• Ogłoszenie:

zmasowany atak x.x

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Postprzez _Darex_ 13 Maj 2008, 15:43

reklama
Eh, niestety tych trzech nie ma na liście po skanowaniu w Hijacku:

O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {0731706B-A118-40E1-917B-ECBD23242FA9} - C:\WINDOWS\system32\ssttu.dll
O2 - BHO: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul0.dll




Log z dss'a:

Kod: Zaznacz wszystko
Deckard's System Scanner v20071014.68
Run by Gwidon on 2008-04-14 08:44:00
Computer is in Normal Mode.
--------------------------------------------------------------------------------

[color=red]System Drive C: has 4.32 GiB (less than 15%) free.[/color]


-- HijackThis (run as Gwidon.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:44:01, on 2008-04-14
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
D:\QuickTime\QTSystem\Web Vulnerability Scanner 4\WVSScheduler.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Icecast2 Win32\icecastService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\PSIService.exe
D:\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
D:\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
D:\FRAPS\FRAPS.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\kRk Software\GG Tools\GGT.exe
C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe
D:\Gadu-Gadu\gg.exe
D:\Winamp\winamp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
D:\ICeQ\Chat.exe
C:\Documents and Settings\Gwidon\Pulpit\dss.exe
D:\HIJACK~1\Gwidon.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:4001
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Burn4Free Toolbar Helper - {60BF5EE3-0105-4858-AD98-17C19F86B042} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul0.dll
O2 - BHO: (no name) - {D6B1AE9B-12F8-424E-AEF0-39BDF8CB9B42} - C:\WINDOWS\system32\ssttu.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Burn4Free Toolbar - {55FAF0F2-44D4-425F-B5F5-6B275B621EAB} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-f7ed0776fb27} - c:\program files\steganos internet anonym 2006\sia2006iep.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [CloneCDTray] "D:\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [WinampAgent] D:\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Fraps] D:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AnyDVD] D:\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [GoD] "D:\GoD\GoD.exe" /tray
O4 - HKCU\..\Run: [VS Online] C:\VSOnline.exe /tray
O4 - HKCU\..\Run: [DAEMON Tools] "D:\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [GG Tools] "D:\kRk Software\GG Tools\GGT.exe" /tray
O4 - HKCU\..\Run: [manager] "C:\Windows\System32\drivers\setup\manager.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -boot
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Rozmowa.lnk = D:\System syntezy mowy\rozmowy.exe
O4 - Startup: UniSpiker-2.6.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk142YYSE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15-3.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3C05AA5D-E5F8-46B2-B6C9-D075058806A2}: NameServer = 194.204.159.1,194.204.152.34
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Acunetix WVS Scheduler (AcuWVSScheduler) - Acunetix Ltd. - D:\QuickTime\QTSystem\Web Vulnerability Scanner 4\WVSScheduler.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Icecast Media Server (Icecast) - Unknown owner - C:\Program Files\Icecast2 Win32\icecastService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 13025 bytes

