ComboFix 08-09-14.02 - MARIA 2008-09-15 9:20:27.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.553 [GMT 2:00]
Uruchomiony z: E:\FILMY\ComboFix.exe
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA
.
((((((((((((((((((((((((( Pliki utworzone od 2008-08-15 do 2008-09-15 )))))))))))))))))))))))))))))))
.
2008-09-15 09:03 . 2008-09-15 09:03
2008-09-14 22:35 . 2008-09-14 22:35 22,016 --a------ C:\WINDOWS\system32\gxpta.dll
2008-09-14 22:35 . 2008-09-14 22:35 4,710 --a------ C:\WINDOWS\system32\c.ico
2008-09-12 19:10 . 2006-10-05 04:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-12 19:10 . 2006-10-05 04:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-09-12 19:09 . 2008-09-12 20:13
2008-09-12 10:06 . 2008-09-12 10:06
2008-09-12 10:06 . 2008-09-12 10:07
2008-09-12 10:05 . 2008-09-12 10:05
2008-09-12 10:03 . 2008-09-12 10:03
2008-09-12 10:02 . 2008-09-12 10:03
2008-09-12 10:02 . 2008-09-12 10:02
2008-09-12 10:02 . 2008-09-12 10:02
2008-09-12 10:02 . 2008-09-12 10:02
2008-09-12 10:02 . 2008-09-12 10:03
2008-09-12 10:02 . 2008-05-07 07:39 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-09-12 10:02 . 2008-05-07 07:38 659,968 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-09-12 10:02 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-09-12 10:02 . 2008-05-07 07:38 20,864 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-09-12 10:02 . 2008-05-07 07:38 17,536 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-09-12 10:02 . 2008-05-07 07:38 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-09-12 10:02 . 2008-06-06 09:24 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-09-12 10:01 . 2008-09-12 10:01
2008-09-12 09:52 . 2008-04-13 20:45 26,112 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-09-12 09:52 . 2008-04-13 20:45 26,112 --a–c— C:\WINDOWS\system32\dllcache\usbser.sys
2008-09-12 09:49 . 2008-09-12 09:49 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-12 09:49 . 2008-09-12 09:49 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-09-10 18:21 . 2008-09-10 18:21
2008-09-09 23:39 . 2008-09-09 23:39
2008-09-09 23:08 . 2008-09-09 23:08
2008-09-09 23:08 . 2008-09-09 23:08 82,380 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS
2008-09-09 23:07 . 2008-09-09 23:09
2008-09-09 23:06 . 2008-09-09 23:06
2008-09-09 23:06 . 2008-09-09 23:06 34 --a------ C:\WINDOWS\hpfsched.ini
2008-09-09 23:05 . 2002-11-22 21:49 356,352 --------- C:\WINDOWS\system32\hphc3204.dll
2008-09-09 23:05 . 2002-11-22 21:49 50,896 -ra------ C:\WINDOWS\system32\drivers\hphid411.sys
2008-09-09 23:05 . 2002-11-22 21:49 50,276 -ra------ C:\WINDOWS\system32\drivers\hphs2k11.sys
2008-09-09 23:05 . 2002-11-22 21:49 18,928 -ra------ C:\WINDOWS\system32\drivers\hphius11.sys
2008-09-09 23:05 . 2002-11-22 21:49 16,112 -ra------ C:\WINDOWS\system32\drivers\hphipr11.sys
2008-09-09 23:05 . 2002-11-22 21:49 4,760 --------- C:\WINDOWS\hphmdl11.dat
2008-09-09 22:36 . 2008-09-09 22:36 381,460 --a------ C:\WINDOWS\system32\ll
2008-09-09 22:36 . 2008-09-09 22:36 4,343 --a------ C:\WINDOWS\system32\DOT4_002
2008-09-09 22:04 . 2008-09-15 08:55 564 --a------ C:\hpfr5550.xml
2008-09-09 21:39 . 2008-09-09 23:02
2008-09-09 21:22 . 2008-09-09 21:48
2008-09-09 21:22 . 2008-09-09 21:22
2008-09-09 21:22 . 2006-01-06 21:07 270,336 --a------ C:\WINDOWS\system32\hpzcon07.dll
2008-09-09 21:22 . 2006-01-06 21:07 208,896 --a------ C:\WINDOWS\system32\hpzcoi07.dll
2008-09-09 20:53 . 2008-04-13 20:39 206,976 --a------ C:\WINDOWS\system32\drivers\Dot4.sys
2008-09-09 20:53 . 2008-04-13 20:39 206,976 --a–c— C:\WINDOWS\system32\dllcache\dot4.sys
2008-09-09 20:53 . 2001-10-26 16:46 23,936 --a------ C:\WINDOWS\system32\drivers\Dot4usb.sys
