Daję loga z Combofixa:
ComboFix 07-05.24.7.V - Running from: “C:\Documents and Settings\Daniel\Pulpit” (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) “C:\windows\system32\iexplore.exe” “C:\WINDOWS\b122.exe” “C:\Program Files\inetget2” ((((((((((((((((((((((((((((((( Files Created from 2007-05-06 to 2007-06-26 )))))))))))))))))))))))))))))))))) 2007-06-26 21:39 6,369 —hs---- C:\WINDOWS\system32\qpqru.bak1 2007-06-26 21:37 266,336 --a------ C:\WINDOWS\system32\urqpq.dll 2007-06-26 21:32 31,254 --a------ C:\WINDOWS\system32\rqrpppp.dll 2007-06-26 21:23 24,442 --a------ C:\WINDOWS\system32\auns.exe 2007-06-26 21:10 37,901 --------- C:\WINDOWS\system32\tnhfqnd.exe 2007-06-26 21:10 31,254 --a------ C:\WINDOWS\system32\gebcbay.dll 2007-06-26 21:09 24,442 --a------ C:\WINDOWS\system32\wkyjg.exe 2007-06-26 19:34 24,442 --a------ C:\WINDOWS\system32\rpsy.exe 2007-06-26 19:22 31,254 --a------ C:\WINDOWS\system32\tuvvwwx.dll 2007-06-26 19:21 24,442 --a------ C:\WINDOWS\system32\oywdvltl.exe 2007-06-25 23:44 31,254 --a------ C:\WINDOWS\system32\nnnlmnk.dll.vir 2007-06-25 23:35 24,442 --a------ C:\WINDOWS\system32\ntvgwqjr.exe 2007-06-25 23:12 24,442 --a------ C:\WINDOWS\system32\azcebkql.exe 2007-06-25 23:07 30,336 --ah----- C:\WINDOWS\system32\sffipllt.exe 2007-06-25 23:05 31,254 --a------ C:\WINDOWS\system32\urqpooo.dll 2007-06-25 22:50 2007-06-25 22:49 31,254 --a------ C:\WINDOWS\system32\ljjgecc.dll 2007-06-25 22:11 6,656 --a------ C:\WINDOWS\system32\ujbvhyx.exe 2007-06-25 22:11 31,254 --a------ C:\WINDOWS\system32\jkkjhff.dll.vir 2007-06-25 22:11 11,148 --a------ C:\WINDOWS\system32\sjalikz.exe 2007-06-25 22:05 24,442 --a------ C:\WINDOWS\system32\kkcclo.exe 2007-06-25 21:54 24,442 --a------ C:\WINDOWS\system32\hvklaxfq.exe 2007-06-25 18:56 24,442 --a------ C:\WINDOWS\system32\kjphrars.exe 2007-06-25 18:29 24,442 --a------ C:\WINDOWS\system32\xlgxwzm.exe 2007-06-24 23:55 182,880 --a------ C:\WINDOWS\system32\iuengine.dll 2007-06-24 21:50 24,442 --a------ C:\WINDOWS\system32\dgrekey.exe 2007-06-24 21:16 2007-06-24 20:23 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-06-24 20:23 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-06-24 13:55 2007-06-24 11:19 2007-06-24 10:31 2007-06-22 19:15 2007-06-22 19:09 2007-06-22 19:07 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll 2007-06-22 19:06 2007-06-22 18:52 2007-06-17 21:41 2007-06-14 21:36 2007-06-14 21:35 299,520 --a------ C:\WINDOWS\uninst.exe 2007-06-14 21:35 2007-06-12 20:42 58,288 -ra------ C:\WINDOWS\system32\drivers\k510bus.sys 2007-06-12 20:42 5,808 -ra------ C:\WINDOWS\system32\drivers\k510whnt.sys 2007-06-12 20:42 5,808 -ra------ C:\WINDOWS\system32\drivers\k510wh.sys 2007-06-11 18:25 2007-06-11 18:22 2007-06-05 18:48 997,888 --a------ C:\WINDOWS\system32\wmvdmoe2.dll 2007-06-05 18:48 892,416 --a------ C:\WINDOWS\system32\wmspdmoe.dll 2007-06-05 18:48 486,536 --a------ C:\WINDOWS\system32\wmspdmod.dll 2007-06-05 18:48 384,512 --a------ C:\WINDOWS\system32\mp4sdmod.dll 2007-06-05 18:48 316,040 --a------ C:\WINDOWS\system32\mp43dmod.dll 2007-06-05 18:48 1,111,040 --a------ C:\WINDOWS\system32\wmsdmoe2.dll 2007-06-05 18:47 143,360 --a------ C:\WINDOWS\system32\wmidx.dll 2007-06-05 18:42 476,320 --a------ C:\WINDOWS\system32\ImagXpr7.dll 2007-06-05 18:42 471,040 --a------ C:\WINDOWS\system32\ImagXRA7.dll 2007-06-05 18:42 38,912 --a------ C:\WINDOWS\system32\picn20.dll 2007-06-05 18:42 364,544 --a------ C:\WINDOWS\system32\TwnLib4.dll 2007-06-05 18:42 262,144 --a------ C:\WINDOWS\system32\ImagXR7.dll 2007-06-05 18:42 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-06-05 