Skocz do zawartości


pawel8704

Rejestracja: 31 paź 2008
OFFLINE Ostatnio: 02 11 2008 10:58
-----

Moje tematy

Logi - Kontrolka

31 10 2008 - 20:33

bardzo prosze o sprawdzenie logow

ComboFix 08-10-30.13 - Paweł 2008-10-31 19:02:46.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1250.1.1045.18.581 [GMT 1:00]
Uruchomiony z: C:\Documents and Settings\Paweł\Pulpit\ComboFix.exe
.

(((((((((((((((((((((((((   Pliki utworzone od 2008-09-28 do 2008-10-31  )))))))))))))))))))))))))))))))
.

2008-10-31 18:27 . 2008-10-31 18:35	<DIR>	d--------	C:\Program Files\Nowe Gadu-Gadu
2008-10-31 18:27 . 2008-10-31 18:28	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\Nowe Gadu-Gadu
2008-10-30 17:51 . 2008-10-30 18:01	<DIR>	d--------	C:\Program Files\Miranda IM
2008-10-30 17:51 . 2008-10-30 17:51	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\Miranda
2008-10-29 21:31 . 2008-10-29 21:31	<DIR>	d--------	C:\Program Files\Common Files\Adobe
2008-10-26 22:22 . 2008-10-15 17:36	337,408	-----c---	C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-19 12:42 . 2008-10-19 12:42	<DIR>	dr-hs----	C:\RESTORE
2008-10-18 14:06 . 2008-10-31 17:51	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\skypePM
2008-10-18 14:06 . 2008-10-18 14:06	56	--ah-----	C:\WINDOWS\system32\ezsidmv.dat
2008-10-18 14:03 . 2008-10-18 14:03	<DIR>	d--------	C:\Program Files\Skype
2008-10-18 14:03 . 2008-10-18 14:03	<DIR>	d--------	C:\Program Files\Common Files\Skype
2008-10-18 14:03 . 2008-10-31 19:06	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\Skype
2008-10-18 14:03 . 2008-10-18 14:03	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-10-18 11:13 . 2008-10-18 11:16	<DIR>	d--------	C:\Program Files\Tlen.pl
2008-10-18 11:13 . 2008-10-18 11:14	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\Tlen.pl
2008-10-17 13:09 . 2008-04-14 18:20	221,184	--a------	C:\WINDOWS\system32\wmpns.dll
2008-10-17 10:50 . 2008-10-17 13:08	49	--a------	C:\WINDOWS\NeroDigital.ini
2008-10-17 08:33 . 2007-09-26 18:37	3,036,456	--a------	C:\WINDOWS\system32\BCGCBPRO860u80.dll
2008-10-17 08:33 . 2007-09-26 18:37	33,576	--a------	C:\WINDOWS\system32\BCGPOleAcc.dll
2008-10-16 23:15 . 2008-10-16 23:15	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\Media Player Classic
2008-10-16 14:44 . 2008-10-16 14:44	<DIR>	d--------	C:\Program Files\Java
2008-10-16 14:44 . 2008-06-10 01:32	73,728	--a------	C:\WINDOWS\system32\javacpl.cpl
2008-10-16 14:34 . 2008-10-17 08:34	<DIR>	d--------	C:\Program Files\Nero
2008-10-16 14:24 . 2008-10-16 14:24	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\Ahead
2008-10-16 14:20 . 2008-10-16 14:34	<DIR>	d--------	C:\Program Files\Common Files\Ahead
2008-10-16 14:19 . 2008-10-16 14:34	<DIR>	d--------	C:\Program Files\Ahead
2008-10-16 14:14 . 2006-03-17 11:45	1,757,184	--a------	C:\WINDOWS\system32\imagX7.dll
2008-10-16 14:14 . 2008-06-23 16:36	773,120	--a------	C:\WINDOWS\system32\NEROINSTAEC43759.DB
2008-10-16 14:14 . 2006-03-17 11:45	497,296	--a------	C:\WINDOWS\system32\imagXpr7.dll
2008-10-15 22:10 . 2008-10-18 14:09	<DIR>	d--------	C:\Program Files\EWB512
2008-10-15 22:10 . 2008-10-15 22:10	216,064	--a------	C:\WINDOWS\iun3405.exe
2008-10-15 12:52 . 2008-10-15 12:52	<DIR>	d--------	C:\Program Files\Common Files\Java
2008-10-15 11:30 . 2008-10-15 21:23	<DIR>	d--------	C:\Program Files\SopCast
2008-10-15 06:43 . 2008-08-14 14:26	2,190,464	-----c---	C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 06:43 . 2008-08-14 14:26	2,146,816	-----c---	C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 06:43 . 2008-08-14 14:26	2,067,328	-----c---	C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 06:43 . 2008-08-14 14:26	2,025,472	-----c---	C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 06:43 . 2008-09-15 16:27	1,846,656	-----c---	C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 06:43 . 2008-09-08 11:41	333,824	-----c---	C:\WINDOWS\system32\dllcache\srv.sys
2008-10-13 19:17 . 2008-10-13 19:17	13,646	--a------	C:\WINDOWS\system32\wpa.bak
2008-10-13 19:06 . 2008-10-13 19:06	<DIR>	d--------	C:\Documents and Settings\LocalService\Pulpit
2008-10-13 17:28 . 2008-10-13 17:28	<DIR>	d--------	C:\WINDOWS\system32\pl
2008-10-13 17:28 . 2008-10-13 17:28	<DIR>	d--------	C:\WINDOWS\system32\bits
2008-10-13 17:28 . 2008-10-13 17:28	<DIR>	d--------	C:\WINDOWS\l2schemas
2008-10-13 17:26 . 2008-10-13 17:26	<DIR>	d--------	C:\WINDOWS\ServicePackFiles
2008-10-13 12:35 . 2008-10-13 12:35	<DIR>	d--------	C:\Program Files\Microsoft.NET
2008-10-13 12:35 . 2003-06-19 00:31	17,920	--a------	C:\WINDOWS\system32\mdimon.dll
2008-10-13 12:35 . 2008-10-13 12:35	421	--a------	C:\WINDOWS\ODBC.INI
2008-10-13 12:34 . 2008-10-13 12:35	<DIR>	d--------	C:\WINDOWS\SHELLNEW
2008-10-13 12:26 . 2008-10-13 17:28	<DIR>	d--------	C:\WINDOWS\system32\pl-pl
2008-10-13 12:26 . 2008-10-03 18:26	6,066,176	-----c---	C:\WINDOWS\system32\dllcache\ieframe.dll
2008-10-13 12:26 . 2007-04-17 10:32	2,455,488	-----c---	C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-10-13 12:26 . 2007-03-08 06:11	1,036,288	-----c---	C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-10-13 12:26 . 2008-08-26 09:26	459,264	-----c---	C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-10-13 12:26 . 2008-08-26 09:26	383,488	-----c---	C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-10-13 12:26 . 2008-08-26 09:26	267,776	-----c---	C:\WINDOWS\system32\dllcache\iertutil.dll
2008-10-13 12:26 . 2008-08-26 09:26	63,488	-----c---	C:\WINDOWS\system32\dllcache\icardie.dll
2008-10-13 12:26 . 2008-08-26 09:26	52,224	-----c---	C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-10-13 12:26 . 2008-08-25 09:38	13,824	-----c---	C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-10-10 12:21 . 2008-10-10 12:21	<DIR>	d--------	C:\Program Files\MSXML 4.0
