. ((((((((((((((((((((((((( Pliki utworzone od 2009-01-22 do 2009-02-22 ))))))))))))))))))))))))))))))) . 2009-02-16 21:51 . 2009-02-16 21:51 2009-02-16 21:23 . 2009-02-22 12:09 81,984 --a------ c:\windows\system32\bdod.bin 2009-02-16 21:16 . 2009-02-16 21:16 2009-02-16 21:16 . 2009-02-16 21:18 2009-02-16 21:15 . 2009-02-16 21:17 2009-02-16 20:55 . 2009-02-22 08:00 2009-02-16 20:55 . 2009-02-16 20:55 56 --ah----- c:\windows\system32\ezsidmv.dat 2009-02-16 20:54 . 2009-02-22 12:12 2009-02-16 20:53 . 2009-02-16 20:53 2009-02-16 20:53 . 2009-02-16 20:53 2009-02-16 20:53 . 2009-02-16 20:53 2009-02-12 21:00 . 2009-02-12 21:00 2009-02-12 21:00 . 2009-02-12 21:02 413,696 --a------ c:\windows\system32\wrap_oal.dll 2009-02-12 21:00 . 2009-02-12 21:02 110,592 --a------ c:\windows\system32\OpenAL32.dll 2009-02-12 20:31 . 2009-02-12 20:31 2009-01-29 14:51 . 2009-01-29 14:51 . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-22 01:50 --------- d-----w c:\documents and settings\Mariusz\Dane aplikacji\Hamachi 2009-02-20 22:13 --------- d-----w c:\program files\SkanerOnline 2009-02-20 22:11 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\avg8 2009-02-17 21:42 --------- d-----w c:\documents and settings\Mariusz\Dane aplikacji\AdobeUM 2009-01-29 13:45 --------- d–h--w c:\program files\InstallShield Installation Information 2009-01-28 08:56 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys 2009-01-28 08:56 107,272 ----a-w c:\windows\system32\drivers\avgtdix.sys 2009-01-28 08:56 10,520 ----a-w c:\windows\system32\avgrsstx.dll 2009-01-25 15:00 201,352 ----a-w c:\windows\system32\PnkBstrB.exe 2009-01-25 15:00 140,216 ----a-w c:\windows\system32\drivers\PnkBstrK.sys 2009-01-21 16:11 473,600 ----a-w c:\windows\system32\SkanerOnline.dll 2009-01-20 17:10 --------- d-----w c:\documents and settings\Mariusz\Dane aplikacji\Winamp 2009-01-17 18:03 2,568 --sha-w c:\documents and settings\All Users\Dane aplikacji\KGyGaAvL.sys 2009-01-14 14:28 --------- d-----w c:\program files\Common Files\INCA Shared 2009-01-10 22:50 --------- d-----w c:\program files\Combined Community Codec Pack 2009-01-09 15:58 --------- d-----w c:\program files\mIRC 2009-01-09 15:58 --------- d-----w c:\documents and settings\Mariusz\Dane aplikacji\mIRC 2009-01-06 18:11 --------- d-----w c:\documents and settings\Mariusz\Dane aplikacji\AVGTOOLBAR 2008-12-29 14:46 --------- d-----w c:\program files\Ligos 2008-12-29 14:37 --------- d-----w c:\program files\AVG 2008-12-24 07:15 --------- d-----w c:\program files\Common Files\Wise Installation Wizard 2008-12-24 07:15 --------- d-----w c:\program files\AGEIA Technologies 2008-10-16 20:55 88 --sh–r c:\documents and settings\All Users\Dane aplikacji\C781E6F90E.sys 2006-06-15 18:33 233,472 ----a-w c:\program files\mozilla firefox\plugins\CrazyTalk4Native.dll 2006-05-25 16:43 204,895 ----a-w c:\program files\mozilla firefox\plugins\ctdomemhelper.dll 2005-09-29 12:41 77,824 ----a-w c:\program files\mozilla firefox\plugins\ctframeplayerobject.dll 2006-06-19 11:10 426,081 ----a-w c:\program files\mozilla firefox\plugins\ctplayerobject.dll 2005-02-02 10:19 458,752 ----a-w c:\program files\mozilla firefox\plugins\imagickrt.dll 2006-04-10 16:35 139,264 ----a-w c:\program files\mozilla firefox\plugins\rlcontentclass.dll 2005-11-09 09:10 204,800 ----a-w c:\program files\mozilla firefox\plugins\RLMusicPacker.dll 2005-11-09 09:42 106,496 ----a-w c:\program files\mozilla firefox\plugins\RLMusicUnpacker.dll 2006-01-04 09:22 212,992 ----a-w c:\program files\mozilla firefox\plugins\RLVoicePacker.dll 2006-01-04 09:21 167,936 ----a-w c:\program files\mozilla firefox\plugins\RLVoiceUnpacker.dll 2008-09-21 20:05 88 --sh–r c:\windows\system32\EFA233CF4A.sys 2008-09-21 20:06 2,828 --sha-w c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“c:\windows\system32\ctfmon.exe” [2004-08-03 15360] “IncrediMail”=“c:\program files\IncrediMail\bin\IncMail.exe” [2005-02-13 192555] “ares”=“c:\ares\Ares.exe” [2007-05-04 961024] “DAEMON Tools Lite”=“c:\daemon tools lite\daemon.exe” [2008-04-01 486856] “Konnekt”=“d:\konnekt\konnekt.exe” [2005-05-24 503808] “SpybotSD TeaTimer”=“c:\program files\Spybot - Search & Destroy\TeaTimer.exe” [2008-09-16 1833296] “Skype”=“c:\program files\Skype\Phone\Skype.exe” [2009-01-29 23975720] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-10-07 