Elektroda.pl
Elektroda.pl
X
Proszę, dodaj wyjątek www.elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

asghost.exe czy to jakis wirus?

..::MISIEK::.. 21 Sie 2007 08:44 13356 5
  • #1 21 Sie 2007 08:44
    ..::MISIEK::..
    Poziom 13  

    Witam.
    Od jakiegoś czasu w procesach systemowych widnieje asghost.exe.
    Czy to jakiś wir? Daje loga z ComboFixa


    Code:
    ComboFix 07-08-17.2 - "Just" 2007-08-21  8:08:58.1 - NTFSx86 
    
    Microsoft Windows XP Professional  5.1.2600.2.1250.1.1045.18.577 [GMT 2:00]
     * Created a new restore point


    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\DOCUME~1\Just\DANEAP~1.\crosof~1.net
    C:\DOCUME~1\Just\DANEAP~1.\crosof~1.net\??crosoft.NET\
    C:\DOCUME~1\Just\DANEAP~1.\crosof~1.net\nslookup.exe
    C:\DOCUME~1\Just\MENUST~1\Programy.\Outerinfo
    C:\DOCUME~1\Just\MENUST~1\Programy.\Outerinfo\Terms.lnk
    C:\DOCUME~1\Just\MENUST~1\Programy.\Outerinfo\Uninstall.lnk
    C:\DOCUME~1\Just\MOJEDO~1.\icroso~1
    C:\Program Files\outerinfo
    C:\Program Files\outerinfo\Terms.rtf
    C:\Program Files\ymante~1
    C:\Program Files\ymante~1\?ttrib.exe
    C:\WINDOWS\scurit~1
    C:\WINDOWS\system32\7_exception.nls
    C:\WINDOWS\system32\drivers\ip6fw.sys
    C:\WINDOWS\system32\drivers\runtime2.sys
    C:\WINDOWS\system32\koos.exe
    C:\WINDOWS\system32\kprof
    C:\WINDOWS\system32\layit.dll
    C:\WINDOWS\system32\poof
    C:\WINDOWS\system32\rpcc.dll
    C:\WINDOWS\system32\winubg32.dll
    E:\Autorun.inf


    (((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))


    -------\LEGACY_POOF
    -------\LEGACY_RUNTIME
    -------\LEGACY_RUNTIME2
    -------\runtime


    (((((((((((((((((((((((((   Files Created from 2007-07-21 to 2007-08-21  )))))))))))))))))))))))))))))))


