AragornBG
(Aragornbg)
22 Wrzesień 2007 09:19
#1
prosze o sprawdzenie moich logow
HJT
Logfile of HijackThis v1.99.1 Scan saved at 11:18:26, on 2007-09-22 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Analog Devices\SoundMAX\Smax4.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Portrait Displays\DisplayView\dtsslsrv.exe C:\Program Files\Portrait Displays\DisplayView\DTSRVC.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Opera\Opera.exe D:\Programy\Programy\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll O4 - HKLM…\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM…\Run: [soundMAX] “C:\Program Files\Analog Devices\SoundMAX\Smax4.exe” /tray O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM…\Run: [nwiz] nwiz.exe /install O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM…\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe” O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU…\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] “C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe” O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Pobierz z &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} (SignActivX Control) - https://www.bph.pl/pi/components/SignActivX.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Asset Management Daemon - Unknown owner - C:\Program Files\Portrait Displays\DisplayView\dtsslsrv.exe O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Portrait Displays\DisplayView\DTSRVC.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Usługa iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
SR
“Silent Runners.vbs”, revision R50, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “CTFMON.EXE” = “C:\WINDOWS\system32\ctfmon.exe” [MS] “BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}” = ““C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe”” [“Nero AG”] HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “SoundMAXPnP” = “C:\Program Files\Analog Devices\Core\smax4pnp.exe” [“Analog Devices, Inc.”] “SoundMAX” = ““C:\Program Files\Analog Devices\SoundMAX\Smax4.exe” /tray” [“Analog Devices, Inc.”] “NvCplDaemon” = “RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup” [MS] “nwiz” = “nwiz.exe /install” [“NVIDIA Corporation”] “NvMediaCenter” = “RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit” [MS] “NeroFilterCheck” = “C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe” [“Nero AG”] “SunJavaUpdateSched” = ““C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe”” [“Sun Microsystems, Inc.”] “Adobe Reader Speed Launcher” = ““C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”” [“Adobe Systems Incorporated”] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM…CLSID} = “Adobe PDF Reader Link Helper” \InProcServer32(Default) = “C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided) -> {HKLM…CLSID} = “SSVHelper Class” \InProcServer32(Default) = “C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll” [“Sun Microsystems, Inc.”] {C08DF07A-3E49-4E25-9AB0-D3882835F153}(Default) = (no title provided) -> {HKLM…CLSID} = “QUICKfind BHO Object” \InProcServer32(Default) = “C:\PROGRA~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll” [null data] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Rozszerzenie CPL kadrowania wyświetlania” -> {HKLM…CLSID} = “Rozszerzenie CPL kadrowania wyświetlania” \InProcServer32(Default) = “deskpan.dll” [file not found] “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] “{A70C977A-BF00-412C-90B7-034C51DA2439}” = “NvCpl DesktopContext Class” -> {HKLM…CLSID} = “DesktopContext Class” \InProcServer32(Default) = “C:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”] “{FFB699E0-306A-11d3-8BD1-00104B6F7516}” = “Play on my TV helper” -> {HKLM…CLSID} = “NVIDIA CPL Extension” \InProcServer32(Default) = “C:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”] “{1CDB2949-8F65-4355-8456-263E7C208A5D}” = “Desktop Explorer” -> {HKLM…CLSID} = “Desktop Explorer” \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A47}” = “Desktop Explorer Menu” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A48}” = “nView Desktop Context Menu” -> {HKLM…CLSID} = “nView Desktop Context Menu” \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{654D0431-C930-43C4-B8DA-9AA01BA5B486}” = “PDI GUI Engine COM Obj” -> {HKLM…CLSID} = “PDI GUI Engine COM Obj” \InProcServer32(Default) = “C:\Program Files\Portrait Displays\DisplayView\HtmlEngine.dll” [“Portrait Displays, Inc”] “{B8323370-FF27-11D2-97B6-204C4F4F5020}” = “SmartFTP Shell Extension DLL” -> {HKLM…CLSID} = “SmartFTP Shell Extension DLL” \InProcServer32(Default) = “C:\Program Files\SmartFTP Client 