-- Files created between 2008-03-14 and 2008-04-14 -----------------------------

2008-04-13 07:44:06    186096 --ahs---- C:\WINDOWS\system32\uttss.ini2
2008-04-13 02:26:16         0 d-------- C:\Program Files\Bonjour
2008-04-13 02:20:08         0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-12 12:04:09     91712 --a------ C:\WINDOWS\system32\rjyynsha.dll
2008-04-12 12:01:09      2112 --a------ C:\WINDOWS\system32\hubksnhd.exe
2008-04-12 11:58:56     98368 --a------ C:\WINDOWS\system32\cibucdfc.dll
2008-04-12 07:16:04         0 d-------- C:\Program Files\Secure Surfing Engine
2008-04-12 07:16:00         0 d-------- C:\Program Files\Steganos Internet Anonym 2006
2008-04-11 10:17:49      2112 --a------ C:\WINDOWS\system32\jcdrdmim.exe
2008-04-11 10:17:43    100416 --a------ C:\WINDOWS\system32\syeecvlh.dll
2008-04-10 10:57:41         0 d-------- C:\Program Files\uTorrent
2008-04-10 08:00:10         0 d-------- C:\Program Files\MSECache
2008-04-05 09:15:38         0 d-------- C:\Program Files\Goolag Scanner
2008-04-04 23:42:18      3860 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-04 23:41:53     25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-04 23:41:53    289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-04-04 23:41:53     86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-04-04 23:41:53    288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-04-04 23:41:53     53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-04-04 23:41:53     82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-04 23:41:53     51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-04 23:41:53     82944 --a------ C:\WINDOWS\system32\404Fix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-04 13:24:44         0 d-------- C:\WINDOWS\ERUNT
2008-04-03 12:35:59         0 d-------- C:\Program Files\Common Files\Screaming Bee
2008-04-03 00:51:04    281600 --a------ C:\WINDOWS\system32\ssttu.dll
2008-04-02 13:07:21         0 d-------- C:\Program Files\Common Files\xing shared
2008-04-02 13:07:06         0 d-------- C:\Program Files\Real
2008-04-02 01:41:32         0 d-------- C:\Documents and Settings\Gwidon\Application Data
2008-04-02 01:41:32         0 d-------- C:\Documents and Settings\Gwidon\Application Data\Syntrillium
2008-04-01 15:35:16         0 d-------- C:\Program Files\Common Files\Reallusion
2008-03-26 10:55:54    233472 --a------ C:\WINDOWS\system32\REX Shared Library.dll <Not Verified; Propellerhead Software AB; REX SDK>
2008-03-26 10:55:54    368640 --a------ C:\WINDOWS\system32\ReWire.dll <Not Verified; Propellerhead Software AB; ReWire>
2008-03-25 00:46:26         0 d-------- C:\WINDOWS\_$MB6Setup_
2008-03-23 06:59:09         0 d-------- C:\Program Files\Common Files\Borland Shared
2008-03-22 03:10:43     29696 --a------ C:\WINDOWS\system32\pthread.dll
2008-03-22 03:10:43     78085 --a------ C:\WINDOWS\system32\pattern.dat
2008-03-22 03:10:43    307200 --a------ C:\WINDOWS\system32\fxstudio.dll
2008-03-22 03:10:43     57344 --a------ C:\WINDOWS\system32\eJ_Capture.dll <Not Verified; eJay AG; PrjCapture>
2008-03-22 03:10:43    147519 --a------ C:\WINDOWS\system32\ej_360VideoFX.dll <Not Verified; eJay AG; PrjVideoFX>
2008-03-22 03:10:43    106496 --a------ C:\WINDOWS\system32\DartWeb.dll <Not Verified; Dart Communications; PowerTCP© Tools>
2008-03-22 03:10:43    159744 --a------ C:\WINDOWS\system32\DartSock.dll <Not Verified; Dart Communications; PowerTCP© Tools>
2008-03-22 03:10:38    280576 --a------ C:\WINDOWS\system32\pxd_kom.dll
2008-03-22 03:10:38     45056 --a------ C:\WINDOWS\system32\fader.dll
2008-03-22 03:10:37     75976 --a------ C:\WINDOWS\system32\BASSDEC.dll
2008-03-21 03:17:13         0 d-------- C:\Program Files\Common Files\Corel
2008-03-21 03:14:36      2516 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-03-21 03:14:36        88 -r-hs---- C:\WINDOWS\system32\8F51133FB5.sys
2008-03-20 05:35:28         0 d-------- C:\Program Files\Jasc Software Inc
2008-03-14 14:02:44         0 d-------- C:\Program Files\Skype
2008-03-14 14:02:44         0 d-------- C:\Program Files\Common Files\Skype
2008-03-14 06:51:06         0 d-------- C:\Program Files\Common Files\Macromedia Shared
2008-03-14 06:50:08         0 d-------- C:\Program Files\Common Files\Macromedia


-- Find3M Report ---------------------------------------------------------------

2008-04-14 08:33:34         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Skype
2008-04-14 08:32:49         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\skypePM
2008-04-13 09:51:23         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Adobe
2008-04-13 07:51:27         0 d-------- C:\Program Files\Opera
2008-04-13 02:27:13         0 d-------- C:\Program Files\QuickTime
2008-04-13 02:26:14         0 d-------- C:\Program Files\Common Files\Adobe
2008-04-13 00:00:18         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Corel
2008-04-12 07:28:06         0 d-------- C:\Program Files\Java
2008-04-12 05:55:40         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Hide IP NG
2008-04-11 00:14:19         0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-10 16:06:32         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\uTorrent
2008-04-06 08:35:14    475568 --a------ C:\WINDOWS\system32\perfh015.dat
2008-04-06 08:35:14     85368 --a------ C:\WINDOWS\system32\perfc015.dat
2008-04-04 10:31:49       664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-03 12:38:23         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Screaming Bee
2008-04-03 12:35:59         0 d-------- C:\Program Files\Common Files
2008-04-02 13:34:35         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Real
2008-04-02 13:07:18         0 d-------- C:\Program Files\Common Files\Real
2008-04-02 12:44:53         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Canon
2008-04-02 04:28:10         0 d-------- C:\Program Files\Winamp Remote
2008-04-01 15:42:31         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Reallusion
2008-04-01 15:34:46         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\InstallShield
2008-03-26 10:56:07         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Propellerhead Software
2008-03-21 07:43:21         0 d-------- C:\Program Files\Microsoft Works
2008-03-18 10:55:21         0 d-------- C:\Program Files\Google
2008-03-14 06:54:45         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Macromedia
2008-02-27 09:28:54         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Apple Computer
2008-02-24 11:47:22         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\3DFA


