ComboFix 11-12-04.04 - Administrator 2011-12-05 8:58.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.2038.1237 [GMT 1:00] Uruchomiony z: c:\documents and settings\Administrator\Moje dokumenty\Pobieranie\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Administrator\Dane aplikacji\My Security Shield c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\promo.exe c:\documents and settings\All Users\Dane aplikacji\3ea58b c:\documents and settings\All Users\Dane aplikacji\3ea58b\7513.mof c:\documents and settings\All Users\Dane aplikacji\3ea58b\mozcrt19.dll c:\documents and settings\All Users\Dane aplikacji\3ea58b\MS3ea_231.exe c:\documents and settings\All Users\Dane aplikacji\3ea58b\MSS.ico c:\documents and settings\All Users\Dane aplikacji\3ea58b\MSSSys\vd952342.bd c:\documents and settings\All Users\Dane aplikacji\3ea58b\sqlite3.dll c:\documents and settings\All Users\Dane aplikacji\TEMP c:\windows\IsUn0415.exe . . ((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_SSHNAS -------\Service_SSHNAS . . ((((((((((((((((((((((((( Pliki utworzone od 2011-11-05 do 2011-12-05 ))))))))))))))))))))))))))))))) . . 2011-12-05 08:31 . 2011-12-05 08:31 56200 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{AD42E669-54C2-4225-B0D1-4BA6D687E1E7}\offreg.dll 2011-12-05 08:31 . 2011-12-05 08:31 63115 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS 2011-12-05 08:31 . 2011-12-05 08:31 4599 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS 2011-12-05 08:31 . 2011-12-05 08:31 8646 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS 2011-12-05 08:31 . 2011-12-05 08:31 6429 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS 2011-12-05 08:31 . 2011-12-05 08:31 9310 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS 2011-12-05 08:31 . 2011-12-05 08:31 5927 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS 2011-12-05 08:30 . 2011-12-05 08:30 8613 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS 2011-12-05 08:30 . 2011-12-05 08:30 1651 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS 2011-12-05 08:30 . 2011-12-05 08:30 6910 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS 2011-12-05 08:30 . 2011-12-05 08:30 18541 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS 2011-12-05 08:30 . 2011-12-05 08:30 8288 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS 2011-12-05 08:30 . 2011-12-05 08:30 6208 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS 2011-12-05 08:30 . 2011-12-05 08:30 51852 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS 2011-12-05 08:30 . 2011-12-05 08:30 20719 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS 2011-12-05 08:30 . 2011-12-05 08:30 7271 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS 2011-12-05 08:30 . 2011-12-05 08:30 23327 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS 2011-12-05 08:30 . 2011-12-05 08:30 8782 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS 2011-12-03 07:28 . 2011-11-21 10:47 6823496 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{AD42E669-54C2-4225-B0D1-4BA6D687E1E7}\mpengine.dll 2011-11-28 19:24 . 2011-11-28 19:24 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\HP Product Assistant 2011-11-28 19:23 . 2011-11-28 19:23 -------- d-----w- c:\program files\Hewlett-Packard 2011-11-28 13:49 . 2011-11-28 13:49 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\HP 2011-11-12 11:46 . 2011-11-12 11:48 -------- d-----w- c:\program files\FileZilla FTP Client 2011-11-11 16:24 . 2011-11-11 16:25 -------- d-----w- c:\program files\SmartFTP Client 2011-11-11 16:23 . 2011-11-11 16:23 -------- d-----w- c:\program files\SmartFTP Client 4.0 Setup Files 2011-11-10 16:46 . 2011-11-10 16:46 -------- d–h--w- c:\program files\Common Files\EAInstaller 2011-11-09 04:59 . 2011-11-09 04:59 359016 ----a-w- c:\windows\vncutil.exe 2011-11-09 04:59 . 2011-11-09 04:59 53864 ----a-w- c:\windows\system32\RtkCoInstXP.dll 2011-11-09 04:59 . 2011-11-09 04:59 129640 ----a-w- c:\windows\RtkAudioService.exe 2011-11-09 04:59 . 2011-11-09 04:59 1395800 ----a-w- c:\windows\system32\drivers\Monfilt.sys 2011-11-09 04:58 . 2011-11-09 04:58 1691480 ----a-w- c:\windows\system32\drivers\Ambfilt.sys 2011-11-09 01:51 . 2008-03-21 12:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll 2011-11-09 01:51 . 2011-11-09 01:51 -------- d-----w- c:\program files\Synaptics 2011-11-09 01:51 . 2011-11-09 01:51 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll 2011-11-09 01:51 . 2011-11-09 01:51 120104 ----a-w- c:\windows\system32\SynTPCo4.dll 2011-11-09 01:51 . 2011-11-09 01:51 161064 ----a-w- c:\windows\system32\SynTPAPI.dll 2011-11-09 01:51 . 2011-11-09 01:51 208816 ----a-w- c:\windows\system32\drivers\SynTP.sys 2011-11-09 01:51 . 2011-11-09 01:51 206120 ----a-w- c:\windows\system32\SynCtrl.dll 2011-11-09 01:51 . 2011-11-09 01:51 169256 ----a-w- c:\windows\system32\SynCOM.dll . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-21 10:47 . 2011-02-28 18:05 6823496 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-11-17 05:08 . 2011-05-23 19:00 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-09 05:01 . 2009-05-11 18:46 45568 ----a-w- c:\windows\system32\drivers\bcm4sbxp.sys 2011-11-09 04:59 . 