
Hijack
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:41:28, on 2007-12-09
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\AcroRd32.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Ashampoo FireWall] "C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - e:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - e:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
--
End of file - 6484 bytes
combofix
- Kod: Zaznacz wszystko
ComboFix 07-12-09.1 - TT 2007-12-09 16:50:07.11 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.191 [GMT 1:00]
Running from: E:\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.
2007-12-07 14:12 . 2007-12-07 14:12 <DIR> d--hs---- C:\FOUND.078
2007-11-29 15:47 . 2007-11-29 15:47 <DIR> d-------- C:\WINDOWS\system32\Lang
2007-11-29 15:25 . 2006-11-08 09:51 62,336 --------- C:\WINDOWS\system32\drivers\rspndr.sys
2007-11-29 15:25 . 2006-11-08 09:51 10,752 --------- C:\WINDOWS\system32\rspndr.exe
2007-11-29 15:22 . 2007-11-29 15:22 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2007-11-29 15:22 . 2007-11-29 15:22 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2007-11-29 15:22 . 2007-11-29 15:22 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2007-11-29 15:22 . 2007-11-29 15:22 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2007-11-29 15:22 . 2007-11-29 15:22 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2007-11-29 15:22 . 2007-11-29 15:22 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2007-11-29 15:19 . 2006-09-13 18:18 153,088 --a------ C:\WINDOWS\system32\irftp.exe
2007-11-29 15:19 . 2006-09-13 18:18 87,424 --a------ C:\WINDOWS\system32\drivers\irda.sys
2007-11-29 15:19 . 2006-09-13 18:19 27,648 --a------ C:\WINDOWS\system32\irmon.dll
2007-11-29 15:19 . 2006-09-13 18:18 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2007-11-29 15:15 . 2006-09-13 18:17 19,584 --a------ C:\WINDOWS\system32\drivers\rasirda.sys
2007-11-29 15:14 . 2001-10-26 19:29 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-11-29 15:14 . 2001-10-26 19:29 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-11-29 14:37 . 2007-11-29 14:37 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-11-27 19:40 . 2007-11-27 19:40 <DIR> d-------- C:\Program Files\Ontrack
2007-11-26 13:55 . 2007-11-26 13:55 <DIR> d-------- C:\WINDOWS\system32\Sunlight
2007-11-26 13:55 . 2004-05-19 14:56 21,632 --a------ C:\WINDOWS\system32\drivers\HidJFilter.sys
2007-11-26 13:55 . 2003-11-29 23:01 11,008 --a------ C:\WINDOWS\system32\drivers\SKBusEnum.sys
2007-11-26 13:55 . 2003-11-27 19:48 3,968 --a------ C:\WINDOWS\system32\drivers\VirtualK.sys
2007-11-26 13:55 . 2003-11-27 20:14 3,840 --a------ C:\WINDOWS\system32\drivers\VirtualM.sys
2007-11-26 13:52 . 2007-11-26 13:52 <DIR> d-------- C:\Program Files\USB all-in-one game controller
2007-11-26 13:28 . 2007-11-26 13:28 <DIR> d--hs---- C:\FOUND.077
2007-11-26 12:27 . 2007-11-26 12:30 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-11-26 12:22 . 2006-09-13 18:18 130,048 --a------ C:\WINDOWS\system32\ksproxy.ax
2007-11-26 12:22 . 2006-09-13 18:18 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-11-26 12:19 . 2007-11-26 12:19 0 --a------ C:\WINDOWS\[INI]
2007-11-25 00:03 . 2007-11-25 00:03 23,552 --a------ C:\WINDOWS\system\dpmodemx.dll
2007-11-24 23:59 . 2001-10-30 08:10 333,824 --a------ C:\WINDOWS\system\DDRAW.DLL
2007-11-24 23:57 . 2007-11-24 23:56 62,464 --a------ C:\WINDOWS\system\dpnmodem.dll
2007-11-24 23:57 . 2007-11-24 23:56 61,952 --a------ C:\WINDOWS\system\dpnwsock.dll
2007-11-24 23:57 . 2007-11-24 23:54 57,344 --a------ C:\WINDOWS\system\dpwsockx.dll
2007-11-24 23:57 . 2007-11-24 23:54 27,136 --a------ C:\WINDOWS\system\ddrawex.dll
2007-11-24 22:43 . 1999-05-05 22:22 471,040 --a------ C:\WINDOWS\system\KERNEL32.DLL
2007-11-24 22:40 . 2001-10-30 08:10 455,680 --a------ C:\WINDOWS\system\DSOUND.DLL
2007-11-24 21:59 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\[u]0[/u]00001_.tmp
2007-11-24 20:34 . 2007-11-24 20:34 <DIR> d-------- C:\WINDOWS\uninstall\DirectX Buster
2007-11-24 20:34 . 2007-11-24 20:34 <DIR> d-------- C:\Program Files\DirectX Buster
2007-11-24 20:12 . 2007-11-24 20:12 <DIR> d-------- C:\Program Files\DirectX Happy Uninstall
2007-11-24 20:02 . 2007-11-24 20:02 0 --a------ C:\WINDOWS\dxinfo.INI
2007-11-24 19:58 . 2007-11-24 19:58 <DIR> d-------- C:\Program Files\directx
2007-11-24 18:50 . 2007-10-04 18:16 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-11-24 18:05 . 2007-11-24 18:05 <DIR> d-------- C:\WINDOWS\uninstall
2007-11-19 14:33 . 2007-11-29 15:23 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2007-11-19 14:33 . 2007-11-29 15:23 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2007-11-19 14:08 . 2007-11-19 14:08 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-11-19 14:06 . 2007-11-19 14:06 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-11-16 20:09 . 2007-11-16 20:09 <DIR> d-------- C:\Program Files\Tlen.pl
2007-11-16 20:09 . 2007-11-16 20:09 <DIR> d-------- C:\Documents and Settings\TT\Dane aplikacji\Tlen.pl
2007-11-15 16:38 . 2007-11-15 16:38 <DIR> d--hs---- C:\FOUND.076
