ComboFix 07-10-23.2 - Ciachos 2007-10-26 1:59:16.3 - NTFSx86 Podczas wykonywania skryptu “C:\ComboFix\osid.vbs” przekroczono limit czasu. Wykonywanie skryptu zosta�o zakoäczone. Running from: E:\instalki\ratownicze po wirusie czy padzie rejestru\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-09-26 to 2007-10-26 ))))))))))))))))))))))))))))))) . 2007-10-25 17:42 512,096 --a------ C:\Windows\System32\drivers\amon.sys 2007-10-25 17:42 298,104 --a------ C:\Windows\System32\imon.dll 2007-10-25 17:42 15,424 --a------ C:\Windows\System32\drivers\nod32drv.sys 2007-10-25 17:26 51,200 --a------ C:\Windows\NirCmd.exe 2007-10-25 17:00 2007-10-25 16:58 102,664 --a------ C:\Windows\System32\drivers\tmcomm.sys 2007-10-25 16:49 2007-10-25 16:49 2007-10-25 16:48 2007-10-25 16:45 2007-10-25 16:24 2007-10-25 15:18 2007-10-25 15:15 2007-10-25 15:15 2007-10-25 15:14 2007-10-25 14:54 2007-10-25 14:52 2007-10-25 14:51 2007-10-21 14:31 2007-10-19 19:44 2007-10-19 19:40 2007-10-19 19:37 20,016 --------- C:\Windows\System32\drivers\pxhelp20.sys 2007-10-19 15:39 2007-10-19 15:31 23 --ahs---- C:\Windows\System32\cbcfbabc_g.dll 2007-10-19 13:13 2007-10-19 13:13 57,344 --a------ C:\Windows\System32\CGZipLibrary.DLL 2007-10-19 11:20 2007-10-18 18:36 2007-10-18 17:45 2007-10-18 17:31 2007-10-18 17:00 40,960 --a------ C:\Windows\System32\SSubTmr6.dll 2007-10-18 16:48 16,896 --a------ C:\Windows\System32\drivers\mondrv.sys 2007-10-18 13:41 2007-10-18 13:08 2007-10-18 13:08 2007-10-18 12:07 2007-10-18 12:07 2007-10-17 18:47 2,463,976 --a------ C:\Windows\System32\NPSWF32.dll 2007-10-17 18:47 190,696 --a------ C:\Windows\System32\NPSWF32_FlashUtil.exe 2007-10-17 17:41 2007-10-15 00:44 2007-10-14 12:03 2007-10-14 12:00 3,727,720 --a------ C:\Windows\System32\d3dx9_35.dll 2007-10-14 12:00 1,358,192 --a------ C:\Windows\System32\D3DCompiler_35.dll 2007-10-14 12:00 444,776 --a------ C:\Windows\System32\d3dx10_35.dll 2007-10-13 11:59 3,497,832 --a------ C:\Windows\System32\d3dx9_34.dll 2007-10-13 11:59 1,124,720 --a------ C:\Windows\System32\D3DCompiler_34.dll 2007-10-13 11:59 443,752 --a------ C:\Windows\System32\d3dx10_34.dll 2007-10-13 11:59 266,088 --a------ C:\Windows\System32\xactengine2_8.dll 2007-10-13 11:59 261,480 --a------ C:\Windows\System32\xactengine2_7.dll 2007-10-13 11:59 255,848 --a------ C:\Windows\System32\xactengine2_6.dll 2007-10-13 11:59 18,280 --a------ C:\Windows\System32\x3daudio1_2.dll 2007-10-13 11:59 15,128 --a------ C:\Windows\System32\x3daudio1_1.dll 2007-10-11 00:04 2,560 --a------ C:\Windows_MSRSTRT.EXE 2007-10-10 23:49 1,024 --a------ C:\Windows\System32\pwdremover.dat 2007-10-10 23:40 149,504 --a------ C:\Windows\UNWISE.EXE 2007-10-09 23:16 8,147,968 --a------ C:\Windows\System32\wmploc.DLL 2007-10-09 23:16 356,864 --a------ C:\Windows\System32\MediaMetadataHandler.dll 2007-10-09 23:16 7,680 --a------ C:\Windows\System32\spwmp.dll 2007-10-09 23:16 4,096 --a------ C:\Windows\System32\dxmasf.dll 2007-10-09 23:14 788,992 --a------ C:\Windows\System32\rpcrt4.dll 2007-10-09 23:14 737,792 --a------ C:\Windows\System32\inetcomm.dll 2007-10-09 23:14 84,480 --a------ C:\Windows\System32\INETRES.dll 2007-10-01 17:59 2007-10-01 12:00 