bazyl
2008-06-06, 00:13
I did some S&D scans and everytime I had Virtumonde detected.
Also the computer is working slower than usually.
I think I did everything as properly with HJT and KAV
KASPERSKY ONLINE SCANNER REPORT
Thursday, June 05, 2008 2:19:08 PM
Operating System: Microsoft Windows XP Professional, Dodatek Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/06/2008
Kaspersky Anti-Virus database records: 830628
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
I:\
J:\
Scan Statistics
Total number of scanned objects 198021
Number of viruses found 18
Number of infected objects 50
Number of suspicious objects 0
Duration of the scan process 05:17:56
Infected Object Name Virus Name Last Action
C:\Documents and Settings\bazyl\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\cert8.db Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\flashgot.log Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\history.dat Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\key3.db Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\search.sqlite Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\abook.mab Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\cert8.db Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\key3.db Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\Local Folders\Inbox.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\Local Folders\Sent.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\Local Folders\Trash.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\mail.polanet.pl\Trash.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\poczta.o2.pl\Trash.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\pop3.wp.pl\Inbox.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\pop3.wp.pl\Trash.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\student.polsl.pl\Inbox.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\student.polsl.pl\Trash.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\panacea.dat Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\parent.lock Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\bazyl\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\bazyl\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbdam Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbdao Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbeam Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbeao Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbm Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\fii.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\fiih.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\hp Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\rpm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Historia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\bibifqtj.dll Infected: Trojan.Win32.Monder.mj skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\bjmwvqdf.dll Infected: Trojan.Win32.Monder.lh skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\dyoolicd.dll Infected: Trojan.Win32.Monder.mj skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\fla2F9.tmp Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\gujvmvfu.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsw skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\ifjhmefy.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsg skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\is202054.exe Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\kiyeplud.dll Infected: Trojan.Win32.Monder.mg skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\lnfbwlog.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vpc skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\mcyiawir.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsf skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\moz_mapi\tleninst55031.exe/data0020 Infected: not-a-virus:AdWare.Win32.Doza.a skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\moz_mapi\tleninst55031.exe NSIS: infected - 1 skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\moz_mapi\tleninst55031.exe UPX: infected - 1 skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\mtbntnxp.dll Infected: Trojan.Win32.Monder.mg skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\npyjwpyj.dll Infected: Trojan.Win32.Monder.kd skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\omfaakvd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vln skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\pfsdkcce.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\qqpwdvci.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\tcmlldli.dll Infected: Trojan.Win32.Monder.li skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\urpggifm.dll Infected: Trojan.Win32.Monder.kh skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\uvbperly.dll Infected: Trojan.Win32.Monder.lb skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\vjjhjmub.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\vtokbecj.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\~DF6144.tmp Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\~DF73C2.tmp Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\8XGXEVGP\kriv[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\AB2JEHAZ\iddqd[1] Infected: Trojan.Win32.Monder.jy skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\I90REXU5\CAKPQ56T Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\I90REXU5\hctp[1] Infected: Trojan.Win32.Monder.il skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\I90REXU5\idkfa[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WT4VGBOR\CAPSM9DR Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WT4VGBOR\CATK655Z Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WT4VGBOR\CAZQIHBB Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WT4VGBOR\installer_pl[1].cab/UGDCPL_0001_N122M2012NetInstaller.exe Infected: not-a-virus:Downloader.Win32.SanitarDiska.a skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WT4VGBOR\installer_pl[1].cab CAB: infected - 1 skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WXAFK5MV\CAOLMFGP Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Ustawienia lokalne\Historia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\play\Ustawienia lokalne\Temporary Internet Files\Content.IE5\4H23ST2N\kb456456[1] Infected: Trojan.Win32.Monder.mg skipped
C:\Documents and Settings\play\Ustawienia lokalne\Temporary Internet Files\Content.IE5\OP6R49U7\kb516107[1] Infected: Trojan.Win32.Monder.mj skipped
C:\Documents and Settings\play\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WDYZGDEV\CA8Y2GWD Infected: not-a-virus:AdWare.Win32.Virtumonde.wtj skipped
C:\Program Files\ESET\cache\CACHE.NDB Object is locked skipped
C:\Program Files\ESET\logs\virlog.dat Object is locked skipped
C:\Program Files\ESET\logs\warnlog.dat Object is locked skipped
C:\RECYCLER\S-1-5-21-1606980848-1326574676-839522115-1003\Dc5.zip/Scarlett Johansson - Anywhere I Lay My Head (2008).exe/data0002 Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-1606980848-1326574676-839522115-1003\Dc5.zip/Scarlett Johansson - Anywhere I Lay My Head (2008).exe Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-1606980848-1326574676-839522115-1003\Dc5.zip ZIP: infected - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\qoMEXNEW.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\rqRLdEvt.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\#MARCIN\Tlen_backup_2007.09.07\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2007.10.10\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2007.10.20\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2007.12.10\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2007.12.27\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2008.02.07\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2008.03.03\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2008.03.27\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\Studia\Dyplom\Timer_ATtiny\PCB.vsd Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
