Daethare
2011-02-14, 02:41
Recently I've got a lot of warnings @ teatimer about this registry change. I've read somewhere that it may be a backdoor attack.
It's annoying, because it pops everytime I turn on my computer no matter if I allow or disallow changes to registry. And if I want to disallow changes, it pops again in second or two. My computer started to work a little bit slower, not really a huge difference, but still annoys me a bit.
I've used combofix, spybot, ESET NOD scans on both normal and safe windows mode.
Edit
Please do NOT run 'FIXES' (ComboFix etc) without being asked (http://forums.spybot.info/showthread.php?t=16806)
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)
Teatimer logs: ("Odmówiono" means "denied" in my language)
2011-02-13 23:48:30 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:48:32 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:48:36 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:48:38 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:49:29 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:49:32 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:49:33 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:55:36 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:01:46 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:01:51 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:01:53 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:01:55 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:02:00 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:02:01 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:03:58 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
And I'm terribly sorry for bumping the topic again, I forgot about DDS logs, here are those:
DDS (Ver_10-12-12.02) - NTFS_AMD64
Run by Ja at 0:37:44,61 on 2011-02-14
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_11
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1250.48.1045.18.4094.2963 [GMT 1:00]
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Eset\nod32krn.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\ESET\nod32kui.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
C:\Users\Ja\Downloads\dds.com
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Pomocnik rejestracji usługi Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
mRun: [nod32kui] "C:\Program Files (x86)\Eset\nod32kui.exe" /WAITSERVICE
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableInstallerDetection = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&ksport do programu Microsoft Excel - C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Pobierz plik wideo we Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
IE: Pobierz w Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
IE: Pobierz wszystkie pliki w Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
IE: Pobierz zaznaczone w Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
LSP: C:\Windows\system32\imon.dll
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files%20(x86)/Plants%20vs.%20Zombies/Images/stg_drm.ocx
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files%20(x86)/Plants%20vs.%20Zombies/Images/armhelper.ocx
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\0moqeuay.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2672188&SearchSource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2672188&q=
FF - component: C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\0moqeuay.default\extensions\{0ed38a68-9a97-450a-a349-62d04f4cc940}\components\FFExternalAlert.dll
FF - component: C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\0moqeuay.default\extensions\{0ed38a68-9a97-450a-a349-62d04f4cc940}\components\RadioWMPCore.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: C:\ProgramData\Gadu-Gadu 10\_userdata\npgg.4.dll
FF - plugin: C:\ProgramData\Gadu-Gadu 10\_userdata\nppl3260.dll
FF - plugin: C:\ProgramData\Gadu-Gadu 10\_userdata\nprpjplug.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: dollarsgroup Toolbar: {0ed38a68-9a97-450a-a349-62d04f4cc940} - %profile%\extensions\{0ed38a68-9a97-450a-a349-62d04f4cc940}
FF - Ext: OneManga Manager: {bbeee172-6a96-6f83-cf0c-a3bf46b77f94} - %profile%\extensions\{bbeee172-6a96-6f83-cf0c-a3bf46b77f94}
============= SERVICES / DRIVERS ===============
R2 NOD32krn;NOD32 Kernel Service;C:\Program Files (x86)\ESET\nod32krn.exe [2008-1-1 552064]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2008-1-21 93696]
=============== Created Last 30 ================
2011-02-13 22:57:30 -------- d-----w- C:\Users\Ja\AppData\Local\temp
2011-02-13 22:55:02 -------- d-----w- C:\$RECYCLE.BIN
2011-02-13 22:45:45 388096 ----a-r- C:\Users\Ja\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-13 22:45:44 -------- d-----w- C:\Program Files (x86)\HJTTTT
2011-02-13 22:36:56 98816 ----a-w- C:\Windows\sed.exe
2011-02-13 22:36:56 89088 ----a-w- C:\Windows\MBR.exe
2011-02-13 22:36:56 256512 ----a-w- C:\Windows\PEV.exe
2011-02-13 22:36:56 161792 ----a-w- C:\Windows\SWREG.exe
2011-02-13 22:34:44 318976 ----a-w- C:\Windows\SysWow64\CF30696.exe
2011-02-13 22:28:26 318976 ----a-w- C:\Windows\SysWow64\CF23942.exe
2011-02-13 22:28:22 8704 ----a-w- C:\Windows\System32\drivers\PROCEXP90.SYS
2011-02-13 22:27:52 318976 ----a-w- C:\Windows\SysWow64\cmd.execf
2011-02-13 22:12:02 318976 ----a-w- C:\Windows\SysWow64\CF29190.exe
2011-02-11 13:12:40 -------- d-----w- C:\Users\Ja\AppData\Roaming\codeblocks
2011-02-11 11:12:42 -------- d-----w- C:\Users\Ja\WapSter
2011-02-11 11:12:21 -------- d-----w- C:\Program Files (x86)\WapSter
2011-02-09 10:11:11 -------- d-----w- C:\Users\Ja\AppData\Roaming\.minecraft server
2011-01-30 13:01:48 -------- d-----w- C:\Users\Ja\AppData\Roaming\.minecraft
==================== Find3M ====================
============= FINISH: 0:37:59,36 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft® Windows Vista™ Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 2008-01-01 01:50:26
System Uptime: 2011-02-13 23:54:30 (1 hours ago)
Motherboard: Gigabyte Technology Co., Ltd. | | P31-DS3L
Processor: Intel(R) Core(TM)2 Duo CPU E6550 @ 2.33GHz | Socket 775 | 2333/333mhz
==== Disk Partitions =========================
F: is CDROM ()
G: is CDROM ()
H: is Removable
I: is Removable
J: is Removable
K: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
@BIOS Ver.2.03
18 Wheels of Steel Haulin
Adobe Flash Player 10 Plugin
Adobe Reader 8 - Polish
AIO_Scan
Archiwizator WinRAR
Ashampoo Burning Studio 9.20
Astroburn Lite
Asystent rejestracji usługi Windows Live
BEU Net 2006
Black and White
BufferChm
Carmageddon II Carpocalypse Now
CDBurnerXP
Copy
CustomerResearchQFolder
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DJ_AIO_ProductContext
DJ_AIO_Software
DJ_AIO_Software_min
eSupportQFolder
EVEREST Ultimate Edition v5.02
F4100
F4100_doccd
F4100_Help
Fraps (remove only)
Free Download Manager 2.5
Free Mp3 Wma Converter V 1.91
Gadu-Gadu 10
Gadu-Gadu 7.7
GG Tools
GTAIII
Guitar Pro 5.2
HiJackThis
HijackThis 2.0.2
HP Photosmart Essential2.01
HP Smart Web Printing
HP Update
HPProductAssistant
HPSSupply
Java(TM) 6 Update 11
JDownloader
K-Lite Codec Pack 4.2.5 (Full)
Lineage II
MadOnion.com/3DMark2001 SE
Mafia II - Demo
MarketResearch
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Minecraft Beta 1.1_02
Mozilla Firefox (3.0.19)
Mozilla Firefox (3.5.16)
MP3 To Wave version 1.2
Nero 7 Premium
neroxml
NOD32 FiX
Nowe Gadu-Gadu
NVIDIA PhysX
Octoshape add-in for Adobe Flash Player
Outlive
Pando Media Booster
PhotoStage Slideshow Producer
PowerDVD
Pro Beach Soccer
PSSWCORE
Real Alternative 2.0.2
save2pc Light 3.56
Scan
Shaiya(POLAND)
Shockwave
Skoki Narciarskie 2002
Skype Toolbars
Skype™ 4.2
Smart MP3 Converter
Snikers4
Soldat 1.5.0
SolutionCenter
SpeedFan (remove only)
Spybot - Search & Destroy
Status
Steam
System Antywirusowy NOD32
t@b ZS4 Video Editor v0.958-686
The Movies(TM)
The Movies(TM) 1.1 Patch
The Sims
Tony Hawk's Pro Skater 3®
Toolbox
Total Commander (Remove or Repair)
TrayApp
UnloadSupport
VideoPad Video Editor
VideoToolkit01
WapSter AQQ
WebReg
Winamp (remove only)
Windows Live installer
Windows Live Messenger
Xvid 1.2.1 final uninstall
XviD MPEG-4 Codec
==== End Of File ===========================
(http://forums.spybot.info/showthread.php?t=16806)Last edited by tashi; Feb 13th, 2011 at 07:54 PM. Reason: Merged 3 posts, removed HJT and CF logs. :-)
-----------------------------------------------------
Updating topic, because now it gotten worse :( Processor usage is 100% all the time and it's impossible to work on the computer. If you guys can, please help me to resolve this problem, because the format is really the last thing i want :) You've helped me with other issue couple of years ago and it would be nice to get such an professional help and assistance again :)
-------------------------------------------------------
The Waiting Room: Post here if waiting for help four days (http://forums.spybot.info/forumdisplay.php?f=37)
It's annoying, because it pops everytime I turn on my computer no matter if I allow or disallow changes to registry. And if I want to disallow changes, it pops again in second or two. My computer started to work a little bit slower, not really a huge difference, but still annoys me a bit.
I've used combofix, spybot, ESET NOD scans on both normal and safe windows mode.
Edit
Please do NOT run 'FIXES' (ComboFix etc) without being asked (http://forums.spybot.info/showthread.php?t=16806)
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)
Teatimer logs: ("Odmówiono" means "denied" in my language)
2011-02-13 23:48:30 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:48:32 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:48:36 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:48:38 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:49:29 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:49:32 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:49:33 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-13 23:55:36 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:01:46 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:01:51 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:01:53 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:01:55 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:02:00 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:02:01 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
2011-02-14 00:03:58 Odmówiono (based on user decision) value "NoDriveTypeAutoRun" (new data: "hex:B1,00,00,") zmienione in System Startup user entry!
And I'm terribly sorry for bumping the topic again, I forgot about DDS logs, here are those:
DDS (Ver_10-12-12.02) - NTFS_AMD64
Run by Ja at 0:37:44,61 on 2011-02-14
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_11
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1250.48.1045.18.4094.2963 [GMT 1:00]
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Eset\nod32krn.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\ESET\nod32kui.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
C:\Users\Ja\Downloads\dds.com
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Pomocnik rejestracji usługi Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
mRun: [nod32kui] "C:\Program Files (x86)\Eset\nod32kui.exe" /WAITSERVICE
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableInstallerDetection = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&ksport do programu Microsoft Excel - C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Pobierz plik wideo we Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
IE: Pobierz w Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
IE: Pobierz wszystkie pliki w Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
IE: Pobierz zaznaczone w Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - C:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
LSP: C:\Windows\system32\imon.dll
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files%20(x86)/Plants%20vs.%20Zombies/Images/stg_drm.ocx
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files%20(x86)/Plants%20vs.%20Zombies/Images/armhelper.ocx
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\0moqeuay.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2672188&SearchSource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2672188&q=
FF - component: C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\0moqeuay.default\extensions\{0ed38a68-9a97-450a-a349-62d04f4cc940}\components\FFExternalAlert.dll
FF - component: C:\Users\Ja\AppData\Roaming\Mozilla\Firefox\Profiles\0moqeuay.default\extensions\{0ed38a68-9a97-450a-a349-62d04f4cc940}\components\RadioWMPCore.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: C:\ProgramData\Gadu-Gadu 10\_userdata\npgg.4.dll
FF - plugin: C:\ProgramData\Gadu-Gadu 10\_userdata\nppl3260.dll
FF - plugin: C:\ProgramData\Gadu-Gadu 10\_userdata\nprpjplug.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: dollarsgroup Toolbar: {0ed38a68-9a97-450a-a349-62d04f4cc940} - %profile%\extensions\{0ed38a68-9a97-450a-a349-62d04f4cc940}
FF - Ext: OneManga Manager: {bbeee172-6a96-6f83-cf0c-a3bf46b77f94} - %profile%\extensions\{bbeee172-6a96-6f83-cf0c-a3bf46b77f94}
============= SERVICES / DRIVERS ===============
R2 NOD32krn;NOD32 Kernel Service;C:\Program Files (x86)\ESET\nod32krn.exe [2008-1-1 552064]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2008-1-21 93696]
=============== Created Last 30 ================
2011-02-13 22:57:30 -------- d-----w- C:\Users\Ja\AppData\Local\temp
2011-02-13 22:55:02 -------- d-----w- C:\$RECYCLE.BIN
2011-02-13 22:45:45 388096 ----a-r- C:\Users\Ja\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-13 22:45:44 -------- d-----w- C:\Program Files (x86)\HJTTTT
2011-02-13 22:36:56 98816 ----a-w- C:\Windows\sed.exe
2011-02-13 22:36:56 89088 ----a-w- C:\Windows\MBR.exe
2011-02-13 22:36:56 256512 ----a-w- C:\Windows\PEV.exe
2011-02-13 22:36:56 161792 ----a-w- C:\Windows\SWREG.exe
2011-02-13 22:34:44 318976 ----a-w- C:\Windows\SysWow64\CF30696.exe
2011-02-13 22:28:26 318976 ----a-w- C:\Windows\SysWow64\CF23942.exe
2011-02-13 22:28:22 8704 ----a-w- C:\Windows\System32\drivers\PROCEXP90.SYS
2011-02-13 22:27:52 318976 ----a-w- C:\Windows\SysWow64\cmd.execf
2011-02-13 22:12:02 318976 ----a-w- C:\Windows\SysWow64\CF29190.exe
2011-02-11 13:12:40 -------- d-----w- C:\Users\Ja\AppData\Roaming\codeblocks
2011-02-11 11:12:42 -------- d-----w- C:\Users\Ja\WapSter
2011-02-11 11:12:21 -------- d-----w- C:\Program Files (x86)\WapSter
2011-02-09 10:11:11 -------- d-----w- C:\Users\Ja\AppData\Roaming\.minecraft server
2011-01-30 13:01:48 -------- d-----w- C:\Users\Ja\AppData\Roaming\.minecraft
==================== Find3M ====================
============= FINISH: 0:37:59,36 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft® Windows Vista™ Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 2008-01-01 01:50:26
System Uptime: 2011-02-13 23:54:30 (1 hours ago)
Motherboard: Gigabyte Technology Co., Ltd. | | P31-DS3L
Processor: Intel(R) Core(TM)2 Duo CPU E6550 @ 2.33GHz | Socket 775 | 2333/333mhz
==== Disk Partitions =========================
F: is CDROM ()
G: is CDROM ()
H: is Removable
I: is Removable
J: is Removable
K: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
@BIOS Ver.2.03
18 Wheels of Steel Haulin
Adobe Flash Player 10 Plugin
Adobe Reader 8 - Polish
AIO_Scan
Archiwizator WinRAR
Ashampoo Burning Studio 9.20
Astroburn Lite
Asystent rejestracji usługi Windows Live
BEU Net 2006
Black and White
BufferChm
Carmageddon II Carpocalypse Now
CDBurnerXP
Copy
CustomerResearchQFolder
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DJ_AIO_ProductContext
DJ_AIO_Software
DJ_AIO_Software_min
eSupportQFolder
EVEREST Ultimate Edition v5.02
F4100
F4100_doccd
F4100_Help
Fraps (remove only)
Free Download Manager 2.5
Free Mp3 Wma Converter V 1.91
Gadu-Gadu 10
Gadu-Gadu 7.7
GG Tools
GTAIII
Guitar Pro 5.2
HiJackThis
HijackThis 2.0.2
HP Photosmart Essential2.01
HP Smart Web Printing
HP Update
HPProductAssistant
HPSSupply
Java(TM) 6 Update 11
JDownloader
K-Lite Codec Pack 4.2.5 (Full)
Lineage II
MadOnion.com/3DMark2001 SE
Mafia II - Demo
MarketResearch
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Minecraft Beta 1.1_02
Mozilla Firefox (3.0.19)
Mozilla Firefox (3.5.16)
MP3 To Wave version 1.2
Nero 7 Premium
neroxml
NOD32 FiX
Nowe Gadu-Gadu
NVIDIA PhysX
Octoshape add-in for Adobe Flash Player
Outlive
Pando Media Booster
PhotoStage Slideshow Producer
PowerDVD
Pro Beach Soccer
PSSWCORE
Real Alternative 2.0.2
save2pc Light 3.56
Scan
Shaiya(POLAND)
Shockwave
Skoki Narciarskie 2002
Skype Toolbars
Skype™ 4.2
Smart MP3 Converter
Snikers4
Soldat 1.5.0
SolutionCenter
SpeedFan (remove only)
Spybot - Search & Destroy
Status
Steam
System Antywirusowy NOD32
t@b ZS4 Video Editor v0.958-686
The Movies(TM)
The Movies(TM) 1.1 Patch
The Sims
Tony Hawk's Pro Skater 3®
Toolbox
Total Commander (Remove or Repair)
TrayApp
UnloadSupport
VideoPad Video Editor
VideoToolkit01
WapSter AQQ
WebReg
Winamp (remove only)
Windows Live installer
Windows Live Messenger
Xvid 1.2.1 final uninstall
XviD MPEG-4 Codec
==== End Of File ===========================
(http://forums.spybot.info/showthread.php?t=16806)Last edited by tashi; Feb 13th, 2011 at 07:54 PM. Reason: Merged 3 posts, removed HJT and CF logs. :-)
-----------------------------------------------------
Updating topic, because now it gotten worse :( Processor usage is 100% all the time and it's impossible to work on the computer. If you guys can, please help me to resolve this problem, because the format is really the last thing i want :) You've helped me with other issue couple of years ago and it would be nice to get such an professional help and assistance again :)
-------------------------------------------------------
The Waiting Room: Post here if waiting for help four days (http://forums.spybot.info/forumdisplay.php?f=37)