2009-05-11 18:46 84584 ----a-w- c:\windows\SOUNDMAN.EXE 2011-11-09 04:59 . 2009-05-11 18:46 1833576 ----a-w- c:\windows\SkyTel.exe 2011-11-09 04:59 . 2009-05-11 18:46 891496 ----a-w- c:\windows\system32\RTSndMgr.CPL 2011-11-09 04:59 . 2009-05-11 18:46 1489512 ----a-w- c:\windows\RtlUpd.exe 2011-11-09 04:59 . 2009-05-11 18:45 6108776 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys 2011-11-09 04:59 . 2009-05-11 18:46 9721960 ----a-w- c:\windows\RTLCPL.EXE 2011-11-09 04:59 . 2009-05-11 18:45 19557480 ----a-w- c:\windows\RTHDCPL.EXE 2011-11-09 04:59 . 2009-05-11 18:45 2180712 ----a-w- c:\windows\MicCal.exe 2011-11-09 04:59 . 2009-05-11 18:45 2815592 ----a-w- c:\windows\ALCWZRD.EXE 2011-11-09 04:59 . 2009-05-11 18:45 64104 ----a-w- c:\windows\ALCMTR.EXE 2011-11-09 04:58 . 2009-05-11 18:45 285288 ----a-w- c:\windows\system32\ALSNDMGR.CPL 2011-10-10 14:21 . 2010-08-18 07:53 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-09-28 07:05 . 2008-04-14 20:50 603136 ----a-w- c:\windows\system32\crypt32.dll 2011-09-26 09:41 . 2008-07-29 22:59 614400 ----a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 09:41 . 2007-10-29 12:00 23040 ----a-w- c:\windows\system32\oleaccrc.dll 2011-09-26 09:41 . 2007-10-29 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll 2011-09-06 14:08 . 2009-05-11 17:52 1868160 ----a-w- c:\windows\system32\win32k.sys 2011-11-10 07:21 . 2011-06-24 15:44 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ------- Sigcheck ------- Note: Unsigned files aren’t necessarily malware. . [-] 2009-05-11 . 8D8B5CD78BE4E9D5B4C4D68D562479EF . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_LOCAL_MACHINE~\Browser Helper Objects{FF6C3CF0-4B15-11D1-ABED-709549C10000}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension] @="{CDC95B92-E27C-4745-A8C5-64A52A78855D}" [HKEY_CLASSES_ROOT\CLSID{CDC95B92-E27C-4745-A8C5-64A52A78855D}] 2011-05-30 14:50 21864 ----a-w- c:\program files\WWW.HOSTJSC.NET\Internet Download Manager\IDMShellExt.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “DriverScanner”=“c:\progra~1\DRIVER~1\launcher.exe” [2011-09-05 338296] “ctfmon.exe”=“c:\windows\system32\ctfmon.exe” [2008-04-14 15360] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] “EnableLinkedConnections”= 1 (0x1) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] “{56F9679E-7826-4C84-81F3-532071A8BCC5}”= “c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll” [2009-05-24 304128] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @=“Service” . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @=“Driver” . [HKLM~\startupfolder\C:^Documents and Settings^Administrator^Menu Start^Programy^Autostart^Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk] path=c:\documents and settings\Administrator\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk backup=c:\windows\pss\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnkStartup . [HKLM~\startupfolder\C:^Documents and Settings^Administrator^Menu Start^Programy^Autostart^Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk] path=c:\documents and settings\Administrator\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnk backup=c:\windows\pss\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2010.lnkStartup . [HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup . [HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^McAfee Security Scan Plus.lnk] path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\McAfee Security Scan Plus.lnk backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup . [HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Windows Search.lnk] path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Windows Search.lnk backup=c:\windows\pss\Windows Search.lnkCommon Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] c:\windows\system32\dumprep 0 -k [X] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2010-09-20 22:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2010-09-23 03:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0] 2010-03-06 01:44 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager] 2010-02-22 02:57 406992 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2011-11-09 04:59 64104 ----a-w- c:\windows\ALCMTR.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync] 2010-03-13 13:54 91520 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-14 20:51 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate] 2010-09-01 06:39 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator] 2010-08-31 18:18 2836656 ----a-w- c:\program files\DAP\DAP.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core] 2009-09-03 21:17 3342336 ----a-w- c:\program files\Electronic Arts\EADM\Core.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu 10] 2011-07-04 17:45 13374048 ----a-w- c:\program files\Gadu-Gadu 10\gg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2011-06-02 02:12 136176 ----atw- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] 2006-11-13 13:57 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] 2009-05-11 18:46 166424 ----a-w- c:\windows\system32\hkcmd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2007-03-11 19:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan] 2011-11-14 11:52 3437976 ----a-w- c:\program files\WWW.HOSTJSC.NET\Internet Download Manager\IDMan.