J:\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:59:26, on 2008-06-05
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Notebook Hardware Control\nhc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sync Now\SyncNow.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\FOXITS~1\FOXITR~1\FOXITR~1.EXE
C:\Program Files\Microsoft Office\Visio11\VISIO.EXE
C:\Program Files\Atmel\AVR Tools\avrstudio4\AvrStudio.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\FOXITS~1\FOXITR~1\FOXITR~1.EXE
C:\PROGRA~1\FOXITS~1\FOXITR~1\FOXITR~1.EXE
C:\Documents and Settings\bazyl\Dane aplikacji\U3\0921D961130188E7\LaunchPad.exe
C:\WINDOWS\system32\taskmgr.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [BM976602d5] Rundll32.exe "C:\WINDOWS\system32\jsvpysih.dll",s
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA5054] command /c del "C:\WINDOWS\system32\wvUnLBQH.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6392] cmd /c del "C:\WINDOWS\system32\wvUnLBQH.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2490] command /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC727] cmd /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6954] command /c del "C:\WINDOWS\system32\pmnmkkKE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8512] cmd /c del "C:\WINDOWS\system32\pmnmkkKE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6521] command /c del "C:\WINDOWS\system32\ugcjpueg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3402] cmd /c del "C:\WINDOWS\system32\ugcjpueg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6848] command /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC790] cmd /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKCU\..\Run: [Komunikator] J:\Tlen.pl\tlen.exe
O4 - HKCU\..\Run: [Sync Now!] C:\Program Files\Sync Now\SyncNow.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB3925] command /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4164] cmd /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2941] command /c del "C:\WINDOWS\system32\pmnmkkKE.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2796] cmd /c del "C:\WINDOWS\system32\pmnmkkKE.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1429] command /c del "C:\WINDOWS\system32\ugcjpueg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2947] cmd /c del "C:\WINDOWS\system32\ugcjpueg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7853] command /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7724] cmd /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] cmd.exe /c md "%SystemRoot%\System32\dllcache" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Subskrybuj w Cafe News - C:\Program Files\CafeNews\addFeed.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files\PlotSoft\PDFill\DownloadPDF.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Menedżer Google Desktop 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
--
End of file - 9642 bytes
Thanks for any help.
Martin
Also the computer is working slower than usually.
I think I did everything as properly with HJT and KAV
KASPERSKY ONLINE SCANNER REPORT
Thursday, June 05, 2008 2:19:08 PM
Operating System: Microsoft Windows XP Professional, Dodatek Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/06/2008
Kaspersky Anti-Virus database records: 830628
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
I:\
J:\
Scan Statistics
Total number of scanned objects 198021
Number of viruses found 18
Number of infected objects 50
Number of suspicious objects 0
Duration of the scan process 05:17:56
Infected Object Name Virus Name Last Action
C:\Documents and Settings\bazyl\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\cert8.db Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\flashgot.log Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\history.dat Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\key3.db Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\search.sqlite Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\abook.mab Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\cert8.db Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\key3.db Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\Local Folders\Inbox.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\Local Folders\Sent.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\Local Folders\Trash.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\mail.polanet.pl\Trash.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\poczta.o2.pl\Trash.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\pop3.wp.pl\Inbox.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\pop3.wp.pl\Trash.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\student.polsl.pl\Inbox.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\Mail\student.polsl.pl\Trash.msf Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\panacea.dat Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\parent.lock Object is locked skipped
C:\Documents and Settings\bazyl\Dane aplikacji\Thunderbird\Profiles\aia62fqm.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\bazyl\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\bazyl\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbdam Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbdao Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbeam Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbeao Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbm Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\fii.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\fiih.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\hp Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\rpm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Google\Google Desktop\f46f61cc5b06\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\jmv06ics.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Historia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\bibifqtj.dll Infected: Trojan.Win32.Monder.mj skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\bjmwvqdf.dll Infected: Trojan.Win32.Monder.lh skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\dyoolicd.dll Infected: Trojan.Win32.Monder.mj skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\fla2F9.tmp Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\gujvmvfu.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsw skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\ifjhmefy.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsg skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\is202054.exe Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\kiyeplud.dll Infected: Trojan.Win32.Monder.mg skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\lnfbwlog.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vpc skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\mcyiawir.