Witam, mam spory problem ze swoim komputerem. Konfoguracja nie jest taka zła, mimo, że kupioony jakis czas temu. procek Pentium D 2.66 GHz, 1GB ram, 250 dysk twardy na sacie, zasilacz feel 350atx, płyta Intela D865GSA, choć jeszcze na AGPX8 GF FX5500. Niedawno próbowałem wsadzić lepsza grafikę, Ati hd2600xt, ale nie było wielkiej poprawy nawet na Carbonie, który jakiś czas temu mi śmigał bardzo ładnie na podstawowych ustawieniach, a na tej Ati zaczął się ciąć Sprawe ze sterownikami przerabiałem, ale nie o to chodzi. Mam porównanie tego co było kiedys do tego co teraz. komputer cos strasznie spowalnia, owszem , do internetu sie nadaje, ale wszelkie gry, nawet te mniej wymagające nie bardzo chcą iść. Skanowałem na obecność wszelkiego rodzaju robactwa, mozliwymi programami, adware, spyboat itp ale nic nie znalazłem. Na nowo postawiłem system i o dziwo tez niewiele to zmieniło. Dziwnie chodzi zasilacz, po uruchomieniu wolno, po chwili jakby szybciej, i po następnej znowu szybciej, mimo, iż nic nie włączam w danym momencie. Co jeszcze zauważyłem, komputer czasami nie chce sie wyłączyć (standardowo) albo uruchomić ponownie, jak przeinstalowywałem system, to w pewnym momencie wystapoił jakiś błąd, chyba dysku i musiałem instalację powtórzyć. Skanowałem narzędziem windowsowskim dysk w poszukiwaniu bad sektorów, ewentualnie w celu naprawienia dysku, ale jakoś nic nie wykazało. programów nie jest dużo. Same podstawowe, a mimo tego widze jakies spowolnienie jego działania. podejrzewam, ze jakaś część zaczyna siadać, tylko jaka??? I dzieje się to powoli, co mnie dziwi, bo albo cos walnie albo nie, a takie psucie na raty jest nieuzasadnione, wydawałoby się.
Ponizej zamieszczę dla pewności logi kolejno z hijackthis, silent runnera i combofixa, moze cos one wam, cos wiecej powiedzą. Prosze o sprawdzenie tych co się na tym znają. Aha, wgrałem tez nowego biosa, programem spod windy, nie było to skomplikowane, ale awarii raczej nie powinno być, bo wskazywał na sukces. po tym przywróciłem Bios do ustawień domyślnych, ale to co mnie zdziwiło, to jak przełączałem zakładki biosa, po prostu reagowały z opóźnieniem na klawisze, widać było że są lekkie zwiechy na biosie!
HIJACKTHIS
Logfile of HijackThis v1.99.1
Scan saved at 20:32:01, on 2008-11-03
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\PROGRA~1\NEOSTR~1\TaskBarIcon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
E:\Instalki\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM…\Run: [soundMan] SOUNDMAN.EXE
O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program Files\Java\jre6\bin\jusched.exe”
O4 - HKLM…\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [nwiz] nwiz.exe /install
O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM…\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM…\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM…\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\GestMaj.exe TaskBarIcon.exe
O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU…\Run: [Gadu-Gadu] “C:\Program Files\Gadu-Gadu\gg.exe” /tray
O4 - HKCU…\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] “C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe”
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Eksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
SILENT RUNNER
“Silent Runners.vbs”, revision 46, http://www.silentrunners.org/
Operating System: Windows XP
Output limited to non-default values, except where indicated by “{++}”
Startup items buried in registry:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
“CTFMON.EXE” = “C:\WINDOWS\system32\ctfmon.exe” [MS]
“Gadu-Gadu” = ““C:\Program Files\Gadu-Gadu\gg.exe” /tray” [“Gadu-Gadu S.A.”]
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}” = ““C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe”” [“Nero AG”]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
“SoundMan” = “SOUNDMAN.EXE” [“Realtek Semiconductor Corp.”]
“SunJavaUpdateSched” = ““C:\Program Files\Java\jre6\bin\jusched.exe”” [“Sun Microsystems, Inc.”]