18:42 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2007-06-05 18:42 1,568,768 --a------ C:\WINDOWS\system32\ImagX7.dll 2007-06-05 18:42 2007-06-05 18:41 2007-06-04 18:36 2007-06-03 17:37 2007-06-03 17:37 2007-06-02 17:26 2007-06-02 17:11 418,304 -ra------ C:\WINDOWS\system32\drivers\cfosspeed.sys 2007-06-02 16:53 200,704 --a------ C:\WINDOWS\system32\cfosspeed.dll 2007-06-02 16:53 2007-06-01 18:28 2007-05-27 21:07 2007-05-26 21:59 2007-05-26 21:58 2007-05-26 21:44 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-26 17:56:05 -------- d-----w C:\DOCUME~1\Daniel\DANEAP~1\foobar2000 2007-06-24 20:14:24 -------- d-----w C:\Program Files\Valve 2007-06-24 19:31:12 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-06-24 19:31:12 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-24 18:51:01 23,016 ----a-w C:\WINDOWS\system32\emptyregdb.dat 2007-06-24 18:48:24 -------- d–h--w C:\Program Files\WindowsUpdate 2007-06-24 18:48:18 -------- d-----w C:\Program Files\Messenger 2007-06-24 11:56:42 -------- d-----w C:\DOCUME~1\Daniel\DANEAP~1\Skype 2007-06-22 16:52:50 -------- d-----w C:\Program Files\GetRight 2007-06-03 17:26:08 -------- d-----w C:\Program Files\Cheating-Death 2007-05-25 20:35:26 -------- d-----w C:\Program Files\TuneUp Utilities 2006 2007-05-25 20:34:00 -------- d-----w C:\DOCUME~1\Daniel\DANEAP~1\TuneUp Software 2007-05-24 18:33:35 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-05-23 20:28:01 34,651 ----a-w C:\WINDOWS\system32\iiffc.exe 2007-05-23 20:24:46 8,436 ----a-w C:\WINDOWS\system32\hggffdc.dll 2007-05-23 20:22:57 8,436 ----a-w C:\WINDOWS\system32\urspqnl.dll 2007-05-21 16:31:47 -------- d-----w C:\DOCUME~1\Daniel\DANEAP~1\Shareaza 2007-05-20 16:48:09 -------- d-----w C:\Program Files\No-IP 2007-05-20 14:40:44 -------- d-----w C:\Program Files\Neostrada TP 2007-05-20 12:19:47 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-05-20 12:16:32 -------- d-----w C:\Program Files\Common Files\InstallShield 2007-05-20 12:07:38 -------- d-----w C:\Program Files\VIAudioi 2007-05-20 12:06:32 -------- d-----w C:\Program Files\VIA 2007-05-20 11:35:19 -------- d-----w C:\Program Files\Skype 2007-05-20 11:35:18 -------- d-----w C:\Program Files\Common Files\Skype 2007-05-20 11:22:25 1,156 ----a-w C:\WINDOWS\mozver.dat 2007-05-20 11:18:21 -------- d-----w C:\Program Files\WapSter 2007-05-20 11:01:51 -------- d-----w C:\DOCUME~1\Daniel\DANEAP~1\Gadu-Gadu 2007-05-20 11:01:17 -------- d-----w C:\Program Files\Gadu-Gadu 2007-05-20 10:55:34 0 ----a-w C:\WINDOWS\nsreg.dat 2007-05-20 10:35:39 -------- d-----w C:\Program Files\Alwil Software 2007-05-20 10:33:17 716 ----a-w C:\WINDOWS\unins000.dat 2007-05-20 10:19:11 -------- d-----w C:\Program Files\SAGEM 2007-05-20 10:01:10 -------- d-----w C:\Program Files\Common Files\ODBC 2007-05-20 10:00:47 -------- d-----w C:\Program Files\Common Files\SpeechEngines 2007-05-20 09:44:39 -------- d-----w C:\Program Files\microsoft frontpage 2007-05-20 09:43:28 0 --sha-r C:\MSDOS.SYS 2007-05-20 09:43:28 0 --sha-r C:\IO.SYS 2007-05-20 09:43:28 0 ----a-w C:\CONFIG.SYS 2007-05-20 09:43:28 0 ----a-w C:\AUTOEXEC.BAT 2007-05-20 09:36:19 -------- d-----w C:\Program Files\Movie Maker 2007-05-20 09:35:07 -------- d-----w C:\Program Files\Common Files\MSSoap 2007-05-20 09:30:58 -------- d-----w C:\Program Files\Usługi online 2007-05-20 09:30:05 -------- d-----w C:\Program Files\MSN Gaming Zone 2007-05-20 09:30:04 -------- d-----w C:\Program Files\Windows NT 2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AvastSS.scr (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {189F4FFB-6747-49A6-B272-FBE78DF536C8}=C:\WINDOWS\System32\urqpq.dll [2007-06-26 21:37] {31FF080D-12A3-439A-A2EF-4BA95A3148E8}=C:\Program Files\GetRight\xx2gr.dll [2007-01-04 23:57] {674DDFA6-BB3D-427B-961F-E9EEEF293004}=C:\WINDOWS\System32\gebcbay.dll [2007-06-26 21:10] {6771D12B-FA53-4261-8E26-5523B23EDAEF}=C:\WINDOWS\System32\yabax.