Logfile of HijackThis v1.99.1
Scan saved at 15:48:17, on 2007-07-18
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\MKS\Bin\NetMonSV.exe
C:\WINNT\system32\CTsvcCDA.exe
C:\Program Files\MKS\Bin\mksmonsv.exe
C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\CTHELPER.EXE
C:\Program Files\MKS\Bin\mks_menu.exe
C:\Program Files\MKS\Bin\ABregmon.exe
C:\Program Files\Topro\tppoll.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\AutoConnect\AutoConnect.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\MKS\Bin\mks_scan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Megaupload\Mega Manager\MegaManager.exe
C:\Documents and Settings\IBM\Pulpit\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: MEGAUPLOADTOOLBAR - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O3 - Toolbar: MEGAUPLOADTOOLBAR - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall\outpost.exe /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe
O4 - HKLM\..\Run: [ABREGMON] C:\Program Files\MKS\Bin\ABregmon.exe
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINNT\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [tppoll] C:\Program Files\Topro\tppoll.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [AutoConnect] C:\Program Files\AutoConnect\AutoConnect.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Szybkie dostosowywanie programu Outpost Firewall Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: www.atshield.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{82E5F248-4E51-460F-8055-1EEA1600DB2A}: NameServer = 194.204.159.1 217.98.63.164
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Agnitum\OUTPOS~1\wl_hook.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. - C:\Program Files\MKS\Bin\NetMonSV.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxcg_device - Unknown owner - C:\WINNT\system32\lxcgcoms.exe
O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:\Program Files\MKS\bin\MkSUpdateInt.exe
O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe
O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS\Bin\mks_scan.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
W logu jest czysto,daj jeszcze ComboFix i SilentRunners.
Jakie problemy występują?
Kiedy klikam na ikone w celu otworzenia Firefoxa muszę czekać około 5 minut aż się internetowa stronka otworzy.
Złączono Posta : 18.07.2007 (Sro) 16:22
LOG COMBOFIX
"IBM" - 2007-07-18 16:13:37 - ComboFix 07-07-14.6 - Dodatek Service Pack 2 NTFS
Popraw tytuł na konkretny.
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 07:57:12 2007-07-19
+ Scan result:
:mozilla.34:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.35:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.36:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.37:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.49:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\IBM\Cookies\ibm@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.45:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Clickhype : No action taken.
:mozilla.38:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.39:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.40:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.68:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.69:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.6:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Netflame : No action taken.
:mozilla.46:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.50:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.51:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.102:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.27:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Yadro : No action taken.
:mozilla.41:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.42:C:\Documents and Settings\IBM\Dane aplikacji\Mozilla\Firefox\Profiles\3ux7ebrd.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
::Report end
sanmac prosiłem o coś. Zamykam. Proszę się zgłosić do mnie lub innego moderatora - podają link do tego tematu, po lekturze tego linku.