
- Kod: Zaznacz wszystko
ComboFix 09-07-02.02 - Właściciel 2009-07-03 15:01.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.447.219 [GMT 2:00]
Uruchomiony z: c:\documents and settings\Właściciel\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2009-06-03 do 2009-07-03 )))))))))))))))))))))))))))))))
.
2009-07-01 18:40 . 2009-07-01 18:40 232 ----a-w- C:\delunins.bat
2009-07-01 14:53 . 2009-07-01 14:53 -------- d-----w- c:\windows\ERUNT
2009-07-01 14:34 . 2009-07-01 14:34 -------- d-----w- c:\program files\DiskTrix
2009-06-30 16:33 . 2009-06-30 16:33 -------- d-----w- c:\program files\Trend Micro
2009-06-29 09:21 . 2009-06-29 09:21 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Malwarebytes
2009-06-27 10:20 . 2009-06-27 10:27 -------- d-----w- c:\program files\NetPeeker
2009-06-27 10:20 . 2009-06-27 10:20 246864 ----a-w- c:\windows\system32\drivers\NetPeeker.sys
2009-06-15 09:00 . 2009-06-15 09:00 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-06-13 07:22 . 2009-04-30 21:17 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-13 07:22 . 2009-04-30 21:17 1985024 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-06-13 07:22 . 2009-04-30 21:17 11064832 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-06-13 07:22 . 2009-04-30 21:17 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-13 07:22 . 2009-06-13 07:22 -------- d-----w- c:\windows\ie8updates
2009-06-13 07:22 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-06-13 07:21 . 2009-06-13 07:22 -------- dc-h--w- c:\windows\ie8
2009-06-09 19:56 . 2009-06-09 19:56 -------- d-----w- c:\documents and settings\Default User\Ustawienia lokalne\Dane aplikacji\Microsoft Help
2009-06-08 07:10 . 2009-06-30 09:33 77128 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-08 07:10 . 2009-06-29 09:34 84832 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-08 07:10 . 2009-06-29 09:34 246128 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-08 07:10 . 2009-06-29 09:34 40288 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-06 13:53 . 2009-06-06 13:53 -------- d-----w- c:\program files\MSXML 4.0
2009-06-05 11:07 . 2009-06-05 11:07 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Apple Computer
2009-06-05 10:57 . 2009-06-05 10:57 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Cyberlink
2009-06-05 10:57 . 2006-06-04 13:48 82432 ----a-w- c:\windows\system32\msxml4r.dll
2009-06-05 10:57 . 2006-06-04 13:48 44544 ----a-w- c:\windows\system32\msxml4a.dll
2009-06-05 10:56 . 2006-06-04 13:48 89088 ------w- c:\windows\system32\atl71.dll
2009-06-05 10:56 . 2006-06-04 13:48 1047552 ------w- c:\windows\system32\MFC71u.dll
2009-06-05 10:56 . 2009-06-05 14:04 -------- d-----w- c:\program files\CyberLink
2009-06-05 10:56 . 2009-06-05 10:56 -------- d-----w- c:\program files\Digital Photo Navigator 1.5
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-03 13:05 . 2009-03-31 09:44 -------- d-----w- c:\program files\BitComet
2009-07-02 07:38 . 2009-05-05 16:49 -------- d-----w- c:\program files\SkanerOnline
2009-06-30 09:33 . 2009-06-22 09:33 376152 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-30 09:33 . 2009-06-22 09:33 146792 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-06-30 09:33 . 2009-06-22 09:33 624504 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-30 09:33 . 2009-06-22 09:33 628072 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-30 09:33 . 2009-06-22 09:33 2414408 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-30 09:33 . 2009-06-22 09:33 690512 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-30 09:33 . 2009-06-22 09:33 581464 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-30 09:33 . 2009-06-22 09:33 1090896 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-29 09:34 . 2009-06-22 09:33 25440 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-29 09:34 . 2009-06-22 09:33 169312 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-29 09:34 . 2009-06-22 09:33 348496 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-29 09:34 . 2009-06-22 09:33 298336 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-29 09:34 . 2009-06-22 09:33 1630560 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-29 09:34 . 2009-06-22 09:33 664424 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-29 07:38 . 2009-04-14 13:39 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Google Updater