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Microsoft Internet Explorer”=“C:\WINDOWS\System32\iexplore.exe” [] “Windows Logon Application”=“C:\WINDOWS\System32\logon.exe” [2001-10-26 19:29] “Spooler SubSystem App”=“C:\WINDOWS\System32\spoolsvc.exe” [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS\System32\ctfmon.exe” [2001-10-26 19:29] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce] “wextract_cleanup0”=rundll32.exe C:\WINDOWS\System32\advpack.dll,DelNodeRunDLL32 “C:\DOCUME~1\Daniel\USTAWI~1\Temp\IXP000.TMP” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] “NoRemoteRecursiveEvents”=1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoSaveSettings”=0 (0x0) “ClearRecentDocsOnExit”=1 (0x1) “NoLowDiskSpaceChecks”=1 (0x1) “NoViewContextMenu”=0 (0x0) “NoChangeStartMenu”=0 (0x0) “NoRecentDocsHistory”=1 (0x1) “MaxRecentDocs”=11 (0xb) “NoStartMenuMFUprogramsList”=0 (0x0) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{674DDFA6-BB3D-427B-961F-E9EEEF293004}”=“C:\WINDOWS\System32\gebcbay.dll” [2007-06-26 21:10] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcbay] gebcbay.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqpq] C:\WINDOWS\System32\urqpq.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] “ERSvc”=2 (0x2) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] “CTFMON.EXE”=C:\WINDOWS\System32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] “AudioDeck”=C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1 “NvCplDaemon”=RUNDLL32.EXE NvQTwk,NvCplDaemon initialize “nwiz”=nwiz.exe /install “Cmaudio”=RunDll32 cmicnfg.cpl,CMICtrlWnd *Newly Created Service* -MSISERVER ~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ backup-20070625-222416-181 O4 - HKLM…\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe backup-20070625-222416-264 R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file) backup-20070625-220924-965 O4 - HKLM…\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe Contents of the ‘Scheduled Tasks’ folder 2007-06-24 19:16:59 C:\WINDOWS\tasks\1-Click Maintenance.job (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) “C:\windows\system32\iexplore.exe” “C:\WINDOWS\b122.exe” “C:\Program Files\inetget2” ((((((((((((((((((((((((((((((( Files Created from 2007-05-06 to 2007-06-26 )))))))))))))))))))))))))))))))))) No new files created in this timespan (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) “C:\windows\system32\iexplore.exe” “C:\WINDOWS\b122.exe” “C:\Program Files\inetget2” ((((((((((((((((((((((((((((((( Files Created from 2007-05-06 to 2007-06-26 )))))))))))))))))))))))))))))))))) No new files created in this timespan (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-26 17:56:05 -------- d-----w C:\DOCUME~1\Daniel\DANEAP~1\foobar2000 2007-06-24 20:14:24 -------- d-----w C:\Program Files\Valve 2007-06-24 19:31:12 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-06-24 19:31:12 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-24 18:51:01 23,016 ----a-w C:\WINDOWS\system32\emptyregdb.dat 2007-06-24 18:48:24 -------- d–h--w C:\Program Files\WindowsUpdate 2007-06-24 18:48:18 -------- d-----w C:\Program Files\Messenger 2007-06-24 11:56:42 -------- d-----w C:\DOCUME~1\Daniel\DANEAP~1\Skype 2007-06-22 