
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:29:18, on 2008-04-07
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Tlen.pl\tlen.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [avpa] C:\WINDOWS\System32\avpo.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://arcaonline.arcabit.com
O15 - Trusted Zone: http://mks.com.pl
O15 - Trusted Zone: http://skaner.mks.com.pl
O15 - Trusted Zone: http://www.mks.com.pl
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} - http://arcaonline.arcabit.com/ArcaOnline.cab
O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} - http://mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1127425333125
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://static.ak.studentix.pl/photouploader/ImageUploader4.cab?nocache=20071128-1
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} - http://skaner.mks.com.pl/SkanerOnline.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/pl/billard8_2_0_0_30.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) - http://67.15.101.3/g_bin/pl/snooker_2_0_0_28.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Harmonogram automatycznej usługi LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O24 - Desktop Component 0: (no name) - http://img.photobucket.com/albums/v499/sandmann21/Pope.jpg
--
End of file - 10713 bytes
- Kod: Zaznacz wszystko
ComboFix 08-04-03.3 - Krzychu 2008-04-07 23:16:23.12 - NTFSx86
Running from: C:\Documents and Settings\Krzychu\Pulpit\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-07 to 2008-04-07 )))))))))))))))))))))))))))))))
.
2008-04-06 21:54 . 2008-04-07 18:04 103,268 -r-hs---- C:\pa39xth.cmd
2008-04-04 23:25 . 2008-04-06 17:11 103,966 -r-hs---- C:\t.com
2008-04-04 16:03 . 2008-04-06 17:12 103,966 --------- C:\WINDOWS\system32\help.exe.tmp
2008-04-04 16:03 . 2002-09-29 00:00 14,848 --a------ C:\WINDOWS\system32\help.exe
2008-04-04 16:03 . 2002-09-29 00:00 14,848 --a--c--- C:\WINDOWS\system32\dllcache\help.exe
2008-04-03 23:58 . 2008-04-03 23:58 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-03 20:35 . 2008-04-04 16:03 103,037 -r-hs---- C:\ranvrgn.exe
2008-04-03 19:45 . 2008-04-03 07:22 103,556 -r-hs---- C:\xyw9tmdj.com
2008-04-03 19:45 . 2007-12-01 20:00 98,620 -r-hs---- C:\ntde1ect.com
2008-04-01 23:46 . 2008-04-02 08:20 103,182 -r-hs---- C:\mvxm.cmd
2008-04-01 19:50 . 2008-04-01 23:45 103,182 -r-hs---- C:\q.com
2008-03-30 16:52 . 2008-03-31 06:53 103,624 -r-hs---- C:\rthrw.com
2008-03-30 00:13 . 2008-03-30 13:22 103,421 -r-hs---- C:\jiwsxh39.exe
2008-03-28 14:34 . 2008-03-29 13:05 103,953 -r-hs---- C:\gjn2pjlw.exe
2008-03-26 20:54 . 2008-03-28 01:28 102,080 -r-hs---- C:\1weicxa.com
2008-03-24 21:57 . 2008-03-24 16:52 100,130 -r-hs---- C:\ino6.com
2008-03-23 16:33 . 2008-03-23 22:15 101,081 -r-hs---- C:\aub0wb8.cmd
2008-03-22 17:16 . 2008-03-22 17:15 100,883 -r-hs---- C:\cb.bat
2008-03-21 17:21 . 2008-03-22 10:32 101,608 -r-hs---- C:\h1dwg20.exe
2008-03-20 11:10 . 2008-03-21 12:45 100,031 -r-hs---- C:\n2de.cmd
2008-03-19 18:54 . 2008-03-20 00:46 100,754 -r-hs---- C:\un9.cmd
2008-03-18 17:04 . 2008-03-19 00:23 99,735 -r-hs---- C:\h6o0re.cmd
2008-03-16 12:16 . 2008-03-18 11:24 100,836 -r-hs---- C:\3o.exe
2008-03-14 17:07 . 2008-03-15 00:05 101,166 -r-hs---- C:\cfdflx.com
2008-03-14 09:15 . 2008-03-14 09:14 101,025 -r-hs---- C:\yo2mq6.exe
2008-03-11 23:59 . 2008-03-12 21:35 100,791 -r-hs---- C:\v.cmd
2008-03-07 23:28 . 2008-03-05 19:25 103,516 -r-hs---- C:\b.com
2008-03-07 08:37 . 2008-03-07 08:38 20,160 --a------ C:\WINDOWS\system32\WinKey.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-07 21:03 32,419 --sh--r C:\WINDOWS\system32\avpo0.dll
2008-04-07 20:02 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-06 15:14 --------- d-----w C:\Documents and Settings\Krzychu\Dane aplikacji\SopCast
2008-04-01 21:46 70,656 --sh--r C:\WINDOWS\system32\amvo2.dll
2008-03-29 12:09 --------- d-----w C:\Program Files\Norton SystemWorks
2008-03-27 14:20 --------- d-----w C:\Documents and Settings\Krzychu\Dane aplikacji\GanymedeNet
2008-03-25 16:06 --------- d-----w C:\Documents and Settings\Krzychu\Dane aplikacji\AdobeUM
2008-03-10 00:15 --------- d-----w C:\Documents and Settings\Krzychu\Dane aplikacji\Azureus
2008-03-09 14:21 --------- d-----w C:\Program Files\Azureus
2008-03-07 17:05 106,068 --sh--r C:\xpbkh.com
2008-03-04 22:02 107,057 --sh--r C:\uisvkqr.exe
2008-03-04 08:36 108,450 --sh--r C:\y82td3td.com
2008-02-29 22:07 105,263 --sh--r C:\ekugb3.bat
2008-02-26 18:37 107,475 --sh--r C:\u2.cmd
2008-02-25 21:51 107,959 --sh--r C:\oufddh.exe
2008-02-24 12:14 --------- d-----w C:\Documents and Settings\Ania\Dane aplikacji\AdobeUM
