Witam. Od niedawna mam następujący problem. Po uruchomieniu się Windowsa pojawia się tło pulpitu i... nic poza tym
Dopiero tak po 1-2 minutach pojawiają się ikonki i pasek zadań. Sprawdziłem kompa antywirusem ArcaVir 2008 i programem Spybot, ale nic nie znalazły. Nie jest to też raczej wina sieci bo od zawsze pracowała na takich ustawieniach i wszystko było dobrze. Problem znika chwilowo po usunięciu plików z folderu Prefetch, ale już przy kolejnych restartach znów mam to samo
Całkowite wyłączenie prefetchingu również nie załatwia sprawy. Co prawda wtedy ikony i pasek pojawiają się normalnie, lecz przez 1-2 minuty nie pojawiają się w pasku obok zegarka, przy próbie wejścia do połączeń sieciowych przez Menu Start zawiesza się ono oraz nie można wejść do Menedżera urządzeń
Proszę o sprawdzenie logów z Combofix i Hijackthis, które zamieszczam poniżej:
ComboFix 09-02-04.04 - GCS 2009-02-05 16:51:31.8 - NTFSx86
Uruchomiony z: c:\documents and settings\GCS\Pulpit\ComboFix.exe
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA [img]http://www.forum.tweaks.pl/public/style_emoticons/default/excl.gif[/img]
.
((((((((((((((((((((((((( Pliki utworzone od 2009-01-05 do 2009-02-05 )))))))))))))))))))))))))))))))
.
2009-02-05 15:40 . 2009-02-05 15:43 72,089,600 --a------ C:\LogFile.Etl
2009-02-05 15:05 . 2007-11-28 22:38 40,056 --a------ c:\windows\system32\NicInst.dll
2009-02-05 15:05 . 2007-12-14 12:05 35,424 --a------ c:\windows\system32\e100bmsg.dll
2009-02-05 15:05 . 2007-08-07 00:28 28,272 --a------ c:\windows\system32\NicCo2.dll
2009-02-05 15:05 . 2007-10-30 16:52 5,590 --a------ c:\windows\system32\e100b325.din
2009-02-04 21:36 . 2008-11-17 07:23 3,636,864 --a------ c:\windows\system32\drivers\NETw5x32.sys
2009-02-04 21:36 . 2008-06-20 09:33 2,756,608 --a------ c:\windows\system32\NETw5r32.dll
2009-02-04 21:36 . 2008-06-20 09:32 663,552 --a------ c:\windows\system32\NETw5c32.dll
2009-02-04 21:20 . 2006-06-29 19:28 2,732,032 --a------ c:\windows\system32\NETw3r32.dll
2009-02-04 21:20 . 2006-07-02 05:00 1,706,752 --a------ c:\windows\system32\drivers\NETw3x32.sys
2009-02-04 21:20 . 2006-06-29 19:28 561,152 --a------ c:\windows\system32\NETw3c32.dll
2009-02-04 21:03 . 2009-02-04 21:09 <DIR> d-------- c:\program files\Microsoft Bootvis
2009-02-04 20:43 . 2009-02-04 20:44 <DIR> d-------- c:\windows\$regcmp$
2009-02-04 19:43 . 2009-02-04 19:43 <DIR> d-------- C:\Deckard
2009-01-23 22:03 . 2009-01-23 22:03 <DIR> d-------- c:\documents and settings\GCS\WapSter
2009-01-12 16:11 . 2009-01-12 16:11 32 --a------ c:\windows\EvMoveCF.INI
2009-01-12 16:10 . 2009-01-12 16:10 <DIR> d--hs---- c:\windows\ftpcache
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 19:42 25,992 -c--a-w c:\windows\system32\pgdfgsvc.exe
2009-02-04 18:57 --------- d-----w c:\documents and settings\GCS\Dane aplikacji\uTorrent
2009-01-24 12:40 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\pdf995
2009-01-19 16:21 --------- d---a-w c:\documents and settings\All Users\Dane aplikacji\TEMP
2009-01-09 20:18 --------- d-----w c:\documents and settings\GCS\Dane aplikacji\Skype
2008-12-30 19:47 --------- d-----w c:\documents and settings\GCS\Dane aplikacji\Tlen.pl
2008-12-28 09:40 1,700,352 ----a-w c:\windows\system32\gdiplus.dll
2008-12-28 09:40 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\ipla
2008-12-28 09:39 --------- d-----w c:\documents and settings\GCS\Dane aplikacji\ipla
2008-12-14 15:29 --------- d-----w c:\documents and settings\GCS\Dane aplikacji\pdf995
2008-12-13 20:18 51,716 ----a-w c:\windows\system32\pdf995mon.dll
2008-12-13 20:18 118,784 ----a-w c:\windows\system32\pdfmona.dll
2008-12-13 20:15 --------- d-----w c:\program files\pdf995
2008-11-30 20:33 50,688 -c--a-w c:\windows\system32\wbhelp2.dll
.
