Hello,
I spent a lot of time by trying to delete rootkit c:\windows\system32\drivers\knkvya.sys
This message is shown: "cannot delete knkvya: cannot read from the source file or disk".
I tried this programs:
KillBox
command prompt
Malwarebytes Anti-Malware
ComboFix
but the knkvya.sys is still there. Here is my ComboFix log (thanks for your advice!):
ComboFix 11-02-21.02 - Jopek . 02. 2011 11:49:30.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3068.1771 [GMT 1:00]
Running from: c:\users\Jopek\Desktop\commy.exe
AV: Norton Internet Security *Disabled/Outdated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Norton Internet Security *Disabled/Outdated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Recycle
.
((((((((((((((((((((((((( Files Created from 2011-01-22 to 2011-02-22 )))))))))))))))))))))))))))))))
.
2011-02-22 11:03 . 2011-02-22 11:09 -------- d-----w- c:\users\Jopek\AppData\Local\temp
2011-02-22 11:03 . 2011-02-22 11:03 -------- d-----w- c:\users\Guest\AppData\Local\temp
2011-02-22 11:03 . 2011-02-22 11:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-22 10:02 . 2011-02-22 10:02 -------- d-----w- c:\users\Jopek\AppData\Roaming\Malwarebytes
2011-02-22 10:01 . 2011-02-22 10:01 -------- d-----w- c:\programdata\Malwarebytes
2011-02-22 10:01 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-22 10:01 . 2011-02-22 10:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-22 10:01 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-22 09:21 . 2011-02-22 09:27 -------- d-----w- c:\programdata\SecTaskMan
2011-02-22 09:21 . 2011-02-22 09:21 -------- d-----w- c:\program files\Security Task Manager
2011-02-21 20:58 . 2011-02-21 20:58 -------- d-----w- c:\users\Jopek\AppData\Roaming\Uniblue
2011-02-21 15:14 . 2011-02-21 15:14 -------- d-----w- c:\users\Jopek\AppData\Local\PackageAware
2011-02-20 21:53 . 2011-02-20 22:01 -------- d-sh--r- c:\users\Jopek\Microsoft-Driver-1-52-2475-9627-8645
2011-02-20 21:36 . 2011-02-20 22:01 -------- d-sh--r- c:\users\Jopek\Microsoft-Update-Service-8-8586-7578-5800
2011-02-20 18:03 . 2011-01-08 08:47 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-02-20 18:03 . 2011-01-08 06:28 292352 ----a-w- c:\windows\system32\atmfd.dll
2011-02-19 17:32 . 2011-01-13 09:41 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5F6AA587-68ED-4A42-A3B3-B01BE09C9382}\mpengine.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-21 10:36 . 2010-05-03 17:03 2018272 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2011-02-20 19:41 . 2010-11-11 11:27 76696 ----a-w- c:\windows\system32\drivers\pxrts.sys
2011-02-20 19:41 . 2010-11-11 11:27 71880 ----a-w- c:\windows\system32\PxSecure.dll
2011-02-20 19:41 . 2010-11-11 11:27 32008 ----a-w- c:\windows\system32\drivers\pxscan.sys
2011-02-20 19:41 . 2010-11-11 11:27 26096 ----a-w- c:\windows\system32\drivers\pxkbf.sys
2010-12-28 15:55 . 2011-01-13 10:03 413696 ----a-w- c:\windows\system32\odbc32.dll
2010-12-14 14:49 . 2011-01-13 10:02 1169408 ----a-w- c:\windows\system32\sdclt.exe
2010-12-04 11:37 . 2010-10-07 17:55 109080 ----a-w- c:\windows\system32\OpenAL32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-07-12 226904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-24 1348904]
"TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-09-25 1152296]
"CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-09-25 189736]
"UCam_Menu"="c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-07-14 814144]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-19 13593120]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-19 92704]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-19 727592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0afvaa6.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0afvaa6.exe
backup=c:\windows\pss\0afvaa6.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0aqaaqq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0aqaaqq.exe
backup=c:\windows\pss\0aqaaqq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0bq6qgg.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0bq6qgg.exe
backup=c:\windows\pss\0bq6qgg.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0ej1otj.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0ej1otj.exe
backup=c:\windows\pss\0ej1otj.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0f8al1q.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0f8al1q.exe
backup=c:\windows\pss\0f8al1q.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0iscccx.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0iscccx.exe
backup=c:\windows\pss\0iscccx.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0llbbgb.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0llbbgb.exe
backup=c:\windows\pss\0llbbgb.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0llq21l.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0llq21l.exe
backup=c:\windows\pss\0llq21l.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0mrhm7m.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0mrhm7m.exe
backup=c:\windows\pss\0mrhm7m.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0mscmm1.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0mscmm1.exe
backup=c:\windows\pss\0mscmm1.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0q6g7gb.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0q6g7gb.exe
backup=c:\windows\pss\0q6g7gb.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0qfqqfq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0qfqqfq.exe
backup=c:\windows\pss\0qfqqfq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0qvqfq1.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0qvqfq1.exe
backup=c:\windows\pss\0qvqfq1.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0rrhhmc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0rrhhmc.exe
backup=c:\windows\pss\0rrhhmc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0t9z31t.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0t9z31t.exe
backup=c:\windows\pss\0t9z31t.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1aqaaqq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1aqaaqq.exe
backup=c:\windows\pss\1aqaaqq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1bbgvbv.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1bbgvbv.exe
backup=c:\windows\pss\1bbgvbv.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1eyyeoj.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1eyyeoj.exe
backup=c:\windows\pss\1eyyeoj.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1fl71fa.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1fl71fa.exe
backup=c:\windows\pss\1fl71fa.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1iinci6.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1iinci6.exe
