ComboFix 08-10-21.06 - XP 2008-10-23 0:34:56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.644 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\XP\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\Documents and Settings\XP\Menu Start\Programy\Autostart\ctfmon.exe
C:\Recycled\Recycled
C:\Recycled\Recycled\ctfmon.exe
C:\WINDOWS\system32\3.tmp
C:\WINDOWS\system32\drivers\TPRVRNPT.sys
C:\WINDOWS\system32\drivers\Winou38.sys
C:\WINDOWS\system32\rcsoft32.dll
C:\WINDOWS\system32\rs32net.exe
C:\WINDOWS\system32\WinCtrl32.dll
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
G:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TCPSR
-------\Legacy_TPRVRNPT
-------\Service_tcpsr
-------\Service_TPRVRNPT
-------\Service_Winou38
((((((((((((((((((((((((( Pliki utworzone od 2008-09-22 do 2008-10-22 )))))))))))))))))))))))))))))))
.
2008-10-23 00:27 . 2008-10-23 00:27 18 --a------ C:\WINDOWS\system32\A.tmp
2008-10-23 00:26 . 2008-10-23 00:26 92 --a------ C:\WINDOWS\system32\5.tmp
2008-10-22 14:48 . 2008-10-22 14:48 29 --a------ C:\WINDOWS\system32\guputdrd.tmp
2008-10-22 14:47 . 2008-10-22 14:47 92 --a------ C:\WINDOWS\system32\4.tmp
2008-10-22 14:47 . 2008-10-22 14:47 18 --a------ C:\WINDOWS\system32\8.tmp
2008-10-22 09:20 . 2008-10-22 09:20
2008-10-22 09:20 . 2008-10-22 09:20 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-10-22 09:20 . 2008-10-22 09:20 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-10-21 15:04 . 2008-10-23 00:27 32,768 --a------ C:\WINDOWS\system32\drivers\ati7flxx.sys
2008-10-21 15:04 . 2008-10-21 15:04 128 --a------ C:\WINDOWS\system32\2.tmp
2008-10-21 15:04 . 2008-10-21 15:04 18 --a------ C:\WINDOWS\system32\6.tmp
2008-10-21 14:55 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-10-21 14:45 . 2008-10-21 14:45
2008-10-21 14:45 . 2008-10-21 14:45
2008-10-21 14:45 . 2006-01-30 18:00 454,656 -ra------ C:\WINDOWS\system32\ZSHP1018.EXE
2008-10-21 14:45 . 2006-01-30 18:00 155,648 -ra------ C:\WINDOWS\apptune1018.exe
2008-10-21 14:45 . 2006-01-30 18:00 129,092 -ra------ C:\WINDOWS\system32\hp1018.img
2008-10-21 14:45 . 2006-01-30 18:00 106,496 -ra------ C:\WINDOWS\system32\vshp1018.dll
2008-10-21 14:45 . 2006-01-30 18:00 102,400 --a------ C:\WINDOWS\system32\zlhp1018.dll
2008-10-21 14:45 . 2006-01-30 18:00 86,016 --a------ C:\WINDOWS\system32\ZSPOOL.DLL
2008-10-21 14:45 . 2006-01-30 18:00 28,672 --a------ C:\WINDOWS\system32\zlm.dll
2008-10-21 14:45 . 2006-01-30 18:00 28,672 --a------ C:\WINDOWS\system32\IMF32.DLL
2008-10-21 14:45 . 2006-01-30 18:00 24,576 --a------ C:\WINDOWS\system32\ZTAG32.DLL
2008-10-21 14:45 . 2006-01-30 18:00 7,564 -ra------ C:\WINDOWS\system32\ZSHP1018.HLP
2008-10-20 21:54 . 2008-10-23 00:35
2008-10-20 21:25 . 2008-10-20 21:25
2008-10-20 21:25 . 2008-10-21 19:57
2008-10-19 23:32 . 2008-10-19 23:32
2008-10-19 22:02 . 2004-08-04 02:35 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-10-19 22:02 . 2001-08-17 23:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-10-19 22:01 . 2004-08-04 02:44 77,312 --a------ C:\WINDOWS\system32\usbui.dll
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-19 18:41 --------- d-----w C:\Program Files\PhotoFiltre Studio
2008-10-19 18:24 --------- d-----w C:\Program Files\Gadu-Gadu
2008-10-19 18:21 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-10-19 18:21 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-19 18:21 --------- d-----w C:\Program Files\Alcatel
2008-10-19 18:19 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-10-19 18:19 --------- d-----w C:\Program Files\Realtek AC97
2008-10-19 18:19 --------- d-----w C:\Program Files\AvRack
2008-10-19 18:10 --------- d-----w C:\Program Files\microsoft frontpage
2008-10-19 18:08 --------- d-----w C:\Program Files\Usługi online
.
