ComboFix 09-04-04.01 - Nobody 2009-04-11 14:09:59.1 - FAT32x86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.48.1045.18.502.72 [GMT 2:00] Uruchomiony z: c:\documents and settings\Nobody\Pulpit\ComboFix.exe * Utworzono nowy punkt przywracania . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\autorun.inf c:\documents and settings\Nobody\Menu Start\Programy\Autostart\ctfmon.exe c:\recycled\Recycled c:\recycled\Recycled\ctfmon.exe c:\windows\system32\pthreadGC2.dll D:\Autorun.inf . ((((((((((((((((((((((((( Pliki utworzone od 2009-03-11 do 2009-04-11 ))))))))))))))))))))))))))))))) . 2009-04-11 12:56 . 2009-04-11 12:56 2009-04-10 19:34 . 2009-04-10 19:34 2009-04-07 20:57 . 2009-04-07 20:57 2009-04-07 20:57 . 2009-04-07 20:57 2009-04-07 20:55 . 2006-04-10 14:03 38,400 --a------ c:\windows\system32\hpz3l054.dll 2009-04-07 20:55 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys 2009-04-07 20:55 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\dllcache\usbscan.sys 2009-04-07 20:54 . 2006-03-03 21:03 282,680 --a------ c:\windows\system32\HPZidr12.dll 2009-04-07 20:54 . 2006-03-03 21:02 204,800 --a------ c:\windows\system32\HPZipr12.dll 2009-04-07 20:54 . 2006-03-03 21:02 94,208 --a------ c:\windows\system32\HPZipt12.dll 2009-04-07 20:54 . 2006-03-03 21:03 69,632 --a------ c:\windows\system32\HPZipm12.exe 2009-04-07 20:54 . 2006-03-03 21:03 65,536 --a------ c:\windows\system32\HPZinw12.exe 2009-04-07 20:54 . 2006-03-03 21:02 57,344 --a------ c:\windows\system32\HPZisn12.dll 2009-04-07 20:53 . 2009-04-07 20:53 2009-04-07 20:52 . 2006-04-13 02:02 827,392 --a------ c:\windows\system32\hpotiop2.dll 2009-04-07 20:52 . 2006-04-13 02:02 659,456 --a------ c:\windows\system32\hpowiax2.dll 2009-04-07 20:52 . 2006-04-13 02:04 282,624 --a------ c:\windows\system32\HPZc3212.dll 2009-04-07 20:52 . 2006-04-13 02:02 254,026 --a------ c:\windows\system32\hpovst09.dll 2009-04-07 20:52 . 2009-04-07 20:58 113,028 --a------ c:\windows\hpoins11.dat 2009-04-07 20:52 . 2005-07-19 03:39 98,304 --a------ c:\windows\system32\hpzjsn01.dll 2009-04-07 20:52 . 2006-01-04 10:12 77,824 --a------ c:\windows\system32\HPZIDS01.dll 2009-04-07 20:52 . 2006-04-13 02:04 49,664 --a------ c:\windows\system32\drivers\HPZid412.sys 2009-04-07 20:52 . 2006-04-13 02:04 21,568 --a------ c:\windows\system32\drivers\HPZius12.sys 2009-04-07 20:52 . 2006-04-13 02:04 16,496 --a------ c:\windows\system32\drivers\HPZipr12.sys 2009-04-07 20:51 . 2006-05-06 08:34 6,947 --a------ c:\windows\hpomdl11.dat 2009-04-07 20:44 . 2004-08-03 23:01 25,856 --a------ c:\windows\system32\drivers\usbprint.sys 2009-04-07 20:44 . 2004-08-03 23:01 25,856 --a------ c:\windows\system32\dllcache\usbprint.sys 2009-04-07 13:36 . 2001-08-17 21:56 7,552 --a------ c:\windows\system32\drivers\SONYPVU1.SYS 2009-04-07 13:36 . 2001-08-17 21:56 7,552 --a------ c:\windows\system32\dllcache\sonypvu1.sys 2009-04-07 11:04 . 2009-04-07 11:04 2009-04-06 14:45 . 2009-04-06 14:45 2009-04-05 12:29 . 2009-04-05 12:29 2009-04-05 12:27 . 2009-04-05 12:27 2009-04-05 12:27 . 2000-05-22 22:58 608,448 --a------ c:\windows\system32\comctl32.ocx 2009-04-04 12:30 . 2009-04-04 12:30 2009-04-04 11:42 . 2009-04-04 11:42 2009-04-04 11:41 . 2009-04-04 11:41 2009-04-04 11:35 . 2009-04-04 11:35 2009-04-04 11:35 . 2009-04-04 11:35 2009-04-04 11:34 . 2009-04-04 11:34 2009-04-04 08:33 . 2009-04-04 08:33 2009-04-04 08:33 . 2009-04-04 08:33 2009-04-04 08:32 . 2009-04-04 08:32 2009-04-04 08:32 . 2009-04-04 08:32 2009-04-04 08:32 . 2009-04-04 08:32 2009-04-03 22:00 . 2009-04-03 22:00 2009-04-03 20:03 . 2009-04-03 20:03 2009-04-03 20:01 . 2009-04-03 20:02 2009-04-03 20:01 . 2004-08-03 23:08 25,600 --a------ c:\windows\system32\drivers\usbser.sys 2009-04-03 20:01 . 2004-08-03 23:08 25,600 --a------ c:\windows\system32\dllcache\usbser.sys 2009-04-03 20:00 . 2009-04-03 20:00 2009-04-03 20:00 . 2009-04-03 20:00 2009-04-03 18:23 . 2009-04-03 18:23 2009-04-03 18:23 . 2009-04-03 18:23 66 --a------ c:\windows\Speed Video Splitter.INI 2009-04-03 18:06 . 2009-04-03 18:06 2009-04-03 18:06 . 2009-04-03 18:06 717,296 --a------ c:\windows\system32\drivers\sptd.sys 2009-04-03 17:53 . 2009-04-03 17:53 2009-04-03 17:52 . 2009-04-03 17:52 2009-04-03 17:52 . 2008-11-06 18:37 3,596,288 --a------ c:\windows\system32\qt-dx331.dll 2009-04-03 17:52 . 2008-09-24 20:41 839,680 --a------ c:\windows\system32\lameACM.acm 2009-04-03 17:52 . 2008-12-07 20:08 795,648 --a------ c:\windows\system32\xvidcore.dll 2009-04-03 17:52 . 2008-11-06 18:33 684,032 --a------ c:\windows\system32\divx.dll 2009-04-03 17:52 . 2004-01-25 18:18 217,088 --a------ c:\windows\system32\yv12vfw.dll 2009-04-03 17:52 . 2008-09-16 21:23 168,448 --a------ c:\windows\system32\unrar.dll 2009-04-03 17:52 . 2008-12-07 20:08 130,048 --a------ c:\windows\system32\xvidvfw.dll 2009-04-03 17:52 . 2007-09-21 02:52 118,784 --a------ c:\windows\system32\ac3acm.acm 2009-04-03 17:52 . 2008-12-11 02:33 86,016 --a------ c:\windows\system32\dpl100.dll 2009-04-03 17:52 . 2009-03-02 20:10 67,584 --a------ c:\windows\system32\ff_vfw.dll 2009-04-03 17:52 . 2007-07-10 18:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest 2009-04-03 17:52 . 2008-10-03 14:30 414 --a------ c:\windows\system32\lame_acm.xml 2009-04-03 15:05 . 2009-04-03 15:05 2009-04-01 19:55 . 2009-04-01 19:55 2009-04-01 19:46 . 2003-06-19 01:31 17,920 --a------ c:\windows\system32\mdimon.dll 2009-04-01 19:46 . 2009-04-01 19:46 421 --a------ c:\windows\ODBC.INI 2009-04-01 19:42 . 2009-04-01 19:42 2009-04-01 19:42 . 2009-04-01 19:42 2009-04-01 19:38 . 2009-04-10 12:19 69 --a------ c:\windows\NeroDigital.ini 2009-04-01 19:16 . 2009-04-01 19:16 2009-04-01 19:03 . 2009-04-01 19:03 2009-04-01 19:03 . 2009-04-01 19:03 2009-04-01 19:03 . 2009-04-01 19:03 2009-04-01 18:33 . 2009-04-01 18:32 410,984 --a------ c:\windows\system32\deploytk.dll 2009-04-01 18:33 . 2009-04-01 18:32 73,728 --a------ c:\windows\system32\javacpl.cpl 2009-04-01 18:32 . 2009-04-01 18:32 2009-04-01 18:30 . 2009-04-01 18:30 2009-04-01 18:22 . 2009-04-01 18:22 2009-04-01 18:21 . 2009-04-01 18:21 2009-04-01 18:21 . 2008-08-14 15:40 2,187,264 --------- c:\windows\system32\dllcache\ntoskrnl.exe 2009-04-01 18:21 . 