backup=c:\windows\pss\1iinci6.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1m9m1cm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1m9m1cm.exe
backup=c:\windows\pss\1m9m1cm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1mcchcr.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1mcchcr.exe
backup=c:\windows\pss\1mcchcr.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1qav0lf.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1qav0lf.exe
backup=c:\windows\pss\1qav0lf.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1uppu7e.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1uppu7e.exe
backup=c:\windows\pss\1uppu7e.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1vqvg4q.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1vqvg4q.exe
backup=c:\windows\pss\1vqvg4q.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1vvaqvq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1vvaqvq.exe
backup=c:\windows\pss\1vvaqvq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1wmrmrr.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1wmrmrr.exe
backup=c:\windows\pss\1wmrmrr.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1wrrhhm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1wrrhhm.exe
backup=c:\windows\pss\1wrrhhm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1xiisnn.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1xiisnn.exe
backup=c:\windows\pss\1xiisnn.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1xrrmhc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1xrrmhc.exe
backup=c:\windows\pss\1xrrmhc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1zkkz7p.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1zkkz7p.exe
backup=c:\windows\pss\1zkkz7p.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^2bww2b5.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2bww2b5.exe
backup=c:\windows\pss\2bww2b5.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^2c981rc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2c981rc.exe
backup=c:\windows\pss\2c981rc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^2ididss.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2ididss.exe
backup=c:\windows\pss\2ididss.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^2llgvgq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2llgvgq.exe
backup=c:\windows\pss\2llgvgq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^3lflfll.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3lflfll.exe
backup=c:\windows\pss\3lflfll.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^42bbr7h.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\42bbr7h.exe
backup=c:\windows\pss\42bbr7h.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^4iid5id.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\4iid5id.exe
backup=c:\windows\pss\4iid5id.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^4vffaf6.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\4vffaf6.exe
backup=c:\windows\pss\4vffaf6.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^5aav1la.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5aav1la.exe
backup=c:\windows\pss\5aav1la.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^5aqqk40.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5aqqk40.exe
backup=c:\windows\pss\5aqqk40.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^5hrchcc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5hrchcc.exe
backup=c:\windows\pss\5hrchcc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^5hrxh72.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5hrxh72.exe
backup=c:\windows\pss\5hrxh72.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^5indsni.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5indsni.exe
backup=c:\windows\pss\5indsni.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^6a7avq0.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\6a7avq0.exe
backup=c:\windows\pss\6a7avq0.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^6wwrwhc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\6wwrwhc.exe
backup=c:\windows\pss\6wwrwhc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^96uka6f.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\96uka6f.exe
backup=c:\windows\pss\96uka6f.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^dssxss3xnn.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dssxss3xnn.exe
backup=c:\windows\pss\dssxss3xnn.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^i9i1xiix7.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\i9i1xiix7.exe
backup=c:\windows\pss\i9i1xiix7.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^idxxssiid.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\idxxssiid.exe
backup=c:\windows\pss\idxxssiid.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^jttotott.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jttotott.exe
backup=c:\windows\pss\jttotott.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^lww1b0br6rw.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lww1b0br6rw.exe
backup=c:\windows\pss\lww1b0br6rw.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^mhhcrc0r.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mhhcrc0r.exe
backup=c:\windows\pss\mhhcrc0r.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^mhmhm76cxcx.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mhmhm76cxcx.exe
backup=c:\windows\pss\mhmhm76cxcx.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^r4rc1mhhm7m.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\r4rc1mhhm7m.exe
backup=c:\windows\pss\r4rc1mhhm7m.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^rmccr7hx.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rmccr7hx.exe
backup=c:\windows\pss\rmccr7hx.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^rrx71rm0r.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rrx71rm0r.exe
backup=c:\windows\pss\rrx71rm0r.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^rxhcrrmm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rxhcrrmm.exe
backup=c:\windows\pss\rxhcrrmm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vqvf4a0qf.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vqvf4a0qf.exe
backup=c:\windows\pss\vqvf4a0qf.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vqvqffaq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vqvqffaq.exe
backup=c:\windows\pss\vqvqffaq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vvalfvlfa.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vvalfvlfa.exe
backup=c:\windows\pss\vvalfvlfa.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vvalfvlv.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vvalfvlv.exe
backup=c:\windows\pss\vvalfvlv.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vvqffvava76.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vvqffvava76.exe