16:52:50 -------- d-----w C:\Program Files\GetRight 2007-06-03 17:26:08 -------- d-----w C:\Program Files\Cheating-Death 2007-05-25 20:35:26 -------- d-----w C:\Program Files\TuneUp Utilities 2006 2007-05-25 20:34:00 -------- d-----w C:\DOCUME~1\Daniel\DANEAP~1\TuneUp Software 2007-05-24 18:33:35 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-05-23 20:28:01 34,651 ----a-w C:\WINDOWS\system32\iiffc.exe 2007-05-23 20:24:46 8,436 ----a-w C:\WINDOWS\system32\hggffdc.dll 2007-05-23 20:22:57 8,436 ----a-w C:\WINDOWS\system32\urspqnl.dll 2007-05-21 16:31:47 -------- d-----w C:\DOCUME~1\Daniel\DANEAP~1\Shareaza 2007-05-20 16:48:09 -------- d-----w C:\Program Files\No-IP 2007-05-20 14:40:44 -------- d-----w C:\Program Files\Neostrada TP 2007-05-20 12:19:47 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-05-20 12:16:32 -------- d-----w C:\Program Files\Common Files\InstallShield 2007-05-20 12:07:38 -------- d-----w C:\Program Files\VIAudioi 2007-05-20 12:06:32 -------- d-----w C:\Program Files\VIA 2007-05-20 11:35:19 -------- d-----w C:\Program Files\Skype 2007-05-20 11:35:18 -------- d-----w C:\Program Files\Common Files\Skype 2007-05-20 11:22:25 1,156 ----a-w C:\WINDOWS\mozver.dat 2007-05-20 11:18:21 -------- d-----w C:\Program Files\WapSter 2007-05-20 11:01:51 -------- d-----w C:\DOCUME~1\Daniel\DANEAP~1\Gadu-Gadu 2007-05-20 11:01:17 -------- d-----w C:\Program Files\Gadu-Gadu 2007-05-20 10:55:34 0 ----a-w C:\WINDOWS\nsreg.dat 2007-05-20 10:35:39 -------- d-----w C:\Program Files\Alwil Software 2007-05-20 10:33:17 716 ----a-w C:\WINDOWS\unins000.dat 2007-05-20 10:19:11 -------- d-----w C:\Program Files\SAGEM 2007-05-20 10:01:10 -------- d-----w C:\Program Files\Common Files\ODBC 2007-05-20 10:00:47 -------- d-----w C:\Program Files\Common Files\SpeechEngines 2007-05-20 09:44:39 -------- d-----w C:\Program Files\microsoft frontpage 2007-05-20 09:43:28 0 --sha-r C:\MSDOS.SYS 2007-05-20 09:43:28 0 --sha-r C:\IO.SYS 2007-05-20 09:43:28 0 ----a-w C:\CONFIG.SYS 2007-05-20 09:43:28 0 ----a-w C:\AUTOEXEC.BAT 2007-05-20 09:36:19 -------- d-----w C:\Program Files\Movie Maker 2007-05-20 09:35:07 -------- d-----w C:\Program Files\Common Files\MSSoap 2007-05-20 09:30:58 -------- d-----w C:\Program Files\Usługi online 2007-05-20 09:30:05 -------- d-----w C:\Program Files\MSN Gaming Zone 2007-05-20 09:30:04 -------- d-----w C:\Program Files\Windows NT 2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AvastSS.scr (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {31FF080D-12A3-439A-A2EF-4BA95A3148E8}=C:\Program Files\GetRight\xx2gr.dll [2007-01-04 23:57] {5BC421C6-997C-4224-A2FA-BD13679FB5FA}=C:\WINDOWS\System32\urqpq.dll [2007-06-26 21:37] {674DDFA6-BB3D-427B-961F-E9EEEF293004}=C:\WINDOWS\System32\gebcbay.dll [2007-06-26 21:10] {6771D12B-FA53-4261-8E26-5523B23EDAEF}=C:\WINDOWS\System32\yabax.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Microsoft Internet Explorer”=“C:\WINDOWS\System32\iexplore.exe” [] “Windows Logon Application”=“C:\WINDOWS\System32\logon.exe” [2001-10-26 19:29] “Spooler SubSystem App”=“C:\WINDOWS\System32\spoolsvc.exe” [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS\System32\ctfmon.exe” [2001-10-26 19:29] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce] “wextract_cleanup0”=rundll32.exe C:\WINDOWS\System32\advpack.dll,DelNodeRunDLL32 “C:\DOCUME~1\Daniel\USTAWI~1\Temp\IXP000.TMP” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] “NoRemoteRecursiveEvents”=1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoSaveSettings”=0 (0x0) “ClearRecentDocsOnExit”=1 (0x1) “NoLowDiskSpaceChecks”=1 (0x1) “NoViewContextMenu”=0 (0x0) “NoChangeStartMenu”=0 (0x0) “NoRecentDocsHistory”=1 (0x1) “MaxRecentDocs”=11 (0xb) “NoStartMenuMFUprogramsList”=0 (0x0) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{674DDFA6-BB3D-427B-961F-E9EEEF293004}”=“C:\WINDOWS\System32\gebcbay.dll” [2007-06-26 21:10] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcbay] gebcbay.