
Specyfikacja:
Procesor: AMD Sempron 2500+
Karta graficzna: Radeon 9250 128 MB
Pamięć: Goodram 1GB DDR PC3200 400Mhz
System: WinXP Professional SP3
Płyta główna: MSI KT6V (MS-7021)
Zasilacz: Tracer MGB-400ATX
Temperatury w okolicach 50st. W EventLog nic odnośnie błędu.
Logi z CF i HiJack:
ComboFix:
- Kod: Zaznacz wszystko
ComboFix 09-11-18.06 - Moongrave 2009-11-18 11:29:06.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.1023.743 [GMT 1:00]
Uruchomiony z: C:\Documents and Settings\Moongrave\Moje dokumenty\Pobieranie\ComboFix.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2009-10-18 do 2009-11-18 )))))))))))))))))))))))))))))))
.
2009-11-16 15:06:44 . 2009-11-16 15:06:44 0 dc----w- C:\WINDOWS\system32\DRVSTORE
2009-11-16 15:05:17 . 2009-11-16 15:06:49 0 d-----w- C:\Program Files\VIA
2009-11-16 15:05:17 . 2005-04-14 06:54:22 331184 ------w- C:\WINDOWS\system32\difxapi.dll
2009-11-16 15:04:49 . 2006-10-17 19:22:26 9216 ----a-w- C:\WINDOWS\system32\drivers\videX32.sys
2009-11-16 15:04:48 . 2006-11-08 13:23:52 102912 ----a-w- C:\WINDOWS\system32\drivers\viamraid.sys
2009-11-16 14:34:51 . 2009-11-16 14:34:51 0 d-----w- C:\Program Files\Lavalys
2009-11-14 18:11:04 . 2000-06-26 10:45:30 106496 ----a-w- C:\WINDOWS\system32\TwnLib20.dll
2009-11-14 18:10:59 . 2001-06-26 07:15:46 38912 ------w- C:\WINDOWS\system32\picn20.dll
2009-11-14 18:10:58 . 2001-07-06 13:41:30 569344 ------w- C:\WINDOWS\system32\imagr5.dll
2009-11-14 18:10:58 . 2001-07-06 11:44:46 544768 ------w- C:\WINDOWS\system32\imagx5.dll
2009-11-14 18:10:57 . 2001-07-06 17:24:18 283920 ------w- C:\WINDOWS\system32\ImagXpr5.dll
2009-11-14 18:10:56 . 2009-11-14 18:13:21 0 d-----w- C:\Program Files\Common Files\Ahead
2009-11-14 18:10:56 . 2001-07-09 10:50:42 155648 ----a-w- C:\WINDOWS\system32\NeroCheck.exe
2009-11-14 18:10:50 . 2009-11-14 18:11:09 0 d-----w- C:\Program Files\Ahead
2009-11-13 21:12:29 . 2009-11-13 22:18:40 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\TeamViewer
2009-11-13 21:12:23 . 2009-11-13 21:12:23 0 d-----w- C:\Program Files\TeamViewer
2009-11-13 21:06:31 . 2009-11-13 21:06:31 0 d-----w- C:\Documents and Settings\Moongrave\temp
2009-11-12 12:14:39 . 2005-01-04 09:43:08 4682 ----a-w- C:\WINDOWS\system32\npptNT2.sys
2009-11-12 12:14:02 . 2009-11-12 12:14:02 0 d-----w- C:\Program Files\Common Files\INCA Shared
2009-11-10 21:30:05 . 2009-11-10 21:30:05 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\Apowersoft
2009-11-10 21:30:01 . 2009-11-10 21:30:01 0 d-----w- C:\Program Files\Apowersoft
2009-11-10 21:20:54 . 2009-11-10 21:24:17 0 d-----w- C:\Program Files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2009-11-10 21:19:40 . 2009-11-10 21:20:56 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\GetRightToGo
2009-11-10 21:17:44 . 2009-11-10 21:17:44 766 ----a-w- C:\Documents and Settings\Moongrave\Dane aplikacji\Microsoft\Installer\{7784A172-61F1-445E-8368-601607E0DD22}\_294823.exe
2009-11-10 21:17:44 . 2009-11-10 21:17:44 2238 ----a-w- C:\Documents and Settings\Moongrave\Dane aplikacji\Microsoft\Installer\{7784A172-61F1-445E-8368-601607E0DD22}\_4ae13d6c.exe
2009-11-10 21:17:44 . 2009-11-10 21:17:44 1518 ----a-w- C:\Documents and Settings\Moongrave\Dane aplikacji\Microsoft\Installer\{7784A172-61F1-445E-8368-601607E0DD22}\_69525f90.exe
