
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:43:28, on 2009-05-22
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\PROGRA~1\WapSter\AQQ\AQQ.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\AVerTV2K\QuickTV.exe
C:\Documents and Settings\PIKUS\Menu Start\Programy\Autostart\Satellite TV for PC Channel Updater.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wp.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [AQQ] C:\PROGRA~1\WapSter\AQQ\AQQ.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [FreeCall] "C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe" -nosplash -minimized
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Satellite TV for PC Channel Updater.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: QuickTV.lnk = C:\Program Files\AVerTV2K\QuickTV.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 6789 bytes
A to z ComboFixa
- Kod: Zaznacz wszystko
ComboFix 09-05-21.03 - PIKUS 2009-05-22 18:26.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.383.194 [GMT 2:00]
Uruchomiony z: c:\documents and settings\PIKUS\Pulpit\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090521-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
.
((((((((((((((((((((((((( Pliki utworzone od 2009-04-22 do 2009-05-22 )))))))))))))))))))))))))))))))
.
2009-05-13 12:26 . 2009-05-17 10:30 -------- d-----w c:\documents and settings\PIKUS\Dane aplikacji\FreeCall
2009-05-13 12:24 . 2009-05-13 12:24 -------- d-----w c:\program files\FreeCall.com
2009-05-11 15:13 . 2009-05-11 15:13 57344 ----a-w c:\documents and settings\PIKUS\Dane aplikacji\Sun\Java\Deployment\cache\6.0\50\5b902232-38b8d48c-n\Decora-SSE.dll
2009-05-11 15:13 . 2009-05-11 15:13 24064 ----a-w c:\documents and settings\PIKUS\Dane aplikacji\Sun\Java\Deployment\cache\6.0\15\4e09eacf-72352ef6-n\Decora-D3D.dll
2009-05-11 15:13 . 2009-05-11 15:13 315392 ----a-w c:\documents and settings\PIKUS\Dane aplikacji\Sun\Java\Deployment\cache\6.0\62\6baea4fe-3abeb3c6-n\jogl.dll
2009-05-11 15:13 . 2009-05-11 15:13 20480 ----a-w c:\documents and settings\PIKUS\Dane aplikacji\Sun\Java\Deployment\cache\6.0\62\6baea4fe-3abeb3c6-n\jogl_awt.dll
2009-05-11 15:13 . 2009-05-11 15:13 114688 ----a-w c:\documents and settings\PIKUS\Dane aplikacji\Sun\Java\Deployment\cache\6.0\62\6baea4fe-3abeb3c6-n\jogl_cg.dll
2009-05-11 15:13 . 2009-05-11 15:13 20480 ----a-w c:\documents and settings\PIKUS\Dane aplikacji\Sun\Java\Deployment\cache\6.0\45\4f710eed-63ff676e-n\gluegen-rt.dll
2009-05-11 15:13 . 2009-05-11 15:13 348160 ----a-w c:\documents and settings\PIKUS\Dane aplikacji\Sun\Java\Deployment\cache\6.0\33\258cea61-6ac85c8c-n\msvcr71.dll
2009-05-11 15:13 . 2009-05-11 15:13 499712 ----a-w c:\documents and settings\PIKUS\Dane aplikacji\Sun\Java\Deployment\cache\6.0\33\258cea61-6ac85c8c-n\msvcp71.dll
2009-05-11 15:13 . 2009-05-11 15:13 499712 ----a-w c:\documents and settings\PIKUS\Dane aplikacji\Sun\Java\Deployment\cache\6.0\33\258cea61-6ac85c8c-n\jmc.dll
2009-04-29 15:13 . 1999-12-17 08:13 86016 ----a-w c:\windows\unvise32.exe
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-22 16:28 . 2008-08-24 10:23 -------- d-----w c:\documents and settings\PIKUS\Dane aplikacji\Skype
2009-05-22 16:21 . 2009-01-31 14:55 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-05-22 16:03 . 2008-08-20 19:53 -------- d-----w c:\program files\Gadu-Gadu
2009-05-22 16:02 . 2009-01-31 14:55 -------- d-----w c:\program files\Norton Security Scan
2009-05-22 16:00 . 2008-08-24 10:24 -------- d-----w c:\documents and settings\PIKUS\Dane aplikacji\skypePM
2009-05-09 13:44 . 2008-08-20 18:20 -------- d-----w c:\program files\Winamp
2009-04-29 15:27 . 2009-02-23 12:12 22328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-04-29 15:27 . 2009-02-23 12:12 107832 ----a-w c:\windows\system32\PnkBstrB.exe
2009-04-03 19:30 . 2009-04-03 19:30 -------- d-----w c:\program files\TVAnts
2009-03-31 17:58 . 2008-08-20 19:36 -------- d-----w c:\program files\Java
2009-03-31 17:58 . 2001-10-26 16:15 49712 ----a-w c:\windows\system32\perfc015.dat
2009-03-31 17:58 . 2001-10-26 16:15 355830 ----a-w c:\windows\system32\perfh015.dat
2009-03-31 17:57 . 2009-03-31 17:57 152576 ----a-w c:\documents and settings\PIKUS\Dane aplikacji\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-22 14:16 . 2009-03-22 14:15 249856 ------w c:\windows\Setup1.exe
2009-03-22 14:16 . 2009-03-22 14:15 73216 ----a-w c:\windows\ST6UNST.EXE
2009-03-15 10:59 . 2009-03-15 10:59 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-03-15 10:56 . 2009-03-15 10:56 24 -csha-w c:\windows\S423A6FD7.tmp
2009-03-09 03:19 . 2008-12-06 20:19 410984 ----a-w c:\windows\system32\deploytk.dll
2009-02-23 12:12 . 2009-02-23 12:12 66872 ----a-w c:\windows\system32\PnkBstrA.exe
2008-09-13 16:12 . 2008-09-13 16:12 0 -c--a-w c:\program files\MultiTransefind.ini
2004-10-01 13:00 . 2008-08-20 19:40 40960 ----a-w c:\program files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-05-22_12.08.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-22 15:59 . 2009-05-22 15:59 16384 c:\windows\Temp\Perflib_Perfdata_4d8.dat
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"AQQ"="c:\progra~1\WapSter\AQQ\AQQ.exe" [2007-02-28 2351864]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-08-11 21858088]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-02 68856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"FreeCall"="c:\program files\FreeCall.com\FreeCall\FreeCall.exe" [2008-09-01 9109296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2006-06-21 35328]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\PIKUS\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Satellite TV for PC Channel Updater.exe [2008-12-16 33982]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
QuickTV.lnk - c:\program files\AVerTV2K\QuickTV.exe [2008-8-20 147456]
[HKLM\~\startupfolder\C:^Documents and Settings^PIKUS^Menu Start^Programy^Autostart^Satellite TV for PC Channel Updater.exe]
path=c:\documents and settings\PIKUS\Menu Start\Programy\Autostart\Satellite TV for PC Channel Updater.exe
backup=c:\windows\pss\Satellite TV for PC Channel Updater.exeStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WapSter\\AQQ\\AQQ.exe"=
"c:\\PROGRA~1\\WapSter\\AQQ\\AQQ.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"e:\\Program Files\\HLSW\\hlsw.exe"=
"e:\\Program Files\\Quake III Arena\\quake3.exe"=
"e:\\Fifa 2007\\RFG-Fi07\\playing_with_my_ball_fifa_style\\FIFA 07\\FIFA 07\\fifa07.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\PIKUS\\Pulpit\\gegra\\samp022server.win32\\samp-server.exe"=
"c:\\Documents and Settings\\PIKUS\\Pulpit\\RÓŻNE\\NTSD2\\NTSD2.4\\NTSD_test1.exe"=
"f:\\f1\\F1Challenge2007.exe"=
"e:\\Program Files\\Quake III Arena 1.32\\quake3.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"e:\\Program Files\\MOHAA\\MOHAA.EXE"=
"c:\\Program Files\\FreeCall.com\\FreeCall\\FreeCall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-08-20 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-08-20 20560]
R2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\BT848.sys [2008-03-06 261696]
R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [2008-03-06 22016]
R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;c:\windows\system32\drivers\btxbar.sys [2008-03-06 13312]
.
Zawartość folderu 'Zaplanowane zadania'
2008-11-20 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8219256216.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 22:52]
2009-05-22 c:\windows\Tasks\Norton Security Scan for PIKUS.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 17:04]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.wp.pl/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-22 18:28
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'explorer.exe'(208)
c:\program files\Gadu-Gadu\ggwhook.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
.
Czas ukończenia: 2009-05-22 18:30
ComboFix-quarantined-files.txt 2009-05-22 16:30
ComboFix2.txt 2009-05-22 12:09
ComboFix3.txt 2008-11-08 11:26
Przed: 1 868 693 504 bajtów wolnych
Po: 1 872 490 496 bajtów wolnych
147