2007-11-14 23:47 . 2007-11-14 23:47 <DIR> d--hs---- C:\FOUND.075
2007-11-14 14:52 . 2007-11-14 14:52 <DIR> d--hs---- C:\FOUND.074
2007-11-12 15:00 . 2007-11-12 15:00 <DIR> d--hs---- C:\FOUND.073
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-06 11:59 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-06 11:58 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-12-06 11:29 12,464 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-11-06 18:59 --------- d-----w C:\Program Files\FDRLab
2007-10-25 17:47 --------- d-----w C:\Program Files\Trend Micro
2007-10-25 13:49 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2007-10-24 19:16 --------- d-----w C:\Program Files\Lavasoft
2007-10-24 19:16 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2007-10-14 22:54 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-10-09 19:38 --------- d-----w C:\Program Files\WinHarp95
2007-10-04 17:16 356,352 ----a-w C:\WINDOWS\system32\nvudisp.exe
2007-10-04 16:14 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-10-04 16:14 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-10-04 16:14 8,491,008 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-10-04 16:14 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-10-04 16:14 6,750,208 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-10-04 16:14 6,344,704 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-10-04 16:14 5,783,424 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-10-04 16:14 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-10-04 16:14 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-10-04 16:14 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-10-04 16:14 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-10-04 16:14 364,544 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-10-04 16:14 36,864 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-10-04 16:14 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-10-04 16:14 3,551,232 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-10-04 16:14 3,334,144 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-10-04 16:14 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-10-04 16:14 2,371,584 ----a-w C:\WINDOWS\system32\nvwss.dll
2007-10-04 16:14 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-10-04 16:14 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2007-10-04 16:14 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2007-10-04 16:14 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-10-04 16:14 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe
2007-10-04 16:14 1,478,656 ----a-w C:\WINDOWS\system32\nview.dll
2007-10-04 16:14 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe
2007-10-04 16:14 1,150,976 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-10-04 16:14 1,019,904 ----a-w C:\WINDOWS\system32\nvwimg.dll
2007-09-21 23:46 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2006-11-18 19:56 492,896 ----a-w C:\Documents and Settings\TT\Install.exe
2006-01-31 13:48 14,976 ----a-w C:\Documents and Settings\TT\Device.dat
2005-08-18 18:48 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2005-08-18 18:48 56 --sh--r C:\WINDOWS\system32\7A835BE76D.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
"Ashampoo FireWall"="C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe" [2007-04-05 14:57]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:44]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-04 00:33]
"nltide_3"="advpack.dll" [2004-08-03 23:43 C:\WINDOWS\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^TT^Menu Start^Programy^Autostart^UniSpiker-2.6.lnk]
path=C:\Documents and Settings\TT\Menu Start\Programy\Autostart\UniSpiker-2.6.lnk
backup=C:\WINDOWS\pss\UniSpiker-2.6.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ashampoo FireWall]
C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe -TRAY
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-03 23:44 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator]
2007-11-07 15:33 6234624 --a------ C:\Program Files\Tlen.pl\tlen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 11:50 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVRaidService]
2004-06-11 05:15 83968 -ra------ C:\WINDOWS\system32\nvraidservice.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 20:24 32768 --a------ C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
D:\Programy\Skype\Phone\Skype.exe /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
d:\gry\steam\steam.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2005-03-04 03:36 36975 --a------ C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
R0 VirtualK;VirtaulK;C:\WINDOWS\system32\drivers\VirtualK.sys
R0 VirtualM;VirtaulM;C:\WINDOWS\system32\drivers\VirtualM.sys
S3 skbusenum;SKBus Enumerator;C:\WINDOWS\system32\DRIVERS\skbusenum.sys
S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2649]
-> C:\Program Files\Gadu-Gadu\ggwhook.dll
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-09 16:51:24
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-09 16:51:51
C:\ComboFix2.txt ... 2007-11-15 20:44
C:\ComboFix3.txt ... 2007-11-15 16:56
.
--- E O F ---