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] 2009-05-11 18:46 141848 ----a-w- c:\windows\system32\igfxtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPLA!] 2011-05-09 08:13 19759104 ----a-w- c:\program files\ipla\ipla.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC] 2011-06-15 13:16 997920 ----a-w- c:\program files\Microsoft Security Client\msseces.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent] 2010-03-26 08:52 1234216 ----a-w- c:\program files\Nero\Nero 10\Nero BackItUp\NBAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4] 2006-10-11 10:45 75304 ----a-w- c:\program files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence] 2009-05-11 18:46 137752 ----a-w- c:\windows\system32\igfxpers.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrzyspieszKomputer] 2010-08-19 05:36 890104 ----a-w- c:\program files\Przyspiesz Komputer\PrzyspieszKomputer.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] 2011-11-09 04:59 19557480 ----a-w- c:\windows\RTHDCPL.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] 2011-11-09 04:59 1833576 ----a-w- c:\windows\SkyTel.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate] 2006-09-28 11:16 185896 ----a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-10-29 12:49 249064 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] 2010-08-29 20:26 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard] 2010-02-19 11:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] 2011-11-09 01:51 1512744 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant] 2010-07-04 19:51 17408 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent] 2010-09-12 10:54 328568 ----a-w- c:\program files\uTorrent\uTorrent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] 2011-07-11 21:47 74752 ----a-w- c:\program files\Winamp\winampa.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON] 2004-10-14 12:25 32768 ------w- c:\progra~1\NEOSTR~1\GestMAJ.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH] 2004-08-23 10:19 20480 ------w- c:\progra~1\NEOSTR~1\Watch.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] “Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” . [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] “%windir%\Network Diagnostic\xpnetdiag.exe”= “%windir%\system32\sessmgr.exe”= “c:\Program Files\uTorrent\uTorrent.exe”= “c:\Program Files\Opera\opera.exe”= “c:\Program Files\Microsoft Office\Office14\GROOVE.EXE”= “c:\Program Files\Microsoft Office\Office14\ONENOTE.EXE”= “c:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE”= “c:\WINDOWS\system32\winver.exe”= “c:\Program Files\Winamp\winamp.exe”= “c:\Program Files\Mozilla Firefox\plugin-container.exe”= “c:\program files\Microsoft ActiveSync\rapimgr.exe”= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager “c:\program files\Microsoft ActiveSync\wcescomm.exe”= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager “c:\program files\Microsoft ActiveSync\WCESMgr.exe”= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application “c:\Program Files\Java\jre6\bin\java.exe”= “c:\Program Files\Java\jre6\bin\javaw.exe”= “c:\Program Files\Gadu-Gadu 10\gg.exe”= “c:\Program Files\SmartFTP Client\SmartFTP.exe”= . [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] “3389:TCP”= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009 “26675:TCP”= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service . R0 sptd;sptd;\SystemRoot\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\SystemRoot\System32\Drivers\sptd.sys [?] R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [2011-02-01 101616] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [2010-03-25 490280] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-06-15 1051976] R2 Wybór systemu operacyjnego;Aktywator programu Acronis OS Selector;c:\program files\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-10-27 2155736] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2010-02-25 10064] S1 MpKsl01ecf5bc;MpKsl01ecf5bc;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{26E16BF6-CC7B-48DD-A5EB-139894F9D146}\MpKsl01ecf5bc.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{26E16BF6-CC7B-48DD-A5EB-139894F9D146}\MpKsl01ecf5bc.sys [?] S1 MpKsl05046eab;MpKsl05046eab;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{9C960FFA-2390-44E4-AB1F-3BFF04E0FA2D}\MpKsl05046eab.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{9C960FFA-2390-44E4-AB1F-3BFF04E0FA2D}\MpKsl05046eab.sys [?] S1 MpKsl0ad4111b;MpKsl0ad4111b;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{73EC1102-A4EB-41A1-965F-7B74C714DD3C}\MpKsl0ad4111b.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{73EC1102-A4EB-41A1-965F-7B74C714DD3C}\MpKsl0ad4111b.sys [?] S1 MpKsl0beac53f;MpKsl0beac53f;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{DCB13160-A3AD-4056-99DD-3C6983B92E79}\MpKsl0beac53f.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{DCB13160-A3AD-4056-99DD-3C6983B92E79}\MpKsl0beac53f.sys [?] S1 MpKsl0c6143f0;MpKsl0c6143f0;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{1D130E4A-08B0-4ED6-92CC-29E45AFFC208}\MpKsl0c6143f0.