

- Kod: Zaznacz wszystko
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.1014.400 [GMT 1:00]
Uruchomiony z: c:\documents and settings\DOM\Pulpit\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Utworzono nowy punkt przywracania
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
c:\windows\system32\45UR612k.exe.a_a
c:\windows\system32\msxml71.dll
c:\windows\system32\x264vfw.dll.
((((((((((((((((((((((((( Pliki utworzone od 2009-02-23 do 2009-03-23 )))))))))))))))))))))))))))))))
2009-03-22 11:43 . 2009-03-22 11:43 <DIR> d-------- c:\program files\SAGEM
2009-03-22 11:33 . 2002-12-09 18:24 49,152 --a------ c:\windows\system32\WooDial2000.dll
2009-03-22 11:33 . 2002-12-09 18:24 48,128 --a------ c:\windows\system32\SMMSCRPT.DLL
2009-03-22 11:33 . 2002-12-09 18:24 5,632 --a------ c:\windows\system32\SMMSETUP.DLL
2009-03-22 11:31 . 2009-03-22 11:43 479 --a------ c:\windows\adiras.ini
2009-03-22 10:26 . 2009-03-22 11:38 <DIR> d-------- c:\program files\Wanadoo
2009-03-22 10:26 . 2003-03-04 10:26 9,728 --a------ c:\windows\system32\rnaph.dll
2009-03-20 11:01 . 2009-03-20 11:01 <DIR> d-------- c:\program files\Common Files\IPSPI
2009-03-19 07:34 . 2009-03-19 07:34 <DIR> d-------- c:\program files\A4Tech
2009-03-18 17:31 . 2009-03-18 17:31 <DIR> d-------- c:\program files\CDex_151
2009-03-17 09:06 . 2009-03-19 14:24 <DIR> d-------- c:\program files\Innovative Solutions
2009-03-16 17:40 . 2007-07-03 16:58 106,792 --a------ c:\windows\system32\drivers\sscdmdm.sys
2009-03-16 17:40 . 2007-07-03 16:54 80,552 --a------ c:\windows\system32\drivers\sscdbus.sys
2009-03-16 17:40 . 2007-07-03 16:57 11,944 --a------ c:\windows\system32\drivers\sscdmdfl.sys
2009-03-16 17:40 . 2007-07-03 17:00 9,256 --a------ c:\windows\system32\drivers\sscdwhnt.sys
2009-03-16 17:40 . 2007-07-03 17:00 9,256 --a------ c:\windows\system32\drivers\sscdwh.sys
2009-03-16 17:40 . 2007-07-03 16:56 9,256 --a------ c:\windows\system32\drivers\sscdcmnt.sys
2009-03-16 17:40 . 2007-07-03 16:56 9,256 --a------ c:\windows\system32\drivers\sscdcm.sys
2009-03-15 10:32 . 2009-03-15 10:32 <DIR> d-------- c:\program files\Qwerty - Nauka Pisania
2009-03-13 20:49 . 2009-03-13 20:49 536,576 --a------ c:\windows\system32\splitter.ax
2009-03-13 20:48 . 2009-03-13 20:48 3,144,192 --a------ c:\windows\system32\ffdshow.ax
2009-03-13 20:48 . 2009-03-13 20:48 246,784 --a------ c:\windows\system32\dxr.dll
2009-03-13 20:46 . 2009-03-13 20:46 1,388,966 --a------ c:\windows\system32\ffmpegmt.dll
2009-03-13 20:45 . 2009-03-13 20:45 557,451 --a------ c:\windows\system32\libmplayer.dll
2009-03-13 20:44 . 2009-03-13 20:44 4,421,889 --a------ c:\windows\system32\libavcodec.dll
2009-03-13 15:30 . 2009-03-15 22:56 <DIR> d-------- c:\program files\Unlocker
2009-03-13 10:34 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-03-13 10:34 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-03-13 10:34 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-03-12 14:39 . 2009-03-12 16:50 <DIR> d-------- c:\documents and settings\DOM\Tracing
2009-03-12 14:11 . 2009-03-12 14:11 <DIR> d-------- c:\program files\Common Files\Windows Live
2009-03-11 20:44 . 2009-03-11 21:03 <DIR> d-------- c:\program files\MySpace
2009-03-11 20:44 . 2009-03-11 20:44 <DIR> d-------- c:\documents and settings\DOM\Dane aplikacji\MySpace
2009-03-11 11:03 . 2009-03-11 11:03 <DIR> d-------- c:\documents and settings\DOM\Dane aplikacji\Broad Intelligence
2009-03-11 10:53 . 2009-03-11 10:53 <DIR> d-------- c:\documents and settings\DOM\Dane aplikacji\OpenCandy
2009-03-11 10:52 . 2009-03-22 20:10 <DIR> d-------- c:\program files\MediaCoder
2009-03-11 10:06 . 2009-03-18 09:56 <DIR> d-------- c:\program files\Winamp
2009-03-10 11:17 . 2009-03-10 13:55 <DIR> d-------- c:\program files\ALLPlayer
2009-03-10 10:23 . 2009-03-10 10:23 795,648 --a------ c:\windows\system32\xvidcore.dll
2009-03-10 10:23 . 2009-03-10 10:23 487,936 --a------ c:\windows\system32\madFlac.ax
2009-03-10 10:23 . 2009-03-10 10:23 130,048 --a------ c:\windows\system32\xvidvfw.dll
2009-03-10 10:23 . 2009-03-10 10:23 118,784 --a------ c:\windows\system32\ac3acm.acm
2009-03-10 10:22 . 2009-03-10 10:22 901,120 --a------ c:\windows\system32\MpaDecFilter.ax
2009-03-10 10:22 . 2009-03-10 10:22 688,128 --a------ c:\windows\system32\mmamr.ax
2009-03-10 10:22 . 2009-03-10 10:22 348,160 --a------ c:\windows\system32\MpaSplitter.ax
2009-03-10 10:22 . 2009-03-10 10:22 348,160 --a------ c:\windows\system32\CoreVorbis.ax
2009-03-10 10:22 . 2009-03-10 10:22 258,048 --a------ c:\windows\system32\libFLAC.dll
2009-03-10 10:21 . 2009-03-10 10:21 892,928 --a------ c:\windows\system32\iconv.dll
2009-03-10 10:21 . 2009-03-10 10:21 860,160 --a------ c:\windows\system32\lameACM.acm
2009-03-10 10:21 . 2009-03-10 10:21 675,840 --a------ c:\windows\system32\ac3filter.ax
2009-03-10 10:21 . 2009-03-10 10:21 177,152 --a------ c:\windows\system32\MonkeySource.ax
2009-03-10 10:20 . 2009-03-10 10:20 1,291,776 --a------ c:\windows\system32\quartzXP.dll
2009-03-10 10:20 . 2009-03-10 10:20 507,904 --a------ c:\windows\system32\MP4Splitter.ax
2009-03-10 10:20 . 2009-03-10 10:20 319,488 --a------ c:\windows\system32\CoreAAC.ax
2009-03-10 10:20 . 2009-03-13 20:48 163,840 --a------ c:\windows\system32\ts.dll
2009-03-10 10:20 . 2009-03-10 10:20 159,744 --a------ c:\windows\system32\mmfinfo.dll
2009-03-10 10:20 . 2009-03-13 20:48 148,480 --a------ c:\windows\system32\mkx.dll
2009-03-10 10:20 . 2009-03-13 20:48 141,312 --a------ c:\windows\system32\mp4.dll
2009-03-10 10:20 . 2009-03-13 20:48 120,832 --a------ c:\windows\system32\ogm.dll
2009-03-10 10:20 . 2009-03-13 20:48 108,032 --a------ c:\windows\system32\avi.dll
2009-03-10 10:20 . 2009-03-13 20:48 79,360 --a------ c:\windows\system32\mkzlib.dll
2009-03-10 10:20 . 2009-03-10 10:20 75,264 --a------ c:\windows\system32\MACDec.dll
2009-03-10 10:20 . 2009-03-10 10:20 23,552 --a------ c:\windows\system32\mkunicode.dll
2009-03-10 10:19 . 2009-03-13 20:45 145,081 --a------ c:\windows\system32\libmpeg2_ff.dll
2009-03-10 10:19 . 2009-03-13 20:46 547 --a------ c:\windows\system32\ffdshow.ax.manifest
2009-03-10 10:18 . 2009-03-13 20:42 98,304 --a------ c:\windows\system32\ff_wmv9.dll
2009-03-10 10:17 . 2009-03-13 20:42 486,400 --a------ c:\windows\system32\ff_libfaad2.dll
2009-03-10 10:17 . 2009-03-13 20:42 257,024 --a------ c:\windows\system32\ff_libdts.dll
2009-03-10 10:17 . 2009-03-13 20:42 183,296 --a------ c:\windows\system32\ff_samplerate.dll
2009-03-10 10:17 . 2009-03-13 20:42 178,688 --a------ c:\windows\system32\ff_libmad.dll
2009-03-10 10:17 . 2009-03-13 20:42 142,848 --a------ c:\windows\system32\ff_liba52.dll
2009-03-10 10:17 . 2009-03-13 20:42 113,152 --a------ c:\windows\system32\ff_unrar.dll
2009-03-10 10:16 . 2009-03-10 10:16 1,415,680 --a------ c:\windows\system32\WMV9VCM.dll
2009-03-10 10:16 . 2009-03-10 10:16 921,600 --a------ c:\windows\system32\vorbisenc.dll
2009-03-10 10:16 . 2009-03-10 10:16 237,568 --a------ c:\windows\system32\OggDS.dll
2009-03-10 10:16 . 2009-03-10 10:16 188,416 --a------ c:\windows\system32\vorbis.dll
2009-03-10 10:16 . 2009-03-10 10:16 45,056 --a------ c:\windows\system32\ogg.dll
2009-03-10 10:15 . 2009-03-10 10:15 873,888 --a------ c:\windows\system32\CLVSD.ax
2009-03-10 10:15 . 2009-03-10 10:15 729,088 --a------ c:\windows\system32\divxdec.ax
2009-03-10 10:15 . 2009-03-10 10:15 417,792 --a------ c:\windows\system32\FLVSplitter.ax
2009-03-10 10:15 . 2009-03-10 10:15 387,584 --a------ c:\windows\system32\MpegSplitter.ax
2009-03-10 10:15 . 2009-03-10 10:15 245,760 --a------ c:\windows\system32\mplvpx.dll
2009-03-10 10:15 . 2009-03-10 10:15 106,496 --a------ c:\windows\system32\lmpgspl.ax
2009-03-10 10:15 . 2009-03-10 10:15 94,208 --a------ c:\windows\system32\lmpgvd.ax
2009-03-10 10:14 . 2009-03-10 10:14 524,288 --a------ c:\windows\system32\DivXsm.exe
2009-03-10 10:14 . 2009-03-10 10:14 77,824 --a------ c:\windows\system32\xvid.ax
2009-03-10 10:14 . 2009-03-10 10:14 69,632 --a------ c:\windows\system32\divxconfig.exe
2009-03-10 10:14 . 2009-03-10 10:14 4,816 --a------ c:\windows\system32\divxsm.tlb
2009-03-09 12:48 . 2009-03-09 12:48 0 --a------ c:\windows\WinPM.INI
2009-03-09 12:47 . 2009-03-09 12:47 <DIR> d-------- c:\program files\Paragon Software
2009-03-09 12:47 . 2004-09-03 10:53 3,870,720 --a------ c:\windows\system32\qt-mt323.dll
2009-03-09 12:47 . 2003-10-07 18:08 6,656 --a------ c:\windows\system32\WnASPI32.dll
2009-03-09 03:00 . 2009-03-09 03:00 <DIR> d-------- c:\program files\MSXML 4.0
2009-03-07 18:25 . 2009-03-16 18:14 <DIR> d-------- c:\documents and settings\DOM\Dane aplikacji\Samsung
2009-03-07 16:56 . 2006-05-03 22:53 174,592 --a------ c:\windows\system32\framedyn.dll
2009-03-07 16:55 . 2009-03-16 17:57 5,632 --a------ c:\windows\system32\drivers\StarOpen.sys
2009-03-07 16:53 . 2009-03-16 17:40 <DIR> d-------- c:\windows\system32\Samsung_USB_Drivers
2009-03-07 16:53 . 2005-08-28 20:51 766 --a------ c:\windows\system32\Uninstall.ico
2009-03-06 14:57 . 2009-03-06 14:57 <DIR> d-------- c:\program files\Klawiatura
2009-03-06 14:50 . 2009-03-06 15:01 <DIR> d-------- c:\program files\Szybkie Pisanie
2009-03-02 14:44 . 2009-03-02 14:44 37,236 --ah----- c:\windows\system32\mlfcache.dat
2009-03-01 18:19 . 2009-03-23 20:14 2,206 --a------ c:\windows\system32\wpa.dbl.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))).
