ComboFix 08-11-07.01 - Sewek 2008-11-08 19:48:27.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.186 [GMT 1:00] Uruchomiony z: c:\documents and settings\Sewek\Pulpit\ComboFix.exe * Utworzono nowy punkt przywracania * Resident AV is active UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_NPF -------\Service_NPF ((((((((((((((((((((((((( Pliki utworzone od 2008-10-08 do 2008-11-08 ))))))))))))))))))))))))))))))) . 2008-11-05 12:27 . 2008-11-05 12:27 2008-11-02 11:01 . 2008-11-02 11:00 410,976 --a------ c:\windows\system32\deploytk.dll 2008-10-28 19:36 . 2008-10-28 19:43 43,520 --a------ c:\windows\system32\CmdLineExt03.dll 2008-10-28 19:23 . 2008-10-30 14:04 2008-10-24 04:32 . 2008-10-15 17:36 337,408 -----c— c:\windows\system32\dllcache\netapi32.dll 2008-10-21 07:54 . 2008-10-21 07:54 2008-10-18 15:35 . 2008-10-18 15:35 2008-10-18 15:35 . 2004-02-22 09:11 719,872 --a------ c:\windows\system32\devil.dll 2008-10-18 15:35 . 2006-10-07 16:43 502,784 --a------ c:\windows\x2.64.exe 2008-10-18 15:35 . 2007-05-17 16:30 318,976 --a------ c:\windows\system32\avisynth.dll 2008-10-18 15:35 . 2005-02-28 12:16 240,128 --a------ c:\windows\system32\x.264.exe 2008-10-18 15:35 . 2006-04-12 08:47 217,073 --a------ c:\windows\meta4.exe 2008-10-18 15:35 . 2004-01-24 23:00 70,656 --a------ c:\windows\system32\yv12vfw.dll 2008-10-18 15:35 . 2004-01-24 23:00 70,656 --a------ c:\windows\system32\i420vfw.dll 2008-10-18 15:35 . 2006-04-05 07:09 66,560 --a------ c:\windows\MOTA113.exe 2008-10-18 15:35 . 2005-07-14 11:31 27,648 --a------ c:\windows\system32\AVSredirect.dll 2008-10-18 15:34 . 2005-02-12 23:00 186,880 -r-hs---- c:\windows\system32\RLOgg.ax 2008-10-18 15:34 . 2005-01-17 23:26 179,200 -r-hs---- c:\windows\system32\DiracSplitter.ax 2008-10-18 15:34 . 2006-08-16 14:53 175,104 -r-hs---- c:\windows\system32\CoreAAC.ax 2008-10-18 15:34 . 2005-02-05 23:00 92,672 -r-hs---- c:\windows\system32\RLVorbisDec.ax 2008-10-18 15:34 . 2005-02-22 16:55 81,920 -r-hs---- c:\windows\system32\aac_parser.ax 2008-10-18 15:34 . 2005-02-12 23:00 67,584 -r-hs---- c:\windows\system32\RLTheoraDec.ax 2008-10-18 15:34 . 2005-02-12 23:00 51,712 -r-hs---- c:\windows\system32\RLSpeexDec.ax 2008-10-15 19:14 . 2008-10-16 10:45 2008-10-15 10:33 . 2008-10-15 10:33 2008-10-15 10:29 . 2008-10-15 10:29 2008-10-15 04:33 . 2008-09-15 16:27 1,846,656 -----c— c:\windows\system32\dllcache\win32k.sys 2008-10-15 04:33 . 2008-09-08 11:41 333,824 -----c— c:\windows\system32\dllcache\srv.sys 2008-10-15 04:32 . 2008-08-14 14:26 2,190,464 -----c— c:\windows\system32\dllcache\ntoskrnl.exe 2008-10-15 04:32 . 2008-08-14 14:26 2,146,816 -----c— c:\windows\system32\dllcache\ntkrnlmp.exe 2008-10-15 04:32 . 2008-08-14 14:26 2,067,328 -----c— c:\windows\system32\dllcache\ntkrnlpa.exe 2008-10-15 04:32 . 2008-08-14 14:26 2,025,472 -----c— c:\windows\system32\dllcache\ntkrpamp.exe 2008-10-13 14:12 . 2008-10-13 14:12 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2008-10-13 14:12 . 2008-10-13 14:12 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01005.Wdf 2008-10-13 14:04 . 2008-10-13 14:04 1,419,232 --a------ c:\windows\system32\wdfcoinstaller01005.dll 2008-10-13 14:04 . 2008-10-13 14:04 21,672 --a------ c:\windows\system32\drivers\ggsemc.sys 2008-10-13 14:04 . 2008-10-13 14:04 13,352 --a------ c:\windows\system32\drivers\ggflt.sys 2008-10-13 14:02 . 2008-10-13 14:04 2008-10-13 11:58 . 2008-10-13 14:05 2008-10-13 11:52 . 2008-10-15 07:50 2008-10-13 11:24 . 2008-10-15 09:57 . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-08 17:08 --------- d-----w c:\documents and settings\Sewek\Dane aplikacji\uTorrent 2008-11-08 16:47 --------- d-----w c:\program files\Warcraft III 2008-11-07 16:47 --------- d-----w c:\documents and settings\Sewek\Dane aplikacji\EurekaLog 2008-11-03 15:12 --------- d-----w c:\program files\Opera 2008-11-02 09:59 --------- d-----w c:\program files\Java 2008-11-01 22:34 --------- d-----w c:\program files\Odkurzacz 2008-11-01 20:09 --------- d-----w c:\program files\Windows Media Connect 2 2008-10-29 16:45 --------- d–h--w c:\program files\InstallShield Installation Information 2008-10-29 16:12 --------- d-----w c:\program files\Steam 2008-10-21 07:17 --------- d-----w c:\program files\python 2008-10-21 07:17 --------- d-----w c:\program files\PhotoScape 2008-10-21 07:17 --------- d-----w c:\program files\NAPI-PROJEKT 2008-10-21 07:17 --------- d-----w c:\program files\Avanquest update 2008-10-16 12:14 --------- d-----w c:\program files\Evil Invasion 2008-10-15 09:29 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Avira 2008-10-13 13:05 --------- d-----w c:\program files\Common Files\Adobe 2008-10-13 13:03 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Sony Ericsson 2008-10-12 18:02 --------- d-----w c:\program files\Image-Line 2008-10-05 17:37 --------- d-----w c:\program files\Rzeznik 2008-10-05 14:31 --------- d-----w c:\program files\Tibia Auto 2008-10-05 14:31 --------- d-----w c:\program files\Tibia 2008-10-03 05:52 --------- d-----w c:\documents and settings\Sewek\Dane aplikacji\Tibia 2008-10-02 12:31 --------- d-----w c:\program files\Lyrics4You 2008-10-02 09:36 2,129,920 ----a-w c:\windows\system32\python26.dll 2008-10-02 09:36 2,129,920 ----a-w c:\windows\python26.dll 2008-09-29 04:54 --------- d-----w c:\program files\Sony Ericsson 2008-09-26 13:36 499,712 ----a-w c:\windows\system32\msvcp71.dll 2008-09-26 13:36 348,160 ----a-w c:\windows\system32\msvcr71.dll 2008-09-26 13:36 --------- d-----w c:\program files\Common Files\xing shared 2008-09-26 13:36 --------- d-----w c:\program files\Common Files\Real 2008-09-26 13:31 8,552 ----a-w c:\windows\system32\drivers\asctrm.sys 2008-09-26 13:31 --------- d-----w c:\program files\Real 2008-09-23 08:45 --------- d-----w c:\program files\Journey to the Center of the Earth 2008-09-21 07:22 --------- d-----w c:\program files\Common Files\InstallShield 2008-09-21 07:17 --------- d-----w c:\program files\PowerISO 2008-09-19 10:13 --------- d-----w c:\program files\Ad-Aware 2008-09-17 12:06 --------- d-----w c:\program files\Common Files\DVDVideoSoft 2008-09-16 06:19 --------- d-----w c:\documents and settings\Sewek\Dane aplikacji\vlc 2008-09-16 06:03 --------- d-----w c:\program files\VideoLAN 2008-09-15 15:27 1,846,656 ----a-w c:\windows\system32\win32k.sys 2008-09-15 14:25 --------- d-----w c:\program files\Aliens vs. Predator 2 2008-09-14 12:10 --------- d-----r c:\documents and settings\Sewek\Dane aplikacji\Brother 2008-09-13 14:54 --------- d-----w c:\program files\Walaber’s Trampoline 2008-09-13 10:04 --------- d-----w c:\program files\DAEMON Tools Lite 2008-09-13 10:01 717,296 ----a-w c:\windows\system32\drivers\sptd.sys 2008-09-13 10:01 --------- d-----w c:\documents and settings\Sewek\Dane aplikacji\DAEMON Tools 2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys 2008-08-20 21:10 2,829 ----a-w c:\windows\War3Unin.pif 2008-08-20 21:10 139,264 ----a-w c:\windows\War3Unin.exe 2008-08-20 05:11 668,672 ----a-w c:\windows\system32\wininet.dll 2008-08-14 13:26 2,190,464 ----a-w c:\windows\system32\ntoskrnl.exe 2008-08-14 13:26 2,067,328 ----a-w c:\windows\system32\ntkrnlpa.exe . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “AQQ”=“c:\progra~1\WapSter\WAPSTE~1\AQQ.exe” [2008-10-17 1648640] “Odkurzacz-MCD”=“c:\program files\Odkurzacz\odk_mcd.exe” [2008-08-16 264704] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “avgnt”=“c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe” [2008-06-12 266497] “SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2008-11-02 136600] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] “vidc.I420”= i420vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] c:\windows\system32\dumprep 0 -k [X] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] --a------ 2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd] --------- 2007-03-12 13:51 663552 c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3] --------- 2007-01-26 14:58 65536 c:\program files\Brother\ControlCenter3\BrCtrCen.