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{1D130E4A-08B0-4ED6-92CC-29E45AFFC208}\MpKsl0c6143f0.sys [?] S1 MpKsl11ea0f7b;MpKsl11ea0f7b;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{29D50446-F2DE-472B-9BB7-8293E08861F3}\MpKsl11ea0f7b.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{29D50446-F2DE-472B-9BB7-8293E08861F3}\MpKsl11ea0f7b.sys [?] S1 MpKsl12feba24;MpKsl12feba24;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{AC708E86-7622-45E5-8632-F87D37EC2105}\MpKsl12feba24.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{AC708E86-7622-45E5-8632-F87D37EC2105}\MpKsl12feba24.sys [?] S1 MpKsl139f157c;MpKsl139f157c;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{900DF2D9-E555-4476-B2F2-88C594F5C944}\MpKsl139f157c.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{900DF2D9-E555-4476-B2F2-88C594F5C944}\MpKsl139f157c.sys [?] S1 MpKsl13d6a45a;MpKsl13d6a45a;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{EC503B19-A2AA-4821-86A8-B69283F6ADEE}\MpKsl13d6a45a.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{EC503B19-A2AA-4821-86A8-B69283F6ADEE}\MpKsl13d6a45a.sys [?] S1 MpKsl1b5f05db;MpKsl1b5f05db;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{D0A51D66-0266-477A-A1ED-E0DEB91A9027}\MpKsl1b5f05db.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{D0A51D66-0266-477A-A1ED-E0DEB91A9027}\MpKsl1b5f05db.sys [?] S1 MpKsl1ba90fa8;MpKsl1ba90fa8;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{739149FC-0BF9-4FDF-8104-EB2CDC78704E}\MpKsl1ba90fa8.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{739149FC-0BF9-4FDF-8104-EB2CDC78704E}\MpKsl1ba90fa8.sys [?] S1 MpKsl1dff7379;MpKsl1dff7379;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{255F5BAF-4364-427C-BB1F-5D87C1DFBB8C}\MpKsl1dff7379.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{255F5BAF-4364-427C-BB1F-5D87C1DFBB8C}\MpKsl1dff7379.sys [?] S1 MpKsl264ff217;MpKsl264ff217;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{A57A5420-0509-4E9F-AD21-746978B47C4F}\MpKsl264ff217.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{A57A5420-0509-4E9F-AD21-746978B47C4F}\MpKsl264ff217.sys [?] S1 MpKsl2d302e3d;MpKsl2d302e3d;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{24891265-242B-4CB7-BC22-50FE8043680D}\MpKsl2d302e3d.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{24891265-242B-4CB7-BC22-50FE8043680D}\MpKsl2d302e3d.sys [?] S1 MpKsl2e4ba220;MpKsl2e4ba220;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{F5204BB4-3CC8-42FD-A172-7E8693B5A5F4}\MpKsl2e4ba220.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{F5204BB4-3CC8-42FD-A172-7E8693B5A5F4}\MpKsl2e4ba220.sys [?] S1 MpKsl314f8739;MpKsl314f8739;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{86453F96-DCCE-473D-93EA-8BD667935797}\MpKsl314f8739.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{86453F96-DCCE-473D-93EA-8BD667935797}\MpKsl314f8739.sys [?] S1 MpKsl37b93523;MpKsl37b93523;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{94EEB5BF-CD6B-4D2E-840A-E96217DB3DC0}\MpKsl37b93523.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{94EEB5BF-CD6B-4D2E-840A-E96217DB3DC0}\MpKsl37b93523.sys [?] S1 MpKsl4f9661e1;MpKsl4f9661e1;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{8E48FB4F-0C9F-4662-B738-931A095220FA}\MpKsl4f9661e1.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{8E48FB4F-0C9F-4662-B738-931A095220FA}\MpKsl4f9661e1.sys [?] S1 MpKsl535fb4cb;MpKsl535fb4cb;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{8ACE5A0D-44F3-459B-8C48-0E552322C6A4}\MpKsl535fb4cb.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{8ACE5A0D-44F3-459B-8C48-0E552322C6A4}\MpKsl535fb4cb.sys [?] S1 MpKsl5b37706c;MpKsl5b37706c;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{D3BCE20B-8BFC-455F-81C3-832E0A1CAD94}\MpKsl5b37706c.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{D3BCE20B-8BFC-455F-81C3-832E0A1CAD94}\MpKsl5b37706c.sys [?] S1 MpKsl68daf81a;MpKsl68daf81a;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{2B1B9B3D-6610-45E2-BC8D-30388B2F2024}\MpKsl68daf81a.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{2B1B9B3D-6610-45E2-BC8D-30388B2F2024}\MpKsl68daf81a.sys [?] S1 MpKsl6a0a1c4c;MpKsl6a0a1c4c;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{ABCC9FE6-6F0E-4F22-8CA1-8BABF5C42FD5}\MpKsl6a0a1c4c.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{ABCC9FE6-6F0E-4F22-8CA1-8BABF5C42FD5}\MpKsl6a0a1c4c.sys [?] S1 MpKsl6e059fbc;MpKsl6e059fbc;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{EBEE0B32-0976-4061-913A-7972281BD0D1}\MpKsl6e059fbc.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{EBEE0B32-0976-4061-913A-7972281BD0D1}\MpKsl6e059fbc.sys [?] S1 MpKsl717ea96a;MpKsl717ea96a;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{28F5891F-DA53-45DF-AB8B-11A87EB6FA83}\MpKsl717ea96a.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{28F5891F-DA53-45DF-AB8B-11A87EB6FA83}\MpKsl717ea96a.sys [?] S1 MpKsl7420ef18;MpKsl7420ef18;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{4012B216-36DD-432B-818A-51B3DF11FFC2}\MpKsl7420ef18.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{4012B216-36DD-432B-818A-51B3DF11FFC2}\MpKsl7420ef18.sys [?] S1 MpKsl746fd954;MpKsl746fd954;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{DCB13160-A3AD-4056-99DD-3C6983B92E79}\MpKsl746fd954.