    2007-08-21 08:10   2   --a------   C:\WINDOWS\system32\wnstsisv.exe




    2007-08-21 08:09   40,183   ---hs----   C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
    2007-08-21 08:07   51,200   --a------   C:\WINDOWS\nircmd.exe
    2007-08-20 12:09   94,424   --a------   C:\WINDOWS\system32\drivers\aswmon2.sys
    2007-08-20 12:09   90,112   --a------   C:\WINDOWS\system32\AVASTSS.scr
    2007-08-20 12:09   85,952   --a------   C:\WINDOWS\system32\drivers\aswmon.sys
    2007-08-20 12:09   689,280   --a------   C:\WINDOWS\system32\aswBoot.exe
    2007-08-20 12:09   43,176   --a------   C:\WINDOWS\system32\drivers\aswTdi.sys
    2007-08-20 12:09   31,560   --a------   C:\WINDOWS\system32\drivers\aavmker4.sys
    2007-08-20 12:09   23,352   --a------   C:\WINDOWS\system32\drivers\aswRdr.sys
    2007-08-20 12:09   <DIR>   d--------   C:\Program Files\Alwil Software
    2007-08-20 11:55   <DIR>   d--------   C:\Program Files\CA
    2007-08-20 11:50   <DIR>   d--------   C:\Program Files\Microsoft Windows Small Business Server
    2007-08-20 11:50   <DIR>   d--------   C:\DOCUME~1\Filoda\DANEAP~1\Teleca
    2007-08-20 11:50   <DIR>   d--------   C:\DOCUME~1\Filoda\DANEAP~1\Sony Ericsson
    2007-08-20 11:50   <DIR>   d--------   C:\DOCUME~1\Filoda\DANEAP~1\LG Electronics
    2007-08-20 11:49   1,048,576   --ah-----   C:\DOCUME~1\Filoda\NTUSER.DAT
    2007-08-20 11:49   <DIR>   dr-h-----   C:\DOCUME~1\Filoda\Dane aplikacji
    2007-08-20 11:49   <DIR>   dr-------   C:\DOCUME~1\Filoda\Ulubione
    2007-08-20 11:49   <DIR>   dr-------   C:\DOCUME~1\Filoda\Moje dokumenty
    2007-08-20 11:49   <DIR>   dr-------   C:\DOCUME~1\Filoda\Menu Start
    2007-08-20 11:49   <DIR>   d--h-----   C:\DOCUME~1\Filoda\Ustawienia lokalne
    2007-08-20 11:49   <DIR>   d--h-----   C:\DOCUME~1\Filoda\Szablony
    2007-08-20 11:49   <DIR>   d--------   C:\DOCUME~1\Filoda\Pulpit
    2007-08-20 11:49   <DIR>   d--------   C:\DOCUME~1\Filoda\DANEAP~1\SampleView
    2007-08-20 11:41   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\DANEAP~1\Teleca
    2007-08-20 11:40   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\DANEAP~1\Sony Ericsson
    2007-08-20 11:40   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\DANEAP~1\LG Electronics
    2007-08-20 11:39   1,048,576   --ah-----   C:\DOCUME~1\JUST~1.MET\NTUSER.DAT
    2007-08-20 11:39   <DIR>   dr-h-----   C:\DOCUME~1\JUST~1.MET\Dane aplikacji
    2007-08-20 11:39   <DIR>   dr-------   C:\DOCUME~1\JUST~1.MET\Ulubione
    2007-08-20 11:39   <DIR>   dr-------   C:\DOCUME~1\JUST~1.MET\Moje dokumenty
    2007-08-20 11:39   <DIR>   dr-------   C:\DOCUME~1\JUST~1.MET\Menu Start
    2007-08-20 11:39   <DIR>   d--hs----   C:\WINDOWS\CSC
    2007-08-20 11:39   <DIR>   d--h-----   C:\DOCUME~1\JUST~1.MET\Ustawienia lokalne
    2007-08-20 11:39   <DIR>   d--h-----   C:\DOCUME~1\JUST~1.MET\Szablony
    2007-08-20 11:39   <DIR>   d--------   C:\WINDOWS\SchCache
    2007-08-20 11:39   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\Pulpit
    2007-08-20 11:39   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\DANEAP~1\SampleView
    2007-08-20 09:21   <DIR>   d--------   C:\Program Files\SkanerOnline
    2007-08-17 12:31   442,368   --a------   C:\WINDOWS\system32\Kopia sqlsrv32.dll
    2007-08-14 14:32   <DIR>   d--h-----   C:\WINDOWS\system32\GroupPolicy
    2007-08-14 12:54   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\Microsoft Games
    2007-08-13 08:14   <DIR>   d--------   C:\Program Files\XML Notepad 2007
    2007-08-12 22:54   <DIR>   d--h-----   C:\LGFolder
    2007-08-12 22:45   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\LG Electronics
    2007-08-12 22:42   <DIR>   d--------   C:\Program Files\LG PC Suite
    2007-08-12 22:39   39,248   --a------   C:\WINDOWS\system32\drivers\lgusbmodem.sys
    2007-08-12 22:39   38,144   --a------   C:\WINDOWS\system32\drivers\lgusbdiag.sys
    2007-08-12 22:39   21,344   --a------   C:\WINDOWS\system32\drivers\lgusbbus.sys
    2007-08-12 22:39   <DIR>   d--------   C:\Program Files\LG Electronics
    2007-08-09 14:54   <DIR>   d--------   C:\Program Files\SystemRequirementsLab
    2007-08-06 18:14   <DIR>   d--------   C:\DOCUME~1\ALLUSE~1\DANEAP~1\Age of Empires 3
    2007-08-06 18:12   443,752   --a------   C:\WINDOWS\system32\d3dx10_34.dll
    2007-08-06 18:12   3,497,832   --a------   C:\WINDOWS\system32\d3dx9_34.dll
    2007-08-06 18:12   266,088   --a------   C:\WINDOWS\system32\xactengine2_8.dll
    2007-08-06 18:12   18,280   --a------   C:\WINDOWS\system32\x3daudio1_2.dll
    2007-08-06 18:12   1,124,720   --a------   C:\WINDOWS\system32\D3DCompiler_34.dll
    2007-08-06 18:11   443,752   --a------   C:\WINDOWS\system32\d3dx10_33.dll
    2007-08-06 18:11   3,495,784   --a------   C:\WINDOWS\system32\d3dx9_33.dll
    2007-08-06 18:11   261,480   --a------   C:\WINDOWS\system32\xactengine2_7.dll
    2007-08-06 18:11   255,848   --a------   C:\WINDOWS\system32\xactengine2_6.dll
    2007-08-06 18:11   1,123,696   --a------   C:\WINDOWS\system32\D3DCompiler_33.dll
    2007-08-06 18:06   <DIR>   d--------   C:\Program Files\Microsoft Games
    2007-08-06 10:09   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\Ulead Systems
    2007-08-06 10:04   <DIR>   d--------   C:\Program Files\Common Files\InterVideo
    2007-08-06 10:04   <DIR>   d--------   C:\DOCUME~1\ALLUSE~1\DANEAP~1\InterVideo
    2007-08-06 10:03   <DIR>   d--------   C:\Program Files\Common Files\LightScribe
    2007-08-06 09:59   <DIR>   d--------   C:\Program Files\Ulead Systems
    2007-08-06 09:59   <DIR>   d--------   C:\Program Files\Common Files\Ulead Systems
    2007-08-06 09:59   <DIR>   d--------   C:\DOCUME~1\ALLUSE~1\DANEAP~1\Ulead Systems
    2007-08-06 09:49   <DIR>   d--------   C:\Program Files\PowerISO
    2007-08-01 14:35   <DIR>   d--------   C:\Program Files\RAR Password Cracker
    2007-08-01 13:32   <DIR>   d-a------   C:\DOCUME~1\ALLUSE~1\DANEAP~1\TEMP
    2007-08-01 13:32   <DIR>   d--------   C:\Program Files\Your Uninstaller 2006
    2007-08-01 13:32   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\URSoft
    2007-08-01 08:10   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\Password Manager
    2007-07-31 21:07   15,872   --a------   C:\WINDOWS\system32\drivers\vd_filedisk.sys
    2007-07-31 21:07   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\HEXelon
    2007-07-30 09:14   <DIR>   d--------   C:\Program Files\Lavalys
    2007-07-26 17:43   110,592   --a------   C:\WINDOWS\system32\ccrpbds6.dll
    2007-07-26 17:43   <DIR>   d--------   C:\Program Files\PIXresizer
    2007-07-26 17:41   <DIR>   d--------   C:\Program Files\DCE AutoEnhance
    2007-07-26 07:30   <DIR>   d--------   C:\download
    2007-07-25 07:32   <DIR>   d--------   C:\Program Files\TC UP
    2007-07-25 07:17   <DIR>   d--------   C:\tc.v7.01
    2007-07-24 12:07   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\AdobeUM
    2007-07-24 11:41   3,426,072   --a------   C:\WINDOWS\system32\d3dx9_32.dll
    2007-07-24 11:41   251,672   --a------   C:\WINDOWS\system32\xactengine2_5.dll
    2007-07-24 07:48   <DIR>   d--------   C:\TotalCmd
    2007-07-23 07:57   85,408   -ra------   C:\WINDOWS\system32\drivers\k510mgmt.sys
    2007-07-23 07:57   83,344   -ra------   C:\WINDOWS\system32\drivers\k510obex.sys
    2007-07-23 07:46   155,648   --a------   C:\WINDOWS\system32\libssl32.dll
    2007-07-22 11:58   <DIR>   d--------   C:\WINDOWS\speech
    2007-07-22 00:46   <DIR>   d--------   C:\Program Files\MarBit