13574144] “NeroFilterCheck”=“c:\windows\system32\NeroCheck.exe” [2001-07-09 155648] “FixCamera”=“c:\windows\FixCamera.exe” [2007-02-12 20480] “tsnp325”=“c:\windows\tsnp325.exe” [2006-10-10 270336] “snp325”=“c:\windows\vsnp325.exe” [2006-10-10 827392] “WinampAgent”=“c:\program files\Winamp\winampa.exe” [2008-09-12 36352] “SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2008-11-10 136600] “NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-10-07 86016] “AVG8_TRAY”=“c:\progra~1\AVG\AVG8\avgtray.exe” [2009-01-28 1601304] “BDMCon”=“c:\program files\Softwin\BitDefender10\bdmcon.exe” [2007-04-02 290816] “BDAgent”=“c:\program files\Softwin\BitDefender10\bdagent.exe” [2007-03-26 69632] “nwiz”=“nwiz.exe” [2008-10-07 c:\windows\system32\nwiz.exe] “SkyTel”=“SkyTel.EXE” [2006-05-16 c:\windows\SkyTel.exe] “RTHDCPL”=“RTHDCPL.EXE” [2006-05-18 c:\windows\RTHDCPL.EXE] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“c:\windows\System32\CTFMON.EXE” [2004-08-03 15360] c:\documents and settings\Mariusz\Menu Start\Programy\Autostart\ hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2008-10-30 625952] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-01-28 09:56 10520 c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] “vidc.ffds”= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] “%windir%\system32\sessmgr.exe”= “c:\Program Files\IncrediMail\bin\IMApp.exe”= “c:\Program Files\IncrediMail\bin\IncMail.exe”= “c:\Program Files\IncrediMail\bin\ImpCnt.exe”= “c:\xampp\mysql\bin\mysqld.exe”= “c:\xampp\apache\bin\apache.exe”= “d:\gry\THQ\Dawn of War\W40k.exe”= “d:\gry\THQ\Dawn of War\W40kWA.exe”= “c:\Ares\Ares.exe”= “d:\gry\THQ\Dawn of War - Soulstorm\Soulstorm.exe”= “d:\gry\EA GAMES\Battlefield 2\BF2.exe”= “c:\Program Files\Bonjour\mDNSResponder.exe”= “c:\WINDOWS\system32\dplaysvr.exe”= “d:\gry\3DO\Heroes 3 Complete\HEROES3.EXE”= “d:\Steam\SteamApps\selerith\counter-strike source\hl2.exe”= “c:\Program Files\AVG\AVG8\avgemc.exe”= “c:\Program Files\AVG\AVG8\avgupd.exe”= “d:\gry\Warhammer® Mark of Chaos\Warhammer.exe”= “c:\Program Files\Mozilla Firefox\firefox.exe”= “c:\Program Files\Skype\Phone\Skype.exe”= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-29 325128] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-12-29 107272] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-29 903960] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-29 298264] R3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\drivers\snp325.sys [2008-09-15 10260864] S3 cdrmkaun;cdrmkaun;??\c:\docume~1\Mariusz\USTAWI~1\Temp\cdrmkaun.sys --> c:\docume~1\Mariusz\USTAWI~1\Temp\cdrmkaun.sys [?] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{6d05ad29-9d30-11dd-b270-0016178f54b8}] \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL . . ------- Skan uzupełniający ------- . uStart Page = hxxp://wodmmorpg.pl/ uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local IE: &Add animation to IncrediMail Style Box - c:\progra~1\INCRED~1\bin\resources\WebMenuImg.htm IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {68282C51-9459-467B-95BF-3C0E89627E55} - hxxp://www.mks.com.pl/skaner/SkanerOnline.cab FF - ProfilePath - c:\documents and settings\Mariusz\Dane aplikacji\Mozilla\Firefox\Profiles\gvwaazoi.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll FF - component: c:\program files\Mozilla Firefox\extensions{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\divx\DivX Player\npDivxPlayerPlugin.dll FF - plugin: c:\divx\DivX Web Player\npdivx32.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npRLCT4Player.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-22 12:11:45 Windows 5.1.2600 Dodatek Service Pack 2 NTFS skanowanie ukrytych procesów … skanowanie ukrytych wpisów autostartu … skanowanie ukrytych plików … skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- [HKEY_USERS\S-1-5-21-790525478-1592454029-725345543-1003\Software\SecuROM\License information*] “datasecu”=hex:69,eb,db,3d,2c,10,78,76,be,e6,64,23,69,97,d2,1d,5a,09,36,28,77, b0,2b,77,1a,87,08,0f,61,21,e5,18,b3,35,02,7f,bd,9f,fc,e8,d3,5c,de,44,51,9d,\ “rkeysecu”=hex:73,f5,9e,c9,c3,9b,32,bf,10,63,06,f6,8a,d1,63,2a . Czas ukończenia: 2009-02-22 12:13:54 ComboFix-quarantined-files.txt 2009-02-22 11:13:51 Przed: 7,708,065,792 bajtów wolnych Po: 8,063,844,352 bajtów wolnych