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 14:06   1135968   --a------   C:\Program Files\Winamp Toolbar\winamptb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D6B1AE9B-12F8-424E-AEF0-39BDF8CB9B42}]
2008-04-03 00:51   281600   --a------   C:\WINDOWS\system32\ssttu.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 14:06 1135968]

[-HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 09:44 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-15 03:20]
"nwiz"="nwiz.exe" [2005-06-15 03:20 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-06-15 03:20]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 03:00]
"OPSE reminder"="C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" [2003-07-07 01:29]
"NWEReboot"="" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 02:50]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 12:37]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-13 19:43]
"CloneCDTray"="D:\SlySoft\CloneCD\CloneCDTray.exe" []
"WinampAgent"="D:\Winamp\winampa.exe" [2007-10-09 23:28]
"QuickTime Task"="D:\QuickTime\qttask.exe" [2007-10-19 13:16]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-18 10:55]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-02 13:07]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 13:25]
"Fraps"="D:\FRAPS\FRAPS.EXE" [2003-05-18 11:32]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:44]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 11:20]
"AnyDVD"="D:\SlySoft\AnyDVD\AnyDVD.exe" []
"GoD"="D:\GoD\GoD.exe" []
"VS Online"="C:\VSOnline.exe" []
"DAEMON Tools"="D:\DAEMON Tools\daemon.exe" []
"AlcoholAutomount"="D:\Alcohol Soft\Alcohol 52\axcmd.exe" [2007-07-02 04:22]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2007-10-22 18:47]
"GG Tools"="D:\kRk Software\GG Tools\GGT.exe" [2007-09-17 08:25]
"manager"="C:\Windows\System32\drivers\setup\manager.exe" []
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 10:26]
"SIA2006"="C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" [2005-11-09 11:35]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe" [2007-04-04 07:41]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"SIA2006"="C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot

C:\Documents and Settings\Gwidon\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 12:16:50]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ssttu




-- End of Deckard's System Scanner: finished at 2008-04-14 08:44:24 ------------

DareX :]
_Darex_
~user
 
Posty: 16
Dołączenie: 27 Kwi 2008, 09:55



Postprzez wojtas 13 Maj 2008, 16:26

Pobierz i uruchom narzędzie
The Avenger
w bialym polu wklej tekst:
Files to delete:

C:\WINDOWS\system32\uttss.ini2
C:\WINDOWS\system32\rjyynsha.dll
C:\WINDOWS\system32\hubksnhd.exe
C:\WINDOWS\system32\cibucdfc.dll
C:\WINDOWS\system32\jcdrdmim.exe
C:\WINDOWS\system32\syeecvlh.dll
C:\WINDOWS\system32\ssttu.dll


Kliknij w Execute i zatwierdz reset kompa.


wklej do notatnika

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D6B1AE9B-12F8-424E-AEF0-39BDF8CB9B42}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NWEReboot"=-

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"manager"=-


w notatniku u góry>>>plik zapisz jako>>>Zmien rozszerzenie z TXT na Wszystkie pliki *.* >>> Zapisz pod nazwą FIX.REG

Klikasz dwa razy na powstały plik fix i dodajesz go do rejestru....

potem tworzysz taki fix:


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=-
"Authentication Packages"=hex(7):6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,00,\
00


tez montujesz go do rejestru
Kasujesz ręcznie z dysku plik: C:\Avenger\backup.zip i wklejasz na forum raport: C:\avenger.txt + log z dss
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez _Darex_ 13 Maj 2008, 20:05

Zrobiłem to ^^. raport z avengera:

Kod: Zaznacz wszystko
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform:  Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "C:\WINDOWS\system32\uttss.ini2" deleted successfully.
File "C:\WINDOWS\system32\rjyynsha.dll" deleted successfully.
File "C:\WINDOWS\system32\hubksnhd.exe" deleted successfully.
File "C:\WINDOWS\system32\cibucdfc.dll" deleted successfully.
File "C:\WINDOWS\system32\jcdrdmim.exe" deleted successfully.
File "C:\WINDOWS\system32\syeecvlh.dll" deleted successfully.
File "C:\WINDOWS\system32\ssttu.dll" deleted successfully.

