ComboFix 08-09-16.05 - Administrator 2008-09-17 14:33:21.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1618 [GMT 2:00]
Uruchomiony z: D:\ComboFix.exe
* Utworzono nowy punkt przywracania
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA
.
((((((((((((((((((((((((( Pliki utworzone od 2008-08-17 do 2008-09-17 )))))))))))))))))))))))))))))))
.
2008-09-17 10:10 . 2003-10-16 18:07 32,768 --a------ C:\WINDOWS\system32\WooDial2000.dll
2008-09-17 10:08 . 2003-12-08 11:53 70,688 --a------ C:\WINDOWS\system32\drivers\alcaudsl.sys
2008-09-17 10:08 . 2003-12-08 11:53 53,600 --a------ C:\WINDOWS\system32\drivers\alcan5wn.sys
2008-09-17 10:08 . 2003-12-08 11:53 5,606 --a------ C:\WINDOWS\system32\stci.dll
2008-09-17 10:08 . 2003-12-08 11:53 5,280 --a------ C:\WINDOWS\system32\drivers\alcawh.sys
2008-09-17 10:08 . 2003-12-08 11:53 3,968 --a------ C:\WINDOWS\system32\drivers\alcacr.sys
2008-09-17 10:05 . 2008-09-17 10:05
2008-09-17 09:50 . 2008-09-17 09:50
2008-09-17 09:08 . 2008-09-17 09:49
2008-09-17 09:08 . 2008-09-17 09:49
2008-09-12 15:28 . 2007-09-21 02:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm
2008-09-12 15:28 . 2007-10-03 17:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2008-09-12 14:44 . 2008-09-12 14:45
2008-09-11 21:57 . 2008-09-12 08:26 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-11 21:57 . 2008-09-11 21:57 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-11 20:26 . 2008-09-11 20:26
2008-09-08 12:24 . 2008-09-17 10:16
2008-09-08 12:22 . 2008-09-17 09:50
2008-09-06 15:36 . 2008-09-13 09:32
2008-09-01 19:57 . 2008-09-01 19:57
2008-09-01 19:47 . 2008-09-01 19:47
2008-09-01 19:47 . 2008-09-01 19:47 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-01 19:47 . 2008-09-01 19:47 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-09-01 19:40 . 2008-09-17 09:51
2008-09-01 19:40 . 2008-09-09 14:51
2008-09-01 19:40 . 2008-09-17 09:51
2008-09-01 19:39 . 2008-09-17 09:51
2008-09-01 19:39 . 2008-09-17 09:51
2008-09-01 19:38 . 2008-09-01 19:38
2008-08-31 16:40 . 2008-08-31 16:40
2008-08-31 16:40 . 2008-09-17 09:51
2008-08-31 16:39 . 2008-08-31 16:43 223,400 --a------ C:\WINDOWS\hpdj3500.his
2008-08-22 20:20 . 2008-09-17 10:08
2008-08-22 20:15 . 2008-09-17 14:32
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-17 07:49 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-16 22:35 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Skype
2008-09-16 22:04 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\skypePM
2008-09-16 11:04 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Tlen.pl
2008-08-24 17:08 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-08-01 11:43 --------- d-----w C:\Program Files\Tlen.pl
2008-07-30 17:45 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Ventrilo
2008-07-30 17:25 --------- d-----w C:\Program Files\Ventrilo
2008-07-30 17:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-29 12:26 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-06-18 13:21 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2008-06-18 13:21 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2008-06-18 13:21 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2008-06-18 13:10 2,829 ----a-w C:\WINDOWS\DIIUnin.pif
2008-06-18 13:10 106,496 ----a-w C:\WINDOWS\DIIUnin.exe
2008-06-18 12:45 315,392 ----a-w C:\WINDOWS\HideWin.exe
.
------- Sigcheck -------
2007-07-10 15:06 642560 ce594e18fe0d0af804f1f3694921ce62 C:\WINDOWS\system32\user32.dll
2007-07-14 00:56 814592 ce7193c5f7c01b19768e066087c1c919 C:\WINDOWS\system32\wininet.dll
2007-07-28 03:15 360576 0fb6743e937c7bb248b2530a5a77abc6 C:\WINDOWS\system32\drivers\tcpip.sys
2007-07-26 19:30 2145792 316acc3ac43fc855204ce5e775f66b91 C:\WINDOWS\system32\ntoskrnl.exe
2007-07-14 00:42 974848 32f67215c57df2c401bf93b7ee65987f C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
“{9CB65206-89C4-402c-BA80-02D8C59F9B1D}”= “C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL” [2008-06-18 57344]
[HKEY_CLASSES_ROOT\clsid{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“IgfxTray”=“C:\WINDOWS\system32\igfxtray.exe” [2007-11-08 141848]
“HotKeysCmds”=“C:\WINDOWS\system32\hkcmd.exe” [2007-11-08 166424]
“Persistence”=“C:\WINDOWS\system32\igfxpers.exe” [2007-11-08 137752]
“SMSERIAL”=“C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe” [2006-11-22 630784]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 39792]
“NeroFilterCheck”=“C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe” [2007-03-01 153136]
“HControlUser”=“C:\Program Files\ATK Hotkey\HcontrolUser.exe” [2008-01-11 98304]
“ATKHOTKEY”=“C:\Program Files\ATK Hotkey\Hcontrol.exe” [2008-02-01 233472]
“MsgTranAgt”=“C:\Program Files\ATK Hotkey\MsgTranAgt.exe” [2007-11-04 106496]
“ACU”=“C:\Program Files\Atheros\ACU.exe” [2007-10-23 376921]
“WooCnxMon”=“C:\PROGRA~1\NEOSTR~1\CnxMon.exe” [2003-10-16 24576]
“SpeedTouch USB Diagnostics”=“C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe” [2004-01-26 866816]
“WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2003-10-16 20480]
“WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” [2003-10-16 53248]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2008-07-19 78008]
“RTHDCPL”=“RTHDCPL.EXE” [2007-10-25 C:\WINDOWS\RTHDCPL.exe]
“SkyTel”=“SkyTel.EXE” [2007-10-11 C:\WINDOWS\SkyTel.exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 15360]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“nltide_2”=“shell32” [X]
“nltide_3”=“advpack.dll” [2007-07-27 C:\WINDOWS\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“DisableStatusMessages”= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoSMMyPictures”= 1 (0x1)
“NoSMConfigurePrograms”= 1 (0x1)
“NoSMHelp”= 1 (0x1)
“NoResolveTrack”= 1 (0x1)
“NoResolveSearch”= 1 (0x1)
[HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer]
“NoSMMyPictures”= 1 (0x1)
“NoSMConfigurePrograms”= 1 (0x1)
“NoSMHelp”= 1 (0x1)
“NoResolveTrack”= 1 (0x1)
“NoResolveSearch”= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“VIDC.YV12”= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusDisableNotify”=dword:00000001
“AntiVirusOverride”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Tlen.pl\tlen.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\PROGRA~1\ATKHOT~1\ASNDIS5.SYS [2004-05-27 16269]
R3 WSIMD;wsimd Service;C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-07-03 57344]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
“C:\Program Files\Common Files\LightScribe\LSRunOnce.exe”
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\hc5pi396.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.pl/
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real Alternative\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real Alternative\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-17 14:34:12
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów …
skanowanie ukrytych wpisów autostartu …
skanowanie ukrytych plików …
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-09-17 14:34:55
ComboFix-quarantined-files.txt 2008-09-17 12:34:52
Przed: 45,106,921,472 bajt˘w wolnych
Po: 45,116,370,944 bajt˘w wolnych
158