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] --a------ 2008-04-14 21:51 15360 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch] --a------ 2007-01-29 20:10 46632 c:\program files\ScanSoft\PaperPort\IndexSearch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --------- 2008-04-14 21:51 1695232 c:\program files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD] --a------ 2007-01-29 20:12 30248 c:\program files\ScanSoft\PaperPort\pptd40nt.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] --------- 2008-02-20 16:20 360448 c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate] --a------ 2006-10-25 08:03 210472 c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] --a------ 2008-09-26 14:36 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\w3dr.exe] --a------ 2008-08-03 15:38 61440 c:\program files\Warcraft III\W3DR.exe [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile] “EnableFirewall”= 0 (0x0) [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] “%windir%\system32\sessmgr.exe”= “c:\Program Files\Opera\opera.exe”= “c:\Program Files\uTorrent\uTorrent.exe”= “%windir%\Network Diagnostic\xpnetdiag.exe”= [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] “8092:TCP”= 8092:TCP:BitComet 8092 TCP “8092:UDP”= 8092:UDP:BitComet 8092 UDP R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [2008-07-16 269736] R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [2008-06-21 66600] R2 AntiVirMailService;Avira AntiVir Premium MailGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [2008-07-11 164097] R2 AVEService;Avira AntiVir Premium MailGuard helper service;c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [2008-05-09 41217] R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-11-02 152984] R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-07-30 95528] R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-07-30 1361192] R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\DRIVERS\sbfwim.sys [2008-06-21 65576] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2008-10-13 13352] S4 antivirwebservice;Avira AntiVir Premium WebGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE [2008-06-12 258305] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{5a1f533d-7e25-11dd-ae1b-000b6a1f4531}] \Shell\AutoRun\command - G:\cl.bat \Shell\explore\Command - G:\cl.bat \Shell\open\Command - G:\cl.bat . - - - - USUNIĘTO PUSTE WPISY - - - - MSConfigStartUp-ares - c:\program files\Ares\Ares.exe MSConfigStartUp-Cmaudio - cmicnfg.cpl MSConfigStartUp-Spol - http://www.toya.net.pl/~spol/site/index.htm . ------- Skan uzupełniający ------- . R0 -: HKCU-Main,Default_Search_URL = hxxp://www.google.com/ie R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s O8 -: Eksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-08 19:57:44 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów … skanowanie ukrytych wpisów autostartu … skanowanie ukrytych plików … skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\windows\system32\ati2evxx.exe c:\windows\system32\ati2evxx.exe c:\program files\Ad-Aware\aawservice.exe c:\program files\Avira\AntiVir PersonalEdition Premium\sched.exe c:\program files\Avira\AntiVir PersonalEdition Premium\avguard.exe c:\program files\Sunbelt Software\Personal Firewall\SbPFCl.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Czas ukończenia: 2008-11-08 20:04:11 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2008-11-08 19:03:59 Przed: 9 854 869 504 bajtów wolnych Po: 9,858,543,616 bajtów wolnych 217 — E O F — 2008-10-24 18:31:56