Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:48:31 AM, on 6/22/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1213902927390
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\VmGateway.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
--
End of file - 9827 bytes
ComboFix 08-06-20.4 - Niunias 2008-06-22 9:51:59.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.204 [GMT -5:00]
Running from: C:\Documents and Settings\Ania\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\setup.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-22 to 2008-06-22 )))))))))))))))))))))))))))))))
.
2008-06-22 09:47 . 2008-06-22 09:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-21 03:17 . 2008-06-21 03:17 <DIR> d-------- C:\Program Files\MSECache
2008-06-21 03:13 . 2008-06-21 03:13 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-06-21 03:13 . 2008-06-21 03:13 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-06-21 03:11 . 2008-06-21 03:13 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-06-21 03:11 . 2008-06-21 03:11 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-21 03:08 . 2008-06-21 03:08 <DIR> dr-h----- C:\MSOCache
2008-06-21 02:01 . 2008-06-21 02:14 <DIR> d-------- C:\Program Files\WinUAE
2008-06-21 01:52 . 2008-06-22 09:18 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-06-21 01:50 . 2008-06-21 03:07 <DIR> d-------- C:\Downloads
2008-06-21 00:19 . 2008-06-21 00:21 <DIR> d-------- C:\Program Files\GetRight
2008-06-21 00:19 . 2008-06-21 01:52 <DIR> d-------- C:\Documents and Settings\Ania\Application Data\GetRight Pro
2008-06-21 00:18 . 2008-06-21 22:04 <DIR> d-------- C:\Program Files\SubEdit-Player
2008-06-20 20:10 . 2008-06-20 21:31 82 --a------ C:\WINDOWS\mafosav.INI
2008-06-20 20:07 . 2008-06-20 20:07 <DIR> d-------- C:\Buziol Games
2008-06-20 19:15 . 2008-06-20 19:15 <DIR> d-------- C:\Program Files\Azureus
2008-06-20 19:15 . 2008-06-21 04:11 <DIR> d-------- C:\Documents and Settings\Ania\Application Data\Azureus
2008-06-20 19:00 . 2008-06-20 19:00 <DIR> d-------- C:\Documents and Settings\Ania\Application Data\Talkback
2008-06-20 14:57 . 2008-06-20 14:57 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-06-20 14:55 . 2008-06-20 14:55 25 --a------ C:\WINDOWS\cdplayer.ini
2008-06-20 14:50 . 2008-06-20 14:50 <DIR> d-------- C:\Program Files\Real
2008-06-20 14:50 . 2008-06-20 14:57 <DIR> d-------- C:\Program Files\Common Files\Real
2008-06-20 13:44 . 2008-06-20 13:44 <DIR> d-------- C:\Documents and Settings\Ania\Application Data\TVU Networks
2008-06-20 13:18 . 2008-06-20 13:48 <DIR> d-------- C:\Program Files\SopCast
2008-06-20 13:13 . 2008-06-20 13:13 <DIR> d-------- C:\Program Files\Aimersoft
2008-06-20 12:56 . 2008-06-20 12:56 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-06-20 12:50 . 2008-06-20 12:50 <DIR> d-------- C:\Program Files\iPod
2008-06-20 12:50 . 2008-06-20 12:50 <DIR> d-------- C:\Documents and Settings\Ania\Application Data\Apple Computer
2008-06-20 12:49 . 2008-06-20 12:50 <DIR> d-------- C:\Program Files\iTunes
2008-06-20 12:49 . 2008-06-20 12:49 <DIR> d-------- C:\Program Files\Bonjour
2008-06-20 12:48 . 2008-06-20 12:48 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-06-20 12:48 . 2008-06-20 12:49 <DIR> d-------- C:\Program Files\QuickTime
2008-06-20 12:48 . 2008-06-20 12:48 <DIR> d-------- C:\Program Files\Apple Software Update
2008-06-20 12:48 . 2008-06-20 12:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-20 12:47 . 2008-06-20 12:47 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-06-20 12:47 . 2008-06-20 12:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-06-20 12:46 . 2006-05-19 16:16 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-06-20 12:46 . 2006-05-19 16:16 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-06-20 12:45 . 2008-06-21 22:15 <DIR> d-------- C:\Program Files\Winamp
2008-06-20 12:41 . 2008-06-20 12:41 <DIR> d-------- C:\Program Files\Skype
2008-06-20 12:41 . 2008-06-20 12:41 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-06-20 12:41 . 2008-06-22 09:51 <DIR> d-------- C:\Documents and Settings\Ania\Application Data\Skype