backup=c:\windows\pss\vvqffvava76.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vvqqqvqfvff.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vvqqqvqfvff.exe
backup=c:\windows\pss\vvqqqvqfvff.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vvqvfaa9.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vvqvfaa9.exe
backup=c:\windows\pss\vvqvfaa9.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^w032bwlw0w.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\w032bwlw0w.exe
backup=c:\windows\pss\w032bwlw0w.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^w2gb0qglq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\w2gb0qglq.exe
backup=c:\windows\pss\w2gb0qglq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^w2rrw7hhb.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\w2rrw7hhb.exe
backup=c:\windows\pss\w2rrw7hhb.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wb93lblgbb.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wb93lblgbb.exe
backup=c:\windows\pss\wb93lblgbb.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wcrwrwhccww.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wcrwrwhccww.exe
backup=c:\windows\pss\wcrwrwhccww.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wgbwww6w.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wgbwww6w.exe
backup=c:\windows\pss\wgbwww6w.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^whrr2m9m.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\whrr2m9m.exe
backup=c:\windows\pss\whrr2m9m.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wm037wrr.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wm037wrr.exe
backup=c:\windows\pss\wm037wrr.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wm081rcc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wm081rcc.exe
backup=c:\windows\pss\wm081rcc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wqqlql6g.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wqqlql6g.exe
backup=c:\windows\pss\wqqlql6g.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wr0hchrm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wr0hchrm.exe
backup=c:\windows\pss\wr0hchrm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wr5mccw40w.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wr5mccw40w.exe
backup=c:\windows\pss\wr5mccw40w.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wrrhm9m1.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wrrhm9m1.exe
backup=c:\windows\pss\wrrhm9m1.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wwhcrr2m9m1.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wwhcrr2m9m1.exe
backup=c:\windows\pss\wwhcrr2m9m1.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wwmb9wwrm0.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wwmb9wwrm0.exe
backup=c:\windows\pss\wwmb9wwrm0.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wwrwrhhb.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wwrwrhhb.exe
backup=c:\windows\pss\wwrwrhhb.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^x5mhmxhh2c9.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\x5mhmxhh2c9.exe
backup=c:\windows\pss\x5mhmxhh2c9.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^x6mcs6mmhm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\x6mcs6mmhm.exe
backup=c:\windows\pss\x6mcs6mmhm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xcnnhnn6c.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xcnnhnn6c.exe
backup=c:\windows\pss\xcnnhnn6c.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xh6hc5r5mr.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xh6hc5r5mr.exe
backup=c:\windows\pss\xh6hc5r5mr.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xhrrm5mccx.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xhrrm5mccx.exe
backup=c:\windows\pss\xhrrm5mccx.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xi1xxdsi.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xi1xxdsi.exe
backup=c:\windows\pss\xi1xxdsi.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xissncxsi.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xissncxsi.exe
backup=c:\windows\pss\xissncxsi.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xixx0iic0xn.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xixx0iic0xn.exe
backup=c:\windows\pss\xixx0iic0xn.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xnsns0sis.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xnsns0sis.exe
backup=c:\windows\pss\xnsns0sis.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xrhh1c9c1rc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xrhh1c9c1rc.exe
backup=c:\windows\pss\xrhh1c9c1rc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xrxhcrrm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xrxhcrrm.exe
backup=c:\windows\pss\xrxhcrrm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xshmxhmmch.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xshmxhmmch.exe
backup=c:\windows\pss\xshmxhmmch.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xss9s1issi.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xss9s1issi.exe
backup=c:\windows\pss\xss9s1issi.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xsxsi6ddnii.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xsxsi6ddnii.exe
backup=c:\windows\pss\xsxsi6ddnii.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xx2h0hxcxc7.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xx2h0hxcxc7.exe
backup=c:\windows\pss\xx2h0hxcxc7.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xx6mrmr8mm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xx6mrmr8mm.exe
backup=c:\windows\pss\xx6mrmr8mm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xxc7m6hhcxx.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xxc7m6hhcxx.exe
backup=c:\windows\pss\xxc7m6hhcxx.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xxcrxrxhc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xxcrxrxhc.exe
backup=c:\windows\pss\xxcrxrxhc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xxsiisnniix.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xxsiisnniix.exe
backup=c:\windows\pss\xxsiisnniix.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xxsx7mhc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xxsx7mhc.exe
backup=c:\windows\pss\xxsx7mhc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^y98nniy6ssn.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\y98nniy6ssn.exe
backup=c:\windows\pss\y98nniy6ssn.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^yi5ssn1dsy9.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\yi5ssn1dsy9.exe
backup=c:\windows\pss\yi5ssn1dsy9.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^yid6s7sni0.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\yid6s7sni0.exe
