Wirus? trojan co zrobić?


(chalk) #1

Pomocy!! Komputer spowalnia. w katalogu systemowym pojawia się plik o dziwnej nazwie: rwjfw i jakies cyfry. Skanery online nie mogągo wywalić, ręcznie też powraca. Zrobiłem skan RSJ Podaję loga:

Logfile of random's system information tool 1.06 (written by random/random)

Run by Blemer at 2009-11-16 15:43:20

Microsoft Windows XP Professional Dodatek Service Pack 2

System drive C: has 26 GB (65%) free of 40 GB

Total RAM: 1023 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:43:31, on 2009-11-16

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\COMODO\COMODO Internet Security\cfp.exe

C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Blemer\Moje dokumenty\Pobieranie\RSIT.exe

C:\Program Files\Trend Micro\HijackThis\Blemer.exe

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O4 - HKLM..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h

O4 - HKLM..\Run: [Ashampoo FireWall] "C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY

O4 - HKUS\S-1-5-19..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')

O4 - HKUS\S-1-5-20..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')

O4 - HKUS\S-1-5-18..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS.DEFAULT..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Zaznaczanie HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O17 - HKLM\System\CCS\Services\Tcpip..{CD4645CE-7E10-4DDA-B39F-11344756045D}: NameServer = 213.241.79.37 83.238.255.76

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe

--

End of file - 3031 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{0347C33E-8762-4905-BF09-768834316C61}]

HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]

HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2009-10-31 1799952]

"Ashampoo FireWall"=C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe [2007-04-05 3251800]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALLUpdate]

C:\Program Files\ALLPlayer\ALLUpdate.exe [2009-06-04 869888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2005-08-06 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]

C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

C:\WINDOWS\SOUNDMAN.EXE [2004-12-22 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

C:\Program Files\Winamp\winampa.exe [2007-04-26 35328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]

C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [2009-10-03 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Synchronizer.lnk]

C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE [2009-02-27 542096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^ATI CATALYST – pasek zadań.lnk]

C:\PROGRA~1\ATITEC~1\ATI.ACE\CLI.exe [2005-08-06 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DSLMON.lnk]

C:\PROGRA~1\SAGEM\SAGEMF~1\dslmon.exe [2007-02-13 1205840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk]

C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-10-14 214360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]

C:\WINDOWS\system32\Ati2evxx.dll [2005-08-04 46080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"dontdisplaylastusername"=1

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"

"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"

"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"

"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"

"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"

"C:\Program Files\Gadu-Gadu\gg.exe"="C:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program główny"

"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"

"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe"

"C:\Program Files\Ares\Ares.exe"="C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows"

"C:\Documents and Settings\Blemer\Pulpit\emule.exe"="C:\Documents and Settings\Blemer\Pulpit\emule.exe:*:Enabled:eMule"

"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2009-11-16 15:43:20 ----D---- C:\rsit

2009-11-16 15:27:46 ----D---- C:\32788R22FWJFW

2009-11-16 14:30:20 ----D---- C:\Program Files\SkanerOnline

2009-11-16 14:26:37 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Symantec

2009-11-16 14:26:37 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Norton

2009-11-16 14:26:28 ----D---- C:\Program Files\NortonInstaller

2009-11-16 14:26:28 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\NortonInstaller

2009-11-15 22:47:00 ----D---- C:\Program Files\Unlocker

2009-11-15 21:46:32 ----HD---- C:\WINDOWS\PIF

2009-11-15 21:46:22 ----A---- C:\WINDOWS\cavscan.INI

2009-11-03 13:48:19 ----A---- C:\WINDOWS\system32\Wing.dll

2009-11-03 13:48:18 ----D---- C:\Program Files\Mapeciątka

2009-11-03 13:48:18 ----A---- C:\WINDOWS\system32\Wing32.dll

2009-11-02 22:40:12 ----A---- C:\WINDOWS\system32\javaw.exe

2009-11-02 22:40:12 ----A---- C:\WINDOWS\system32\java.exe

2009-11-02 22:39:39 ----D---- C:\Program Files\Java

2009-11-02 22:39:38 ----D---- C:\Program Files\Common Files\Java

2009-11-02 22:21:27 ----D---- C:\WINDOWS\system32\appmgmt

2009-11-02 22:18:55 ----D---- C:\WINDOWS\Sun

2009-11-02 22:17:02 ----A---- C:\WINDOWS\system32\deploytk.dll

2009-11-02 22:15:00 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\Sun

2009-11-02 22:06:57 ----D---- C:\Program Files\Adobe

2009-11-01 18:57:29 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\HPAppData

2009-11-01 18:57:28 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Google

2009-11-01 18:56:03 ----A---- C:\WINDOWS\cdplayer.ini

2009-11-01 18:54:57 ----A---- C:\WINDOWS\system32\rmoc3260.dll

2009-11-01 18:54:51 ----A---- C:\WINDOWS\system32\pndx5032.dll

2009-11-01 18:54:51 ----A---- C:\WINDOWS\system32\pndx5016.dll

2009-11-01 18:54:42 ----D---- C:\Program Files\Common Files\xing shared

2009-11-01 18:54:19 ----A---- C:\WINDOWS\system32\pncrt.dll

2009-11-01 18:54:14 ----D---- C:\Program Files\Real

2009-11-01 18:54:13 ----D---- C:\Program Files\Common Files\Real

2009-11-01 18:54:12 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Real

2009-11-01 18:54:04 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\Real

2009-11-01 18:52:16 ----D---- C:\Program Files\Google

2009-11-01 17:10:05 ----A---- C:\WINDOWS\NeroDigital.ini

2009-11-01 16:43:08 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\CyberLink

