1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154.
155.
156.
157.
158.
159.
160.
161.
162.
163.
164.
165.
166.
167.
168.
169.
170.
171.
172.
173.
174.
175.
176.
177.
178.
179.
180.
181.
182.
183.
184.
185.
186.
187.
188.
189.
190.
191.
192.
193.
194.
195.
196.
197.
198.
199.
200.
201.
202.
203.
204.
205.
206.
207.
208.
209.
210.
211.
212.
213.
214.
215.
216.
217.
218.
219.
220.
221.
222.
223.
224.
225.
226.
227.
228.
229.
230.
231.
232.
233.
234.
235.
236.
237.
238.
239.
240.
241.
242.
243.
244.
245.
246.
247.
248.
249.
250.
251.
252.
253. | ComboFix 08-10-11.02 - Marek 2008-10-12 13:08:43.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1543 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\Marek\Moje dokumenty\Pobrane pliki\ComboFix.exe
Użyto następujących komend :: C:\Documents and Settings\Marek\Moje dokumenty\Pobrane pliki\CFScript.txt
* Utworzono nowy punkt przywracania
[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
FILE ::
C:\WINDOWS\system32\iccylokg.ini
C:\WINDOWS\system32\qxsvksmu.dll
C:\WINDOWS\system32\TmpA5804109
C:\WINDOWS\system32\urqomnfe.dll.ren
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
C:\WINDOWS\system32\iccylokg.ini
C:\WINDOWS\system32\TmpA5804109
C:\WINDOWS\system32\urqomnfe.dll.ren
.
((((((((((((((((((((((((( Pliki utworzone od 2008-09-12 do 2008-10-12 )))))))))))))))))))))))))))))))
.
2008-10-12 10:38 . 2008-10-12 10:38 <DIR> dr------- C:\Documents and Settings\Administrator\Moje dokumenty
2008-10-12 09:56 . 2008-10-12 09:56 <DIR> d-------- C:\WINDOWS\ERUNT
2008-10-12 09:56 . 2008-10-12 13:09 <DIR> d--h----- C:\Documents and Settings\Administrator\Ustawienia lokalne
2008-10-12 09:56 . 2008-10-12 09:56 <DIR> dr------- C:\Documents and Settings\Administrator\Ulubione
2008-10-12 09:56 . 2006-09-11 19:13 <DIR> d--h----- C:\Documents and Settings\Administrator\Szablony
2008-10-12 09:56 . 2008-10-12 09:56 <DIR> d-------- C:\Documents and Settings\Administrator\Pulpit
2008-10-12 09:56 . 2006-09-11 21:08 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Start
2008-10-12 09:56 . 2006-09-11 21:08 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dane aplikacji
2008-10-12 09:56 . 2008-10-12 10:38 <DIR> d-------- C:\Documents and Settings\Administrator
2008-10-12 09:54 . 2008-10-12 10:01 <DIR> d-------- C:\SDFix
2008-10-11 22:06 . 2008-10-11 22:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-11 17:14 . 2008-10-11 17:14 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-10-11 14:25 . 2008-10-12 13:10 <DIR> d-------- C:\Program Files\cFosSpeed
2008-10-11 14:25 . 2008-02-12 15:16 717,016 -ra------ C:\WINDOWS\system32\drivers\cfosspeed.sys
2008-10-11 14:25 . 2008-02-12 15:16 285,912 --a------ C:\WINDOWS\system32\cfosspeed.dll
2008-10-11 13:07 . 2008-10-11 13:07 <DIR> d-------- C:\Program Files\8-8_xp32_dd_67975
2008-10-10 23:40 . 2008-10-10 23:40 <DIR> d-------- C:\Program Files\Gadu-Gadu
2008-10-10 19:26 . 2008-10-10 19:27 <DIR> d-------- C:\Program Files\WinClamAVShield
2008-10-10 19:26 . 2008-10-10 20:16 <DIR> d-------- C:\Documents and Settings\Marek\Dane aplikacji\Spyware Terminator
2008-10-09 21:45 . 2008-10-09 21:48 <DIR> d-------- C:\Program Files\HackCleaner
2008-10-09 21:06 . 2008-10-09 21:06 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\SUPERAntiSpyware.com
2008-09-29 19:01 . 2008-09-29 19:01 <DIR> d-------- C:\Documents and Settings\Marek\Dane aplikacji\Disney Interactive Studios
2008-09-24 17:10 . 2008-10-12 12:55 5,974,560 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-24 17:10 . 2008-10-12 12:55 860,192 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-24 17:10 . 2008-10-12 12:55 49,852 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-24 17:10 . 2008-10-12 12:55 5,068 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-24 17:05 . 2008-10-12 12:57 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-09-24 14:01 . 2008-10-06 16:49 <DIR> d-------- C:\WINDOWS\Logs
2008-09-21 14:55 . 2008-09-21 14:55 <DIR> d-------- C:\Documents and Settings\lol\Dane aplikacji\DivX
2008-09-15 15:15 . 2008-09-15 15:15 919 --a------ C:\WINDOWS\GTA-SA_Trn_Settings.ini
2008-09-15 15:05 . 2008-09-22 21:50 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-15 15:05 . 2008-09-15 15:05 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-12 10:54 --------- d-----w C:\Documents and Settings\Marek\Dane aplikacji\uTorrent
2008-10-11 11:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-11 08:29 --------- d-----w C:\Documents and Settings\Marek\Dane aplikacji\Gadu-Gadu
2008-10-10 21:38 --------- d-----w C:\Documents and Settings\Marek\Dane aplikacji\Nowe Gadu-Gadu
2008-10-10 18:16 --------- d-----w C:\Program Files\Spyware Terminator
2008-10-10 18:16 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Spyware Terminator
2008-10-10 17:26 141,312 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-10-09 12:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-09 12:46 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-10-09 12:30 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\IconTweaker
2008-09-24 20:14 --------- d-----w C:\Program Files\SubEdit-Player
2008-09-24 12:08 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-09-22 19:49 --------- d-----w C:\Documents and Settings\Marek\Dane aplikacji\Ableton
2008-09-18 16:21 1,228 ----a-w C:\Documents and Settings\Marek\Dane aplikacji\wklnhst.dat
2008-09-07 08:17 --------- d-----w C:\Program Files\Digidesign
2008-09-02 17:21 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2008-08-23 08:39 81,920 ----a-w C:\Documents and Settings\Marek\Dane aplikacji\ezpinst.exe
