
ComboFix 09-02-08.02 - istari 2009-02-09 18:38:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.511.300 [GMT 1:00]
Uruchomiony z: c:\documents and settings\istari\Pulpit\ComboFix.exe
Użyto następujących komend :: c:\documents and settings\istari\Pulpit\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090205-1] *On-access scanning disabled* (Updated)
FW: ActiveArmor Firewall *disabled*
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\1utbfd.bat
C:\autorun.inf
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds1.dll
c:\windows\system32\olhrwef.exe
D:\1utbfd.bat
D:\Autorun.inf
D:\m0vnonh.bat
.
((((((((((((((((((((((((( Pliki utworzone od 2009-01-09 do 2009-02-09 )))))))))))))))))))))))))))))))
.
2009-02-09 18:40 . 2009-02-09 18:40 <DIR> d-------- c:\windows\system32\xircom
2009-02-09 18:40 . 2009-02-09 18:40 <DIR> d-------- c:\programy\microsoft frontpage
2009-02-09 18:40 . 2009-02-09 18:40 53,248 --a------ c:\temp\catchme.dll
2009-02-09 18:31 . 2009-02-09 18:31 <DIR> d-------- c:\documents and settings\istari\Dane aplikacji\Gadu-Gadu
2009-02-09 18:17 . 2009-02-09 18:17 <DIR> d-------- c:\programy\SubEdit-Player
2009-02-09 18:17 . 2009-02-09 18:17 <DIR> d-------- c:\programy\CCleaner
2009-02-09 18:17 . 2009-02-09 18:31 <DIR> d-------- c:\documents and settings\istari\Gadu-Gadu
2009-02-09 18:16 . 2009-02-09 18:16 <DIR> d-------- c:\programy\Gadu-Gadu
2009-02-09 18:09 . 2004-05-02 09:47 23,040 -ra------ c:\windows\system32\drivers\GVCplDrv.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-09 17:20 --------- d-----w c:\programy\Common Files\Adobe
2009-02-09 16:48 --------- d--h--w c:\programy\InstallShield Installation Information
2009-02-09 16:47 --------- d-----w c:\programy\DIFX
2009-02-09 16:42 --------- d-----w c:\programy\NVIDIA Corporation
2009-02-09 16:42 --------- d-----w c:\programy\Common Files\InstallShield
2009-02-09 16:32 --------- d-----w c:\documents and settings\istari\Dane aplikacji\InterTrust
2009-02-09 16:20 --------- d-----w c:\programy\Alwil Software
2009-02-09 16:07 --------- d-----w c:\programy\Usługi online
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="c:\programy\Gadu-Gadu\gg.exe" [2007-11-14 2131392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\programy\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-12 7626752]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-12 86016]
"nwiz"="nwiz.exe" [2006-07-12 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2004-08-04 c:\windows\system32\advpack.dll]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-02-09 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-02-09 20560]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-cdoosoft - c:\windows\system32\olhrwef.exe
.
------- Skan uzupełniający -------
.
FF - ProfilePath - c:\documents and settings\istari\Dane aplikacji\Mozilla\Firefox\Profiles\csbsgkpt.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-09 18:40:28
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\programy\Alwil Software\Avast4\aswUpdSv.exe
c:\programy\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\rundll32.exe
c:\programy\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\programy\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\programy\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\windows\system32\nvsvc32.exe
c:\programy\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Czas ukończenia: 2009-02-09 18:41:10 - komputer został uruchomiony ponownie [istari]
ComboFix-quarantined-files.txt 2009-02-09 17:41:07
Przed: 77 883 142 144 bajtów wolnych
Po: 77,886,701,568 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noexecute=alwaysoff /usepmtimer
114