2.0\smarthook.dll” [“SmartFTP”] “{B327765E-D724-4347-8B16-78AE18552FC3}” = “NeroDigitalIconHandler” -> {HKLM…CLSID} = “NeroDigitalIconHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] “{7F1CF152-04F8-453A-B34C-E609530A9DC8}” = “NeroDigitalPropSheetHandler” -> {HKLM…CLSID} = “NeroDigitalPropSheetHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] “{42042206-2D85-11D3-8CFF-005004838597}” = “Microsoft Office HTML Icon Handler” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Microsoft Office\OFFICE11\msohev.dll” [MS] “{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}” = “Shell Extensions for RealOne Player” -> {HKLM…CLSID} = “RealOne Player Context Menu Class” \InProcServer32(Default) = “C:\Program Files\Real\RealPlayer\rpshell.dll” [“RealNetworks, Inc.”] “{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}” = “iTunes” -> {HKLM…CLSID} = “iTunes” \InProcServer32(Default) = “C:\Program Files\iTunes\iTunesMiniPlayer.dll” [“Apple Inc.”] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\ <> “AppInit_DLLs” = “C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL” [“Google”] HKLM\Software\Classes\PROTOCOLS\Filter\ <> text/xml\CLSID = “{807553E5-5146-11D5-A672-00B0D022E945}” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL” [MS] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {7D4D6379-F301-4311-BEBA-E26EB0561882}(Default) = “NeroDigitalExt.NeroDigitalColumnHandler” -> {HKLM…CLSID} = “NeroDigitalColumnHandler Class” \InProcServer32(Default) = “C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] {F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = “PDF Column Info” -> {HKLM…CLSID} = “PDF Shell Extension” \InProcServer32(Default) = “C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ FineReader8(Default) = “{F7091C74-EBB1-49D7-94C7-FE4886CCC18D}” -> {HKLM…CLSID} = “FineReader8ExplorerContextMenuHandler” \InProcServer32(Default) = “C:\Program Files\ABBYY FineReader 8.0 Professional Edition\FECMenu.dll” [“ABBYY Software”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} “undockwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ “Wallpaper” = “C:\WINDOWS\ACD Wallpaper.bmp” Startup items in “Bartek W” & “All Users” startup folders: ---------------------------------------------------------- C:\Documents and Settings\Bartek W\Menu Start\Programy\Autostart “Adobe Gamma” -> shortcut to: “C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe” [“Adobe Systems, Inc.”] Enabled Scheduled Tasks: ------------------------ “AppleSoftwareUpdate” -> launches: “C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task” [“Apple Inc.”] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 13 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ HKLM\Software\Classes\CLSID{FF059E31-CC5A-4E2E-BF3B-96E929D65503}(Default) = “&Badanie” Implemented Categories{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32(Default) = “C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL” [MS] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ “MenuText” = “Sun Java Console” “CLSIDExtension” = “{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}” -> {HKCU…CLSID} = “Java Plug-in 1.6.0_02” \InProcServer32(Default) = “C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll” [“Sun Microsystems, Inc.”] -> {HKLM…CLSID} = “Java Plug-in 1.6.0_02” \InProcServer32(Default) = “C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll” [“Sun Microsystems, Inc.”] {92780B25-18CC-41C8-B9BE-3C9C571A8263}\ “ButtonText” = “Badanie” Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Apple Mobile Device, Apple Mobile Device, ““C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe”” [“Apple, Inc.”] Asset Management Daemon, Asset Management Daemon, “C:\Program Files\Portrait Displays\DisplayView\dtsslsrv.exe” [null data] NVIDIA Display Driver Service, NVSvc, “C:\WINDOWS\system32\nvsvc32.exe” [“NVIDIA Corporation”] Portrait Displays Display Tune Service, DTSRVC, “C:\Program Files\Portrait Displays\DisplayView\DTSRVC.exe” [null data] StarWind iSCSI Service, StarWindService, “C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe” [“Rocket Division Software”] Windows User Mode Driver Framework, UMWdf, “C:\WINDOWS\system32\wdfmgr.exe” [MS] Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ Microsoft Document Imaging Writer Monitor\Driver = “mdimon.dll” [MS] ---------- <>: Suspicious data at a malware launch point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points, use the -supp parameter or answer “No” at the first message box and “Yes” at the second message box. ---------- (total run time: 18 seconds, including 3 seconds for message boxes)
Frefol
(Novi00)
22 Wrzesień 2007 09:21
#2
Ja w logach nic nie widzę…
może ktoś mnie poprawi…
Jedyne co zapreferuje to:
Start>>Uruchom>>msconfig>>zakładka uruchomianie i wyłącz programy, które nie muszą startowac z systemem to przyśpieszy nieco prace kompa.
