Witam zrobiłem log ComboFixem i proszę o sprawdzenie, chcę mieć pewność że wszystko jest dobrze.
AV: avast! antivirus 4.8.1356 [VPS 100106-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
- TRYB ZREDUKOWANEJ FUNKCJONALNOŚCI -
.
((((((((((((((((((((((((( Pliki utworzone od 2009-12-06 do 2010-01-06 )))))))))))))))))))))))))))))))
.
2010-01-04 17:11 . 2010-01-04 17:11 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\AnvSoft
2010-01-04 17:10 . 2010-01-04 17:10 -------- d-----w- c:\program files\AnvSoft
2009-12-20 18:16 . 2009-12-20 18:16 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\Ahead
2009-12-20 18:15 . 2003-03-29 15:45 89184 ----a-w- c:\windows\system32\drivers\imagedrv.sys
2009-12-20 18:15 . 2009-12-20 18:15 -------- d-----w- c:\program files\Common Files\Ahead
2009-12-19 12:38 . 2009-12-19 12:38 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-19 12:38 . 2009-12-29 10:36 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\skypePM
2009-12-19 12:35 . 2009-12-29 10:37 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\Skype
2009-12-19 12:33 . 2009-12-19 12:33 -------- d-----w- c:\program files\Common Files\Skype
2009-12-19 12:33 . 2009-12-19 12:34 -------- d-----r- c:\program files\Skype
2009-12-19 12:21 . 2009-12-19 12:38 -------- d-----w- C:\vcs5BGEffects
2009-12-11 13:57 . 2009-12-11 14:13 -------- d-----w- c:\windows\system32\VITrans
2009-12-11 13:57 . 2009-12-11 14:14 -------- d-----w- C:\VTPFiles
2009-12-11 13:57 . 2006-12-03 16:15 111104 ----a-w- c:\windows\system32\Uharc.exe
2009-12-11 13:57 . 2006-12-03 16:15 19968 ----a-w- c:\windows\system32\reico.exe
2009-12-11 13:57 . 2006-12-03 16:15 69632 ----a-w- c:\windows\system32\moveex.exe
2009-12-11 13:57 . 2006-12-03 16:14 8636 ----a-w- c:\windows\system32\modifype.exe
2009-12-11 13:57 . 2004-11-27 18:00 94208 ----a-w- c:\windows\system32\pskill.exe
2009-12-11 13:57 . 2009-03-23 16:39 20480 ----a-w- c:\windows\system32\scrnrdr.exe
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-06 04:14 . 2007-08-18 18:57 -------- d-----w- c:\program files\Microsoft SQL Server
2010-01-05 19:13 . 2009-11-29 13:36 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\TrackMania
2010-01-03 21:51 . 2009-07-18 13:04 12 ----a-w- c:\windows\bthservsdp.dat
2010-01-02 12:05 . 2009-04-29 18:16 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\Any Video Converter
2009-12-27 16:04 . 2007-08-18 18:56 94136 ----a-w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-12-25 21:54 . 2008-09-20 07:55 -------- d-----w- c:\program files\Valve
2009-12-21 18:56 . 2008-09-12 08:39 -------- d-----w- c:\program files\Google
2009-12-20 18:15 . 2008-06-11 13:46 -------- d-----w- c:\program files\Ahead
2009-12-19 12:33 . 2009-03-14 20:47 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Skype
2009-12-14 06:51 . 2009-10-19 05:51 3695616 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-12-13 11:58 . 2008-07-30 16:45 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\GanymedeNet
2009-12-13 11:57 . 2008-07-30 16:40 -------- d-----w- c:\program files\Ganymede
2009-12-12 11:32 . 2007-08-18 18:50 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-10 16:57 . 2007-08-18 19:40 549202 ----a-w- c:\windows\system32\perfh015.dat
2009-12-10 16:57 . 2007-08-18 19:40 107196 ----a-w- c:\windows\system32\perfc015.dat
2009-12-10 16:00 . 2007-08-18 18:54 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2009-12-05 21:03 . 2009-12-05 21:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-29 16:53 . 2009-11-29 16:53 15872 ----a-r- c:\documents and settings\Marcinek\Dane aplikacji\Microsoft\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C9.exe
2009-11-24 19:15 . 2009-11-24 19:15 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-11-24 13:39 . 2008-09-23 16:52 -------- d-----w- c:\program files\Java
2009-11-24 13:38 . 2009-11-24 13:38 152576 ----a-w- c:\documents and settings\Marcinek\Dane aplikacji\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-24 13:37 . 2009-11-24 13:37 79488 ----a-w- c:\documents and settings\Marcinek\Dane aplikacji\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-24 13:32 . 2009-11-23 16:47 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\uTorrent
2009-11-21 08:48 . 2008-08-05 20:15 -------- d-----w- c:\program files\UltraISO