backup=c:\windows\pss\yid6s7sni0.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^yotojjee2.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\yotojjee2.exe
backup=c:\windows\pss\yotojjee2.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ytty7ytyi.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ytty7ytyi.exe
backup=c:\windows\pss\ytty7ytyi.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^z6u7ffzz.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\z6u7ffzz.exe
backup=c:\windows\pss\z6u7ffzz.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^z6zooj1z.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\z6zooj1z.exe
backup=c:\windows\pss\z6zooj1z.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^zeojeejeue1.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zeojeejeue1.exe
backup=c:\windows\pss\zeojeejeue1.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^zjej8eez1pe.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zjej8eez1pe.exe
backup=c:\windows\pss\zjej8eez1pe.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^zoouoeojee.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zoouoeojee.exe
backup=c:\windows\pss\zoouoeojee.exe.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDAgent]
2008-09-26 01:36 1148200 ------w- c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25 125952 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 09:16 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVAgent]
2008-09-24 17:07 206120 ------w- c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
2008-06-13 17:11 210216 ------w- c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
2008-06-13 17:11 210216 ------w- c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut]
2008-06-13 17:11 210216 ------w- c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]
2008-09-26 09:15 210216 ------w- c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\NIS\1002000.007\SYMNDISV.SYS [2008-12-12 40496]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
S0 pxscan;pxscan;c:\windows\System32\drivers\pxscan.sys [2011-02-20 32008]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-07 691696]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\\SystemRoot\System32\Drivers\NIS\1002000.007\SYMEFA.SYS [x]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\NIS\1002000.007\BHDrvx86.sys [2008-12-12 255536]
S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\NIS\1002000.007\ccHPx86.sys [2008-12-16 362544]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090331.007\IDSvix86.sys [2009-01-29 292912]
S1 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2011-02-20 76696]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};c:\program files\Hewlett-Packard\Media\DVD\000.fcl [2008-09-26 59376]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2009-01-19 277544]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_408c4e5a\aestsrv.exe [2008-06-27 77824]
S2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2010-11-27 6416120]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-08-07 24880]
S2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe [2008-12-12 115560]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2008-09-24 296320]
S2 TVSched;TV Task Scheduler (TVTS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2008-09-24 116096]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-09-16 599344]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-09-04 54784]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-08-07 97536]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-08-06 44576]
S3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2011-02-20 26096]
S3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-09-16 40752]
--- Other Services/Drivers In Memory ---
*Deregistered* - knkvya
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 09:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2011-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4218994666-1609149145-1912675028-1000Core.job
- c:\users\Jopek\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-06 19:54]
2011-02-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4218994666-1609149145-1912675028-1000UA.job
- c:\users\Jopek\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-06 19:54]
2009-10-22 c:\windows\Tasks\NSSstub.job
- c:\windows\System32\Adobe\Shockwave 11\nssstub.exe [2009-10-22 05:29]
.
.
------- Supplementary Scan -------
.
uStart Page = https://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv=1eic6yu9oa4y3&scc=1<mpl=default<mplcache=2
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=sk_sk&c=91&bd=Pavilion&pf=cnnb
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SmartMenu - %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
HKLM-Run-SysTrayApp - %ProgramFiles%\IDT\WDM\sttray.exe
MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
AddRemove-{8EB85C0E-DE7D-4A53-BD66-708B8F2C80B0} - c:\users\Jopek\AppData\Local\HHD Software\Hex Editor Neo\Setup\uninstHEX.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-22 12:08
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.2.0.7\diMaster.dll\" /prefetch:1"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\knkvya]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-4218994666-1609149145-1912675028-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:d9,41,5b,32,b6,e4,3d,ed,2f,aa,d4,0d,c6,02,e0,7b,ea,c0,47,03,20,7a,2b,
83,5d,a6,73,73,56,b1,a5,e3,fb,61,0c,b5,d3,50,b0,fe,dc,58,ca,50,00,70,b4,5b,\
"??"=hex:61,af,b9,29,dc,ad,af,b5,2d,19,88,12,a0,64,03,d3
[HKEY_USERS\S-1-5-21-4218994666-1609149145-1912675028-1000\Software\SecuROM\License information*]
"datasecu"=hex:d2,db,cf,46,ed,31,aa,36,69,4c,de,3c,a4,62,4a,df,47,92,80,f2,99,
cf,bf,7f,5b,a1,48,82,34,6e,50,88,89,80,88,e8,97,e5,77,b8,e0,bc,cd,4c,9e,1b,\
"rkeysecu"=hex:77,6f,df,33,3b,4c,0e,93,93,19,68,88,ee,9a,6d,21
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3808)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\windows\system32\btmmhook.dll
c:\program files\DigitalPersona\Bin\DpoSet.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_408c4e5a\STacSV.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\WLANExt.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
c:\program files\IDT\WDM\sttray.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2011-02-22 12:25:38 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-22 11:25
Pre-Run: 237Â 950Â 390Â 272 bytes free
Post-Run: 237Â 604Â 667Â 392 bytes free
- - End Of File - - 0C8AA821B0767685D7E54D49CBEB9C97
I spent a lot of time by trying to delete rootkit c:\windows\system32\drivers\knkvya.sys
This message is shown: "cannot delete knkvya: cannot read from the source file or disk".
