Zrobiłam to wszystko. Hm, logi już wrzucam, tylko jedno ale mam...
Wyskakują mi ciągle raporty o wirusach jakiegoś programu, którego nie sposób wyłaczyć, ba, nawet po odinstalowaniu działa dalej od czasu karząc pobierać coś (nie pobieram!) i otwierając albo "oczyszczaczkomputera" albo jakieś, ehm, strony pornograficzne. Viruscheat bodajże to się nazywa.
A teraz logi.
SDFix napisał(a):SDFix: Version 1.160
Run by Mojwa on 2008-03-23 at 11:56
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default IE HomePage
Rebooting
Checking Files :
Trojan Files Found:
C:\Documents and Settings\All Users\Pulpit\Online Security Guide.url - Deleted
C:\Documents and Settings\All Users\Menu Start\Online Security Guide.url - Deleted
C:\Documents and Settings\All Users\Pulpit\Security Troubleshooting.url - Deleted
C:\Documents and Settings\All Users\Menu Start\Security Troubleshooting.url - Deleted
C:\Program Files\NetProject\scit.exe - Deleted
C:\Program Files\NetProject\sbmntr.exe - Deleted
C:\Program Files\NetProject\sbun.exe - Deleted
C:\Program Files\NetProject\scm.exe - Deleted
C:\Program Files\NetProject\sbmdl.dll - Deleted
C:\Program Files\NetProject\wamdl.dll - Deleted
C:\Program Files\NetProject\sbsm.exe - Deleted
C:\Program Files\NetProject\waun.exe - Deleted
C:\Program Files\NetProject\ts.ico - Deleted
C:\Program Files\NetProject\ot.ico - Deleted
C:\WINDOWS\system32\tdidrv32.sys - Deleted
Folder C:\Program Files\Helper - Removed
Folder C:\Program Files\NetProject - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-23 12:18:42
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"H:\\Program Files\\WapSter\\AQQ\\AQQ.exe"="H:\\Program Files\\WapSter\\AQQ\\AQQ.exe:*:Enabled:P2P AQQ"
"H:\\PROGRA~1\\WapSter\\AQQ\\AQQ.exe"="H:\\PROGRA~1\\WapSter\\AQQ\\AQQ.exe:*:Enabled:P2P AQQ"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"H:\\Program Files\\Gadu-Gadu\\gg.exe"="H:\\Program Files\\Gadu-Gadu\\gg.exe:*:Enabled:Gadu-Gadu - program g˘wny"
"C:\\WINDOWS\\System32\\dpvsetup.exe"="C:\\WINDOWS\\System32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\System32\\RUNDLL32.EXE"="C:\\WINDOWS\\System32\\RUNDLL32.EXE:*:Enabled:Uruchamia plik DLL jako aplikacj©"
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"="C:\\Program Files\\BitTornado\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\\Program Files\\Winamp Remote\\BIN\\Orb.exe"="C:\\Program Files\\Winamp Remote\\BIN\\Orb.exe:*:Enabled:Orb"
"C:\\Program Files\\Winamp Remote\\BIN\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\BIN\\OrbTray.exe:*:Enabled:OrbTray"
"C:\\Program Files\\Winamp Remote\\BIN\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\BIN\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"H:\\Program Files\\BitTyrant\\Azureus.exe"="H:\\Program Files\\BitTyrant\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Konnekt\\konnekt.exe"="C:\\Program Files\\Konnekt\\konnekt.exe:*:Enabled:Konnekt - Core"
"C:\\Program Files\\SHOUTcast\\sc_serv.exe"="C:\\Program Files\\SHOUTcast\\sc_serv.exe:*:Enabled:sc_serv"
"C:\\Program Files\\Tlen.pl\\tlen.exe"="C:\\Program Files\\Tlen.pl\\tlen.exe:*:Enabled:Komunikator Tlen.pl"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Wed 12 Dec 2007 4,909,064 ...H. --- "C:\Program Files\Picasa2\setup.exe"
Fri 1 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT1.tmp"
Finished!
ComboFix napisał(a):ComboFix 08-03-22.3 - Mojwa 2008-03-23 12:24:13.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.69 [GMT 1:00]
Running from: C:\Documents and Settings\Mojwa\Moje dokumenty\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\VirusHeat 4.3
C:\Program Files\VirusHeat 4.3\vpp.ini
.
((((((((((((((((((((((((( Files Created from 2008-02-23 to 2008-03-23 )))))))))))))))))))))))))))))))
.