Completed script processing.

*******************

Finished!  Terminate.


A tu nowy log z dss'a:
Kod: Zaznacz wszystko
Deckard's System Scanner v20071014.68
Run by Gwidon on 2008-04-14 13:05:27
Computer is in Normal Mode.
--------------------------------------------------------------------------------

[color=red]System Drive C: has 4.27 GiB (less than 15%) free.[/color]


-- HijackThis (run as Gwidon.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:05:36, on 2008-04-14
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
D:\QuickTime\QTSystem\Web Vulnerability Scanner 4\WVSScheduler.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Icecast2 Win32\icecastService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\PSIService.exe
D:\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
D:\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
D:\FRAPS\FRAPS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\WgaTray.exe
D:\kRk Software\GG Tools\GGT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Gadu-Gadu\gg.exe
D:\Winamp\winamp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Gwidon\Pulpit\dss.exe
D:\HIJACK~1\Gwidon.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:4001
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Burn4Free Toolbar Helper - {60BF5EE3-0105-4858-AD98-17C19F86B042} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul0.dll
O2 - BHO: (no name) - {D6B1AE9B-12F8-424E-AEF0-39BDF8CB9B42} - C:\WINDOWS\system32\ssttu.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Burn4Free Toolbar - {55FAF0F2-44D4-425F-B5F5-6B275B621EAB} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-f7ed0776fb27} - c:\program files\steganos internet anonym 2006\sia2006iep.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [CloneCDTray] "D:\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [WinampAgent] D:\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Fraps] D:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AnyDVD] D:\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [GoD] "D:\GoD\GoD.exe" /tray
O4 - HKCU\..\Run: [VS Online] C:\VSOnline.exe /tray
O4 - HKCU\..\Run: [DAEMON Tools] "D:\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [GG Tools] "D:\kRk Software\GG Tools\GGT.exe" /tray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -boot
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Rozmowa.lnk = D:\System syntezy mowy\rozmowy.exe
O4 - Startup: UniSpiker-2.6.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk142YYSE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15-3.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3C05AA5D-E5F8-46B2-B6C9-D075058806A2}: NameServer = 194.204.159.1,194.204.152.34
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Acunetix WVS Scheduler (AcuWVSScheduler) - Acunetix Ltd. - D:\QuickTime\QTSystem\Web Vulnerability Scanner 4\WVSScheduler.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Icecast Media Server (Icecast) - Unknown owner - C:\Program Files\Icecast2 Win32\icecastService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 13122 bytes

