przez marcinjuve 07 Lip 2009, 13:22
[code][ComboFix 09-07-06.02 - dom 2007-07-07 13:21.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.2047.1697 [GMT 2:00]
Uruchomiony z: c:\documents and settings\dom\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((( Pliki utworzone od 2007-06-07 do 2007-07-07 )))))))))))))))))))))))))))))))
.
2009-03-15 10:25 . 2009-03-15 10:25 56268 ----a-w- c:\windows\system32\drivers\scdemu.sys
2009-01-21 15:11 . 2009-01-21 15:11 473600 ----a-w- c:\windows\system32\SkanerOnline.dll
2008-04-11 19:17 . 2008-04-11 19:17 89088 ----a-w- c:\windows\system32\SkanerOnlineUninstall.exe
2007-07-06 08:59 . 2007-07-06 08:59 -------- d-----w- c:\program files\PowerISO
2007-07-06 08:31 . 2007-07-06 08:31 -------- d-----w- c:\program files\7-Zip
2007-07-05 17:03 . 2007-07-05 17:03 -------- d-----w- c:\documents and settings\dom\Dane aplikacji\Ubisoft
2007-07-05 17:03 . 2007-07-05 17:03 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Ubisoft
2007-07-05 16:23 . 2008-11-06 00:03 -------- d-----w- C:\SDFix
2007-07-05 16:08 . 2007-07-05 16:08 -------- d-----w- c:\documents and settings\dom\Dane aplikacji\Malwarebytes
2007-07-05 16:08 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2007-07-05 16:08 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2007-07-05 16:08 . 2007-07-05 16:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2007-07-05 16:08 . 2007-07-05 16:08 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Malwarebytes
2007-07-05 15:59 . 2007-07-05 15:59 -------- d-----w- c:\windows\Logs
2007-07-05 15:41 . 2007-07-05 15:41 -------- d-----w- c:\program files\Alwil Software
2007-07-05 15:22 . 2007-07-05 20:59 -------- d-----w- c:\program files\trend micro
2007-07-05 15:22 . 2007-07-05 15:23 -------- d-----w- C:\rsit
2007-07-05 14:12 . 2007-07-05 14:49 -------- d-----w- c:\program files\SkanerOnline
2007-07-05 13:47 . 2007-05-23 14:58 29264 ----a-w- c:\windows\system32\drivers\kcom.sys
2007-07-05 13:47 . 2007-05-23 14:58 83024 ----a-w- c:\windows\system32\drivers\iksyssec.sys
2007-07-05 13:47 . 2007-05-23 14:58 57424 ----a-w- c:\windows\system32\drivers\iksysflt.sys
2007-07-05 13:47 . 2007-05-23 14:58 53840 ----a-w- c:\windows\system32\drivers\ikfilesec.sys
2007-07-05 13:47 . 2007-05-23 14:58 39376 ----a-w- c:\windows\system32\drivers\ikfileflt.sys
2007-07-05 13:47 . 2007-07-05 15:40 -------- d-----w- c:\program files\Spyware Doctor
2007-07-05 13:47 . 2007-07-05 13:47 -------- d-----w- c:\documents and settings\dom\Dane aplikacji\PC Tools
2007-07-05 13:47 . 2005-09-23 05:29 626688 ----a-w- c:\windows\system32\msvcr80.dll
2007-07-05 13:47 . 2005-07-06 15:13 499712 ----a-w- c:\windows\system32\msvcp71.dll
2007-07-05 13:47 . 2005-07-06 15:13 348160 ----a-w- c:\windows\system32\msvcr71.dll
2007-07-05 13:44 . 2007-07-05 13:44 -------- d--h--w- c:\windows\system32\GroupPolicy
2007-07-05 13:29 . 2004-04-30 07:37 160640 ----a-w- c:\windows\system32\drivers\a347bus.sys
2007-07-05 13:29 . 2004-04-30 07:33 5248 ----a-w- c:\windows\system32\drivers\a347scsi.sys
2007-07-05 13:29 . 2007-07-05 13:29 -------- d-----w- c:\program files\Alcohol Soft
2007-07-05 12:25 . 2006-08-01 07:02 49152 ------r- c:\windows\system32\ChCfg.exe
2007-07-05 12:24 . 2006-07-21 08:14 159744 ------r- c:\windows\SoundMan.exe
2007-07-05 12:24 . 2008-04-02 01:27 1196032 ------r- c:\windows\RtlUpd.exe
2007-07-05 12:24 . 2007-03-23 11:19 9715200 ------r- c:\windows\RTLCPL.exe
2007-07-05 12:24 . 2008-04-17 08:33 4707328 ------r- c:\windows\system32\drivers\RtkHDAud.sys
2007-07-05 12:24 . 2008-04-10 08:52 16861184 ------r- c:\windows\RTHDCPL.exe
