Trj/CI.A
#1
co to za trojan?

Logfile of HijackThis v1.99.1
Scan saved at 13:52:27, on 2010-02-07
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\SYSTEM32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\Program Files\Panda Security\Panda Internet Security 2010\TPSrv.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\PROGRAM FILES\PANDA SECURITY\PANDA INTERNET SECURITY 2010\WebProxy.exe
H:\Program Files\Bonjour\mDNSResponder.exe
H:\WINDOWS\system32\svchost.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\Program Files\Panda Security\Panda Internet Security 2010\PsCtrls.exe
H:\Program Files\Panda Security\Panda Internet Security 2010\PavFnSvr.exe
h:\program files\panda security\panda internet security 2010\firewall\PSHOST.EXE
H:\WINDOWS\Explorer.EXE
H:\Program Files\Panda Security\Panda Internet Security 2010\PsImSvc.exe
H:\Program Files\Panda Security\Panda Internet Security 2010\PskSvc.exe
H:\WINDOWS\system32\RUNDLL32.EXE
H:\WINDOWS\RTHDCPL.EXE
H:\PROGRA~1\PESTPA~1\PPControl.exe
H:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
H:\Program Files\Java\jre6\bin\jusched.exe
H:\PROGRA~1\PESTPA~1\PPMemCheck.exe
H:\Program Files\Synaptics\SynTP\SynTPEnh.exe
H:\PROGRA~1\PESTPA~1\CookiePatrol.exe
H:\WINDOWS\system32\rundll32.exe
H:\Program Files\Panda Security\Panda Internet Security 2010\APVXDWIN.EXE
H:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
H:\Program Files\Skype\Phone\Skype.exe
H:\WINDOWS\system32\svchost.exe
I:\DYSK D\Wojtek\gg\Gadu-Gadu\gg.exe
H:\Program Files\Messenger\msmsgs.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
H:\Program Files\Panda Security\Panda Internet Security 2010\pavsrv51.exe
H:\Program Files\Panda Security\Panda Internet Security 2010\AVENGINE.EXE
H:\Program Files\ERA\GlobeTrotter Connect\GlobeTrotter Connect.exe
H:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
H:\WINDOWS\system32\wbem\wmiapsrv.exe
H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
H:\Program Files\Skype\Plugin Manager\skypePM.exe
H:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
H:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
H:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
H:\WINDOWS\System32\svchost.exe
H:\Program Files\Panda Security\Panda Internet Security 2010\SRVLOAD.EXE
H:\Program Files\Panda Security\Panda Internet Security 2010\PavBckPT.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\Xara\Webstyle 4\WebStyle.exe
H:\WINDOWS\system32\xwsindex.exe
I:\DYSK D\Wojtek\instalki\Alligator Flash Designer 7.1 PL Crack\hijackthis.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

[Aby zobaczyć linki, zarejestruj się tutaj]

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

[Aby zobaczyć linki, zarejestruj się tutaj]

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

[Aby zobaczyć linki, zarejestruj się tutaj]

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

[Aby zobaczyć linki, zarejestruj się tutaj]

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - H:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SynTPStart]H:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [NvMediaCenter]RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon]RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL]RTHDCPL.EXE
O4 - HKLM\..\Run: [PestPatrol Control Center]H:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [GrooveMonitor]"H:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched]"H:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task]"H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PPMemCheck]H:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol]H:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent]rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [APVXDWIN]"H:\Program Files\Panda Security\Panda Internet Security 2010\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO]"H:\Program Files\Panda Security\Panda Internet Security 2010\Inicio.exe"
O4 - HKCU\..\Run: [Skype]"H:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Gadu-Gadu]"I:\DYSK D\Wojtek\gg\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [MSMSGS]"H:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount]"H:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ctfmon.exe]H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray]"H:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - Startup: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = H:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: GlobeTrotter Connect.lnk = H:\Program Files\ERA\GlobeTrotter Connect\GlobeTrotter Connect.exe
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel -

[Aby zobaczyć linki, zarejestruj się tutaj]

:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra ''Tools'' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - H:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra ''Tools'' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: h:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL]International
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) -

[Aby zobaczyć linki, zarejestruj się tutaj]

O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) -

[Aby zobaczyć linki, zarejestruj się tutaj]

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

[Aby zobaczyć linki, zarejestruj się tutaj]

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - H:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - H:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\Program Files\Skype\toolbars\Shared\Skype4ComAPI.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - H:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: avldr - H:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Bonjour Service - Apple Inc. - H:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - H:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GtDetectSc - Option - H:\Program Files\ERA\GlobeTrotter Connect\GtDetectSc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Program Files\Java\jre6\bin\jqs.exe" -service -config "H:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Software Controller - Panda Security, S.L. - H:\Program Files\Panda Security\Panda Internet Security 2010\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Security, S.L. - H:\Program Files\Panda Security\Panda Internet Security 2010\PavFnSvr.exe
O23 - Service: Panda On-Access Anti-Malware Service (PAVSRV) - Panda Security, S.L. - H:\Program Files\Panda Security\Panda Internet Security 2010\pavsrv51.exe
O23 - Service: Panda Security Generic Uninstaller (PSGenUn) - Unknown owner - H:\PROGRA~1\INSTAL~1\{E55FB~1\SMCL\SMCLpav.exe (file missing)
O23 - Service: Panda Host Service (PSHost) - Panda Security International - h:\program files\panda security\panda internet security 2010\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - H:\Program Files\Panda Security\Panda Internet Security 2010\PsImSvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - H:\Program Files\Panda Security\Panda Internet Security 2010\PskSvc.exe
O23 - Service: ServiceLayer - Nokia - H:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - H:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - H:\Program Files\Panda Security\Panda Internet Security 2010\TPSrv.exe
Odpowiedz
#2
Panda większość wirusów wykrywa jako CI.A Wink
Kiedyś w regulaminie był zapis że jeżeli zostanie wykryte pirackie oprogramowanie osoba sprawdzająca powinna zaprzestać sprawdzania
Kod:
I:\DYSK D\Wojtek\instalki\Alligator Flash Designer 7.1 PL Crack\hijackthis.com
Odpowiedz
#3
juz wywalilemto komputer po bracie jaszcze bez formata
Odpowiedz
#4
Meir, Eugeniusz
Proszę nie wyręczać w pracy moderatorów. Poproszę o log z

[Aby zobaczyć linki, zarejestruj się tutaj]

"Nie jestem konsumentem mieszczącym się w standardzie
Nie jestem gatunkiem skazanym na wymarcie
Nie jestem obiektem medialnego hałasu
Jestem nielegalnym zabójcą czasu"
Odpowiedz


Skocz do:


Użytkownicy przeglądający ten wątek: 1 gości