“NeroFilterCheck” = “C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe” [“Nero AG”]
“Adobe Reader Speed Launcher” = ““C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”” [“Adobe Systems Incorporated”]
“NvCplDaemon” = “RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup” [MS]
“nwiz” = “nwiz.exe /install” [“NVIDIA Corporation”]
“NvMediaCenter” = “RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit” [MS]
“AdslTaskBar” = “rundll32.exe stmctrl.dll,TaskBar” [MS]
“WOOWATCH” = “C:\PROGRA~1\NEOSTR~1\Watch.exe” [“France Télécom RD”]
“WOOTASKBARICON” = “C:\PROGRA~1\NEOSTR~1\GestMaj.exe TaskBarIcon.exe” [“France Télécom RD”]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided)
- {HKLM…CLSID} = “Adobe PDF Reader Link Helper”
\InProcServer32(Default) = “C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided)
- {HKLM…CLSID} = “Java Plug-In SSV Helper”
\InProcServer32(Default) = “C:\Program Files\Java\jre6\bin\ssv.dll” [“Sun Microsystems, Inc.”]
{DBC80044-A445-435b-BC74-9C25C1C588A9}(Default) = (no title provided)
- {HKLM…CLSID} = “Java Plug-In 2 SSV Helper”
\InProcServer32(Default) = “C:\Program Files\Java\jre6\bin\jp2ssv.dll” [“Sun Microsystems, Inc.”]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C}(Default) = “JQSIEStartDetectorImpl”
- {HKLM…CLSID} = “JQSIEStartDetectorImpl Class”
\InProcServer32(Default) = “C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll” [“Sun Microsystems, Inc.”]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
“{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Rozszerzenie CPL kadrowania wyświetlania”
- {HKLM…CLSID} = “Rozszerzenie CPL kadrowania wyświetlania”
\InProcServer32(Default) = “deskpan.dll” [file not found]
“{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu”
- {HKLM…CLSID} = “HyperTerminal Icon Ext”
\InProcServer32(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”]
“{e82a2d71-5b2f-43a0-97b8-81be15854de8}” = “ShellLink for Application References”
- {HKLM…CLSID} = “ShellLink for Application References”
\InProcServer32(Default) = “C:\WINDOWS\system32\dfshim.dll” [MS]
“{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}” = “Shell Icon Handler for Application References”
- {HKLM…CLSID} = “Shell Icon Handler for Application References”
\InProcServer32(Default) = “C:\WINDOWS\system32\dfshim.dll” [MS]
“{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension”
- {HKLM…CLSID} = “WinRAR”
\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data]
“{42042206-2D85-11D3-8CFF-005004838597}” = “Microsoft Office HTML Icon Handler”
- {HKLM…CLSID} = (no title provided)
\InProcServer32(Default) = “C:\Program Files\Microsoft Office\Office10\msohev.dll” [MS]
“{21569614-B795-46b1-85F4-E737A8DC09AD}” = “Shell Search Band”
- {HKLM…CLSID} = “Shell Search Band”
\InProcServer32(Default) = “C:\WINDOWS\system32\browseui.dll” [MS]
“{0561EC90-CE54-4f0c-9C55-E226110A740C}” = “Haali Column Provider”
- {HKLM…CLSID} = “Haali Column Provider”
\InProcServer32(Default) = “C:\WINDOWS\system32\mmfinfo.dll” [null data]
“{5574006C-28F5-4a65-A28C-74DE6BFBE0BB}” = “Haali Matroska Shell Property Page”
- {HKLM…CLSID} = “Haali Matroska Shell Property Page”
\InProcServer32(Default) = “C:\WINDOWS\system32\mmfinfo.dll” [null data]
“{327669A0-59A7-4be9-B99E-1C9F3A57611A}” = “Haali Matroska Thumbnail Extractor”
- {HKLM…CLSID} = “Haali Matroska Thumbnail Extractor”
\InProcServer32(Default) = “C:\WINDOWS\system32\mmfinfo.dll” [null data]
“{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2}” = “NeroCoverEd Live Icons”
- {HKLM…CLSID} = “NeroCoverEdLiveIcons Class”
\InProcServer32(Default) = “C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll” [“Nero AG”]
“{A70C977A-BF00-412C-90B7-034C51DA2439}” = “NvCpl DesktopContext Class”
- {HKLM…CLSID} = “DesktopContext Class”
\InProcServer32(Default) = “C:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”]
“{FFB699E0-306A-11d3-8BD1-00104B6F7516}” = “Play on my TV helper”
- {HKLM…CLSID} = “NVIDIA CPL Extension”