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqpq] C:\WINDOWS\System32\urqpq.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] “ERSvc”=2 (0x2) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] “CTFMON.EXE”=C:\WINDOWS\System32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] “AudioDeck”=C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1 “NvCplDaemon”=RUNDLL32.EXE NvQTwk,NvCplDaemon initialize “nwiz”=nwiz.exe /install “Cmaudio”=RunDll32 cmicnfg.cpl,CMICtrlWnd *Newly Created Service* -MSISERVER ~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ backup-20070625-222416-181 O4 - HKLM…\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe backup-20070625-222416-264 R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file) backup-20070625-220924-965 O4 - HKLM…\Run: [Application Layer Gateway Service] C:\WINDOWS\System32\algs.exe Contents of the ‘Scheduled Tasks’ folder 2007-06-24 19:16:59 C:\WINDOWS\tasks\1-Click Maintenance.job
Wydaje mi się że log jest dwa razy bo dwa razy klikałem ten plik exe.
Btw. Tamto usunąłem(algs.exe i jakieś pliki jkkasdas.exe[nazwy dokładnej nie pamiętam bo vundo je usuwał i miały szyfrowaną losowo nazwę]) jednak teraz mam jeszcze inny problem. Właśnie z procesem iexplore.exe. Jak go wyłączam w menadżerze zadań to po ok 20s komputer mi sam się restartuje, a właściwie to resetuje bez wznowienia pracy, zatrzymuje się na czarnym ekranie i muszę walnąć mu reset. Poza tym przed restartem nie wyświetla nic tylko odrazu tak jakby się wyłączał (wiem że w innych porzypadkach jest odliczanie 59s do wyłączenia a tu nie ma więc shutdown -a nie można użyć żeby to zatrzymać. Nie wiem czemu tak się robi. Pomocy jeszcze raz.
Złączono Posta : 26.06.2007 (Wto) 22:30
Logfile of HijackThis v1.99.1
Scan saved at 22:10, on 2007-06-26
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\cFosSpeed\spd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\logon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\ComboFix\21847.cfexe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\rundll32.exe
C:\ComboFix\23003.cfexe
C:\ComboFix\23071.cfexe
C:\WINDOWS\explorer.exe
D:\Program Files\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = L1cza
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM…\Run: [Microsoft Internet Explorer] C:\WINDOWS\System32\iexplore.exe
O4 - HKLM…\Run: [Windows Logon Application] C:\WINDOWS\System32\logon.exe
O4 - HKLM…\Run: [spooler SubSystem App] C:\WINDOWS\System32\spoolsvc.exe
O4 - HKLM…\RunOnce: [wextract_cleanup0] rundll32.exe C:\WINDOWS\System32\advpack.dll,DelNodeRunDLL32 “C:\DOCUME~1\Daniel\USTAWI~1\Temp\IXP000.TMP”
O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O17 - HKLM\System\CCS\Services\Tcpip…{397AC643-4EB2-4F5C-997E-9EE3066B4223}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CS1\Services\Tcpip…{397AC643-4EB2-4F5C-997E-9EE3066B4223}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CS2\Services\Tcpip…{397AC643-4EB2-4F5C-997E-9EE3066B4223}: NameServer = 194.204.159.1 217.98.63.164
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: cFosSpeed System Service (cFosSpeedS) - Unknown owner - C:\Program Files\cFosSpeed\spd.exe" -service (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe