
Ostatnio komputer się zawiesza, wyskakuję BSOD z informacja o sterowniku usbport.sys albo imapi.sys. Skanowałem KAV 2009 - czysto. Przeinstalowywałem sterowniki USB i dalej jest to samo. Nie wiem co robić. Daje logi z HijackThis i GMER'a. Poza tym, miałem włamanie na pocztę, hasło trudne do zgadnięcia wiec myślę że, jest to jakiś haker co umieścił rootkit i teraz się ze mną bawi.
GMER
- Kod: Zaznacz wszystko
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-07-04 23:20:09
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwAdjustPrivilegesToken [0xF011FAB2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwClose [0xF011FF84]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwConnectPort [0xF012171E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateFile [0xF012116A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateKey [0xF011F4EE]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreatePagingFile [0xF7312A20]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xF0122E52]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateThread [0xF011FDAE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeleteKey [0xF011F82A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeleteValueKey [0xF011F9C8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeviceIoControlFile [0xF0121438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDuplicateObject [0xF012327C]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateKey [0xF73132A8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateValueKey [0xF731E910]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwFsControlFile [0xF012132C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwLoadDriver [0xF01229C4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenFile [0xF0120FC6]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwOpenKey [0xF731E794]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenProcess [0xF011FBD6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenSection [0xF0122E7C]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryKey [0xF73132C8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryMultipleValueKey [0xF011F8EA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryValueKey [0xF011F72A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueueApcThread [0xF0122BFA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwReplaceKey [0xF011F1BE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwRequestWaitReplyPort [0xF0121EB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwRestoreKey [0xF011F320]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwResumeThread [0xF012315A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSaveKey [0xF011F010]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSecureConnectPort [0xF01215EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetContextThread [0xF011FEAC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetSecurityObject [0xF0122A8C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetSystemInformation [0xF0122EA6]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwSetSystemPowerState [0xF731E0B0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetValueKey [0xF011F60C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSuspendProcess [0xF0122F54]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSuspendThread [0xF0123038]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSystemDebugControl [0xF0122936]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwTerminateProcess [0xF011FC7E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwWriteVirtualMemory [0xF011FCF0]
INT 0x63 ? 86CECBF8
INT 0x73 ? 86F69BF8
INT 0x73 ? 86F69BF8
INT 0x73 ? 86FDABF8
INT 0x73 ? 86CECBF8
INT 0x73 ? 86F69BF8
INT 0x83 ? 86CECBF8
INT 0x94 ? 86CECBF8
INT 0xB4 ? 86CECBF8
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.14 ----
.text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804EAE40 5 Bytes JMP F01334E0 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab)
.text ntkrnlpa.exe!IoIsOperationSynchronous 804EF634 5 Bytes JMP F013389A \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab)
.text ntkrnlpa.exe!ZwCallbackReturn + 2E6E 80503A6E 6 Bytes [ 12, F0, 10, F0, 11, F0 ]
.text ntkrnlpa.exe!ZwCallbackReturn + 2F28 80503B28 5 Bytes [ 54, 2F, 12, F0, 38 ]
.text ntkrnlpa.exe!ZwCallbackReturn + 2F2E 80503B2E 6 Bytes [ 12, F0, 36, 29, 12, F0 ]
? spuk.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F6A6B62C 5 Bytes JMP 86CEC1D8
---- User code sections - GMER 1.0.14 ----
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[376] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[376] USER32.dll!VRipOutput + FFFA5010 77D42A78 4 Bytes [ 70, 11, 41, 35 ]
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1880] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1880] USER32.dll!VRipOutput + FFFA5010 77D42A78 4 Bytes [ 70, 11, 41, 35 ]
.text C:\Program Files\Tibia\Tibia.exe[3884] kernel32.dll!LoadLibraryExW + C4 7C801BB5 4 Bytes [ 47, E4, 60, 87 ]
.text C:\Program Files\Tibia\Tibia.exe[3884] USER32.dll!GetMessageA 77D6EA45 6 Bytes JMP 5F040F5A
.text C:\Program Files\Tibia\Tibia.exe[3884] WS2_32.dll!connect 71AB406A 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Tibia\Tibia.exe[3884] WS2_32.dll!send 71AB428A 6 Bytes JMP 5F0A0F5A
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7351040] spuk.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F735113C] spuk.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73510BE] spuk.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73517FC] spuk.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73516D2] spuk.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F7361048] spuk.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] 864C9DC0
IAT \SystemRoot\system32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] 864C9DC0
---- User IAT/EAT - GMER 1.0.14 ----
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] 01120D60
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] 01120A50
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 01119540
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 0111AA80
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CloseHandle] 0111DBF0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 0111B7D0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 0111ADB0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileW] 0111CF30
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalUnlock] 0111FF30