2009-11-01 16:00:18 ----D---- C:\Program Files\eMule

2009-11-01 15:58:41 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\WinRAR

2009-11-01 14:15:42 ----SHD---- C:\Config.Msi

2009-11-01 14:15:24 ----D---- C:\Program Files\MSXML 4.0

2009-11-01 14:14:37 ----D---- C:\Program Files\Ares

2009-11-01 12:16:35 ----D---- C:\Downloads

2009-11-01 11:42:49 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\uTorrent

2009-11-01 11:28:53 ----D---- C:\Program Files\Trend Micro

2009-11-01 11:15:23 ----D---- C:\WINDOWS\system32\Adobe

2009-10-31 22:45:37 ----D---- C:\Program Files\Ashampoo

2009-10-31 21:34:02 ----D---- C:\Program Files\Winamp

2009-10-31 21:27:29 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\Gadu-Gadu

2009-10-31 21:19:49 ----D---- C:\Program Files\Gadu-Gadu

2009-10-31 20:21:49 ----A---- C:\WINDOWS\system32\MRT.exe

2009-10-31 19:42:28 ----D---- C:\WINDOWS\ServicePackFiles

2009-10-31 19:39:52 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\HP

2009-10-31 19:39:20 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\WEBREG

2009-10-31 19:37:29 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Hewlett-Packard

2009-10-31 19:37:14 ----RA---- C:\WINDOWS\system32\hpzids01.dll

2009-10-31 19:37:11 ----A---- C:\WINDOWS\system32\hpzll5mu.dll

2009-10-31 19:36:05 ----RA---- C:\WINDOWS\system32\hppldcoi.dll

2009-10-31 19:36:05 ----RA---- C:\WINDOWS\system32\difxapi.dll

2009-10-31 19:36:04 ----RA---- C:\WINDOWS\system32\hpowiax7.dll

2009-10-31 19:36:04 ----RA---- C:\WINDOWS\system32\hpovst15.dll

2009-10-31 19:36:04 ----RA---- C:\WINDOWS\system32\hpotscl6.dll

2009-10-31 19:31:28 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\HP Product Assistant

2009-10-31 19:31:28 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\HP

2009-10-31 19:31:09 ----D---- C:\Program Files\Hewlett-Packard

2009-10-31 19:31:03 ----D---- C:\Program Files\Common Files\Hewlett-Packard

2009-10-31 19:30:47 ----D---- C:\Program Files\Common Files\HP

2009-10-31 19:29:45 ----DC---- C:\WINDOWS\system32\DRVSTORE

2009-10-31 19:29:04 ----D---- C:\Program Files\HP

2009-10-31 18:58:56 ----N---- C:\WINDOWS\system32\tzchange.exe

2009-10-31 18:56:37 ----D---- C:\WINDOWS\system32\PreInstall

2009-10-31 18:56:37 ----A---- C:\WINDOWS\system32\spupdsvc.exe

2009-10-31 18:56:35 ----HD---- C:\WINDOWS\$hf_mig$

2009-10-31 18:47:54 ----A---- C:\WINDOWS\cfplogvw.INI

2009-10-31 18:47:38 ----D---- C:\WINDOWS\system32\SoftwareDistribution

2009-10-31 18:38:21 ----D---- C:\WINDOWS\RegisteredPackages

2009-10-31 18:37:05 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\Winamp

2009-10-31 18:23:52 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\Macromedia

2009-10-31 17:56:09 ----A---- C:\WINDOWS\system32\xvidcore.dll

2009-10-31 17:56:09 ----A---- C:\WINDOWS\system32\iconv.dll

2009-10-31 17:56:01 ----D---- C:\Program Files\NAPI-PROJEKT

2009-10-31 17:56:00 ----D---- C:\Program Files\ALLPlayer

2009-10-31 17:51:01 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\GRETECH

2009-10-31 17:50:17 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\GRETECH

2009-10-31 17:49:17 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\BESTplayer

2009-10-31 17:46:24 ----D---- C:\Program Files\Common Files\Adobe

2009-10-31 17:46:16 ----D---- C:\WINDOWS\SxsCaPendDel

2009-10-31 17:43:29 ----D---- C:\Program Files\K-Lite Codec Pack

2009-10-31 17:40:00 ----D---- C:\Program Files\WinRAR

2009-10-31 17:21:12 ----D---- C:\WINDOWS\pss

2009-10-31 17:18:03 ----A---- C:\WINDOWS\Fast800.ini

2009-10-31 17:18:03 ----A---- C:\WINDOWS\adidsl.ini

2009-10-31 17:17:59 ----A---- C:\WINDOWS\adirasx64.exe

2009-10-31 17:17:59 ----A---- C:\WINDOWS\adiras.ini

2009-10-31 17:17:59 ----A---- C:\WINDOWS\adiras.exe

2009-10-31 17:17:58 ----A---- C:\WINDOWS\system32\IPDETECT.EXE

2009-10-31 17:17:58 ----A---- C:\WINDOWS\system32\adadix32.dll

2009-10-31 17:17:56 ----A---- C:\WINDOWS\system32\unaddrv.x64.exe

2009-10-31 17:17:56 ----A---- C:\WINDOWS\system32\unaddrv.exe

2009-10-31 17:17:56 ----A---- C:\WINDOWS\system32\coclassfast.dll

2009-10-31 17:17:56 ----A---- C:\WINDOWS\system32\ADADIX2K.DLL

2009-10-31 17:17:56 ----A---- C:\WINDOWS\system32\ADADIX16.DLL

2009-10-31 17:17:56 ----A---- C:\WINDOWS\enddisk32.exe

2009-10-31 17:17:56 ----A---- C:\WINDOWS\autoclk.exe

2009-10-31 17:17:46 ----D---- C:\Program Files\SAGEM

2009-10-31 17:17:43 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\InstallShield

2009-10-31 17:06:17 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\Comodo

2009-10-31 17:04:43 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Comodo

2009-10-31 17:04:41 ----A---- C:\WINDOWS\system32\guard32.dll

2009-10-31 17:04:40 ----D---- C:\Program Files\COMODO

2009-10-31 17:02:48 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\Mozilla