------- Sigcheck -------
2008-04-14 21:50 702976 1fd3017efbafdc8eddbf60d90352e8a0 c:\windows\ServicePackFiles\i386\wininet.dll
2008-04-14 21:50 702976 1fd3017efbafdc8eddbf60d90352e8a0 c:\windows\system32\wininet.dll
2008-04-14 21:51 977408 f042e3426d45d86d9bb55f6a79ab441a c:\windows\explorer.exe
2008-04-14 21:51 977408 f042e3426d45d86d9bb55f6a79ab441a c:\windows\ServicePackFiles\i386\explorer.exe
2008-04-14 21:51 101888 e1a9a883950adb8f0536e2201a3c2a00 c:\windows\ServicePackFiles\i386\wuauclt.exe
2008-04-14 21:51 101888 e1a9a883950adb8f0536e2201a3c2a00 c:\windows\system32\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="d:\bezpieczenstwo\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2006-07-04 217088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-25 8470528]
"AvMenu"="d:\bezpieczenstwo\ArcaBit\ArcaVir\AVMenu.exe" [2008-11-09 514568]
"ArcaCheck"="d:\bezpieczenstwo\ArcaBit\ArcaVir\ArcaCheck.exe" [2008-10-16 630784]
"ABRegmon"="d:\bezpieczenstwo\ArcaBit\ArcaVir\ABregmon.exe" [2007-10-23 348160]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-25 81920]
"nwiz"="nwiz.exe" [2007-07-25 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-11-24 09:36 73728 c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0[/u]OODBS
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe"
"QuickTime Task"="d:\video\QuickTime\qttask.exe" -atboottime
"nwiz"=nwiz.exe /installquiet /nodetect
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"ISBMgr.exe"=c:\program files\Sony\ISB Utility\ISBMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Tlen.pl\\tlen.exe"=
"d:\\Dżony-Łoker\\mirc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\MATLAB\\R2007b\\bin\\win32\\MATLAB.exe"=
"d:\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"d:\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\GCS\\Pulpit\\utorrent.exe"=
R1 ABTDI;ABTDI;d:\bezpieczenstwo\ArcaBit\ArcaVir\ABTDI.sys [2007-05-08 51208]
R2 ABFileMon;ArcaBit FileMonitor;d:\bezpieczenstwo\ArcaBit\ArcaVir\FileMonSV.exe [2007-10-09 158216]
R2 ArcaBit.TaskScheduler;ArcaBit.TaskScheduler;d:\bezpieczenstwo\ArcaBit\Common\taskscheduler.exe [2007-10-25 151552]
R2 AVUpdate;ArcaBit Update Service;d:\bezpie~1\ArcaBit\ARCAUP~1\update.exe [2007-10-28 117256]
R3 ABFLT;ArcaBit File Monitor Driver;d:\bezpie~1\ArcaBit\ArcaVir\ABFLT.sys [2007-09-12 37896]
R3 ArcaBit.Core.Configurator;ArcaBit.Core.Configurator;d:\bezpieczenstwo\ArcaBit\Common\ArcaBit.Core.Configurator2.exe [2007-04-18 200704]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2008-04-10 72704]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2008-04-10 43904]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2006-09-06 30976]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-11-06 227328]
S3 ArcaBit.Core.LoggingService;ArcaBit.Core.LoggingService;d:\bezpieczenstwo\ArcaBit\Common\ArcaBit.Core.LoggingService.exe [2007-04-18 241664]
S3 WRSWanDD;WinPoET PPPoE Adapter;c:\windows\system32\drivers\WrKPoETNic2000.sys [2008-04-16 65604]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c8a3565-e481-11dd-9b32-0019c1b4e290}]
\Shell\AutoRun\command - M:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3e7aece7-39f3-11dd-99a0-0019c1b4e290}]
\Shell\AutoRun\command - N:\USBNB.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94c15abe-df0e-11dd-9b29-0019c1b4e290}]
\Shell\AutoRun\command - L:\
\Shell\open\Command - rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a953cc9c-c365-11dd-9acf-0019c1b4e290}]
\Shell\AutoRun\command - l:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\lin32.exe
\Shell\open\command - l:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\lin32.exe
.