2009-06-16 15:35 . 2009-03-31 10:43 -------- d-----w- c:\program files\Ganymede
2009-06-15 09:03 . 2009-03-30 17:43 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2009-06-13 07:30 . 2009-03-30 17:45 -------- d-----w- c:\program files\Microsoft Works
2009-06-13 07:24 . 2006-03-02 12:00 83660 ----a-w- c:\windows\system32\perfc015.dat
2009-06-13 07:24 . 2006-03-02 12:00 490284 ----a-w- c:\windows\system32\perfh015.dat
2009-06-08 07:10 . 2009-04-11 07:19 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-05 14:04 . 2009-03-30 14:50 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-03 13:41 . 2009-03-31 07:57 -------- d-----w- c:\program files\Nowe Gadu-Gadu
2009-06-01 14:39 . 2009-05-22 17:57 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-06-01 14:39 . 2009-06-01 14:39 -------- d-----w- c:\program files\LSoft Technologies
2009-05-29 13:45 . 2009-05-29 13:45 -------- d-----w- c:\program files\Ashampoo
2009-05-21 09:42 . 2009-05-21 09:42 -------- d-----w- c:\program files\QuickTime
2009-05-21 09:42 . 2009-05-21 09:42 -------- d-----w- c:\program files\Xilisoft
2009-05-16 12:18 . 2009-04-03 09:26 -------- d-----w- c:\program files\Google
2009-05-15 09:23 . 2009-05-15 09:15 -------- d-----w- c:\program files\Creative
2009-05-13 19:08 . 2009-05-13 14:14 -------- d-----w- c:\program files\NCH Software
2009-05-13 14:14 . 2009-05-13 14:14 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\NCH Software
2009-05-13 09:43 . 2009-05-13 09:43 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-13 05:06 . 2006-03-02 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:34 . 2006-03-02 12:00 347648 ----a-w- c:\windows\system32\localspl.dll
2009-04-25 10:16 . 2009-04-25 10:16 64160 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-04-19 19:51 . 2006-03-02 12:00 1847424 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:54 . 2006-03-02 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-09 19:00 . 2009-03-30 14:33 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-09 08:23 . 2009-04-09 08:23 21 --sh--w- C:\date.bin
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-31 86016]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-31 1683456]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-01-30 16116224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^Właściciel^Menu Start^Programy^Autostart^HDDlife.lnk]
path=c:\documents and settings\Właściciel\Menu Start\Programy\Autostart\HDDlife.lnk
backup=c:\windows\pss\HDDlife.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=2 (0x2)
"gupdate1c9bd06f8baf463"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Właściciel\\Pulpit\\BlueCafe\\BlueCafe.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Lib\\NMIndexStoreSvr.exe"=
"c:\\WINDOWS\\system32\\nwiz.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware\\AAWService.exe"=
"c:\\Program Files\\Java\\jre1.6.0_05\\bin\\jucheck.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware\\AAWTray.exe"=
"c:\\Program Files\\Google\\Update\\1.2.183.7\\GoogleCrashHandler.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\ComboFix\\NirCmdC.cfexe"=
"c:\\Documents and Settings\\All Users\\Dane aplikacji\\EPSON\\EPW!3 SSRP\\E_S40RP7.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20932:TCP"= 20932:TCP:BitComet 20932 TCP
"20932:UDP"= 20932:UDP:BitComet 20932 UDP
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-31 64160]
R1 NetPeeker;NetPeeker;c:\windows\system32\drivers\NetPeeker.sys [2009-06-27 246864]
R3 aic32p;aic32p;\??\c:\windows\system32\drivers\kipopl.sys --> c:\windows\system32\drivers\kipopl.sys [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 1090896]
S3 V0260VID;Live! Cam Vista IM;c:\windows\system32\drivers\V0260Vid.sys [2009-05-15 178913]
S4 gupdate1c9bd06f8baf463;Usługa Google Update (gupdate1c9bd06f8baf463);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 133104]
.