2009-10-31 17:02:07 ----D---- C:\Program Files\Mozilla Firefox

2009-10-31 15:30:05 ----A---- C:\WINDOWS\iun6002.exe

2009-10-31 15:26:18 ----D---- C:\Program Files\GRETECH

2009-10-31 15:23:30 ----N---- C:\WINDOWS\system32\spmsg.dll

2009-10-31 15:22:14 ----D---- C:\Program Files\xp-AntiSpy

2009-10-31 15:21:54 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\Adobe

2009-10-31 15:21:32 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Adobe

2009-10-31 15:19:35 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\MusicIP

2009-10-31 15:19:23 ----N---- C:\WINDOWS\system32\vxblock.dll

2009-10-31 15:19:23 ----N---- C:\WINDOWS\system32\pxwave.dll

2009-10-31 15:19:23 ----N---- C:\WINDOWS\system32\pxsfs.dll

2009-10-31 15:19:23 ----N---- C:\WINDOWS\system32\pxmas.dll

2009-10-31 15:19:23 ----N---- C:\WINDOWS\system32\pxinsa64.exe

2009-10-31 15:19:23 ----N---- C:\WINDOWS\system32\pxhpinst.exe

2009-10-31 15:19:23 ----N---- C:\WINDOWS\system32\pxdrv.dll

2009-10-31 15:19:23 ----N---- C:\WINDOWS\system32\pxcpya64.exe

2009-10-31 15:19:23 ----N---- C:\WINDOWS\system32\pxafs.dll

2009-10-31 15:19:23 ----N---- C:\WINDOWS\system32\px.dll

2009-10-31 15:18:47 ----D---- C:\Program Files\CCleaner

2009-10-31 15:18:06 ----A---- C:\WINDOWS\system32\h323log.txt

2009-10-31 15:16:15 ----A---- C:\WINDOWS\ODBC.INI

2009-10-31 15:16:12 ----A---- C:\WINDOWS\system32\mdimon.dll

2009-10-31 15:15:51 ----A---- C:\WINDOWS\system32\ativvaxx.dll

2009-10-31 15:15:51 ----A---- C:\WINDOWS\system32\ati3duag.dll

2009-10-31 15:15:51 ----A---- C:\WINDOWS\system32\ati3d1ag.dll

2009-10-31 15:15:50 ----A---- C:\WINDOWS\system32\ati2dvag.dll

2009-10-31 15:15:50 ----A---- C:\WINDOWS\system32\ati2cqag.dll

2009-10-31 15:15:24 ----A---- C:\WINDOWS\system32\usbui.dll

2009-10-31 15:14:18 ----SHD---- C:\WINDOWS\Installer

2009-10-31 15:14:18 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

2009-10-31 15:14:17 ----D---- C:\Program Files\Common Files\ODBC

2009-10-31 15:14:17 ----A---- C:\WINDOWS\ODBCINST.INI

2009-10-31 15:14:15 ----D---- C:\Program Files\Common Files\SpeechEngines

2009-10-31 15:14:14 ----RD---- C:\Program Files

2009-10-31 15:14:14 ----D---- C:\Program Files\Common Files\Microsoft Shared

2009-10-31 15:14:14 ----D---- C:\Program Files\Common Files

2009-10-31 15:14:11 ----RA---- C:\WINDOWS\system32\kbdtuq.dll

2009-10-31 15:14:11 ----RA---- C:\WINDOWS\system32\kbdtuf.dll

2009-10-31 15:14:11 ----RA---- C:\WINDOWS\system32\kbdazel.dll

2009-10-31 15:14:11 ----D---- C:\Program Files\Common Files\DESIGNER

2009-10-31 15:14:10 ----RA---- C:\WINDOWS\system32\kbdycc.dll

2009-10-31 15:14:10 ----RA---- C:\WINDOWS\system32\kbduzb.dll

2009-10-31 15:14:10 ----RA---- C:\WINDOWS\system32\kbdur.dll

2009-10-31 15:14:10 ----RA---- C:\WINDOWS\system32\kbdtat.dll

2009-10-31 15:14:10 ----RA---- C:\WINDOWS\system32\kbdru1.dll

2009-10-31 15:14:10 ----RA---- C:\WINDOWS\system32\kbdru.dll

2009-10-31 15:14:10 ----RA---- C:\WINDOWS\system32\kbdmon.dll

2009-10-31 15:14:10 ----RA---- C:\WINDOWS\system32\kbdkyr.dll

2009-10-31 15:14:10 ----RA---- C:\WINDOWS\system32\kbdkaz.dll

2009-10-31 15:14:10 ----RA---- C:\WINDOWS\system32\kbdaze.dll

2009-10-31 15:14:09 ----RA---- C:\WINDOWS\system32\kbdbu.dll

2009-10-31 15:14:09 ----RA---- C:\WINDOWS\system32\kbdblr.dll

2009-10-31 15:14:08 ----RA---- C:\WINDOWS\system32\kbdhept.dll

2009-10-31 15:14:08 ----RA---- C:\WINDOWS\system32\kbdhela3.dll

2009-10-31 15:14:08 ----RA---- C:\WINDOWS\system32\kbdhela2.dll

2009-10-31 15:14:08 ----RA---- C:\WINDOWS\system32\kbdhe319.dll

2009-10-31 15:14:08 ----RA---- C:\WINDOWS\system32\kbdhe220.dll

2009-10-31 15:14:08 ----RA---- C:\WINDOWS\system32\kbdhe.dll

2009-10-31 15:14:08 ----RA---- C:\WINDOWS\system32\kbdgkl.dll

2009-10-31 15:14:06 ----RA---- C:\WINDOWS\system32\kbdlv1.dll

2009-10-31 15:14:06 ----RA---- C:\WINDOWS\system32\kbdlv.dll

2009-10-31 15:14:06 ----RA---- C:\WINDOWS\system32\kbdlt1.dll

2009-10-31 15:14:06 ----RA---- C:\WINDOWS\system32\kbdlt.dll

2009-10-31 15:14:06 ----RA---- C:\WINDOWS\system32\kbdest.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\kbdycl.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\kbdsl1.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\kbdsl.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\kbdro.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\kbdhu1.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\kbdhu.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\kbdcz2.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\kbdcz1.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\kbdcz.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\kbdcr.dll