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-25 23:57 --------- d-----w C:\Users\Ciachos\AppData\Roaming\VMware 2007-10-25 00:39 --------- d-----w C:\Program Files\Steam 2007-10-22 14:28 --------- d-----w C:\Program Files\Sony 2007-10-22 14:27 --------- d-----w C:\Program Files\VSTplugins 2007-10-21 12:31 --------- d-----w C:\Program Files\Słownik synonimów 1.0 2007-10-21 10:28 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-10-19 17:41 --------- d-----w C:\Program Files\Common Files\Adobe 2007-10-19 10:23 --------- d-----w C:\Users\Ciachos\AppData\Roaming\Bioshock 2007-10-18 15:00 --------- d-----w C:\Program Files\Add-Remove Master 6.0 2007-10-18 13:12 --------- d-----w C:\Users\Ciachos\AppData\Roaming\Skype 2007-10-16 19:39 --------- d-----w C:\Program Files\Common Files\Steam 2007-10-15 09:40 --------- d-----w C:\Users\Ciachos\AppData\Roaming\Notepad++ 2007-10-15 09:40 --------- d-----w C:\Program Files\Notepad++ 2007-10-14 09:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-10-14 09:59 --------- d-----w C:\Program Files\AGEIA Technologies 2007-10-13 18:48 --------- d-----w C:\Program Files\World of Warcraft 2007-10-09 21:40 --------- d-----w C:\Program Files\Windows Mail 2007-10-09 21:15 56,320 ----a-w C:\Windows\System32\iesetup.dll 2007-10-09 21:15 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2007-10-09 21:15 26,624 ----a-w C:\Windows\System32\ieUnatt.exe 2007-09-17 19:02 --------- d-----w C:\Users\Ciachos\AppData\Roaming\Thunderbird 2007-09-17 19:02 --------- d-----w C:\Program Files\Mozilla Thunderbird 2007-09-15 13:03 22,328 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys 2007-09-15 13:03 103,736 ----a-w C:\Windows\System32\PnkBstrB.exe 2007-09-13 07:45 70,944 ----a-w C:\Windows\System32\PhysXLoader.dll 2007-09-11 20:28 86,016 ----a-w C:\Windows\System32\nvsvc.dll 2007-09-11 20:28 81,920 ----a-w C:\Windows\System32\nvmctray.dll 2007-09-11 20:28 8,497,696 ----a-w C:\Windows\System32\nvcpl.dll 2007-09-11 20:28 753,664 ----a-w C:\Windows\System32\nvcplui.exe 2007-09-11 20:28 7,623,968 ----a-w C:\Windows\system32\drivers\nvlddmkm.sys 2007-09-11 20:28 6,942,720 ----a-w C:\Windows\System32\nvoglv32.dll 2007-09-11 20:28 6,344,704 ----a-w C:\Windows\System32\nvdisps.dll 2007-09-11 20:28 5,509,120 ----a-w C:\Windows\System32\nvdispsr.dll 2007-09-11 20:28 458,752 ----a-w C:\Windows\System32\nvmccssr.dll 2007-09-11 20:28 45,056 ----a-w C:\Windows\System32\nvmccsrs.dll 2007-09-11 20:28 4,988,928 ----a-w C:\Windows\System32\nvd3dum.dll 2007-09-11 20:28 364,544 ----a-w C:\Windows\System32\nvapi.dll 2007-09-11 20:28 36,864 ----a-w C:\Windows\System32\nvcod100.dll 2007-09-11 20:28 36,864 ----a-w C:\Windows\System32\nvcod.dll 2007-09-11 20:28 356,352 ----a-w C:\Windows\System32\nvuninst.exe 2007-09-11 20:28 356,352 ----a-w C:\Windows\System32\nvudisp.exe 2007-09-11 20:28 307,200 ----a-w C:\Windows\System32\nvexpbar.dll 2007-09-11 20:28 3,629,056 ----a-w C:\Windows\System32\nvvitvsr.dll 2007-09-11 20:28 3,551,232 ----a-w C:\Windows\System32\nvvitvs.dll 2007-09-11 20:28 3,334,144 ----a-w C:\Windows\System32\nvgames.dll 2007-09-11 20:28 3,166,208 ----a-w C:\Windows\System32\nvgamesr.dll 2007-09-11 20:28 