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{DCB13160-A3AD-4056-99DD-3C6983B92E79}\MpKsl746fd954.sys [?] S1 MpKsl75a92023;MpKsl75a92023;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{DC0805B0-D349-4C5D-B56C-9E9A6A55FD4D}\MpKsl75a92023.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{DC0805B0-D349-4C5D-B56C-9E9A6A55FD4D}\MpKsl75a92023.sys [?] S1 MpKsl81c8001e;MpKsl81c8001e;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{1D0602B6-F923-4BAC-ADC4-4C735042EA27}\MpKsl81c8001e.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{1D0602B6-F923-4BAC-ADC4-4C735042EA27}\MpKsl81c8001e.sys [?] S1 MpKsl876c7e94;MpKsl876c7e94;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{739149FC-0BF9-4FDF-8104-EB2CDC78704E}\MpKsl876c7e94.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{739149FC-0BF9-4FDF-8104-EB2CDC78704E}\MpKsl876c7e94.sys [?] S1 MpKsl892340f0;MpKsl892340f0;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{AD42E669-54C2-4225-B0D1-4BA6D687E1E7}\MpKsl892340f0.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{AD42E669-54C2-4225-B0D1-4BA6D687E1E7}\MpKsl892340f0.sys [?] S1 MpKsl8b2c6d73;MpKsl8b2c6d73;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{198C3F9B-B0F2-42E1-84B3-3A72143582C1}\MpKsl8b2c6d73.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{198C3F9B-B0F2-42E1-84B3-3A72143582C1}\MpKsl8b2c6d73.sys [?] S1 MpKsl913d4c3d;MpKsl913d4c3d;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{786FC620-F5BC-462E-95E7-9CB83D6D5907}\MpKsl913d4c3d.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{786FC620-F5BC-462E-95E7-9CB83D6D5907}\MpKsl913d4c3d.sys [?] S1 MpKsl915b4bf4;MpKsl915b4bf4;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{D3BCE20B-8BFC-455F-81C3-832E0A1CAD94}\MpKsl915b4bf4.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{D3BCE20B-8BFC-455F-81C3-832E0A1CAD94}\MpKsl915b4bf4.sys [?] S1 MpKsl93502c95;MpKsl93502c95;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{9C960FFA-2390-44E4-AB1F-3BFF04E0FA2D}\MpKsl93502c95.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{9C960FFA-2390-44E4-AB1F-3BFF04E0FA2D}\MpKsl93502c95.sys [?] S1 MpKsl98a505de;MpKsl98a505de;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{29D50446-F2DE-472B-9BB7-8293E08861F3}\MpKsl98a505de.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{29D50446-F2DE-472B-9BB7-8293E08861F3}\MpKsl98a505de.sys [?] S1 MpKsl9ce2e8c0;MpKsl9ce2e8c0;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{53399719-5459-490A-9B8D-17FA22A3EACE}\MpKsl9ce2e8c0.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{53399719-5459-490A-9B8D-17FA22A3EACE}\MpKsl9ce2e8c0.sys [?] S1 MpKsl9f8abcac;MpKsl9f8abcac;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{6C70287F-B729-4A49-BB06-8792531F1FB9}\MpKsl9f8abcac.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{6C70287F-B729-4A49-BB06-8792531F1FB9}\MpKsl9f8abcac.sys [?] S1 MpKsl9ff1cc01;MpKsl9ff1cc01;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{D3BCE20B-8BFC-455F-81C3-832E0A1CAD94}\MpKsl9ff1cc01.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{D3BCE20B-8BFC-455F-81C3-832E0A1CAD94}\MpKsl9ff1cc01.sys [?] S1 MpKsla3be7e2f;MpKsla3be7e2f;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{DC0805B0-D349-4C5D-B56C-9E9A6A55FD4D}\MpKsla3be7e2f.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{DC0805B0-D349-4C5D-B56C-9E9A6A55FD4D}\MpKsla3be7e2f.sys [?] S1 MpKsla47d901d;MpKsla47d901d;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{F5204BB4-3CC8-42FD-A172-7E8693B5A5F4}\MpKsla47d901d.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{F5204BB4-3CC8-42FD-A172-7E8693B5A5F4}\MpKsla47d901d.sys [?] S1 MpKsla5016a44;MpKsla5016a44;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{7FA508B0-7C07-47F6-A1DC-91E72A0CAB6A}\MpKsla5016a44.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{7FA508B0-7C07-47F6-A1DC-91E72A0CAB6A}\MpKsla5016a44.sys [?] S1 MpKsla6197b3d;MpKsla6197b3d;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{7FA508B0-7C07-47F6-A1DC-91E72A0CAB6A}\MpKsla6197b3d.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{7FA508B0-7C07-47F6-A1DC-91E72A0CAB6A}\MpKsla6197b3d.sys [?] S1 MpKsla8dbcbfc;MpKsla8dbcbfc;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{AD42E669-54C2-4225-B0D1-4BA6D687E1E7}\MpKsla8dbcbfc.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{AD42E669-54C2-4225-B0D1-4BA6D687E1E7}\MpKsla8dbcbfc.sys [?] S1 MpKslad6d0fab;MpKslad6d0fab;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{2B1B9B3D-6610-45E2-BC8D-30388B2F2024}\MpKslad6d0fab.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{2B1B9B3D-6610-45E2-BC8D-30388B2F2024}\MpKslad6d0fab.sys [?] S1 MpKslaeabaee0;MpKslaeabaee0;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{72D902A8-2464-407D-8532-EBFF013FEC47}\MpKslaeabaee0.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{72D902A8-2464-407D-8532-EBFF013FEC47}\MpKslaeabaee0.sys [?] S1 MpKslaee203ab;MpKslaee203ab;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{74DA46A7-7EB3-4716-AF54-4F329D35C5F5}\MpKslaee203ab.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{74DA46A7-7EB3-4716-AF54-4F329D35C5F5}\MpKslaee203ab.sys [?] S1 MpKslb0a9d89a;MpKslb0a9d89a;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{AE1B7E91-2F5B-4316-80A3-7B95BC26B56D}\MpKslb0a9d89a.