.
------- Skan uzupełniający -------
.
IE: &Download with &DAP - d:\dap\dapextie.htm
IE: Download &all with DAP - d:\dap\dapextie2.htm
IE: E&ksport do programu Microsoft Excel - d:\micros~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\GCS\Dane aplikacji\Mozilla\Firefox\Profiles\kbdltfcq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ig
FF - component: d:\dap\DAPFireFox\components\DAPFireFox.dll
FF - plugin: d:\adobe_reader\Reader\browser\nppdf32.dll
FF - plugin: d:\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: d:\video\QuickTime\Plugins\npqtplugin.dll
FF - plugin: d:\video\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: d:\video\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: d:\video\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: d:\video\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: d:\video\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: d:\video\QuickTime\Plugins\npqtplugin7.dll
FF - plugin: d:\video\<a href="http://www.download.net.pl/107/Real-Alternative/">Real Alternative</a>\browser\plugins\nppl3260.dll
FF - plugin: d:\video\<a href="http://www.download.net.pl/107/Real-Alternative/">Real Alternative</a>\browser\plugins\nprpjplug.dll
---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-05 16:52:38
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_USERS\S-1-5-21-1343024091-179605362-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Intel\Wireless\Folders\¬ r*:*]
"Path"="c:\\WINDOWS\\system32\\config\\systemprofile\\Dane aplikacji\\Intel\\Wireless\\"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="AFA511E8CB70B541708551A92B1DE74A9F26424F79659740E630F40723356FC300A934D853C9
81D1DA8C3E81E0EC858ACAAF8BA24908A1C751FD263E3703D07E65038B80A2F7CCF4603EA8E1F7300
D4468CEDB8DD3F5D532F76A0FA14BB5575270285C3CC86D5CF7B915C35277EE0502FEBC9E127BECC7
4CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74
CA6A0AC4980AC79339DB7CE019D40AA5CA2D97226D213B555A6A0AC4980AC79335850E53D76295F59
4324EFA3520E55C826F75E947A96DEDF7DF7AD723B8A94F755BDF4E4DDCD8EF665601936919DA8104
CE01480E9A4CADA4B60CDAAE2D7CB381B2B7F3302265D044D8EAACC7DFD0C9BC284224DF49A4BB3A8
289DE741A29A788F0360BA4B1EA9868920F128F3301EAEE0F8648916ACE287572CA7260A7782547D0
77382C2B415398C5A3C7CF9C6C3BFE1A93AB568A4D42BFD1C7DD290F2C79C13CB1C8619FB07082FD8
DBF0B8EAA378E8D406452F5E29A5A3FBB54E50477455E2BA3E36A01D28942C87A8A179D9A838788D3
1A34DCC2C3237236670673CD538640F45F14F53E73623297C20AEE20291F8BAA72C4CF4EC418A3CAC
83962BFB316FDA9E9341EC78739653366E6AEA234AB71758315870C1F551C82AC34502BC6044833B6
4354CCE0D6FEEB88565E842DCE33035F644EBC0A7271C02647C43311B85BF8F258DEAA5F1F7BB69D1
FB6BDAF8136B393603A8476286DDDF8BE905B669391D9807D152FBC961C9B4B22C102D803DFCDD1CA
E7B75E4540A6C53DEF1ED87C8FDD0322CA3126C3CFE08FB1C0DBB8A3E71A24A044EAE23D26FDAC8D2
C8BC6704153C40EB90F0E78116D6F5132ACCDF57260D55649E1B45ADB25FEEDE5B4CAB9CEBDE4205E
0607E8C9B185D7CC2EC012C4E2247D27D29A571CBB2BB410F88AD28DF423A8C6E6EA49D73C461E7C8
EA20C672709A798F05540F861118DBDF23F92321759FBDAB6E05D5D05DA60A3FD823916A84C2268FA
614DC823CE3B3DA92516A3589DBF819767B3E3FE245BBBE8E245EE67525C749445E9332F66FF4228D
