1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114. | Logfile of HijackThis v1.99.1
Scan saved at 23:39:17, on 2009-12-05
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\\windows\\System32\\smss.exe
C:\\windows\\system32\\winlogon.exe
C:\\windows\\system32\\services.exe
C:\\windows\\system32\\lsass.exe
C:\\windows\\system32\\svchost.exe
C:\\windows\\System32\\svchost.exe
C:\\windows\\Explorer.EXE
C:\\Program Files\\Alwil Software\\Avast4\\aswUpdSv.exe
C:\\Program Files\\Alwil Software\\Avast4\\ashServ.exe
C:\\windows\\system32\\spoolsv.exe
C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe
C:\\Program Files\\IVT Corporation\\BlueSoleil\\BTNtService.exe
C:\\Program Files\\Bonjour\\mDNSResponder.exe
C:\\windows\\system32\\FsUsbExService.Exe
C:\\Program Files\\Java\\jre6\\bin\\jqs.exe
C:\\windows\\system32\\svchost.exe
C:\\Program Files\\Alwil Software\\Avast4\\ashMaiSv.exe
C:\\Program Files\\Alwil Software\\Avast4\\ashWebSv.exe
C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe
C:\\windows\\RTHDCPL.EXE
C:\\Program Files\\CyberLink DVD Solution\\PowerDVD\\PDVDServ.exe
C:\\PROGRA~1\\LAUNCH~1\\LManager.exe
C:\\windows\\system32\\spool\\drivers\\w32x86\\3\\hpztsb09.exe
C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe
C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe
C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpotdd01.exe
C:\\Program Files\\Common Files\\Onet.pl\\AutoUpdate.exe
C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe
C:\\Program Files\\Java\\jre6\\bin\\jusched.exe
C:\\windows\\system32\\ctfmon.exe
C:\\Program Files\\CursorXP\\CursorXP.exe
C:\\Program Files\\Messenger\\msmsgs.exe
C:\\Program Files\\Samsung\\Samsung New PC Studio\\NPSAgent.exe
C:\\Program Files\\SAGEM\\SAGEM F@st 800-840\\dslmon.exe
C:\\WINDOWS\\BricoPacks\\Vista Inspirat 2\\RocketDock\\RocketDock.exe
C:\\DOCUME~1\\ADMINI~1\\USTAWI~1\\Temp\\RtkBtMnt.exe
C:\\WINDOWS\\system32\\wbem\\wmiapsrv.exe
C:\\WINDOWS\\system32\\wbem\\unsecapp.exe
C:\\Program Files\\Opera\\opera.exe
C:\\Program Files\\Gadu-Gadu 10\\spellchecker_gg.exe
C:\\Program Files\\Java\\jre6\\bin\\jucheck.exe
C:\\Program Files\\Winamp\\winamp.exe
C:\\Program Files\\PC Connectivity Solution\\ServiceLayer.exe
C:\\Program Files\\PC Connectivity Solution\\Transports\\NclUSBSrv.exe
C:\\Program Files\\PC Connectivity Solution\\Transports\\NclRSSrv.exe
C:\\Program Files\\RelevantKnowledge\\rlvknlg.exe
C:\\Program Files\\Gadu-Gadu 10\\gg.exe
C:\\WINDOWS\\system32\\igfxsrvc.exe
C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE
C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE
C:\\Program Files\\hijackthis\\HijackThis.exe
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://www.wyborcza.pl/0,0.html?p=016
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://www.wyborcza.pl/0,0.html?p=016
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Local Page =
R1 - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings,ProxyOverride = *.local
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\\Program Files\\Adobe\\Acrobat 5.0\\Reader\\ActiveX\\AcroIEHelper.ocx
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files\\Java\\jre6\\bin\\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\\Program Files\\Java\\jre6\\lib\\deploy\\jqs\\ie\\jqs_plugin.dll
O2 - BHO: Loader Class - {F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} - (no file)
O4 - HKLM\\..\\Run: [SynTPEnh] C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe
O4 - HKLM\\..\\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\\..\\Run: [RemoteControl] \"C:\\Program Files\\CyberLink DVD Solution\\PowerDVD\\PDVDServ.exe\"
O4 - HKLM\\..\\Run: [IgfxTray] C:\\WINDOWS\\system32\\igfxtray.exe
