
HiJackThis:
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 02:42:47, on 2012-11-20
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
D:\WINDOWS\system32\RUNDLL32.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\REALTEK Semiconductor Corp\REALTEK RTL8180 Wireless LAN Driver and Utility\RtlWake.exe
D:\Program Files\K2T\WTW\wtw.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\FIFA 13\Game\fifa13.exe
D:\WINDOWS\system32\taskmgr.exe
D:\Program Files\Opera\opera.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [XboxStat] "d:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: WTW.lnk = D:\Program Files\K2T\WTW\wtw.exe
O4 - Global Startup: RtlWake.lnk = ?
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://D:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Wyślij &do programu OneNote - res://D:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - D:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - D:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Moduł wstępnego ładowania interfejsu Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Demon buforu kategorii składników - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.21\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.5.20\bin\mysqld.exe
--
End of file - 5092 bytes
Combofix:
- Kod: Zaznacz wszystko
ComboFix 12-11-19.03 - Mik 2012-11-20 2:52.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3327.2215 [GMT 1:00]
Uruchomiony z: d:\documents and settings\Mik\Ustawienia lokalne\Dane aplikacji\Opera\Opera\temporary_downloads\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
.
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
d:\documents and settings\All Users\Dane aplikacji\AMMYY
d:\documents and settings\All Users\Dane aplikacji\AMMYY\hr
d:\documents and settings\All Users\Dane aplikacji\AMMYY\settings.bin
d:\documents and settings\All Users\Dane aplikacji\hpe66D.dll
d:\documents and settings\All Users\Dane aplikacji\TEMP
d:\documents and settings\Mik\KMPlayer_EN_3.3.0.33(dobreprogramy.pl).exe
d:\windows\system32\tmp76C.tmp
d:\windows\system32\tmp76D.tmp
.
.
((((((((((((((((((((((((( Pliki utworzone od 2012-10-20 do 2012-11-20 )))))))))))))))))))))))))))))))
.
.
2012-11-20 01:42 . 2012-11-20 01:42 388096 ----a-r- d:\documents and settings\Mik\Dane aplikacji\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-11-20 01:42 . 2012-11-20 01:42 -------- d-----w- d:\program files\Trend Micro
2012-11-12 22:29 . 2012-11-12 22:29 -------- d-----w- d:\program files\RaymanForever
2012-11-08 21:07 . 2012-11-08 21:07 -------- d-----w- d:\documents and settings\Mik\Ustawienia lokalne\Dane aplikacji\DOSBox
2012-11-06 13:12 . 2012-11-06 13:12 -------- d-----w- d:\windows\system32\config\systemprofile\Oracle
2012-11-05 13:30 . 2012-11-05 13:30 -------- d-----w- d:\documents and settings\Mik\Dane aplikacji\Subversion
2012-11-05 13:30 . 2012-11-05 13:30 -------- d-----w- d:\documents and settings\Mik\Dane aplikacji\SQL Developer
2012-11-05 13:23 . 2012-11-05 13:23 -------- d-----w- d:\documents and settings\Mik\Oracle
2012-11-05 13:22 . 2012-11-05 13:22 -------- d-----w- D:\oraclexe
2012-11-05 10:40 . 2012-11-05 10:40 -------- d-----w- d:\program files\EA GAMES
2012-10-25 18:04 . 2012-10-25 18:04 -------- d---a-w- d:\documents and settings\Mik\Ustawienia lokalne\Dane aplikacji\Rockstar Games
2012-10-25 17:02 . 2012-10-25 17:02 -------- d-----w- d:\windows\system32\xlive
2012-10-25 17:02 . 2012-10-25 17:02 -------- d-----w- d:\program files\Microsoft Games for Windows - LIVE
2012-10-25 16:43 . 2012-10-25 16:43 -------- d-----w- d:\windows\system32\XPSViewer
2012-10-25 16:43 . 2012-10-25 16:43 -------- d-----w- d:\program files\Reference Assemblies
2012-10-25 16:43 . 2006-10-14 14:43 27648 ----a-w- d:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2012-10-25 16:43 . 2006-06-29 11:07 14048 ------w- d:\windows\system32\spmsg2.dll
2012-10-25 16:42 . 2012-10-25 16:48 -------- d-----w- d:\program files\Rockstar Games
2012-10-23 21:40 . 2012-10-23 21:40 -------- d-----w- d:\program files\Fifa Master
.