229,376 ----a-w C:\Windows\System32\nvmccs.dll 2007-09-11 20:28 2,854,912 ----a-w C:\Windows\System32\nvmoblsr.dll 2007-09-11 20:28 2,441,216 ----a-w C:\Windows\System32\nvwssr.dll 2007-09-11 20:28 2,371,584 ----a-w C:\Windows\System32\nvwss.dll 2007-09-11 20:28 188,416 ----a-w C:\Windows\System32\nvmccss.dll 2007-09-11 20:28 147,456 ----a-w C:\Windows\System32\nvcolor.exe 2007-09-11 20:28 1,521,664 ----a-w C:\Windows\System32\nvwgf2um.dll 2007-09-11 20:28 1,150,976 ----a-w C:\Windows\System32\nvmobls.dll 2007-09-11 20:28 1,073,152 ----a-w C:\Windows\System32\nvcpluir.dll 2007-09-11 10:55 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe 2007-09-11 06:43 22,328 ----a-w C:\Users\Ciachos\AppData\Roaming\PnkBstrK.sys 2007-09-11 04:44 --------- d-----w C:\Users\Ciachos\AppData\Roaming\IGN_DLM 2007-09-03 11:08 --------- d-----w C:\Program Files\Cyanide 2007-08-28 23:21 174 --sha-w C:\Program Files\desktop.ini 2007-08-28 23:19 --------- d-----w C:\Program Files\Windows Calendar 2007-08-28 23:12 8,192 ----a-w C:\Windows\System32\riched32.dll 2007-08-28 23:12 77,824 ----a-w C:\Windows\System32\rascfg.dll 2007-08-28 23:12 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys 2007-08-28 23:12 694,784 ----a-w C:\Windows\System32\localspl.dll 2007-08-28 23:12 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys 2007-08-28 23:12 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys 2007-08-28 23:12 52,736 ----a-w C:\Windows\System32\rasdiag.dll 2007-08-28 23:12 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys 2007-08-28 23:12 384,000 ----a-w C:\Windows\System32\netcfgx.dll 2007-08-28 23:12 36,864 ----a-w C:\Windows\System32\cdd.dll 2007-08-28 23:12 33,280 ----a-w C:\Windows\System32\traffic.dll 2007-08-28 23:12 32,768 ----a-w C:\Windows\System32\rasmxs.dll 2007-08-28 23:12 286,208 ----a-w C:\Windows\System32\ipnathlp.dll 2007-08-28 23:12 22,016 ----a-w C:\Windows\System32\rasser.dll 2007-08-28 23:12 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys 2007-08-28 23:12 15,360 ----a-w C:\Windows\System32\pacerprf.dll 2007-08-28 23:12 134,656 ----a-w C:\Windows\System32\dps.dll 2007-08-28 23:12 13,824 ----a-w C:\Windows\System32\wshqos.dll 2007-08-28 23:12 13,824 ----a-w C:\Windows\System32\icsunattend.exe 2007-08-28 23:11 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr 2007-08-28 23:11 61,440 ----a-w C:\Windows\System32\ntprint.exe 2007-08-28 23:11 320,000 ----a-w C:\Windows\system32\drivers\csc.sys 2007-08-28 23:11 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe 2007-08-28 23:11 3,470,008 ----a-w C:\Windows\System32\ntoskrnl.exe 2007-08-28 23:11 269,824 ----a-w C:\Windows\System32\schannel.dll 2007-08-28 23:11 25,600 ----a-w C:\Windows\System32\LangCleanupSysprepAction.dll 2007-08-28 23:11 23,552 ----a-w C:\Windows\System32\lpremove.exe 2007-08-28 23:11 220,160 ----a-w C:\Windows\System32\ntprint.dll 2007-08-28 23:11 166,912 ----a-w C:\Windows\System32\lpksetup.exe 2007-08-28 23:11 120,320 ----a-w C:\Windows\System32\dhcpcsvc6.dll 2007-08-28 23:11 105,984 ----a-w C:\Windows\System32\CscMig.dll 2007-08-28 23:11 10,240 ----a-w C:\Windows\System32\MUILanguageCleanup.dll 2007-08-28 23:11 10,240 ----a-w