\InProcServer32(Default) = “C:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”]
“{1CDB2949-8F65-4355-8456-263E7C208A5D}” = “Desktop Explorer”
- {HKLM…CLSID} = “Desktop Explorer”
\InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”]
“{1E9B04FB-F9E5-4718-997B-B8DA88302A47}” = “Desktop Explorer Menu”
- {HKLM…CLSID} = (no title provided)
\InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”]
“{1E9B04FB-F9E5-4718-997B-B8DA88302A48}” = “nView Desktop Context Menu”
- {HKLM…CLSID} = “nView Desktop Context Menu”
\InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”]
HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{0561EC90-CE54-4f0c-9C55-E226110A740C}(Default) = “Haali Column Provider”
- {HKLM…CLSID} = “Haali Column Provider”
\InProcServer32(Default) = “C:\WINDOWS\system32\mmfinfo.dll” [null data]
{F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = “PDF Column Info”
- {HKLM…CLSID} = “PDF Shell Extension”
\InProcServer32(Default) = “C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”]
HKLM\Software\Classes*\shellex\ContextMenuHandlers\
Cover Designer(Default) = “{73FCA462-9BD5-4065-A73F-A8E5F6904EF7}”
- {HKLM…CLSID} = “NeroCoverEdContextMenu Class”
\InProcServer32(Default) = “C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll” [“Nero AG”]
WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}”
- {HKLM…CLSID} = “WinRAR”
\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}”
- {HKLM…CLSID} = “WinRAR”
\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}”
- {HKLM…CLSID} = “WinRAR”
\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data]
Active Desktop and Wallpaper:
Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKCU\Control Panel\Desktop\
“Wallpaper” = “C:\Documents and Settings\Robunio\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp”
Startup items in “Robunio” “All Users” startup folders:
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
“Microsoft Office” - shortcut to: “C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l” [MS]
Winsock2 Service Provider DLLs:
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS]
000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS]
000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{FB5F1910-F110-11D2-BB9E-00C04F795683}\
“ButtonText” = “Messenger”
“MenuText” = “Windows Messenger”
“Exec” = “C:\Program Files\Messenger\msmsgs.exe” [MS]
Miscellaneous IE Hijack Points
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
Missing lines (compared with English-language version):
“{08C06D61-F1F3-4799-86F8-BE1A89362C85}” = (no title provided)
- {HKLM…CLSID} = “Search Class”
\InProcServer32(Default) = “C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL” [empty string]
Running Services (Display Name, Service Name, Path {Service DLL}):
France Telecom Routing Table Service, FTRTSVC, “C:\WINDOWS\System32\FTRTSVC.exe” [“France Telecom”]
Java Quick Starter, JavaQuickStarterService, ““C:\Program Files\Java\jre6\bin\jqs.exe” -service -config “C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf”” [“Sun Microsystems, Inc.”]
NMIndexingService, NMIndexingService, ““C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe”” [“Nero AG”]
NVIDIA Display Driver Service, NVSvc, “C:\WINDOWS\system32\nvsvc32.exe” [“NVIDIA Corporation”]
Windows User Mode Driver Framework, UMWdf, “C:\WINDOWS\system32\wdfmgr.exe” [MS]
-
This report excludes default entries except where indicated.
-
To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
- To search all directories of local fixed drives for DESKTOP.INI
DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
use the -supp parameter or answer “No” at the first message box.
---------- (total run time: 27 seconds, including 10 seconds for message boxes)
COMBOFIX
ComboFix 08-11-01.04 - Robunio 2008-11-03 20:37:46.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.656 [GMT 1:00]
Uruchomiony z: E:\Instalki\Sterowniki do kompa-grafika, lan, audio\ComboFix.exe
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA
.
