
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:35:10, on 2008-06-14
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\RunDll32.exe
D:\Programy\ZoneAlarm\zlclient.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\A4Tech\Mouse\Amoumain.exe
C:\WINNT\system32\ctfmon.exe
D:\Programy\Adaware\aawservice.exe
C:\Program Files\Opera\Opera.exe
D:\Instalki\Bezpieczeństwo\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Programy\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Programy\reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Programy\Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://D:\Programy\Office\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Programy\Adaware\aawservice.exe
O23 - Service: Urządzenie mobilne Apple (Apple Mobile Device) - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
--
End of file - 5267 bytes
i z ComboFixa:
ComboFix 08-06-07.3 - Grazka&Art 2008-06-14 8:36:15.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1401 [GMT 2:00]
Running from: D:\Instalki\Bezpieczeństwo\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-14 to 2008-06-14 )))))))))))))))))))))))))))))))
.
2008-06-14 08:15 . 2008-06-14 08:15 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-08 17:07 . 2008-06-08 17:07 98,304 --a------ C:\WINNT\system32\CmdLineExt.dll
2008-06-08 08:31 . 2008-06-14 08:37 <DIR> d--h----- C:\Documents and Settings\Administrator\Ustawienia lokalne
2008-06-08 08:31 . 2008-01-21 01:36 <DIR> d-------- C:\Documents and Settings\Administrator\Ulubione
2008-06-08 08:31 . 2008-01-20 17:41 <DIR> d--h----- C:\Documents and Settings\Administrator\Szablony
2008-06-08 08:31 . 2008-01-21 01:36 <DIR> d-------- C:\Documents and Settings\Administrator\Pulpit
2008-06-08 08:31 . 2008-01-21 01:36 <DIR> d-------- C:\Documents and Settings\Administrator\Moje dokumenty
2008-06-08 08:31 . 2008-01-21 01:36 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Start
2008-06-08 08:31 . 2008-01-21 01:36 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dane aplikacji
2008-06-08 08:31 . 2008-06-08 08:31 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-08 01:38 . 2008-06-08 01:38 0 --a------ C:\WINNT\BMd3b440ab.xml
2008-06-07 23:03 . 2008-06-07 23:03 82,944 --a------ C:\WINNT\system32\hoabiaps.dll
2008-06-07 22:58 . 2008-06-07 22:58 <DIR> d-------- C:\WINNT\system32\xircom
2008-06-07 22:58 . 2008-06-07 22:58 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-06-07 15:50 . 2008-06-14 08:23 <DIR> dr-h----- C:\$VAULT$.AVG
2008-06-06 23:14 . 2008-06-06 23:14 <DIR> d-------- C:\Program Files\Microsoft Games
2008-05-28 00:32 . 2008-05-28 00:32 <DIR> d-------- C:\Documents and Settings\Grazka&Art\Dane aplikacji\Apple Computer
2008-05-28 00:31 . 2008-05-28 00:32 <DIR> d-------- C:\Program Files\QuickTime
2008-05-28 00:31 . 2008-05-28 00:31 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-05-28 00:31 . 2008-05-28 00:31 <DIR> d-------- C:\Program Files\Apple Software Update
2008-05-28 00:31 . 2008-06-08 09:09 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2008-05-28 00:31 . 2008-05-28 00:31 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 06:37 45,553,696 --sha-w C:\WINNT\system32\drivers\fidbox.dat
2008-06-14 06:12 --------- d-----w C:\Documents and Settings\LocalService\Dane aplikacji\AVG7
2008-06-13 23:38 532,040 --sha-w C:\WINNT\system32\drivers\fidbox.idx
2008-06-13 20:42 --------- d-----w C:\Documents and Settings\Grazka&Art\Dane aplikacji\AVG7
2008-06-11 13:57 5,584,029 ----a-w C:\WINNT\Internet Logs\tvDebug.zip
2008-06-08 14:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-08 07:11 --------- d-----w C:\Documents and Settings\Grazka&Art\Dane aplikacji\Skype
2008-06-07 21:13 --------- d-----w C:\Program Files\Opera
2008-06-07 13:56 2,042,368 ----a-w C:\WINNT\Internet Logs\xDB4.tmp
2008-05-31 16:01 --------- d-----w C:\Documents and Settings\Grazka&Art\Dane aplikacji\BitTorrent
2008-05-30 16:58 --------- d-----w C:\Documents and Settings\Grazka&Art\Dane aplikacji\teamspeak2
2008-05-22 06:06 1,568,768 ----a-w C:\WINNT\Internet Logs\xDB3.tmp
2008-05-11 07:47 --------- d-----w C:\Program Files\Autodesk
2008-05-02 08:22 2,672,128 ----a-w C:\WINNT\Internet Logs\xDB2.tmp
2008-05-02 05:49 --------- d-----w C:\Documents and Settings\Grazka&Art\Dane aplikacji\GeoVid
2008-05-02 05:48 --------- d-----w C:\Program Files\Common Files\GeoVid
2008-04-25 18:51 1,654,272 ----a-w C:\WINNT\Internet Logs\xDB1.tmp
2008-01-30 11:27 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2004-10-01 14:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-08_ 9.06.54,45 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-02-10 14:16:14 53,248 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-06-08 15:06:47 53,248 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2008-02-10 14:16:14 12,800 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-06-08 15:06:47 12,800 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2008-02-10 14:16:15 473,600 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-06-08 15:06:47 473,600 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2008-02-10 14:16:10 2,676,224 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-08 15:06:44 2,676,224 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-10 14:16:11 2,846,720 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-08 15:06:45 2,846,720 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-10 14:16:12 563,712 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-08 15:06:45 563,712 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-10 14:16:12 567,296 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-08 15:06:45 567,296 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-10 14:16:12 576,000 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-08 15:06:46 576,000 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-10 14:16:13 577,024 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-08 15:06:46 577,024 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-10 14:16:13 577,536 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-08 15:06:46 577,536 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-10 14:16:13 577,536 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-08 15:06:46 577,536 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-10 14:16:14 578,560 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-08 15:06:47 578,560 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-10 14:16:15 578,560 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-06-08 15:06:48 578,560 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-02-10 14:16:15 145,920 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-06-08 15:06:48 145,920 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2008-02-10 14:16:15 159,232 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-06-08 15:06:48 159,232 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2008-02-10 14:16:15 364,544 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-06-08 15:06:48 364,544 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2008-02-10 14:16:15 178,176 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-06-08 15:06:48 178,176 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2008-02-10 14:16:14 223,232 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-06-08 15:06:47 223,232 ----a-w C:\WINNT\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2008-06-08 07:01:18 2,048 --s-a-w C:\WINNT\bootstat.dat
+ 2008-06-14 05:34:36 2,048 --s-a-w C:\WINNT\bootstat.dat
- 2008-04-25 18:42:46 1,038,336 ----a-r C:\WINNT\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
+ 2008-06-14 06:15:43 1,038,336 ----a-r C:\WINNT\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
- 2008-04-25 18:42:46 178,688 ----a-r C:\WINNT\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
+ 2008-06-14 06:15:43 178,688 ----a-r C:\WINNT\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
- 2008-04-25 18:42:46 171,008 ----a-r C:\WINNT\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe
+ 2008-06-14 06:15:43 171,008 ----a-r C:\WINNT\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe
- 2008-04-25 18:42:46 8,704 ----a-r C:\WINNT\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe
+ 2008-06-14 06:15:43 8,704 ----a-r C:\WINNT\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe
- 2005-05-04 13:45:28 15,584 ------w C:\WINNT\system32\spmsg.dll
+ 2005-05-04 12:45:28 15,584 ------w C:\WINNT\system32\spmsg.dll
+ 2008-06-14 06:21:10 16,384 ----atw C:\WINNT\Temp\Perflib_Perfdata_ebc.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [2008-01-20 19:22 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-01-20 19:22 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 02:44 15360]
"DriverUpdaterPro"="C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 13:35 90112]
"C6501Sound"="c6501.cpl" []
"ZoneAlarm Client"="D:\Programy\ZoneAlarm\zlclient.exe" [2007-11-14 17:05 919016]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-16 17:29 579584]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 21:24 32768]
"Adobe Reader Speed Launcher"="D:\Programy\reader\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"WheelMouse"="C:\Program Files\A4Tech\Mouse\Amoumain.exe" [2006-08-04 17:55 147456]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINNT\system32\CTFMON.EXE" [2004-08-04 02:44 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-26 23:56 219136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINNT\system32\tscupgrd.exe" [2004-08-04 02:33 44544]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-01-20 19:28:32 113664]
Microsoft Office.lnk - D:\Programy\Office\Office10\OSA.EXE [2001-02-13 11:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= D:\Programy\ACEMEG~1\SystemS\Intel\iac25_32.ax
"vidc.avrn"= D:\Programy\ACEMEG~1\SystemS\AVIDAV~1.DLL
"vidc.advj"= D:\Programy\ACEMEG~1\SystemS\AVIDAV~1.DLL
"vidc.mszh"= D:\Programy\ACEMEG~1\SystemS\avimszh.dll
"vidc.zlib"= D:\Programy\ACEMEG~1\SystemS\avizlib.dll
"vidc.cscd"= D:\Programy\ACEMEG~1\SystemS\camcodec.dll
"vidc.cvid"= D:\Programy\ACEMEG~1\SystemS\iccvid.dll
"msacm.trspch"= D:\Programy\ACEMEG~1\SystemS\tssoft32.acm
"vidc.em2v"= D:\Programy\ACEMEG~1\SystemS\etxcodec.dll
"vidc.mkvc"= D:\Programy\ACEMEG~1\SystemS\kmvidc32.dll
"vidc.hfyu"= D:\Programy\ACEMEG~1\SystemS\huffyuv.dll