    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-08-20 13:35   ---------   d--------   C:\Program Files\DAEMON Tools SearchBar
    2007-08-16 09:06   ---------   d--------   C:\Program Files\ivo
    2007-08-16 09:06   ---------   d--------   C:\Program Files\Digital Red
    2007-08-14 12:52   ---------   d--------   C:\Program Files\Winamp
    2007-08-14 07:36   769   --ahs----   C:\WINDOWS\system32\mmf.sys
    2007-08-13 22:35   ---------   d--h-----   C:\Program Files\InstallShield Installation Information
    2007-08-06 10:03   ---------   d--------   C:\Program Files\DivX
    2007-08-05 21:48   ---------   d--------   C:\Program Files\RM Converter
    2007-08-05 19:43   ---------   d--------   C:\Program Files\Ultra RM Converter
    2007-08-01 10:22   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\DivX
    2007-07-23 07:58   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Teleca
    2007-07-22 00:48   ---------   d--------   C:\Program Files\DVDlabPro2
    2007-07-20 14:52   ---------   d--------   C:\Program Files\RegDoctor
    2007-07-20 14:09   903238   --a------   C:\WINDOWS\IVO Glossary Uninstaller.exe
    2007-07-20 12:28   ---------   d--------   C:\Program Files\RapGet
    2007-07-20 08:24   ---------   d--------   C:\Program Files\CyberLink
    2007-07-19 12:39   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Media Player Classic
    2007-07-19 08:58   3583488   --a------   C:\WINDOWS\system32\dllcache\mshtml.dll
    2007-07-18 23:39   ---------   d--------   C:\Program Files\CDex_150b6
    2007-07-17 13:08   8464   --a------   C:\WINDOWS\system32\sporder.dll
    2007-07-17 10:22   1700352   --a------   C:\WINDOWS\system32\gdiplus.dll
    2007-07-17 09:00   ---------   d--------   C:\Program Files\Common Files\WhenU
    2007-07-17 08:56   ---------   d--------   C:\Program Files\Alcohol Soft
    2007-07-17 08:55   685816   --a------   C:\WINDOWS\system32\drivers\sptd.sys
    2007-07-17 08:03   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Ahead
    2007-07-17 07:24   ---------   d--------   C:\Program Files\Super DVD Creator 9.30
    2007-07-17 07:18   ---------   d--------   C:\Program Files\UltraISO
    2007-07-17 07:18   ---------   d--------   C:\Program Files\Common Files\EZB Systems
    2007-07-17 01:32   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Digital Red
    2007-07-16 23:33   ---------   d--------   C:\Program Files\Project Zoo
    2007-07-16 23:22   26   --a------   C:\WINDOWS\winstart.bat
    2007-07-16 23:22   123   --a------   C:\WINDOWS\tmpcpyis.bat
    2007-07-16 23:22   122   --a------   C:\WINDOWS\tmpdelis.bat
    2007-07-16 17:23   ---------   d--------   C:\Program Files\PowerArchiver
    2007-07-16 17:21   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\WinRAR
    2007-07-16 14:30   ---------   d--------   C:\Program Files\Proxy Switcher Standard
    2007-07-16 14:24   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\WNR
    2007-07-16 00:32   ---------   d--------   C:\Program Files\Mplayer
    2007-07-16 00:05   ---------   d--------   C:\Program Files\Common Files\Ahead
    2007-07-16 00:05   ---------   d--------   C:\Program Files\Ahead
    2007-07-15 00:10   ---------   d--------   C:\Program Files\Sierra
    2007-07-15 00:05   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\InstallShield
    2007-07-14 23:54   86016   --a------   C:\WINDOWS\system32\OpenAL32.dll
    2007-07-14 23:54   413696   --a------   C:\WINDOWS\system32\wrap_oal.dll
    2007-07-14 23:50   ---------   d--------   C:\Program Files\ND Games
    2007-07-14 23:45   108144   --a------   C:\WINDOWS\system32\CmdLineExt.dll
    2007-07-14 23:45   ---------   dr-h-----   C:\DOCUME~1\Just\DANEAP~1\SecuROM
    2007-07-14 23:38   ---------   d--------   C:\Program Files\PlayLogic
    2007-07-14 23:37   ---------   d--------   C:\Program Files\OpenAL
    2007-07-13 01:32   765952   --a------   C:\WINDOWS\system32\dllcache\vgx.dll
    2007-07-12 10:49   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\.BitTornado
    2007-07-11 23:40   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Ankh
    2007-07-11 23:04   48640   --a------   C:\WINDOWS\mmfs.dll
    2007-07-11 13:50   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Real
    2007-07-11 12:47   ---------   d--------   C:\Program Files\ElcomSoft
    2007-07-11 11:34   ---------   d--------   C:\Program Files\Passware
    2007-07-11 01:11   ---------   d--------   C:\Program Files\MSXML 4.0
    2007-07-11 00:43   ---------   d--------   C:\Program Files\Team6
    2007-07-11 00:42   ---------   d--------   C:\Program Files\Barrel Mania
    2007-07-10 19:09   ---------   d--------   C:\Program Files\Project IGI
    2007-07-10 11:40   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\vlc
    2007-07-10 11:39   ---------   d--------   C:\Program Files\VideoLAN
    2007-07-10 09:53   ---------   d--------   C:\Program Files\BitComet
    2007-07-10 08:56   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Gadu-Gadu
    2007-07-10 08:28   54313   --a------   C:\Program Files\tor-bundle-uninstall.exe
    2007-07-10 08:03   ---------   d--------   C:\Program Files\Gadu-Gadu
    2007-07-10 07:45   ---------   d--------   C:\Program Files\K-Lite Codec Pack
    2007-07-10 07:14   ---------   d--------   C:\Program Files\INTERIAPL
    2007-07-09 21:58   ---------   d--h-----   C:\Program Files\WindowsUpdate
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Windows NT
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Windows Media Connect
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Synaptics
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Sonic
    2007-07-09 21:58   ---------   d--------   C:\Program Files\MSN Gaming Zone
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Movie Maker
    2007-07-09 21:58   ---------   d--------   C:\Program Files\microsoft frontpage
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Messenger
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Hp
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Hewlett-Packard
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Fingerprint Sensor
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\TiVo Shared
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\SureThing Shared
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\SpeechEngines
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\Sonic Shared
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\ODBC
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\MSSoap
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\InstallShield
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Analog Devices
    2007-07-09 21:57   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\SampleView
    2007-07-09 21:55   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\InterVideo
    2007-07-09 20:33   ---------   d--------   C:\Program Files\Codemasters
    2007-07-09 20:16   21840   --a------   C:\WINDOWS\system32\SIntfNT.dll
    2007-07-09 20:16   17212   --a------   C:\WINDOWS\system32\SIntf32.dll
    2007-07-09 20:16   12067   --a------   C:\WINDOWS\system32\SIntf16.dll
    2007-07-09 19:57   ---------   d--------   C:\Program Files\directx
    2007-07-09 17:50   ---------   d--------   C:\Program Files\Common Files\Teleca Shared
    2007-07-09 17:49   ---------   d--------   C:\Program Files\Sony Ericsson
    2007-07-09 17:49   ---------   d--------   C:\Program Files\Common Files\Sony Ericsson Shared
    2007-07-09 17:49   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Sony Ericsson
    2007-07-09 15:56   ---------   d--------   C:\Program Files\Neostrada TP