2008-10-10 08:28 . 2008-10-10 08:28	<DIR>	d--------	C:\Program Files\Common Files\EZB Systems
2008-10-10 08:27 . 2008-10-10 08:28	<DIR>	d--------	C:\Program Files\UltraISO
2008-10-10 08:00 . 2008-10-10 08:11	<DIR>	d--------	C:\Program Files\CubeDesktop
2008-10-10 08:00 . 2008-10-10 08:00	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\Thinking Minds Budiling Bytes
2008-10-10 07:55 . 2008-10-10 07:56	<DIR>	d-a------	C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-10-10 07:47 . 2008-10-10 07:47	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\OtakuSoftware
2008-10-10 07:36 . 2008-10-31 18:51	<DIR>	d--------	C:\Program Files\Mozilla Thunderbird
2008-10-10 07:36 . 2008-10-10 07:36	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\Thunderbird
2008-10-10 07:36 . 2008-10-10 07:36	0	--a------	C:\WINDOWS\nsreg.dat
2008-10-09 22:29 . 2004-05-06 11:11	40,448	--a------	C:\Documents and Settings\Paweł\trial_setup.exe
2008-10-09 22:29 . 2004-05-06 11:11	40,448	--a------	C:\Documents and Settings\Paweł\trial_setup.exe
2008-10-09 22:22 . 2008-10-09 22:22	<DIR>	d--------	C:\Program Files\PowerISO
2008-10-09 20:42 . 2008-10-31 18:47	<DIR>	d--------	C:\Program Files\Kalendarz XP
2008-10-09 20:36 . 2008-10-09 20:36	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\Nero
2008-10-09 20:33 . 2008-10-16 14:15	<DIR>	d--------	C:\Program Files\Common Files\Nero
2008-10-09 20:33 . 2008-10-16 14:15	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\Nero
2008-10-09 20:11 . 2008-05-22 23:22	3,596,288	--a------	C:\WINDOWS\system32\qt-dx331.dll
2008-10-09 20:11 . 2008-07-04 07:34	860,160	--a------	C:\WINDOWS\system32\lameACM.acm
2008-10-09 20:11 . 2008-01-10 13:15	755,027	--a------	C:\WINDOWS\system32\xvidcore.dll
2008-10-09 20:11 . 2008-05-31 00:22	683,520	--a------	C:\WINDOWS\system32\divx.dll
2008-10-09 20:11 . 2004-01-25 17:18	217,088	--a------	C:\WINDOWS\system32\yv12vfw.dll
2008-10-09 20:11 . 2007-09-04 17:56	164,352	--a------	C:\WINDOWS\system32\unrar.dll
2008-10-09 20:11 . 2008-01-10 13:16	159,839	--a------	C:\WINDOWS\system32\xvidvfw.dll
2008-10-09 20:11 . 2007-09-21 01:52	118,784	--a------	C:\WINDOWS\system32\ac3acm.acm
2008-10-09 20:11 . 2008-05-22 23:19	81,920	--a------	C:\WINDOWS\system32\dpl100.dll
2008-10-09 20:11 . 2007-10-03 16:03	414	--a------	C:\WINDOWS\system32\lame_acm.xml
2008-10-09 20:10 . 2008-10-14 23:37	<DIR>	d--------	C:\Program Files\K-Lite Codec Pack
2008-10-09 20:10 . 2004-01-11 23:00	348,160	--a------	C:\WINDOWS\system32\msvcr71.dll
2008-10-09 20:10 . 2008-06-12 19:36	7,680	--a------	C:\WINDOWS\system32\ff_vfw.dll
2008-10-09 20:10 . 2007-07-10 17:10	547	--a------	C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-10-09 20:08 . 2008-10-14 23:40	<DIR>	d--------	C:\Program Files\NAPI-PROJEKT
2008-10-09 20:08 . 2008-10-14 23:38	<DIR>	d--------	C:\Program Files\ALLPlayer
2008-10-09 16:59 . 2008-10-09 16:59	<DIR>	d---s----	C:\Documents and Settings\Paweł\UserData
2008-10-09 16:59 . 2008-10-09 16:59	<DIR>	d---s----	C:\Documents and Settings\Paweł\UserData
2008-10-09 16:44 . 2008-10-09 16:44	<DIR>	d--------	C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar
2008-10-09 16:44 . 2008-10-09 16:44	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar
2008-10-09 16:43 . 2008-10-09 16:47	<DIR>	d--------	C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>
2008-10-09 16:43 . 2008-10-09 16:47	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>
2008-10-09 16:41 . 2008-10-31 18:31	<DIR>	d--------	C:\Program Files\ESET
2008-10-09 16:41 . 2008-10-09 16:41	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\ESET
2008-10-09 15:29 . 2006-06-27 04:40	12,800	-----c---	C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-10-09 15:29 . 2006-06-27 04:40	3,584	-----c---	C:\WINDOWS\system32\dllcache\WgaLogon.dll
2008-10-09 15:11 . 2004-08-03 23:35	701,440	---------	C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-10-09 15:06 . 2008-04-11 20:06	691,712	-----c---	C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-10-09 15:06 . 2008-06-14 18:36	273,024	---------	C:\WINDOWS\system32\drivers\bthport.sys
2008-10-09 15:06 . 2008-06-14 18:36	273,024	-----c---	C:\WINDOWS\system32\dllcache\bthport.sys
2008-10-09 15:06 . 2008-05-08 15:02	203,136	-----c---	C:\WINDOWS\system32\dllcache\rmcast.sys
2008-10-09 14:58 . 2008-10-09 14:58	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\Gadu-Gadu
2008-10-09 14:57 . 2008-10-09 14:57	<DIR>	d--------	C:\Program Files\Gadu-Gadu
2008-10-09 14:57 . 2008-10-09 14:58	<DIR>	d--------	C:\Documents and Settings\Paweł\Gadu-Gadu
2008-10-09 14:57 . 2008-10-09 14:58	<DIR>	d--------	C:\Documents and Settings\Paweł\Gadu-Gadu
2008-10-09 14:51 . 2008-10-09 14:51	<DIR>	d--------	C:\Program Files\Opera
2008-10-09 13:57 . 2008-10-09 13:57	940,794	--a------	C:\WINDOWS\system32\LoopyMusic.wav
2008-10-09 13:57 . 2008-10-09 13:57	146,650	--a------	C:\WINDOWS\system32\BuzzingBee.wav
2008-10-09 13:56 . 2007-12-19 10:11	180,224	-ra------	C:\WINDOWS\system32\igfxres.dll
2008-10-09 13:54 . 2008-10-09 13:54	<DIR>	d--------	C:\WINDOWS\OPTIONS
2008-10-09 13:54 . 2008-10-09 13:54	<DIR>	d--------	C:\Documents and Settings\Paweł\Dane aplikacji\InstallShield
2008-10-09 13:54 . 2007-11-14 14:18	553	-r-------	C:\WINDOWS\USetup.iss
2008-10-09 13:52 . 2008-10-09 13:52	<DIR>	d--------	C:\Program Files\Realtek
2008-10-09 13:52 . 2008-10-20 17:16	<DIR>	d--h-----	C:\Program Files\InstallShield Installation Information
2008-10-09 13:52 . 2008-10-15 21:23	<DIR>	d--------	C:\Program Files\Common Files\InstallShield
2008-10-07 13:00 . 2008-04-13 19:45	32,128	--a------	C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-07 13:00 . 2008-04-14 18:20	21,504	--a------	C:\WINDOWS\system32\hidserv.dll
2008-10-07 13:00 . 2008-04-14 17:20	14,720	--a------	C:\WINDOWS\system32\drivers\kbdhid.sys