2009-11-21 08:47 . 2009-07-26 16:02 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Norton
2009-11-21 08:47 . 2009-06-26 14:01 -------- d-----w- c:\program files\Norton Security Scan
2009-11-21 08:46 . 2009-11-17 20:06 -------- d-----w- c:\program files\Common Files\Nokia
2009-11-21 08:46 . 2009-11-21 08:46 86016 ----a-w- c:\windows\system32\frapsvid.dll
2009-11-20 18:48 . 2009-08-02 12:26 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\SpeedBit
2009-11-20 18:48 . 2009-06-08 17:47 -------- d---a-w- c:\documents and settings\All Users\Dane aplikacji\TEMP
2009-11-20 18:37 . 2009-08-02 09:14 -------- d-----w- c:\program files\PowerISO
2009-11-20 18:33 . 2009-11-15 19:38 -------- d-----w- c:\program files\Secret Maryo Chronicles
2009-11-20 17:00 . 2007-08-18 19:05 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-11-18 13:59 . 2009-11-18 14:00 33984304 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_pol_web.exe
2009-11-17 20:25 . 2009-11-17 20:25 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-11-17 20:25 . 2009-11-17 20:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-11-17 20:23 . 2009-11-17 20:06 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\PC Suite
2009-11-17 20:19 . 2009-11-17 20:06 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\Nokia
2009-11-17 20:07 . 2009-11-17 20:06 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\PC Suite
2009-11-17 20:07 . 2009-11-17 20:07 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-11-17 20:07 . 2009-11-17 20:07 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-11-17 20:06 . 2009-02-03 19:23 -------- d-----w- c:\program files\DIFX
2009-11-17 20:06 . 2009-11-17 20:05 -------- d-----w- c:\program files\PC Connectivity Solution
2009-11-17 20:04 . 2009-11-17 20:04 95232 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-11-17 20:04 . 2009-11-17 20:04 8192 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-11-17 20:04 . 2009-11-17 20:04 61440 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-11-17 20:04 . 2009-11-17 20:04 10240 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-11-17 20:04 . 2009-11-17 20:04 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Installations
2009-11-17 20:04 . 2009-11-17 20:05 33984304 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\PCsiute.exe
2009-11-16 19:16 . 2009-11-16 19:16 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\GHISLER
2009-11-16 19:14 . 2009-11-06 22:09 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\FileZilla
2009-11-15 21:38 . 2009-11-15 21:38 -------- d-----w- c:\program files\Conduit
2009-11-15 12:11 . 2009-07-04 16:14 -------- d-----w- c:\program files\SpeedFan
2009-11-14 20:10 . 2008-10-16 16:04 -------- d-----w- c:\documents and settings\Marcinek\Dane aplikacji\gtk-2.0
2009-10-29 07:43 . 2007-04-18 12:33 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 06:03 . 2004-08-04 18:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:03 . 2004-08-04 18:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2004-08-04 18:00 263552 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-19 05:51 . 2009-10-19 05:51 562552 -c--a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-10-19 05:51 . 2009-10-19 05:51 566632 -c--a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-10-19 05:51 . 2009-10-19 05:51 2353992 -c--a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-10-19 05:51 . 2009-10-19 05:51 640760 -c--a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-10-19 05:51 . 2009-10-19 05:51 520024 -c--a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-10-19 05:51 . 2009-10-19 05:51 1028432 -c--a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-10-14 16:32 . 2009-10-14 16:32 0 -c--a-w- c:\windows\nsreg.dat
2009-10-13 10:53 . 2004-08-04 18:00 267776 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:54 . 2004-08-04 18:00 69632 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:54 . 2004-08-04 18:00 112640 ----a-w- c:\windows\system32\rastls.dll
2009-10-11 03:17 . 2009-08-29 17:27 411368 ----a-w- c:\windows\system32\deploytk.dll
2004-03-07 09:28 . 2009-10-06 19:22 531 ----a-w- c:\program files\README FIRST.txt
1998-04-30 12:56 . 2008-07-02 11:44 129024 ----a-w- c:\program files\UNWISE.EXE
.