2009-11-10 21:17:44 . 2009-11-10 21:17:44 1078 ----a-w- C:\Documents and Settings\Moongrave\Dane aplikacji\Microsoft\Installer\{7784A172-61F1-445E-8368-601607E0DD22}\_2cd672ae.exe
2009-11-10 21:17:44 . 2009-11-10 21:17:44 1078 ----a-w- C:\Documents and Settings\Moongrave\Dane aplikacji\Microsoft\Installer\{7784A172-61F1-445E-8368-601607E0DD22}\_18be6784.exe
2009-11-10 21:17:41 . 2009-11-10 21:17:41 0 d-----w- C:\Program Files\MP3 Player Utilities 4.00
2009-11-10 14:14:38 . 2007-02-27 18:31:10 171008 ----a-w- C:\WINDOWS\system32\drivers\ctusfsyn.sys
2009-11-10 14:14:38 . 2005-12-08 14:54:52 114688 ----a-w- C:\WINDOWS\system32\drivers\ctoss2k.sys
2009-11-10 14:14:38 . 2005-12-08 14:54:48 21504 ----a-w- C:\WINDOWS\system32\sfman32.dll
2009-11-10 14:14:38 . 2005-12-08 14:54:46 120832 ----a-w- C:\WINDOWS\system32\sfms32.dll
2009-11-10 14:14:38 . 2005-12-08 14:54:44 142336 ----a-w- C:\WINDOWS\system32\drivers\ctsfm2k.sys
2009-11-10 12:12:39 . 2009-11-10 12:12:39 0 d-----w- C:\Documents and Settings\Moongrave\Ustawienia lokalne\Dane aplikacji\Google
2009-11-10 11:20:11 . 2005-04-22 14:27:40 73728 ----a-w- C:\WINDOWS\MIDIDEF.EXE
2009-11-10 11:20:08 . 2009-11-10 11:20:08 0 d-----w- C:\Documents and Settings\All Users\Dane aplikacji\Creative
2009-11-10 11:20:07 . 2009-11-10 14:34:46 444952 ----a-w- C:\WINDOWS\system32\wrap_oal.dll
2009-11-10 11:20:07 . 2009-11-10 14:34:45 109080 ----a-w- C:\WINDOWS\system32\OpenAL32.dll
2009-11-10 11:20:07 . 2009-06-03 12:06:50 809496 ----a-w- C:\WINDOWS\OALInst.exe
2009-11-10 11:20:07 . 2007-07-02 14:45:26 10670 ----a-w- C:\WINDOWS\SB0792.reg
2009-11-10 11:20:07 . 2007-07-02 14:45:18 10670 ----a-w- C:\WINDOWS\SB0790.reg
2009-11-10 10:56:38 . 2006-07-03 15:55:56 53248 ----a-w- C:\WINDOWS\resdef.exe
2009-11-10 10:56:38 . 2006-06-02 14:08:00 197632 ----a-w- C:\WINDOWS\SF32.exe
2009-11-10 10:56:38 . 2003-04-02 10:13:32 139264 ----a-w- C:\WINDOWS\system32\EAX.DLL
2009-11-10 10:56:37 . 2009-11-10 14:37:08 0 d-----w- C:\Program Files\Creative
2009-11-10 10:56:37 . 2005-06-15 14:07:24 11264 ----a-w- C:\WINDOWS\InRes.DLL
2009-11-10 10:56:37 . 2001-10-26 16:29:28 98304 -c--a-w- C:\WINDOWS\system32\dllcache\a3d.dll
2009-11-10 10:56:37 . 2001-10-26 16:29:28 98304 ----a-w- C:\WINDOWS\system32\a3d.dll
2009-11-08 19:10:19 . 2009-11-08 19:10:54 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\Ventrilo
2009-11-08 19:10:10 . 2009-11-08 19:10:11 0 d-----w- C:\Program Files\Ventrilo
2009-11-08 19:09:57 . 2009-11-08 19:09:57 0 d-----w- C:\Program Files\Common Files\Wise Installation Wizard
2009-11-08 14:40:09 . 2001-10-26 17:28:16 1677824 -c--a-w- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2009-11-08 14:40:09 . 2001-10-26 17:28:16 1677824 ----a-w- C:\WINDOWS\system32\chsbrkr.dll
2009-11-08 14:40:08 . 2001-10-26 17:28:22 70656 -c--a-w- C:\WINDOWS\system32\dllcache\korwbrkr.dll
2009-11-08 14:40:08 . 2001-10-26 17:28:22 70656 ----a-w- C:\WINDOWS\system32\korwbrkr.dll
2009-11-08 14:40:08 . 2001-10-26 17:28:18 838144 -c--a-w- C:\WINDOWS\system32\dllcache\chtbrkr.dll
2009-11-08 14:40:08 . 2001-10-26 17:28:18 838144 ----a-w- C:\WINDOWS\system32\chtbrkr.dll
2009-11-08 14:40:07 . 2001-10-26 17:28:22 98304 -c--a-w- C:\WINDOWS\system32\dllcache\msir3jp.dll
2009-11-08 14:40:07 . 2001-10-26 17:28:22 98304 ----a-w- C:\WINDOWS\system32\msir3jp.dll