Zawartość folderu 'Zaplanowane zadania'
2009-06-30 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 09:33]
2009-07-03 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-14 13:39]
2009-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 13:43]
2009-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 13:43]
2009-07-03 c:\windows\Tasks\User_Feed_Synchronization-{E76B61F8-F171-44EA-9D24-53C588CA9C18}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.gazeta.pl/
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Pobierz wszystkie VIdeo za pomocą BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: Pobierz wszystko za pomocą BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Pobierz za pomocą BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
FF - ProfilePath - c:\documents and settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\n6q2o4wp.default\
FF - prefs.js: browser.startup.homepage - www.onet.pl
FF - component: c:\documents and settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\n6q2o4wp.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\platform\WINNT_x86-msvc\components\SSSLauncher.dll
FF - component: c:\documents and settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\n6q2o4wp.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npganymedenet.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-03 15:05
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\WACICI~1\USTAWI~1\Temp\ASFWHide"
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'explorer.exe'(3088)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll
c:\program files\Common Files\Ahead\Lib\MFC71U.DLL
c:\program files\Common Files\Ahead\Lib\BCGCBPRO800u.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Czas ukończenia: 2009-07-03 15:07
ComboFix-quarantined-files.txt 2009-07-03 13:07
Przed: 20 550 795 264 bajtów wolnych
Po: 20 591 849 472 bajtów wolnych
190 --- E O F --- 2009-06-15 09:03
Dodano Dzisiaj, 14:50:
Chyba coś nie tak zrobiłem i nie doszedł do Ciebie. Podłączyłem i już przesyłam
- Kod: Zaznacz wszystko
ComboFix 09-07-02.02 - Właściciel 2009-07-03 15:01.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.447.219 [GMT 2:00]
Uruchomiony z: c:\documents and settings\Właściciel\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2009-06-03 do 2009-07-03 )))))))))))))))))))))))))))))))
.
2009-07-01 18:40 . 2009-07-01 18:40 232 ----a-w- C:\delunins.bat
2009-07-01 14:53 . 2009-07-01 14:53 -------- d-----w- c:\windows\ERUNT
2009-07-01 14:34 . 2009-07-01 14:34 -------- d-----w- c:\program files\DiskTrix
2009-06-30 16:33 . 2009-06-30 16:33 -------- d-----w- c:\program files\Trend Micro
2009-06-29 09:21 . 2009-06-29 09:21 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Malwarebytes
2009-06-27 10:20 . 2009-06-27 10:27 -------- d-----w- c:\program files\NetPeeker
2009-06-27 10:20 . 2009-06-27 10:20 246864 ----a-w- c:\windows\system32\drivers\NetPeeker.sys
2009-06-15 09:00 . 2009-06-15 09:00 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-06-13 07:22 . 2009-04-30 21:17 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-13 07:22 . 2009-04-30 21:17 1985024 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-06-13 07:22 . 2009-04-30 21:17 11064832 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-06-13 07:22 . 2009-04-30 21:17 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-13 07:22 . 2009-06-13 07:22 -------- d-----w- c:\windows\ie8updates
2009-06-13 07:22 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-06-13 07:21 . 2009-06-13 07:22 -------- dc-h--w- c:\windows\ie8
2009-06-09 19:56 . 2009-06-09 19:56 -------- d-----w- c:\documents and settings\Default User\Ustawienia lokalne\Dane aplikacji\Microsoft Help
2009-06-08 07:10 . 2009-06-30 09:33 77128 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-08 07:10 . 2009-06-29 09:34 84832 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-08 07:10 . 2009-06-29 09:34 246128 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-08 07:10 . 2009-06-29 09:34 40288 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-06 13:53 . 2009-06-06 13:53 -------- d-----w- c:\program files\MSXML 4.0
