ComboFix 09-03-19.02 - Maciek 2009-03-22 15:36:05.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3582.3056 [GMT 1:00] Uruchomiony z: c:\documents and settings\Maciek\Pulpit\1\ComboFix.exe AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) . /wow section - STAGE 41 System nie może odnaleźć określonej ścieżki. System nie może odnaleźć określonej ścieżki. System nie może odnaleźć określonej ścieżki. Nie można odnaleźć c:\combofix\temp03. ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\win32hlp.cnf Zainfekowana kopia została znaleziona. Problem naprawiono Plik odzyskano z - . ((((((((((((((((((((((((( Pliki utworzone od 2009-02-22 do 2009-03-22 ))))))))))))))))))))))))))))))) . 2009-03-22 14:33 . 2009-03-22 15:26 2009-03-22 14:33 . 2008-10-13 17:16 2009-03-22 14:33 . 2008-10-13 15:20 2009-03-22 14:33 . 2009-03-22 14:52 2009-03-22 14:33 . 2008-10-13 17:16 2009-03-22 14:33 . 2008-10-13 17:16 2009-03-22 14:33 . 2009-03-22 14:51 2009-03-22 14:33 . 2009-03-22 14:33 2009-03-22 14:15 . 2009-03-22 14:15 2009-03-22 14:15 . 2009-03-22 14:15 2009-03-22 14:13 . 2009-03-22 14:13 580,096 --a------ c:\windows\system32\dllcache\user32.dll 2009-03-22 14:12 . 2009-03-22 14:12 2009-03-22 14:07 . 2009-03-22 14:52 2009-03-22 12:50 . 2009-03-22 15:39 2009-03-22 12:38 . 2009-03-22 13:48 2009-03-14 02:50 . 2009-03-22 12:25 4,194,322 --a------ C:\memory_map.tga 2009-03-13 20:27 . 2009-03-13 20:27 2009-03-13 20:26 . 2008-10-10 04:52 4,379,984 --a------ c:\windows\system32\D3DX9_40.dll 2009-03-13 20:26 . 2008-10-10 04:52 2,036,576 --a------ c:\windows\system32\D3DCompiler_40.dll 2009-03-13 20:26 . 2008-10-27 10:04 514,384 --a------ c:\windows\system32\XAudio2_3.dll 2009-03-13 20:26 . 2008-10-10 04:52 452,440 --a------ c:\windows\system32\d3dx10_40.dll 2009-03-13 20:26 . 2008-10-27 10:04 235,856 --a------ c:\windows\system32\xactengine3_3.dll 2009-03-13 20:26 . 2008-10-27 10:04 70,992 --a------ c:\windows\system32\XAPOFX1_2.dll 2009-03-13 20:26 . 2008-10-27 10:04 23,376 --a------ c:\windows\system32\X3DAudio1_5.dll 2009-03-13 19:46 . 2009-03-22 12:49 2009-03-13 19:05 . 2009-03-22 12:39 2009-03-08 11:17 . 2009-03-08 12:43 154 --a------ c:\windows\ACP.ini 2009-03-05 19:19 . 2009-03-05 19:19 2009-03-05 19:18 . 2009-03-05 19:19 2009-03-05 13:46 . 2009-03-05 13:46 2009-03-05 13:14 . 2008-04-10 11:52 5,174 --a------ c:\windows\system32\nppt9x.vxd 2009-03-05 13:14 . 2008-04-10 11:52 4,682 --a------ c:\windows\system32\npptNT2.sys 2009-03-05 13:08 . 2009-03-15 14:22 2009-02-22 13:40 . 2004-01-12 00:00 348,160 --a------ c:\windows\system\msvcr71.dll . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-22 14:38 --------- d-----w c:\program files\cFosSpeed 2009-03-22 00:14 --------- d-----w c:\documents and settings\Maciek\Dane aplikacji\uTorrent 2009-03-13 21:07 --------- d-----w c:\documents and settings\Maciek\Dane aplikacji\teamspeak2 2009-03-12 14:52 --------- d–h--w c:\program files\InstallShield Installation Information 2009-03-05 19:00 --------- d-----w c:\program files\Lavalys 2009-03-05 18:18 --------- d-----w c:\program files\Gadu-Gadu 2009-02-17 20:35 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Microsoft Help 2009-02-16 12:02 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Electronic Arts 2009-02-06 17:25 --------- d-----w c:\program files\Wiedźmin 2009-01-31 23:12 --------- d-----w c:\program files\Teamspeak2_RC2 2009-01-28 00:18 --------- d-----w c:\program files\Real 2009-01-28 00:08 --------- d-----w c:\program files\Common Files\Windows Live 2009-01-23 15:48 --------- d-----w c:\documents and settings\Maciek\Dane aplikacji\Skype 2009-01-23 15:30 --------- d-----w c:\documents and settings\Maciek\Dane aplikacji\skypePM 2009-01-23 15:25 --------- d-----w c:\program files\Skype 2009-01-23 15:25 --------- d-----w c:\program files\Common Files\Skype 2009-01-23 15:25 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Skype 2008-11-16 12:19 11,114 ----a-w c:\documents and settings\All Users\Dane aplikacji\MainApp.dll 2008-11-16 09:47 47,360 ----a-w c:\documents and settings\Maciek\Dane aplikacji\pcouffin.sys 2008-10-13 14:33 16,384 --sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat 2008-10-13 14:33 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat 2008-10-13 14:33 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\MSHist012008101320081014\index.dat 2008-10-13 14:33 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat . ------- Sigcheck ------- 2008-06-20 12:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows$hf_mig$\KB951748\SP3QFE\tcpip.sys 2008-05-02 07:48 361344 8e036eec565910417ea020ce0962aa24 c:\windows$NtUninstallKB951748$\tcpip.sys 2008-10-20 21:09 361600 d24ea301e2b36c4e975fd216ca85d8e7 c:\windows\system32\dllcache\tcpip.sys 2008-10-20 21:09 361600 d24ea301e2b36c4e975fd216ca85d8e7 c:\windows\system32\drivers\tcpip.sys . ((((((((((((((((((((((((((((( SnapShot@2009-03-22_15.25.49,40 ))))))))))))))))))))))))))))))))))))))))) . - 2009-03-22 12:06:02 104,960 ----a-w c:\windows\system32\dllcache\userinit.exe + 2008-04-14 20:51:46 26,624 ----a-w c:\windows\system32\dllcache\userinit.exe - 2009-03-22 12:06:02 104,960 ----a-w c:\windows\system32\userinit.exe + 2008-04-14 20:51:46 26,624 ----a-w c:\windows\system32\userinit.exe . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“c:\windows\system32\ctfmon.exe” [2008-04-14 15360] “IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe” [2008-06-24 1840424] “Gadu-Gadu”=“c:\program files\Gadu-Gadu\gg.exe” [2008-03-20 2127296] “Nowe Gadu-Gadu”=“c:\program files\Nowe Gadu-Gadu\gg.exe” [2009-02-27 9339496] “DAEMON Tools Lite”=“c:\program files\DAEMON Tools Lite\daemon.exe” [2008-08-08 490952] “Steam”=“c:\program files\Steam\Steam.exe” [2009-03-22 1410296] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMAXPnP”=“c:\program files\Analog Devices\Core\smax4pnp.exe” [2006-12-18 868352] “razer”=“c:\program files\Razer\razerhid.exe” [2005-05-17 147456] “HP Software Update”=“c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe” [2002-12-17 49152] “HPDJ Taskbar Utility”=“c:\windows\system32\spool\drivers\w32x86\3\hpztsb08.exe” [2003-03-26 172032] “DeviceDiscovery”=“c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe” [2002-12-02 40960] “GrooveMonitor”=“c:\program files\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-26 31016] “egui”=“c:\program files\ESET\ESET NOD32 Antivirus\egui.exe” [2008-07-01 1447168] “RemoteControl”=“c:\program files\CyberLink\PowerDVD\PDVDServ.exe” [2003-10-31 32768] “NeroFilterCheck”=“c:\program files\Common Files\Nero\Lib\NeroCheck.exe” [2008-06-19 570664] “NBKeyScan”=“c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe” [2008-06-08 2221352] “cFosSpeed”=“c:\program files\cFosSpeed\cFosSpeed.exe” [2008-07-18 