2009-03-23 19:14 --------- d-----w c:\documents and settings\DOM\Dane aplikacji\uTorrent
2009-03-23 18:59 --------- d-----w c:\documents and settings\DOM\Dane aplikacji\Skype
2009-03-23 18:48 --------- d-----w c:\documents and settings\DOM\Dane aplikacji\gtk-2.0
2009-03-22 22:01 --------- d-----w c:\documents and settings\DOM\Dane aplikacji\Winamp
2009-03-22 19:13 --------- d---a-w c:\documents and settings\All Users\Dane aplikacji\TEMP
2009-03-22 10:54 --------- d-----w c:\program files\Lx_cats
2009-03-22 10:43 22 ----a-w c:\windows\system32\drivers\adidsl.cfg
2009-03-22 10:43 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-21 15:08 --------- d-----w c:\program files\Odkurzacz
2009-03-19 19:31 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2009-03-19 13:18 --------- d-----w c:\program files\NAPI-PROJEKT
2009-03-19 12:22 --------- d-----w c:\documents and settings\DOM\Dane aplikacji\Thinstall
2009-03-19 09:20 --------- d-----w c:\program files\Google
2009-03-18 08:19 --------- d-----w c:\documents and settings\DOM\Dane aplikacji\U3
2009-03-16 16:39 --------- d-----w c:\program files\Samsung
2009-03-14 20:38 --------- d-----w c:\documents and settings\DOM\Dane aplikacji\TransEngPol41
2009-03-12 19:32 --------- d-----w c:\documents and settings\DOM\Dane aplikacji\skypePM
2009-03-12 19:02 --------- d-----w c:\program files\eMule
2009-03-12 18:59 --------- d-----w c:\program files\Nokia
2009-03-11 19:16 --------- d-----w c:\program files\uTorrent
2009-03-11 19:09 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Skype
2009-03-11 19:09 --------- d-----r c:\program files\Skype
2009-03-10 10:21 --------- d-----w c:\program files\Real Alternative
2009-03-10 07:32 --------- d-----w c:\documents and settings\DOM\Dane aplikacji\dvdcss
2009-03-03 12:18 --------- d-----w c:\program files\Common Files\Ahead
2009-03-03 12:18 --------- d-----w c:\program files\Ahead
2009-03-03 07:46 --------- d-----w c:\program files\PITy
2009-03-01 18:13 --------- d-----w c:\program files\IrfanView
2009-01-16 12:10 1,213,952 ----a-w c:\program files\BESTplayer.exe
2008-10-29 10:20 4,338,923 ----a-w c:\program files\Klawiatura_wozniak.exe
2008-04-10 13:20 720,482 ----a-w c:\program files\mxClock.exe
2008-04-02 13:19 32 ----a-w c:\documents and settings\All Users\Dane aplikacji\ezsid.dat
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))).