.
((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-09 12:52	315,392	----a-w	C:\WINDOWS\HideWin.exe
2008-10-07 11:49	---------	d-----w	C:\Program Files\microsoft frontpage
2008-10-07 11:48	---------	d-----w	C:\Program Files\Usługi online
2008-09-15 15:27	1,846,656	----a-w	C:\WINDOWS\system32\win32k.sys
2008-09-15 15:27	1,846,656	----a-w	C:\WINDOWS\system32\win32k(2).sys
2008-09-08 10:41	333,824	----a-w	C:\WINDOWS\system32\drivers\srv.sys
2008-08-26 08:27	826,368	----a-w	C:\WINDOWS\system32\wininet.dll
2008-08-14 13:26	2,146,816	----a-w	C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:26	2,025,472	----a-w	C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-21 22:14	9,728	----a-r	C:\WINDOWS\system32\RtNicProp32.dll
2008-07-18 20:10	94,920	----a-w	C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10	53,448	----a-w	C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10	45,768	----a-w	C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10	36,552	----a-w	C:\WINDOWS\system32\wups.dll
2008-07-18 20:09	563,912	----a-w	C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09	325,832	----a-w	C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09	205,000	----a-w	C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09	1,811,656	----a-w	C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:29	253,952	----a-w	C:\WINDOWS\system32\es.dll
2008-07-03 14:51	16,876,032	------r	C:\WINDOWS\RTHDCPL.exe
.