    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
     
     
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MsmqIntCert"="regsvr32 /s mqrt.dll" []
    "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 10:11]
    "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-05-06 14:06]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
    "PTHOSTTR"="C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.exe" [2006-02-14 11:56]
    "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
    "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-08-31 05:20]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-10 20:04]
    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 14:17]
    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 14:13]
    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 14:17]
    "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 10:49]
    "CognizanceTS"="C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 20:12]
    "QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-02 15:39]
    "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2006-02-22 08:03]
    "Recguard"="C:\WINDOWS\Sminst\Recguard.exe" [2005-12-20 15:51]
    "Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" [2006-01-23 16:11]
    "Scheduler"="C:\WINDOWS\SMINST\Scheduler.exe" [2006-02-15 15:43]
    "WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2005-11-08 11:59]
    "NWTRAY"="NWTRAY.EXE" [2002-03-12 11:37 C:\WINDOWS\system32\nwtray.exe]
    "Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" []
    "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-05-28 10:14]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
    "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 16:24]
    "LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 16:21]
    "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 14:23]
    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-01-15 18:28]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:00]
    "Twdw"="C:\DOCUME~1\Just\DANEAP~1\CROSOF~1.NET\nslookup.exe" []
    "Ahgnaeqo"="C:\Program Files\?ymantec\?ttrib.exe" []

    C:\Documents and Settings\Just\Menu Start\Programy\Autostart\
    PowerReg Scheduler V3.exe [2007-07-09 19:56:33]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "CompatibleRUPSecurity"=1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoWelcomeScreen"=1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
    C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll 2005-07-25 20:41 40960 C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"= msv1_0 nwv1_0
    "Notification Packages"= scecli AsWlnPkg

    R0 NICM;Program obsługi komunikacji między usługami firmy Novell;C:\WINDOWS\system32\drivers\nicm.sys
    R0 NWFILTER;Filtr ścieżki UNC firmy Novell;C:\WINDOWS\system32\NetWare\nwfilter.sys
    R1 ISODrive;ISO DVD/CD-ROM Device Driver;\??\C:\Program Files\UltraISO\drivers\ISODrive.sys
    R1 VD_FileDisk;VD_FileDisk;C:\WINDOWS\system32\drivers\VD_FileDisk.sys
    R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};\??\C:\Program Files\CyberLink\PowerDVD\000.fcl
    R2 ASChannel;Local Communication Channel;C:\WINDOWS\System32\svchost.exe -k Cognizance
    R2 MSMQ;Message Queuing;C:\WINDOWS\system32\mqsvc.exe
    R2 MSMQTriggers;Message Queuing Triggers;C:\WINDOWS\system32\mqtgsvc.exe
    R2 NetwareWorkstation;Klient Novell dla systemu Windows;C:\WINDOWS\system32\NetWare\nwfs.sys
    R2 NWDHCP;Klient protokołu DHCP firmy Novell;C:\WINDOWS\system32\NetWare\nwdhcp.sys
    R2 RESMGR;Menedżer zasobów firmy Novell NetWare;C:\WINDOWS\system32\NetWare\resmgr.sys
    R2 SRVLOC;Lokalizacja usługi Novell;C:\WINDOWS\system32\NetWare\srvloc.sys
    R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys
    R3 HBtnKey;HBtnKey;C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
    R3 MQAC;Message Queuing access control;\??\C:\WINDOWS\system32\drivers\mqac.sys
    R3 NWDNS;Moduł obsługi przestrzeni nazw serwera DNS firmy Novell;C:\WINDOWS\system32\NetWare\nwdns.sys
    R3 NWHOST;Moduł obsługi przestrzeni nazw plików hosta firmy Novell;C:\WINDOWS\system32\NetWare\NWHOST.sys
    R3 NWSLP;Moduł obsługi przestrzeni nazw SLP firmy Novell;C:\WINDOWS\system32\NetWare\nwslp.sys
    R3 NWSNS;Proste usługi nazewnicze firmy Novell;C:\WINDOWS\system32\NetWare\NWSNS.sys
    R3 RMCAST;Reliable Multicast Protocol driver;\??\C:\WINDOWS\system32\drivers\RMCast.sys
    S2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe
    S2 LogWatch;Event Log Watch;"C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe"
    S2 NWSIPX32;Interfejs transportowy IPX/SPX firmy Novell NetWare;C:\WINDOWS\system32\NetWare\nwsipx32.sys
    S3 CA_LIC_CLNT;CA License Client;"C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe"
    S3 CA_LIC_SRVR;CA License Server;"C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe"
    S3 cusrvc;Client Update Service for Novell;C:\WINDOWS\system32\cusrvc.exe
    S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys
    S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k510mdfl.sys
    S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\k510mdm.sys
    S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\k510mgmt.sys
    S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys
    S3 NWSAP;Moduł obsługi przestrzeni nazw SAP firmy Novell;C:\WINDOWS\system32\NetWare\NWSAP.sys

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    Cognizance   ASChannel


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480


    **************************************************************************

    catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-08-21 08:14:13
    Windows 5.1.2600 Dodatek Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ????g??????(?@???????@

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    Completion time: 2007-08-21  8:15:32 - machine was rebooted
    C:\ComboFix-quarantined-files.txt ... 2007-08-21 08:15

       --- E O F ---



    Poprawiłam temat postu oraz sam post.
    Proszę nie używać wielokrotnie ??, to na prawdę nie są ozdobniki.
    Proszę pisać zgodnie z zasadami ortografii i interpunkcji języka polskiego.
    Zdanie rozpoczynamy z dużej litery i kończymy kropką.
    Dziękuję.
    charm_spider

    0 5
  • #2 21 Sie 2007 08:56
    *mondzio*
    Poziom 30  

    A to nie jest przypadkiem jakiś proces z urządzenia drukarki
    Hewlett-Packard jaką masz zainstalowaną

    0
  • #3 21 Sie 2007 09:07
    ..::MISIEK::..
    Poziom 13  

    Nie mam drukarki mam laptopa HP.

    0
  • #4 21 Sie 2007 10:31
    Kolobos
    Spec od komputerów

    Masz cala mase trojanow (wiekszosc i tak juz usunal combofix), a Twoja uwage zrwocil normalny program heh...

    Pierwszy lepszy link z google:
    http://www.processlibrary.com/directory/files/asghost

    Do tego na E masz resztki infekcji z pendrive'a.

    Wklej do notatnika to:
    REGEDIT4

    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Realtime Monitor"=-

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Twdw"=-
    "Ahgnaeqo"=-

    Zapisz jako fix.reg i uruchom.