2008-02-20 09:11 107,052 --sh--r C:\gumkrhf.bat
2008-02-19 06:38 105,441 --sh--r C:\8ng8w.com
2008-02-18 10:30 104,946 --sh--r C:\[u]0[/u]hct8ybw.bat
2008-02-17 01:23 103,461 --sh--r C:\d6fagcs8.cmd
2008-02-15 13:28 104,813 --sh--r C:\3wcxx91.cmd
2008-02-13 22:20 102,211 --sh--r C:\x.com
2008-02-11 17:57 --------- d-----w C:\Program Files\Unlocker
2008-02-07 15:15 --------- d-----w C:\Program Files\Ganymede
2008-02-06 07:18 103,673 --sh--r C:\188qsm.bat
2008-02-05 14:44 103,367 --sh--r C:\2ifetri.cmd
2008-02-02 08:05 103,574 --sh--r C:\h.cmd
2008-01-29 22:26 103,683 --sh--r C:\ylr.exe
2008-01-28 13:30 121,336 ----a-w C:\Documents and Settings\Krzychu\Dane aplikacji\GDIPFONTCACHEV1.DAT
2008-01-28 13:08 105,293 --sh--r C:\xo8wr9.exe
2008-01-25 11:04 104,822 --sh--r C:\qd.cmd
2008-01-24 13:36 106,936 --sh--r C:\awda2.exe
2008-01-23 14:47 105,199 --sh--r C:\xn1i9x.com
2008-01-17 21:58 105,525 --sh--r C:\m1t8ta.com
2008-01-16 21:23 104,863 --sh--r C:\juok3st.bat
2008-01-15 06:28 105,698 --sh--r C:\d.com
2008-01-09 21:10 104,392 --sh--r C:\tio8x6.cmd
2008-01-08 21:02 103,956 --sh--r C:\u.bat
2008-01-03 22:14 121,336 ----a-w C:\Documents and Settings\Tomek\Dane aplikacji\GDIPFONTCACHEV1.DAT
2007-01-07 22:07 122,312 ----a-w C:\Documents and Settings\Ania\Dane aplikacji\GDIPFONTCACHEV1.DAT
2006-03-05 14:08 49 ----a-w C:\Program Files\Nowy Dokument tekstowy.txt
2005-08-03 11:17 284 ----a-w C:\Documents and Settings\Krzychu\Dane aplikacji\ViewerApp.dat
2002-11-19 15:01 28,672 ----a-w C:\Program Files\opera\program\plugins\PlugDef.dll
2005-05-17 17:25 56 --sh--r C:\WINDOWS\system32\75CD28371C.sys
2007-12-01 18:00 98,620 --sh--r C:\WINDOWS\system32\avpo.exe
2005-05-17 17:37 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
------- Sigcheck -------
2004-08-04 00:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-08 18:43 1953792]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-23 23:38 68856]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2004-12-28 19:02 770048]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-29 00:00 13312]
"avpa"="C:\WINDOWS\System32\avpo.exe" [2007-12-01 20:00 98620]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-29 17:50 4620288]
"nwiz"="nwiz.exe" [2004-10-29 17:50 921600 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-10-29 17:50 86016]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 21:51 131072]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-03-30 16:50 58992]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-05-07 22:23 100056]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 15:49 49152]
"pdfFactory Dispatcher v2"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [2005-01-19 15:00 471040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-09-29 00:00 13312]
"Symantec NetDriver Warning"="C:\PROGRA~1\SYMNET~1\SNDWarn.exe" [2004-10-29 08:52 218232]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-08-03 17:40 67264]
"Norton SystemWorks"="C:\Program Files\Norton SystemWorks\cfgwiz.exe" [2004-09-24 11:31 132208]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-24 06:37:56 217194]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 19:28:24 258048]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 11:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
R0 xmasbus;xmasbus;C:\WINDOWS\System32\DRIVERS\xmasbus.sys [2003-12-21 18:24]
R0 xmasscsi;xmasscsi;C:\WINDOWS\System32\Drivers\xmasscsi.sys [2003-12-23 03:15]
R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 17:40]
S0 ElbyVCD;ElbyVCD;C:\WINDOWS\System32\DRIVERS\ElbyVCD.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-04-07 10:00:00 C:\WINDOWS\Tasks\Funkcja One Button Checkup pakietu Norton SystemWorks.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2008-04-07 18:00:00 C:\WINDOWS\Tasks\HPpromotions journeysoftware.job"
- C:\Program Files\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe
"2008-04-04 18:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Skanuj komputer - Krzychu.job"
- C:\PROGRA~1\NORTON~1\NORTON~3\Navw32.exef/task:
"2008-04-06 22:00:01 C:\WINDOWS\Tasks\Symantec Drmc.job"
- C:\Program Files\Common Files\Symantec Shared\SymDrmc.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-07 23:20:49
Windows 5.1.2600 Dodatek Service Pack. 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Gadu-Gadu\ggwhook.dll
.
Completion time: 2008-04-07 23:24:46
ComboFix-quarantined-files.txt 2008-04-07 21:24:41
ComboFix2.txt 2008-04-04 12:11:24
Pre-Run: 369,664,000 bajtów wolnych
Post-Run: 357,138,432 bajtów wolnych
.
2007-12-21 13:32:54 --- E O F ---