((((((((((((((((((((((((((((( SnapShot_2009-12-22_10.28.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-05 20:25 . 2010-01-05 20:25 16384 c:\windows\Temp\Perflib_Perfdata_b24.dat
+ 2010-01-01 10:52 . 2010-01-01 10:52 16384 c:\windows\Temp\Perflib_Perfdata_6e4.dat
+ 2010-01-05 20:25 . 2010-01-05 20:25 16384 c:\windows\Temp\Perflib_Perfdata_678.dat
+ 2008-08-21 09:30 . 2006-07-28 08:30 62744 c:\windows\system32\xinput1_2.dll
- 2008-08-21 09:30 . 2006-07-28 07:30 62744 c:\windows\system32\xinput1_2.dll
- 2008-08-21 09:30 . 2006-03-31 10:39 62672 c:\windows\system32\xinput1_1.dll
+ 2008-08-21 09:30 . 2006-03-31 11:39 62672 c:\windows\system32\xinput1_1.dll
+ 2004-08-04 18:00 . 2004-08-04 18:00 28672 c:\windows\system32\dllcache\custsat.dll
+ 2009-12-27 08:44 . 2009-12-27 08:44 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2009-12-27 08:44 . 2009-12-27 08:44 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-27 08:44 . 2009-12-27 08:44 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-12-27 08:44 . 2009-12-27 08:44 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-12-27 08:44 . 2009-12-27 08:44 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-27 08:44 . 2009-12-27 08:44 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-27 08:44 . 2009-12-27 08:44 25214 c:\windows\Installer\{C084BC61-E537-11DE-8616-005056806466}\ARPPRODUCTICON.exe
- 2009-08-02 09:55 . 2009-08-02 09:55 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2009-08-02 09:55 . 2009-08-02 09:55 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-12-24 11:55 . 2009-12-24 11:55 5120 c:\windows\Installer\{789289CA-F73A-4A16-A331-54D498CE069F}\Icon789289CA.exe
- 2009-12-21 20:35 . 2009-12-21 20:35 5120 c:\windows\Installer\{789289CA-F73A-4A16-A331-54D498CE069F}\Icon789289CA.exe
- 2008-08-21 09:30 . 2006-07-28 07:30 236824 c:\windows\system32\xactengine2_3.dll
+ 2008-08-21 09:30 . 2006-07-28 08:30 236824 c:\windows\system32\xactengine2_3.dll
+ 2008-08-21 09:30 . 2006-05-31 06:24 230168 c:\windows\system32\xactengine2_2.dll
- 2008-08-21 09:30 . 2006-05-31 05:24 230168 c:\windows\system32\xactengine2_2.dll
- 2008-08-21 09:30 . 2006-03-31 10:39 229584 c:\windows\system32\xactengine2_1.dll
+ 2008-08-21 09:30 . 2006-03-31 11:39 229584 c:\windows\system32\xactengine2_1.dll
+ 2004-08-04 18:00 . 2004-08-04 18:00 146432 c:\windows\system32\dllcache\winspool.drv
- 2004-08-04 19:00 . 2004-08-04 19:00 146432 c:\windows\system32\dllcache\winspool.drv
- 2004-08-04 18:00 . 2004-08-04 18:00 189440 c:\windows\system32\dllcache\smtpadm.dll
+ 2009-07-20 09:47 . 2004-08-03 22:44 189440 c:\windows\system32\dllcache\smtpadm.dll
- 2004-08-04 18:00 . 2004-08-04 18:00 221696 c:\windows\system32\dllcache\seo.dll
+ 2009-07-20 09:47 . 2004-08-03 22:44 221696 c:\windows\system32\dllcache\seo.dll
+ 2003-03-24 13:52 . 2004-08-03 22:43 618605 c:\windows\system32\dllcache\fp4autl.dll
+ 2008-08-21 09:30 . 2006-03-31 10:27 578560 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
- 2008-08-21 09:30 . 2006-03-31 09:27 578560 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
+ 2010-01-06 04:08 . 2010-01-06 04:08 817152 c:\windows\Installer\1a8c6e1.msi
- 2009-08-02 09:55 . 2009-08-02 09:55 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2009-08-02 09:55 . 2009-08-02 09:55 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-08-02 09:55 . 2009-08-02 09:55 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2009-08-02 09:55 . 2009-08-02 09:55 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2009-08-02 09:55 . 2009-08-02 09:55 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-08-21 13:47 . 2008-08-21 13:47 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-12-28 11:04 . 2008-12-28 11:04 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-12-28 11:04 . 2008-12-28 11:04 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-12-28 11:04 . 2008-12-28 11:04 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-12-28 11:04 . 2008-12-28 11:04 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-08-02 09:55 . 2009-08-02 09:55 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-08-02 09:55 . 2009-08-02 09:55 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-12-28 11:04 . 2008-12-28 11:04 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-08-02 09:55 . 2009-08-02 09:55 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2007-08-18 19:35 . 2009-11-22 20:23 1652992 c:\windows\system32\FNTCACHE.DAT
