302-B61DC907B6BF}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{B73F50D0-423C-4F92-82A6-7BFAE8930F21}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{1D8627F7-80AE-49BE-8BFB-088E057247D0}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{387D39B2-1D62-4EC2-AF5D-2A0AFA0A0EC5}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{F62B626A-96D8-463A-BF0D-5B1B5C9A4B4C}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{332A8232-31B3-45D6-B57E-67A929A8C727}"= UDP:8461:GoD High Port
"{1AD5A8C6-E953-40F4-B55A-44D903153585}"= UDP:8462:GoD Low Port
"{197C2601-E5D5-4AE1-B342-B41BA3629690}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{B60B699A-EA79-49CD-B0AF-23D83E380742}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{B88CFA24-70D9-4616-8A71-72561EA532A0}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{AEF654F6-3B46-40DE-A9FA-F3622E71E5AF}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{73B8309C-B835-416D-BAF0-7940F22662AE}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{20818624-EDA9-4B5B-89B0-979CD790E540}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{AFC9EBE6-CE1C-4FBA-A2A3-85684D25D562}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{AC8BA2CC-FA25-4ED3-BF54-F87B7070300D}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{14EECA14-9B86-4389-BEB0-F48616F82944}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{6FB68B20-9B5B-424E-A010-FF62C2EAFE59}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{09B8E300-86FA-4ABB-8F09-247E48B12D82}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{8B57DF36-2DF6-4C8D-9DA9-752D31203711}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{54D1AE96-E355-4D4B-A65E-58B109CBB659}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{16585CE9-72F3-4F75-AF88-8121C096FC6F}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{049BD856-6B52-4154-ADE4-959C36E27D90}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{997BD7AE-A5AB-4958-A80B-2616B4971CEA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5989AF23-9E7E-4561-94EB-3866BE79BF8B}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{BE54DFCB-970A-414E-9102-972E768E49DB}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{38462043-A381-43B3-B094-A0DFE2726650}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{FAD7334B-2D7A-430E-91F1-E44F7876D41E}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{45CB9B9E-9873-4FAF-A03C-565E61D81D5B}"= UDP:c:\program files\iMesh Applications\iMesh\iMesh.exe:iMesh
"{1D6DE0F6-29E0-4B6C-9B48-8090F0A2B3B0}"= TCP:c:\program files\iMesh Applications\iMesh\iMesh.exe:iMesh
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\System32\drivers\sfsync03.sys [2005-10-13 35328]
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [2009-03-19 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-03-19 731840]
R2 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-12-27 51816]
R3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\System32\drivers\e4usbaw.sys [2007-12-28 104344]
R3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [2007-09-01 118784]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);c:\windows\System32\drivers\e4ldr.sys [2007-12-28 69656]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe --> c:\program files\MAGIX\Common\Database\bin\fbserver.exe [?]
S3 vmfilter323;323 filter service, Normal;c:\windows\System32\drivers\vmfilter323.sys [2007-12-02 476672]
S3 ZSMC326;VIMICRO USB2.0 PC Camera(VC0323);c:\windows\System32\drivers\usbvm323.sys [2007-12-02 260096]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {019749A1-F9BC-476C-2614-58D9ED0A6F40} /qb
.
Zawartość folderu 'Zaplanowane zadania'
2009-07-10 c:\windows\Tasks\User_Feed_Synchronization-{869EE33E-1842-4C4B-8D4C-59C00E385110}.job
- c:\windows\system32\msfeedssync.exe [2009-07-28 20:13]
2009-07-10 c:\windows\Tasks\User_Feed_Synchronization-{BACF6632-50E9-4023-8836-C475979C8FE8}.job
- c:\windows\system32\msfeedssync.exe [2009-07-28 20:13]
2009-07-09 c:\windows\Tasks\User_Feed_Synchronization-{F5D9BFC7-BA35-45C9-A4C1-2B5EB23D040C}.job
- c:\windows\system32\msfeedssync.exe [2009-07-28 20:13]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-RunOnce-Shockwave Updater - c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150595.exe -Update -1150595 -Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618; InfoPath.2; Creative ZENcast v2.00.13)
HKLM-Run-CtrlVol - c:\program files\Launch Manager\CtrlVol.exe
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.onet.pl/
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {E1F190C4-8F36-465B-A3BF-638BB252F6B4} = 213.241.79.37 83.238.255.76
.
.
------- Skojarzenia plików -------
.
vbefile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
vbsfile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
jsefile\shell\open2\command=c:\windows\System32\CScript.exe "%1" %*
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-30 13:51
Windows 6.0.6000 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CtrlVol = c:\program files\Launch Manager\CtrlVol.exe?????H?A???????A?(6A????w????(6A?????0???<???????|??????w?q?w????3 ?w!??w??????A???A?=?^v????L???~z?w??A?????x?A?????? A???A?????? A?Ln? =?^v?????????a@?`??????????? ?A???? ????? A???@???A??x@???A?dn? ??@???A????
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Czas ukończenia: 2009-07-30 13:57
ComboFix-quarantined-files.txt 2009-07-30 11:57
ComboFix2.txt 2009-02-25 20:15
Przed: 31 772 651 520 bajtów wolnych
Po: 31 798 968 320 bajtów wolnych
245 --- E O F --- 2009-07-28 17:32


Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"HonorAutoRunSetting"=dword:00000001
"NoCDBurning"=dword:00000000
"NoControlPanel"=dword:00000000
"NoDriveTypeAutoRun "=dword:00000000
"NoRun"=dword:00000000
"NoViewContextMenu "=dword:00000000
"BindDirectlyToPropertySetStorage"=dword:00000000

| Pozdrawiam! Adax
Jedyną rzeczą wartą zauważenia był fakt, że gdy chciałam zatwierdzić we Właściwościach Paska Zadań ustawienia, explorer (a właściwie Pasek Zadań) zawiesił się i musiałam ponownie go uruchamiać.
| Pozdrawiam! Adax
| Pozdrawiam! AdaxUżytkownicy przeglądający ten dział: Brak zidentyfikowanych użytkowników i 0 gości