ComboFix 08-09-16.05 - Pawel 2008-09-18 11:20:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.130 [GMT 2:00]
Uruchomiony z: G:\ComboFix.exe
* Utworzono nowy punkt przywracania
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Pawel\Cookies\pawel@ad.yieldmanager[2].txt
C:\Documents and Settings\Pawel\Cookies\pawel@nuggad[1].txt
C:\Documents and Settings\Pawel\Cookies\pawel@tradedoubler[1].txt
C:\WINDOWS\system32\AutoRun.inf
.
((((((((((((((((((((((((( Pliki utworzone od 2008-08-18 do 2008-09-18 )))))))))))))))))))))))))))))))
.
2008-09-06 17:57 . 2008-09-06 17:55 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-09-04 23:55 . 2008-09-04 23:55
2008-09-04 23:54 . 2008-09-04 23:55
2008-09-02 18:47 . 2008-09-04 22:22
2008-09-02 18:37 . 2004-04-30 09:37 160,640 --a------ C:\WINDOWS\system32\drivers\a347bus.sys
2008-09-02 18:37 . 2004-04-30 09:33 5,248 --a------ C:\WINDOWS\system32\drivers\a347scsi.sys
2008-09-01 22:04 . 2008-09-06 18:01 13,030 --a------ C:\PDOXUSRS.NET
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-17 11:31 --------- d-----w C:\Documents and Settings\Pawel\Dane aplikacji\Skype
2008-09-17 08:43 --------- d-----w C:\Documents and Settings\Pawel\Dane aplikacji\skypePM
2008-09-16 21:00 --------- d-----w C:\Program Files\Programy
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:33 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:24 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:41 662,016 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 08:03 4,608 ----a-w C:\WINDOWS\system32\w95inf32.dll
2008-06-20 08:03 2,272 ----a-w C:\WINDOWS\system32\w95inf16.dll
2008-02-07 17:31 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2008-02-07 17:29 18,617,128 ----a-w C:\Documents and Settings\PROG\Onet-SkypeSetup.exe
2004-09-28 02:00 26,240 ----a-w C:\WINDOWS\inf\RAMDSK.SYS
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Gadu-Gadu”=“C:\Program Files\Programy\Gadu-Gadu\gg.exe” [2003-09-02 729088]
“Komunikator”=“C:\Program Files\Tlen.pl\tlen.exe” [2006-12-08 1118208]
“RegClean Expert Scheduler”=“C:\Program Files\Programy\Registry Clean Expert\RCHelper.exe” [2008-08-07 602872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“DevconDefaultDB”=“C:\WINDOWS\READREG” [X]
“TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2007-01-14 185896]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 132496]
“avast!”=“C:\PROGRA~1\Programy\Avast4\ashDisp.exe” [2008-07-19 78008]
“UpdReg”=“C:\WINDOWS\Updreg.exe” [1999-11-12 86016]
“Jet Detection”=“C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe” [2001-11-29 28672]
“Adobe Reader Speed Launcher”=“C:\Program Files\Programy\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 39792]
“HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2007-03-11 49152]
“WINDVDPatch”=“CTHELPER.EXE” [2002-07-02 C:\WINDOWS\system32\CTHELPER.EXE]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 15360]
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioHQ]
–a------ 1999-11-30 02:00 204800 C:\Program Files\Creative\SBLive2k\AudioHQ\Ahqtb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
–a------ 2003-09-02 15:08 729088 C:\Program Files\Programy\Gadu-Gadu\gg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator]
–a------ 2006-12-08 19:22 1118208 C:\Program Files\Tlen.pl\tlen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a------ 2001-07-09 12:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a------ 2002-03-20 09:15 10752 C:\Program Files\Programy\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefaultMIDI]
–a------ 2002-01-14 15:42 61440 C:\WINDOWS\MIDIDEF.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusOverride”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Programy\Gadu-Gadu\gg.exe”=
“C:\Program Files\Tlen.pl\tlen.exe”=
“C:\Program Files\Programy\Skype\Phone\Skype.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“8461:TCP”= 8461:TCP:GoD High Port
“8462:TCP”= 8462:TCP:GoD Low Port
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{8f56b610-790e-11dd-9216-00c0df022d36}]
\Shell\AutoRun\command - H:\SETUP.EXE
*Newly Created Service* - PROCEXP90
.
-
-
-
- USUNIĘTO PUSTE WPISY - - - -
MSConfigStartUp-dlmMgr - C:\Program Files\Common Files\Adobe\ESD\AdobeDownloadManager.exe
MSConfigStartUp-LXSUPMON - C:\WINDOWS\system32\LXSUPMON.EXE
MSConfigStartUp-Skype - C:\Program Files\Programy\Skype\Skype.exe
.
------- Skan uzupełniający -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.myhpf.co.uk/mypage.asp?OrgID=170153
O8 -: Download with DAP - C:\PROGRA~1\Programy\DAP\dapextie.htm
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-18 11:27:33
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów …
skanowanie ukrytych wpisów autostartu …
skanowanie ukrytych plików …
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-09-18 11:32:41
ComboFix-quarantined-files.txt 2008-09-18 09:31:39
Przed: 1,480,138,752 bajt˘w wolnych
Po: 1,810,493,440 bajt˘w wolnych
138 — E O F — 2008-09-12 09:19:23