1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73. | Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:59:52, on 2009-02-05
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\\WINDOWS\\System32\\smss.exe
C:\\WINDOWS\\system32\\winlogon.exe
C:\\WINDOWS\\system32\\services.exe
C:\\WINDOWS\\system32\\lsass.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\WINDOWS\\Explorer.EXE
C:\\WINDOWS\\system32\\spoolsv.exe
C:\\WINDOWS\\system32\\RunDll32.exe
E:\\Winamp\\winampa.exe
C:\\Program Files\\COMODO\\SafeSurf\\cssurf.exe
E:\\Comodo\\Firewall\\cfp.exe
C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe
C:\\WINDOWS\\system32\\ctfmon.exe
C:\\PROGRA~1\\Grisoft\\AVG7\\avgamsvr.exe
C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe
C:\\PROGRA~1\\Grisoft\\AVG7\\avgupsvc.exe
C:\\PROGRA~1\\Grisoft\\AVG7\\avgemc.exe
E:\\Comodo\\Firewall\\cmdagent.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\system32\\wscntfy.exe
C:\\Program Files\\Gadu-Gadu\\gg.exe
C:\\Program Files\\Mozilla Firefox\\firefox.exe
D:\\Program Files\\Trend Micro\\HijackThis\\HijackThis.exe
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://www.comodo.com/search/
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\\Program Files\\Winamp Toolbar\\winamptb.dll
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\\Program Files\\AskSBar\\SrchAstt\\1.bin\\A2SRCHAS.DLL
F2 - REG:system.ini: UserInit=C:\\WINDOWS\\system32\\userinit.exe,userinit.exe
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\\Program Files\\AskSBar\\SrchAstt\\1.bin\\A2SRCHAS.DLL
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\\Program Files\\Winamp Toolbar\\winamptb.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\\Program Files\\AskSBar\\bar\\1.bin\\ASKSBAR.DLL
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\\Program Files\\Winamp Toolbar\\winamptb.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\\Program Files\\AskSBar\\bar\\1.bin\\ASKSBAR.DLL
O4 - HKLM\\..\\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\\..\\Run: [WinampAgent] E:\\Winamp\\winampa.exe
O4 - HKLM\\..\\Run: [COMODO SafeSurf] \"C:\\Program Files\\COMODO\\SafeSurf\\cssurf.exe\" -s
O4 - HKLM\\..\\Run: [COMODO Firewall Pro] \"E:\\Comodo\\Firewall\\cfp.exe\" -h
O4 - HKLM\\..\\Run: [COMODO Internet Security] \"E:\\Comodo\\Firewall\\cfp.exe\" -h
O4 - HKLM\\..\\Run: [AVG7_CC] C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP
O4 - HKLM\\..\\Run: [NeroFilterCheck] C:\\WINDOWS\\system32\\NeroCheck.exe
O4 - HKCU\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\system32\\ctfmon.exe
O4 - HKCU\\..\\Run: [ALLUpdate] \"E:\\ALLPlayer\\ALLUpdate.exe\" \"sleep\"
O4 - HKCU\\..\\Run: [Orb] \"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe\" /background
O4 - HKUS\\S-1-5-19\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\system32\\CTFMON.EXE (User \'USŁUGA LOKALNA\')
O4 - HKUS\\S-1-5-19\\..\\Run: [AVG7_Run] C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE (User \'USŁUGA LOKALNA\')
O4 - HKUS\\S-1-5-20\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\system32\\CTFMON.EXE (User \'USŁUGA SIECIOWA\')
O4 - HKUS\\S-1-5-18\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\system32\\CTFMON.EXE (User \'SYSTEM\')
O4 - HKUS\\.DEFAULT\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\system32\\CTFMON.EXE (User \'Default user\')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\\MICROS~1\\OFFICE11\\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\\MICROS~1\\OFFICE11\\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O9 - Extra \'Tools\' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\PROGRA~1\\COMMON~1\\Skype\\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\\WINDOWS\\system32\\guard32.dll C:\\WINDOWS\\system32\\cssdll32.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\aspnet_state.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\\PROGRA~1\\Grisoft\\AVG7\\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\\PROGRA~1\\Grisoft\\AVG7\\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\\PROGRA~1\\Grisoft\\AVG7\\avgemc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - E:\\Comodo\\Firewall\\cmdagent.exe
O23 - Service: mysql - Unknown owner - D:\\XAmpp\\xampplite\\mysql\\bin\\mysqld-nt.exe (file missing)
--
End of file - 4745 bytes
|