2007-07-05 12:24 . 2007-06-28 08:44 2165760 ------r- c:\windows\MicCal.exe
2007-07-05 12:24 . 2007-07-05 12:24 -------- d-----w- c:\program files\Realtek
2007-07-05 12:24 . 2006-05-04 08:26 2808832 ------r- c:\windows\alcwzrd.exe
2007-07-05 12:24 . 2008-03-05 10:07 520192 ------r- c:\windows\RtlExUpd.dll
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-16 12:18 . 2007-07-05 16:05 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-03-16 12:18 . 2007-07-05 16:05 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-03-16 12:18 . 2007-07-05 16:05 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2009-03-16 12:18 . 2007-07-05 16:05 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2009-03-09 13:27 . 2007-07-05 16:05 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-03-09 13:27 . 2007-07-05 16:05 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2009-03-09 13:27 . 2007-07-05 16:05 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
2008-10-27 08:04 . 2007-07-05 16:05 514384 ----a-w- c:\windows\system32\XAudio2_3.dll
2008-10-27 08:04 . 2007-07-05 16:05 235856 ----a-w- c:\windows\system32\xactengine3_3.dll
2008-10-27 08:04 . 2007-07-05 16:05 23376 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2008-10-27 08:04 . 2007-07-05 16:05 70992 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2008-10-10 02:52 . 2007-07-05 16:05 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2008-10-10 02:52 . 2007-07-05 16:05 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2008-10-10 02:52 . 2007-07-05 16:05 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2008-07-30 04:20 . 2007-07-05 16:05 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2008-07-30 04:20 . 2007-07-05 16:05 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2008-07-30 04:20 . 2007-07-05 16:05 238088 ----a-w- c:\windows\system32\xactengine3_2.dll
2008-07-10 09:01 . 2007-07-05 16:05 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2008-07-10 09:00 . 2007-07-05 16:05 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2008-07-10 09:00 . 2007-07-05 16:05 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2008-07-09 13:59 . 2007-07-05 10:33 446464 ----a-w- c:\windows\system32\NVUNINST.EXE
2008-05-30 12:19 . 2007-07-05 16:05 507400 ----a-w- c:\windows\system32\XAudio2_1.dll
2008-05-30 12:18 . 2007-07-05 16:05 238088 ----a-w- c:\windows\system32\xactengine3_1.dll
2008-05-30 12:17 . 2007-07-05 16:05 65032 ----a-w- c:\windows\system32\XAPOFX1_0.dll
2008-05-30 12:17 . 2007-07-05 16:05 25608 ----a-w- c:\windows\system32\X3DAudio1_4.dll
2008-05-30 12:11 . 2007-07-05 16:05 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
2008-05-30 12:11 . 2007-07-05 16:05 3850760 ----a-w- c:\windows\system32\D3DX9_38.dll
2008-05-30 12:11 . 2007-07-05 16:05 1491992 ----a-w- c:\windows\system32\D3DCompiler_38.dll
2008-03-05 14:03 . 2007-07-05 16:05 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2008-03-05 14:03 . 2007-07-05 16:05 238088 ----a-w- c:\windows\system32\xactengine3_0.dll
2008-03-05 14:00 . 2007-07-05 16:05 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll
2008-03-05 13:56 . 2007-07-05 16:05 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
2008-03-05 13:56 . 2007-07-05 16:05 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2008-02-05 21:07 . 2007-07-05 16:05 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
2008-01-10 06:30 . 2007-07-05 10:33 442368 ----a-r- c:\windows\system32\nvusmb.exe
2008-01-03 14:10 . 2007-07-05 10:31 105856 ----a-r- c:\windows\system32\drivers\Rtenicxp.sys