.
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-20 00:23 . 2012-07-30 23:56 151552 ----a-w- d:\windows\KMSEmulator.exe
2012-10-25 22:34 . 2012-07-30 19:21 73656 ----a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-25 22:34 . 2012-07-30 19:21 696760 ----a-w- d:\windows\system32\FlashPlayerApp.exe
2012-10-25 17:04 . 2012-09-03 22:44 107888 ----a-w- d:\windows\system32\CmdLineExt.dll
2012-10-16 21:10 . 2012-10-16 21:10 22 --sha-w- d:\documents and settings\Mik\Dane aplikacji\Windows1569_SettingsRepository.bin
2012-09-29 17:54 . 2012-09-28 14:04 22856 ----a-w- d:\windows\system32\drivers\mbam.sys
2012-09-23 14:28 . 2012-10-15 22:05 888168 ----a-w- d:\windows\system32\nvdispgenco32.dll
2012-09-23 14:28 . 2012-10-15 22:05 5947392 ----a-w- d:\windows\system32\nvopencl.dll
2012-09-07 05:10 . 2012-09-07 05:10 93672 ----a-w- d:\windows\system32\WindowsAccessBridge.dll
2012-09-07 05:10 . 2012-09-07 05:10 143872 ----a-w- d:\windows\system32\javacpl.cpl
2012-09-07 05:10 . 2012-08-08 16:58 821736 ----a-w- d:\windows\system32\npDeployJava1.dll
2012-09-07 05:10 . 2012-08-08 16:58 746984 ----a-w- d:\windows\system32\deployJava1.dll
2012-10-11 01:05 . 2012-10-11 19:10 261600 ----a-w- d:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- d:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"avast"="d:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
"XboxStat"="d:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 718688]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
.
d:\documents and settings\Mik\Menu Start\Programy\Autostart\
WTW.lnk - d:\program files\K2T\WTW\wtw.exe [2012-7-30 2129408]
.
d:\documents and settings\All Users\Menu Start\Programy\Autostart\
RtlWake.lnk - d:\program files\REALTEK Semiconductor Corp.\REALTEK RTL8180 Wireless LAN Driver and Utility\RtlWake.exe [2012-9-12 720896]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\D:^Documents and Settings^Mik^Menu Start^Programy^Autostart^Treston.lnk]
path=d:\documents and settings\Mik\Menu Start\Programy\Autostart\Treston.lnk
backup=d:\windows\pss\Treston.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-02 08:07 843712 ----a-r- d:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-03-27 12:41 37296 ----a-w- d:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2012-04-04 04:09 446392 ------w- d:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
2012-03-09 14:26 1073312 ----a-w- d:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- d:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-15 12:00 15360 ----a-w- d:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2012-04-17 15:19 3671872 ----a-w- d:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-08-12 22:51 116648 ----atw- d:\documents and settings\Mik\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2012-05-15 09:40 15504192 ----a-w- d:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2012-05-15 09:40 108352 ----a-w- d:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2012-05-15 10:18 1634112 ----a-w- d:\program files\NVIDIA Corporation\nview\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]
2010-12-20 22:59 718720 ----a-w- d:\program files\Microsoft Office\Office14\MSOSYNC.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC]
2008-11-14 12:35 305064 ----a-r- d:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 11:33 17418928 ----a-r- d:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 07:04 252848 ----a-w- d:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 11:37 517096 ----a-w- d:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"TunngleService"=3 (0x3)
"SkypeUpdate"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"OMSI download service"=2 (0x2)
"MozillaMaintenance"=3 (0x3)
"Microsoft SharePoint Workspace Audit Service"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Opera\\opera.exe"=
"d:\\Program Files\\K2T\\WTW\\wtw.exe"=
"d:\\Program Files\\FIFA 12\\Game\\fifa.exe"=
"d:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"d:\\Program Files\\SopCast\\SopCast.exe"=
"d:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\Soldat\\Soldat.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Documents and Settings\\Mik\\Pulpit\\ghost recon\\GhostRecon.exe"=
"d:\\Program Files\\Tunngle\\TnglCtrl.exe"=
"d:\\Program Files\\Tunngle\\Tunngle.exe"=
"c:\\wamp\\bin\\apache\\Apache2.2.21\\bin\\httpd.exe"=
"d:\\Program Files\\Sony Ericsson\\Sony Ericsson PC Suite\\SEPCSuite.exe"=
"d:\\Program Files\\KONAMI\\Pro Evolution Soccer 2013\\pes2013.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Documents and Settings\\Mik\\Pulpit\\Q3Ademo\\quake3.exe"=
"d:\\Documents and Settings\\Mik\\Pulpit\\Folder\\uTorrent 3 Portable\\uTorrent.exe"=
"d:\\Program Files\\FIFA 13\\Game\\fifa13.exe"=
"d:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"d:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"d:\\Program Files\\RaymanForever\\Rayman\\RAYMAN.EXE"=
.
