10 Paź 2006, 16:02
Logfile of HijackThis v1.99.1
Scan saved at 15:49:40, on 2006-10-10
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesWinRARWinRAR.exe
C:DOCUME~1DOMINI~1USTAWI~1TempRar$EX00.391HijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_08inssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [avast!] D:programsAvast4ashDisp.exe
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.5.0_08injusched.exe"
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [ABBYY Community Agent] C:PROGRA~1SPRINT~1.0OFSprintCAgent.exe
O4 - HKLM..Run: [Ashampoo FireWall] "C:Program FilesAshampooAshampoo FireWallFireWall.exe" -TRAY
O4 - HKLM..Run: [Ashampoo AntiSpyWare Guard] C:Program FilesAshampooAshampoo AntiSpyWareAntiSpyWareGuard.exe
O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot - Search & DestroyTeaTimer.exe
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O10 - Unknown file in Winsock LSP: c:program filesashampooashampoo firewallspi.dll
O10 - Unknown file in Winsock LSP: c:program filesashampooashampoo firewallspi.dll
O10 - Unknown file in Winsock LSP: c:program filesashampooashampoo firewallspi.dll
O10 - Unknown file in Winsock LSP: c:program filesashampooashampoo firewallspi.dll
O10 - Unknown file in Winsock LSP: c:program filesashampooashampoo firewallspi.dll
O10 - Unknown file in Winsock LSP: c:program filesashampooashampoo firewallspi.dll
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.my-etrust.com/Support/PestScanner/pestscan.cab
O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} - http://mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:programsAvast4aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:programsAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:programsAvast4ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:programsAvast4ashWebSv.exe" /service (file missing)
O23 - Service: AVK Service (AVKService) - Unknown owner - C:Program FilesG DATAAntiVirenKit InternetSecurityAVKAVKService.exe (file missing)
O23 - Service: Strażnik AVK (AVKWCtl) - Unknown owner - C:Program FilesG DATAAntiVirenKit InternetSecurityAVKAVKWCtl.exe (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:Program Filesewido anti-spyware 4.0guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32
vsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe10 Paź 2006, 16:09
10 Paź 2006, 17:51
10 Paź 2006, 19:57
10 Paź 2006, 21:12
tornado napisał(a):Hmm ale skoro jest w trybie awaryjnym to on chyba zaduzo tam nie pokaze
11 Paź 2006, 12:52
pp3088 napisał(a):tornado napisał(a):Hmm ale skoro jest w trybie awaryjnym to on chyba zaduzo tam nie pokaze
Właśnie w trybie awaryjnym wirusy mają ograniczone możliwości krycia
11 Paź 2006, 14:59
{HKLM...CLSID} = "Yahoo! Toolbar Helper"
{HKLM...CLSID} = "AcroIEHlprObj Class"
{HKLM...CLSID} = (no title provided)
{HKLM...CLSID} = "SSVHelper Class"
{HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
{HKLM...CLSID} = "HyperTerminal Icon Ext"
{HKLM...CLSID} = "DesktopContext Class"
{HKLM...CLSID} = "Desktop Explorer"
{HKLM...CLSID} = (no title provided)
{HKLM...CLSID} = "nView Desktop Context Menu"
{HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
{HKLM...CLSID} = "avast"
{HKLM...CLSID} = "WinRAR"
{HKLM...CLSID} = "Nokia Phone Browser"
{HKLM...CLSID} = "NVIDIA CPL Extension"
{HKLM...CLSID} = "a-squared Free Context Menu"
{HKLM...CLSID} = "Portable Media Devices Menu"
{HKLM...CLSID} = "CShellExecuteHookImpl Object"
{HKLM...CLSID} = "PDF Shell Extension"
{HKLM...CLSID} = "avast"
{HKLM...CLSID} = "CContextScan Object"
{HKLM...CLSID} = "WinRAR"
{HKLM...CLSID} = "CContextScan Object"
{HKLM...CLSID} = "WinRAR"
{HKLM...CLSID} = "a-squared Free Context Menu"
{HKLM...CLSID} = "avast"
{HKLM...CLSID} = "WinRAR"
{HKLM...CLSID} = "a-squared Free Context Menu"
{HKLM...CLSID} = "Yahoo! Toolbar"
{HKLM...CLSID} = "Yahoo! Toolbar"
11 Paź 2006, 15:47
Note: detected settings may not have any effect.
HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem
"DisableRegistryTools" = (REG_DWORD) hex:0x00000000
{User Configuration|Administrative Templates|System|
Prevent access to registry editing tools}
HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}
11 Paź 2006, 20:39
11 Paź 2006, 20:46
tak wogóle to znasz to, wygląda na syf
11 Paź 2006, 21:06
11 Paź 2006, 21:18
11 Paź 2006, 21:29
11 Paź 2006, 21:38
11 Paź 2006, 21:50
)