2007-10-22 01:39 . 2007-07-05 16:05 267272 ----a-w- c:\windows\system32\xactengine2_10.dll
2007-10-22 01:37 . 2007-07-05 13:36 17928 ----a-w- c:\windows\system32\X3DAudio1_2.dll
2007-10-12 13:14 . 2007-07-05 16:05 3734536 ----a-w- c:\windows\system32\d3dx9_36.dll
2007-10-12 13:14 . 2007-07-05 16:05 1374232 ----a-w- c:\windows\system32\D3DCompiler_36.dll
2007-10-02 07:56 . 2007-07-05 16:05 444776 ----a-w- c:\windows\system32\d3dx10_36.dll
2007-07-19 22:57 . 2007-07-05 16:05 267112 ----a-w- c:\windows\system32\xactengine2_9.dll
2007-07-19 16:14 . 2007-07-05 16:05 444776 ----a-w- c:\windows\system32\d3dx10_35.dll
2007-07-19 16:14 . 2007-07-05 16:05 1358192 ----a-w- c:\windows\system32\D3DCompiler_35.dll
2007-07-19 16:14 . 2007-07-05 16:05 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2007-07-05 15:15 . 2007-07-05 10:38 -------- d-----w- c:\program files\Winamp
2007-07-05 12:24 . 2007-07-05 10:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2007-07-05 11:13 . 2001-10-26 14:15 49492 ----a-w- c:\windows\system32\perfc015.dat
2007-07-05 11:13 . 2001-10-26 14:15 355486 ----a-w- c:\windows\system32\perfh015.dat
2007-07-05 11:12 . 2007-07-05 11:12 -------- d-----w- c:\documents and settings\dom\Dane aplikacji\Gadu-Gadu
2007-07-05 10:40 . 2007-07-05 10:40 -------- d-----w- c:\program files\Gadu-Gadu
2007-07-05 10:34 . 2007-07-05 10:34 315392 ----a-w- c:\windows\HideWin.exe
2007-07-05 10:34 . 2007-07-05 10:34 -------- d-----w- c:\program files\Common Files\InstallShield
2007-07-05 10:34 . 2007-07-05 10:34 -------- d-----w- c:\program files\AMD
2007-07-05 10:34 . 2007-07-05 10:34 -------- d-----w- c:\documents and settings\dom\Dane aplikacji\InstallShield
2007-07-05 10:01 . 2007-07-05 10:01 -------- d-----w- c:\program files\microsoft frontpage
2007-07-05 10:00 . 2007-07-05 10:00 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2007-07-05 09:59 . 2007-07-05 09:59 -------- d-----w- c:\program files\Usługi online
2007-07-05 09:58 . 2007-07-05 09:58 21856 ----a-w- c:\windows\system32\emptyregdb.dat
2007-05-31 17:30 . 2007-07-05 13:36 266088 ----a-w- c:\windows\system32\xactengine2_8.dll
2007-05-16 14:45 . 2007-07-05 13:36 443752 ----a-w- c:\windows\system32\d3dx10_34.dll
2007-05-16 14:45 . 2007-07-05 13:36 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll
2007-05-16 14:45 . 2007-07-05 13:36 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-25 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-25 86016]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 258048]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-06-25 1712128]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-04-10 16861184]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\nwiz.exe"=
"c:\\WINDOWS\\RTHDCPL.EXE"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\PowerISO\\PWRISOVM.EXE"=
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\rhpr.sys --> c:\windows\system32\drivers\rhpr.sys [?]
S3 sdAuxService;Spyware Doctor Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [2007-07-05 708424]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\g:\ntglm7x.sys --> g:\NTGLM7X.sys [?]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKLM-Run-UnlockerAssistant - c:\program files\Unlocker\UnlockerAssistant.exe
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://interia.pl/
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-07 13:23
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2007-07-07 13:24
ComboFix-quarantined-files.txt 2007-07-07 11:24
Przed: 44 067 516 416 bajtów wolnych
Po: 44 858 167 296 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
186
/code]