2008-06-20 12:41 . 2008-06-20 12:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-06-20 12:36 . 2008-06-20 12:36 <DIR> d-------- C:\Program Files\TVUPlayer
2008-06-20 12:36 . 2008-06-20 12:36 <DIR> d-------- C:\Documents and Settings\Ania\LocalLow
2008-06-20 12:36 . 2008-06-20 12:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-06-20 12:33 . 2008-06-20 12:33 <DIR> d-------- C:\Program Files\totalcmd
2008-06-20 12:33 . 2008-06-22 09:45 2,598 --a------ C:\WINDOWS\wincmd.ini
2008-06-20 12:33 . 2008-04-22 07:03 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2008-06-20 12:24 . 2008-06-20 12:24 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-06-20 12:24 . 2008-06-20 12:24 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-06-20 12:24 . 2008-06-20 12:24 <DIR> d-------- C:\Program Files\MSBuild
2008-06-20 12:23 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-06-20 12:11 . 2008-06-20 12:11 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-20 12:07 . 2008-06-20 12:07 <DIR> d-------- C:\Program Files\Alwil Software
2008-06-20 12:02 . 2008-06-20 12:02 <DIR> d-------- C:\Documents and Settings\Ania\Application Data\Gadu-Gadu
2008-06-20 11:56 . 2008-06-21 11:59 <DIR> d-------- C:\Documents and Settings\Ania\Gadu-Gadu
2008-06-20 11:55 . 2008-06-20 11:56 <DIR> d-------- C:\Program Files\Gadu-Gadu
2008-06-20 03:38 . 2008-06-13 06:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-20 03:38 . 2008-05-08 09:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-19 17:21 . 2008-06-19 17:21 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-06-19 17:21 . 2008-06-19 17:21 <DIR> d-------- C:\WINDOWS\system32\en
2008-06-19 17:21 . 2008-06-19 17:21 <DIR> d-------- C:\WINDOWS\l2schemas
2008-06-19 14:41 . 2008-04-13 19:10 844,314 -----c--- C:\WINDOWS\system32\dllcache\msdxm.ocx
2008-06-19 14:16 . 2008-06-19 14:16 <DIR> d-------- C:\Program Files\PowerQuest
2008-06-19 14:15 . 2008-06-19 14:16 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-06-19 14:15 . 2008-06-19 14:15 <DIR> d---s---- C:\Documents and Settings\Ania\UserData
2008-06-19 13:53 . 2008-06-19 13:53 <DIR> d-------- C:\WINDOWS\provisioning
2008-06-19 13:53 . 2008-06-19 17:21 <DIR> d-------- C:\WINDOWS\peernet
2008-06-19 13:50 . 2008-06-19 13:50 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-06-19 13:43 . 2008-06-19 17:09 <DIR> d-------- C:\WINDOWS\EHome
2008-06-19 13:34 . 2002-04-15 21:11 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2008-06-19 13:34 . 2008-04-14 05:42 11,264 --------- C:\WINDOWS\system32\spnpinst.exe
2008-06-19 13:34 . 2004-08-02 14:20 7,208 --------- C:\WINDOWS\system32\secupd.sig
2008-06-19 13:34 . 2004-08-02 14:20 4,569 --------- C:\WINDOWS\system32\secupd.dat
2008-06-19 13:21 . 2008-06-22 09:23 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-06-19 13:21 . 2007-08-10 20:46 26,488 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-06-19 13:20 . 2008-06-19 17:21 <DIR> d-------- C:\WINDOWS\system32\bits
2008-06-19 13:19 . 2008-04-13 12:39 438,784 --a------ C:\WINDOWS\system32\xpob2res.dll
2008-06-19 13:19 . 2008-04-13 19:12 354,304 --a------ C:\WINDOWS\system32\winhttp.dll
2008-06-19 13:19 . 2008-04-13 19:12 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-06-19 13:19 . 2008-04-13 19:11 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2008-06-19 13:19 . 2008-04-13 19:11 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2008-06-19 13:16 . 2007-07-30 19:19 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2008-06-19 13:16 . 2007-07-30 19:19 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2008-06-19 13:16 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2008-06-19 13:16 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-06-19 13:16 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-06-19 13:16 . 2007-07-30 19:18 33,624 --a------ C:\WINDOWS\system32\wups.dll
2008-06-19 13:16 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-06-19 13:16 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-06-19 13:16 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-06-19 10:40 . 2008-06-21 03:12 <DIR> d-------- C:\Program Files\Microsoft Works