2008-08-14 15:40 2,144,256 --------- c:\windows\system32\dllcache\ntkrnlmp.exe 2009-04-01 18:21 . 2008-08-14 15:41 2,064,256 --------- c:\windows\system32\dllcache\ntkrnlpa.exe 2009-04-01 18:21 . 2008-08-14 15:40 2,022,400 --------- c:\windows\system32\dllcache\ntkrpamp.exe 2009-04-01 18:20 . 2009-04-01 18:20 2009-04-01 18:20 . 2009-04-01 18:20 2009-04-01 18:05 . 2009-04-01 18:05 2009-04-01 18:04 . 2009-04-01 18:04 2009-04-01 17:52 . 2009-04-01 17:52 2009-04-01 17:52 . 2009-04-01 17:52 2009-04-01 17:51 . 2008-06-14 20:01 273,024 --------- c:\windows\system32\dllcache\bthport.sys 2009-04-01 17:39 . 2008-10-24 13:10 453,632 --------- c:\windows\system32\dllcache\mrxsmb.sys 2009-03-17 13:36 . 2009-03-17 13:36 2009-03-17 13:35 . 2006-08-26 08:04 2009-03-17 13:35 . 2009-03-17 13:35 2009-03-17 13:35 . 2006-08-26 08:04 2009-03-17 13:35 . 2006-08-26 08:04 2009-03-17 13:35 . 2009-03-17 13:35 2009-03-17 13:35 . 2006-08-26 08:04 2009-03-17 13:35 . 2006-08-26 08:44 2009-03-17 13:35 . 2006-08-26 08:04 . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-17 11:43 --------- d-----w c:\program files\Yahoo! 2009-03-17 11:39 --------- d-----w c:\program files\Launch Manager 2009-03-17 11:37 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\CyberLink 2009-03-17 11:35 --------- d-----w c:\program files\Acer 2009-02-09 14:19 1,846,528 ----a-w c:\windows\system32\win32k.sys 2009-02-09 14:19 1,846,528 ----a-w c:\windows\system32\dllcache\win32k.sys . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “MSMSGS”=“c:\program files\Messenger\msmsgs.exe” [2004-08-04 1667584] “Google Update”=“c:\documents and settings\Nobody\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe” [2009-04-01 133104] “BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe” [2007-09-20 202024] “DAEMON Tools Lite”=“c:\program files\DAEMON Tools Lite\daemon.exe” [2008-12-29 687560] “Skype”=“c:\program files\Skype\Phone\Skype.exe” [2009-03-27 24103720] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “LaunchApp”=“Alaunch” [X] “igfxtray”=“c:\windows\system32\igfxtray.exe” [2006-03-23 94208] “igfxhkcmd”=“c:\windows\system32\hkcmd.exe” [2006-03-23 77824] “igfxpers”=“c:\windows\system32\igfxpers.exe” [2006-03-23 118784] “AzMixerSel”=“c:\program files\Realtek\InstallShield\AzMixerSel.exe” [2005-12-21 53248] “SynTPEnh”=“c:\program files\Synaptics\SynTP\SynTPEnh.exe” [2006-03-03 761946] “ntiMUI”=“c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe” [2006-05-15 45056] “ADMTray.exe”=“c:\acer\Empowering Technology\admtray.exe” [2005-10-24 2462208] “eDataSecurity Loader”=“c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe” [2005-12-27 69632] “IMJPMIG8.1”=“c:\windows\IME\imjp8_1\IMJPMIG.EXE” [2004-08-04 208952] “MSPY2002”=“c:\windows\system32\IME\PINTLGNT\ImScInst.exe” [2004-08-04 59392] “PHIME2002ASync”=“c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE” [2004-08-04 455168] “PHIME2002A”=“c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE” [2004-08-04 455168] “PCMService”=“c:\program files\Acer\Acer Arcade\PCMService.exe” [2006-08-09 151552] “ePower_DMC”=“c:\acer\Empowering