((((((((((((((((((((((((( Pliki utworzone od 2008-10-03 do 2008-11-03 )))))))))))))))))))))))))))))))
.
2008-11-03 13:35 . 2008-11-03 13:35
2008-11-03 13:33 . 2008-04-13 19:45 10,368 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-11-03 13:33 . 2008-04-13 19:45 10,368 --a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2008-11-02 20:04 . 2008-11-02 20:20
2008-11-02 08:38 . 2008-04-14 18:20 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-11-02 08:08 . 2008-11-02 08:08
2008-11-02 08:08 . 2008-11-02 08:08
2008-11-02 08:08 . 2008-11-02 08:08
2008-11-02 08:08 . 2008-11-02 08:08
2008-11-02 08:06 . 2008-11-02 08:06
2008-11-02 08:03 . 2008-11-02 08:32 2,675 --a------ C:\WINDOWS\imsins.BAK
2008-11-01 21:46 . 2008-11-01 21:46
2008-11-01 07:10 . 2008-11-01 07:10
2008-11-01 07:10 . 2008-11-01 07:10
2008-11-01 07:10 . 2006-06-02 21:38 425,984 -ra------ C:\WINDOWS\system32\stmcfg32.dll
2008-11-01 07:10 . 2006-06-02 14:01 151,552 -ra------ C:\WINDOWS\system32\stmctrl.dll
2008-11-01 07:10 . 2008-11-01 07:10 2,849 --a------ C:\WINDOWS\stsetup.htm
2008-11-01 07:09 . 2004-08-23 13:49 40,960 --a------ C:\WINDOWS\system32\FTRTSVC.exe
2008-11-01 07:09 . 2005-10-06 14:55 36,864 --a------ C:\WINDOWS\system32\IfHelper.dll
2008-10-31 19:20 . 2004-08-23 13:50 32,768 --a------ C:\WINDOWS\system32\WooDial2000.dll
2008-10-31 19:02 . 2003-08-04 13:22 94,208 --a------ C:\WINDOWS\system32\W32n50.dll
2008-10-31 19:02 . 2003-08-04 13:22 16,128 --------- C:\WINDOWS\system32\PCANDIS5.SYS
2008-10-31 19:01 . 2008-11-03 20:38
2008-10-31 18:56 . 2008-10-31 18:56
2008-10-31 18:20 . 2008-10-31 18:22
2008-10-31 18:20 . 2008-10-31 18:20
2008-10-31 18:20 . 2005-12-10 04:16 180,224 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-10-31 18:20 . 2005-12-10 03:06 180,224 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-10-31 18:20 . 2008-11-03 20:29 43,573 --a------ C:\WINDOWS\system32\nvapps.xml
2008-10-31 18:20 . 2005-12-10 03:06 16,356 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-10-29 14:33 . 2008-10-29 14:33
2008-10-29 14:33 . 2008-10-29 14:33
2008-10-29 14:33 . 2008-05-27 11:41 117,672 --a------ C:\WINDOWS\system32\drivers\s0017unic.sys
2008-10-29 14:33 . 2008-05-27 11:41 115,496 --a------ C:\WINDOWS\system32\drivers\s0017mgmt.sys
2008-10-29 14:33 . 2008-05-27 11:41 10,792 --a------ C:\WINDOWS\system32\drivers\s0017cr.sys
2008-10-29 14:32 . 2008-10-29 14:32
2008-10-29 14:32 . 2008-10-29 14:32
2008-10-29 14:32 . 2008-10-29 14:32
2008-10-29 14:32 . 2008-05-27 11:41 122,152 --a------ C:\WINDOWS\system32\drivers\s0017mdm.sys
2008-10-29 14:32 . 2008-05-27 11:41 111,912 --a------ C:\WINDOWS\system32\drivers\s0017obex.sys
2008-10-29 14:32 . 2008-05-27 11:41 90,536 --a------ C:\WINDOWS\system32\drivers\s0017bus.sys
2008-10-29 14:32 . 2008-05-27 11:41 25,768 --a------ C:\WINDOWS\system32\drivers\s0017nd5.sys
2008-10-29 14:32 . 2008-05-27 11:41 15,016 --a------ C:\WINDOWS\system32\drivers\s0017mdfl.sys
2008-10-29 14:32 . 2008-05-27 11:41 12,200 --a------ C:\WINDOWS\system32\drivers\s0017whnt.sys
2008-10-29 14:32 . 2008-05-27 11:41 12,200 --a------ C:\WINDOWS\system32\drivers\s0017wh.sys
2008-10-29 14:32 . 2008-05-27 11:41 12,200 --a------ C:\WINDOWS\system32\drivers\s0017cmnt.sys
2008-10-29 14:32 . 2008-05-27 11:41 12,200 --a------ C:\WINDOWS\system32\drivers\s0017cm.sys
2008-10-29 14:31 . 2008-10-29 14:31
2008-10-29 13:21 . 2008-10-29 13:31
2008-10-28 21:04 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-10-28 19:06 . 2008-10-28 19:06
2008-10-28 18:24 . 2005-12-10 03:06 3,955,456 --a------ C:\WINDOWS\system32\nv4_disp.dll
