sek.
Dodano po 1 [minuty]: Logfile of HijackThis v1.99.0
Scan saved at 16:51:56, on 2005-02-08
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\NORTON~1\NORTON~2\GHOSTS~2.EXE
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
G:\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
G:\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
G:\OUTPOS~1\outpost.exe
G:\NORTON~1\SPEEDD~1\nopdb.exe
D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
G:\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
D:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
D:\Program Files\PCI Audio Applications\Mixer.exe
D:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
D:\Program Files\HP\hpcoretech\hpcmpmgr.exe
D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
D:\Program Files\E-Color\Registration\SonnReg.exe
G:\Winamp3\winampa.exe
D:\Program Files\Parallel Tasking\ptask.exe
D:\Program Files\ISTsvc\istsvc.exe
D:\Program Files\Internet Optimizer\optimize.exe
D:\WINDOWS\plcqvifi.exe
C:\Program Files\Vxengf\Pgmpp.exe
D:\Program Files\webHancer\Programs\whSurvey.exe
C:\program files\n-case\msbb.exe
D:\Program Files\webHancer\Programs\whAgent.exe
D:\WINDOWS\system32\hiden.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\E-Color\Colorific\hgcctl95.exe
D:\Program Files\E-Color\E-Color Indicator\TICIcon.exe
D:\Program Files\Internet Optimizer\actalert.exe
G:\WinExit\WinExit.exe
D:\Documents and Settings\Tomek\Pulpit\hijackthis\HijackThis.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
G:\Gadu-Gadu 6.1\gg.exe
G:\Winamp3\winamp3.exe
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - D:\WINDOWS\nem220.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - G:\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - D:\Program Files\webHancer\programs\whiehlpr.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - G:\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "D:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] G:\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [EM_EXEC] D:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [C-Media Mixer] D:\Program Files\PCI Audio Applications\Mixer.exe /startup
O4 - HKLM\..\Run: [HP Software Update] "D:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "D:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [E-Color Registration] D:\Program Files\E-Color\Registration\SonnReg.exe
O4 - HKLM\..\Run: [WinampAgent] "G:\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [CloneCDTray] "G:\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Parallel Tasking] D:\Program Files\Parallel Tasking\ptask.exe
O4 - HKLM\..\Run: [IST Service] D:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [EV8Y] D:\WINDOWS\plcqvifi.exe
O4 - HKLM\..\Run: [Internet Optimizer] "D:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [-
] D:\WINDOWS\plcqvifi.exe
O4 - HKLM\..\Run: [Outpost Firewall] G:\OUTPOS~1\outpost.exe /waitservice
O4 - HKLM\..\Run: [Xkjlj] C:\Program Files\Vxengf\Pgmpp.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] "D:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [msbb] c:\program files\n-case\msbb.exe
O4 - HKLM\..\Run: [webHancer Agent] "D:\Program Files\webHancer\Programs\whAgent.exe"
O4 - HKLM\..\Run: [wtgzmp] D:\WINNT\wtgzmp.exe
O4 - HKLM\..\Run: [EV8Ý9żĚ*ú]Mú*ŔaîžaaD:\Program Files\ISTsvc\istsvc.exe] D:\WINDOWS\plcqvifi.exe
O4 - HKLM\..\Run: [hiden.exe] hiden.exe
O4 - HKLM\..\Run: [zSPGuard] g:\spguard\spguard.exe /s /r
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Gadu-Gadu] "G:\Gadu-Gadu 6.1\gg.exe" /tray
O4 - Startup: WinExit.lnk = G:\WinExit\WinExit2Tray.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: E-Color.lnk = D:\Program Files\E-Color\Registration\SonnReg.exe
O4 - Global Startup: 3Deep.lnk = D:\Program Files\E-Color\3Deep\3Deepctl.exe
O4 - Global Startup: Colorific.lnk = D:\Program Files\E-Color\Colorific\hgcctl95.exe
O4 - Global Startup: E-Color Indicator.lnk = D:\Program Files\E-Color\E-Color Indicator\TICIcon.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://G:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - G:\OUTPOS~1\TRASH.EXE (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - G:\OUTPOS~1\TRASH.EXE (HKCU)
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O16 - DPF: komentator -
http://sport.onet.pl/komentator.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8997C9F3-16B5-4986-894D-DF448850C840}: NameServer = 194.204.159.1 194.204.152.34
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - D:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: Symantec Event Manager - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - G:\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Usługa Auto-Protect w programie Norton AntiVirus - Symantec Corporation - G:\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - G:\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Outpost Firewall Service - Agnitum - G:\OUTPOS~1\outpost.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - G:\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe