1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154. |
DDS (Ver_09-09-29.01) - NTFSx86
Run by Przemysaw at 20:28:26,35 on 2010-03-05
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.2038.1346 [GMT 1:00]
AV: Norton AntiVirus *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FW: Outpost Firewall Pro *enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Documents and Settings\Przemysław\Pulpit\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.pl/
uInternet Connection Wizard,ShellNext = iexplore
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
BHO: Expressivo: {85f685c3-20d9-4943-95e4-eb4224056c3f} - c:\program files\ivo\expressivo\integr\ih-iexplorer\IH_iexplorer.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Expressivo: {85f685c3-20d9-4943-95e4-eb4224056c3f} - c:\program files\ivo\expressivo\integr\ih-iexplorer\IH_iexplorer.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [OutpostMonitor] c:\progra~1\agnitum\outpos~1\op_mon.exe /tray /noservice
mRun: [OutpostFeedBack] "c:\program files\agnitum\outpost firewall pro\feedback.exe" /dump:os_startup
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\menust~1\programy\autost~1\blueto~1.lnk - c:\program files\toshiba\bluetooth toshiba stack\TosBtMng.exe
StartupFolder: c:\docume~1\alluse~1\menust~1\programy\autost~1\autoru~1\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\menust~1\programy\autost~1\autoru~1\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: Download by GAS - c:\progra~1\getasf~1\ie_MenuExt.htm
IE: E&ksport do programu Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Funkcja Google Sidewiki - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {44627E97-789B-40d4-B5C2-58BD171129A1} - {A1A7E22D-1587-4230-8F16-081C68D21448} - c:\program files\agnitum\outpost firewall pro\ie_bar.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {132DDA35-4981-4D21-9598-9523BFEC295A} = 194.204.152.34 194.204.159.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\agnitum\outpos~1\wl_hook.dll
============= SERVICES / DRIVERS ===============
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [2009-11-2 673920]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\agnitum\outpos~1\acs.exe [2009-11-2 1238344]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [2009-11-2 30864]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2009-11-2 234640]
R3 ASWFilt;ASWFilt;c:\windows\system32\filt\ASWFilt.dll [2009-11-2 33408]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-2-16 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100305.004\NAVENG.SYS [2010-3-5 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100305.004\NAVEX15.SYS [2010-3-5 1324720]
R3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2009-12-23 1245064]
S2 gupdate;Usługa Google Update (gupdate);"c:\program files\google\update\googleupdate.exe" /svc --> c:\program files\google\update\GoogleUpdate.exe [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2010-3-4 0]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
=============== Created Last 30 ================
2010-03-05 18:13 <DIR> --d-hr-- c:\documents and settings\przemysław\Recent
2010-03-05 14:15 <DIR> --d----- c:\docume~1\alluse~1\daneap~1\KONAMI
2010-03-05 14:06 <DIR> --d----- c:\program files\KONAMI
2010-03-05 13:07 <DIR> --d----- c:\program files\FastStone Capture
2010-03-05 12:55 <DIR> --d----- c:\docume~1\przemy~1\daneap~1\FastStone
2010-03-05 12:51 293,376 -------- c:\windows\system32\browserchoice.exe
2010-03-04 20:37 0 a------- c:\windows\system32\drivers\DrvAgent32.sys
2010-02-28 19:08 3,686,454 a------- c:\windows\gry.bmp
2010-02-27 13:59 <DIR> --d----- c:\docume~1\przemy~1\daneap~1\TVU Networks
2010-02-27 11:17 139,264 a------- c:\windows\system32\eax.dll
2010-02-26 20:34 <DIR> --d----- c:\docume~1\przemy~1\daneap~1\Styler
2010-02-26 20:33 <DIR> --d----- c:\program files\Styler
2010-02-20 15:51 <DIR> --d----- c:\program files\Free Pascal
2010-02-18 16:15 <DIR> --d----- c:\docume~1\przemy~1\daneap~1\AnvSoft
2010-02-18 16:15 <DIR> --d----- c:\program files\AnvSoft
2010-02-16 16:54 <DIR> --d----- c:\program files\Team17
2010-02-15 17:26 83 a------- c:\windows\WWP.INI
2010-02-13 14:32 1,409 a------- c:\windows\system32\tmpE9C2E.FOT
2010-02-13 14:32 1,409 a------- c:\windows\system32\tmp71B2E.FOT
2010-02-13 14:32 1,409 a------- c:\windows\system32\tmp56B2E.FOT
2010-02-13 14:32 1,409 a------- c:\windows\system32\tmp3BB2E.FOT
2010-02-13 14:32 1,409 a------- c:\windows\system32\tmp2FB2E.FOT
2010-02-13 14:32 1,409 a------- c:\windows\system32\tmp05C2E.FOT
2010-02-13 14:32 1,409 a------- c:\windows\system32\tmpB7A2E.FOT
2010-02-13 14:32 1,409 a------- c:\windows\system32\tmp9CA2E.FOT
2010-02-11 10:21 <DIR> --d----- c:\program files\CAPCOM
2010-02-07 13:57 107,888 a------- c:\windows\system32\CmdLineExt.dll
==================== Find3M ====================
2010-03-05 19:05 6,029,312 a---h--- c:\documents and settings\przemysław\NTUSER.DAT
2010-01-04 13:06 490,866 a------- c:\windows\system32\perfh015.dat
2010-01-04 13:06 84,078 a------- c:\windows\system32\perfc015.dat
2009-12-23 08:56 60,808 a------- c:\windows\system32\S32EVNT1.DLL
2009-12-21 20:08 916,480 a------- c:\windows\system32\wininet.dll
2009-12-17 08:42 345,088 a------- c:\windows\system32\mspaint.exe
2009-12-14 08:10 33,280 a------- c:\windows\system32\csrsrv.dll
2009-12-09 11:11 2,146,816 a------- c:\windows\system32\ntoskrnl.exe
2009-12-09 11:11 2,025,472 a------- c:\windows\system32\ntkrnlpa.exe
2009-11-10 18:41 32,768 a--sh--- c:\windows\system32\config\systemprofile\ustawienia lokalne\historia\history.ie5\mshist012009110220091109\index.dat
2009-11-10 18:41 32,768 a--sh--- c:\windows\system32\config\systemprofile\ustawienia lokalne\historia\history.ie5\mshist012009111020091111\index.dat
============= FINISH: 20:28:51,75 ===============
|