"msacm.lameacm"= D:\Programy\ACEMEG~1\SystemS\lameacm.acm
"msacm.lhacm"= D:\Programy\ACEMEG~1\SystemS\lhacm.acm
"msacm.l3acm"= D:\Programy\ACEMEG~1\SystemS\l3codecp.acm
"vidc.sjpg"= D:\Programy\ACEMEG~1\SystemS\pmjpeg32.dll
"vidc.dmb2"= D:\Programy\ACEMEG~1\SystemS\pmjpeg32.dll
"vidc.gepj"= D:\Programy\ACEMEG~1\SystemS\pmjpeg32.dll
"vidc.qpeg"= D:\Programy\ACEMEG~1\SystemS\Qpeg32.dll
"vidc.q1.0"= D:\Programy\ACEMEG~1\SystemS\Qpeg32.dll
"msacm.sl_anet"= D:\Programy\ACEMEG~1\SystemS\sl_anet.acm
"vidc.tscc"= D:\Programy\ACEMEG~1\SystemS\tsccvid.dll
"vidc.vifp"= D:\Programy\ACEMEG~1\SystemS\vfcodec.dll
"vidc.wrpr"= D:\Programy\ACEMEG~1\SystemS\aviwrap.dll
"vidc.wnv1"= D:\Programy\ACEMEG~1\SystemS\wnvplay1.dll
"vidc.advs"= D:\Programy\ACEMEG~1\SystemS\Adaptec\Dvc.dll
"vidc.aflc"= D:\Programy\ACEMEG~1\SystemS\Autodesk\FLCCOD~1.DLL
"vidc.afli"= D:\Programy\ACEMEG~1\SystemS\Autodesk\FLCCOD~1.DLL
"vidc.aasc"= D:\Programy\ACEMEG~1\SystemS\Autodesk\Aasc32.dll
"vidc.aas4"= D:\Programy\ACEMEG~1\SystemS\Autodesk\Aasc32.dll
"vidc.asv1"= D:\Programy\ACEMEG~1\SystemS\ASUS\asusasv1.dll
"vidc.asv2"= D:\Programy\ACEMEG~1\SystemS\ASUS\asusasv2.dll
"vidc.asvx"= D:\Programy\ACEMEG~1\SystemS\ASUS\asusasv2.dll
"vidc.vcr1"= D:\Programy\ACEMEG~1\SystemS\ATI\ativcr1.dll
"vidc.vcr2"= D:\Programy\ACEMEG~1\SystemS\ATI\ativcr2.dll
"vidc.yv12"= D:\Programy\ACEMEG~1\SystemS\ATI\atiyuv12.DLL
"vidc.mwv1"= D:\Programy\ACEMEG~1\SystemS\Aware\icmw_32.dll
"vidc.bt20"= D:\Programy\ACEMEG~1\SystemS\BROOKT~1\btvvc32.drv
"vidc.y41p"= D:\Programy\ACEMEG~1\SystemS\BROOKT~1\btvvc32.drv
"msacm.pcdv"= D:\Programy\ACEMEG~1\SystemS\Canopus\pcdv.acm
"vidc.cdvc"= D:\Programy\ACEMEG~1\SystemS\Canopus\CSCCDVC.DLL
"vidc.ddvc"= D:\Programy\ACEMEG~1\SystemS\Canopus\CSCdvsd.DLL
"vidc.png1"= D:\Programy\ACEMEG~1\SystemS\Core\COREPN~1.DLL
"msacm.CoreFLAC_ACM"= D:\Programy\ACEMEG~1\SystemS\Core\COREFL~1.ACM
"vidc.davc"= D:\Programy\ACEMEG~1\SystemS\dicas\davcvfw.dll
"vidc.div3"= D:\Programy\ACEMEG~1\SystemS\DivX\DivXc32.dll
"vidc.div5"= D:\Programy\ACEMEG~1\SystemS\DivX\DivXc32.dll
"vidc.mpg3"= D:\Programy\ACEMEG~1\SystemS\DivX\DivXc32.dll
"vidc.div4"= D:\Programy\ACEMEG~1\SystemS\DivX\DivXc32f.dll
"vidc.div6"= D:\Programy\ACEMEG~1\SystemS\DivX\DivXc32f.dll
"vidc.ap41"= D:\Programy\ACEMEG~1\SystemS\DivX\DivXc32f.dll
"vidc.dvx4"= D:\Programy\ACEMEG~1\SystemS\DivX\divx4.dll
"vidc.divx"= D:\Programy\ACEMEG~1\SystemS\DivX\DivX520.dll
"msacm.divxa32"= D:\Programy\ACEMEG~1\SystemS\DivX\divxa32.acm
"vidc.frwd"= D:\Programy\ACEMEG~1\SystemS\Forward\frwd.dll
"vidc.frwt"= D:\Programy\ACEMEG~1\SystemS\Forward\frwd.dll
"vidc.frwa"= D:\Programy\ACEMEG~1\SystemS\Forward\frwt.dll
"vidc.frwu"= D:\Programy\ACEMEG~1\SystemS\Forward\frwu.dll
"vidc.glzw"= D:\Programy\ACEMEG~1\SystemS\Gabest\GLZW.dll
"vidc.gpeg"= D:\Programy\ACEMEG~1\SystemS\Gabest\GPEG.dll
"vidc.i263"= D:\Programy\ACEMEG~1\SystemS\Intel\i263_32.drv
"vidc.iv30"= D:\Programy\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv31"= D:\Programy\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv32"= D:\Programy\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv33"= D:\Programy\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv34"= D:\Programy\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv35"= D:\Programy\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv36"= D:\Programy\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv37"= D:\Programy\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv38"= D:\Programy\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv39"= D:\Programy\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv40"= D:\Programy\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv41"= D:\Programy\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv42"= D:\Programy\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv43"= D:\Programy\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv44"= D:\Programy\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv45"= D:\Programy\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv46"= D:\Programy\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv47"= D:\Programy\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv48"= D:\Programy\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv49"= D:\Programy\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv50"= D:\Programy\ACEMEG~1\SystemS\Intel\ir50_32.dll
"vidc.iyuv"= D:\Programy\ACEMEG~1\SystemS\Intel\iyuv_32.dll
"vidc.yvu9"= D:\Programy\ACEMEG~1\SystemS\Intel\Iyvu9_32.dll
"vidc.ir21"= D:\Programy\ACEMEG~1\SystemS\Intel\IR21_R.DLL
"vidc.rt21"= D:\Programy\ACEMEG~1\SystemS\Intel\IR21_R.DLL
"msacm.imc"= D:\Programy\ACEMEG~1\SystemS\Intel\IMC32.ACM
"vidc.lead"= D:\Programy\ACEMEG~1\SystemS\LEAD\LCODCCMP.DLL
"vidc.dvsd"= D:\Programy\ACEMEG~1\SystemS\MAINCO~1\MCDVD_32.DLL
"vidc.dvc"= D:\Programy\ACEMEG~1\SystemS\MAINCO~1\MCDVD_32.DLL
"vidc.dvcs"= D:\Programy\ACEMEG~1\SystemS\MAINCO~1\MCDVD_32.DLL
"vidc.dcmj"= D:\Programy\ACEMEG~1\SystemS\MAINCO~1\MCMJPG32.DLL
"vidc.avi1"= D:\Programy\ACEMEG~1\SystemS\MAINCO~1\MCMJPG32.DLL
"vidc.avi2"= D:\Programy\ACEMEG~1\SystemS\MAINCO~1\MCMJPG32.DLL
"vidc.dv25"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.dv50"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.msmc"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mmjp"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx1"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx2"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx3"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx4"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx5"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx6"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx7"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx8"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mtx9"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.mmes"= D:\Programy\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"msacm.msadpcm"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msadp32.acm
"msacm.imaadpcm"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\imaadp32.acm
"msacm.msg711"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msg711.acm
"msacm.msg723"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msg723.acm
"msacm.msgsm610"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msgsm32.acm
"vidc.m261"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msh261.drv
"vidc.m263"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msh263.drv
"vidc.i420"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msh263.drv
"vidc.mrle"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msrle32.dll
"vidc.uyvy"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yuy2"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yvyu"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.msvc"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msvidc32.dll