    Usuwasz z autostartu:
    C:\Documents and Settings\Just\Menu Start\Programy\Autostart\
    PowerReg Scheduler V3.exe [2007-07-09 19:56:33]

    Z dysku usun te pliki i katalogi:
    C:\WINDOWS\system32\wnstsisv.exe
    C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
    C:\Program Files\CA <- odinsaluj CA
    C:\Program Files\MarBit
    C:\Program Files\DAEMON Tools SearchBar
    C:\WINDOWS\system32\mmf.sys
    C:\Program Files\Common Files\WhenU
    C:\WINDOWS\winstart.bat
    C:\WINDOWS\tmpcpyis.bat
    C:\WINDOWS\tmpdelis.bat
    C:\Program Files\tor-bundle-uninstall.exe

    Zrob tez skan przy pomocy SuperAntiSpyware, po wszystkim daj w ZALACZNIKU nowy log z combofix oraz hijackthis.

    0
  • #5 21 Sie 2007 12:55
    ..::MISIEK::..
    Poziom 13  

    Om tak zrobie
    Dziekuje

    Dodano po 43 [minuty]:

    Log z ComboFix'a

    Code:
    ComboFix 07-08-17.2 - "Just" 2007-08-21 12:20:52.2 - NTFSx86 
    
    Microsoft Windows XP Professional  5.1.2600.2.1250.48.1045.18.592 [GMT 2:00]


    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\Program Files\Common Files\Yazzle1162OinAdmin.exe


    (((((((((((((((((((((((((   Files Created from 2007-07-21 to 2007-08-21  )))))))))))))))))))))))))))))))


    2007-08-21 11:56   <DIR>   d--------   C:\Program Files\SUPERAntiSpyware
    2007-08-21 11:56   <DIR>   d--------   C:\Program Files\Common Files\Wise Installation Wizard
    2007-08-21 11:56   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\SUPERAntiSpyware.com
    2007-08-21 11:56   <DIR>   d--------   C:\DOCUME~1\ALLUSE~1\DANEAP~1\SUPERAntiSpyware.com
    2007-08-21 10:31   36,864   --a------   C:\WINDOWS\RmvDir.exe
    2007-08-21 10:31   24,152   --a------   C:\WINDOWS\system32\drivers\ino_flpy.sys
    2007-08-21 10:31   155,992   --a------   C:\WINDOWS\system32\drivers\ino_fltr.sys
    2007-08-21 10:26   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\DANEAP~1\URSoft
    2007-08-21 10:08   <DIR>   d--------   C:\Program Files\CA
    2007-08-21 09:39   <DIR>   d--------   C:\Program Files\RFA Platinum
    2007-08-21 09:39   <DIR>   d--------   C:\DOCUME~1\ALLUSE~1\DANEAP~1\RFA_Backups
    2007-08-21 08:22   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\Uniblue
    2007-08-21 08:07   51,200   --a------   C:\WINDOWS\nircmd.exe
    2007-08-20 12:09   <DIR>   d--------   C:\Program Files\Alwil Software
    2007-08-20 11:50   <DIR>   d--------   C:\Program Files\Microsoft Windows Small Business Server
    2007-08-20 11:50   <DIR>   d--------   C:\DOCUME~1\Filoda\DANEAP~1\Teleca
    2007-08-20 11:50   <DIR>   d--------   C:\DOCUME~1\Filoda\DANEAP~1\Sony Ericsson
    2007-08-20 11:50   <DIR>   d--------   C:\DOCUME~1\Filoda\DANEAP~1\LG Electronics
    2007-08-20 11:49   1,048,576   --ah-----   C:\DOCUME~1\Filoda\NTUSER.DAT
    2007-08-20 11:49   <DIR>   dr-h-----   C:\DOCUME~1\Filoda\Dane aplikacji
    2007-08-20 11:49   <DIR>   dr-------   C:\DOCUME~1\Filoda\Ulubione
    2007-08-20 11:49   <DIR>   dr-------   C:\DOCUME~1\Filoda\Moje dokumenty
    2007-08-20 11:49   <DIR>   dr-------   C:\DOCUME~1\Filoda\Menu Start
    2007-08-20 11:49   <DIR>   d--h-----   C:\DOCUME~1\Filoda\Ustawienia lokalne
    2007-08-20 11:49   <DIR>   d--h-----   C:\DOCUME~1\Filoda\Szablony
    2007-08-20 11:49   <DIR>   d--------   C:\DOCUME~1\Filoda\Pulpit
    2007-08-20 11:49   <DIR>   d--------   C:\DOCUME~1\Filoda\DANEAP~1\SampleView
    2007-08-20 11:41   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\DANEAP~1\Teleca
    2007-08-20 11:40   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\DANEAP~1\Sony Ericsson
    2007-08-20 11:40   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\DANEAP~1\LG Electronics
    2007-08-20 11:39   1,310,720   --ah-----   C:\DOCUME~1\JUST~1.MET\NTUSER.DAT
    2007-08-20 11:39   <DIR>   dr-h-----   C:\DOCUME~1\JUST~1.MET\Dane aplikacji
    2007-08-20 11:39   <DIR>   dr-------   C:\DOCUME~1\JUST~1.MET\Ulubione
    2007-08-20 11:39   <DIR>   dr-------   C:\DOCUME~1\JUST~1.MET\Moje dokumenty
    2007-08-20 11:39   <DIR>   dr-------   C:\DOCUME~1\JUST~1.MET\Menu Start
    2007-08-20 11:39   <DIR>   d--hs----   C:\WINDOWS\CSC
    2007-08-20 11:39   <DIR>   d--h-----   C:\DOCUME~1\JUST~1.MET\Ustawienia lokalne
    2007-08-20 11:39   <DIR>   d--h-----   C:\DOCUME~1\JUST~1.MET\Szablony
    2007-08-20 11:39   <DIR>   d--------   C:\WINDOWS\SchCache
    2007-08-20 11:39   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\Pulpit
    2007-08-20 11:39   <DIR>   d--------   C:\DOCUME~1\JUST~1.MET\DANEAP~1\SampleView
    2007-08-20 09:21   <DIR>   d--------   C:\Program Files\SkanerOnline
    2007-08-17 12:31   442,368   --a------   C:\WINDOWS\system32\Kopia sqlsrv32.dll
    2007-08-14 14:32   <DIR>   d--h-----   C:\WINDOWS\system32\GroupPolicy
    2007-08-14 12:54   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\Microsoft Games
    2007-08-13 08:14   <DIR>   d--------   C:\Program Files\XML Notepad 2007
    2007-08-12 22:54   <DIR>   d--h-----   C:\LGFolder
    2007-08-12 22:45   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\LG Electronics
    2007-08-12 22:42   <DIR>   d--------   C:\Program Files\LG PC Suite
    2007-08-12 22:39   39,248   --a------   C:\WINDOWS\system32\drivers\lgusbmodem.sys
    2007-08-12 22:39   38,144   --a------   C:\WINDOWS\system32\drivers\lgusbdiag.sys
    2007-08-12 22:39   21,344   --a------   C:\WINDOWS\system32\drivers\lgusbbus.sys
    2007-08-12 22:39   <DIR>   d--------   C:\Program Files\LG Electronics
    2007-08-09 14:54   <DIR>   d--------   C:\Program Files\SystemRequirementsLab
    2007-08-06 18:14   <DIR>   d--------   C:\DOCUME~1\ALLUSE~1\DANEAP~1\Age of Empires 3
    2007-08-06 18:12   443,752   --a------   C:\WINDOWS\system32\d3dx10_34.dll
    2007-08-06 18:12   3,497,832   --a------   C:\WINDOWS\system32\d3dx9_34.dll
    2007-08-06 18:12   266,088   --a------   C:\WINDOWS\system32\xactengine2_8.dll
    2007-08-06 18:12   18,280   --a------   C:\WINDOWS\system32\x3daudio1_2.dll
    2007-08-06 18:12   1,124,720   --a------   C:\WINDOWS\system32\D3DCompiler_34.dll
    2007-08-06 18:11   443,752   --a------   C:\WINDOWS\system32\d3dx10_33.dll
    2007-08-06 18:11   3,495,784   --a------   C:\WINDOWS\system32\d3dx9_33.dll
    2007-08-06 18:11   261,480   --a------   C:\WINDOWS\system32\xactengine2_7.dll
    2007-08-06 18:11   255,848   --a------   C:\WINDOWS\system32\xactengine2_6.dll
    2007-08-06 18:11   1,123,696   --a------   C:\WINDOWS\system32\D3DCompiler_33.dll
    2007-08-06 18:06   <DIR>   d--------   C:\Program Files\Microsoft Games
    2007-08-06 10:09   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\Ulead Systems
    2007-08-06 10:04   <DIR>   d--------   C:\Program Files\Common Files\InterVideo
    2007-08-06 10:04   <DIR>   d--------   C:\DOCUME~1\ALLUSE~1\DANEAP~1\InterVideo
    2007-08-06 10:03   <DIR>   d--------   C:\Program Files\Common Files\LightScribe
    2007-08-06 09:59   <DIR>   d--------   C:\Program Files\Ulead Systems
    2007-08-06 09:59   <DIR>   d--------   C:\Program Files\Common Files\Ulead Systems
    2007-08-06 09:59   <DIR>   d--------   C:\DOCUME~1\ALLUSE~1\DANEAP~1\Ulead Systems
    2007-08-06 09:49   <DIR>   d--------   C:\Program Files\PowerISO
    2007-08-01 13:32   <DIR>   d-a------   C:\DOCUME~1\ALLUSE~1\DANEAP~1\TEMP
    2007-08-01 13:32   <DIR>   d--------   C:\Program Files\Your Uninstaller 2006
    2007-08-01 13:32   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\URSoft
    2007-08-01 08:10   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\Password Manager
    2007-07-31 21:07   15,872   --a------   C:\WINDOWS\system32\drivers\vd_filedisk.sys
    2007-07-31 21:07   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\HEXelon
    2007-07-30 09:14   <DIR>   d--------   C:\Program Files\Lavalys
    2007-07-26 17:43   110,592   --a------   C:\WINDOWS\system32\ccrpbds6.dll
    2007-07-26 17:43   <DIR>   d--------   C:\Program Files\PIXresizer
    2007-07-26 17:41   <DIR>   d--------   C:\Program Files\DCE AutoEnhance
    2007-07-26 07:30   <DIR>   d--------   C:\download
    2007-07-25 07:32   <DIR>   d--------   C:\Program Files\TC UP
    2007-07-25 07:17   <DIR>   d--------   C:\tc.v7.01
    2007-07-24 12:07   <DIR>   d--------   C:\DOCUME~1\Just\DANEAP~1\AdobeUM
    2007-07-24 11:41   3,426,072   --a------   C:\WINDOWS\system32\d3dx9_32.dll
    2007-07-24 11:41   251,672   --a------   C:\WINDOWS\system32\xactengine2_5.dll
    2007-07-24 07:48   <DIR>   d--------   C:\TotalCmd
    2007-07-23 07:57   85,408   -ra------   C:\WINDOWS\system32\drivers\k510mgmt.sys
    2007-07-23 07:57   83,344   -ra------   C:\WINDOWS\system32\drivers\k510obex.sys
    2007-07-23 07:46   155,648   --a------   C:\WINDOWS\system32\libssl32.dll
    2007-07-22 11:58   <DIR>   d--------   C:\WINDOWS\speech