2008-10-28 18:24 . 2005-12-10 03:06 3,955,456 --a–c— C:\WINDOWS\system32\dllcache\nv4_disp.dll
2008-10-28 18:24 . 2005-12-10 03:06 3,536,768 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-10-28 18:24 . 2005-12-10 03:06 3,536,768 --a–c— C:\WINDOWS\system32\dllcache\nv4_mini.sys
2008-10-28 17:51 . 2008-10-31 18:14 10 --a------ C:\WINDOWS\WININIT.INI
2008-10-28 17:13 . 2008-10-28 17:13 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-10-28 16:49 . 2008-10-28 16:49
2008-10-28 16:17 . 2008-10-28 16:17
2008-10-28 16:14 . 2008-10-28 16:14
2008-10-28 00:42 . 2008-11-01 22:00 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-10-28 00:31 . 2008-10-31 18:28 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-10-28 00:31 . 2008-10-28 16:58 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-10-28 00:31 . 2008-10-31 18:28 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-10-27 23:48 . 2008-10-27 23:48
2008-10-27 23:48 . 1998-11-13 14:10 307,200 --a------ C:\WINDOWS\IsUn0415.exe
2008-10-27 23:48 . 2001-04-04 14:00 245,760 --------- C:\WINDOWS\system32\DECO_32.DLL
2008-10-27 23:45 . 2008-10-27 23:46
2008-10-27 23:26 . 2008-10-27 23:26
2008-10-27 23:16 . 2008-10-28 21:04
2008-10-27 23:16 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2008-10-27 23:16 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2008-10-27 23:16 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2008-10-27 23:16 . 2007-03-12 16:42 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2008-10-27 23:16 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2008-10-27 23:16 . 2007-03-15 16:57 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2008-10-27 23:16 . 2007-06-20 20:46 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2008-10-27 23:16 . 2007-04-04 18:55 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2008-10-27 23:16 . 2007-01-24 15:27 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2008-10-27 23:16 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2008-10-27 23:16 . 2007-06-20 20:45 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2008-10-27 23:16 . 2007-03-05 12:42 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2008-10-27 23:04 . 2004-08-04 00:35 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-10-27 23:03 . 2008-10-27 23:03
2008-10-27 22:48 . 2008-10-27 22:48
2008-10-27 22:43 . 2008-10-27 22:43
2008-10-27 22:43 . 2008-10-27 22:46
2008-10-27 22:43 . 2008-10-27 22:43
2008-10-27 22:32 . 2008-10-27 22:31 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-10-27 22:32 . 2008-10-27 22:31 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-27 22:31 . 2008-10-27 22:31
2008-10-27 22:27 . 2008-10-27 22:27
2008-10-27 22:22 . 2008-10-27 22:22
2008-10-27 22:18 . 2008-10-27 22:18
2008-10-27 22:18 . 2008-10-27 22:53
2008-10-27 22:13 . 2008-10-27 22:13
2008-10-27 22:13 . 2008-10-27 22:13 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-10-27 22:03 . 2008-10-27 22:03 892,928 --a------ C:\WINDOWS\system32\iconv.dll
2008-10-27 22:03 . 2008-10-27 22:03 860,160 --a------ C:\WINDOWS\system32\lameACM.acm
2008-10-27 22:03 . 2008-10-27 22:03 688,128 --a------ C:\WINDOWS\system32\mmamr.ax
2008-10-27 22:03 . 2008-10-27 22:03 487,936 --a------ C:\WINDOWS\system32\madFlac.ax
2008-10-27 22:03 . 2008-10-27 22:03 348,160 --a------ C:\WINDOWS\system32\CoreVorbis.ax
2008-10-27 22:03 . 2008-10-27 22:03 319,488 --a------ C:\WINDOWS\system32\CoreAAC.ax
2008-10-27 22:03 . 2008-04-14 18:10 290,816 --a------ C:\WINDOWS\system32\l3codeca.acm