C:\Windows\System32\dhcpcmonitor.dll 2007-08-28 23:11 1,984,512 ----a-w C:\Windows\System32\authui.dll 2007-08-28 23:10 88,576 ----a-w C:\Windows\System32\avifil32.dll 2007-08-28 23:10 82,944 ----a-w C:\Windows\System32\mciavi32.dll 2007-08-28 23:10 8,138,240 ----a-w C:\Windows\System32\ssBranded.scr 2007-08-28 23:10 750,080 ----a-w C:\Windows\System32\qmgr.dll 2007-08-28 23:10 712,192 ----a-w C:\Windows\System32\WindowsCodecs.dll 2007-07-21 23:33:20 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 2007-07-21 23:33:20 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 2007-07-21 23:33:20 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Windows Defender”=“C:\Program Files\Windows Defender\MSASCui.exe” [2007-06-28 13:54] “GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-27 00:47] “nod32kui”=“C:\Program Files\Eset\nod32kui.exe” [2007-10-25 17:42] “RemoteControl”=“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” [2007-02-07 16:24] “LanguageShortcut”=“C:\Program Files\CyberLink\PowerDVD\Language\Language.exe” [2007-02-07 16:21] “RegistryMechanic”="" [] “vmware-tray”=“C:\Program Files\VMware\VMware Workstation\vmware-tray.exe” [2007-05-01 22:52] “VMware hqtray”=“C:\Program Files\VMware\VMware Workstation\hqtray.exe” [2007-05-01 22:52] “NvSvc”=“C:\Windows\system32\nvsvc.dll” [2007-09-11 22:28] “NvCplDaemon”=“C:\Windows\system32\NvCpl.dll” [2007-09-11 22:28] “NvMediaCenter”=“C:\Windows\system32\NvMcTray.dll” [2007-09-11 22:28] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Sidebar”=“C:\Program Files\Windows Sidebar\sidebar.exe” [2006-11-02 14:33] “DAEMON Tools”=“C:\Program Files\DAEMON Tools\daemon.exe” [2007-04-04 00:29] “Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-06-08 15:18] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-05-10 16:36] “igndlm.exe”=“C:\Program Files\IGN\Download Manager\DLM.exe” [2007-03-05 13:57] C:\Users\Ciachos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-06-29 23:08:37] Tworzenie wycink˘w ekranu i uruchamianie programu OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoCloseDragDropBands "=0 (0x0) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{93994DE8-8239-4655-B1D1-5F4E91300429}”= C:\Program Files\DVDIdle Pro\DVDShell.dll [2004-10-09 15:18 49152] R1 ISODrive;ISO CD-ROM Device Driver;??\C:\Program Files\UltraISO\drivers\ISODrive.sys S2 ELOADER;General Purpose USB Driver (adildr.sys);C:\Windows\system32\Drivers\adildr.sys S3 Memctl;Memctl;??\C:\Program Files\U-ABIT\BlackBox\Memctl.sys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs wscsvc AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe Open(&0)\command - Recycled\ctfmon.exe . Contents of the ‘Scheduled Tasks’ folder “2007-10-18 20:39:04 C:\Windows\Tasks\AppleSoftwareUpdate.job” “2007-10-19 00:01:15 C:\Windows\Tasks\At1.job” “2007-10-25 22:46:24 C:\Windows\Tasks\User_Feed_Synchronization-{874ABE32-1A43-40C3-B05D-94887647CCD9}.job” . ************************************************************************** catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-26 02:06:36 Windows 6.0.6000 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-10-26 2:07:11 - machine was rebooted . — E O F —