I tried this programs:
KillBox
command prompt
Malwarebytes Anti-Malware
ComboFix
but the knkvya.sys is still there. Here is my ComboFix log (thanks for your advice!):
ComboFix 11-02-21.02 - Jopek . 02. 2011 11:49:30.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3068.1771 [GMT 1:00]
Running from: c:\users\Jopek\Desktop\commy.exe
AV: Norton Internet Security *Disabled/Outdated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Norton Internet Security *Disabled/Outdated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Recycle
.
((((((((((((((((((((((((( Files Created from 2011-01-22 to 2011-02-22 )))))))))))))))))))))))))))))))
.
2011-02-22 11:03 . 2011-02-22 11:09 -------- d-----w- c:\users\Jopek\AppData\Local\temp
2011-02-22 11:03 . 2011-02-22 11:03 -------- d-----w- c:\users\Guest\AppData\Local\temp
2011-02-22 11:03 . 2011-02-22 11:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-22 10:02 . 2011-02-22 10:02 -------- d-----w- c:\users\Jopek\AppData\Roaming\Malwarebytes
2011-02-22 10:01 . 2011-02-22 10:01 -------- d-----w- c:\programdata\Malwarebytes
2011-02-22 10:01 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-22 10:01 . 2011-02-22 10:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-22 10:01 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-22 09:21 . 2011-02-22 09:27 -------- d-----w- c:\programdata\SecTaskMan
2011-02-22 09:21 . 2011-02-22 09:21 -------- d-----w- c:\program files\Security Task Manager
2011-02-21 20:58 . 2011-02-21 20:58 -------- d-----w- c:\users\Jopek\AppData\Roaming\Uniblue
2011-02-21 15:14 . 2011-02-21 15:14 -------- d-----w- c:\users\Jopek\AppData\Local\PackageAware
2011-02-20 21:53 . 2011-02-20 22:01 -------- d-sh--r- c:\users\Jopek\Microsoft-Driver-1-52-2475-9627-8645
2011-02-20 21:36 . 2011-02-20 22:01 -------- d-sh--r- c:\users\Jopek\Microsoft-Update-Service-8-8586-7578-5800
2011-02-20 18:03 . 2011-01-08 08:47 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-02-20 18:03 . 2011-01-08 06:28 292352 ----a-w- c:\windows\system32\atmfd.dll
2011-02-19 17:32 . 2011-01-13 09:41 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5F6AA587-68ED-4A42-A3B3-B01BE09C9382}\mpengine.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-21 10:36 . 2010-05-03 17:03 2018272 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2011-02-20 19:41 . 2010-11-11 11:27 76696 ----a-w- c:\windows\system32\drivers\pxrts.sys
2011-02-20 19:41 . 2010-11-11 11:27 71880 ----a-w- c:\windows\system32\PxSecure.dll
2011-02-20 19:41 . 2010-11-11 11:27 32008 ----a-w- c:\windows\system32\drivers\pxscan.sys
2011-02-20 19:41 . 2010-11-11 11:27 26096 ----a-w- c:\windows\system32\drivers\pxkbf.sys
2010-12-28 15:55 . 2011-01-13 10:03 413696 ----a-w- c:\windows\system32\odbc32.dll
2010-12-14 14:49 . 2011-01-13 10:02 1169408 ----a-w- c:\windows\system32\sdclt.exe
2010-12-04 11:37 . 2010-10-07 17:55 109080 ----a-w- c:\windows\system32\OpenAL32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-07-12 226904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-24 1348904]
"TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-09-25 1152296]
"CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-09-25 189736]
"UCam_Menu"="c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-07-14 814144]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-19 13593120]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-19 92704]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-19 727592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0afvaa6.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0afvaa6.exe
backup=c:\windows\pss\0afvaa6.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0aqaaqq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0aqaaqq.exe
backup=c:\windows\pss\0aqaaqq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0bq6qgg.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0bq6qgg.exe
backup=c:\windows\pss\0bq6qgg.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0ej1otj.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0ej1otj.exe
backup=c:\windows\pss\0ej1otj.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0f8al1q.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0f8al1q.exe
backup=c:\windows\pss\0f8al1q.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0iscccx.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0iscccx.exe
backup=c:\windows\pss\0iscccx.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0llbbgb.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0llbbgb.exe
backup=c:\windows\pss\0llbbgb.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0llq21l.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0llq21l.exe
backup=c:\windows\pss\0llq21l.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0mrhm7m.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0mrhm7m.exe
backup=c:\windows\pss\0mrhm7m.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0mscmm1.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0mscmm1.exe
backup=c:\windows\pss\0mscmm1.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0q6g7gb.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0q6g7gb.exe
backup=c:\windows\pss\0q6g7gb.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0qfqqfq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0qfqqfq.exe
backup=c:\windows\pss\0qfqqfq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0qvqfq1.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0qvqfq1.exe
backup=c:\windows\pss\0qvqfq1.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0rrhhmc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0rrhhmc.exe
backup=c:\windows\pss\0rrhhmc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^0t9z31t.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0t9z31t.exe
backup=c:\windows\pss\0t9z31t.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1aqaaqq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1aqaaqq.exe
backup=c:\windows\pss\1aqaaqq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1bbgvbv.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1bbgvbv.exe
backup=c:\windows\pss\1bbgvbv.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1eyyeoj.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1eyyeoj.exe
backup=c:\windows\pss\1eyyeoj.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1fl71fa.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1fl71fa.exe
backup=c:\windows\pss\1fl71fa.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1iinci6.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1iinci6.exe
backup=c:\windows\pss\1iinci6.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1m9m1cm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1m9m1cm.exe