28C0F213CFBE4F601BC29B5D4876F32772DF6AD797F49E59DCD0600B026A6C94274C0AADCEB8794AA
9B19856AF5B1E0310B0CB486AE405A7F095A5C5D48784E5AA1978759D2F56169EBDBADDF02E934334
CBB467DDF605332C4873F595E2C707C213948CF893396AA9805D0573583AD04A1125D825293D43D63
18C72E7352942348D85988FF58AB02B74AC6412E28F55ED466FC2EBA25DE46CFE8A91605DAEA4F73F
CA430510441839F72B141F0024C07414BAD14DAB2CE61DC157B289DBF27E3AC3333B6FBBF5131DCE2
F345C829AC5628502355B3102DE4B70B434E15824655B96E330D9F6C3D5D3A1E06803E22E5C748B93
A19AC3CCA30FE134FA5A1B833270"
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(1196)
c:\windows\system32\VESWinlogon.dll
- - - - - - - > 'lsass.exe'(1252)
c:\windows\system32\scecli.dll
.
Czas ukończenia: 2009-02-05 16:54:01
ComboFix-quarantined-files.txt 2009-02-05 15:53:59
Przed: 8 041 152 512 bajtów wolnych
Po: 8,055,148,544 bajtów wolnych
176
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:36:25, on 2009-02-05
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Bezpieczenstwo\ArcaBit\Common\ArcaBit.Core.Configurator2.exe
C:\WINDOWS\Explorer.EXE
D:\BEZPIE~1\ArcaBit\ARCAUP~1\update.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
D:\Bezpieczenstwo\ArcaBit\ArcaVir\FileMonSV.exe
D:\Bezpieczenstwo\ArcaBit\ArcaVir\NetMonSV.exe
D:\Bezpieczenstwo\ArcaBit\Common\TaskScheduler.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
D:\Bezpieczenstwo\ArcaBit\ArcaVir\AVMenu.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Mozilla Firefox\firefox.exe
C:\Program Files\Outlook Express\msimn.exe
D:\Bezpieczenstwo\ArcaBit\Common\ArcaBit.Core.LoggingService.exe
D:\Bezpieczenstwo\Hijack\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\BEZPIE~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AvMenu] D:\Bezpieczenstwo\ArcaBit\ArcaVir\AVMenu.exe
O4 - HKLM\..\Run: [ArcaCheck] D:\Bezpieczenstwo\ArcaBit\ArcaVir\ArcaCheck.exe /startup
O4 - HKLM\..\Run: [ABRegmon] D:\Bezpieczenstwo\ArcaBit\ArcaVir\ABregmon.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Bezpieczenstwo\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Download with &DAP - D:\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - D:\DAP\dapextie2.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\BEZPIE~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\BEZPIE~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O23 - Service: ArcaBit FileMonitor (ABFileMon) - ArcaBit - D:\Bezpieczenstwo\ArcaBit\ArcaVir\FileMonSV.exe
O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit - D:\Bezpieczenstwo\ArcaBit\ArcaVir\NetMonSV.exe
O23 - Service: ArcaBit.Core.Configurator - ArcaBit - D:\Bezpieczenstwo\ArcaBit\Common\ArcaBit.Core.Configurator2.exe
O23 - Service: ArcaBit.Core.LoggingService - ArcaBit - D:\Bezpieczenstwo\ArcaBit\Common\ArcaBit.Core.LoggingService.exe
O23 - Service: ArcaBit.TaskScheduler - ArcaBit - D:\Bezpieczenstwo\ArcaBit\Common\TaskScheduler.exe
O23 - Service: ArcaBit Update Service (AVUpdate) - ArcaBit - D:\BEZPIE~1\ArcaBit\ARCAUP~1\update.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\WINDOWS\system32\DRIVERS\xaudio.exe
--
End of file - 5502 bytes