2009-06-05 11:07 . 2009-06-05 11:07 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Apple Computer
2009-06-05 10:57 . 2009-06-05 10:57 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Cyberlink
2009-06-05 10:57 . 2006-06-04 13:48 82432 ----a-w- c:\windows\system32\msxml4r.dll
2009-06-05 10:57 . 2006-06-04 13:48 44544 ----a-w- c:\windows\system32\msxml4a.dll
2009-06-05 10:56 . 2006-06-04 13:48 89088 ------w- c:\windows\system32\atl71.dll
2009-06-05 10:56 . 2006-06-04 13:48 1047552 ------w- c:\windows\system32\MFC71u.dll
2009-06-05 10:56 . 2009-06-05 14:04 -------- d-----w- c:\program files\CyberLink
2009-06-05 10:56 . 2009-06-05 10:56 -------- d-----w- c:\program files\Digital Photo Navigator 1.5
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-03 13:05 . 2009-03-31 09:44 -------- d-----w- c:\program files\BitComet
2009-07-02 07:38 . 2009-05-05 16:49 -------- d-----w- c:\program files\SkanerOnline
2009-06-30 09:33 . 2009-06-22 09:33 376152 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-30 09:33 . 2009-06-22 09:33 146792 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-06-30 09:33 . 2009-06-22 09:33 624504 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-30 09:33 . 2009-06-22 09:33 628072 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-30 09:33 . 2009-06-22 09:33 2414408 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-30 09:33 . 2009-06-22 09:33 690512 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-30 09:33 . 2009-06-22 09:33 581464 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-30 09:33 . 2009-06-22 09:33 1090896 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-29 09:34 . 2009-06-22 09:33 25440 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-29 09:34 . 2009-06-22 09:33 169312 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-29 09:34 . 2009-06-22 09:33 348496 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-29 09:34 . 2009-06-22 09:33 298336 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-29 09:34 . 2009-06-22 09:33 1630560 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-29 09:34 . 2009-06-22 09:33 664424 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-29 07:38 . 2009-04-14 13:39 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Google Updater
2009-06-16 15:35 . 2009-03-31 10:43 -------- d-----w- c:\program files\Ganymede
2009-06-15 09:03 . 2009-03-30 17:43 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2009-06-13 07:30 . 2009-03-30 17:45 -------- d-----w- c:\program files\Microsoft Works
2009-06-13 07:24 . 2006-03-02 12:00 83660 ----a-w- c:\windows\system32\perfc015.dat
2009-06-13 07:24 . 2006-03-02 12:00 490284 ----a-w- c:\windows\system32\perfh015.dat
2009-06-08 07:10 . 2009-04-11 07:19 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-05 14:04 . 2009-03-30 14:50 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-03 13:41 . 2009-03-31 07:57 -------- d-----w- c:\program files\Nowe Gadu-Gadu
2009-06-01 14:39 . 2009-05-22 17:57 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-06-01 14:39 . 2009-06-01 14:39 -------- d-----w- c:\program files\LSoft Technologies
2009-05-29 13:45 . 2009-05-29 13:45 -------- d-----w- c:\program files\Ashampoo
2009-05-21 09:42 . 2009-05-21 09:42 -------- d-----w- c:\program files\QuickTime
2009-05-21 09:42 . 2009-05-21 09:42 -------- d-----w- c:\program files\Xilisoft
2009-05-16 12:18 . 2009-04-03 09:26 -------- d-----w- c:\program files\Google
2009-05-15 09:23 . 2009-05-15 09:15 -------- d-----w- c:\program files\Creative
2009-05-13 19:08 . 2009-05-13 14:14 -------- d-----w- c:\program files\NCH Software
2009-05-13 14:14 . 2009-05-13 14:14 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\NCH Software
2009-05-13 09:43 . 2009-05-13 09:43 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-13 05:06 . 2006-03-02 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:34 . 2006-03-02 12:00 347648 ----a-w- c:\windows\system32\localspl.dll
2009-04-25 10:16 . 2009-04-25 10:16 64160 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-04-19 19:51 . 2006-03-02 12:00 1847424 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:54 . 2006-03-02 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-09 19:00 . 2009-03-30 14:33 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-09 08:23 . 2009-04-09 08:23 21 --sh--w- C:\date.bin