+ 2007-08-18 19:35 . 2009-12-27 16:03 1652992 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-20 09:47 . 2004-08-03 22:44 2134528 c:\windows\system32\dllcache\smtpsnap.dll
- 2004-08-04 18:00 . 2004-08-04 18:00 2134528 c:\windows\system32\dllcache\smtpsnap.dll
- 2008-08-21 09:30 . 2006-03-31 10:40 2388176 c:\windows\system32\d3dx9_30.dll
+ 2008-08-21 09:30 . 2006-03-31 11:40 2388176 c:\windows\system32\d3dx9_30.dll
+ 2009-12-27 08:44 . 2009-12-27 08:44 1262080 c:\windows\Installer\46c4155.msi
- 2008-12-28 11:04 . 2008-12-28 11:04 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2010-01-05 17:24 . 2010-01-05 17:24 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-12-28 11:04 . 2008-12-28 11:04 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-12-22 03:16 . 2009-01-16 09:31 58453856 c:\windows\SoftwareDistribution\Download\Install\SQLServer2005ExpressSP3-KB955706-x86-ENU.exe
.
-- Migawka wyzerowana --
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2007-07-04 475136]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-01-21 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-01-21 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-01-21 134656]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winah20.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Acer Empowering Technology.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Acer Empowering Technology.lnk
backup=c:\windows\pss\Acer Empowering Technology.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Marcinek^Menu Start^Programy^Autostart^UniSpiker-2.6.lnk]
path=c:\documents and settings\Marcinek\Menu Start\Programy\Autostart\UniSpiker-2.6.lnk
backup=c:\windows\pss\UniSpiker-2.6.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\WINDOWS\\system32\\winver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\Program Files\\GG\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Age Of Empires 2 & The Conquerors Expansion - Full Game\\empires2.EXE"=
"c:\\Program Files\\Age Of Empires 2 & The Conquerors Expansion - Full Game\\age2_x1.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\stunt101deville\\counter-strike\\hl.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\stunt101deville\\condition zero\\hl.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\trackmania nations forever\\TmForever.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\trackmania nations forever\\TmForeverLauncher.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\stunt101deville\\condition zero deleted scenes\\hl.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\stunt101deville\\day of defeat\\hl.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8461:TCP"= 8461:TCP:GoD High Port
"8462:TCP"= 8462:TCP:GoD Low Port
"27015:TCP"= 27015:TCP:counetr strike
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-08-04 64160]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [2006-07-05 63352]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-11-24 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-24 20560]
S0 Winah20;Winah20;c:\windows\system32\drivers\Winah20.sys [2004-08-04 31616]
S2 gupdate1c989e6f7005f90;Google Update Service (gupdate1c989e6f7005f90);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-07-03 1028432]
S3 PAC207;Trust WB-1200p Mini Webcam;c:\windows\system32\DRIVERS\pfc027.sys --> c:\windows\system32\DRIVERS\pfc027.sys [?]