"vidc.cram"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msvidc32.dll
"vidc.mpg4"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\mpg4c32.dll
"vidc.mp41"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\mpg4c32.dll
"vidc.mp42"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\mpg4c32.dll
"vidc.mp43"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\mpg4c32.dll
"vidc.mp4s"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\mpg4c32.dll
"vidc.mp4v"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\mpg4c32.dll
"vidc.wmv3"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\WMV9VCM.dll
"msacm.msaudio1"= D:\Programy\ACEMEG~1\SystemS\MICROS~1\msaud32.acm
"vidc.vixl"= D:\Programy\ACEMEG~1\SystemS\Miro\miroxl32.dll
"vidc.nt00"= D:\Programy\ACEMEG~1\SystemS\Newtek\ntcodec.dll
"msacm.vorbis"= D:\Programy\ACEMEG~1\SystemS\OGG\vorbis.acm
"vidc.vp30"= D:\Programy\ACEMEG~1\SystemS\ON2TEC~1\vp31vfw.dll
"vidc.vp31"= D:\Programy\ACEMEG~1\SystemS\ON2TEC~1\vp31vfw.dll
"vidc.vp60"= D:\Programy\ACEMEG~1\SystemS\ON2TEC~1\vp6vfw.dll
"vidc.vp61"= D:\Programy\ACEMEG~1\SystemS\ON2TEC~1\vp6vfw.dll
"vidc.pdvc"= D:\Programy\ACEMEG~1\SystemS\PANASO~1\idvcodec.dll
"vidc.ipdv"= D:\Programy\ACEMEG~1\SystemS\PANASO~1\idvcodec.dll
"vidc.pvw2"= D:\Programy\ACEMEG~1\SystemS\Pegasus\pvwv220.dll
"vidc.pimj"= D:\Programy\ACEMEG~1\SystemS\Pegasus\pvljpg20.dll
"vidc.mjpx"= D:\Programy\ACEMEG~1\SystemS\Pegasus\pvmjpg21.dll
"vidc.miro"= D:\Programy\ACEMEG~1\SystemS\Pinnacle\MIRODV~1.DLL
"vidc.dcap"= D:\Programy\ACEMEG~1\SystemS\Pinnacle\MIRODV~1.DLL
"vidc.mjpa"= D:\Programy\ACEMEG~1\SystemS\Pinnacle\RTMJPG~1.DLL
"vidc.gpjm"= D:\Programy\ACEMEG~1\SystemS\Pinnacle\RTMJPG~1.DLL
"vidc.pim1"= D:\Programy\ACEMEG~1\SystemS\Pinnacle\pclepim1.dll
"msacm.qmpeg"= D:\Programy\ACEMEG~1\SystemS\QDesign\qmpeg.acm
"vidc.rmp4"= D:\Programy\ACEMEG~1\SystemS\REALMA~1\rmp4.dll
"vidc.rud0"= D:\Programy\ACEMEG~1\SystemS\Rududu\rududu.dll
"msacm.at3"= D:\Programy\ACEMEG~1\SystemS\SONY\atrac3.acm
"vidc.sony"= D:\Programy\ACEMEG~1\SystemS\SONY\sonydv.dll
"vidc.dvcp"= D:\Programy\ACEMEG~1\SystemS\SONY\sonydv.dll
"vidc.s422"= D:\Programy\ACEMEG~1\SystemS\Tekram\tekyuv.dll
"vidc.t420"= D:\Programy\ACEMEG~1\SystemS\Toshiba\tsbyuv.dll
"vidc.y411"= D:\Programy\ACEMEG~1\SystemS\Toshiba\tsbyuv.dll
"vidc.vssv"= D:\Programy\ACEMEG~1\SystemS\VANGUA~1\vsscodec.dll
"msacm.voxacm160"= D:\Programy\ACEMEG~1\SystemS\VoxWare\vct3216.acm
"vidc.xvid"= D:\Programy\ACEMEG~1\SystemS\XviD\xvidvfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverUpdaterPro]
C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
D:\Programy\itunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 17:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Programy\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Microsoft Games\\Dungeon Siege 2\\DungeonSiege2.exe"=
"D:\\Gry\\nw2\\nwn2main.exe"=
"D:\\Gry\\nw2\\nwn2main_amdxp.exe"=
"D:\\Gry\\nw2\\nwupdate.exe"=
"D:\\Gry\\nw2\\nwn2server.exe"=
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface;C:\WINNT\system32\drivers\c6501.sys [2007-07-10 03:42]
*Newly Created Service* - AAWSERVICE
.
Contents of the 'Scheduled Tasks' folder
"2008-06-13 09:46:01 C:\WINNT\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-14 08:37:21
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-14 8:37:52
ComboFix-quarantined-files.txt 2008-06-14 06:37:49
ComboFix2.txt 2008-06-08 07:07:06
Pre-Run: 11,171,160,064 bajtów wolnych
Post-Run: 11,151,056,896 bajtów wolnych
346