Deckard's System Scanner v20070603.47
Run by Kajtek on 2007-06-04 at 22:32:04
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2007-06-04 20:32:09 UTC - RP1 - Punkt kontrolny systemu
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Kajtek.exe) ----------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 22:32:35, on 2007-06-04
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\Explorer.EXE
D:\WINNT\system32\spoolsv.exe
D:\WINNT\system32\RUNDLL32.EXE
D:\WINNT\system32\CTHELPER.EXE
D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
D:\WINNT\system32\ctfmon.exe
C:\Program Files\RivChat2\RivChat.exe
D:\WINNT\system32\nvsvc32.exe
D:\WINNT\System32\PAStiSvc.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\wscntfy.exe
D:\WINNT\system32\wuauclt.exe
C:\Program Files\INTERIAPL\Stefan\Stefan.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Documents and Settings\Kajtek\Pulpit\dss.exe
D:\DOCUME~1\Kajtek\Pulpit\HIJACK~1\Kajtek.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://miasto.interia.pl/pa.html?srv=java_download.w.interia.pl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - D:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - D:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] D:\WINNT\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "D:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [RivChat] C:\Program Files\RivChat2\RivChat.exe
O4 - HKCU\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1177883632031
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: STI Simulator - Unknown owner - D:\WINNT\System32\PAStiSvc.exe
-- HijackThis Fixed Entries (D:\DOCUME~1\Kajtek\Pulpit\HIJACK~1\backups\) ------
backup-20070604-180332-802 O23 - Service: Microsoft Internet Explorer - Unknown owner - D:\WINNT\iexplore.exe
backup-20070604-180721-361 O23 - Service: MySQL - Unknown owner - C:\AppServ\mysql\bin\mysqld-nt.exe (file missing)
backup-20070604-180721-444 O23 - Service: Apache - Unknown owner - C:\AppServ\Apache\Apache.exe" --ntservice (file missing)
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 PAC207 (SoC PC-Camer@) - d:\winnt\system32\drivers\pfc027.sys
S3 AME (PC Camera(6029 CIF)) - d:\winnt\system32\drivers\pfc027.sys
S3 hamachi (Hamachi Network Interface) - d:\winnt\system32\drivers\hamachi.sys <Not Verified; Applied Networking Inc.; Hamachi Virtual Network Interface Driver>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 STI Simulator - d:\winnt\system32\pastisvc.exe
S4 Apache - "c:\appserv\apache\apache.exe" --ntservice (file missing)
S4 Microsoft Internet Explorer - "d:\winnt\iexplore.exe"
S4 MySQL - c:\appserv\mysql\bin\mysqld-nt.exe mysql (file missing)
-- Files created between 2007-05-04 and 2007-06-04 -----------------------------
2007-06-30 12:52:30 0 d--h----- D:\Program Files\Common Files\delsim
2007-06-30 12:32:48 505344 -r-hs---- D:\WINNT\iexplore.exe
2007-06-29 12:39:47 192569 --a------ D:\WINNT\system32\msrpjt40.dll <Not Verified; Microsoft Corporation; Microsoft (R) Jet>
2007-06-29 12:39:01 97552 --a------ D:\WINNT\system32\rdocurs.dll <Not Verified; Microsoft Corporation; Microsoft RDO Client Cursor Library>
2007-06-29 12:39:01 376592 --a------ D:\WINNT\system32\msrdo20.dll <Not Verified; Microsoft Corporation; Microsoft Corporation Remote Data Object>
2007-06-29 12:39:00 32830 --a------ D:\WINNT\system32\dbmsshrn.dll <Not Verified; Microsoft Corporation; Microsoft SQL Server>
2007-06-29 12:38:35 0 d-------- D:\Program Files\Microsoft SQL Server
2007-06-29 12:31:39 306688 --a------ D:\WINNT\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2007-06-04 18:10:41 0 d-------- D:\WINNT\LastGood
2007-06-04 18:01:36 0 d--hs---- D:\WINNT\CSC
2007-05-24 17:26:51 0 d-------- D:\WINNT\system32\appmgmt
2007-05-21 18:11:46 0 d-------- D:\Program Files\Azureus
2007-05-21 02:56:14 0 d-------- D:\Program Files\uTorrent
2007-05-19 00:02:26 0 d-------- D:\Program Files\UnH Solutions
2007-05-15 21:51:59 10345 --a------ D:\WINNT\system32\drivers\hamachi.sys <Not Verified; Applied Networking Inc.; Hamachi Virtual Network Interface Driver>
2007-05-15 21:17:03 0 d-------- D:\Program Files\Alcohol Soft
2007-05-08 01:20:42 0 d-------- D:\Program Files\MegauploadToolbar
-- Find3M Report ---------------------------------------------------------------
2007-06-30 14:54:03 355486 --a------ D:\WINNT\system32\perfh015.dat