-- Files created between 2008-03-14 and 2008-04-14 -----------------------------

2008-04-13 02:26:16         0 d-------- C:\Program Files\Bonjour
2008-04-13 02:20:08         0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-12 07:16:04         0 d-------- C:\Program Files\Secure Surfing Engine
2008-04-12 07:16:00         0 d-------- C:\Program Files\Steganos Internet Anonym 2006
2008-04-10 10:57:41         0 d-------- C:\Program Files\uTorrent
2008-04-10 08:00:10         0 d-------- C:\Program Files\MSECache
2008-04-05 09:15:38         0 d-------- C:\Program Files\Goolag Scanner
2008-04-04 23:42:18      3860 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-04 23:41:53     25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-04 23:41:53    289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-04-04 23:41:53     86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-04-04 23:41:53    288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-04-04 23:41:53     53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-04-04 23:41:53     82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-04 23:41:53     51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-04 23:41:53     82944 --a------ C:\WINDOWS\system32\404Fix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-04 13:24:44         0 d-------- C:\WINDOWS\ERUNT
2008-04-03 12:35:59         0 d-------- C:\Program Files\Common Files\Screaming Bee
2008-04-02 13:07:21         0 d-------- C:\Program Files\Common Files\xing shared
2008-04-02 13:07:06         0 d-------- C:\Program Files\Real
2008-04-02 01:41:32         0 d-------- C:\Documents and Settings\Gwidon\Application Data
2008-04-02 01:41:32         0 d-------- C:\Documents and Settings\Gwidon\Application Data\Syntrillium
2008-04-01 15:35:16         0 d-------- C:\Program Files\Common Files\Reallusion
2008-03-26 10:55:54    233472 --a------ C:\WINDOWS\system32\REX Shared Library.dll <Not Verified; Propellerhead Software AB; REX SDK>
2008-03-26 10:55:54    368640 --a------ C:\WINDOWS\system32\ReWire.dll <Not Verified; Propellerhead Software AB; ReWire>
2008-03-25 00:46:26         0 d-------- C:\WINDOWS\_$MB6Setup_
2008-03-23 06:59:09         0 d-------- C:\Program Files\Common Files\Borland Shared
2008-03-22 03:10:43     29696 --a------ C:\WINDOWS\system32\pthread.dll
2008-03-22 03:10:43     78085 --a------ C:\WINDOWS\system32\pattern.dat
2008-03-22 03:10:43    307200 --a------ C:\WINDOWS\system32\fxstudio.dll
2008-03-22 03:10:43     57344 --a------ C:\WINDOWS\system32\eJ_Capture.dll <Not Verified; eJay AG; PrjCapture>
2008-03-22 03:10:43    147519 --a------ C:\WINDOWS\system32\ej_360VideoFX.dll <Not Verified; eJay AG; PrjVideoFX>
2008-03-22 03:10:43    106496 --a------ C:\WINDOWS\system32\DartWeb.dll <Not Verified; Dart Communications; PowerTCP© Tools>
2008-03-22 03:10:43    159744 --a------ C:\WINDOWS\system32\DartSock.dll <Not Verified; Dart Communications; PowerTCP© Tools>
2008-03-22 03:10:38    280576 --a------ C:\WINDOWS\system32\pxd_kom.dll
2008-03-22 03:10:38     45056 --a------ C:\WINDOWS\system32\fader.dll
2008-03-22 03:10:37     75976 --a------ C:\WINDOWS\system32\BASSDEC.dll
2008-03-21 03:17:13         0 d-------- C:\Program Files\Common Files\Corel
2008-03-21 03:14:36      2516 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-03-21 03:14:36        88 -r-hs---- C:\WINDOWS\system32\8F51133FB5.sys
2008-03-20 05:35:28         0 d-------- C:\Program Files\Jasc Software Inc
2008-03-14 14:02:44         0 d-------- C:\Program Files\Skype
2008-03-14 14:02:44         0 d-------- C:\Program Files\Common Files\Skype
2008-03-14 06:51:06         0 d-------- C:\Program Files\Common Files\Macromedia Shared
2008-03-14 06:50:08         0 d-------- C:\Program Files\Common Files\Macromedia


-- Find3M Report ---------------------------------------------------------------

2008-04-14 12:57:54         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Skype
2008-04-14 12:57:23         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\skypePM
2008-04-13 09:51:23         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Adobe
2008-04-13 07:51:27         0 d-------- C:\Program Files\Opera
2008-04-13 02:27:13         0 d-------- C:\Program Files\QuickTime
2008-04-13 02:26:14         0 d-------- C:\Program Files\Common Files\Adobe
2008-04-13 00:00:18         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Corel
2008-04-12 07:28:06         0 d-------- C:\Program Files\Java
2008-04-12 05:55:40         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Hide IP NG
2008-04-11 00:14:19         0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-10 16:06:32         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\uTorrent
2008-04-06 08:35:14    475568 --a------ C:\WINDOWS\system32\perfh015.dat
2008-04-06 08:35:14     85368 --a------ C:\WINDOWS\system32\perfc015.dat
2008-04-04 10:31:49       664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-03 12:38:23         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Screaming Bee
2008-04-03 12:35:59         0 d-------- C:\Program Files\Common Files
2008-04-02 13:34:35         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Real
2008-04-02 13:07:18         0 d-------- C:\Program Files\Common Files\Real
2008-04-02 12:44:53         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Canon
2008-04-02 04:28:10         0 d-------- C:\Program Files\Winamp Remote
2008-04-01 15:42:31         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Reallusion
2008-04-01 15:34:46         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\InstallShield
2008-03-26 10:56:07         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Propellerhead Software
2008-03-21 07:43:21         0 d-------- C:\Program Files\Microsoft Works
2008-03-18 10:55:21         0 d-------- C:\Program Files\Google
2008-03-14 06:54:45         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Macromedia
2008-02-27 09:28:54         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Apple Computer
2008-02-24 11:47:22         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\3DFA


