Logfile of Trend Micro HijackThis v2.0.2Scan saved at 15:14:46, on 2008-07-09Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16674)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\WINDOWS\System32\FTRTSVC.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\PnkBstrA.exeC:\Program Files\Common Files\Protexis\License Service\PSIService.exeD:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exeC:\WINDOWS\RTHDCPL.EXEC:\WINDOWS\system32\RUNDLL32.EXEC:\WINDOWS\system32\rundll32.exeC:\PROGRA~1\Grisoft\AVG7\avgcc.exeC:\Program Files\Common Files\InstallShield\UpdateService\issch.exeD:\Program Files\Winamp\winampa.exeC:\Program Files\Java\jre1.6.0_05\bin\jusched.exeC:\Program Files\Common Files\Onet.pl\AutoUpdate.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Winamp Remote\bin\OrbTray.exeC:\PROGRA~1\NEOSTR~1\TaskBarIcon.exeC:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exeC:\Program Files\Logitech\SetPoint\SetPoint.exeC:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXEC:\WINDOWS\explorer.exeC:\Program Files\neostrada tp\neostradatp.exeC:\Program Files\neostrada tp\ComComp.exeC:\PROGRA~1\NEOSTR~1\Toaster.exeC:\PROGRA~1\NEOSTR~1\Inactivity.exeC:\PROGRA~1\NEOSTR~1\PollingModule.exeC:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXEC:\Program Files\neostrada tp\Watch.exeD:\Program Files\Lavasoft\Ad-Aware\aawservice.exeC:\Program Files\Mozilla Firefox\firefox.exeD:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://www.neostrada.pl"]http://www.neostrada.pl[/url]R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157[/url]R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896[/url]R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896[/url]R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157[/url]R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ŁączaR3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLLO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-781cd0e19f00} - c:\program files\steganos internet anonym pro 7\siapro7iep.dllO4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXEO4 - HKLM\..\Run: [SkyTel] SkyTel.EXEO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exeO4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXEO4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBarO4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUPO4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startupO4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -startO4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp\winampa.exe"O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exeO4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\GestMaj.exe TaskBarIcon.exeO4 - HKLM\..\Run: [Onet.pl AutoUpdate] C:\Program Files\Common Files\Onet.pl\AutoUpdate.exe /tsrO4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\VistaCodecPack\QT\QTTask.exe" -atboottimeO4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [Gadu-Gadu] "D:\Program Files\Gadu-Gadu\gg.exe" /trayO4 - HKCU\..\Run: [AlcoholAutomount] "D:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automountO4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /backgroundO4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'USŁUGA LOKALNA')O4 - HKUS\S-1-5-19\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'USŁUGA LOKALNA')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')O4 - HKUS\S-1-5-20\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'USŁUGA SIECIOWA')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [SIAPRO7] "C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" -firstboot (User 'Default user')O4 - Startup: Registration .LNK = F:\support\Registration.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exeO4 - Global Startup: Logitech SetPoint.lnk = ?O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar\ieToolbar\resources\en-US\local\search.htmlO8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - [url="http://arcaonline.arcabit.com/ArcaOnline.cab"]http://arcaonline.arcabit.com/ArcaOnline.cab[/url]O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - [url="http://www.eset.eu/buxus/docs/programs/OnlineScanner.cab"]http://www.eset.eu/buxus/docs/programs/OnlineScanner.cab[/url]O17 - HKLM\System\CCS\Services\Tcpip\..\{38650B2E-A0E1-461C-B970-9B3C6892642C}: NameServer = 194.204.159.1 217.98.63.164O17 - HKLM\System\CS1\Services\Tcpip\..\{38650B2E-A0E1-461C-B970-9B3C6892642C}: NameServer = 194.204.159.1 217.98.63.164O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dllO23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exeO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - D:\Program Files\Ares\chatServer.exe (file missing)O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exeO23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: NBService - Nero AG - E:\Program files\Nero 7\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exeO23 - Service: FIM Speedway GP3 Drivers Auto Removal (pr2aq6eb) (pr2aq6eb) - Techland Sp.z o.o. - C:\WINDOWS\system32\pr2aq6eb.exeO23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exeO23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exeO23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe--End of file - 9486 bytesComboFix:
ComboFix 08-07-05.1 - Właściciel 2008-07-09 14:45:30.5 - NTFSx86Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.670 [GMT 2:00]Running from: C:\Documents and Settings\Właściciel\Pulpit\Wojtek\ComboFix.exe<strong class='bbc'>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
</strong>.((((((((((((((((((((((((( Files Created from 2008-06-09 to 2008-07-09 ))))))))))))))))))))))))))))))).2008-07-09 12:33 . 2008-07-09 12:34 <DIR> d-------- C:\Program Files\Blocker SP3 XP2008-07-08 00:34 . 2008-07-08 00:34 250 --a------ C:\WINDOWS\gmer.ini2008-06-26 21:59 . 2008-06-26 21:59 <DIR> d-------- C:\Documents and Settings\Właściciel\Dane aplikacji\Winamp2008-06-22 20:47 . 2008-06-22 20:47 <DIR> d-------- C:\Documents and Settings\Właściciel\FileDownloader2008-06-22 20:47 . 2008-06-22 20:47 <DIR> d-------- C:\Documents and Settings\Właściciel\FileDownloader2008-06-22 20:25 . 2008-06-22 20:31 <DIR> d-------- C:\Documents and Settings\Właściciel\Dane aplikacji\Hide IP NG2008-06-22 00:59 . 2008-06-22 00:59 <DIR> d-------- C:\Program Files\Steganos Internet Anonym Pro 72008-06-22 00:59 . 2008-06-22 00:59 <DIR> d-------- C:\Program Files\Secure Surfing Engine2008-06-19 15:55 . 2008-06-19 15:55 <DIR> d-------- C:\Program Files\Apple Software Update2008-06-19 15:55 . 2008-06-19 15:55 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple2008-06-12 06:56 . 2008-06-15 10:07 54,156 --ah----- C:\WINDOWS\QTFont.qfn2008-06-12 06:56 . 2008-06-12 06:56 1,409 --a------ C:\WINDOWS\QTFont.for2008-06-11 19:53 . 2008-06-14 20:01 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys2008-06-11 19:53 . 2008-06-14 20:01 273,024 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys2008-06-09 20:59 . 2008-07-04 01:21 <DIR> d-------- C:\Documents and Settings\Właściciel\Dane aplikacji\gtk-2.02008-06-09 20:59 . 2008-06-09 20:59 <DIR> d-------- C:\Documents and Settings\Właściciel\.thumbnails2008-06-09 20:59 . 2008-06-09 20:59 <DIR> d-------- C:\Documents and Settings\Właściciel\.thumbnails2008-06-09 20:46 . 2008-07-05 22:40 <DIR> d-------- C:\Documents and Settings\Właściciel\.<a href="http://www.download.net.pl/354/GIMP/">gimp</a>-2.42008-06-09 20:46 . 2008-07-05 22:40 <DIR> d-------- C:\Documents and Settings\Właściciel\.<a href="http://www.download.net.pl/354/GIMP/">gimp</a>-2.4.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2008-07-09 12:45 --------- d-----w C:\Program Files\neostrada tp2008-07-09 10:12 --------- d-----w C:\Documents and Settings\Właściciel\Dane aplikacji\AVG72008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys2008-06-09 14:06 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Avg72008-06-08 17:12 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\OrbNetworks2008-06-08 17:11 --------- d-----w C:\Program Files\Winamp Remote2008-05-25 16:58 --------- d-----w C:\Program Files\Common Files\Onet.pl2008-05-25 16:57 --------- d-----w C:\Documents and Settings\Właściciel\Dane aplikacji\Onet2008-05-25 16:57 --------- d-----w C:\Documents and Settings\Właściciel\Dane aplikacji\MozillaControl2008-05-25 16:57 --------- d-----w C:\Documents and Settings\Właściciel\Dane aplikacji\Listonosz2008-05-25 16:57 --------- d-----w C:\Documents and Settings\Właściciel\Dane aplikacji\AutoUpdate2008-05-21 13:08 --------- d-----w C:\Program Files\Google2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll2008-04-23 07:20 826,368 ----a-w C:\WINDOWS\system32\wininet.dll2008-03-15 21:42 88 --sh--r C:\WINDOWS\system32\39785E14CB.sys2008-03-15 21:42 2,516 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys.((((((((((((((((((((((((((((( snapshot@2008-07-07_22.59.42,93 ))))))))))))))))))))))))))))))))))))))))).- 2008-07-07 15:07:28 2,048 --s-a-w C:\WINDOWS\bootstat.dat+ 2008-07-09 11:57:48 2,048 --s-a-w C:\WINDOWS\bootstat.dat+ 2008-07-07 22:34:11 884,736 ----a-w C:\WINDOWS\gmer.dll+ 2008-04-17 19:13:02 811,008 ----a-w C:\WINDOWS\gmer.exe- 2006-03-02 12:00:00 138,496 -c--a-w C:\WINDOWS\system32\dllcache\afd.sys+ 2008-06-20 10:44:38 138,368 -c--a-w C:\WINDOWS\system32\dllcache\afd.sys- 2008-02-20 05:38:07 148,992 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll+ 2008-06-20 17:42:20 148,992 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll- 2006-03-02 12:00:00 246,784 -c--a-w C:\WINDOWS\system32\dllcache\mswsock.dll+ 2008-06-20 17:42:21 246,784 -c--a-w C:\WINDOWS\system32\dllcache\mswsock.dll- 2007-10-30 17:20:55 360,064 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys+ 2008-06-20 10:45:13 360,320 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys- 2006-08-16 09:37:30 225,664 -c--a-w C:\WINDOWS\system32\dllcache\tcpip6.sys+ 2008-06-20 09:52:06 225,920 -c--a-w C:\WINDOWS\system32\dllcache\tcpip6.sys- 2008-02-20 05:38:07 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll+ 2008-06-20 17:42:20 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll+ 2008-07-07 22:34:11 85,969 ----a-w C:\WINDOWS\system32\drivers\gmer.sys- 2008-05-29 23:35:11 17,486,968 ----a-w C:\WINDOWS\system32\MRT.exe+ 2008-06-25 16:15:46 17,972,344 ----a-w C:\WINDOWS\system32\MRT.exe- 2007-11-30 11:21:28 19,320 ------w C:\WINDOWS\system32\spmsg.dll+ 2007-11-30 12:40:46 19,320 ------w C:\WINDOWS\system32\spmsg.dll.