2009-10-31 15:14:03 ----A---- C:\WINDOWS\system32\KBDAL.DLL

2009-10-31 15:14:02 ----A---- C:\WINDOWS\system32\spxcoins.dll

2009-10-31 15:14:02 ----A---- C:\WINDOWS\system32\irclass.dll

2009-10-31 15:14:02 ----A---- C:\WINDOWS\system32\EqnClass.Dll

2009-10-31 15:14:02 ----A---- C:\WINDOWS\system32\dgsetup.dll

2009-10-31 15:14:02 ----A---- C:\WINDOWS\system32\dgrpsetu.dll

2009-10-31 15:14:00 ----N---- C:\WINDOWS\system32\CONFIG.TMP

2009-10-31 15:14:00 ----A---- C:\WINDOWS\TASKMAN.EXE

2009-10-31 15:13:59 ----A---- C:\WINDOWS\system32\batt.dll

2009-10-31 15:13:59 ----A---- C:\WINDOWS\NOTEPAD.EXE

2009-10-31 15:13:58 ----A---- C:\WINDOWS\system32\storprop.dll

2009-10-31 15:13:51 ----ASH---- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini

2009-10-31 15:13:47 ----RA---- C:\WINDOWS\SET8.tmp

2009-10-31 15:13:44 ----RA---- C:\WINDOWS\SET4.tmp

2009-10-31 15:13:43 ----RA---- C:\WINDOWS\SET3.tmp

2009-10-31 15:13:38 ----D---- C:\WINDOWS\system32\CatRoot2

2009-10-31 15:13:38 ----D---- C:\WINDOWS\system32\CatRoot

2009-10-31 15:13:33 ----SD---- C:\Documents and Settings\All Users\Dane aplikacji\Microsoft

2009-10-31 15:13:18 ----D---- C:\WINDOWS\SHELLNEW

2009-10-31 15:13:13 ----SHD---- C:\System Volume Information

2009-10-31 15:13:13 ----D---- C:\Documents and Settings

2009-10-31 15:13:07 ----D---- C:\Program Files\Microsoft.NET

2009-10-31 15:13:06 ----D---- C:\Program Files\Microsoft Office

2009-10-31 15:12:02 ----SH---- C:\boot.ini

2009-10-31 15:08:06 ----RSHDC---- C:\WINDOWS\system32\dllcache

2009-10-31 15:08:06 ----RSD---- C:\WINDOWS\Fonts

2009-10-31 15:08:06 ----RD---- C:\WINDOWS\Web

2009-10-31 15:08:06 ----HD---- C:\WINDOWS\inf

2009-10-31 15:08:06 ----D---- C:\WINDOWS\WinSxS

2009-10-31 15:08:06 ----D---- C:\WINDOWS\twain_32

2009-10-31 15:08:06 ----D---- C:\WINDOWS\Temp

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\wins

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\wbem

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\usmt

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\spool

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\ShellExt

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\Setup

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\ras

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\oobe

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\npp

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\mui

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\inetsrv

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\IME

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\icsxml

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\ias

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\export

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\drivers

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\dhcp

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\config

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\3com_dmi

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\3076

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\2052

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\1054

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\1045

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\1042

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\1041

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\1037

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\1033

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\1031

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\1028

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32\1025

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system32

2009-10-31 15:08:06 ----D---- C:\WINDOWS\system

2009-10-31 15:08:06 ----D---- C:\WINDOWS\security

2009-10-31 15:08:06 ----D---- C:\WINDOWS\Resources

2009-10-31 15:08:06 ----D---- C:\WINDOWS\repair

2009-10-31 15:08:06 ----D---- C:\WINDOWS\Provisioning

2009-10-31 15:08:06 ----D---- C:\WINDOWS\PeerNet

2009-10-31 15:08:06 ----D---- C:\WINDOWS\pchealth

2009-10-31 15:08:06 ----D---- C:\WINDOWS\mui

2009-10-31 15:08:06 ----D---- C:\WINDOWS\msapps

2009-10-31 15:08:06 ----D---- C:\WINDOWS\msagent

2009-10-31 15:08:06 ----D---- C:\WINDOWS\Media

2009-10-31 15:08:06 ----D---- C:\WINDOWS\java

2009-10-31 15:08:06 ----D---- C:\WINDOWS\ime

2009-10-31 15:08:06 ----D---- C:\WINDOWS\Help

2009-10-31 15:08:06 ----D---- C:\WINDOWS\ehome

2009-10-31 15:08:06 ----D---- C:\WINDOWS\Driver Cache

2009-10-31 15:08:06 ----D---- C:\WINDOWS\Debug

2009-10-31 15:08:06 ----D---- C:\WINDOWS\Cursors

2009-10-31 15:08:06 ----D---- C:\WINDOWS\Connection Wizard

2009-10-31 15:08:06 ----D---- C:\WINDOWS\Config

2009-10-31 15:08:06 ----D---- C:\WINDOWS\AppPatch

2009-10-31 15:08:06 ----D---- C:\WINDOWS\addins

2009-10-31 15:08:06 ----D---- C:\WINDOWS

2009-10-31 15:07:40 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\CyberLink

2009-10-31 15:07:33 ----D---- C:\Program Files\CyberLink

2009-10-31 15:05:37 ----D---- C:\Program Files\Common Files\Nero

2009-10-31 15:04:41 ----A---- C:\WINDOWS\system32\TwnLib20.dll

2009-10-31 15:04:38 ----N---- C:\WINDOWS\system32\ImagXRA7.dll

2009-10-31 15:04:38 ----N---- C:\WINDOWS\system32\ImagXR7.dll

2009-10-31 15:04:38 ----N---- C:\WINDOWS\system32\ImagXpr7.dll

2009-10-31 15:04:38 ----N---- C:\WINDOWS\system32\ImagX7.dll

2009-10-31 15:04:37 ----A---- C:\WINDOWS\system32\NeroCheck.exe

2009-10-31 15:04:34 ----D---- C:\Program Files\Common Files\Ahead

2009-10-31 15:04:33 ----D---- C:\Program Files\Ahead

2009-10-31 15:03:11 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\ATI

2009-10-31 14:56:23 ----RSD---- C:\WINDOWS\assembly

2009-10-31 14:56:23 ----D---- C:\WINDOWS\system32\URTTemp

2009-10-31 14:56:23 ----D---- C:\WINDOWS\Microsoft.NET

2009-10-31 14:55:56 ----N---- C:\WINDOWS\system32\ati2sgag.exe

2009-10-31 14:55:50 ----RA---- C:\WINDOWS\system32\atiiiexx.dll

2009-10-31 14:55:34 ----D---- C:\Program Files\ATI Technologies

2009-10-31 14:49:01 ----A---- C:\WINDOWS\system32\ksuser.dll

2009-10-31 14:48:59 ----D---- C:\Program Files\Realtek Sound Manager

2009-10-31 14:48:57 ----N---- C:\WINDOWS\avrack.ini

2009-10-31 14:48:57 ----D---- C:\Program Files\AvRack

2009-10-31 14:48:54 ----N---- C:\WINDOWS\system32\ChCfg.exe

2009-10-31 14:48:54 ----A---- C:\WINDOWS\system32\RTLCPAPI.dll

2009-10-31 14:48:54 ----A---- C:\WINDOWS\SOUNDMAN.EXE

2009-10-31 14:48:51 ----A---- C:\WINDOWS\system32\RTLCPL.EXE

2009-10-31 14:48:45 ----N---- C:\WINDOWS\alcupd.exe

2009-10-31 14:48:45 ----N---- C:\WINDOWS\alcrmv.exe

2009-10-31 14:48:22 ----D---- C:\Program Files\AMD

2009-10-31 14:48:21 ----HD---- C:\Program Files\InstallShield Installation Information

2009-10-31 14:48:18 ----D---- C:\Program Files\Common Files\InstallShield

2009-10-31 14:48:08 ----D---- C:\WINDOWS\system32\ReinstallBackups

2009-10-31 14:48:05 ----A---- C:\WINDOWS\system32\UnAGP.exe

2009-10-31 14:48:05 ----A---- C:\WINDOWS\system32\rmagp.exe

2009-10-31 14:48:05 ----A---- C:\WINDOWS\system32\Install.EXE

2009-10-31 14:47:59 ----A---- C:\WINDOWS\IsUninst.exe

2009-10-31 14:45:57 ----SHD---- C:\RECYCLER

2009-10-31 14:29:38 ----D---- C:\Documents and Settings\Blemer\Dane aplikacji\Identities

2009-10-31 14:29:36 ----HD---- C:\Program Files\Uninstall Information

2009-10-31 14:29:31 ----ASH---- C:\Documents and Settings\Blemer\Dane aplikacji\desktop.ini

2009-10-31 14:29:30 ----SD---- C:\Documents and Settings\Blemer\Dane aplikacji\Microsoft

2009-10-31 14:26:50 ----D---- C:\WINDOWS\SoftwareDistribution

2009-10-31 14:26:49 ----D---- C:\WINDOWS\Prefetch

2009-10-31 14:26:48 ----SD---- C:\WINDOWS\system32\Microsoft

2009-10-31 14:26:48 ----A---- C:\WINDOWS\SchedLgU.Txt

2009-10-31 14:23:29 ----D---- C:\WINDOWS\system32\xircom

2009-10-31 14:23:29 ----D---- C:\Program Files\xerox

2009-10-31 14:23:29 ----D---- C:\Program Files\microsoft frontpage

2009-10-31 14:23:11 ----A---- C:\WINDOWS\control.ini

2009-10-31 14:23:11 ----A---- C:\AUTOEXEC.BAT

2009-10-31 14:22:53 ----A---- C:\WINDOWS\system32\mapi32.dll

2009-10-31 14:22:01 ----RD---- C:\WINDOWS\Offline Web Pages

2009-10-31 14:22:00 ----SD---- C:\WINDOWS\Downloaded Program Files

2009-10-31 14:22:00 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest

2009-10-31 14:21:54 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest

2009-10-31 14:21:50 ----HD---- C:\Program Files\WindowsUpdate

2009-10-31 14:21:47 ----D---- C:\Program Files\Usługi online

2009-10-31 14:21:30 ----D---- C:\WINDOWS\system32\DirectX

2009-10-31 14:21:10 ----A---- C:\WINDOWS\system32\atrace.dll

2009-10-31 14:21:08 ----A---- C:\WINDOWS\system32\desktop.ini

2009-10-31 14:21:08 ----A---- C:\WINDOWS\desktop.ini

2009-10-31 14:21:03 ----A---- C:\WINDOWS\system32\nmevtmsg.dll

2009-10-31 14:21:02 ----D---- C:\Program Files\Common Files\Services

2009-10-31 14:21:02 ----A---- C:\WINDOWS\system32\acctres.dll

2009-10-31 14:20:59 ----SD---- C:\WINDOWS\Tasks

2009-10-31 14:20:59 ----A---- C:\WINDOWS\system32\icfgnt5.dll

2009-10-31 14:20:58 ----D---- C:\Program Files\Common Files\MSSoap

2009-10-31 14:20:55 ----D---- C:\WINDOWS\system32\Macromed

2009-10-31 14:20:55 ----D---- C:\WINDOWS\srchasst

2009-10-31 14:20:53 ----A---- C:\WINDOWS\system32\wuweb.dll

2009-10-31 14:20:52 ----A---- C:\WINDOWS\system32\wups.dll

2009-10-31 14:20:52 ----A---- C:\WINDOWS\system32\wucltui.dll

2009-10-31 14:20:52 ----A---- C:\WINDOWS\system32\wuauserv.dll

2009-10-31 14:20:52 ----A---- C:\WINDOWS\system32\wuaueng1.dll

2009-10-31 14:20:52 ----A---- C:\WINDOWS\system32\wuaueng.dll

2009-10-31 14:20:52 ----A---- C:\WINDOWS\system32\wuauclt1.exe

2009-10-31 14:20:52 ----A---- C:\WINDOWS\system32\wuauclt.exe

2009-10-31 14:20:52 ----A---- C:\WINDOWS\system32\wuapi.dll

2009-10-31 14:20:52 ----A---- C:\WINDOWS\system32\bitsprx3.dll

2009-10-31 14:20:51 ----A---- C:\WINDOWS\system32\qmgrprxy.dll

2009-10-31 14:20:51 ----A---- C:\WINDOWS\system32\qmgr.dll

2009-10-31 14:20:51 ----A---- C:\WINDOWS\system32\bitsprx2.dll

2009-10-31 14:20:48 ----D---- C:\Program Files\Movie Maker

2009-10-31 14:20:45 ----A---- C:\WINDOWS\system32\safrslv.dll

2009-10-31 14:20:45 ----A---- C:\WINDOWS\system32\safrdm.dll

2009-10-31 14:20:45 ----A---- C:\WINDOWS\system32\safrcdlg.dll

2009-10-31 14:20:45 ----A---- C:\WINDOWS\system32\racpldlg.dll

2009-10-31 14:20:43 ----A---- C:\WINDOWS\system32\fltmc.exe

2009-10-31 14:20:43 ----A---- C:\WINDOWS\system32\fltlib.dll

2009-10-31 14:20:42 ----D---- C:\WINDOWS\system32\Restore

2009-10-31 14:20:42 ----A---- C:\WINDOWS\system32\srsvc.dll

2009-10-31 14:20:42 ----A---- C:\WINDOWS\system32\srrstr.dll

2009-10-31 14:20:42 ----A---- C:\WINDOWS\system32\srclient.dll

2009-10-31 14:20:42 ----A---- C:\WINDOWS\system32\isrdbg32.dll

2009-10-31 14:20:42 ----A---- C:\WINDOWS\system32\ils.dll

2009-10-31 14:20:41 ----A---- C:\WINDOWS\system32\nmmkcert.dll

2009-10-31 14:20:41 ----A---- C:\WINDOWS\system32\msconf.dll

2009-10-31 14:20:41 ----A---- C:\WINDOWS\system32\mnmsrvc.exe

2009-10-31 14:20:41 ----A---- C:\WINDOWS\system32\mnmdd.dll

2009-10-31 14:20:39 ----D---- C:\Program Files\NetMeeting

2009-10-31 14:20:39 ----A---- C:\WINDOWS\system32\msoert2.dll

2009-10-31 14:20:39 ----A---- C:\WINDOWS\system32\msoeacct.dll

2009-10-31 14:20:38 ----A---- C:\WINDOWS\system32\inetres.dll

2009-10-31 14:20:38 ----A---- C:\WINDOWS\system32\inetcomm.dll

2009-10-31 14:20:37 ----D---- C:\Program Files\Outlook Express

2009-10-31 14:20:37 ----A---- C:\WINDOWS\system32\schedsvc.dll

2009-10-31 14:20:37 ----A---- C:\WINDOWS\system32\mstinit.exe

2009-10-31 14:20:37 ----A---- C:\WINDOWS\system32\mstask.dll

2009-10-31 14:20:36 ----A---- C:\WINDOWS\system32\isign32.dll

2009-10-31 14:20:36 ----A---- C:\WINDOWS\system32\inetcfg.dll

2009-10-31 14:20:36 ----A---- C:\WINDOWS\system32\icwphbk.dll

2009-10-31 14:20:36 ----A---- C:\WINDOWS\system32\icwdial.dll

2009-10-31 14:20:31 ----D---- C:\Program Files\Common Files\System

2009-10-31 14:20:27 ----D---- C:\Program Files\Internet Explorer

2009-10-31 14:19:52 ----D---- C:\Program Files\ComPlus Applications

2009-10-31 14:19:51 ----A---- C:\WINDOWS\vbaddin.ini

2009-10-31 14:19:51 ----A---- C:\WINDOWS\vb.ini

2009-10-31 14:19:47 ----D---- C:\WINDOWS\Registration

2009-10-31 14:19:41 ----D---- C:\Program Files\Windows Media Player

2009-10-31 14:19:33 ----D---- C:\Program Files\MSN Gaming Zone

2009-10-31 14:19:33 ----A---- C:\WINDOWS\system32\write.exe

2009-10-31 14:19:21 ----A---- C:\WINDOWS\system32\winchat.exe

2009-10-31 14:19:21 ----A---- C:\WINDOWS\system32\sndvol32.exe

2009-10-31 14:19:21 ----A---- C:\WINDOWS\system32\hticons.dll

2009-10-31 14:19:21 ----A---- C:\WINDOWS\system32\avwav.dll

2009-10-31 14:19:21 ----A---- C:\WINDOWS\system32\avtapi.dll

2009-10-31 14:19:21 ----A---- C:\WINDOWS\system32\avmeter.dll

2009-10-31 14:19:14 ----A---- C:\WINDOWS\system32\getuname.dll

2009-10-31 14:19:14 ----A---- C:\WINDOWS\system32\charmap.exe

2009-10-31 14:19:14 ----A---- C:\WINDOWS\system32\calc.exe

2009-10-31 14:19:13 ----A---- C:\WINDOWS\system32\winmine.exe

2009-10-31 14:19:13 ----A---- C:\WINDOWS\system32\sol.exe

2009-10-31 14:19:13 ----A---- C:\WINDOWS\system32\mshearts.exe

2009-10-31 14:19:13 ----A---- C:\WINDOWS\system32\freecell.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\usrlogon.cmd

