
Log:
- Kod: Zaznacz wszystko
Logfile of random's system information tool 1.06 (written by random/random)
Run by matwiej at 2009-09-29 23:47:09
Microsoft Windows XP Professional Dodatek Service Pack 3
System drive C: has 64 GB (84%) free of 76 GB
Total RAM: 502 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:47:10, on 2009-09-29
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nowe Gadu-Gadu\gg.exe
C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Temp\wpv791254042811.exe
C:\WINDOWS\system32\restorer32_a.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\matwiej\Dane aplikacji\seres.exe
C:\Documents and Settings\matwiej\Dane aplikacji\svcst.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\matwiej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\matwiej\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\matwiej\Moje dokumenty\Downloads\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\matwiej.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [sysgif32] C:\WINDOWS\Temp\wpv791254042811.exe
O4 - HKLM\..\Run: [restorer32_a] C:\WINDOWS\system32\restorer32_a.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKLM\..\Run: [Antivirus Pro 2010] "C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe" /hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\matwiej\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [restorer32_a] C:\Documents and Settings\matwiej\restorer32_a.exe
O4 - HKCU\..\Run: [mserv] C:\Documents and Settings\matwiej\Dane aplikacji\seres.exe
O4 - HKCU\..\Run: [svchost] C:\Documents and Settings\matwiej\Dane aplikacji\svcst.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O4 - Startup: ikowin32.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Usługa konfiguracji Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
--
End of file - 4855 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-776561741-1972579041-1606980848-1003Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-776561741-1972579041-1606980848-1003UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [2003-11-04 54248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-06-28 41368]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2004-11-02 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2004-11-02 126976]
"LtMoh"=C:\Program Files\ltmoh\Ltmoh.exe [2005-04-12 184320]
"sysgif32"=C:\WINDOWS\Temp\wpv791254042811.exe [2009-09-29 36352]
"restorer32_a"=C:\WINDOWS\system32\restorer32_a.exe [2009-09-29 43520]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
"Antivirus Pro 2010"=C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe [2009-09-29 567808]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Nowe Gadu-Gadu"=C:\Program Files\Nowe Gadu-Gadu\gg.exe [2009-08-31 11391592]
"Google Update"=C:\Documents and Settings\matwiej\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2009-09-29 133104]
"restorer32_a"=C:\Documents and Settings\matwiej\restorer32_a.exe [2009-09-29 43520]
"mserv"=C:\Documents and Settings\matwiej\Dane aplikacji\seres.exe [2009-09-29 13312]
"svchost"=C:\Documents and Settings\matwiej\Dane aplikacji\svcst.exe [2009-09-29 13312]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
C:\Program Files\BearShare\BearShare.exe /pause []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-07-24 490952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2009-03-09 37888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk]
C:\PROGRA~1\SAGEMW~1\WLANUTL.exe [2006-01-19 925696]
C:\Documents and Settings\matwiej\Menu Start\Programy\Autostart
ikowin32.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-11-02 348160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-05-08 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceClassicControlPanel"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Nowe Gadu-Gadu\gg.exe"="C:\Program Files\Nowe Gadu-Gadu\gg.exe:*:Enabled:Nowe Gadu-Gadu"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74681008-bb07-11dd-8a45-000fb0877b0c}]
shell\AutoRun\command - E:\abk.bat
shell\explore\command - E:\abk.bat
shell\open\command - E:\abk.bat
======List of files/folders created in the last 1 months======
2009-09-29 23:47:09 ----D---- C:\rsit
2009-09-29 23:38:45 ----A---- C:\WINDOWS\system32\egunu.bat
2009-09-29 23:38:45 ----A---- C:\WINDOWS\ivasovo.bat
2009-09-29 23:38:45 ----A---- C:\WINDOWS\ihoneke.vbs
2009-09-29 23:38:45 ----A---- C:\Program Files\Common Files\owalipe.com
2009-09-29 23:38:45 ----A---- C:\Documents and Settings\All Users\Dane aplikacji\okidafej.vbs
2009-09-29 23:37:46 ----D---- C:\Program Files\AntivirusPro_2010
2009-09-29 23:36:20 ----A---- C:\Documents and Settings\matwiej\Dane aplikacji\lizkavd.exe