2009-11-08 14:40:03 . 2001-10-26 17:28:18 10096640 -c--a-w- C:\WINDOWS\system32\dllcache\hwxcht.dll
2009-11-08 14:38:53 . 2008-04-14 20:36:28 13463552 -c--a-w- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2009-11-08 11:55:06 . 2009-11-08 11:55:06 0 d-----w- C:\Documents and Settings\Moongrave\Ustawienia lokalne\Dane aplikacji\Identities
2009-11-06 19:30:40 . 2009-11-06 19:30:40 0 d-----w- C:\Documents and Settings\Moongrave\dwhelper
2009-11-06 11:58:38 . 2009-11-14 18:13:50 0 d-----w- C:\Program Files\ASCII Art Generator
2009-11-05 20:30:01 . 2009-11-05 20:30:01 0 d-----w- C:\Documents and Settings\Moongrave\Ustawienia lokalne\Dane aplikacji\WMTools Downloaded Files
2009-11-04 14:37:38 . 2009-11-17 17:19:48 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\skypePM
2009-11-04 14:37:38 . 2009-11-04 14:37:38 56 ---ha-w- C:\WINDOWS\system32\ezsidmv.dat
2009-11-04 14:37:16 . 2009-11-17 18:21:54 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\Skype
2009-11-04 14:36:37 . 2009-11-04 14:36:37 0 d-----w- C:\Program Files\Common Files\Skype
2009-11-04 14:36:32 . 2009-11-04 14:37:09 0 d-----r- C:\Program Files\Skype
2009-11-04 14:36:24 . 2009-11-04 14:36:29 0 d-----w- C:\Documents and Settings\All Users\Dane aplikacji\Skype
2009-11-03 21:36:16 . 2008-04-13 23:15:40 26368 -c--a-w- C:\WINDOWS\system32\dllcache\usbstor.sys
2009-11-03 18:28:56 . 2009-11-03 18:28:56 0 d-----w- C:\Documents and Settings\All Users\Dane aplikacji\Adobe Systems
2009-11-03 18:28:40 . 2009-11-03 18:28:40 0 d-----w- C:\Program Files\Common Files\Adobe Systems Shared
2009-11-02 20:21:45 . 2009-11-02 20:23:53 0 d-----w- C:\Documents and Settings\Moongrave\Gadu-Gadu
2009-11-02 20:21:43 . 2009-11-02 20:21:44 0 d-----w- C:\Program Files\Gadu-Gadu
2009-11-02 19:56:43 . 2009-11-02 19:56:43 0 d-----w- C:\Documents and Settings\Moongrave\Ustawienia lokalne\Dane aplikacji\Opera
2009-11-02 19:56:38 . 2009-11-02 19:56:41 0 d-----w- C:\Program Files\Opera
2009-11-02 17:50:23 . 2009-11-02 17:50:23 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\gtk-2.0
2009-11-02 17:43:16 . 2009-11-02 17:43:16 0 d-----w- C:\Documents and Settings\Moongrave\.thumbnails
2009-11-02 17:42:34 . 2009-11-03 14:19:01 0 d-----w- C:\Documents and Settings\Moongrave\.gimp-2.6
2009-11-02 17:42:01 . 2009-11-02 17:42:06 0 d-----w- C:\Program Files\GIMP-2.0
2009-11-02 15:40:31 . 2009-11-03 21:20:46 0 d-----w- C:\Documents and Settings\Moongrave\Ustawienia lokalne\Dane aplikacji\Adobe
2009-11-02 15:40:30 . 2009-11-03 18:30:42 0 d-----w- C:\Program Files\Common Files\Adobe
2009-11-02 15:39:08 . 2009-11-02 15:39:08 0 d-----w- C:\Program Files\Conduit
2009-11-02 15:39:08 . 2009-11-02 15:39:08 0 d-----w- C:\Documents and Settings\Moongrave\Ustawienia lokalne\Dane aplikacji\Conduit
2009-11-02 15:39:06 . 2009-10-06 16:10:14 52224 ------w- C:\Documents and Settings\Moongrave\Dane aplikacji\Mozilla\Firefox\Profiles\gorrfal6.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
2009-11-02 15:39:06 . 2009-10-06 16:10:14 114688 ------w- C:\Documents and Settings\Moongrave\Dane aplikacji\Mozilla\Firefox\Profiles\gorrfal6.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\npmozax.dll
2009-11-02 15:38:26 . 2009-11-07 18:36:05 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\Xfire
