
- Kod: Zaznacz wszystko
ComboFix 08-10-19.04 - Dawid 2008-10-20 19:22:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.577 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\Dawid\Pulpit\Nowy folder\ComboFix.exe
* Utworzono nowy punkt przywracania
[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9PLUGIN.DLL
C:\Program Files\myglobalsearch\bar\1.bin\MGSBAR.DLL
C:\Program Files\myglobalsearch\bar\1.bin\NPMYGLSH.DLL
C:\Program Files\myglobalsearch\bar\Cache\[u]0[/u]0232706
C:\Program Files\myglobalsearch\bar\Cache\[u]0[/u]02572EA.bin
C:\Program Files\myglobalsearch\bar\Cache\[u]0[/u]0257589.bin
C:\Program Files\myglobalsearch\bar\Cache\[u]0[/u]025777D.bin
C:\Program Files\myglobalsearch\bar\Cache\files.ini
C:\Program Files\myglobalsearch\bar\History\search
C:\Program Files\myglobalsearch\bar\Settings\prevcfg.htm
C:\v0s.cmd
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
D:\Autorun.inf
D:\v0s.cmd
G:\Autorun.inf
G:\v0s.cmd
H:\Autorun.inf
H:\v0s.cmd
.
((((((((((((((((((((((((( Pliki utworzone od 2008-09-20 do 2008-10-20 )))))))))))))))))))))))))))))))
.
2008-10-05 13:18 . 2008-10-05 13:18 94,208 --a------ C:\WINDOWS\DIIUnin.exe
2008-10-05 13:18 . 2008-10-05 13:23 28,864 --a------ C:\WINDOWS\DIIUnin.dat
2008-10-05 13:18 . 2008-10-05 13:18 2,829 --a------ C:\WINDOWS\DIIUnin.pif
2008-09-21 16:46 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-09-21 16:46 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-09-21 16:46 . 2006-11-30 15:11 18,704 -ra------ C:\WINDOWS\system32\drivers\se46nd5.sys
2008-09-21 16:45 . 2008-09-21 16:45 <DIR> d-------- C:\Documents and Settings\Dawid\Dane aplikacji\Teleca
2008-09-21 16:45 . 2006-11-30 15:11 97,088 -ra------ C:\WINDOWS\system32\drivers\se46mdm.sys
2008-09-21 16:45 . 2006-11-30 15:11 90,800 -ra------ C:\WINDOWS\system32\drivers\se46unic.sys
2008-09-21 16:45 . 2006-11-30 15:11 88,624 -ra------ C:\WINDOWS\system32\drivers\se46mgmt.sys
2008-09-21 16:45 . 2006-11-30 15:11 86,432 -ra------ C:\WINDOWS\system32\drivers\se46obex.sys
2008-09-21 16:45 . 2006-11-30 15:11 9,360 -ra------ C:\WINDOWS\system32\drivers\se46mdfl.sys
2008-09-21 16:45 . 2006-11-30 15:11 6,240 -ra------ C:\WINDOWS\system32\drivers\se46cmnt.sys
2008-09-21 16:45 . 2006-11-30 15:11 6,240 -ra------ C:\WINDOWS\system32\drivers\se46cm.sys
2008-09-21 16:45 . 2006-11-30 15:11 4,128 -ra------ C:\WINDOWS\system32\drivers\se46cr.sys
2008-09-21 16:44 . 2008-09-21 16:44 <DIR> d-------- C:\Documents and Settings\Dawid\Dane aplikacji\Sony Ericsson
2008-09-21 16:42 . 2008-09-21 23:43 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-09-21 16:41 . 2008-09-21 23:44 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2008-09-21 16:38 . 2006-11-30 16:11 61,536 -ra------ C:\WINDOWS\system32\drivers\se46bus.sys
2008-09-21 16:38 . 2006-11-30 16:11 5,872 -ra------ C:\WINDOWS\system32\drivers\se46whnt.sys
2008-09-21 16:38 . 2006-11-30 16:11 5,872 -ra------ C:\WINDOWS\system32\drivers\se46wh.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-20 14:25 --------- d-----w C:\Program Files\Kalendarz XP
2008-10-20 11:13 --------- d-----w C:\Program Files\AIMP2
2008-09-07 21:49 --------- d-----w C:\Program Files\Debugging Tools for Windows
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-24 11:27 --------- d-----w C:\Program Files\Winamp
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 167368]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-24 786521]