------- Sigcheck -------
2004-08-04 11:44 1078272 26f77ffd95946baf495995e807140318 C:\WINDOWS\explorer.exe
2004-08-04 11:44 1044992 b6ecff949f5487344fb3da0badc7f1be C:\WINDOWS\system32\dllcache\explorer.exe
2004-08-04 11:44 26624 2f66d4e9e86abb357ba37f40394bb333 C:\WINDOWS\system32\ctfmon.exe
2004-08-04 11:44 26624 5977428e8fd1aa023f2957a96898b677 C:\WINDOWS\system32\dllcache\ctfmon.exe
2004-08-04 11:44 69120 babf0d22de41b1a6a8dbfa8834a3690a C:\WINDOWS\system32\spoolsv.exe
2004-08-04 11:44 69120 0c91d968834754d28cb05045094583cc C:\WINDOWS\system32\dllcache\spoolsv.exe
2004-08-04 11:44 254976 dfd554a329e3cc50c19d6b58613ae572 C:\WINDOWS\system32\wuauclt.exe
2004-08-04 11:44 123392 7627ee032d03c4fa7736cd7a0a49a9dc C:\WINDOWS\system32\dllcache\wuauclt.exe
2004-08-04 11:44 36352 b70082d3bfc2408f1fc45d941831fecf C:\WINDOWS\system32\userinit.exe
2004-08-04 11:44 36352 7464577d0efbb9a6e17fdcd79709df10 C:\WINDOWS\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 26624]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2008-03-20 2127296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“UserFaultCheck”=“C:\WINDOWS\system32\dumprep 0 -u” [X]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-03-09 7561216]
“NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2006-03-09 86016]
“SpeedTouch USB Diagnostics”=“C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe” [2002-06-06 905216]
“OrderReminder”=“C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe” [2006-01-30 110592]
“SoundMan”=“SOUNDMAN.EXE” [2006-08-03 C:\WINDOWS\soundman.exe]
“nwiz”=“nwiz.exe” [2006-03-09 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 26624]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7flxx.sys]
@=“Driver”
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\uTorrent\utorrent.exe”=
“C:\Program Files\Gadu-Gadu\gg.exe”=
R0 ati7flxx;ati7flxx;C:\WINDOWS\system32\Drivers\ati7flxx.sys [2008-10-23 32768]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\Recycled\ctfmon.exe
\Shell\Open(O)\command - C:\Recycled\Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(0)\command - D:\Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(0)\command - E:\Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(0)\command - F:\Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(0)\command - G:\Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\autorun.exe
*Newly Created Service* - WRNSRMRU
.
-
-
-
- USUNIĘTO PUSTE WPISY - - - -
HKLM-Run-irqaejfn - C:\WINDOWS\irqaejfn.exe
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\XP\Dane aplikacji\Mozilla\Firefox\Profiles\wmvfzfs4.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-23 00:37:19
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
skanowanie ukrytych procesów …
skanowanie ukrytych wpisów autostartu …
skanowanie ukrytych plików …
C:\WINDOWS\system32\drivers\WRNSRMRU.sys 181248 bytes executable
skanowanie pomyślnie ukończone
ukryte pliki: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Abiosdsk]
–
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinSock2]
–
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WRNSRMRU]
“ImagePath”="??\C:\WINDOWS\system32\drivers\WRNSRMRU.sys"
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Czas ukończenia: 2008-10-23 0:38:16 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-10-22 22:38:11
Przed: 34 472 845 312 bajtów wolnych
Po: 34,473,914,368 bajtów wolnych
171