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\tsshutdn.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\tslabels.ini

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\tskill.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\tsdiscon.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\tscon.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\shadow.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\rwinsta.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\reset.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\regini.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\rdpcfgex.dll

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\qwinsta.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\qappsrv.exe

2009-10-31 14:19:12 ----A---- C:\WINDOWS\system32\msg.exe

2009-10-31 14:19:11 ----A---- C:\WINDOWS\system32\msdtcprf.ini

2009-10-31 14:19:11 ----A---- C:\WINDOWS\system32\logoff.exe

2009-10-31 14:19:11 ----A---- C:\WINDOWS\system32\dcomcnfg.exe

2009-10-31 14:19:11 ----A---- C:\WINDOWS\system32\cdmodem.dll

2009-10-31 14:19:10 ----A---- C:\WINDOWS\system32\stclient.dll

2009-10-31 14:19:10 ----A---- C:\WINDOWS\system32\mtxlegih.dll

2009-10-31 14:19:10 ----A---- C:\WINDOWS\system32\mtxex.dll

2009-10-31 14:19:10 ----A---- C:\WINDOWS\system32\mtxdm.dll

2009-10-31 14:19:10 ----A---- C:\WINDOWS\system32\comsnap.dll

2009-10-31 14:19:10 ----A---- C:\WINDOWS\system32\comrepl.dll

2009-10-31 14:19:10 ----A---- C:\WINDOWS\system32\comaddin.dll

2009-10-31 14:19:05 ----A---- C:\WINDOWS\system32\wmimgmt.msc

2009-10-31 14:19:04 ----A---- C:\WINDOWS\system32\sndrec32.exe

2009-10-31 14:19:04 ----A---- C:\WINDOWS\system32\mplay32.exe

2009-10-31 14:19:04 ----A---- C:\WINDOWS\system32\accwiz.exe

2009-10-31 14:19:03 ----D---- C:\Program Files\Windows NT

2009-10-31 14:19:03 ----A---- C:\WINDOWS\system32\spider.exe

2009-10-31 14:19:03 ----A---- C:\WINDOWS\system32\mspaint.exe

2009-10-31 14:19:03 ----A---- C:\WINDOWS\system32\hypertrm.dll

2009-10-31 14:19:03 ----A---- C:\WINDOWS\system32\clipbrd.exe

2009-10-31 14:19:02 ----A---- C:\WINDOWS\system32\tscupgrd.exe

2009-10-31 14:19:02 ----A---- C:\WINDOWS\system32\tscfgwmi.dll

2009-10-31 14:19:02 ----A---- C:\WINDOWS\system32\sessmgr.exe

2009-10-31 14:19:02 ----A---- C:\WINDOWS\system32\remotepg.dll

2009-10-31 14:19:02 ----A---- C:\WINDOWS\system32\rdshost.exe

2009-10-31 14:19:02 ----A---- C:\WINDOWS\system32\rdsaddin.exe

2009-10-31 14:19:02 ----A---- C:\WINDOWS\system32\rdchost.dll

2009-10-31 14:19:02 ----A---- C:\WINDOWS\system32\mstscax.dll

2009-10-31 14:19:02 ----A---- C:\WINDOWS\system32\mstsc.exe

2009-10-31 14:19:01 ----D---- C:\WINDOWS\system32\MsDtc

2009-10-31 14:19:01 ----A---- C:\WINDOWS\system32\termsrv.dll

2009-10-31 14:19:01 ----A---- C:\WINDOWS\system32\rdpwsx.dll

2009-10-31 14:19:01 ----A---- C:\WINDOWS\system32\rdpsnd.dll

2009-10-31 14:19:01 ----A---- C:\WINDOWS\system32\rdpclip.exe

2009-10-31 14:19:01 ----A---- C:\WINDOWS\system32\qprocess.exe

2009-10-31 14:19:01 ----A---- C:\WINDOWS\system32\mtxoci.dll

2009-10-31 14:19:01 ----A---- C:\WINDOWS\system32\msdtcuiu.dll

2009-10-31 14:19:01 ----A---- C:\WINDOWS\system32\msdtcprx.dll

2009-10-31 14:19:01 ----A---- C:\WINDOWS\system32\icaapi.dll

2009-10-31 14:19:01 ----A---- C:\WINDOWS\system32\cfgbkend.dll

2009-10-31 14:19:00 ----D---- C:\WINDOWS\system32\Com

2009-10-31 14:19:00 ----A---- C:\WINDOWS\system32\xolehlp.dll

2009-10-31 14:19:00 ----A---- C:\WINDOWS\system32\msdtctm.dll

2009-10-31 14:19:00 ----A---- C:\WINDOWS\system32\msdtclog.dll

2009-10-31 14:19:00 ----A---- C:\WINDOWS\system32\msdtc.exe

2009-10-31 14:19:00 ----A---- C:\WINDOWS\system32\colbact.dll

2009-10-31 14:18:59 ----A---- C:\WINDOWS\system32\comuid.dll

2009-10-31 14:18:59 ----A---- C:\WINDOWS\system32\comsvcs.dll

2009-10-31 14:18:59 ----A---- C:\WINDOWS\system32\clbcatq.dll

2009-10-31 14:18:59 ----A---- C:\WINDOWS\system32\clbcatex.dll

2009-10-31 14:18:59 ----A---- C:\WINDOWS\system32\catsrvut.dll

2009-10-31 14:18:59 ----A---- C:\WINDOWS\system32\catsrvps.dll

2009-10-31 14:18:59 ----A---- C:\WINDOWS\system32\catsrv.dll

2009-10-31 14:18:53 ----A---- C:\WINDOWS\system32\servdeps.dll

2009-10-31 14:18:53 ----A---- C:\WINDOWS\system32\mmfutil.dll

2009-10-31 14:18:53 ----A---- C:\WINDOWS\system32\licwmi.dll

2009-10-31 14:18:53 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2009-11-01 18:54:19 ----A---- C:\WINDOWS\system32\msvcr71.dll