2009-11-02 15:38:22 . 2009-11-07 17:12:38 0 d-----w- C:\Program Files\Xfire
2009-11-02 15:18:36 . 2008-02-17 16:16:00 90112 ----a-w- C:\Documents and Settings\Moongrave\Dane aplikacji\Mozilla\Firefox\Profiles\gorrfal6.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
2009-11-02 15:18:36 . 2007-12-28 10:15:38 172032 ----a-w- C:\Documents and Settings\Moongrave\Dane aplikacji\Mozilla\Firefox\Profiles\gorrfal6.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\puttygen.exe
2009-11-02 15:18:36 . 2007-10-08 00:57:52 307200 ----a-w- C:\Documents and Settings\Moongrave\Dane aplikacji\Mozilla\Firefox\Profiles\gorrfal6.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\psftp.exe
2009-11-01 20:22:47 . 2009-11-01 20:23:32 0 d-----w- C:\Program Files\Google
2009-11-01 20:22:43 . 2009-11-01 20:22:44 0 d-----w- C:\Program Files\IrfanView
2009-11-01 14:15:54 . 2009-11-17 19:58:20 0 d-----w- C:\Program Files\Steam
2009-11-01 14:05:14 . 2009-11-01 14:05:14 0 d-----w- C:\ATI
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-17 09:42:28 . 2009-11-01 13:35:27 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\foobar2000
2009-11-16 15:07:00 . 2009-11-01 12:44:07 0 d--h--w- C:\Program Files\InstallShield Installation Information
2009-11-14 10:13:19 . 2009-11-01 13:27:38 0 d-----w- C:\Program Files\Tlen.pl
2009-11-13 10:40:04 . 2001-10-26 16:15:16 79648 ----a-w- C:\WINDOWS\system32\perfc015.dat
2009-11-13 10:40:04 . 2001-10-26 16:15:16 458716 ----a-w- C:\WINDOWS\system32\perfh015.dat
2009-11-13 09:20:45 . 2009-11-01 13:28:04 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\Tlen.pl
2009-11-12 13:34:56 . 2009-11-01 12:56:08 24568 ----a-w- C:\Documents and Settings\Moongrave\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-11-06 14:57:23 . 2009-11-01 12:30:41 86327 ----a-w- C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
2009-11-01 13:35:24 . 2009-11-01 13:35:16 0 d-----w- C:\Program Files\foobar2000
2009-11-01 13:35:08 . 2009-11-01 13:35:07 0 d-----w- C:\Program Files\7-Zip
2009-11-01 13:30:20 . 2009-11-01 13:30:20 0 d-----w- C:\Program Files\Realtek Sound Manager
2009-11-01 13:30:20 . 2009-11-01 13:30:20 0 d-----w- C:\Program Files\AvRack
2009-11-01 13:30:15 . 2009-11-01 13:30:11 0 d-----w- C:\Program Files\Realtek AC97
2009-11-01 13:29:02 . 2009-11-01 12:43:19 0 d-----w- C:\Program Files\Common Files\InstallShield
2009-11-01 13:28:04 . 2009-11-01 13:28:04 0 d-----w- C:\Documents and Settings\All Users\Dane aplikacji\Tlen.pl
2009-11-01 13:15:28 . 2009-11-01 13:15:28 0 ----a-w- C:\WINDOWS\nsreg.dat
2009-11-01 13:05:35 . 2009-11-01 12:51:45 0 d-----w- C:\Program Files\Wirelwss LAN Utility
2009-11-01 12:55:54 . 2009-11-01 12:55:54 0 d-----w- C:\Documents and Settings\Moongrave\Dane aplikacji\ATI
2009-11-01 12:55:48 . 2009-11-01 12:55:48 134 ----a-w- C:\Documents and Settings\Moongrave\Ustawienia lokalne\Dane aplikacji\fusioncache.dat
2009-11-01 12:48:51 . 2009-11-01 12:44:09 0 d-----w- C:\Program Files\ATI Technologies
2009-11-01 12:32:12 . 2009-11-01 12:32:12 0 d-----w- C:\Program Files\microsoft frontpage
2009-11-01 12:29:52 . 2009-11-01 12:29:52 0 d-----w- C:\Program Files\Usługi online
2009-11-01 12:27:37 . 2009-11-01 12:27:37 21856 ----a-w- C:\WINDOWS\system32\emptyregdb.dat