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsf skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\moz_mapi\tleninst55031.exe/data0020 Infected: not-a-virus:AdWare.Win32.Doza.a skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\moz_mapi\tleninst55031.exe NSIS: infected - 1 skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\moz_mapi\tleninst55031.exe UPX: infected - 1 skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\mtbntnxp.dll Infected: Trojan.Win32.Monder.mg skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\npyjwpyj.dll Infected: Trojan.Win32.Monder.kd skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\omfaakvd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vln skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\pfsdkcce.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\qqpwdvci.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\tcmlldli.dll Infected: Trojan.Win32.Monder.li skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\urpggifm.dll Infected: Trojan.Win32.Monder.kh skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\uvbperly.dll Infected: Trojan.Win32.Monder.lb skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\vjjhjmub.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\vtokbecj.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\~DF6144.tmp Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temp\~DF73C2.tmp Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\8XGXEVGP\kriv[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\AB2JEHAZ\iddqd[1] Infected: Trojan.Win32.Monder.jy skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\I90REXU5\CAKPQ56T Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\I90REXU5\hctp[1] Infected: Trojan.Win32.Monder.il skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\I90REXU5\idkfa[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WT4VGBOR\CAPSM9DR Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WT4VGBOR\CATK655Z Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WT4VGBOR\CAZQIHBB Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WT4VGBOR\installer_pl[1].cab/UGDCPL_0001_N122M2012NetInstaller.exe Infected: not-a-virus:Downloader.Win32.SanitarDiska.a skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WT4VGBOR\installer_pl[1].cab CAB: infected - 1 skipped
C:\Documents and Settings\bazyl\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WXAFK5MV\CAOLMFGP Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Ustawienia lokalne\Historia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\play\Ustawienia lokalne\Temporary Internet Files\Content.IE5\4H23ST2N\kb456456[1] Infected: Trojan.Win32.Monder.mg skipped
C:\Documents and Settings\play\Ustawienia lokalne\Temporary Internet Files\Content.IE5\OP6R49U7\kb516107[1] Infected: Trojan.Win32.Monder.mj skipped
C:\Documents and Settings\play\Ustawienia lokalne\Temporary Internet Files\Content.IE5\WDYZGDEV\CA8Y2GWD Infected: not-a-virus:AdWare.Win32.Virtumonde.wtj skipped
C:\Program Files\ESET\cache\CACHE.NDB Object is locked skipped
C:\Program Files\ESET\logs\virlog.dat Object is locked skipped
C:\Program Files\ESET\logs\warnlog.dat Object is locked skipped
C:\RECYCLER\S-1-5-21-1606980848-1326574676-839522115-1003\Dc5.zip/Scarlett Johansson - Anywhere I Lay My Head (2008).exe/data0002 Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-1606980848-1326574676-839522115-1003\Dc5.zip/Scarlett Johansson - Anywhere I Lay My Head (2008).exe Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-1606980848-1326574676-839522115-1003\Dc5.zip ZIP: infected - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\qoMEXNEW.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\rqRLdEvt.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\#MARCIN\Tlen_backup_2007.09.07\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2007.10.10\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2007.10.20\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2007.12.10\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2007.12.27\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2008.02.07\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2008.03.03\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\#MARCIN\Tlen_backup_2008.03.27\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
D:\Studia\Dyplom\Timer_ATtiny\PCB.vsd Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
J:\Tlen.pl\plugins\DozaKultury.tpl Infected: not-a-virus:AdWare.Win32.Doza.a skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:59:26, on 2008-06-05
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Notebook Hardware Control\nhc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sync Now\SyncNow.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\FOXITS~1\FOXITR~1\FOXITR~1.EXE
C:\Program Files\Microsoft Office\Visio11\VISIO.EXE
C:\Program Files\Atmel\AVR Tools\avrstudio4\AvrStudio.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\FOXITS~1\FOXITR~1\FOXITR~1.EXE
C:\PROGRA~1\FOXITS~1\FOXITR~1\FOXITR~1.EXE
C:\Documents and Settings\bazyl\Dane aplikacji\U3\0921D961130188E7\LaunchPad.exe
C:\WINDOWS\system32\taskmgr.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [BM976602d5] Rundll32.exe "C:\WINDOWS\system32\jsvpysih.dll",s
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA5054] command /c del "C:\WINDOWS\system32\wvUnLBQH.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6392] cmd /c del "C:\WINDOWS\system32\wvUnLBQH.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2490] command /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC727] cmd /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6954] command /c del "C:\WINDOWS\system32\pmnmkkKE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8512] cmd /c del "C:\WINDOWS\system32\pmnmkkKE.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6521] command /c del "C:\WINDOWS\system32\ugcjpueg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3402] cmd /c del "C:\WINDOWS\system32\ugcjpueg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6848] command /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC790] cmd /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKCU\..\Run: [Komunikator] J:\Tlen.pl\tlen.exe
O4 - HKCU\..\Run: [Sync Now!] C:\Program Files\Sync Now\SyncNow.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB3925] command /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4164] cmd /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2941] command /c del "C:\WINDOWS\system32\pmnmkkKE.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2796] cmd /c del "C:\WINDOWS\system32\pmnmkkKE.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1429] command /c del "C:\WINDOWS\system32\ugcjpueg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2947] cmd /c del "C:\WINDOWS\system32\ugcjpueg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7853] command /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7724] cmd /c del "C:\WINDOWS\system32\jsvpysih.dll_old"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] cmd.exe /c md "%SystemRoot%\System32\dllcache" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Subskrybuj w Cafe News - C:\Program Files\CafeNews\addFeed.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files\PlotSoft\PDFill\DownloadPDF.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Menedżer Google Desktop 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
--
End of file - 9642 bytes
Thanks for any help.
Martin