867544] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] “nltide_2”=“shell32” [X] “nltide_3”=“advpack.dll” [2008-03-01 c:\windows\system32\advpack.dll] c:\documents and settings\All Users\Menu Start\Programy\Autostart\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696] [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] “%windir%\Network Diagnostic\xpnetdiag.exe”= “%windir%\system32\sessmgr.exe”= “c:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE”= “c:\Program Files\Microsoft Office\Office12\GROOVE.EXE”= “c:\Program Files\Microsoft Office\Office12\ONENOTE.EXE”= “c:\Program Files\uTorrent\utorrent.exe”= “c:\Program Files\Gadu-Gadu\gg.exe”= “c:\Program Files\Nero\Nero8\Nero ShowTime\ShowTime.exe”= “c:\Program Files\Ventrilo\Ventrilo.exe”= “c:\Program Files\Opera\opera.exe”= “c:\Program Files\Skype\Phone\Skype.exe”= “c:\Documents and Settings\Maciek\Pulpit\L2 Walker\eL2Walker10.8.6\WalkerPatcher\WP507F.exe”= “c:\Program Files\Nowe Gadu-Gadu\gg.exe”= R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-07-01 34312] R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-07-01 468224] R3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [2008-10-13 13225] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{be15a39e-f542-11dd-835c-001d60cbffc8}] \Shell\AutoRun\command - I:\WDSetup.exe . . ------- Skan uzupełniający ------- . IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Maciek\Dane aplikacji\Mozilla\Firefox\Profiles\nafwiebb.default\ FF - prefs.js: browser.search.selectedEngine - DAEMON Search FF - prefs.js: browser.startup.homepage - hxxp://www.interia.pl/ FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-22 15:39:11 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów … skanowanie ukrytych wpisów autostartu … skanowanie ukrytych plików … skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- [HKEY_USERS\S-1-5-21-789336058-299502267-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{45B6BC31-B2B0-5731-994D-3ED52613CC94}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) “abfbfhjcnfnkgkahdaoglnemjladepebfm”=hex:61,62,70,66,61,61,63,6c,69,67,6f,64, 6f,68,6f,63,6e,67,6f,68,66,66,61,64,6a,70,63,6c,66,67,61,6c,66,6d,00,77 “bbfbfhjcnfnkgkahdajhioobkncdlladgdff”=hex:61,62,6d,66,65,6f,6a,67,66,63,65,6f, 6c,6d,69,64,70,67,66,69,63,6b,6b,70,66,6d,6c,6e,6f,6e,6e,66,61,69,00,77 . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- - - - - - - - > ‘winlogon.exe’(992) c:\windows\system32\Ati2evxx.dll . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\windows\system32\ati2evxx.exe c:\windows\system32\ati2evxx.exe c:\program files\cFosSpeed\spd.exe c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe c:\windows\system32\IoctlSvc.exe c:\program files\Common Files\Nero\Lib\NMIndexingService.exe c:\program files\Razer\razertra.exe c:\program files\Razer\razerofa.exe c:\program files\Nowe Gadu-Gadu\spellchecker_gg.exe c:\windows\system32\wscntfy.exe c:\windows\system32\control.exe . ************************************************************************** . Czas ukończenia: 2009-03-22 15:40:24 - komputer został uruchomiony ponownie [Maciek] ComboFix-quarantined-files.txt 2009-03-22 14:40:21 ComboFix2.txt 2009-03-22 14:26:19 Przed: 14 295 597 056 bajtów wolnych Po: 14,239,268,864 bajtów wolnych WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Microsoft Windows XP Professional” /noexecute=optin /fastdetect 206 — E O F — 2008-10-15 16:39:22