Hmm cos ciekawego, od dzisiaj moj komp strasznie sie spowolnil a lacze takze posiadam 5 procesow svchost.exe jeden to svcchost.exe, jednak svchost posiadam tylko w system32 niewiem czy jest to plik zarazony. Znalazlem w nim:
Logoff User
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Logon User Name
This program cannot be run in DOS mode.
wRwiawjwxyw Pwzw
_t 3PMQPPuSh
V39s WuVVjh
Internet Explorer
0/Welcome Finished
Days between clean up
Last used time
Software\Microsoft\Windows NT\CurrentVersion
Desktop More Programs Pane
Desktop User Pane
Software\Microsoft\Windows NT\CurrentVersion\Windows
Software\Microsoft\Windows\Internet Settings
Enable Balloon Tip
PProxy Desktop
Icon Cleanup Time
Control Panel\Appearance
Control Panel\Desktop\WindowMetrics
Software\Microsoft\Active Setup\Installed Components\InitiallyClear
Default Taskbar
Default Taskbar
SOFTWARE\Microsoft\Windows NT\CurrentVersion\srvWiz
SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel
\Microsoft Office\Office10\OUTLOOK.EXE
Shell Startup
Shell Startup
Control Panel\Desktop\ResourceLocale
nusrmgr.cpl ,initialTask
t9x uWuj
Lfy uEhc
RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL
2N2SjP TaskbarVert
explorer.exe /e,
Microsoft\Internet Explorer\Quick Launch
Software\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU
Software\Microsoft\Internet Explorer\TypedURLs
Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu
FShell Object Offsets
\Start Menu\Programs\Accessories\System Tools\Files and Settings Transfer Wizard.lnk
\Start Menu\Programs\Accessories\Windows Movie Maker.lnk
\Start Menu\Programs\Accessories\Tour Windows XP.lnk
\Start Menu\Programs\Windows Messenger.lnk
\Start Menu\Programs\Windows Media Player.lnk
\Start Menu\Programs\MSN Explorer.lnk
\Start Menu\Programs\Get Online with MSN.lnk
\Start Menu\Programs\Get Going with Tablet PC.lnk
\Start Menu\Set Program Access and Defaults.lnk
\Start Menu\Programs\Windows Journal.lnk
\Start Menu\Programs\Accessories\Media Center\Media Center.lnk
\Start Menu\Programs\Internet Explorer.lnk
Set Program Access and Defaults.lnk
CoFreeUnusedLibraries RegisterDragDrop
Dodatek Service Pack. 1
sk Manager\TaskMan.exe
\Documents and Settings\All Users\Menu Start\Programy\Sunbelt Software\Personal Firewall\Start Firewall.lnk
qo xc
ykT4jO ad00
Zabezpieczenia systemu Windows…
czenia sieciowe
Drukarki i faksy
Pasek zadaD i
menu Start
Mysle ze to takze jest keylogger a tutaj reszta:
Synchronizuj
Urucho
c i obsBuga techniczna
Pomo
Wyszukaj
sterowania
Panel
Ustawienia
Puste
Dokumenty
Puste
bione
Puste
Programy
Iipw
wqmhhUAix
FFiqrwpFFd
yaag
yuqob
fimqrx
urpih6
Iiipqu
xwqoigTA3
iioq
urqmihggA
yurqoiihhUp
rporrx
\yOme
hilka
711EEOPUTkkgifhZ
valkmnrd
bgcehj
nB_oddmqaa
aumm\hhp
nllollkj
OPXYccjjfe
ojsy
eca_rnW.
2khlbmuwxRP6
NDsrqol
KCigea
9srqoZE
wytsrqnlifc
7a_2jrqnlifc
/kjigb\B
zywtrqnmjhfa
zywtrqnmjhfa\ZXVM
zxwtrqnmjhfa\ZXVQTOLF
zxutrqnmjhfa\ZXVQTOLFEC
jhfa\B,
\ZXHoutrqnmjhfa\ZXVQTOLFEC
VQQUNqnmjhfa\ZXVQTOLFEC
UOL.jhfa\ZXVQTOLFEC
SvaZ
I5bgiz
Wf,og
kDqFsJuKvJuFsDqGn
pRWeYJaTfCnWmFtT
JKQtilo
OJKQfillpo
pRWeYJaTfCnWmFtT
olit
MQoo
MMzoo
JKMMilloo
JKMMQtilloo
JJKMMfiilloo
HJJKMMiijzl
66HJJKMMtifxixtfw
pRWeYJaTfCnWmFtT
YYYtpie
wwwuphc
/hoB
UetiXQSYVNU
uiim
Uooqkezs
6UUqqinvYoww
6UiinVXZdwaf
88VVWXZEFajj
8WWXYD4GJef
ssvrniqqU6
ossWViiU6
ddoZYXWVV88
iahMVr9m
Auqqptoxslh
ZpromP
Rnoj
xywe
xuywd
xuyphC
vsuqwptd
2OQQtponquxvzvxqpttd7
PPPtrxvmsuoeC
ojmms
oilml1
ffill6
ZattB
PLKGFeDcbb\
RQO3KJGFEeb
QO3KJGFEeDDstb
O3KJGFEeDDdb
cceccYY
oqkIJyVYf
snidvTW.9
Oraalow
daab
uxttc
kivhgkk
eeeii
FFkRReJJO661
rtgil7
osZlo7
cejacG
biih
pppo
u1nhffVT
ooogV1
uqhff2WV
juquq
hffa
fffa
CHUZZXY2_c/Q_0a
777Ga.P1WZZXYi
uqgq
uqqVnvviaV2N\
uuqqmk2h0V1M\
hmqqmmkk2ar
I7POYhXQdSuJ
YmZ_s_AssiyxPaSzMeV.hA
SL8UZ,bo2\e
sskZagsa
vvaM71…5BWaks
kUZva___g_g_g_g_g_g_ggmgmgg__gmmnssyzszssyyzz
gUZaaBVV_____m_m__g__g__g__gg__
spgkW7IMUat
vvkaZURQMWa
ktta
bbcemgk
ygvaZaZSt
bcemggk
Flood…
RegEnumKeyExW
RegSetValueExW
RegCreateKeyExW
RegQueryValueExW
RegQueryInfoKeyW
RegOpenKeyExW
RegEnumValueW
RegDeleteValueW
RegCreateKeyW
RegCloseKey
RegQueryValueW
RegOpenKeyExA
RegQueryValueExA
RegNotifyChangeKeyValue
RegEnumKeyW
RegSetValueW
_except_handler3
_ftol
_itow
free
memmove
realloc
I pelno innych… Prosze o porady, posiadam nod32 ale on nic niewykryl oraz Windows XP+ KPF ~150polaczen wychodzacych z niego do microsoft-ds