2008-06-19 10:34 . 2008-06-19 10:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\VAIO Media Platform
2008-06-19 10:32 . 2008-06-19 10:32 <DIR> d-------- C:\Program Files\drag'n drop cd+dvd
2008-06-19 10:32 . 2003-09-08 21:15 2 --------- C:\WINDOWS\system32\Px.ini
2008-06-19 10:31 . 1999-12-04 04:11 151,552 --------- C:\WINDOWS\system32\UILib.cpl
2008-06-19 10:31 . 2003-12-05 13:33 118,784 --a------ C:\WINDOWS\system32\tvtuner.cpl
2008-06-19 10:30 . 2008-06-19 10:30 <DIR> d-------- C:\Program Files\InterVideo
2008-06-19 10:30 . 2002-11-21 10:57 204,800 --a------ C:\WINDOWS\system32\IVIresizeW7.dll
2008-06-19 10:30 . 2002-11-21 10:57 200,704 --a------ C:\WINDOWS\system32\IVIresizeA6.dll
2008-06-19 10:30 . 2002-11-21 10:57 192,512 --a------ C:\WINDOWS\system32\IVIresizeP6.dll
2008-06-19 10:30 . 2002-11-21 10:57 192,512 --a------ C:\WINDOWS\system32\IVIresizeM6.dll
2008-06-19 10:30 . 2002-11-21 10:57 188,416 --a------ C:\WINDOWS\system32\IVIresizePX.dll
2008-06-19 10:30 . 2002-11-21 10:57 20,480 --a------ C:\WINDOWS\system32\IVIresize.dll
2008-06-19 10:29 . 2008-06-20 13:17 <DIR> d-------- C:\Documents and Settings\Ania\Application Data\Symantec
2008-06-19 10:29 . 2008-06-21 13:45 <DIR> d-------- C:\Documents and Settings\Ania
2008-06-19 10:29 . 2008-04-13 19:12 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-06-19 10:28 . 2004-03-31 19:02 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec
2008-06-19 10:28 . 2008-06-19 10:28 0 -rah----- C:\WINDOWS\system32\drivers\Sony_PCV-RS630G(UC).mrk
2008-06-19 10:24 . 2001-08-17 15:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-19 10:24 . 2008-04-13 13:45 10,368 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-05-27 10:50 . 2008-05-27 10:50 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-05-27 10:50 . 2008-05-27 10:50 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-20 17:15 --------- d-----w C:\Program Files\Norton Internet Security
2008-06-20 17:04 --------- d-----w C:\Program Files\Quicken
2008-06-20 17:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 17:03 --------- d-----w C:\Program Files\Sony
2008-06-20 17:01 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-20 17:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-20 16:52 --------- d-----w C:\Program Files\Symantec
2008-06-19 15:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-06-19 15:34 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-19 15:33 --------- d-----w C:\Program Files\Common Files\Sony Shared
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-28 06:52 2,121,235 ----a-w C:\WINDOWS\system32\x264vfw.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 10:42 985,088 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 10:41 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:11 997,376 ----a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 21:00 103,424 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:24 2,145,280 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:35 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll
2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:31 2,023,936 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 18:14 76,800 ------w C:\WINDOWS\system32\msshavmsg.dll
2008-04-13 17:39 2,897,920 ------w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 17:39 187,392 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:28 2,940,928 ----a-w C:\WINDOWS\system32\wmploc.dll
2008-04-13 17:27 79,872 ------w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 17:26 94,208 ----a-w C:\WINDOWS\system32\odbcint.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:24 20,480 ----a-w C:\WINDOWS\system32\msorc32r.dll
2008-04-13 17:23 8,192 ----a-w C:\WINDOWS\system32\asferror.dll
2008-04-13 17:23 168,448 ----a-w C:\WINDOWS\system32\wmerror.dll
2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 17:09 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-13 17:03 63,488 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-13 17:03 549,376 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-13 16:48 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 16:45 216,064 ----a-w C:\WINDOWS\system32\moricons.dll