(((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane 
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\winamptb.dll" [2008-07-16 1266992]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-09-23 21755688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-19 131072]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>Agent"="C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>\winampa.exe" [2008-08-04 36352]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-03 C:\WINDOWS\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Kalendarz XP.lnk - C:\Program Files\Kalendarz XP\Kalendarz.exe [2008-10-09 882176]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Opera\\opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"E:\\pes\\PES2008.exe"=
"C:\\Program Files\\Miranda IM\\miranda32.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-07-01 34312]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}]
C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\lin32.exe
.
- - - - USUNIĘTO PUSTE WPISY - - - -

HKCU-Run-DeskSpace - C:\Program Files\DeskSpace\deskspace.exe
HKCU-Run-Komunikator - C:\Program Files\Tlen.pl\tlen.exe
HKCU-Run-CubeDesktop - (no file)


.
------- Skan uzupełniający -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.pl/
O8 -: &<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Search - C:\Documents and Settings\All Users\Dane aplikacji\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\ieToolbar\resources\en-US\local\search.html
O8 -: E&ksport do programu Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-31 19:06:39
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ... 

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ... 

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************
.
Czas ukończenia: 2008-10-31 19:07:18
ComboFix-quarantined-files.txt  2008-10-31 18:07:16

Przed: 11,244,982,272 bajtów wolnych
Po: 12,368,084,992 bajtów wolnych

225	--- E O F ---	2008-10-26 22:19:46


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:09:50, on 2008-10-31
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>\winampa.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Kalendarz XP\Kalendarz.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Opera\Opera\profile\cache4\temporary_download\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: <a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\winamptb.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: <a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\winamptb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: <a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\winamptb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>Agent] "C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>\winampa.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Kalendarz XP.lnk = C:\Program Files\Kalendarz XP\Kalendarz.exe
O8 - Extra context menu item: &<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Search - C:\Documents and Settings\All Users\Dane aplikacji\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

--
End of file - 5861 bytes