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41F21158-4211-4D32-9E02-D57B19661561}]
2009-01-14 17:54 444416 --a------ c:\progra~1\ALLPLA~1\REDTUB~1.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-03-02 65536]
"Paseczek"="c:\program files\Paseczek\Paseczek.exe" [2008-03-07 1616384]
"mxClock"="c:\program files\mxClock.exe" [2008-04-10 720482]
"Odkurzacz-MCD"="c:\program files\Odkurzacz\odk_mcd.exe" [2008-08-16 264704]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-24 401491]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2008-11-13 243072]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-03-01 270128]
"ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2008-11-24 869888]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-11 24095528]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [2008-08-04 488808]
"DriverMax"="c:\program files\Innovative Solutions\DriverMax\devices.exe" [2009-02-10 5391192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2003-10-31 192512]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-11-17 1077327]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2005-01-21 675840]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-29 53248]
"TOSHIBA Accessibility"="c:\program files\TOSHIBA\Accessibility\FnKeyHook.exe" [2004-12-07 24576]
"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-12-23 28672]
"SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-25 65536]
"Tvs"="c:\program files\TOSHIBA\Tvs\TvsTray.exe" [2004-11-12 73728]
"NDSTray.exe"="c:\program files\TOSHIBA\ConfigFree\NDSTray.exe" [2004-12-17 933888]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-01-14 122939]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-04-27 69632]
"lxcgmon.exe"="c:\program files\Lexmark 2300 Series\lxcgmon.exe" [2005-05-05 200704]
"EzPrint"="c:\program files\Lexmark 2300 Series\ezprint.exe" [2005-06-08 94208]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-05-03 299008]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-10-11 140568]
"CFSServ.exe"="c:\program files\TOSHIBA\ConfigFree\CFSServ.exe" [2004-12-18 548864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-08-01 98304]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-03-09 37888]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-10-12 2611312]
"TFncKy"="c:\program files\TOSHIBA\TOSHIBA Controls\TFncKy.exe" [2005-03-29 118784]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-10-12 905992]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2007-02-10 188416]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-28 c:\windows\agrsmmsg.exe]
"Zooming"="ZoomingHook.exe" [2004-07-14 c:\windows\system32\ZoomingHook.exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-02-16 c:\windows\system32\TCtrlIOHook.exe]
"TPSMain"="TPSMain.exe" [2005-01-21 c:\windows\system32\TPSMain.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\DOM\Menu Start\Programy\Autostart\
Tworzenie wycink˘w ekranu i uruchamianie programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2009-03-22 962667]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"Msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"msacm.mpegacm"= mpegacm.acm
"msacm.ulmp3acm"= ulmp3acm.acm
"MSACM.CEGSM"= mobilev.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\lxcgcoms.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\TOSHIBA\\ConfigFree\\CFXFER.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"c:\\Documents and Settings\\DOM\\Dane aplikacji\\Thinstall\\O&O Defrag Professional\\40000014e00002i\\oodag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [2008-07-31 20616]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-02-20 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-02-20 472320]
R3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\drivers\Amps2prt.sys [2007-02-09 14336]
S2 gupdate1c9a720ddcbb49b;Google Update Service (gupdate1c9a720ddcbb49b);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-17 133104]
S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [2008-12-07 30088]
S3 CrystalSysInfo;CrystalSysInfo;\??\c:\program files\MediaCoder\SysInfo.sys --> c:\program files\MediaCoder\SysInfo.sys [?]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2008-07-02 26248]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b9d6038-00bc-11dd-96ca-000fb08d59f6}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a.
Zawartość folderu 'Zaplanowane zadania'
2009-03-23 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-17 17:53].
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-ALLPasswordManager - c:\program files\MarBit\ALLPassword Manager\ALLPasswordManager.exe
HKLM-Run-SmoothView - c:\program files\TOSHIBA\Program narzędziowy TOSHIBA Zooming Utility\SmoothView.exe.
------- Skan uzupełniający -------
.uStart Page = hxxp://mystart.magentic.com/english/
uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe"
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {851C5EFD-4F84-42FF-B075-8DD4C9F39F40} = 194.204.152.34 217.98.63.164
FF - ProfilePath - c:\documents and settings\DOM\Dane aplikacji\Mozilla\Firefox\Profiles\p6n0hpzx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.pajacyk.pl
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\documents and settings\DOM\Dane aplikacji\Mozilla\Firefox\Profiles\p6n0hpzx.default\extensions\trenpl4ff@kompas.info.pl\components\trenpl4ff.dll
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJPI150.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPOJI610.dll
---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 1000000
FF - user.js: nglayout.initialpaint.delay - 600
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-23 20:14:17
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'lsass.exe'(932)
c:\windows\system32\relog_ap.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\TOSHIBA\Program narzc:\program files\TOSHIBA\Tvs\TvsTray.exe
c:\windows\system32\TPSBattM.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\progra~1\Magentic\bin\MgApp.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\UTSCSI.EXE
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\windows\system32\lxcgcoms.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Czas ukończenia: 2009-03-23 20:18:08 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-03-23 19:17:55
Przed: 20˙201˙148˙416 bajt˘w wolnych
Po: 20,338,282,496 bajt˘w wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
331 --- E O F --- 2009-03-15 08:55:58
- Kod: Zaznacz wszystko