Daj log z ComboFix, bo moze…
AragornBG
(Aragornbg)
22 Wrzesień 2007 10:26
#3
raczej to nie wina, programow, bo kompa mam szybkiego, poprostu przy wlaczaniu filmow np Allplayerem, za kazdym razem sie wylacza All, mimo instalowania od nowa, przy WMP tez blad wyskakuje
“Bartek W” - 07-09-22 12:26:02 Dodatek Service Pack 2 ComboFix 07-03-27.4 - Running from: “D:\Programy\Programy” ((((((((((((((((((((((((((((((( Files Created from 2007-08-22 to 2007-09-22 )))))))))))))))))))))))))))))))))) 2007-09-22 10:56 2007-09-20 19:28 395,776 --a------ C:\WINDOWS\system32\libmplayer.dll 2007-09-20 19:28 34,820 --a------ C:\WINDOWS\system32\ffdshow.reg 2007-09-20 19:28 262,144 --a------ C:\WINDOWS\system32\TomsMoComp_ff.dll 2007-09-20 19:28 2,255,360 --a------ C:\WINDOWS\system32\libavcodec.dll 2007-09-20 19:28 112,640 --a------ C:\WINDOWS\system32\libmpeg2_ff.dll 2007-09-20 19:28 1,060,864 --a------ C:\WINDOWS\system32\MFC71.DLL 2007-09-20 19:28 2007-09-20 19:28 2007-09-20 19:27 2007-09-20 19:26 2007-09-20 19:26 2007-09-19 16:35 556,544 --------- C:\WINDOWS\system32\NexPlayerX.dll 2007-09-19 16:35 44,304 --a------ C:\WINDOWS\system32\msrpfs35.dll 2007-09-19 16:35 415,504 --a------ C:\WINDOWS\system32\msrepl35.dll 2007-09-19 16:35 39,424 --a------ C:\WINDOWS\system32\JETCOMP.exe 2007-09-19 16:35 368,912 --a------ C:\WINDOWS\system32\VBAR332.DLL 2007-09-19 16:35 344,064 --a------ C:\WINDOWS\system32\msexch35.dll 2007-09-19 16:35 294,912 --a------ C:\WINDOWS\system32\msxbse35.dll 2007-09-19 16:35 262,144 --a------ C:\WINDOWS\system32\msrd2x35.dll 2007-09-19 16:35 252,688 --a------ C:\WINDOWS\system32\msexcl35.dll 2007-09-19 16:35 250,128 --a------ C:\WINDOWS\system32\mspdox35.dll 2007-09-19 16:35 24,848 --a------ C:\WINDOWS\system32\msjter35.dll 2007-09-19 16:35 168,720 --a------ C:\WINDOWS\system32\msltus35.dll 2007-09-19 16:35 166,672 --a------ C:\WINDOWS\system32\mstext35.dll 2007-09-19 16:35 139,264 --a------ C:\WINDOWS\system32\msjint35.dll 2007-09-19 16:35 1,238,288 --a------ C:\WINDOWS\system32\msjt4jlt.dll 2007-09-19 16:35 1,050,896 --a------ C:\WINDOWS\system32\msjet35.dll 2007-09-19 16:27 2007-09-17 20:23 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll 2007-09-17 20:23 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll 2007-09-17 20:22 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll 2007-09-17 20:22 739,840 --a------ C:\WINDOWS\system32\DivX.dll 2007-09-14 23:08 2007-09-14 23:07 2007-09-14 23:07 2007-09-13 22:14 2007-09-13 22:07 2007-09-13 22:07 2007-09-13 22:07 2007-09-13 15:03 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-09-13 15:03 2007-09-13 15:02 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll 2007-09-13 15:02 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll 2007-09-13 15:02 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll 2007-09-13 15:02 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll 2007-09-13 15:02 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll 2007-09-13 15:02 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll 2007-09-13 15:02 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll 2007-09-13 15:02 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll 2007-09-13 15:02 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll 2007-09-13 15:00 2007-09-13 14:59 2007-09-12 01:14 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2007-09-11 11:53 16 --a------ C:\WINDOWS\system32\wpfb.dat 2007-09-08 22:02 2007-09-08 22:02 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-09-22 11:19 49492 --a------ C:\WINDOWS\system32\perfc015.dat 2007-09-22 11:19 355486 --a------ C:\WINDOWS\system32\perfh015.dat 2007-09-22 11:16 -------- d-------- C:\Program Files\xvid 2007-09-22 10:53 -------- d-------- C:\Program Files\divx 2007-09-20 11:20 -------- d-------- C:\Program Files\dc++ 2007-09-19 16:35 -------- d–h----- C:\Program Files\installshield installation information 2007-09-19 16:35 -------- d-------- C:\Program Files\samsung 2007-09-19 16:35 -------- d-------- C:\Program Files\Common Files\installshield 2007-09-18 23:23 -------- d-------- C:\Program Files\gadu-gadu 2007-09-17 23:29 -------- d-------- C:\DOCUME~1\BARTEK~1\DANEAP~1\skype 2007-09-13 22:14 -------- d-------- C:\Program Files\ipod 2007-09-08 22:07 -------- d-------- C:\Program Files\skaneronline 2007-09-07 14:14 -------- d-------- C:\Program Files\opera 2007-09-07 03:38 -------- d-------- C:\Program Files\java 2007-09-06 14:18 -------- d-------- C:\DOCUME~1\BARTEK~1\DANEAP~1\tlen.pl 2007-08-21 02:26 81920 --a------ C:\WINDOWS\system32\dpl100.dll 2007-08-21 02:26 196608 --a–c— C:\WINDOWS\system32\dtu100.dll 2007-08-16 