2009-10-15 00:01:24 . 2009-10-15 00:01:24 41872 ----a-w- C:\WINDOWS\system32\xfcodec.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 21:51:32 1695232]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-01 20:23:33 39408]
"SetDefaultMIDI"="MIDIDef.exe" - C:\WINDOWS\MIDIDEF.EXE [2005-04-22 14:27:40 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-01 20:05:00 339968]
"TI WLAN"="C:\Program Files\Wirelwss LAN Utility\TIWLANCu.exe" [2004-12-09 15:49:26 1150976]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 15:41:22 45056]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2008-04-13 20:13:52 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-13 20:13:38 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-13 20:13:54 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-13 20:13:54 455168]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50:42 155648]
"SoundMan"="SOUNDMAN.EXE" - C:\WINDOWS\soundman.exe [2006-11-17 04:42:52 577536]
"P17Helper"="SPIRun.dll" - C:\WINDOWS\system32\SPIRun.dll [2006-07-03 15:43:16 10752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 20:51:12 15360]
C:\Documents and Settings\Moongrave\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Tlen.pl\\tlen.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\Steam\\steamapps\\moongrave\\counter-strike\\hl.exe"=
"C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 TNET1130;802.11 WLAN;C:\WINDOWS\system32\drivers\TNET1130.sys [2009-11-01 14:05:35 438912]
S3 dump_wmimmc;dump_wmimmc;\??\D:\Program Files\Cabanos\Cabal.7z\Cabal\GameGuard\dump_wmimmc.sys --> D:\Program Files\Cabanos\Cabal.7z\Cabal\GameGuard\dump_wmimmc.sys [?]
S3 npggsvc;nProtect GameGuard Service;C:\WINDOWS\system32\GameMon.des -service --> C:\WINDOWS\system32\GameMon.des -service [?]
--- Inne Usługi/Sterowniki w Pamięci ---
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
.
------- Skan uzupełniający -------
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
IE: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
TCP: {D919E08E-550B-4FDC-8682-427551DB2B9B} = 192.168.0.99,194.204.159.1
FF - ProfilePath - C:\Documents and Settings\Moongrave\Dane aplikacji\Mozilla\Firefox\Profiles\gorrfal6.default\
FF - component: C:\Documents and Settings\Moongrave\Dane aplikacji\Mozilla\Firefox\Profiles\gorrfal6.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-cbvcs - C:\WINDOWS\system32\urretnd.exe
HiJack:
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:13, on 2009-11-19
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Wirelwss LAN Utility\TIWLANCu.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CPUCooL\cpucool.exe
C:\Program Files\CPUCooL\CooLSrv.exe
C:\Program Files\Wirelwss LAN Utility\tiwlnsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [TI WLAN] C:\Program Files\Wirelwss LAN Utility\TIWLANCu.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: CPUCooL.lnk = C:\Program Files\CPUCooL\cpucool.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{D919E08E-550B-4FDC-8682-427551DB2B9B}: NameServer = 192.168.0.99,194.204.159.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:\Program Files\CPUCooL\CooLSrv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: TI Wlan Service (tiwlnsvc) - Unknown owner - C:\Program Files\Wirelwss LAN Utility\tiwlnsvc.exe
--
End of file - 4456 bytes