
Skan z Pandy
- Kod: Zaznacz wszystko
00097560 HackTool/PassRead.A HackTools No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Gadu-Gadu\backup\Devil\gpr.exe
00119206 Trj/Antinap.A Virus/Trojan No 0 Yes No E:\folder.htt
00119206 Trj/Antinap.A Virus/Trojan No 0 Yes No F:\folder.htt
00120941 W32/Hoodtray.A.worm Virus/Worm No 0 Yes No C:\Documents and Settings\Damian\Recent\Recent.exe
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.doubleclick.net/]
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.tradedoubler.com/]
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.tradedoubler.com/]
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.gostats.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.statcounter.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Damian\Dane aplikacji\Mozilla\Firefox\Profiles\leht39mo.default\cookies.txt[.go.com/]
00282813 W32/Perlovga.A.worm Virus/Worm No 0 Yes No C:\copy.exe
00282813 W32/Perlovga.A.worm Virus/Worm No 0 Yes No F:\copy.exe
00282813 W32/Perlovga.A.worm Virus/Worm No 0 Yes No E:\copy.exe
00282813 W32/Perlovga.A.worm Virus/Worm No 0 Yes No C:\WINDOWS\xcopy.exe
00291864 Trj/Dropper.UN Virus/Trojan No 1 Yes No F:\host.exe
00291864 Trj/Dropper.UN Virus/Trojan No 1 Yes No C:\host.exe
00291864 Trj/Dropper.UN Virus/Trojan No 1 Yes No E:\host.exe
00291864 Trj/Dropper.UN Virus/Trojan No 1 Yes No C:\WINDOWS\svchost.exe
00292040 W32/Nethood.B.worm Virus No 0 Yes No C:\Program Files\NetMeeting\folder.htt
00292040 W32/Nethood.B.worm Virus No 0 Yes No C:\Documents and Settings\Damian\PrintHood\folder.htt
00292040 W32/Nethood.B.worm Virus No 0 Yes No E:\Gry\folder.htt
00292040 W32/Nethood.B.worm Virus No 0 Yes No F:\Filmy\The Mist\folder.htt
00292040 W32/Nethood.B.worm Virus No 0 Yes No C:\Documents and Settings\folder.htt
00292040 W32/Nethood.B.worm Virus No 0 Yes No E:\Programy\folder.htt
00292040 W32/Nethood.B.worm Virus No 0 Yes No E:\Programy\Alcohol120\folder.htt
00296652 Trj/Perlovga.B Virus/Trojan No 0 Yes No C:\WINDOWS\system32\temp1.exe
00364849 Adware/SaveNow Adware No 0 Yes No C:\Program Files\DAEMON Tools\SetupDTSB.exe
00364850 Adware/SaveNow Adware No 0 No No C:\Program Files\DAEMON Tools\SetupDTSB.exe[C:\Program Files\DAEMON Tools\SetupDTSB.exe][DaemonTools_WhenUSave_Installer.exe]
01076997 Generic Trojan Virus/Trojan No 0 Yes No C:\Gry\Gothic III\Gothic3.exe
01076997 Generic Trojan Virus/Trojan No 0 No No E:\Gry\Gothic\Gothic III\Gothic3v1.12NoDVDFixedexeEuro.rar[Gothic3.exe]
02414229 Bck/Agent.GTC Virus/Trojan No 1 Yes No C:\WINDOWS\system32\temp2.exe
02884116 W32/Perlovga.A.worm Virus/Worm No 0 Yes No F:\autorun.inf
02884116 W32/Perlovga.A.worm Virus/Worm No 0 Yes No C:\WINDOWS\autorun.inf
02884116 W32/Perlovga.A.worm Virus/Worm No 0 Yes No C:\autorun.inf
02884116 W32/Perlovga.A.worm Virus/Worm No 0 Yes No E:\autorun.inf
03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\Program Files\mIRC\authpatch.exe
Hijack
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:45:19, on 2008-09-21
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\mIRC\mirc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Damian\Pulpit\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
F3 - REG:win.ini: load=C:\WINDOWS\svchost.exe
O1 - Hosts: 217.79.177.181 uni1.en.x-wars.net
O1 - Hosts: 217.79.177.181 en.x-wars.net
O1 - Hosts: 217.79.177.181 pt.x-wars.net
O1 - Hosts: 217.79.177.181 uni1.pt.x-wars.net
O1 - Hosts: 217.79.177.181 fr.x-wars.net
O1 - Hosts: 217.79.177.181 uni2.fr.x-wars.net
O1 - Hosts: 217.79.177.181 uni1.pl.x-wars.net
O1 - Hosts: 217.79.177.181 pl.x-wars.net
O1 - Hosts: 217.79.177.181 images.x-wars.net
O1 - Hosts: 217.79.177.181 uni1.en.x-wars.net
O1 - Hosts: 217.79.177.181 en.x-wars.net
O1 - Hosts: 217.79.177.181 uni1.en.x-wars.net
O1 - Hosts: 217.79.177.181 graphicpacks.x-wars.net
O1 - Hosts: 217.79.177.181 www.x-wars.net
O1 - Hosts: 85.232.232.39 www.dadxwars.cba.pl
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [TempCom] C:\WINDOWS\FONTS\201C9.com
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Vidalia] "C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4446591F-3BB0-4C06-9140-D52388D66918}: NameServer = 83.142.120.242
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 6111 bytes