    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-08-16 09:06   ---------   d--------   C:\Program Files\ivo
    2007-08-16 09:06   ---------   d--------   C:\Program Files\Digital Red
    2007-08-14 12:52   ---------   d--------   C:\Program Files\Winamp
    2007-08-14 07:36   769   --ahs----   C:\WINDOWS\system32\mmf.sys
    2007-08-13 22:35   ---------   d--h-----   C:\Program Files\InstallShield Installation Information
    2007-08-06 10:03   ---------   d--------   C:\Program Files\DivX
    2007-08-05 21:48   ---------   d--------   C:\Program Files\RM Converter
    2007-08-05 19:43   ---------   d--------   C:\Program Files\Ultra RM Converter
    2007-08-01 10:22   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\DivX
    2007-07-23 07:58   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Teleca
    2007-07-22 00:48   ---------   d--------   C:\Program Files\DVDlabPro2
    2007-07-20 14:09   903238   --a------   C:\WINDOWS\IVO Glossary Uninstaller.exe
    2007-07-20 12:28   ---------   d--------   C:\Program Files\RapGet
    2007-07-20 08:24   ---------   d--------   C:\Program Files\CyberLink
    2007-07-19 12:39   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Media Player Classic
    2007-07-19 08:58   3583488   --a------   C:\WINDOWS\system32\dllcache\mshtml.dll
    2007-07-18 23:39   ---------   d--------   C:\Program Files\CDex_150b6
    2007-07-17 13:08   8464   --a------   C:\WINDOWS\system32\sporder.dll
    2007-07-17 10:22   1700352   --a------   C:\WINDOWS\system32\gdiplus.dll
    2007-07-17 08:56   ---------   d--------   C:\Program Files\Alcohol Soft
    2007-07-17 08:55   685816   --a------   C:\WINDOWS\system32\drivers\sptd.sys
    2007-07-17 08:03   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Ahead
    2007-07-17 07:24   ---------   d--------   C:\Program Files\Super DVD Creator 9.30
    2007-07-17 07:18   ---------   d--------   C:\Program Files\UltraISO
    2007-07-17 07:18   ---------   d--------   C:\Program Files\Common Files\EZB Systems
    2007-07-17 01:32   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Digital Red
    2007-07-16 23:33   ---------   d--------   C:\Program Files\Project Zoo
    2007-07-16 17:23   ---------   d--------   C:\Program Files\PowerArchiver
    2007-07-16 17:21   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\WinRAR
    2007-07-16 14:30   ---------   d--------   C:\Program Files\Proxy Switcher Standard
    2007-07-16 14:24   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\WNR
    2007-07-16 00:32   ---------   d--------   C:\Program Files\Mplayer
    2007-07-16 00:05   ---------   d--------   C:\Program Files\Common Files\Ahead
    2007-07-16 00:05   ---------   d--------   C:\Program Files\Ahead
    2007-07-15 00:10   ---------   d--------   C:\Program Files\Sierra
    2007-07-15 00:05   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\InstallShield
    2007-07-14 23:54   86016   --a------   C:\WINDOWS\system32\OpenAL32.dll
    2007-07-14 23:54   413696   --a------   C:\WINDOWS\system32\wrap_oal.dll
    2007-07-14 23:50   ---------   d--------   C:\Program Files\ND Games
    2007-07-14 23:45   108144   --a------   C:\WINDOWS\system32\CmdLineExt.dll
    2007-07-14 23:45   ---------   dr-h-----   C:\DOCUME~1\Just\DANEAP~1\SecuROM
    2007-07-14 23:38   ---------   d--------   C:\Program Files\PlayLogic
    2007-07-14 23:37   ---------   d--------   C:\Program Files\OpenAL
    2007-07-13 01:32   765952   --a------   C:\WINDOWS\system32\dllcache\vgx.dll
    2007-07-12 10:49   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\.BitTornado
    2007-07-11 23:40   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Ankh
    2007-07-11 23:04   48640   --a------   C:\WINDOWS\mmfs.dll
    2007-07-11 13:50   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Real
    2007-07-11 12:47   ---------   d--------   C:\Program Files\ElcomSoft
    2007-07-11 11:34   ---------   d--------   C:\Program Files\Passware
    2007-07-11 01:11   ---------   d--------   C:\Program Files\MSXML 4.0
    2007-07-11 00:43   ---------   d--------   C:\Program Files\Team6
    2007-07-11 00:42   ---------   d--------   C:\Program Files\Barrel Mania
    2007-07-10 19:09   ---------   d--------   C:\Program Files\Project IGI
    2007-07-10 11:40   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\vlc
    2007-07-10 11:39   ---------   d--------   C:\Program Files\VideoLAN
    2007-07-10 09:53   ---------   d--------   C:\Program Files\BitComet
    2007-07-10 08:56   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Gadu-Gadu
    2007-07-10 08:03   ---------   d--------   C:\Program Files\Gadu-Gadu
    2007-07-10 07:45   ---------   d--------   C:\Program Files\K-Lite Codec Pack
    2007-07-10 07:14   ---------   d--------   C:\Program Files\INTERIAPL
    2007-07-09 21:58   ---------   d--h-----   C:\Program Files\WindowsUpdate
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Windows NT
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Windows Media Connect
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Synaptics
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Sonic
    2007-07-09 21:58   ---------   d--------   C:\Program Files\MSN Gaming Zone
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Movie Maker
    2007-07-09 21:58   ---------   d--------   C:\Program Files\microsoft frontpage
    2007-07-09 21:58   ---------   d--------   C:\Program Files\Messenger
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Hp
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Hewlett-Packard
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Fingerprint Sensor
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\TiVo Shared
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\SureThing Shared
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\SpeechEngines
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\Sonic Shared
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\ODBC
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\MSSoap
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Common Files\InstallShield
    2007-07-09 21:57   ---------   d--------   C:\Program Files\Analog Devices
    2007-07-09 21:57   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\SampleView
    2007-07-09 21:55   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\InterVideo
    2007-07-09 20:33   ---------   d--------   C:\Program Files\Codemasters
    2007-07-09 20:16   21840   --a------   C:\WINDOWS\system32\SIntfNT.dll
    2007-07-09 20:16   17212   --a------   C:\WINDOWS\system32\SIntf32.dll
    2007-07-09 20:16   12067   --a------   C:\WINDOWS\system32\SIntf16.dll
    2007-07-09 19:57   ---------   d--------   C:\Program Files\directx
    2007-07-09 17:50   ---------   d--------   C:\Program Files\Common Files\Teleca Shared
    2007-07-09 17:49   ---------   d--------   C:\Program Files\Sony Ericsson
    2007-07-09 17:49   ---------   d--------   C:\Program Files\Common Files\Sony Ericsson Shared
    2007-07-09 17:49   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Sony Ericsson
    2007-07-09 15:56   ---------   d--------   C:\Program Files\Neostrada TP
    2007-07-09 15:42   ---------   d--------   C:\DOCUME~1\Just\DANEAP~1\Help
    2007-07-09 13:56   ---------   d--------   C:\Program Files\Google
    2007-07-09 13:56   ---------   d--------   C:\Program Files\Common Files\Symantec Shared
    2007-07-09 13:48   0   -rahs----   C:\MSDOS.SYS
    2007-07-09 13:48   0   -rahs----   C:\IO.SYS
    2007-07-09 13:46   544816   --a------   C:\WINDOWS\system32\pscl.dll
    2007-07-09 13:46   43760   --a------   C:\WINDOWS\system32\nwlocale.dll


