Prośba o pomoc w analizie loga z HijackThis.

Witam!

Nie jestem pewien jednego wpisu w tym logu – "DLLcacheV2".

Czy nie jest to coś zbędnego?


Pozdrawiam!


Marcin K.


LOG:

Logfile of HijackThis v1.99.0
Scan saved at 23:32:58, on 2005–01–16
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32 vsvc32.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumFirewallPavFires.exe
C:Program FilesPanda SoftwarePanda Antivirus Platinumpavsrv51.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAVENGINE.EXE
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32RUNDLL32.EXE
C:WINDOWSsystem32CTHELPER.EXE
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE
C:PROGRA~1A4TechMouseAmoumain.exe
C:Program FilesD–Toolsdaemon.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumpavProxy.exe
C:Program FilesFreshDevicesFreshDownloadfd.exe
C:Program FilesWinampwinamp.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:Program FilesWinRARWinRAR.exe
C:DOCUME~1MarcinUSTAWI~1TempRar$EX07.156HijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.wp.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 – BHO: (no name) – {206E52E0–D52E–11D4–AD54–0000E86C26F6} – C:PROGRA~1FRESHD~1FRESHD~1fdcatch.dll
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [WINDVDPatch] CTHELPER.EXE
O4 – HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 – HKLM..Run: [Jet Detection] "C:Program FilesCreativeSBLivePROGRAMADGJDet.exe"
O4 – HKLM..Run: [SCANINICIO] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [DllCacherv2] C:WINDOWSsystem32dllcachev2.exe
O4 – HKLM..Run: [WheelMouse] C:PROGRA~1A4TechMouseAmoumain.exe
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [awxDTools] rundll32 C:PROGRA~1arniWORXAWXDTO~1awxDTools.dll,awxRegisterDll /r /s
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_04in pjpi142_04.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_04in pjpi142_04.dll
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O16 – DPF: {31B7EB4E–8B4B–11D1–A789–00A0CC6651A8} (Cult3D ActiveX Player) – http://www.cult3d.com/download/cult.cab
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102522892828
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – C:WINDOWSsystem32 vsvc32.exe
O23 – Service: Panda Firewall Service – Unknown – C:Program FilesPanda SoftwarePanda Antivirus PlatinumFirewallPavFires.exe
O23 – Service: Panda anti–virus service – Unknown – C:Program FilesPanda SoftwarePanda Antivirus Platinumpavsrv51.exe

Odpowiedzi: 3

MarcinK.:
Znaczy się "do kosza"??
:)
No ja mysle :wink: .

P.S. Chyba ze lubisz hodowac syfa :D .
EL NINO
Dodano
17.01.2005 01:11:45
Znaczy się "do kosza"??
:)

Pozdrawiam!!


Marcin K.
MarcinK.
Dodano
17.01.2005 00:54:54
O4 – HKLM..Run: [DllCacherv2] C:WINDOWSsystem32dllcachev2.exe

To BACKDOOR.LATEDA TROJAN
http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=41357
lub
http://www–cu.symantec.com/avcenter/venc/data/backdoor.lateda.html
EL NINO
Dodano
17.01.2005 00:51:16
MarcinK.
Dodano:
17.01.2005 00:39:03
Komentarzy:
3
Strona 1 / 1