2008-09-09 20:53 . 2001-10-26 16:46 23,936 --a–c— C:\WINDOWS\system32\dllcache\dot4usb.sys
2008-09-09 20:53 . 2001-08-17 21:47 12,928 --a------ C:\WINDOWS\system32\drivers\Dot4Prt.sys
2008-09-09 20:53 . 2001-08-17 21:47 12,928 --a–c— C:\WINDOWS\system32\dllcache\dot4prt.sys
2008-09-08 18:43 . 2008-09-15 08:02
2008-09-08 18:43 . 2008-09-08 18:43 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-09-08 18:41 . 2008-09-08 18:41
2008-09-08 18:41 . 2008-09-08 18:41
2008-09-08 18:41 . 2008-09-15 09:15
2008-09-08 18:41 . 2008-09-08 18:41
2008-09-08 18:40 . 2008-09-08 18:40
2008-09-08 18:37 . 2008-09-08 18:47
2008-09-08 18:37 . 2008-09-08 18:44
2008-09-05 21:18 . 2008-09-07 19:42 424 --a------ C:\WINDOWS\zipgenius.xml
2008-09-05 21:14 . 2008-09-05 21:14
2008-09-05 07:17 . 2008-09-05 07:19
2008-09-05 07:17 . 2008-09-05 07:17
2008-09-04 20:02 . 2008-09-04 20:02
2008-09-04 20:02 . 2008-09-04 20:02
2008-09-04 20:02 . 2008-09-04 20:02
2008-09-04 20:00 . 2008-09-04 20:03
2008-09-04 19:51 . 2008-09-04 19:51
2008-09-04 19:15 . 2008-06-23 18:42 459,264 -----c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-09-04 19:15 . 2008-06-23 18:42 52,224 -----c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-09-04 19:14 . 2008-09-04 20:02
2008-09-04 19:14 . 2008-06-23 18:42 6,066,176 -----c— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-09-04 19:14 . 2007-04-17 11:32 2,455,488 -----c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-09-04 19:14 . 2007-03-08 07:11 1,036,288 -----c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-09-04 19:14 . 2008-06-23 18:42 383,488 -----c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-09-04 19:14 . 2008-06-23 18:42 267,776 -----c— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-09-04 19:14 . 2008-06-23 18:42 63,488 -----c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-09-04 19:14 . 2008-06-23 11:20 13,824 -----c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-09-04 18:27 . 2004-08-04 00:35 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-09-03 09:28 . 2008-09-03 09:28
2008-09-03 09:27 . 2008-09-03 09:27
2008-09-03 09:27 . 2008-09-03 09:27
2008-09-03 08:35 . 2008-09-03 08:42
2008-09-03 04:04 . 2008-09-04 12:07
2008-09-03 04:04 . 2008-09-07 18:17
2008-09-03 03:58 . 2008-09-03 03:58
2008-09-03 03:58 . 2008-09-03 03:58
2008-09-03 03:58 . 2008-09-03 03:58
2008-09-03 03:54 . 2008-09-06 07:29
2008-09-03 03:53 . 2008-09-04 06:52
2008-09-02 22:13 . 2008-04-11 21:06 691,712 -----c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-02 22:13 . 2008-06-14 19:36 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-09-02 22:13 . 2008-06-14 19:36 273,024 -----c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-02 22:13 . 2008-05-08 16:02 203,136 -----c— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-02 22:11 . 2007-08-10 20:53 26,488 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-09-02 22:11 . 2008-09-02 22:11 13,646 --a------ C:\WINDOWS\system32\wpa.bak
2008-09-02 21:59 . 2008-09-02 21:59
2008-09-02 21:59 . 2003-03-18 22:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-09-02 21:59 . 2003-03-18 21:14 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2008-09-02 21:59 . 2003-02-21 05:42 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll
2008-09-02 21:36 . 2008-09-02 21:54 27,893,944 --a------ C:\setuppol.exe
2008-09-02 21:24 . 2008-09-12 10:05
2008-09-02 21:24 . 2008-09-02 21:24
2008-09-02 21:23 . 2008-09-02 21:33
2008-09-02 21:05 . 2001-10-26 16:57 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-09-02 21:05 . 2001-10-26 16:57 12,160 --a–c— C:\WINDOWS\system32\dllcache\mouhid.sys