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{AE1B7E91-2F5B-4316-80A3-7B95BC26B56D}\MpKslb0a9d89a.sys [?] S1 MpKslb1627a5f;MpKslb1627a5f;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{35829203-E76D-4861-8D4B-F794D3390E57}\MpKslb1627a5f.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{35829203-E76D-4861-8D4B-F794D3390E57}\MpKslb1627a5f.sys [?] S1 MpKslb287e022;MpKslb287e022;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{8DA47A17-4B09-4B5D-9B7D-172240E7D7D1}\MpKslb287e022.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{8DA47A17-4B09-4B5D-9B7D-172240E7D7D1}\MpKslb287e022.sys [?] S1 MpKslb4ac9f6e;MpKslb4ac9f6e;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{E3E15427-BD0A-463A-A0D7-4855CAC63D37}\MpKslb4ac9f6e.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{E3E15427-BD0A-463A-A0D7-4855CAC63D37}\MpKslb4ac9f6e.sys [?] S1 MpKslb5915312;MpKslb5915312;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{6C70287F-B729-4A49-BB06-8792531F1FB9}\MpKslb5915312.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{6C70287F-B729-4A49-BB06-8792531F1FB9}\MpKslb5915312.sys [?] S1 MpKslb80878b4;MpKslb80878b4;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{EEA8151E-EAEB-4286-832A-BFF3678844E8}\MpKslb80878b4.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{EEA8151E-EAEB-4286-832A-BFF3678844E8}\MpKslb80878b4.sys [?] S1 MpKslb8aea7c9;MpKslb8aea7c9;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{A126AE9E-65A7-4762-AD9C-31EAEA828575}\MpKslb8aea7c9.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{A126AE9E-65A7-4762-AD9C-31EAEA828575}\MpKslb8aea7c9.sys [?] S1 MpKslc1876a0d;MpKslc1876a0d;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{BA44D8D3-EBF0-40AC-937E-19ECCC4645FA}\MpKslc1876a0d.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{BA44D8D3-EBF0-40AC-937E-19ECCC4645FA}\MpKslc1876a0d.sys [?] S1 MpKslcf9df5cc;MpKslcf9df5cc;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{0ACB2DC2-CBB0-4E29-BA25-4D21098C405B}\MpKslcf9df5cc.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{0ACB2DC2-CBB0-4E29-BA25-4D21098C405B}\MpKslcf9df5cc.sys [?] S1 MpKsld15ef7cf;MpKsld15ef7cf;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{2B1B9B3D-6610-45E2-BC8D-30388B2F2024}\MpKsld15ef7cf.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{2B1B9B3D-6610-45E2-BC8D-30388B2F2024}\MpKsld15ef7cf.sys [?] S1 MpKsld1f9e842;MpKsld1f9e842;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{6FF94342-BB14-4EC0-B812-BD03980CD561}\MpKsld1f9e842.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{6FF94342-BB14-4EC0-B812-BD03980CD561}\MpKsld1f9e842.sys [?] S1 MpKsld439a034;MpKsld439a034;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{66A52161-E07C-4009-AD49-96BDF4814C06}\MpKsld439a034.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{66A52161-E07C-4009-AD49-96BDF4814C06}\MpKsld439a034.sys [?] S1 MpKsld4736574;MpKsld4736574;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{F5A0EBA8-AA7C-47ED-BEE2-ACB6C1272FB8}\MpKsld4736574.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{F5A0EBA8-AA7C-47ED-BEE2-ACB6C1272FB8}\MpKsld4736574.sys [?] S1 MpKsld56ea2ac;MpKsld56ea2ac;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{9AF5A2C7-AE95-4B84-902C-D2827B57EF89}\MpKsld56ea2ac.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{9AF5A2C7-AE95-4B84-902C-D2827B57EF89}\MpKsld56ea2ac.sys [?] S1 MpKsld58fb2de;MpKsld58fb2de;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{73EC1102-A4EB-41A1-965F-7B74C714DD3C}\MpKsld58fb2de.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{73EC1102-A4EB-41A1-965F-7B74C714DD3C}\MpKsld58fb2de.sys [?] S1 MpKsld6caad12;MpKsld6caad12;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{82A5A0CB-94D0-4F76-9698-CE86985A1F3C}\MpKsld6caad12.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{82A5A0CB-94D0-4F76-9698-CE86985A1F3C}\MpKsld6caad12.sys [?] S1 MpKsld734fa72;MpKsld734fa72;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{66A52161-E07C-4009-AD49-96BDF4814C06}\MpKsld734fa72.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{66A52161-E07C-4009-AD49-96BDF4814C06}\MpKsld734fa72.sys [?] S1 MpKsld78215f2;MpKsld78215f2;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{DA067CC2-4287-43A9-A57C-582F904C2950}\MpKsld78215f2.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{DA067CC2-4287-43A9-A57C-582F904C2950}\MpKsld78215f2.sys [?] S1 MpKsldd2ae819;MpKsldd2ae819;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{D3BCE20B-8BFC-455F-81C3-832E0A1CAD94}\MpKsldd2ae819.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{D3BCE20B-8BFC-455F-81C3-832E0A1CAD94}\MpKsldd2ae819.sys [?] S1 MpKsldddfe5d9;MpKsldddfe5d9;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{BA44D8D3-EBF0-40AC-937E-19ECCC4645FA}\MpKsldddfe5d9.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{BA44D8D3-EBF0-40AC-937E-19ECCC4645FA}\MpKsldddfe5d9.sys [?] S1 MpKsle23523ea;MpKsle23523ea;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{4012B216-36DD-432B-818A-51B3DF11FFC2}\MpKsle23523ea.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{4012B216-36DD-432B-818A-51B3DF11FFC2}\MpKsle23523ea.sys [?] S1 MpKsleeb07aeb;MpKsleeb07aeb;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{72052530-3AE7-49CD-B97E-72357D988FBA}\MpKsleeb07aeb.