2008-08-23 08:39 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-08-23 08:39 47,360 ----a-w C:\Documents and Settings\Marek\Dane aplikacji\pcouffin.sys
2008-08-23 08:39 --------- d-----w C:\Program Files\McFunSoft Video Capture Convert Burn Solution
2008-08-23 08:39 --------- d-----w C:\Documents and Settings\Marek\Dane aplikacji\Vso
2008-08-22 15:24 --------- d-----w C:\Program Files\u-he
2008-08-22 14:46 --------- d-----w C:\Program Files\Common Files\reFX
2008-08-20 09:52 --------- d-----w C:\Program Files\Sony Ericsson
2008-08-20 09:52 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-08-20 09:52 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Teleca
2008-08-20 09:52 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Sony Ericsson
2008-08-20 09:27 --------- d-----w C:\Documents and Settings\Marek\Dane aplikacji\Sony Ericsson
2008-08-16 15:35 --------- d-----w C:\Documents and Settings\Marek\Dane aplikacji\DivX
2008-08-15 10:52 --------- d-----w C:\Documents and Settings\Marek\Dane aplikacji\Tlen.pl
2008-07-31 08:41 68,616 ----a-w C:\WINDOWS\system32\XAPOFX1_1.dll
2008-07-31 08:41 238,088 ----a-w C:\WINDOWS\system32\xactengine3_2.dll
2008-07-31 08:40 509,448 ----a-w C:\WINDOWS\system32\XAudio2_2.dll
2008-07-29 18:21 218,376 ----a-w C:\WINDOWS\system32\klogon.dll
2008-07-25 08:36 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 16:50 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-07-23 16:50 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-07-23 16:50 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-23 16:46 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-12 06:18 467,984 ----a-w C:\WINDOWS\system32\d3dx10_39.dll
2008-07-12 06:18 3,851,784 ----a-w C:\WINDOWS\system32\D3DX9_39.dll
2008-07-12 06:18 1,493,528 ----a-w C:\WINDOWS\system32\D3DCompiler_39.dll
2008-05-04 17:40 22,328 ----a-w C:\Documents and Settings\Marek\Dane aplikacji\PnkBstrK.sys
.
((((((((((((((((((((((((((((( snapshot@2008-10-11_22.20.12.90 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 14:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-10-12 07:56:53 372,736 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000001\NTUSER.DAT
+ 2008-10-12 07:56:53 8,192 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-08-07 14:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-10-12 07:56:50 372,736 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000001\NTUSER.DAT
+ 2008-10-12 07:56:50 8,192 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000002\UsrClass.dat
- 2008-10-11 20:18:26 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-10-12 08:44:00 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-10-11 20:18:26 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
+ 2008-10-12 08:44:00 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
- 2008-10-11 20:18:26 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-12 08:44:00 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
"SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 557056]
"Google Update"="C:\Documents and Settings\Marek\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" [2008-10-08 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 86016]
"Media Codec Update Service"="C:\Program Files\Essentials Codec Pack\update.exe" [2007-04-08 303104]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"cFosSpeed"="C:\Program Files\cFosSpeed\cFosSpeed.exe" [2008-02-12 863448]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-07-29 206088]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 C:\WINDOWS\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
C:\Documents and Settings\Marek\Menu Start\Programy\Autostart\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-02-28 3450608]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-28 113664]
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-04-27 1205840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 00:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Marek^Menu Start^Programy^Autostart^WinFlip.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 06:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Realtime Audio Engine]
--a------ 2005-01-20 13:02 53248 C:\WINDOWS\system32\MMRTKRNL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\gry\\Counter strike 1.6\\hl.exe"=
"D:\\gry\\Counter strike 1.6\\hltv.exe"=
"D:\\gry\\Valve\\hl.exe"=
"D:\\gry\\Valve\\hltv.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"D:\\gry\\Call of duty 4\\iw3mp.exe"=
"C:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Polish\\setup.exe"=
"D:\\gry\\Stronghold legends\\StrongholdLegends.exe"=
"C:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\Polish\\setup.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-10-10 141312]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2007-01-04 104344]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2007-01-04 69656]
S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\WINDOWS\system32\regedt32.exe [2001-10-26 3584]
.
Zawartość folderu 'Zaplanowane zadania'
2008-10-12 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\Marek\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2008-10-08 20:10]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-12 13:10:03
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\C:\DOCUME~1\Marek\USTAWI~1\Temp\ASFWHide"
.
Czas ukończenia: 2008-10-12 13:10:45
ComboFix-quarantined-files.txt 2008-10-12 11:10:42
ComboFix2.txt 2008-10-12 08:47:05
ComboFix3.txt 2008-10-11 20:20:37
Przed: 35 146 059 776 bajtów wolnych
Po: 35,133,042,688 bajtów wolnych
214 --- E O F --- 2008-04-16 22:15:21
|