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 14:06   1135968   --a------   C:\Program Files\Winamp Toolbar\winamptb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D6B1AE9B-12F8-424E-AEF0-39BDF8CB9B42}]
         C:\WINDOWS\system32\ssttu.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 14:06 1135968]

[-HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 09:44 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-15 03:20]
"nwiz"="nwiz.exe" [2005-06-15 03:20 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-06-15 03:20]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 03:00]
"OPSE reminder"="C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" [2003-07-07 01:29]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 02:50]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 12:37]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-13 19:43]
"CloneCDTray"="D:\SlySoft\CloneCD\CloneCDTray.exe" []
"WinampAgent"="D:\Winamp\winampa.exe" [2007-10-09 23:28]
"QuickTime Task"="D:\QuickTime\qttask.exe" [2007-10-19 13:16]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-18 10:55]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-02 13:07]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 13:25]
"Fraps"="D:\FRAPS\FRAPS.EXE" [2003-05-18 11:32]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:44]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 11:20]
"AnyDVD"="D:\SlySoft\AnyDVD\AnyDVD.exe" []
"GoD"="D:\GoD\GoD.exe" []
"VS Online"="C:\VSOnline.exe" []
"DAEMON Tools"="D:\DAEMON Tools\daemon.exe" []
"AlcoholAutomount"="D:\Alcohol Soft\Alcohol 52\axcmd.exe" [2007-07-02 04:22]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2007-10-22 18:47]
"GG Tools"="D:\kRk Software\GG Tools\GGT.exe" [2007-09-17 08:25]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 10:26]
"SIA2006"="C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" [2005-11-09 11:35]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe" [2007-04-04 07:41]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"SIA2006"="C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot

C:\Documents and Settings\Gwidon\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 12:16:50]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL




-- End of Deckard's System Scanner: finished at 2008-04-14 13:06:03 ------------
DareX :]
_Darex_
~user
 
Posty: 16
Dołączenie: 27 Kwi 2008, 09:55



Postprzez wojtas 13 Maj 2008, 22:28

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul0.dll
O2 - BHO: (no name) - {D6B1AE9B-12F8-424E-AEF0-39BDF8CB9B42} - C:\WINDOWS\system32\ssttu.dll (file missing)
O3 - Toolbar: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul0.dll


poszukaj tych wpisow w hijacku i pogrubione foldery wywal do kosza... jesli nie znajdziesz to moze w awaryjnym (F8 przy starcie kompa),, jesli nie sciagnij jakas inna wersje hijacka moze ona wykryje i wroc z logiem
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Postprzez _Darex_ 14 Maj 2008, 08:37

Znalazłem te wpisy i wywaliłem, foldery pogrubione też usunąłem ^^. Log z dss'a:

Kod: Zaznacz wszystko
Deckard's System Scanner v20071014.68
Run by Gwidon on 2008-04-15 01:37:21
Computer is in Normal Mode.
--------------------------------------------------------------------------------

[color=red]System Drive C: has 4.18 GiB (less than 15%) free.[/color]


-- HijackThis (run as Gwidon.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:37:23, on 2008-04-15
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
D:\QuickTime\QTSystem\Web Vulnerability Scanner 4\WVSScheduler.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Icecast2 Win32\icecastService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\PSIService.exe
D:\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
D:\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
D:\FRAPS\FRAPS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe
D:\Gadu-Gadu\gg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Winamp\winamp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Documents and Settings\Gwidon\Pulpit\dss.exe
D:\HIJACK~1\Gwidon.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:4001
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Burn4Free Toolbar Helper - {60BF5EE3-0105-4858-AD98-17C19F86B042} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Burn4Free Toolbar - {55FAF0F2-44D4-425F-B5F5-6B275B621EAB} - C:\Program Files\Burn4Free Toolbar\v3.3.0.0\Burn4Free_Toolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-f7ed0776fb27} - c:\program files\steganos internet anonym 2006\sia2006iep.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [CloneCDTray] "D:\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [WinampAgent] D:\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Fraps] D:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AnyDVD] D:\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [GoD] "D:\GoD\GoD.exe" /tray
O4 - HKCU\..\Run: [VS Online] C:\VSOnline.exe /tray
O4 - HKCU\..\Run: [DAEMON Tools] "D:\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [GG Tools] "D:\kRk Software\GG Tools\GGT.exe" /tray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -boot
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SIA2006] "C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Rozmowa.lnk = D:\System syntezy mowy\rozmowy.exe
O4 - Startup: UniSpiker-2.6.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk142YYSE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15-3.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3C05AA5D-E5F8-46B2-B6C9-D075058806A2}: NameServer = 194.204.159.1,194.204.152.34
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Acunetix WVS Scheduler (AcuWVSScheduler) - Acunetix Ltd. - D:\QuickTime\QTSystem\Web Vulnerability Scanner 4\WVSScheduler.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Icecast Media Server (Icecast) - Unknown owner - C:\Program Files\Icecast2 Win32\icecastService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 12532 bytes