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-31 86016]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-31 1683456]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-01-30 16116224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^Właściciel^Menu Start^Programy^Autostart^HDDlife.lnk]
path=c:\documents and settings\Właściciel\Menu Start\Programy\Autostart\HDDlife.lnk
backup=c:\windows\pss\HDDlife.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=2 (0x2)
"gupdate1c9bd06f8baf463"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Właściciel\\Pulpit\\BlueCafe\\BlueCafe.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Lib\\NMIndexStoreSvr.exe"=
"c:\\WINDOWS\\system32\\nwiz.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware\\AAWService.exe"=
"c:\\Program Files\\Java\\jre1.6.0_05\\bin\\jucheck.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware\\AAWTray.exe"=
"c:\\Program Files\\Google\\Update\\1.2.183.7\\GoogleCrashHandler.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\ComboFix\\NirCmdC.cfexe"=
"c:\\Documents and Settings\\All Users\\Dane aplikacji\\EPSON\\EPW!3 SSRP\\E_S40RP7.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20932:TCP"= 20932:TCP:BitComet 20932 TCP
"20932:UDP"= 20932:UDP:BitComet 20932 UDP
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-31 64160]
R1 NetPeeker;NetPeeker;c:\windows\system32\drivers\NetPeeker.sys [2009-06-27 246864]
R3 aic32p;aic32p;\??\c:\windows\system32\drivers\kipopl.sys --> c:\windows\system32\drivers\kipopl.sys [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 1090896]
S3 V0260VID;Live! Cam Vista IM;c:\windows\system32\drivers\V0260Vid.sys [2009-05-15 178913]
S4 gupdate1c9bd06f8baf463;Usługa Google Update (gupdate1c9bd06f8baf463);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 133104]
.
Zawartość folderu 'Zaplanowane zadania'
2009-06-30 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 09:33]
2009-07-03 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-14 13:39]
2009-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 13:43]
2009-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 13:43]
2009-07-03 c:\windows\Tasks\User_Feed_Synchronization-{E76B61F8-F171-44EA-9D24-53C588CA9C18}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.gazeta.pl/
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Pobierz wszystkie VIdeo za pomocą BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: Pobierz wszystko za pomocą BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Pobierz za pomocą BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
FF - ProfilePath - c:\documents and settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\n6q2o4wp.default\
FF - prefs.js: browser.startup.homepage - www.onet.pl
FF - component: c:\documents and settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\n6q2o4wp.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\platform\WINNT_x86-msvc\components\SSSLauncher.dll
FF - component: c:\documents and settings\Właściciel\Dane aplikacji\Mozilla\Firefox\Profiles\n6q2o4wp.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npganymedenet.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-03 15:05
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\WACICI~1\USTAWI~1\Temp\ASFWHide"
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'explorer.exe'(3088)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll
c:\program files\Common Files\Ahead\Lib\MFC71U.DLL
c:\program files\Common Files\Ahead\Lib\BCGCBPRO800u.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Czas ukończenia: 2009-07-03 15:07
ComboFix-quarantined-files.txt 2009-07-03 13:07
Przed: 20 550 795 264 bajtów wolnych
Po: 20 591 849 472 bajtów wolnych
190 --- E O F --- 2009-06-15 09:03
Ponawiam w takim razie pytanie, co mogło spowodować kłopoty a właściwie brak komunikacji z mojego kompa na inne poprzez otoczenie sieciowe? Czy to mógłby byc program do blokowania portów dla robactwa bodajże WWC coś tam coś tam...a może Combofix??