2009-11-01 18:54:19 ----A---- C:\WINDOWS\system32\msvcp71.dll

2009-10-31 19:46:46 ----A---- C:\WINDOWS\win.ini

2009-10-31 19:46:46 ----A---- C:\WINDOWS\system.ini

2009-10-20 01:08:10 ----A---- C:\WINDOWS\system32\mshtml.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;Sterownik procesora AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 43008]

R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2009-10-31 132296]

R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2009-10-31 25160]

R1 WS2IFSL;Środowisko wspomagające dostawcę usług innych niż IFS - Windows Socket 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]

R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-12-22 2304320]

R3 ASFWHide;ASFWHide; \??\C:\DOCUME~1\Blemer\USTAWI~1\Temp\ASFWHide []

R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-04 1273344]

R3 e4usbaw;USB ADSL2 WAN Adapter; C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2007-01-04 104344]

R3 hidusb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-18 9600]

R3 mouhid;Sterownik myszy HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-26 12160]

R3 usbehci;Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]

R3 usbhub;Koncentrator z obsługą USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]

R3 usbohci;Sterownik Miniport otwartego kontrolera hosta USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]

S2 E4LOADER;General Purpose USB Driver (e4ldr.sys); C:\WINDOWS\System32\Drivers\e4ldr.sys [2007-01-04 69656]

S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-10-29 49920]

S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-10-29 16496]

S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-10-29 21568]

S3 usbccgp;Rodzajowy sterownik nadrzędny USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]

S3 usbprint;Klasa PRINTER USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]

S3 usbscan;Sterownik skanera USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]

S3 USBSTOR;Sterownik magazynu masowego USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]

S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-04 380928]

R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2009-10-31 723632]

R2 hpqddsvc;Usługa HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]

R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]

R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]

R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]

R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]

S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-08-05 516096]

S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]

S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2004-02-04 89136]

-----------------EOF-----------------

Z góry dzeki za pomoc.


(Henio Mazurek) #2

Widzę, że był uruchamiany ComboFix więc z niego też wklej log.

Logi wklej na wklejto.pl a tutaj tylko link do wklejki, nie w poście.


(chalk) #3

Tak combofix był uruchamiany,ale wyskakiwał jakiś błąd i się on wyłączał.


(Henio Mazurek) #4

Jaki błąd wyskakiwał przy uruchomieniu ComboFix'a?

Wklej logi z trochę innych narzędzi,

OTL, uruchom program i pod Custom Scans/Fixes wklej

Następnie przestaw Processes i Modules na All, kliknij Run Scan , wklej log który powstanie ( OTL.txt ) + log Extras.txt który powstanie jako drugi.

GMER, zakładka Rootkit/Malware , klikasz Szukaj , po skanie Kopiuj lub Zapisz.

System Repair Engineer, instrukcja w linku.

Logi wklej na wklejto.pl a tutaj tylko link do wklejki.


(chalk) #5

oto log z OTL:

http://www.wklejto.pl/47493

http://www.wklejto.pl/47494

Log z gmera:

GMER 1.0.15.15227 - http://www.gmer.net

Rootkit quick scan 2009-11-16 21:58:37

Windows 5.1.2600 Dodatek Service Pack 2

Running: gmer.exe; Driver: C:\DOCUME~1\Blemer\USTAWI~1\Temp\ffkyyfod.sys

---- System - GMER 1.0.15 ----

SSDT \??\C:\DOCUME~1\Blemer\USTAWI~1\Temp\ASFWHide ZwQuerySystemInformation [0xF7B90486]

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)

AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)

AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)

AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)

---- EOF - GMER 1.0.15 ----

W przypadku combofixa wyskakiwał komunikat ,że nei możę zanleźćścieżki do katalogu i podawał ścięzkę do katalogu z wirusem.


(Henio Mazurek) #6

Pobierz od nowa ComboFix, zmień mu nazwę w momencie pobierania na losową, uruchom i wklej log.

Napisz co to za katalog.


(chalk) #7

w zasadzie to co chwila comodo krzyczy o jakimś wirusie ,ajk uruchamiam combofixa np podaję ścieżkę c:? 32788r22FWJFW\hidec.exei pare innych w tym katalogu np iexplore.exe, n.exe.Jak wszystko poznazanczam "usuń" to wyskakuje komunikat:ze system windows nie może odnaleźć pliku 32788R22FWJFW\ ( na te katalogi).


(Henio Mazurek) #8

A to Ty nie wiesz, że wszelkie programy zabezpieczające mają być wyłączone na czas pobierania i pracy ComboFix'a?

To wszystko co pokazuje Comodo to od ComboFix.


(chalk) #9

Po wyłączeniu wszystkich programów zabezpieczających: "system windows nie może znaleźć nie może znaleźć określonego urządzenia ścieżki lub pliku. Możesz nie mieć odpowiednich uprawnień aby uzyskać dostęp do elementu". Taki komunikat wyskakuje przy uruchamianiu combofixa.


(Henio Mazurek) #10

Skoro COMODO wybebeszył ComboFix'a to jakim niby sposobem ma działać. Pobierz go na nowo, zmień nazwę na losową i rozszerzenie na com. W momencie pobierania i uruchamiania ComboFix'a COMODO ma być całkowicie zneutralizowany.


(chalk) #11

Robię tak jak piszesz i nadal ten sam komunikat. chyba jednak położę od nowa system....


(Henio Mazurek) #12

Przeskanuj system za pomocą Dr.WEB CureIt, wklej z niego log + logi z OTL, GMER, SRENG.