1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154. |
DDS (Ver_09-09-29.01) - NTFSx86
Run by Przemysaw at 20:28:26,35 on 2010-03-05
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.2038.1346 [GMT 1:00]
AV: Norton AntiVirus *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FW: Outpost Firewall Pro *enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
============== Running Processes ===============
C:\\WINDOWS\\system32\\svchost -k DcomLaunch
svchost.exe
C:\\WINDOWS\\System32\\svchost.exe -k netsvcs
C:\\Program Files\\Intel\\Wireless\\Bin\\EvtEng.exe
C:\\Program Files\\Intel\\Wireless\\Bin\\S24EvMon.exe
C:\\WINDOWS\\Explorer.EXE
C:\\Program Files\\Intel\\Wireless\\Bin\\WLKeeper.exe
svchost.exe
svchost.exe
C:\\Program Files\\Common Files\\Symantec Shared\\ccSvcHst.exe
C:\\WINDOWS\\system32\\spoolsv.exe
svchost.exe
C:\\Program Files\\Symantec\\LiveUpdate\\AluSchedulerSvc.exe
svchost.exe
C:\\Program Files\\Java\\jre6\\bin\\jqs.exe
C:\\Program Files\\Common Files\\Microsoft Shared\\VS7Debug\\mdm.exe
C:\\Program Files\\Intel\\Wireless\\Bin\\RegSrvc.exe
C:\\WINDOWS\\system32\\svchost.exe -k imgsvc
C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtSrv.exe
C:\\WINDOWS\\system32\\wbem\\wmiapsrv.exe
C:\\WINDOWS\\system32\\rundll32.exe
C:\\Program Files\\Intel\\Wireless\\bin\\ZCfgSvc.exe
C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe
C:\\Program Files\\Common Files\\Symantec Shared\\ccSvcHst.exe
C:\\WINDOWS\\system32\\ctfmon.exe
C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtMng.exe
C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosA2dp.exe
C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtHid.exe
C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtHsp.exe
C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosAVRC.exe
C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\tosOBEX.exe
C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\tosBtProc.exe
C:\\PROGRA~1\\COMMON~1\\SYMANT~1\\CCPD-LC\\symlcsvc.exe
C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe
C:\\Documents and Settings\\Przemysław\\Pulpit\\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.pl/
uInternet Connection Wizard,ShellNext = iexplore
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\\program files\\adobe\\acrobat 7.0\\activex\\AcroIEHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\\progra~1\\common~1\\symant~1\\ids\\IPSBHO.dll
BHO: Expressivo: {85f685c3-20d9-4943-95e4-eb4224056c3f} - c:\\program files\\ivo\\expressivo\\integr\\ih-iexplorer\\IH_iexplorer.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\\program files\\ask.com\\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\\program files\\java\\jre6\\bin\\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\\program files\\java\\jre6\\lib\\deploy\\jqs\\ie\\jqs_plugin.dll
TB: Expressivo: {85f685c3-20d9-4943-95e4-eb4224056c3f} - c:\\program files\\ivo\\expressivo\\integr\\ih-iexplorer\\IH_iexplorer.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\\program files\\ask.com\\GenericAskToolbar.dll
uRun: [CTFMON.EXE] c:\\windows\\system32\\ctfmon.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [IntelZeroConfig] \"c:\\program files\\intel\\wireless\\bin\\ZCfgSvc.exe\"
mRun: [IntelWireless] \"c:\\program files\\intel\\wireless\\bin\\ifrmewrk.exe\" /tf Intel PROSet/Wireless
mRun: [OutpostMonitor] c:\\progra~1\\agnitum\\outpos~1\\op_mon.exe /tray /noservice
mRun: [OutpostFeedBack] \"c:\\program files\\agnitum\\outpost firewall pro\\feedback.exe\" /dump:os_startup