Technology\ePower\ePower_DMC.exe” [2006-08-10 352256] “Acer ePower Management”=“c:\acer\Empowering Technology\ePower\Acer ePower Management.exe” [2006-05-22 3080704] “LManager”=“c:\progra~1\LAUNCH~1\LManager.exe” [2006-07-20 593920] “eRecoveryService”=“c:\acer\Empowering Technology\eRecovery\Monitor.exe” [2006-01-24 397312] “WarReg_PopUp”=“c:\acer\WR_PopUp\WarReg_PopUp.exe” [2006-09-23 61440] “SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2009-04-01 148888] “NeroFilterCheck”=“c:\program files\Common Files\Nero\Lib\NeroCheck.exe” [2007-03-01 153136] “BluetoothAuthenticationAgent”=“bthprops.cpl” [2004-08-04 c:\windows\system32\bthprops.cpl] “SkyTel”=“SkyTel.EXE” [2006-05-16 c:\windows\SkyTel.exe] “RTHDCPL”=“RTHDCPL.EXE” [2006-06-28 c:\windows\RTHDCPL.exe] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2004-08-04 15360] c:\documents and settings\All Users\Menu Start\Programy\Autostart\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] “VIDC.FFDS”= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] “AntiVirusDisableNotify”=dword:00000001 “UpdatesDisableNotify”=dword:00000001 [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] “%windir%\system32\sessmgr.exe”= “c:\Program Files\Acer\Acer Arcade\PCMService.exe”= “c:\Program Files\Java\jre6\launch4j-tmp\JDownloader.exe”= “c:\WINDOWS\System32\java.exe”= “c:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe”= “c:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe”= “c:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe”= “c:\Program Files\Nowe Gadu-Gadu\gg.exe”= “c:\Program Files\Skype\Phone\Skype.exe”= R1 OsaFsLoc;OsaFsLoc;c:\windows\system32\drivers\OsaFsLoc.sys [2005-10-15 12106] R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2005-06-30 7296] R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2005-01-14 4010] R3 NdisFilt;OSA NdisFilter Protocol;c:\windows\system32\drivers\NdisFilt.sys [2005-09-13 4392] — Inne Usługi/Sterowniki w Pamięci — *NewlyCreated* - INT15.SYS . Zawartość folderu ‘Zaplanowane zadania’ 2009-04-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1836318382-3511668726-703985623-1006.job - c:\documents and settings\Nobody\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2009-04-01 17:32] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://www.daemon-search.com/default mStart Page = hxxp://pl.intl.acer.yahoo.com uInternet Connection Wizard,ShellNext = hxxp://pl.intl.acer.yahoo.com/ uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ycomp/ … .yahoo.com IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-11 14:11:13 Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI skanowanie ukrytych procesów … skanowanie ukrytych wpisów autostartu … skanowanie ukrytych plików … skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** . Czas ukończenia: 2009-04-11 14:12:17 ComboFix-quarantined-files.txt 2009-04-11 12:12:16 Przed: 34 786 770 944 bajtów wolnych Po: 35,673,374,720 bajtów wolnych WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=“Microsoft Windows XP Home Edition” /noexecute=optin /fastdetect 231 — E O F — 2009-04-01 17:24:06