2008-03-23 11:55 . 2008-03-23 11:55 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-23 11:52 . 2008-03-23 07:25 <DIR> d-------- C:\SDFix
2008-03-23 02:00 . 2008-03-23 02:00 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-23 01:24 . 2008-03-23 01:24 <DIR> d-------- C:\Program Files\Alwil Software
2008-03-23 01:24 . 2003-03-18 21:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-03-23 01:24 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-03-23 01:24 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-03-23 01:24 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-03-23 01:24 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-23 01:24 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-23 01:24 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-23 01:24 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-23 01:24 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-23 01:17 . 2008-03-23 01:17 <DIR> d--hs---- C:\FOUND.015
2008-03-23 01:14 . 2008-03-23 01:14 <DIR> d--hs---- C:\FOUND.014
2008-03-23 01:11 . 2008-03-23 01:11 <DIR> d--hs---- C:\FOUND.013
2008-03-23 01:09 . 2008-03-23 01:09 <DIR> d--hs---- C:\FOUND.012
2008-03-23 01:04 . 2008-03-23 01:04 <DIR> d--hs---- C:\FOUND.011
2008-03-23 01:01 . 2008-03-23 01:01 <DIR> d--hs---- C:\FOUND.010
2008-03-22 20:22 . 2008-03-22 20:22 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-03-22 01:28 . 2008-03-22 01:28 <DIR> d--hs---- C:\FOUND.009
2008-03-19 15:28 . 2008-03-19 15:28 <DIR> d--hs---- C:\FOUND.008
2008-03-16 22:56 . 2008-03-16 22:56 <DIR> d-------- C:\Documents and Settings\Mojwa\Dane aplikacji\Sony
2008-03-16 22:56 . 2008-03-16 22:56 <DIR> d-------- C:\Documents and Settings\Mojwa\Dane aplikacji\Publish Providers
2008-03-16 22:56 . 2008-03-16 22:56 156 --a------ C:\WINDOWS\Twunk001.MTX
2008-03-16 22:56 . 2008-03-16 22:57 2 --a------ C:\WINDOWS\Twain001.Mtx
2008-03-16 22:56 . 2008-03-16 22:56 0 --a------ C:\WINDOWS\Twunk002.MTX
2008-03-16 22:53 . 2008-03-16 22:53 <DIR> d-------- C:\Program Files\Vstplugins
2008-03-16 22:52 . 2008-03-16 22:52 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Sony
2008-03-13 22:10 . 2008-03-13 22:10 <DIR> d-------- C:\videooutput
2008-03-13 22:10 . 2008-03-13 22:10 <DIR> d-------- C:\Program Files\Free FLV to AVI Converter
2008-03-13 22:10 . 2007-03-07 00:45 3,086,336 --a------ C:\WINDOWS\system32\flvvideo.dll
2008-03-11 18:47 . 2008-03-11 18:47 5,016,215 --a------ C:\06 - - AudioTrack 06.mp3
2008-03-11 18:47 . 2008-03-11 18:47 1,100,780 --a------ C:\07 - - AudioTrack 07.wav
2008-03-11 18:47 . 2008-03-12 07:44 368 --a------ C:\WINDOWS\CDPLAYER.INI
2008-03-11 18:46 . 2008-03-11 18:46 6,840,606 --a------ C:\04 - - AudioTrack 04.mp3
2008-03-11 18:45 . 2008-03-11 18:45 5,040,665 --a------ C:\03 - - AudioTrack 03.mp3
2008-03-11 18:44 . 2008-03-11 18:44 4,152,293 --a------ C:\02 - - AudioTrack 02.mp3
2008-03-11 18:44 . 2008-03-11 18:44 3,411,278 --a------ C:\01 - - AudioTrack 01.mp3
2008-03-06 09:43 . 2008-03-06 09:43 <DIR> d-------- C:\Program Files\Audio Phonics, Inc
2008-03-06 09:43 . 2008-03-06 09:43 <DIR> d-------- C:\Documents and Settings\Mojwa\WINDOWS
2008-03-06 09:43 . 1998-02-06 22:37 299,520 --a------ C:\WINDOWS\uninst.exe
2008-03-04 20:28 . 2008-03-04 20:28 <DIR> d-------- C:\Program Files\Guitar Pro 5
2008-03-03 10:41 . 2008-03-03 10:41 <DIR> d-------- C:\Program Files\Tlen.pl
2008-03-03 10:41 . 2008-03-03 10:41 <DIR> d-------- C:\Documents and Settings\Mojwa\Dane aplikacji\Tlen.pl
2008-02-25 21:47 . 2008-02-25 21:47 <DIR> d--hs---- C:\FOUND.007
2008-02-24 14:13 . 2008-02-24 14:13 <DIR> d-------- C:\Program Files\SHOUTcast
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 14:53 --------- d-----w C:\Program Files\Konnekt
2008-02-16 14:53 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\stamina
2008-02-13 22:45 --------- d-----w C:\Program Files\Eurobarre
2008-02-11 17:03 --------- d-----w C:\Documents and Settings\Mojwa\Dane aplikacji\BitTyrant
2008-02-06 14:30 --------- d-----w C:\Program Files\Mp3tag
2008-02-06 14:30 --------- d-----w C:\Documents and Settings\Mojwa\Dane aplikacji\Mp3tag
2008-02-06 12:15 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Last.fm
2008-02-06 12:14 --------- d-----w C:\Program Files\Last.fm
2008-02-04 21:22 --------- d-----w C:\Program Files\eMule
2008-02-04 19:39 --------- d-----w C:\Program Files\ASCII
2008-02-01 18:06 --------- d-----w C:\Program Files\WinAVIVideoConverter
2008-02-01 17:49 --------- d-----w C:\Program Files\Media Player Classic
2008-02-01 02:01 --------- d-----w C:\Program Files\MSXML 4.0
2008-01-31 18:51 --------- d-----w C:\Program Files\Google
2008-01-27 12:27 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Adobe Systems
2008-01-27 12:21 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-01-27 10:06 --------- d-----w C:\Program Files\Total Video Converter
2007-12-24 12:49 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2007-12-17 11:15 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{140BD8E3-C167-11D4-B4A3-080000180323}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-12-13 17:49 1185120 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2007-12-13 17:49 1185120]
"{DB9FBA9D-AB1B-4CC6-9745-F3B549D64E40}"= "C:\Program Files\NetProject\wamdl.dll" [ ]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CLASSES_ROOT\clsid\{db9fba9d-ab1b-4cc6-9745-f3b549d64e40}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 17:49 1185120]
"{DB9FBA9D-AB1B-4CC6-9745-F3B549D64E40}"= C:\Program Files\NetProject\wamdl.dll [ ]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CLASSES_ROOT\clsid\{db9fba9d-ab1b-4cc6-9745-f3b549d64e40}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 22:44 15360]
"AQQ"="H:\PROGRA~1\WapSter\AQQ\AQQ.exe" [2007-02-28 13:18 2351864]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 21:02 495616]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"Gadu-Gadu"="H:\Program Files\Gadu-Gadu\gg.exe" [2007-11-14 11:54 2131392]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-12-07 15:11 21803304]
"Konnekt"="C:\Program Files\Konnekt\konnekt.exe" [2005-05-24 22:41 503808]
"Komunikator"="C:\Program Files\Tlen.pl\tlen.exe" [2008-02-29 13:18 5884416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="H:\Program Files\Winamp\winampa.exe" [2008-01-15 23:54 37376]
"AudioDeck"="C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe" [2006-11-02 16:57 528384]
"VTTimer"="VTTimer.exe" [2006-09-14 18:54 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2007-04-25 15:41 176128 C:\WINDOWS\system32\VTTrayp.exe]
"Maplom"="H:\Program Files\SlySoft\Game Jackal\GameJackal.exe" [2007-06-23 09:37 4872704]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 11:48 157592]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 16:40 155648]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-04-20 00:17 421888]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 22:44 15360]
C:\Documents and Settings\Mojwa\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2008-02-06 13:14:16 106496]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{7d7bd0c4-4913-4933-b870-7388a7bffb82}"= C:\WINDOWS\system32\lvhjtsa.dll [2007-11-25 18:34 13312]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"H:\\Program Files\\WapSter\\AQQ\\AQQ.exe"=
"H:\\PROGRA~1\\WapSter\\AQQ\\AQQ.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"H:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\WINDOWS\\System32\\dpvsetup.exe"=
"C:\\WINDOWS\\System32\\RUNDLL32.EXE"=
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"C:\\Program Files\\Winamp Remote\\BIN\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\BIN\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\BIN\\OrbStreamerClient.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"H:\\Program Files\\BitTyrant\\Azureus.exe"=
"C:\\Program Files\\Konnekt\\konnekt.exe"=
"C:\\Program Files\\SHOUTcast\\sc_serv.exe"=
"C:\\Program Files\\Tlen.pl\\tlen.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8461:TCP"= 8461:TCP:GoD High Port
"8462:TCP"= 8462:TCP:GoD Low Port
"6882:UDP"= 6882:UDP:6882
"6882:TCP"= 6882:TCP:6882
R3 PAC207;SoC PC-Camera Beta3;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-04-12 06:58]
S3 axsaki;axsaki;C:\WINDOWS\system32\DRIVERS\axsaki.sys []
S3 axskbus;axskbus;C:\WINDOWS\system32\DRIVERS\axskbus.sys []
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\autorun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-23 12:26:14
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\lvhjtsa.dll
.
Completion time: 2008-03-23 12:27:01
ComboFix-quarantined-files.txt 2008-03-23 11:27:00
.
2008-02-14 02:01:02 --- E O F ---
Hijack napisał(a):Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:31:13, on 2008-03-23
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
H:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\WINDOWS\system32\wuauclt.exe
H:\Program Files\Winamp\winamp.exe
C:\Program Files\Last.fm\LastFM.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\WapSter\AQQ\AQQ.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66020
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66020
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - (no file)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Internet Service - {DB9FBA9D-AB1B-4CC6-9745-F3B549D64E40} - C:\Program Files\NetProject\wamdl.dll (file missing)
O4 - HKLM\..\Run: [WinampAgent] "H:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Maplom] H:\Program Files\SlySoft\Game Jackal\GameJackal.exe /silent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AQQ] H:\PROGRA~1\WapSter\AQQ\AQQ.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Gadu-Gadu] "H:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Konnekt] "C:\Program Files\Konnekt\konnekt.exe" /autostart
O4 - HKCU\..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O22 - SharedTaskScheduler: figpecker - {7d7bd0c4-4913-4933-b870-7388a7bffb82} - C:\WINDOWS\system32\lvhjtsa.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
--
End of file - 7279 bytes