"ACU"="C:\Program Files\Atheros\ACU.exe" [2006-11-17 348249]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2007-09-24 110592]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-26 161328]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"SkyTel"="SkyTel.EXE" [2006-05-16 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
C:\Documents and Settings\Dawid\Menu Start\Programy\Autostart\
CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-09-29 49152]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-12-11 113664]
Kalendarz XP.lnk - C:\Program Files\Kalendarz XP\Kalendarz.exe [2007-11-27 882176]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\[u]0[/u]]
Source= D:\zdjęcia\Zdj_cie000.jpg
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\GokaDCek\\GokaDCek.exe"=
"H:\\gry\\fifa 2007\\fifa07.exe"=
"C:\\WINDOWS\\system32\\winver.exe"=
"H:\\gry\\fm08\\fm.exe"=
"C:\\Program Files\\Synapse\\synapse.exe"=
"C:\\Program Files\\WebServ\\apache2\\bin\\WebServ(apache).exe"=
"C:\\Program Files\\WebServ\\mysql\\bin\\WebServ(mysqld).exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;C:\WINDOWS\System32\StkCSrv.exe [2007-10-21 24576]
R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\WINDOWS\ATK0100\ASNDIS5.SYS [2007-09-24 16269]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;C:\WINDOWS\system32\Drivers\StkCMini.sys [2007-10-21 1245056]
R3 WSIMD;wsimd Service;C:\WINDOWS\system32\DRIVERS\wsimd.sys [2006-07-20 54432]
S3 RTSTOR;USB Mass Stroage Device;C:\WINDOWS\system32\drivers\RTSTOR.SYS [ ]
S3 se46bus;Sony Ericsson Device 070 driver (WDM);C:\WINDOWS\system32\DRIVERS\se46bus.sys [2006-11-30 61536]
S3 se46mdfl;Sony Ericsson Device 070 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\se46mdfl.sys [2006-11-30 9360]
S3 se46mdm;Sony Ericsson Device 070 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\se46mdm.sys [2006-11-30 97088]
S3 se46mgmt;Sony Ericsson Device 070 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\se46mgmt.sys [2006-11-30 88624]
S3 se46nd5;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (NDIS);C:\WINDOWS\system32\DRIVERS\se46nd5.sys [2006-11-30 18704]
S3 se46obex;Sony Ericsson Device 070 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\se46obex.sys [2006-11-30 86432]
S3 se46unic;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (WDM);C:\WINDOWS\system32\DRIVERS\se46unic.sys [2006-11-30 90800]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{444a0556-6a78-11dc-919f-001bfcf39a9d}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{444a0557-6a78-11dc-919f-001bfcf39a9d}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0694eaa-75c5-11dc-91c5-0015af30c551}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\Dawid\Dane aplikacji\Mozilla\Firefox\Profiles\hyydb9nw.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.onet.pl
FF -: plugin - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.0_03\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.0_03\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.0_03\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.0_03\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.0_03\bin\NPJPI140_03.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.0_03\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npOggX.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-20 19:25:29
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
.
**************************************************************************
.
Czas ukończenia: 2008-10-20 19:27:57 - komputer został uruchomiony ponownie [Dawid]
ComboFix-quarantined-files.txt 2008-10-20 17:27:53
Przed: 6 718 136 320 bajtów wolnych
Po: 7,008,329,728 bajtów wolnych
179 --- E O F --- 2008-10-15 10:44:49