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{72052530-3AE7-49CD-B97E-72357D988FBA}\MpKsleeb07aeb.sys [?] S1 MpKslf4a351c0;MpKslf4a351c0;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{9880B424-0395-476C-804A-15E76216E9E9}\MpKslf4a351c0.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{9880B424-0395-476C-804A-15E76216E9E9}\MpKslf4a351c0.sys [?] S1 MpKslf5f39fd6;MpKslf5f39fd6;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{A3C391EB-A2D2-49CC-BD11-89D5547C7606}\MpKslf5f39fd6.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{A3C391EB-A2D2-49CC-BD11-89D5547C7606}\MpKslf5f39fd6.sys [?] S1 MpKslf8ad873f;MpKslf8ad873f;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{C9FC7E49-DFA7-4DE7-9530-71543452BE6C}\MpKslf8ad873f.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{C9FC7E49-DFA7-4DE7-9530-71543452BE6C}\MpKslf8ad873f.sys [?] S1 MpKslf8f027c9;MpKslf8f027c9;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{7F66DE18-E45F-4D77-A0AF-D8D659858CF0}\MpKslf8f027c9.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{7F66DE18-E45F-4D77-A0AF-D8D659858CF0}\MpKslf8f027c9.sys [?] S1 MpKslf9d4c9c5;MpKslf9d4c9c5;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{2B1B9B3D-6610-45E2-BC8D-30388B2F2024}\MpKslf9d4c9c5.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{2B1B9B3D-6610-45E2-BC8D-30388B2F2024}\MpKslf9d4c9c5.sys [?] S1 MpKslf9f32f68;MpKslf9f32f68;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{E0AD9D46-1A3D-42BE-B5BA-28D698D7B204}\MpKslf9f32f68.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{E0AD9D46-1A3D-42BE-B5BA-28D698D7B204}\MpKslf9f32f68.sys [?] S1 MpKslfadcf330;MpKslfadcf330;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{739149FC-0BF9-4FDF-8104-EB2CDC78704E}\MpKslfadcf330.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{739149FC-0BF9-4FDF-8104-EB2CDC78704E}\MpKslfadcf330.sys [?] S1 MpKslffadffd0;MpKslffadffd0;??\c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{7D9607F6-144B-48E4-8719-95F5B5DBAF89}\MpKslffadffd0.sys --> c:\documents and settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates{7D9607F6-144B-48E4-8719-95F5B5DBAF89}\MpKslffadffd0.sys [?] S2 gupdate;Usługa Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-29 136176] S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [2010-08-18 64000] S2 KMService;KMService;c:\windows\system32\srvany.exe [2011-02-06 8192] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-11-09 1691480] S3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\drivers\e4usbaw.sys [2010-08-18 116992] S3 gupdatem;Usługa Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-29 136176] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Zawartość folderu ‘Zaplanowane zadania’ . 2011-12-02 c:\windows\Tasks\AdobeAAMUpdater-1.0-JACHE-2774D74FC-Administrator.job - c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-09-25 01:44] . 2011-11-29 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 08:04] . 2011-12-05 c:\windows\Tasks\DriverScanner.job - c:\program files\DriverScanner\dsmonitor.exe [2011-09-27 14:20] . 2011-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-29 20:26] . 2011-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-29 20:26] . 2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1292428093-1177238915-500Core.job - c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2011-07-10 02:12] . 2011-12-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1292428093-1177238915-500UA.job - c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2011-07-10 02:12] . 2011-12-05 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39] . 2011-12-05 c:\windows\Tasks\User_Feed_Synchronization-{AFE85B82-9A03-4ECF-B837-0477E1685087}.job - c:\windows\system32\msfeedssync.exe [2010-08-18 02:31] . 2011-11-28 c:\windows\Tasks\WebReg Deskjet F4100 series.job - c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2007-03-11 20:27] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://start.facemoods.com/?a=ddr mStart Page = hxxp://home.sweetim.com IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm IE: &Download with &DAP - c:\program files\DAP\dapextie.htm IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000 IE: Easy-WebPrint – Dodaj do listy drukowania - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html IE: Easy-WebPrint – Drukuj - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html IE: Easy-WebPrint – Drukuj z dużą szybkością - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html IE: Easy-WebPrint – Podgląd - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html IE: Funkcja Google Sidewiki - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: Wyślij &do programu OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105 IE: Ściągnij przez IDM - c:\program files\WWW.HOSTJSC.NET\Internet Download Manager\IEExt.htm IE: Ściągnij wszystkie linki przez IDM - c:\program files\WWW.HOSTJSC.NET\Internet Download Manager\IEGetAll.htm TCP: DhcpNameServer = 194.204.152.34 194.204.159.1 Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll FF - ProfilePath - c:\documents and settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\z0uopkjr.default\ FF - prefs.js: browser.startup.homepage - hxxp://start.facemoods.com/?a=ddr FF - prefs.js: keyword.URL - hxxp://start.facemoods.com/results.php?f=5&a=ddr&q= FF - user.js: network.http.max-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 750 FF - user.js: content.notify.interval - 750000 FF - user.js: content.max.tokenizing.time - 2250000 . - - - - USUNIĘTO PUSTE WPISY - - - - . WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file) MSConfigStartUp-AdobeBridge - c:\program files\Adobe\Adobe Bridge CS4\Bridge.exe MSConfigStartUp-AdobeCS4ServiceManager - c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe MSConfigStartUp-ASH24SXZ9S - c:\docume~1\ADMINI~1\USTAWI~1\Temp\Kj3.exe MSConfigStartUp-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe MSConfigStartUp-DriverScanner - c:\program files\Uniblue\DriverScanner\launcher.exe MSConfigStartUp-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.3\facemoodssrv.exe MSConfigStartUp-GrooveMonitor - c:\program files\Microsoft Office\Office12\GrooveMonitor.exe MSConfigStartUp-LogMeIn Hamachi Ui - D:\hamachi-2-ui.exe MSConfigStartUp-MSS - c:\documents and settings\All Users\Dane aplikacji\3ea58b\MS3ea_231.exe MSConfigStartUp-My Security Shield - c:\documents and settings\All Users\Dane aplikacji\3ea58b\MS3ea_231.exe MSConfigStartUp-OTGV1DNWQQ - c:\docume~1\ADMINI~1\USTAWI~1\Temp\Kj6.exe AddRemove-Easy-WebPrint - c:\windows\IsUn0415.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-12-05 09:33 Windows 5.1.2600 Dodatek Service Pack 3 NTFS . skanowanie ukrytych procesów … . skanowanie ukrytych wpisów autostartu … . skanowanie ukrytych plików … . skanowanie pomyślnie ukończone ukryte pliki: 0 . ************************************************************************** . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_USERS\S-1-5-21-448539723-1292428093-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (Administrator) “88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977”=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ee,03,e9,44,92,4f,19,40,b7,b3,b7,\ “2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81”=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ee,03,e9,44,92,4f,19,40,b7,b3,b7,\ “6256FFB019F8FDFBD36745B06F4540E9AEAF222A25”=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ee,03,e9,44,92,4f,19,40,b7,b3,b7,\ . [HKEY_LOCAL_MACHINE\software\Classes\CLSID{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}] @Denied: (Full) (Everyone) “scansk”=hex(0):4c,be,66,1f,ac,89,b1,1b,a1,8a,31,3b,94,e1,df,28,68,a2,b3,14,91, 90,79,72,45,f0,f4,8f,fd,ae,3f,ab,03,5d,05,91,81,56,56,41,00,00,00,00,00,00,\ . [HKEY_LOCAL_MACHINE\software\Classes\CLSID{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) “scansk”=hex(0):19,1a,9e,01,02,29,df,70,29,45,cc,1b,36,39,04,75,0a,92,d3,5a,5b, 8d,09,34,ff,19,0a,d6,25,c3,7c,62,ed,a6,5a,36,22,f1,4b,4c,00,00,00,00,00,00,\ . [HKEY_LOCAL_MACHINE\software\Classes\CLSID{7ce93a8d-9463-4360-bc17-da34c6f1838e}] @Denied: (Full) (Everyone) “Model”=dword:00000164 “Therad”=dword:0000001d “MData”=hex(0):16,a0,5f,f1,e6,75,ab,8b,33,94,1b,49,cd,1b,3c,70,1a,06,ff,db,85, f4,a9,53,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\ . [HKEY_LOCAL_MACHINE\software\Classes\CLSID{b3361ea3-de6c-4fcf-b2a5-f5eef91839ea}] @Denied: (Full) (Everyone) “Model”=dword:000000de “Therad”=dword:0000001f “MData”=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26, 38,95,44,88,79,0d,22,8e,33,17,75,e6,82,db,74,d6,1f,ea,8f,73,52,5e,1c,c4,05,\ . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- . - - - - - - - > ‘explorer.exe’(1552) c:\windows\system32\WININET.dll c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf c:\progra~1\MICROS~1\Office14\1045\GrooveIntlResource.dll c:\program files\WWW.HOSTJSC.NET\Internet Download Manager\IDMShellExt.dll c:\program files\WWW.HOSTJSC.NET\Internet Download Manager\IDMNetMon.DLL c:\program files\SmartFTP Client\en-US\sfShellTools.dll.mui c:\windows\system32\msi.dll c:\windows\system32\wpdshserviceobj.dll c:\windows\system32\webcheck.dll c:\windows\system32\portabledevicetypes.dll c:\windows\system32\portabledeviceapi.dll c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.POL . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe c:\windows\System32\FTRTSVC.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\progra~1\DRIVER~1\driverscanner.exe c:\windows\system32\wscntfy.exe c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe c:\windows\system32\wbem\wmiapsrv.exe . ************************************************************************** . Czas ukończenia: 2011-12-05 09:42:22 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2011-12-05 08:42 . Przed: 5 502 537 728 bajtów wolnych Po: 25 619 169 280 bajtów wolnych . WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe ; This boot.ini was automatically generated by NeoSmart Technologies’ BootGrabber.exe ; Use EasyBCD from http://neosmart.net/dl.php?id=1 to manage your bootloader [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons UnsupportedDebug=“do not select this” /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Windows XP on D:” /fastdetect . - - End Of File - - EE8783C07BF91A473D99737A328E16A8