    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
     
     
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MsmqIntCert"="regsvr32 /s mqrt.dll" []
    "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 10:11]
    "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-05-06 14:06]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
    "PTHOSTTR"="C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.exe" [2006-02-14 11:56]
    "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
    "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-08-31 05:20]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-10 20:04]
    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 14:17]
    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 14:13]
    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 14:17]
    "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 10:49]
    "CognizanceTS"="C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 20:12]
    "QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-02 15:39]
    "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2006-02-22 08:03]
    "Recguard"="C:\WINDOWS\Sminst\Recguard.exe" [2005-12-20 15:51]
    "Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" [2006-01-23 16:11]
    "Scheduler"="C:\WINDOWS\SMINST\Scheduler.exe" [2006-02-15 15:43]
    "WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2005-11-08 11:59]
    "NWTRAY"="NWTRAY.EXE" [2002-03-12 11:37 C:\WINDOWS\system32\nwtray.exe]
    "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-05-28 10:14]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
    "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 16:24]
    "LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 16:21]
    "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 14:23]
    "rfagent"="C:\Program Files\RFA Platinum\rfagent.exe" [2007-06-12 15:37]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:00]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "CompatibleRUPSecurity"=1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoWelcomeScreen"=1 (0x1)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
    C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll 2005-07-25 20:41 40960 C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"= msv1_0 nwv1_0
    "Notification Packages"= scecli AsWlnPkg

