Logfile of HijackThis v1.99.1
Scan saved at 21:16:23, on 2008-02-07
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32CTsvcCDA.EXE
C
rogram FilesOLYMPUSDeviceDetectorDM1Service.exe
C:WINDOWSSystem32svchost.exe
C
rogram FilesCommon FilesYDPUserAccessManageruseraccess.exe
C:WINDOWSsystem32MsPMSPSv.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:YDPDictwatch.exe
C
rogram FilesJavajre1.6.0_03binjusched.exe
C:WINDOWSSOUNDMAN.EXE
C
rogram FilesHewlett-PackardHP Share-to-Webhpgs2wnd.exe
C
rogram FilesCyberLinkPowerDVDPDVDServ.exe
C
rogram FilesQuickTimeqttask.exe
C
rogram FilesIntelPROSetWiredNCSPROSetPRONoMgr.exe
C
rogram FilesMusicMatchMusicMatch Jukeboxmm_tray.exe
C:WINDOWSsystem32igfxtray.exe
C:WINDOWSsystem32hkcmd.exe
C
rogram FilesASUSProbeAsusProb.exe
C:WINDOWSALCWZRD.EXE
C:WINDOWSALCMTR.EXE
C:WINDOWSsystem32wscntfy.exe
C
rogram FilesRealRealPlayerRealPlay.exe
C
rogram FilesCommon FilesOnet.plAutoUpdate.exe
C
rogram FilesSony EricssonMobile2Application LauncherApplication Launcher.exe
C:WINDOWSsystem32Rundll32.exe
C
rogram FilesCreativeSound Blaster X-FiVolume PanelVolPanlu.exe
C
rogram FilesMessengermsmsgs.exe
C:WINDOWSSystem32svchost322.exe
D
rogram FilesGadu-Gadugg.exe
C:WINDOWSsystem32ctfmon.exe
C
rogram FilesCreativeMediaSourceDetectorCTDetect.exe
C
rogram FilesCommon FilesTeleca SharedCapabilityManager.exe
C:YDPDICTWatch.exe
C
rogram FilesOLYMPUSDeviceDetectorDevDtct2.exe
c
rogram FilesHewlett-PackardHP Share-to-Webhpgs2wnf.exe
C
rogram FilesCommon FilesTeleca SharedGeneric.exe
C
rogram FilesSony EricssonMobile2Mobile Phone Monitorepmworker.exe
C
rogram FilesMozilla Firefoxfirefox.exe
C
rogram FilesMusicMatchMusicMatch Jukeboxmmjb.exe
C
rogram FilesMusicMatchMusicMatch JukeboxMMDiag.exe
C
rogram FilesMicrosoft OfficeOffice10WINWORD.EXE
C:WINDOWSmsagentAgentSvr.exe
C:WINDOWSsystem32dwwin.exe
C
rogram FilesHijackThisHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,SearchAssistant =
http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C
rogram FilesBearShare applicationsBearShare MediaBarMediaBar.dll
F3 - REG:win.ini: load=C:YDPDictwatch.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C
rogram FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C
rogram FilesAdobeAcrobat 5.0 CEReaderActiveXAcroIEHelper.ocx
O2 - BHO: PK IE Plugin - {1E1B2879-88FF-11D3-8D96-D7ACAC95951A} - C
ROGRA~1BPKqwertywb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C
rogram FilesJavajre1.6.0_03binssv.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C
ROGRA~1FlashGetjccatch.dll (file missing)
O2 - BHO: (no name) - {B8C5186E-EC37-4889-9C2E-F73649FFB7BB} - C
rogram FilesVideo ActiveX Accessiesplg.dll (file missing)
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C
ROGRA~1TEXTwareQUICKF~1PlugInsIEHelp.dll
O2 - BHO: XBTP02634 - {F97DA966-F09D-4cab-BF29-75A0026986EA} - C
ROGRA~1BEARSH~1BEARSH~2MediaBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C
rogram FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C
rogram FilesBearShare applicationsBearShare MediaBarMediaBar.dll
O4 - HKLM..Run: [sys32cmd] C
ocuments and SettingsDarekPulpitAdiActive Key Loggersys32win.exe
O4 - HKLM..Run: [SunJavaUpdateSched] "C
rogram FilesJavajre1.6.0_03binjusched.exe"
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [Skrót do strony właściwości High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM..Run: [Share-to-Web Namespace Daemon] c
rogram FilesHewlett-PackardHP Share-to-Webhpgs2wnd.exe
O4 - HKLM..Run: [RemoteControl] "C
rogram FilesCyberLinkPowerDVDPDVDServ.exe"
O4 - HKLM..Run: [QuickTime Task] "C
rogram FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [PRONoMgrWired] C
rogram FilesIntelPROSetWiredNCSPROSetPRONoMgr.exe
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [MMTray] C
rogram FilesMusicMatchMusicMatch Jukeboxmm_tray.exe
O4 - HKLM..Run: [IgfxTray] C:WINDOWSsystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSsystem32hkcmd.exe
O4 - HKLM..Run: [ASUS Probe] C
rogram FilesASUSProbeAsusProb.exe
O4 - HKLM..Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM..Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM..Run: [RealTray] C
rogram FilesRealRealPlayerRealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM..Run: [LanzarL2007] "C
OCUME~1DarekUSTAWI~1Temp{F3416172-C9D8-4A64-8A57-75B2D33860FE}{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}....L2007tmpSetup.exe" /SETUP:"/l0x0015"
O4 - HKLM..Run: [Onet.pl AutoUpdate] C
rogram FilesCommon FilesOnet.plAutoUpdate.exe /tsr
O4 - HKLM..Run: [Sony Ericsson PC Suite] "C
rogram FilesSony EricssonMobile2Application LauncherApplication Launcher.exe" /startoptions
O4 - HKLM..Run: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry
O4 - HKLM..Run: [VolPanel] "C
rogram FilesCreativeSound Blaster X-FiVolume PanelVolPanlu.exe" /r
O4 - HKCU..Run: [MSMSGS] "C
rogram FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [inifesh] C:WINDOWSSystem32svchost322.exe
O4 - HKCU..Run: [Gadu-Gadu] "D
rogram FilesGadu-Gadugg.exe" /tray
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [Windows Registry Repair Pro] C
rogram Files3B SoftwareWindows Registry Repair ProRegistryRepairPro.exe 4
O4 - HKCU..Run: [Creative Detector] "C
rogram FilesCreativeMediaSourceDetectorCTDetect.exe" /R
O4 - Global Startup: Aktywacja Testera.lnk = C:YDPDICTWatch.exe
O4 - Global Startup: Device Detector 2.lnk = C
rogram FilesOLYMPUSDeviceDetectorDevDtct2.exe
O4 - Global Startup: Microsoft Office.lnk = C
rogram FilesMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: &Search -
http://kn.bar.need2find.com/KN/menusearch.html?p=KN
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C
rogram FilesJavajre1.6.0_03binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C
rogram FilesJavajre1.6.0_03binssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:WINDOWSsystem32Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O20 - Winlogon Notify: igfxcui - C:WINDOWSSYSTEM32igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:WINDOWSsystem32CTsvcCDA.EXE
O23 - Service: DM1Service - OLYMPUS OPTICAL CO.,LTD - C
rogram FilesOLYMPUSDeviceDetectorDM1Service.exe
O23 - Service: Intel NCS NetService (NetSvc) - IntelŽ Corporation - C
rogram FilesIntelPROSetWiredNCSSyncNetSvc.exe
O23 - Service: Securom User Access for Windows 2000 and Windows XP a technology by Sony DADC (UserAccess) - Unknown owner - C
rogram FilesCommon FilesYDPUserAccessManageruseraccess.exe