2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
2008-04-13 16:22 48,128 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2008-03-28 17:41 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-06-20 12:02 2127296]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-03-12 15:05 25590312]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2003-05-23 13:43 88363 C:\WINDOWS\AGRSMMSG.exe]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-04-07 02:19 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-07 02:07 114688]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-11-15 21:00 335872]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 13:29 40960]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 18:19 79224]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-20 14:57 180269]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-01-23 14:47 847872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"VIDC.X264"= x264vfw.dll
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Remocon Driver.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Remocon Driver.lnk
backup=C:\WINDOWS\pss\Remocon Driver.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2003-09-06 02:20 70816 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreateCD_Reminder]
--a------ 2004-03-05 19:32 53248 C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
--a------ 2003-08-20 15:55 124096 C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-06-02 11:13 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 19:12 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite]
--a------ 2008-01-23 14:47 847872 c:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
--a------ 2003-09-06 18:36 70840 C:\Program Files\Norton Internet Security\UrlLstCk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Recovery]
--a------ 2003-04-20 00:08 28672 C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2]
--a------ 2004-01-17 06:36 135168 C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIOSurvey]
--a------ 2003-11-03 14:55 1052672 c:\program files\sony\vaio survey\surveysa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 18:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 18:16]
R2 VAIO Entertainment File Import Service;VAIO Entertainment File Import Service;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe [2004-03-12 17:32]
S3 VAIO Entertainment UPnP Client Adapter;VAIO Entertainment UPnP Client Adapter;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe [2004-03-12 16:57]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-19 15:28:48 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2008-06-19 15:28:48 C:\WINDOWS\Tasks\Registration reminder 2.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2008-06-19 15:28:48 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
C:\WINDOWS\RUNDLL32.EXE shell32.dll,SHExitWindowsEx 5
niunias napisał(a):wkleilem ta komende ale wyskakuje mi komunikat ze nie moze znalesc pliku rundll32.exe w katalogu winodws
c:\WINDOWS\system32\shutdown.exe -s -t 0
niunias napisał(a):PS..wiem wiem bedziecie mieli niezly ubaw..ale ja nie wiem o co chodzi z tymi tagami i jak mam ten log z sdfix wstawiwc..
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"="C:\\Program Files\\TVUPlayer\\TVUPlayer.exe:*:Enabled:TVUPlayer Component"
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"="C:\\Program Files\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\\Program Files\\SopCast\\SopCast.exe"="C:\\Program Files\\SopCast\\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
Files with Hidden Attributes :
Fri 23 Apr 1999 93,890 A..H. --- "C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP32\A0009705.COM"
Fri 23 Apr 1999 222,390 A..H. --- "C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP32\A0009706.SYS"
Fri 12 Jan 2001 9 A..H. --- "C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP32\A0009707.SYS"
niunias napisał(a):http://img385.imageshack.us/img385/1588/screencw3.th.jpg
AGRSMMSG
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 12 gości