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalLock] 0111FF70
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcessHeap] 011210B0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] 0111FB20
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DuplicateHandle] 0111DB50
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] 0111C2F0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 0111B480
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW] 0111BD70
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent] 01121630
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!ReadFile] 0111D280
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetFilePointer] 0111D9B0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx] 0111E5E0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW] 0111E0C0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!MapViewOfFile] 0111E560
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW] 0111F080
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile] 0111E750
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] 0111B130
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!TerminateProcess] 0111C1A0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GlobalAlloc] 01120050
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile] 0111E200
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileSize] 0111DAF0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!WriteFile] 0111D6B0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileType] 0111DD00
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetACP] 011210D0
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileMappingA] 0111E000
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadIconW] 01121370
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadCursorW] 01121310
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateDialogParamW] 01121560
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DialogBoxParamW] 01121600
IAT C:\Program Files\TibiaBot NG\loader.exe[3520] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!LoadStringW] 01121430
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 86F671F8
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
Device \Driver\usbuhci \Device\USBPDO-0 86CEB1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86FD81F8
Device \Driver\dmio \Device\DmControl\DmConfig 86FD81F8
Device \Driver\dmio \Device\DmControl\DmPnP 86FD81F8
Device \Driver\dmio \Device\DmControl\DmInfo 86FD81F8
Device \Driver\usbuhci \Device\USBPDO-1 86CEB1F8
Device \Driver\usbehci \Device\USBPDO-2 86CDD500
Device \Driver\usbuhci \Device\USBPDO-3 86CEB1F8
Device \Driver\usbuhci \Device\USBPDO-4 86CEB1F8
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
Device \Driver\usbuhci \Device\USBPDO-5 86CEB1F8
Device \Driver\usbehci \Device\USBPDO-6 86CDD500
Device \Driver\Ftdisk \Device\HarddiskVolume1 86F6A1F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 86F6A1F8
Device \Driver\Cdrom \Device\CdRom0 86BA0318
Device \FileSystem\Rdbss \Device\FsWrap 869DB310
Device \Driver\atapi \Device\Ide\IdePort0 86F691F8
Device \Driver\atapi \Device\Ide\IdePort1 86F691F8
Device \Driver\atapi \Device\Ide\IdePort2 86F691F8
Device \Driver\atapi \Device\Ide\IdePort3 86F691F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 864863D8
Device \Driver\NetBT \Device\NetBT_Tcpip_{1975B402-0703-43DD-A370-FCCA23519F54} 864863D8
Device \FileSystem\Srv \Device\LanmanServer 86DB3278
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
Device \Driver\usbuhci \Device\USBFDO-0 86CEB1F8
Device \Driver\usbuhci \Device\USBFDO-1 86CEB1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 864A91F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 869D4DF0
Device \Driver\usbehci \Device\USBFDO-2 86CDD500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 864A91F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 869D4DF0
Device \Driver\usbuhci \Device\USBFDO-3 86CEB1F8
Device \FileSystem\Npfs \Device\NamedPipe 86A9FC28
Device \Driver\usbuhci \Device\USBFDO-4 86CEB1F8
Device \Driver\Ftdisk \Device\FtControl 86F6A1F8
Device \FileSystem\Msfs \Device\Mailslot 86AD8980
Device \Driver\usbuhci \Device\USBFDO-5 86CEB1F8
Device \Driver\usbehci \Device\USBFDO-6 86CDD500
Device \Driver\NetBT \Device\NetBT_Tcpip_{AFCA640A-15BF-4F85-B678-F01041D8A306} 864863D8
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target0Lun0 86B9EAE8
Device \Driver\JRAID \Device\Scsi\JRAID1 86B9EAE8
Device \Driver\JRAID \Device\Scsi\JRAID1Port4Path0Target1Lun0 86B9EAE8
Device \Driver\d347prt \Device\Scsi\d347prt1 86F681F8
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 869D43B0
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 869D43B0
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 869D43B0
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 869D43B0
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 869D43B0
Device \FileSystem\Cdfs \Cdfs 86371500
---- Threads - GMER 1.0.14 ----
Thread 4:640 865057D0
Thread 4:644 865057D0
Thread 4:648 864D6EB0
Thread 4:652 864D6EB0
Thread 4:656 864D6EB0
Thread 4:2616 86076E60
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@khjeh 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x90 0x48 0xCF 0xDF ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x90 0x48 0xCF 0xDF ...
---- EOF - GMER 1.0.14 ----
HIJACKTHIS
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:24:52, on 2008-07-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
c:\program files\freecall.com\freecall\freecall.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Pawel\LOCALS~1\Temp\Rar$EX00.250\gmer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [FreeCall] "c:\program files\freecall.com\freecall\freecall.exe" -nosplash -minimized
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Dodaj do listy blokowanych banerów - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Statystyki ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1975B402-0703-43DD-A370-FCCA23519F54}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CS2\Services\Tcpip\..\{1975B402-0703-43DD-A370-FCCA23519F54}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CS3\Services\Tcpip\..\{1975B402-0703-43DD-A370-FCCA23519F54}: NameServer = 194.204.159.1 217.98.63.164
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Kaspersky Internet Security (avp) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5067 bytes
Z góry dziękuję za pomoc.