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]"Gadu-Gadu"="D:\Program Files\Gadu-Gadu\gg.exe" [2007-07-09 09:39 2119104]"AlcoholAutomount"="D:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" [2007-07-02 12:22 219008]"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-04-01 03:54 507904][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 13:26 7700480]"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 13:26 86016]"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 16:49 77824]"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-15 17:23 579584]"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 16:15 221184]"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 16:15 81920]"WinampAgent"="D:\Program Files\Winamp\winampa.exe" [2008-04-01 20:49 36352]"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2004-08-23 14:49 20480]"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\GestMaj.exe" [2004-10-14 16:55 32768]"Onet.pl AutoUpdate"="C:\Program Files\Common Files\Onet.pl\AutoUpdate.exe" [2006-02-08 16:40 260096]"QuickTime Task"="D:\Program Files\VistaCodecPack\QT\QTTask.exe" [2008-05-27 10:50 413696]"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 05:49 16269312 C:\WINDOWS\RTHDCPL.exe]"SkyTel"="SkyTel.EXE" [2006-05-16 04:04 2879488 C:\WINDOWS\SkyTel.exe]"nwiz"="nwiz.exe" [2007-04-19 13:26 1626112 C:\WINDOWS\system32\nwiz.exe]"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]"AdslTaskBar"="stmctrl.dll" [2006-06-02 11:01 151552 C:\WINDOWS\system32\stmctrl.dll][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 15:19 219136][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"SIAPRO7"="C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe" [2005-07-20 14:05 274432]C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 07:05:26 29696]Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-07-31 16:32:40 67128]Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-07-31 16:32:03 688128][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]"msacm.avis"= ff_acm.acm[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]@=""[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusOverride"=dword:00000001[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="D:\\Program Files\\Gadu-Gadu\\gg.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="D:\\Program Files\\EA Sports\\FIFA 08\\FIFA08.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe"="C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"="D:\\Program Files\\Techland\\FIM Speedway GP3\\sgp3.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"8461:TCP"= 8461:TCP:GoD High Port"8462:TCP"= 8462:TCP:GoD Low Port"11510:TCP"= 11510:TCP:BitComet 11510 TCP"11510:UDP"= 11510:UDP:BitComet 11510 UDPR0 pe3aq6eb;FIM Speedway GP3 Environment Driver (pe3aq6eb);C:\WINDOWS\system32\drivers\pe3aq6eb.sys [2008-04-03 09:36]R0 ps7aq6eb;FIM Speedway GP3 Synchronization Driver (ps7aq6eb);C:\WINDOWS\system32\drivers\ps7aq6eb.sys [2008-04-03 09:35]R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2005-10-13 15:46]R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2003-08-12 14:51]R3 TaurusUsb;ADSL Modem USB Service;C:\WINDOWS\system32\DRIVERS\torususb.sys [2006-05-25 15:28]S2 pr2aq6eb;FIM Speedway GP3 Drivers Auto Removal (pr2aq6eb);C:\WINDOWS\system32\pr2aq6eb.exe svc []S3 {DEF85C80-216A-43ab-AF70-1665EDBE2780};{DEF85C80-216A-43ab-AF70-1665EDBE2780};C:\WINDOWS\TEMP\1EB.tmp []*Newly Created Service* - CATCHME.Contents of the 'Scheduled Tasks' folder"2008-07-02 20:02:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"- C:\Program Files\Apple Software Update\SoftwareUpdate.exe.**************************************************************************catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url="http://www.gmer.net"]http://www.gmer.net[/url]Rootkit scan 2008-07-09 14:46:50Windows 5.1.2600 Dodatek Service Pack 2 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}]"ImagePath"="\??\C:\WINDOWS\TEMP\1EB.tmp".--------------------- DLLs Loaded Under Running Processes ---------------------PROCESS: C:\WINDOWS\system32\lsass.exe-> C:\Program Files\Secure Surfing Engine\sselsp.dll.Completion time: 2008-07-09 14:47:57ComboFix-quarantined-files.txt 2008-07-09 12:47:53ComboFix2.txt 2008-07-07 22:29:25ComboFix3.txt 2008-07-07 22:22:24ComboFix4.txt 2008-07-07 21:02:58ComboFix5.txt 2008-07-07 20:59:55Pre-Run: 16,636,473,344 bajtów wolnychPost-Run: 16,627,466,240 bajtów wolnych174 --- E O F --- 2008-07-09 10:34:36Z góry dziękuję za odpowiedzi




Moja zawartość
Nie podano