    R0 NICM;Program obsługi komunikacji między usługami firmy Novell;C:\WINDOWS\system32\drivers\nicm.sys
    R0 NWFILTER;Filtr ścieżki UNC firmy Novell;C:\WINDOWS\system32\NetWare\nwfilter.sys
    R1 ISODrive;ISO DVD/CD-ROM Device Driver;\??\C:\Program Files\UltraISO\drivers\ISODrive.sys
    R1 VD_FileDisk;VD_FileDisk;C:\WINDOWS\system32\drivers\VD_FileDisk.sys
    R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};\??\C:\Program Files\CyberLink\PowerDVD\000.fcl
    R2 Alert Notification Server;Alert Notification Server;"C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE"
    R2 ASChannel;Local Communication Channel;C:\WINDOWS\System32\svchost.exe -k Cognizance
    R2 MSMQ;Message Queuing;C:\WINDOWS\system32\mqsvc.exe
    R2 MSMQTriggers;Message Queuing Triggers;C:\WINDOWS\system32\mqtgsvc.exe
    R2 NetwareWorkstation;Klient Novell dla systemu Windows;C:\WINDOWS\system32\NetWare\nwfs.sys
    R2 NWDHCP;Klient protokołu DHCP firmy Novell;C:\WINDOWS\system32\NetWare\nwdhcp.sys
    R2 RESMGR;Menedżer zasobów firmy Novell NetWare;C:\WINDOWS\system32\NetWare\resmgr.sys
    R2 SRVLOC;Lokalizacja usługi Novell;C:\WINDOWS\system32\NetWare\srvloc.sys
    R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys
    R3 HBtnKey;HBtnKey;C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
    R3 MQAC;Message Queuing access control;\??\C:\WINDOWS\system32\drivers\mqac.sys
    R3 NWDNS;Moduł obsługi przestrzeni nazw serwera DNS firmy Novell;C:\WINDOWS\system32\NetWare\nwdns.sys
    R3 NWHOST;Moduł obsługi przestrzeni nazw plików hosta firmy Novell;C:\WINDOWS\system32\NetWare\NWHOST.sys
    R3 NWSLP;Moduł obsługi przestrzeni nazw SLP firmy Novell;C:\WINDOWS\system32\NetWare\nwslp.sys
    R3 NWSNS;Proste usługi nazewnicze firmy Novell;C:\WINDOWS\system32\NetWare\NWSNS.sys
    R3 RMCAST;Reliable Multicast Protocol driver;\??\C:\WINDOWS\system32\drivers\RMCast.sys
    S2 LogWatch;Event Log Watch;"C:\Documents and Settings\Just\Pulpit\eTrust Antiwirus 7.0\German\Bin\License\Lang\DE\LIC98\LogWatNT.exe"
    S2 NWSIPX32;Interfejs transportowy IPX/SPX firmy Novell NetWare;C:\WINDOWS\system32\NetWare\nwsipx32.sys
    S3 CA_LIC_CLNT;CA License Client;"C:\Documents and Settings\Just\Pulpit\eTrust Antiwirus 7.0\German\Bin\License\Lang\DE\LIC98\lic98rmt.exe"
    S3 CA_LIC_SRVR;CA License Server;"C:\Documents and Settings\Just\Pulpit\eTrust Antiwirus 7.0\German\Bin\License\Lang\DE\LIC98\lic98rmtd.exe"
    S3 cusrvc;Client Update Service for Novell;C:\WINDOWS\system32\cusrvc.exe
    S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys
    S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k510mdfl.sys
    S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\k510mdm.sys
    S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\k510mgmt.sys
    S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys
    S3 NWSAP;Moduł obsługi przestrzeni nazw SAP firmy Novell;C:\WINDOWS\system32\NetWare\NWSAP.sys

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    Cognizance   ASChannel


    **************************************************************************

    catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-08-21 12:23:08
    Windows 5.1.2600 Dodatek Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ????c??????(?@???????@

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    Completion time: 2007-08-21 12:23:30
    C:\ComboFix-quarantined-files.txt ... 2007-08-21 12:23
    C:\ComboFix2.txt ... 2007-08-21 08:15

       --- E O F ---


    Log z HijackThis v1.99.1

    Code:
    Logfile of HijackThis v1.99.1
    
    Scan saved at 12:24:09, on 08-21-2007
    Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
    C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\WINDOWS\system32\mqsvc.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\WINDOWS\system32\mqtgsvc.exe
    C:\Program Files\HPQ\IAM\bin\asghost.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    C:\WINDOWS\SMINST\Scheduler.exe
    C:\WINDOWS\system32\NWTRAY.EXE
    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\Program Files\RFA Platinum\rfagent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
    C:\Program Files\Common Files\Teleca Shared\Generic.exe
    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
    C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Mplayer\Assets\Blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
    O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
    O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [rfagent] "C:\Program Files\RFA Platinum\rfagent.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Startup: Registration Call of Juarez.LNK = C:\Priv\Gry\coj\Register\RegistrationReminder.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: BTTray.lnk = ?
    O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O4 - Global Startup: LG SyncManager.lnk = C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
    O4 - Global Startup: Privoxy.lnk = C:\Program Files\Privoxy\privoxy.exe
    O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = metalplast-system.local
    O17 - HKLM\Software\..\Telephony: DomainName = metalplast-system.local
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = metalplast-system.local
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = metalplast-system.local
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Alert Notification Server - Computer Associates International, Inc. - C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
    O23 - Service: CA License Client (CA_LIC_CLNT) - Unknown owner - C:\Documents and Settings\Just\Pulpit\eTrust Antiwirus 7.0\German\Bin\License\Lang\DE\LIC98\lic98rmt.exe (file missing)
    O23 - Service: CA License Server (CA_LIC_SRVR) - Unknown owner - C:\Documents and Settings\Just\Pulpit\eTrust Antiwirus 7.0\German\Bin\License\Lang\DE\LIC98\lic98rmtd.exe (file missing)
    O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Event Log Watch (LogWatch) - Unknown owner - C:\Documents and Settings\Just\Pulpit\eTrust Antiwirus 7.0\German\Bin\License\Lang\DE\LIC98\LogWatNT.exe (file missing)
    O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe



    Dodano po 28 [minuty]:

    Wyjasni mi ktos te logi?

    0
  • #6 21 Sie 2007 17:14
    Kolobos
    Spec od komputerów

    Obsluga forum sprawia Ci az taki duzy problem, ze nie potrafisz umiescic plikow w zalaczniku?!

    Logi wygladaja ok.

    0