S3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\drivers\DB3G.sys [2009-02-03 13225]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-06-10 717296]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
wmcmgc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{Y2F05033-7NVM-FV51-G71C-8DB8O18IYDNQ}]
c:\documents and settings\Marcinek\Dane aplikacji\svchost.exe Restart
.
Zawartość folderu 'Zaplanowane zadania'
2010-01-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 05:51]
2010-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 12:15]
2010-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 12:15]
2010-01-06 c:\windows\Tasks\User_Feed_Synchronization-{44E41BEF-89AB-4027-B19D-51D4DF6F1E0A}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.ask.com?o=15161&l=dis
uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCxdm490YYPL&fl=0&ptb=pHacLk5Eq5QgEsqX634myA&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search -
http://edits.mywebsearch.com/toolbar...p=ZCxdm490YYPL
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {3F44642C-960F-4A2F-AC61-94964C9AB846} = 194.204.152.34,194.204.159.1
DPF: {18506D80-9B80-11D4-82C2-0080C8D7ED4A} - hxxp://download.gamedesire.com/g_bin/pl/roulette_2_0_0_27.cab
DPF: {2A781DED-4153-C22D-9812-CEA98A32981C} - hxxp://cached.gamedesire.com/g_bin/pl/cardsmakao_2_0_0_32.cab
DPF: {2A781DED-C22D-4153-9812-CEA98A32981C} - hxxp://cached.gamedesire.com/g_bin/pl/cardsmakao_2_0_0_29.cab
DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} - hxxp://powersoccer.minigry.pl/applet/PowerLoader.cab
DPF: {83AFB5CA-11D4-ED35-A452-0080C8D85045} - hxxp://cached.gamedesire.com/g_bin/pl/poker_2_0_0_52.cab
DPF: {A6212120-01D4-11D5-9A39-0080C8D85044} - hxxp://download.gamedesire.com/g_bin/pl/slots70_2_0_0_35.cab
DPF: {AC120B1D-9411-4111-AF52-118052D85D45} - hxxp://download.gamedesire.com/g_bin/pl/darts_2_0_0_42.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game10.zylom.com/activex/zylomgamesplayer.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://195.74.79.83:30/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Marcinek\Dane aplikacji\Mozilla\Firefox\Profiles\uxhh8gyo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2304564&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
Google
FF - prefs.js: keyword.URL -
FF - component: c:\documents and settings\Marcinek\Dane aplikacji\Mozilla\Firefox\Profiles\uxhh8gyo.default\extensions\{48405d3d-2674-4cd8-b1ef-9a719443bd3f}\components\FFExternalAlert.dll
FF - plugin: c:\documents and settings\Marcinek\Dane aplikacji\Nowe Gadu-Gadu\_userdata\npgg.1.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npganymedenet.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPSNOOKER.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2010-01-06 21:20
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(912)
c:\windows\system32\igfxdev.dll
- - - - - - - > 'explorer.exe'(1364)
c:\windows\system32\WININET.dll
c:\acer\Empowering Technology\ePower\SysHook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Czas ukończenia: 2010-01-06 21:24
ComboFix-quarantined-files.txt 2010-01-06 20:24
ComboFix2.txt 2010-01-02 19:32
ComboFix3.txt 2009-12-22 10:33
ComboFix4.txt 2009-12-10 20:20
ComboFix5.txt 2010-01-06 20:17
Przed: 26*110*447*616 bajtów wolnych
Po: 26*151*350*272 bajtów wolnych
- - End Of File - - F99890AD5F49B32BCFC4E6DD063FE57D