backup=c:\windows\pss\1m9m1cm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1mcchcr.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1mcchcr.exe
backup=c:\windows\pss\1mcchcr.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1qav0lf.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1qav0lf.exe
backup=c:\windows\pss\1qav0lf.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1uppu7e.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1uppu7e.exe
backup=c:\windows\pss\1uppu7e.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1vqvg4q.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1vqvg4q.exe
backup=c:\windows\pss\1vqvg4q.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1vvaqvq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1vvaqvq.exe
backup=c:\windows\pss\1vvaqvq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1wmrmrr.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1wmrmrr.exe
backup=c:\windows\pss\1wmrmrr.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1wrrhhm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1wrrhhm.exe
backup=c:\windows\pss\1wrrhhm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1xiisnn.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1xiisnn.exe
backup=c:\windows\pss\1xiisnn.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1xrrmhc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1xrrmhc.exe
backup=c:\windows\pss\1xrrmhc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^1zkkz7p.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1zkkz7p.exe
backup=c:\windows\pss\1zkkz7p.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^2bww2b5.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2bww2b5.exe
backup=c:\windows\pss\2bww2b5.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^2c981rc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2c981rc.exe
backup=c:\windows\pss\2c981rc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^2ididss.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2ididss.exe
backup=c:\windows\pss\2ididss.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^2llgvgq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2llgvgq.exe
backup=c:\windows\pss\2llgvgq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^3lflfll.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3lflfll.exe
backup=c:\windows\pss\3lflfll.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^42bbr7h.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\42bbr7h.exe
backup=c:\windows\pss\42bbr7h.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^4iid5id.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\4iid5id.exe
backup=c:\windows\pss\4iid5id.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^4vffaf6.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\4vffaf6.exe
backup=c:\windows\pss\4vffaf6.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^5aav1la.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5aav1la.exe
backup=c:\windows\pss\5aav1la.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^5aqqk40.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5aqqk40.exe
backup=c:\windows\pss\5aqqk40.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^5hrchcc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5hrchcc.exe
backup=c:\windows\pss\5hrchcc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^5hrxh72.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5hrxh72.exe
backup=c:\windows\pss\5hrxh72.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^5indsni.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5indsni.exe
backup=c:\windows\pss\5indsni.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^6a7avq0.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\6a7avq0.exe
backup=c:\windows\pss\6a7avq0.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^6wwrwhc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\6wwrwhc.exe
backup=c:\windows\pss\6wwrwhc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^96uka6f.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\96uka6f.exe
backup=c:\windows\pss\96uka6f.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^dssxss3xnn.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dssxss3xnn.exe
backup=c:\windows\pss\dssxss3xnn.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^i9i1xiix7.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\i9i1xiix7.exe
backup=c:\windows\pss\i9i1xiix7.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^idxxssiid.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\idxxssiid.exe
backup=c:\windows\pss\idxxssiid.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^jttotott.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jttotott.exe
backup=c:\windows\pss\jttotott.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^lww1b0br6rw.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lww1b0br6rw.exe
backup=c:\windows\pss\lww1b0br6rw.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^mhhcrc0r.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mhhcrc0r.exe
backup=c:\windows\pss\mhhcrc0r.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^mhmhm76cxcx.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mhmhm76cxcx.exe
backup=c:\windows\pss\mhmhm76cxcx.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^r4rc1mhhm7m.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\r4rc1mhhm7m.exe
backup=c:\windows\pss\r4rc1mhhm7m.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^rmccr7hx.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rmccr7hx.exe
backup=c:\windows\pss\rmccr7hx.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^rrx71rm0r.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rrx71rm0r.exe
backup=c:\windows\pss\rrx71rm0r.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^rxhcrrmm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rxhcrrmm.exe
backup=c:\windows\pss\rxhcrrmm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vqvf4a0qf.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vqvf4a0qf.exe
backup=c:\windows\pss\vqvf4a0qf.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vqvqffaq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vqvqffaq.exe
backup=c:\windows\pss\vqvqffaq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vvalfvlfa.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vvalfvlfa.exe
backup=c:\windows\pss\vvalfvlfa.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vvalfvlv.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vvalfvlv.exe
backup=c:\windows\pss\vvalfvlv.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vvqffvava76.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vvqffvava76.exe