2007-06-30 14:54:03 49492 --a------ D:\WINNT\system32\perfc015.dat
2007-06-29 14:06:00 0 d-------- D:\Documents and Settings\Kajtek\Dane aplikacji\Hamachi
2007-06-29 11:31:20 0 d--h----- D:\Program Files\InstallShield Installation Information
2007-06-04 18:00:27 24 --a------ D:\WINNT\system32\DVCStateBkp-{00000000-00000000-0000000A-00001102-00000002-80651102}.dat
2007-06-04 18:00:27 24 --a------ D:\WINNT\system32\DVCState-{00000000-00000000-0000000A-00001102-00000002-80651102}.dat
2007-06-04 17:58:27 16896 --a------ D:\WINNT\system32\tftp.exe
2007-06-04 17:58:27 44544 --a------ D:\WINNT\system32\ftp.exe
2007-05-25 22:38:14 0 d-------- D:\Program Files\DC++
2007-05-23 00:20:14 0 d-------- D:\Documents and Settings\Kajtek\Dane aplikacji\Azureus
2007-05-21 18:05:11 0 d-------- D:\Documents and Settings\Kajtek\Dane aplikacji\uTorrent
2007-05-09 17:53:51 0 d-------- D:\Documents and Settings\Kajtek\Dane aplikacji\MegauploadToolbar
2007-04-30 06:32:44 0 d-------- D:\Program Files\PC Camer@
2007-04-30 06:32:44 0 d-------- D:\Program Files\Common Files\PCCamera
2007-04-30 03:56:20 4096 --a------ D:\WINNT\d3dx.dat
2007-04-30 03:51:31 0 d-------- D:\Program Files\DAEMON Tools
2007-04-30 01:48:38 0 d-------- D:\Program Files\XP Codec Pack
2007-04-29 18:18:01 0 d-------- D:\Program Files\MarBit
2007-04-29 17:10:09 0 d-------- D:\Program Files\Common Files\ODBC
2007-04-29 17:10:05 0 d-------- D:\Program Files\Common Files\SpeechEngines
2007-04-29 17:09:26 62 --ahs---- D:\Documents and Settings\Kajtek\Dane aplikacji\desktop.ini
2007-04-29 16:42:08 0 d-------- D:\Program Files\Winamp
2007-04-29 16:16:37 1156 --a------ D:\WINNT\mozver.dat
2007-04-29 16:05:08 0 d-------- D:\Program Files\Common Files\InstallShield
2007-04-29 15:57:24 0 d-------- D:\Program Files\INTERIAPL
2007-04-29 15:55:22 0 d-------- D:\Documents and Settings\Kajtek\Dane aplikacji\Sun
2007-04-29 15:55:03 0 d-------- D:\Program Files\Java
2007-04-29 15:53:19 0 d-------- D:\Program Files\Common Files\Java
2007-04-29 15:52:02 0 --a------ D:\WINNT\nsreg.dat
2007-04-29 15:51:58 0 d-------- D:\Documents and Settings\Kajtek\Dane aplikacji\Mozilla
2007-04-29 15:44:56 0 d-------- D:\Documents and Settings\Kajtek\Dane aplikacji\Macromedia
2007-04-29 15:43:16 0 d-------- D:\Documents and Settings\Kajtek\Dane aplikacji\INTERIAPL
2007-04-29 15:39:52 0 d-------- D:\Program Files\Creative
2007-04-29 15:26:17 0 d-------- D:\Documents and Settings\Kajtek\Dane aplikacji\Identities
2007-04-29 15:20:20 0 d--h----- D:\Program Files\WindowsUpdate
2007-04-29 15:20:15 0 d-------- D:\Program Files\Usługi online
2007-04-29 15:19:24 0 d-------- D:\Program Files\Common Files\MSSoap
2007-04-29 15:19:16 0 d-------- D:\Program Files\Movie Maker
2007-04-29 15:18:14 21856 --a------ D:\WINNT\system32\emptyregdb.dat
2007-04-29 15:17:33 0 d-------- D:\Program Files\Messenger
2007-04-29 15:17:28 0 d-------- D:\Program Files\MSN Gaming Zone
2007-04-29 15:17:16 0 d-------- D:\Program Files\Windows NT
2007-03-27 03:39:14 20480 --a------ D:\WINNT\system32\ac3config.exe
-- Registry Dump ---------------------------------------------------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} D:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE D:\\WINNT\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE D:\\WINNT\\system32\\NvMcTray.dll,NvTaskbarInit"
"WINDVDPatch"="CTHELPER.EXE"
"UpdReg"="D:\\WINNT\\UpdReg.EXE"
"Jet Detection"="\"D:\\Program Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\""
"SunJavaUpdateSched"="\"D:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="D:\\WINNT\\system32\\ctfmon.exe"
"RivChat"="C:\\Program Files\\RivChat2\\RivChat.exe"
"DAEMON Tools"="\"D:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nlsf"=hex(2):63,6d,64,2e,65,78,65,20,2f,43,20,6d,6f,76,65,20,2f,59,20,22,25,\
53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,32,5c,73,79,73,73,\
65,74,75,62,2e,64,6c,6c,22,20,22,25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,\
79,73,74,65,6d,33,32,5c,73,79,73,73,65,74,75,70,2e,64,6c,6c,22,00
"tscuninstall"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,6d,\
33,32,5c,74,73,63,75,70,67,72,64,2e,65,78,65,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="D:\\WINNT\\system32\\CTFMON.EXE"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
-- End of Deckard's System Scanner: finished at 2007-06-04 at 22:32:56 ---------
znow mi sie jakies paskudztwo wryło...