-- Files created between 2008-03-15 and 2008-04-15 -----------------------------

2008-04-13 02:26:16         0 d-------- C:\Program Files\Bonjour
2008-04-13 02:20:08         0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-12 07:16:04         0 d-------- C:\Program Files\Secure Surfing Engine
2008-04-12 07:16:00         0 d-------- C:\Program Files\Steganos Internet Anonym 2006
2008-04-10 10:57:41         0 d-------- C:\Program Files\uTorrent
2008-04-10 08:00:10         0 d-------- C:\Program Files\MSECache
2008-04-05 09:15:38         0 d-------- C:\Program Files\Goolag Scanner
2008-04-04 23:42:18      3860 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-04 23:41:53     25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-04 23:41:53    289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-04-04 23:41:53     86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-04-04 23:41:53    288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-04-04 23:41:53     53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-04-04 23:41:53     82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-04 23:41:53     51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-04 23:41:53     82944 --a------ C:\WINDOWS\system32\404Fix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-04 13:24:44         0 d-------- C:\WINDOWS\ERUNT
2008-04-03 12:35:59         0 d-------- C:\Program Files\Common Files\Screaming Bee
2008-04-02 13:07:21         0 d-------- C:\Program Files\Common Files\xing shared
2008-04-02 13:07:06         0 d-------- C:\Program Files\Real
2008-04-02 01:41:32         0 d-------- C:\Documents and Settings\Gwidon\Application Data
2008-04-02 01:41:32         0 d-------- C:\Documents and Settings\Gwidon\Application Data\Syntrillium
2008-04-01 15:35:16         0 d-------- C:\Program Files\Common Files\Reallusion
2008-03-26 10:55:54    233472 --a------ C:\WINDOWS\system32\REX Shared Library.dll <Not Verified; Propellerhead Software AB; REX SDK>
2008-03-26 10:55:54    368640 --a------ C:\WINDOWS\system32\ReWire.dll <Not Verified; Propellerhead Software AB; ReWire>
2008-03-25 00:46:26         0 d-------- C:\WINDOWS\_$MB6Setup_
2008-03-23 06:59:09         0 d-------- C:\Program Files\Common Files\Borland Shared
2008-03-22 03:10:43     29696 --a------ C:\WINDOWS\system32\pthread.dll
2008-03-22 03:10:43     78085 --a------ C:\WINDOWS\system32\pattern.dat
2008-03-22 03:10:43    307200 --a------ C:\WINDOWS\system32\fxstudio.dll
2008-03-22 03:10:43     57344 --a------ C:\WINDOWS\system32\eJ_Capture.dll <Not Verified; eJay AG; PrjCapture>
2008-03-22 03:10:43    147519 --a------ C:\WINDOWS\system32\ej_360VideoFX.dll <Not Verified; eJay AG; PrjVideoFX>
2008-03-22 03:10:43    106496 --a------ C:\WINDOWS\system32\DartWeb.dll <Not Verified; Dart Communications; PowerTCP© Tools>
2008-03-22 03:10:43    159744 --a------ C:\WINDOWS\system32\DartSock.dll <Not Verified; Dart Communications; PowerTCP© Tools>
2008-03-22 03:10:38    280576 --a------ C:\WINDOWS\system32\pxd_kom.dll
2008-03-22 03:10:38     45056 --a------ C:\WINDOWS\system32\fader.dll
2008-03-22 03:10:37     75976 --a------ C:\WINDOWS\system32\BASSDEC.dll
2008-03-21 03:17:13         0 d-------- C:\Program Files\Common Files\Corel
2008-03-21 03:14:36      2516 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-03-21 03:14:36        88 -r-hs---- C:\WINDOWS\system32\8F51133FB5.sys
2008-03-20 05:35:28         0 d-------- C:\Program Files\Jasc Software Inc