O4 - HKLM\\..\\Run: [HotKeysCmds] C:\\WINDOWS\\system32\\hkcmd.exe
O4 - HKLM\\..\\Run: [Persistence] C:\\WINDOWS\\system32\\igfxpers.exe
O4 - HKLM\\..\\Run: [LManager] C:\\PROGRA~1\\LAUNCH~1\\LManager.exe
O4 - HKLM\\..\\Run: [HPDJ Taskbar Utility] C:\\windows\\system32\\spool\\drivers\\w32x86\\3\\hpztsb09.exe
O4 - HKLM\\..\\Run: [HP Software Update] \"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe\"
O4 - HKLM\\..\\Run: [HP Component Manager] \"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"
O4 - HKLM\\..\\Run: [DeviceDiscovery] C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpotdd01.exe
O4 - HKLM\\..\\Run: [Onet.pl AutoUpdate] C:\\Program Files\\Common Files\\Onet.pl\\AutoUpdate.exe /tsr
O4 - HKLM\\..\\Run: [avast!] C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe
O4 - HKLM\\..\\Run: [SunJavaUpdateSched] \"C:\\Program Files\\Java\\jre6\\bin\\jusched.exe\"
O4 - HKCU\\..\\Run: [CTFMON.EXE] C:\\windows\\system32\\ctfmon.exe
O4 - HKCU\\..\\Run: [PowerBar] \"C:\\Program Files\\CyberLink DVD Solution\\Multimedia Launcher\\PowerBar.exe\" /AtBootTime
O4 - HKCU\\..\\Run: [CursorXP] \"C:\\Program Files\\CursorXP\\CursorXP.exe\" -s
O4 - HKCU\\..\\Run: [MSMSGS] \"C:\\Program Files\\Messenger\\msmsgs.exe\" /background
O4 - HKCU\\..\\Run: [AutoStartNPSAgent] C:\\Program Files\\Samsung\\Samsung New PC Studio\\NPSAgent.exe
O4 - Startup: Adobe Gamma.lnk = C:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe
O4 - Startup: Rejestrowanie produktów Corela.lnk = C:\\Program Files\\Corel\\Graphics9\\Register\\Remind32.exe
O4 - Startup: RocketDock.lnk = C:\\WINDOWS\\BricoPacks\\Vista Inspirat 2\\RocketDock\\RocketDock.exe
O4 - Global Startup: DSLMON.lnk = C:\\Program Files\\SAGEM\\SAGEM F@st 800-840\\dslmon.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\\PROGRA~1\\MICROS~1\\OFFICE11\\EXCEL.EXE/3000
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\PROGRA~1\\MICROS~1\\OFFICE11\\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O9 - Extra \'Tools\' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\\program files\\bonjour\\mdnsnsp.dll
O12 - Plugin for .spop: C:\\Program Files\\Internet Explorer\\Plugins\\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: igfxcui - C:\\windows\\SYSTEM32\\igfxdev.dll
O20 - Winlogon Notify: RelevantKnowledge - C:\\Program Files\\RelevantKnowledge\\rlls.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\\Program Files\\Common Files\\Adobe Systems Shared\\Service\\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\\Program Files\\Alwil Software\\Avast4\\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\\Program Files\\Alwil Software\\Avast4\\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\\Program Files\\Alwil Software\\Avast4\\ashMaiSv.exe\" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\\Program Files\\Alwil Software\\Avast4\\ashWebSv.exe\" /service (file missing)
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\\Program Files\\IVT Corporation\\BlueSoleil\\BTNtService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\\Program Files\\Bonjour\\mDNSResponder.exe
O23 - Service: FsUsbExService - Teruten - C:\\windows\\system32\\FsUsbExService.Exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\\Program Files\\Common Files\\InstallShield\\Driver\\11\\Intel 32\\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\\Program Files\\Java\\jre6\\bin\\jqs.exe\" -service -config \"C:\\Program Files\\Java\\jre6\\lib\\deploy\\jqs\\jqs.conf (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\\Program Files\\PC Connectivity Solution\\ServiceLayer.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\\windows\\system32\\DRIVERS\\xaudio.exe
|