00:33 524288 --a------ C:\WINDOWS\system32\divxsm.exe 2007-08-16 00:33 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-08-16 00:33 200704 --a------ C:\WINDOWS\system32\ssldivx.dll 2007-08-16 00:33 1044480 --a------ C:\WINDOWS\system32\libdivx.dll 2007-08-16 00:31 593920 --a------ C:\WINDOWS\system32\dpugui11.dll 2007-08-16 00:31 57344 --a------ C:\WINDOWS\system32\dpv11.dll 2007-08-16 00:31 53248 --a–c— C:\WINDOWS\system32\dpugui10.dll 2007-08-16 00:31 344064 --a–c— C:\WINDOWS\system32\dpus11.dll 2007-08-16 00:31 294912 --a–c— C:\WINDOWS\system32\dpu10.dll 2007-08-16 00:31 294912 --a------ C:\WINDOWS\system32\dpu11.dll 2007-08-16 00:30 12288 --a------ C:\WINDOWS\system32\divxwmpexttype.dll 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll 2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” “BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”="“C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe”" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “SoundMAXPnP”=“C:\Program Files\Analog Devices\Core\smax4pnp.exe” “SoundMAX”="“C:\Program Files\Analog Devices\SoundMAX\Smax4.exe” /tray" “NvCplDaemon”=“RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup” “nwiz”=“nwiz.exe /install” “NvMediaCenter”=“RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit” “NeroFilterCheck”=“C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe” “SunJavaUpdateSched”="“C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe”" “Adobe Reader Speed Launcher”="“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] @="" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” @="" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “Installed”=“1” “NoChange”=“1” @="" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” @="" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk” “backup”=“C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE " “item”=“Adobe Reader Speed Launch” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DisplayView.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DisplayView.lnk” “backup”=“C:\WINDOWS\pss\DisplayView.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\PROGRA~1\PORTRA~1\DISPLA~1\dthtml.exe -startup_folder” “item”=“DisplayView” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“AdobeUpdater” “hkey”=“HKCU” “command”=“C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“GoogleDesktop” “hkey”=“HKLM” “command”=”“C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” /startup" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“iTunesHelper” “hkey”=“HKLM” “command”="“C:\Program Files\iTunes\iTunesHelper.exe”" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“tlen” “hkey”=“HKCU” “command”=“C:\Program Files\Tlen.pl\tlen.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiquidView] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“lviewj” “hkey”=“HKLM” “command”=“C:\Program Files\LiquidView\lviewj.exe -nogui” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load] “key”=“SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows” “item”=“watch” “hkey”=“HKCU” “command”=“C:\YDPDict\watch.exe” “inimapping”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PivotSoftware] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“wpctrl” “hkey”=“HKLM” “command”="“C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe”" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“QTTask” “hkey”=“HKLM” “command”="“C:\Program Files\QuickTime\QTTask.exe” -atboottime" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“realsched” “hkey”=“HKLM” “command”="“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“winampa” “hkey”=“HKLM” “command”=“C:\Program Files\Winamp\winampa.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] “wscsvc”=dword:00000002 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] “appinit_dlls”=“C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL” [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 Contents of the ‘Scheduled Tasks’ folder C:\WINDOWS\tasks\AppleSoftwareUpdate.job ******************************************************************** catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes … scanning hidden services … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-09-22 12:27:39
Gutek
(Gutek)
22 Wrzesień 2007 10:44
#4
Problemem moga być kodeki, które sa źle dobrane
usuń z zaplanowanych zadań AppleSoftwareUpdate.job
Czy inny program do otwierania filmów też się gaśnie?
AragornBG
(Aragornbg)
22 Wrzesień 2007 11:29
#5
tak, inne programy tez sie wylaczaja, wyskakuje blad explorera i nie da sie odtworzyc zadnego filmu
Gutek
(Gutek)
22 Wrzesień 2007 12:33
#6