
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:22:29, on 2007-11-30
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\tlntsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\WapSter\AQQ\AQQ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\BarolNexusMovement\Pulpit\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/pl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [AQQ] C:\PROGRA~1\WapSter\AQQ\AQQ.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{CCD28044-5092-4260-89FC-53E524F7FFF8}: NameServer = 83.238.255.76 213.241.79.37
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 3237 bytes
Witam,Proszę o sprawdzenie loga, ponieważ komputer strasznie mi muli i net często chodzi wolno(jak ma dobre dni to chodzi normalnie).Programy same się często wyłączają(Nfs underground 2,gry,mozilla...)Można skasować "coś" dla polepszenia wydajności?
Z góry dzięki
[ Dodano: Dzisiaj o 20:44 ]
- Kod: Zaznacz wszystko
ComboFix 07-11-19.4C - BarolNexusMovement 2007-11-30 20:35:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.119 [GMT 1:00]
Running from: C:\Documents and Settings\BarolNexusMovement\Pulpit\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-30 )))))))))))))))))))))))))))))))
.
2007-11-28 18:15 <DIR> d-------- C:\Program Files\Common Files\DirectX
2007-11-28 18:14 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\nView_Profiles
2007-11-28 18:09 286,720 --a------ C:\WINDOWS\system32\nvwrsesm.dll
2007-11-28 18:09 167,936 --a------ C:\WINDOWS\system32\nvrsfi.dll
2007-11-28 18:08 <DIR> d-------- C:\WINDOWS\nview
2007-11-28 18:08 843,776 --a------ C:\WINDOWS\system32\nwiz.exe
2007-11-28 18:08 454,656 --a------ C:\WINDOWS\system32\nvshell.dll
2007-11-28 18:08 438,272 --a------ C:\WINDOWS\system32\nvappbar.exe
2007-11-28 18:06 114,755 --a------ C:\WINDOWS\system32\nvsvc32.exe
2007-11-28 10:54 <DIR> d-------- C:\Program Files\AC3Filter
2007-11-19 13:36 <DIR> d-------- C:\Program Files\D-Tools
2007-11-19 13:36 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2007-11-19 13:36 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2007-11-15 20:34 <DIR> d-------- C:\Program Files\Opera
2007-11-15 20:31 <DIR> d-------- C:\Program Files\FireTune
2007-11-15 20:31 737,280 --a------ C:\WINDOWS\iun6002.exe
2007-11-10 10:20 <DIR> d-------- C:\Documents and Settings\bass\Dane aplikacji\Winamp
2007-11-10 10:17 <DIR> d-------- C:\Documents and Settings\bass\Dane aplikacji\DivX
2007-11-10 10:16 <DIR> d--h----- C:\Documents and Settings\bass\Ustawienia lokalne
2007-11-10 10:16 <DIR> dr------- C:\Documents and Settings\bass\Ulubione
2007-11-10 10:16 <DIR> d--h----- C:\Documents and Settings\bass\Szablony
2007-11-10 10:16 <DIR> d-------- C:\Documents and Settings\bass\Pulpit
2007-11-10 10:16 <DIR> dr------- C:\Documents and Settings\bass\Moje dokumenty
2007-11-10 10:16 <DIR> dr------- C:\Documents and Settings\bass\Menu Start
2007-11-10 10:16 <DIR> dr-h----- C:\Documents and Settings\bass\Dane aplikacji
2007-11-08 00:27 <DIR> d-------- C:\Documents and Settings\BarolNexusMovement\Dane aplikacji\GanymedeNet
2007-11-08 00:27 4 --a------ C:\WINDOWS\system32\proc-220146841.bin
2007-11-01 09:52 <DIR> d-------- C:\Documents and Settings\BarolNexusMovement\Dane aplikacji\Winamp
2007-10-27 19:58 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2007-10-25 15:28 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Sony
2007-10-25 15:27 <DIR> d-------- C:\Program Files\Vstplugins
2007-10-24 14:02 <DIR> d-------- C:\Program Files\IKEA HomePlanner
2007-10-24 14:01 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-24 08:58 <DIR> d-------- C:\Program Files\BearShare Applications
2007-10-24 08:58 <DIR> d-------- C:\Documents and Settings\BarolNexusMovement\Dane aplikacji\BearShare
2007-10-19 08:05 <DIR> d-------- C:\Program Files\Walaber's Trampoline
2007-10-05 14:02 <DIR> d-------- C:\Documents and Settings\BarolNexusMovement\Dane aplikacji\Media Player Classic
2007-10-05 13:48 <DIR> d-------- C:\Program Files\SpeedFan
2007-10-05 13:25 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2007-10-05 13:24 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-01 08:53 --------- d-----w C:\Program Files\Winamp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AQQ"="C:\PROGRA~1\WapSter\AQQ\AQQ.exe" [2007-02-28 13:18]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-03 23:44]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2005-01-05 14:24]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-08-06 08:45]
"MMTray"="MMTray.exe" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 14:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 19:24]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2004-07-01 15:12 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-30 20:37:49
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-30 20:39:02
.
--- E O F ---