backup=c:\windows\pss\vvqffvava76.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vvqqqvqfvff.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vvqqqvqfvff.exe
backup=c:\windows\pss\vvqqqvqfvff.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^vvqvfaa9.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vvqvfaa9.exe
backup=c:\windows\pss\vvqvfaa9.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^w032bwlw0w.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\w032bwlw0w.exe
backup=c:\windows\pss\w032bwlw0w.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^w2gb0qglq.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\w2gb0qglq.exe
backup=c:\windows\pss\w2gb0qglq.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^w2rrw7hhb.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\w2rrw7hhb.exe
backup=c:\windows\pss\w2rrw7hhb.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wb93lblgbb.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wb93lblgbb.exe
backup=c:\windows\pss\wb93lblgbb.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wcrwrwhccww.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wcrwrwhccww.exe
backup=c:\windows\pss\wcrwrwhccww.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wgbwww6w.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wgbwww6w.exe
backup=c:\windows\pss\wgbwww6w.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^whrr2m9m.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\whrr2m9m.exe
backup=c:\windows\pss\whrr2m9m.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wm037wrr.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wm037wrr.exe
backup=c:\windows\pss\wm037wrr.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wm081rcc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wm081rcc.exe
backup=c:\windows\pss\wm081rcc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wqqlql6g.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wqqlql6g.exe
backup=c:\windows\pss\wqqlql6g.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wr0hchrm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wr0hchrm.exe
backup=c:\windows\pss\wr0hchrm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wr5mccw40w.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wr5mccw40w.exe
backup=c:\windows\pss\wr5mccw40w.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wrrhm9m1.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wrrhm9m1.exe
backup=c:\windows\pss\wrrhm9m1.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wwhcrr2m9m1.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wwhcrr2m9m1.exe
backup=c:\windows\pss\wwhcrr2m9m1.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wwmb9wwrm0.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wwmb9wwrm0.exe
backup=c:\windows\pss\wwmb9wwrm0.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wwrwrhhb.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wwrwrhhb.exe
backup=c:\windows\pss\wwrwrhhb.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^x5mhmxhh2c9.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\x5mhmxhh2c9.exe
backup=c:\windows\pss\x5mhmxhh2c9.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^x6mcs6mmhm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\x6mcs6mmhm.exe
backup=c:\windows\pss\x6mcs6mmhm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xcnnhnn6c.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xcnnhnn6c.exe
backup=c:\windows\pss\xcnnhnn6c.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xh6hc5r5mr.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xh6hc5r5mr.exe
backup=c:\windows\pss\xh6hc5r5mr.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xhrrm5mccx.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xhrrm5mccx.exe
backup=c:\windows\pss\xhrrm5mccx.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xi1xxdsi.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xi1xxdsi.exe
backup=c:\windows\pss\xi1xxdsi.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xissncxsi.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xissncxsi.exe
backup=c:\windows\pss\xissncxsi.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xixx0iic0xn.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xixx0iic0xn.exe
backup=c:\windows\pss\xixx0iic0xn.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xnsns0sis.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xnsns0sis.exe
backup=c:\windows\pss\xnsns0sis.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xrhh1c9c1rc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xrhh1c9c1rc.exe
backup=c:\windows\pss\xrhh1c9c1rc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xrxhcrrm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xrxhcrrm.exe
backup=c:\windows\pss\xrxhcrrm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xshmxhmmch.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xshmxhmmch.exe
backup=c:\windows\pss\xshmxhmmch.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xss9s1issi.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xss9s1issi.exe
backup=c:\windows\pss\xss9s1issi.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xsxsi6ddnii.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xsxsi6ddnii.exe
backup=c:\windows\pss\xsxsi6ddnii.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xx2h0hxcxc7.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xx2h0hxcxc7.exe
backup=c:\windows\pss\xx2h0hxcxc7.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xx6mrmr8mm.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xx6mrmr8mm.exe
backup=c:\windows\pss\xx6mrmr8mm.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xxc7m6hhcxx.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xxc7m6hhcxx.exe
backup=c:\windows\pss\xxc7m6hhcxx.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xxcrxrxhc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xxcrxrxhc.exe
backup=c:\windows\pss\xxcrxrxhc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xxsiisnniix.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xxsiisnniix.exe
backup=c:\windows\pss\xxsiisnniix.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^xxsx7mhc.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\xxsx7mhc.exe
backup=c:\windows\pss\xxsx7mhc.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^y98nniy6ssn.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\y98nniy6ssn.exe
backup=c:\windows\pss\y98nniy6ssn.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^yi5ssn1dsy9.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\yi5ssn1dsy9.exe
backup=c:\windows\pss\yi5ssn1dsy9.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^yid6s7sni0.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\yid6s7sni0.exe