2009-09-29 23:35:59 ----A---- C:\Documents and Settings\matwiej\Dane aplikacji\svcst.exe
2009-09-29 23:35:59 ----A---- C:\Documents and Settings\matwiej\Dane aplikacji\seres.exe
2009-09-29 23:35:53 ----A---- C:\WINDOWS\system32\restorer32_a.exe
2009-09-29 18:30:06 ----D---- C:\WINDOWS\LastGood
2009-09-29 08:52:30 ----A---- C:\Program Files\ChromeSetup.exe
2009-09-29 05:16:58 ----D---- C:\Program Files\Trend Micro
2009-09-29 05:16:39 ----A---- C:\Program Files\HJTInstall.exe
2009-09-29 05:09:43 ----D---- C:\WINDOWS\pss
2009-09-29 04:56:08 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Windows Genuine Advantage
2009-09-29 04:43:07 ----D---- C:\Program Files\CCleaner
2009-09-13 11:57:27 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
======List of files/folders modified in the last 1 months======
2009-09-29 23:47:02 ----D---- C:\WINDOWS\Prefetch
2009-09-29 23:38:45 ----D---- C:\WINDOWS\system32
2009-09-29 23:38:45 ----D---- C:\WINDOWS
2009-09-29 23:38:45 ----D---- C:\Program Files\Common Files
2009-09-29 23:37:46 ----RD---- C:\Program Files
2009-09-29 23:35:48 ----D---- C:\WINDOWS\Temp
2009-09-29 23:34:25 ----D---- C:\Program Files\Mozilla Firefox
2009-09-29 18:31:23 ----HD---- C:\WINDOWS\inf
2009-09-29 18:30:05 ----D---- C:\WINDOWS\system32\CatRoot2
2009-09-29 12:45:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-09-29 12:03:08 ----D---- C:\Documents and Settings\matwiej\Dane aplikacji\Nowe Gadu-Gadu
2009-09-29 08:54:41 ----SHD---- C:\WINDOWS\Installer
2009-09-29 08:54:40 ----D---- C:\WINDOWS\WinSxS
2009-09-29 08:54:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-09-29 08:54:21 ----D---- C:\Program Files\Nowe Gadu-Gadu
2009-09-29 08:53:26 ----SD---- C:\WINDOWS\Tasks
2009-09-29 05:10:27 ----SH---- C:\boot.ini
2009-09-29 05:10:27 ----A---- C:\WINDOWS\win.ini
2009-09-29 05:10:27 ----A---- C:\WINDOWS\system.ini
2009-09-29 04:56:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-09-29 04:48:53 ----D---- C:\Program Files\DarkSwords
2009-09-29 04:48:37 ----HD---- C:\Program Files\InstallShield Installation Information
2009-09-29 04:48:11 ----D---- C:\Program Files\Sims
2009-09-29 04:46:52 ----D---- C:\Program Files\BearShare
2009-09-29 04:46:31 ----D---- C:\Program Files\BS.Player ControlBar
2009-09-29 04:44:07 ----D---- C:\WINDOWS\Debug
2009-09-29 04:44:06 ----D---- C:\WINDOWS\Minidump
2009-09-29 04:39:19 ----D---- C:\Program Files\Java
2009-09-29 04:39:04 ----D---- C:\WINDOWS\ie7updates
2009-09-24 19:53:39 ----D---- C:\Documents and Settings\matwiej\Dane aplikacji\Winamp
2009-09-13 11:56:53 ----HD---- C:\WINDOWS\$hf_mig$
2009-09-08 12:56:22 ----D---- C:\WINDOWS\system32\CatRoot
2009-09-06 10:39:53 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Sterownik procesora Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.7.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-11-25 21035]
R3 AgereSoftModem;TOSHIBA V92 Software Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2005-04-12 1066278]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-04-19 2317504]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2004-12-22 393600]
R3 CmBatt;Sterownik baterii Microsoft o metodzie kontroli ACPI; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 hidusb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-11-02 773565]
R3 mouhid;Sterownik myszy HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-26 12160]
R3 usbehci;Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Koncentrator z obsługą USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Sterownik Miniport uniwersalnego kontrolera hosta USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2005-03-30 230400]
S3 axogix2c;axogix2c; C:\WINDOWS\system32\drivers\axogix2c.sys []
S3 oflpydin;oflpydin; \??\C:\DOCUME~1\matwiej\USTAWI~1\Temp\oflpydin.sys []
S3 PCANDIS5;PCANDIS5 Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver; C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys [2005-12-22 402432]
S3 USBSTOR;Sterownik magazynu masowego USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-05-08 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-05-08 82944]
S3 ZDCndis5;ZDCndis5 Protocol Driver; \??\C:\WINDOWS\system32\ZDCndis5.SYS []
S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys [2006-01-18 17664]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACS;Usługa konfiguracji Atheros; C:\WINDOWS\system32\acs.exe [2005-09-26 36864]
S3 WMPNetworkSvc;Usługa udostępniania w sieci programu Windows Media Player; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-12-01 918016]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------