mRun: [ccApp] \"c:\\program files\\common files\\symantec shared\\ccApp.exe\"
mRun: [osCheck] \"c:\\program files\\norton antivirus\\osCheck.exe\"
dRun: [CTFMON.EXE] c:\\windows\\system32\\CTFMON.EXE
StartupFolder: c:\\docume~1\\alluse~1\\menust~1\\programy\\autost~1\\blueto~1.lnk - c:\\program files\\toshiba\\bluetooth toshiba stack\\TosBtMng.exe
StartupFolder: c:\\docume~1\\alluse~1\\menust~1\\programy\\autost~1\\autoru~1\\adober~1.lnk - c:\\program files\\adobe\\acrobat 7.0\\reader\\reader_sl.exe
StartupFolder: c:\\docume~1\\alluse~1\\menust~1\\programy\\autost~1\\autoru~1\\micros~1.lnk - c:\\program files\\microsoft office\\office10\\OSA.EXE
IE: Download by GAS - c:\\progra~1\\getasf~1\\ie_MenuExt.htm
IE: E&ksport do programu Microsoft Excel - c:\\progra~1\\micros~2\\office10\\EXCEL.EXE/3000
IE: Funkcja Google Sidewiki - c:\\program files\\google\\google toolbar\\component\\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\\Network Diagnostic\\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\\program files\\messenger\\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC} - c:\\program files\\java\\jre6\\bin\\jp2iexp.dll
IE: {44627E97-789B-40d4-B5C2-58BD171129A1} - {A1A7E22D-1587-4230-8F16-081C68D21448} - c:\\program files\\agnitum\\outpost firewall pro\\ie_bar.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {132DDA35-4981-4D21-9598-9523BFEC295A} = 194.204.152.34 194.204.159.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\\progra~1\\common~1\\skype\\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\\progra~1\\agnitum\\outpos~1\\wl_hook.dll
============= SERVICES / DRIVERS ===============
R1 SandBox;SandBox;c:\\windows\\system32\\drivers\\SandBox.sys [2009-11-2 673920]
R2 acssrv;Agnitum Client Security Service;c:\\progra~1\\agnitum\\outpos~1\\acs.exe [2009-11-2 1238344]
R2 ccEvtMgr;Symantec Event Manager;c:\\program files\\common files\\symantec shared\\CCSVCHST.EXE [2008-1-25 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\\program files\\common files\\symantec shared\\CCSVCHST.EXE [2008-1-25 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\\program files\\common files\\symantec shared\\CCSVCHST.EXE [2008-1-25 149352]
R3 afw;Agnitum firewall driver;c:\\windows\\system32\\drivers\\afw.sys [2009-11-2 30864]
R3 afwcore;afwcore;c:\\windows\\system32\\drivers\\afwcore.sys [2009-11-2 234640]
R3 ASWFilt;ASWFilt;c:\\windows\\system32\\filt\\ASWFilt.dll [2009-11-2 33408]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\\program files\\common files\\symantec shared\\eengine\\EraserUtilRebootDrv.sys [2010-2-16 102448]
R3 NAVENG;NAVENG;c:\\progra~1\\common~1\\symant~1\\virusd~1\\20100305.004\\NAVENG.SYS [2010-3-5 84912]
R3 NAVEX15;NAVEX15;c:\\progra~1\\common~1\\symant~1\\virusd~1\\20100305.004\\NAVEX15.SYS [2010-3-5 1324720]
R3 Symantec Core LC;Symantec Core LC;c:\\progra~1\\common~1\\symant~1\\ccpd-lc\\symlcsvc.exe [2009-12-23 1245064]
S2 gupdate;Usługa Google Update (gupdate);\"c:\\program files\\google\\update\\googleupdate.exe\" /svc --> c:\\program files\\google\\update\\GoogleUpdate.exe [?]
S3 COH_Mon;COH_Mon;c:\\windows\\system32\\drivers\\COH_Mon.sys [2008-1-12 23888]
S3 DrvAgent32;DrvAgent32;c:\\windows\\system32\\drivers\\DrvAgent32.sys [2010-3-4 0]
S3 NPF;NetGroup Packet Filter Driver;c:\\windows\\system32\\drivers\\npf.sys [2007-11-6 34064]
S3 npggsvc;nProtect GameGuard Service;c:\\windows\\system32\\gamemon.des -service --> c:\\windows\\system32\\GameMon.des -service [?]