-- Find3M Report ---------------------------------------------------------------

2008-04-15 01:30:19         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Skype
2008-04-15 01:30:16         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\skypePM
2008-04-14 13:57:53         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\uTorrent
2008-04-13 09:51:23         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Adobe
2008-04-13 07:51:27         0 d-------- C:\Program Files\Opera
2008-04-13 02:27:13         0 d-------- C:\Program Files\QuickTime
2008-04-13 02:26:14         0 d-------- C:\Program Files\Common Files\Adobe
2008-04-13 00:00:18         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Corel
2008-04-12 07:28:06         0 d-------- C:\Program Files\Java
2008-04-12 05:55:40         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Hide IP NG
2008-04-11 00:14:19         0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-06 08:35:14    475568 --a------ C:\WINDOWS\system32\perfh015.dat
2008-04-06 08:35:14     85368 --a------ C:\WINDOWS\system32\perfc015.dat
2008-04-04 10:31:49       664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-03 12:38:23         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Screaming Bee
2008-04-03 12:35:59         0 d-------- C:\Program Files\Common Files
2008-04-02 13:34:35         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Real
2008-04-02 13:07:18         0 d-------- C:\Program Files\Common Files\Real
2008-04-02 12:44:53         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Canon
2008-04-02 04:28:56         0 d-------- C:\Program Files\Skype
2008-04-02 04:28:10         0 d-------- C:\Program Files\Winamp Remote
2008-04-01 15:42:31         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Reallusion
2008-04-01 15:34:46         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\InstallShield
2008-03-26 10:56:07         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Propellerhead Software
2008-03-21 07:43:21         0 d-------- C:\Program Files\Microsoft Works
2008-03-18 10:55:21         0 d-------- C:\Program Files\Google
2008-03-14 14:02:44         0 d-------- C:\Program Files\Common Files\Skype
2008-03-14 06:54:45         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Macromedia
2008-03-14 06:51:06         0 d-------- C:\Program Files\Common Files\Macromedia Shared
2008-03-14 06:50:08         0 d-------- C:\Program Files\Common Files\Macromedia
2008-02-27 09:28:54         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\Apple Computer
2008-02-24 11:47:22         0 d-------- C:\Documents and Settings\Gwidon\Dane aplikacji\3DFA


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 14:06   1135968   --a------   C:\Program Files\Winamp Toolbar\winamptb.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 14:06 1135968]

[-HKEY_CLASSES_ROOT\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 09:44 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-15 03:20]
"nwiz"="nwiz.exe" [2005-06-15 03:20 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-06-15 03:20]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 03:00]
"OPSE reminder"="C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" [2003-07-07 01:29]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 02:50]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 12:37]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-13 19:43]
"CloneCDTray"="D:\SlySoft\CloneCD\CloneCDTray.exe" []
"WinampAgent"="D:\Winamp\winampa.exe" [2007-10-09 23:28]
"QuickTime Task"="D:\QuickTime\qttask.exe" [2007-10-19 13:16]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-18 10:55]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-02 13:07]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 13:25]
"Fraps"="D:\FRAPS\FRAPS.EXE" [2003-05-18 11:32]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:44]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 11:20]
"AnyDVD"="D:\SlySoft\AnyDVD\AnyDVD.exe" []
"GoD"="D:\GoD\GoD.exe" []
"VS Online"="C:\VSOnline.exe" []
"DAEMON Tools"="D:\DAEMON Tools\daemon.exe" []
"AlcoholAutomount"="D:\Alcohol Soft\Alcohol 52\axcmd.exe" [2007-07-02 04:22]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2007-10-22 18:47]
"GG Tools"="D:\kRk Software\GG Tools\GGT.exe" [2007-09-17 08:25]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 10:26]
"SIA2006"="C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" [2005-11-09 11:35]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe" [2007-04-04 07:41]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"SIA2006"="C:\Program Files\Steganos Internet Anonym 2006\SIA2006.exe" -firstboot

C:\Documents and Settings\Gwidon\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 12:16:50]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL




-- End of Deckard's System Scanner: finished at 2008-04-15 01:37:52 ------------
DareX :]
_Darex_
~user
 
Posty: 16
Dołączenie: 27 Kwi 2008, 09:55



Postprzez Magik 14 Maj 2008, 15:53

Nt, Twojego ostatniego postu


Kod: Zaznacz wszystko
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk142YYSE
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
   O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBIniti alSetup1.0.0.15-3.cab


to wywalasz, poza tym nic starsznego nie widac
Image Image
Awatar użytkownika
Magik
~user
 
Posty: 7956
Dołączenie: 08 Maj 2004, 09:17
Miejscowość: Głogów
Pochwały: 886



Poprzednia

Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 14 gości