2008-10-27 22:02 . 2008-10-27 22:02 516,096 --a------ C:\WINDOWS\system32\MP4Splitter.ax
2008-10-27 22:02 . 2008-10-27 22:02 163,840 --a------ C:\WINDOWS\system32\ts.dll
2008-10-27 22:02 . 2008-10-27 22:02 148,992 --a------ C:\WINDOWS\system32\mkx.dll
2008-10-27 22:02 . 2008-10-27 22:02 108,032 --a------ C:\WINDOWS\system32\avi.dll
2008-10-27 22:02 . 2008-10-27 22:02 23,552 --a------ C:\WINDOWS\system32\mkunicode.dll
2008-10-27 21:53 . 2008-10-27 21:53 116,540 --a------ C:\WINDOWS\system32\ffdshow.ax
2008-10-27 21:51 . 2008-09-08 11:41 333,824 -----c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-27 21:51 . 2008-06-14 18:36 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-10-27 21:51 . 2008-06-14 18:36 273,024 -----c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-10-27 21:50 . 2008-09-15 16:27 1,846,656 -----c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-27 21:47 . 2008-10-27 21:47 3,569,152 --a------ C:\WINDOWS\system32\libavcodec.dll
2008-10-27 21:47 . 2008-10-27 21:47 2,041,363 --a------ C:\WINDOWS\system32\x264vfw.dll
2008-10-27 21:46 . 2008-08-14 14:26 2,190,464 -----c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-27 21:46 . 2008-08-14 14:26 2,146,816 -----c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-27 21:46 . 2008-08-14 14:26 2,067,328 -----c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-27 21:46 . 2008-08-14 14:26 2,025,472 -----c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-27 21:41 . 2008-10-27 21:41
2008-10-27 21:33 . 2008-04-11 20:06 691,712 -----c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-10-27 21:33 . 2008-05-08 15:02 203,136 -----c— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-10-27 21:31 . 2008-11-01 17:01
2008-10-27 21:31 . 2008-10-27 21:31 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-29 13:33 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-10-27 21:03 258,048 ----a-w C:\WINDOWS\system32\libFLAC.dll
2008-10-27 21:02 79,360 ----a-w C:\WINDOWS\system32\mkzlib.dll
2008-10-27 21:02 159,744 ----a-w C:\WINDOWS\system32\mmfinfo.dll
2008-10-27 21:02 141,312 ----a-w C:\WINDOWS\system32\mp4.dll
2008-10-27 21:02 120,832 ----a-w C:\WINDOWS\system32\ogm.dll
2008-10-27 20:47 56,832 ----a-w C:\WINDOWS\system32\ff_unrar.dll
2008-10-27 20:47 52,224 ----a-w C:\WINDOWS\system32\ff_liba52.dll
2008-10-27 20:47 456,192 ----a-w C:\WINDOWS\system32\libmplayer.dll
2008-10-27 20:47 397,312 ----a-w C:\WINDOWS\system32\ff_libfaad2.dll
2008-10-27 20:47 23,552 ----a-w C:\WINDOWS\system32\ff_wmv9.dll
2008-10-27 20:47 172,032 ----a-w C:\WINDOWS\system32\ff_libdts.dll
2008-10-27 20:47 143,360 ----a-w C:\WINDOWS\system32\ff_libmad.dll
2008-10-27 20:47 135,168 ----a-w C:\WINDOWS\system32\ff_samplerate.dll
2008-10-27 20:47 119,296 ----a-w C:\WINDOWS\system32\libmpeg2_ff.dll
2008-10-27 20:47 118,784 ----a-w C:\WINDOWS\system32\ff_realaac.dll
2008-10-27 20:47 102,912 ----a-w C:\WINDOWS\system32\ff_tremor.dll
2008-10-27 20:46 921,600 ----a-w C:\WINDOWS\system32\vorbisenc.dll
2008-10-27 20:46 9,216 ----a-w C:\WINDOWS\system32\cpuinf32.dll
2008-10-27 20:46 45,056 ----a-w C:\WINDOWS\system32\ogg.dll
2008-10-27 20:46 245,760 ----a-w C:\WINDOWS\system32\mplvpx.dll
2008-10-27 20:46 237,568 ----a-w C:\WINDOWS\system32\OggDS.dll
2008-10-27 20:46 188,416 ----a-w C:\WINDOWS\system32\vorbis.dll
2008-10-27 20:46 1,415,680 ----a-w C:\WINDOWS\system32\WMV9VCM.dll
2008-10-27 20:45 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-10-27 20:41 755,027 ----a-w C:\WINDOWS\system32\xvidcore.dll
2008-10-27 20:41 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll
2008-10-27 19:29 --------- d-----w C:\Documents and Settings\Robunio\Dane aplikacji\ATI
2008-10-27 19:24 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-27 19:24 --------- d-----w C:\Program Files\Common Files\ATI Technologies
2008-10-27 19:11 --------- d-----w C:\Program Files\microsoft frontpage
2008-10-27 19:09 --------- d-----w C:\Program Files\Usługi online
2008-09-15 15:27 1,846,656 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:11 668,672 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:26 2,146,816 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:26 2,025,472 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((( snapshot@2008-11-03_16.03.12,40 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-03 19:29:57 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_79c.dat
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2008-04-14 15360]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2008-10-27 2127296]
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe” [2007-01-15 147456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre6\bin\jusched.exe” [2008-10-27 136600]
“NeroFilterCheck”=“C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe” [2006-01-12 155648]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 39792]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2005-12-10 7311360]
“NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2005-12-10 86016]
“WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2004-08-23 20480]
“WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\GestMaj.exe” [2004-10-14 32768]
“SoundMan”=“SOUNDMAN.EXE” [2006-11-17 C:\WINDOWS\SOUNDMAN.EXE]
“nwiz”=“nwiz.exe” [2005-12-10 C:\WINDOWS\system32\nwiz.exe]
“AdslTaskBar”=“stmctrl.dll” [2006-06-02 C:\WINDOWS\system32\stmctrl.dll]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2008-04-14 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“C:\Program Files\eMule\emule.exe”=
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-27 152984]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2003-08-12 60255]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);C:\WINDOWS\system32\DRIVERS\s0017bus.sys [2008-05-27 90536]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s0017mdfl.sys [2008-05-27 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s0017mdm.sys [2008-05-27 122152]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s0017mgmt.sys [2008-05-27 115496]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);C:\WINDOWS\system32\DRIVERS\s0017nd5.sys [2008-05-27 25768]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s0017obex.sys [2008-05-27 111912]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);C:\WINDOWS\system32\DRIVERS\s0017unic.sys [2008-05-27 117672]
S3 TaurusUsb;ADSL Modem USB Service;C:\WINDOWS\system32\DRIVERS\torususb.sys [2006-05-25 684265]
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\Robunio\Dane aplikacji\Mozilla\Firefox\Profiles\8rpwb1q8.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.wp.pl
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-03 20:40:22
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów …
skanowanie ukrytych wpisów autostartu …
skanowanie ukrytych plików …
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-11-03 20:42:39
ComboFix-quarantined-files.txt 2008-11-03 19:42:30
ComboFix2.txt 2008-11-03 15:05:09
Przed: 33 826 553 856 bajtów wolnych
Po: 33,845,563,392 bajtów wolnych
242 — E O F — 2008-11-02 08:44:31