2008-09-02 21:05 . 2008-04-13 20:45 10,368 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-10 16:20 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-09 21:08 --------- d-----w C:\Documents and Settings\MARIA\Dane aplikacji\Folder przesyłania Share-to-Web
2008-09-04 19:13 --------- d-----w C:\Program Files\Google
2008-08-10 07:49 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-10 07:47 --------- d-----w C:\Program Files\Usługi online
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:46 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:42 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:48 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{D80C8DC6-A525-4AE5-AAF3-A4B13105A700}]
2008-09-14 22:35 22016 --a------ C:\WINDOWS\system32\gxpta.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2008-04-14 15360]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe” [2008-08-10 171448]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2008-04-14 1695232]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2008-03-20 2127296]
“Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2008-08-12 21741864]
“Nokia.PCSync”=“C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe” [2008-06-17 1249280]
“PC Suite Tray”=“C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe” [2008-08-11 1124352]
“Picasa Media Detector”=“C:\Program Files\Picasa2\PicasaMediaDetector.exe” [2008-08-21 443968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2008-07-19 78008]
“{0228e555-4f9c-4e35-a3ec-b109a192b4c2}”=“C:\Program Files\Google\Gmail Notifier\gnotify.exe” [2005-07-15 479232]
“HPDJ Taskbar Utility”=“C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe” [2006-01-06 188416]
“HPHmon04”=“C:\WINDOWS\system32\hphmon04.exe” [2002-11-22 348160]
“HPHUPD04”=“C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe” [2002-11-22 49152]
“Share-to-Web Namespace Daemon”=“C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe” [2002-04-17 69632]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2008-06-12 34672]
“AGRSMMSG”=“AGRSMMSG.exe” [2005-04-19 C:\WINDOWS\AGRSMMSG.exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“msacm.divxa32”= msaud32_divx.acm
“vidc.tscc”= C:\PROGRA~1\MpcStar\Codecs\tscc\tsccvid.dll
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\BitComet\BitComet.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“16605:TCP”= 16605:TCP:BitComet 16605 TCP
“16605:UDP”= 16605:UDP:BitComet 16605 UDP
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5211.sys [2005-02-17 449344]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Zawartość folderu ‘Zaplanowane zadania’
.
.
------- Skan uzupełniający -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.onet.pl/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}sourceid=ie7rls=com.microsoft:en-USie=utf8oe=utf8
R0 -: HKCU-Main,Default_Search_URL = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: Download with BitComet - C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 -: Download all video with BitComet - C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 -: Download all with BitComet - C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 -: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 09:21:44
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów …
skanowanie ukrytych wpisów autostartu …
skanowanie ukrytych plików …
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-09-15 9:22:23
ComboFix-quarantined-files.txt 2008-09-15 07:22:20
ComboFix2.txt 2008-09-15 07:16:31
Przed: 40,125,632,512 bajt˘w wolnych
Po: 40,116,011,008 bajt˘w wolnych
213 — E O F — 2008-09-10 03:57:07