=============== Created Last 30 ================
2010-03-05 18:13 <DIR> --d-hr-- c:\\documents and settings\\przemysław\\Recent
2010-03-05 14:15 <DIR> --d----- c:\\docume~1\\alluse~1\\daneap~1\\KONAMI
2010-03-05 14:06 <DIR> --d----- c:\\program files\\KONAMI
2010-03-05 13:07 <DIR> --d----- c:\\program files\\FastStone Capture
2010-03-05 12:55 <DIR> --d----- c:\\docume~1\\przemy~1\\daneap~1\\FastStone
2010-03-05 12:51 293,376 -------- c:\\windows\\system32\\browserchoice.exe
2010-03-04 20:37 0 a------- c:\\windows\\system32\\drivers\\DrvAgent32.sys
2010-02-28 19:08 3,686,454 a------- c:\\windows\\gry.bmp
2010-02-27 13:59 <DIR> --d----- c:\\docume~1\\przemy~1\\daneap~1\\TVU Networks
2010-02-27 11:17 139,264 a------- c:\\windows\\system32\\eax.dll
2010-02-26 20:34 <DIR> --d----- c:\\docume~1\\przemy~1\\daneap~1\\Styler
2010-02-26 20:33 <DIR> --d----- c:\\program files\\Styler
2010-02-20 15:51 <DIR> --d----- c:\\program files\\Free Pascal
2010-02-18 16:15 <DIR> --d----- c:\\docume~1\\przemy~1\\daneap~1\\AnvSoft
2010-02-18 16:15 <DIR> --d----- c:\\program files\\AnvSoft
2010-02-16 16:54 <DIR> --d----- c:\\program files\\Team17
2010-02-15 17:26 83 a------- c:\\windows\\WWP.INI
2010-02-13 14:32 1,409 a------- c:\\windows\\system32\\tmpE9C2E.FOT
2010-02-13 14:32 1,409 a------- c:\\windows\\system32\\tmp71B2E.FOT
2010-02-13 14:32 1,409 a------- c:\\windows\\system32\\tmp56B2E.FOT
2010-02-13 14:32 1,409 a------- c:\\windows\\system32\\tmp3BB2E.FOT
2010-02-13 14:32 1,409 a------- c:\\windows\\system32\\tmp2FB2E.FOT
2010-02-13 14:32 1,409 a------- c:\\windows\\system32\\tmp05C2E.FOT
2010-02-13 14:32 1,409 a------- c:\\windows\\system32\\tmpB7A2E.FOT
2010-02-13 14:32 1,409 a------- c:\\windows\\system32\\tmp9CA2E.FOT
2010-02-11 10:21 <DIR> --d----- c:\\program files\\CAPCOM
2010-02-07 13:57 107,888 a------- c:\\windows\\system32\\CmdLineExt.dll
==================== Find3M ====================
2010-03-05 19:05 6,029,312 a---h--- c:\\documents and settings\\przemysław\\NTUSER.DAT
2010-01-04 13:06 490,866 a------- c:\\windows\\system32\\perfh015.dat
2010-01-04 13:06 84,078 a------- c:\\windows\\system32\\perfc015.dat
2009-12-23 08:56 60,808 a------- c:\\windows\\system32\\S32EVNT1.DLL
2009-12-21 20:08 916,480 a------- c:\\windows\\system32\\wininet.dll
2009-12-17 08:42 345,088 a------- c:\\windows\\system32\\mspaint.exe
2009-12-14 08:10 33,280 a------- c:\\windows\\system32\\csrsrv.dll
2009-12-09 11:11 2,146,816 a------- c:\\windows\\system32\\ntoskrnl.exe
2009-12-09 11:11 2,025,472 a------- c:\\windows\\system32\\ntkrnlpa.exe
2009-11-10 18:41 32,768 a--sh--- c:\\windows\\system32\\config\\systemprofile\\ustawienia lokalne\\historia\\history.ie5\\mshist012009110220091109\\index.dat
2009-11-10 18:41 32,768 a--sh--- c:\\windows\\system32\\config\\systemprofile\\ustawienia lokalne\\historia\\history.ie5\\mshist012009111020091111\\index.dat
============= FINISH: 20:28:51,75 ===============
|