R0 PCTCore;PCTools KDS;d:\windows\system32\drivers\PCTCore.sys [2012-09-28 207792]
R1 aswSnx;aswSnx;d:\windows\system32\drivers\aswSnx.sys [2012-07-30 729752]
R1 aswSP;aswSP;d:\windows\system32\drivers\aswSP.sys [2012-07-30 355632]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;d:\windows\system32\drivers\dtsoftbus01.sys [2012-07-30 242240]
R1 VBoxDrv;VirtualBox Service;d:\windows\system32\drivers\VBoxDrv.sys [2012-08-02 158552]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;d:\windows\system32\drivers\VBoxUSBMon.sys [2012-08-02 91992]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [2012-07-30 21256]
R2 EAPPkt;Realtek EAPPkt Protocol;d:\windows\system32\drivers\EAPPkt.sys [2012-09-12 8576]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;d:\windows\system32\drivers\VBoxNetFlt.sys [2012-06-05 116056]
S3 rtl8180;Realtek RTL8180 Wireless LAN (Mini-)PCI NIC NT Driver;d:\windows\system32\drivers\RTL8180.sys [2008-12-01 183680]
S3 SwitchBoard;SwitchBoard;d:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);d:\windows\system32\drivers\tap0901t.sys [2012-08-28 27136]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;d:\windows\system32\drivers\VBoxNetAdp.sys [2012-06-05 104792]
S4 OMSI download service;Sony Ericsson OMSI download service;d:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2012-09-14 90112]
S4 sdAuxService;PC Tools Auxiliary Service;d:\program files\Spyware Doctor\pctsAuxs.exe [2012-09-28 359624]
S4 SkypeUpdate;Skype Updater;d:\program files\Skype\Updater\Updater.exe [2012-07-13 160944]
S4 TunngleService;TunngleService;d:\program files\Tunngle\TnglCtrl.exe [2012-08-28 738152]
.
Zawartość folderu 'Zaplanowane zadania'
.
2012-11-20 d:\windows\Tasks\AutoKMS.job
- d:\windows\AutoKMS\AutoKMS.exe [2012-07-30 23:56]
.
2012-11-20 d:\windows\Tasks\avast! Emergency Update.job
- d:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-30 09:12]
.
2012-11-09 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-484061587-1801674531-1003Core.job
- d:\documents and settings\Mik\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2012-08-12 22:51]
.
2012-11-20 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-484061587-1801674531-1003UA.job
- d:\documents and settings\Mik\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2012-08-12 22:51]
.
.
------- Skan uzupełniający -------
.
IE: E&ksportuj do programu Microsoft Excel - d:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Wyślij &do programu OneNote - d:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 8.8.8.8 188.122.20.62
FF - ProfilePath - d:\documents and settings\Mik\Dane aplikacji\Mozilla\Firefox\Profiles\k4172jyw.default\
FF - ExtSQL: 2012-10-11 21:12; {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}; d:\documents and settings\Mik\Dane aplikacji\Mozilla\Firefox\Profiles\k4172jyw.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi
.
- - - - USUNIĘTO PUSTE WPISY - - - -
.
MSConfigStartUp-Sony PC Companion - d:\program files\Sony\Sony PC Companion\PCCompanion.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-20 02:56
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
.
skanowanie ukrytych procesów ...
.
skanowanie ukrytych wpisów autostartu ...
.
skanowanie ukrytych plików ...
.
skanowanie pomyślnie ukończone
ukryte pliki: 0
.
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
Czas ukończenia: 2012-11-20 02:57:30
ComboFix-quarantined-files.txt 2012-11-20 01:57
.
Przed: 34 588 049 408 bajtów wolnych
Po: 34 522 718 208 bajtów wolnych
.
- - End Of File - - F453D065DEDE52335CC72EB6590CD59D