backup=c:\windows\pss\yid6s7sni0.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^yotojjee2.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\yotojjee2.exe
backup=c:\windows\pss\yotojjee2.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ytty7ytyi.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ytty7ytyi.exe
backup=c:\windows\pss\ytty7ytyi.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^z6u7ffzz.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\z6u7ffzz.exe
backup=c:\windows\pss\z6u7ffzz.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^z6zooj1z.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\z6zooj1z.exe
backup=c:\windows\pss\z6zooj1z.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^zeojeejeue1.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zeojeejeue1.exe
backup=c:\windows\pss\zeojeejeue1.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^zjej8eez1pe.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zjej8eez1pe.exe
backup=c:\windows\pss\zjej8eez1pe.exe.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Jopek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^zoouoeojee.exe]
path=c:\users\Jopek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zoouoeojee.exe
backup=c:\windows\pss\zoouoeojee.exe.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDAgent]
2008-09-26 01:36 1148200 ------w- c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25 125952 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 09:16 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVAgent]
2008-09-24 17:07 206120 ------w- c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
2008-06-13 17:11 210216 ------w- c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
2008-06-13 17:11 210216 ------w- c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut]
2008-06-13 17:11 210216 ------w- c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]
2008-09-26 09:15 210216 ------w- c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\NIS\1002000.007\SYMNDISV.SYS [2008-12-12 40496]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936]
S0 pxscan;pxscan;c:\windows\System32\drivers\pxscan.sys [2011-02-20 32008]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-07 691696]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\\SystemRoot\System32\Drivers\NIS\1002000.007\SYMEFA.SYS [x]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\NIS\1002000.007\BHDrvx86.sys [2008-12-12 255536]
S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\NIS\1002000.007\ccHPx86.sys [2008-12-16 362544]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090331.007\IDSvix86.sys [2009-01-29 292912]
S1 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2011-02-20 76696]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};c:\program files\Hewlett-Packard\Media\DVD\000.fcl [2008-09-26 59376]
S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2009-01-19 277544]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_408c4e5a\aestsrv.exe [2008-06-27 77824]
S2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2010-11-27 6416120]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-08-07 24880]
S2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe [2008-12-12 115560]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2008-09-24 296320]
S2 TVSched;TV Task Scheduler (TVTS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2008-09-24 116096]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-09-16 599344]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-09-04 54784]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-08-07 97536]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-08-06 44576]
S3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2011-02-20 26096]
S3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-09-16 40752]
--- Other Services/Drivers In Memory ---
*Deregistered* - knkvya
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 09:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2011-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4218994666-1609149145-1912675028-1000Core.job
- c:\users\Jopek\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-06 19:54]
2011-02-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4218994666-1609149145-1912675028-1000UA.job
- c:\users\Jopek\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-06 19:54]
2009-10-22 c:\windows\Tasks\NSSstub.job
- c:\windows\System32\Adobe\Shockwave 11\nssstub.exe [2009-10-22 05:29]
.
.
------- Supplementary Scan -------
.
uStart Page = https://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv=1eic6yu9oa4y3&scc=1<mpl=default<mplcache=2
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=sk_sk&c=91&bd=Pavilion&pf=cnnb
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SmartMenu - %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
HKLM-Run-SysTrayApp - %ProgramFiles%\IDT\WDM\sttray.exe
MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
AddRemove-{8EB85C0E-DE7D-4A53-BD66-708B8F2C80B0} - c:\users\Jopek\AppData\Local\HHD Software\Hex Editor Neo\Setup\uninstHEX.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-22 12:08
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.2.0.7\diMaster.dll\" /prefetch:1"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\knkvya]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-4218994666-1609149145-1912675028-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:d9,41,5b,32,b6,e4,3d,ed,2f,aa,d4,0d,c6,02,e0,7b,ea,c0,47,03,20,7a,2b,
83,5d,a6,73,73,56,b1,a5,e3,fb,61,0c,b5,d3,50,b0,fe,dc,58,ca,50,00,70,b4,5b,\
"??"=hex:61,af,b9,29,dc,ad,af,b5,2d,19,88,12,a0,64,03,d3
[HKEY_USERS\S-1-5-21-4218994666-1609149145-1912675028-1000\Software\SecuROM\License information*]
"datasecu"=hex:d2,db,cf,46,ed,31,aa,36,69,4c,de,3c,a4,62,4a,df,47,92,80,f2,99,
cf,bf,7f,5b,a1,48,82,34,6e,50,88,89,80,88,e8,97,e5,77,b8,e0,bc,cd,4c,9e,1b,\
"rkeysecu"=hex:77,6f,df,33,3b,4c,0e,93,93,19,68,88,ee,9a,6d,21
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3808)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\windows\system32\btmmhook.dll
c:\program files\DigitalPersona\Bin\DpoSet.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_408c4e5a\STacSV.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\WLANExt.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
c:\program files\IDT\WDM\sttray.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2011-02-22 12:25:38 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-22 11:25
Pre-Run: 237Â 950Â 390Â 272 bytes free
Post-Run: 237Â 604Â 667Â 392 bytes free
- - End Of File - - 0C8AA821B0767685D7E54D49CBEB9C97