1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90. | Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:49:07, on 2009-12-21
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\\WINDOWS\\System32\\smss.exe
C:\\WINDOWS\\system32\\winlogon.exe
C:\\WINDOWS\\system32\\services.exe
C:\\WINDOWS\\system32\\lsass.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\Program Files\\Lavasoft\\Ad-Aware\\AAWService.exe
C:\\WINDOWS\\Explorer.EXE
C:\\WINDOWS\\system32\\spoolsv.exe
C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe
C:\\Program Files\\Lavasoft\\Ad-Aware\\AAWTray.exe
C:\\WINDOWS\\System32\\FTRTSVC.exe
C:\\Program Files\\Vtune\\TBPanel.exe
C:\\WINDOWS\\system32\\nvsvc32.exe
C:\\WINDOWS\\system32\\RUNDLL32.EXE
C:\\WINDOWS\\system32\\PnkBstrA.exe
C:\\WINDOWS\\system32\\PnkBstrB.exe
C:\\WINDOWS\\SOUNDMAN.EXE
C:\\WINDOWS\\system32\\RUNDLL32.EXE
C:\\WINDOWS\\system32\\ctfmon.exe
C:\\Program Files\\AutoConnect\\AutoConnect.exe
C:\\WINDOWS\\system32\\wscntfy.exe
C:\\Program Files\\DNA\\btdna.exe
C:\\Program Files\\DAEMON Tools Lite\\daemon.exe
C:\\WINDOWS\\system32\\rundll32.exe
C:\\Program Files\\Mozilla Firefox\\firefox.exe
C:\\Program Files\\WapSter\\WapSter AQQ\\AQQ.exe
C:\\Program Files\\Trend Micro\\HijackThis\\HijackThis.exe
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://www.ask.com/?o=101764&l=dis
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Window Title = neostrada tp
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\\PROGRA~1\\NEOSTR~1\\SEARCH~1.DLL
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\\Program Files\\AskSearch\\bin\\DefaultSearch.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\\Program Files\\Adobe\\Acrobat 7.0\\ActiveX\\AcroIEHelper.dll
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\\WINDOWS\\system32\\gigagetbho_v10.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\\Program Files\\AskBarDis\\bar\\bin\\askBar.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\\Program Files\\Google\\GoogleToolbarNotifier\\5.1.1309.3572\\swg.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\\Program Files\\AskBarDis\\bar\\bin\\askBar.dll (file missing)
O4 - HKLM\\..\\Run: [SpeedTouch USB Diagnostics] \"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon
O4 - HKLM\\..\\Run: [WOOWATCH] C:\\PROGRA~1\\NEOSTR~1\\Watch.exe
O4 - HKLM\\..\\Run: [RivaTunerStartupDaemon] \"C:\\RivaTuner v2.24\\RivaTuner.exe\" /S
O4 - HKLM\\..\\Run: [Ad-Watch] C:\\Program Files\\Lavasoft\\Ad-Aware\\AAWTray.exe
O4 - HKLM\\..\\Run: [Gigaget] \"C:\\Program Files\\Giganology\\Gigaget\\GigagetShell.exe\" /s
O4 - HKLM\\..\\Run: [Gainward] C:\\Program Files\\Vtune\\TBPanel.exe /A
O4 - HKLM\\..\\Run: [NvCplDaemon] RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup
O4 - HKLM\\..\\Run: [nwiz] nwiz.exe /install
O4 - HKLM\\..\\Run: [NvMediaCenter] RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\\..\\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\\..\\Run: [MS_MASTER] RUNDLL32.EXE C:\\WINDOWS\\system32\\xml_inc.dll,i
O4 - HKCU\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\system32\\ctfmon.exe
O4 - HKCU\\..\\Run: [AutoConnect] C:\\Program Files\\AutoConnect\\AutoConnect.exe
O4 - HKCU\\..\\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] \"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\"
O4 - HKCU\\..\\Run: [cdoosoft] C:\\DOCUME~1\\CYS~1.BLA\\USTAWI~1\\Temp\\herss.exe
O4 - HKCU\\..\\Run: [swg] C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe
O4 - HKCU\\..\\Run: [BitTorrent DNA] \"C:\\Program Files\\DNA\\btdna.exe\"
O4 - HKCU\\..\\Run: [DAEMON Tools Lite] \"C:\\Program Files\\DAEMON Tools Lite\\daemon.exe\" -autorun
O4 - HKCU\\..\\Run: [ALLUpdate] \"C:\\Program Files\\ALLPlayer\\ALLUpdate.exe\" \"sleep\"
O4 - HKCU\\..\\Run: [AQQ] C:\\PROGRA~1\\WapSter\\WAPSTE~1\\AQQ.exe
O4 - HKUS\\S-1-5-19\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\System32\\CTFMON.EXE (User \'USŁUGA LOKALNA\')
O4 - HKUS\\S-1-5-20\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\System32\\CTFMON.EXE (User \'USŁUGA SIECIOWA\')
O4 - HKUS\\S-1-5-18\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\System32\\CTFMON.EXE (User \'SYSTEM\')
O4 - HKUS\\.DEFAULT\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\System32\\CTFMON.EXE (User \'Default user\')
O4 - Startup: OneWay.lnk = C:\\Program Files\\5Fantastic\\OneWay\\OneWay.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\\Program Files\\Microsoft Office\\Office\\OSA9.EXE
O8 - Extra context menu item: &Download All by Gigaget - C:\\Program Files\\Giganology\\Gigaget\\getallurl.htm
O8 - Extra context menu item: &Download by Gigaget - C:\\Program Files\\Giganology\\Gigaget\\geturl.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O9 - Extra \'Tools\' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{826FAE1B-27CD-45BC-AD79-5ABEF5F5A347}: NameServer = 194.204.159.1 194.204.152.34
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\PROGRA~1\\COMMON~1\\Skype\\SKYPE4~1.DLL
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\\WINDOWS\\System32\\FTRTSVC.exe
O23 - Service: Usługa Google Update (gupdate1ca210217f035b0) (gupdate1ca210217f035b0) - Google Inc. - C:\\Program Files\\Google\\Update\\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\\Program Files\\Lavasoft\\Ad-Aware\\AAWService.exe
O23 - Service: NMIndexingService - Unknown owner - C:\\Program Files\\Common Files\\Ahead\\Lib\\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\\WINDOWS\\system32\\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\\WINDOWS\\system32\\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\\WINDOWS\\system32\\PnkBstrB.exe
--
End of file - 6276 bytes |