
- Kod: Zaznacz wszystko
ComboFix 08-09-15.02 - r0tfl 2008-09-16 16:06:36.3 - NTFSx86
Uruchomiony z: C:\Documents and Settings\r0tfl\Pulpit\ComboFix.exe
[color=red][b]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/b][/color]
.
((((((((((((((((((((((((( Pliki utworzone od 2008-08-16 do 2008-09-16 )))))))))))))))))))))))))))))))
.
2008-09-16 14:24 . 2007-03-08 01:51 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-09-16 14:24 . 2007-03-08 01:51 43,528 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-09-16 14:24 . 2007-03-08 01:51 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-16 14:24 . 2007-03-08 01:51 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-09-16 14:23 . 2008-09-16 14:50 <DIR> d-------- C:\Program Files\Winamp
2008-09-16 14:23 . 2008-09-16 14:51 <DIR> d-------- C:\Documents and Settings\r0tfl\Dane aplikacji\Winamp
2008-09-16 14:09 . 2008-09-16 14:56 151 --a------ C:\WINDOWS\system\cmicnfg.ini
2008-09-15 20:00 . 2008-09-15 20:00 <DIR> d-------- C:\Program Files\Auslogics
2008-09-13 17:26 . 2008-09-13 17:26 4 --a------ C:\WINDOWS\system32\proc-220146841.bin
2008-09-13 11:37 . 2008-09-13 11:38 <DIR> d-------- C:\Documents and Settings\r0tfl\Dane aplikacji\teamspeak2
2008-09-13 11:37 . 2008-09-13 11:37 34,064 --a------ C:\WINDOWS\system32\lhacm.acm
2008-09-13 11:36 . 2008-09-13 11:37 <DIR> d-------- C:\Program Files\Teamspeak2_RC2
2008-09-12 20:29 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-12 20:27 . 2008-09-12 20:29 <DIR> d-------- C:\Program Files\Java
2008-09-12 20:27 . 2008-09-12 20:27 <DIR> d-------- C:\Program Files\Common Files\Java
2008-09-12 20:03 . 2008-09-13 20:26 <DIR> d-------- C:\Program Files\SwiftKit
2008-09-12 20:03 . 2008-09-12 20:03 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\SwiftKit
2008-09-12 19:22 . 2001-07-22 00:23 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-09-12 19:21 . 2001-10-26 19:28 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-09-12 19:20 . 2001-10-26 17:29 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_smtpsnap.dll
2008-09-12 19:18 . 2001-10-26 19:29 159,744 --a--c--- C:\WINDOWS\system32\dllcache\icwhelp.dll
2008-09-12 19:13 . 2001-08-17 20:13 27,165 --a------ C:\WINDOWS\system32\drivers\fetnd5.sys
2008-09-12 16:34 . 2008-09-14 14:05 <DIR> d-------- C:\Documents and Settings\r0tfl\Dane aplikacji\GanymedeNet
2008-09-12 16:33 . 2008-09-13 17:29 <DIR> d-------- C:\Program Files\Ganymede
2008-09-12 15:01 . 2008-09-12 15:01 <DIR> d-------- C:\!FixIEDef
2008-09-12 14:04 . 2008-09-12 14:04 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-11 21:48 . 2008-09-11 21:48 <DIR> d-------- C:\WINDOWS\Sun
2008-09-11 21:48 . 2008-09-13 22:41 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2008-09-11 21:48 . 2008-09-13 20:27 24 --a------ C:\Documents and Settings\r0tfl\jagex_runescape_preferences.dat
2008-09-11 21:46 . 2008-09-11 21:46 <DIR> d-------- C:\Program Files\Sun
2008-09-11 15:52 . 2008-09-11 15:53 <DIR> d-------- C:\Documents and Settings\r0tfl\Dane aplikacji\Media Player Classic
2008-09-11 15:37 . 2008-09-11 15:38 <DIR> d-------- C:\Program Files\Real Alternative
2008-09-11 15:37 . 2003-03-19 05:14 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-09-11 15:37 . 2004-01-12 00:00 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-09-10 21:42 . 2008-09-10 21:42 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-10 21:42 . 2008-09-10 21:58 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-09-10 21:08 . 2008-09-10 21:08 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-09-10 21:00 . 2008-09-10 21:01 <DIR> d-------- C:\Program Files\SkanerOnline
2008-09-10 20:42 . 2008-09-10 21:04 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-09-10 20:42 . 2008-09-10 21:04 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-09-10 20:41 . 2008-09-10 20:41 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-09-10 20:41 . 2008-09-16 15:13 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-09-10 20:41 . 2008-09-16 16:14 2,007,072 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-10 20:41 . 2008-09-16 16:15 77,856 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-10 20:41 . 2008-09-16 16:14 33,152 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-10 20:41 . 2008-09-16 16:14 9,368 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-10 20:40 . 2008-09-10 20:40 <DIR> d-------- C:\kav
2008-09-10 20:15 . 2008-09-10 20:15 <DIR> d-------- C:\Documents and Settings\r0tfl\Dane aplikacji\Gadu-Gadu
2008-09-10 19:41 . 2008-09-10 19:41 <DIR> d-------- C:\Program Files\Gadu-Gadu
2008-09-10 19:41 . 2008-09-10 20:16 <DIR> d-------- C:\Documents and Settings\r0tfl\Gadu-Gadu
2008-09-10 17:51 . 2008-09-15 21:04 <DIR> d--h----- C:\Documents and Settings\Administrator\Ustawienia lokalne
2008-09-10 17:51 . 2008-09-10 17:31 <DIR> d-------- C:\Documents and Settings\Administrator\Ulubione
2008-09-10 17:51 . 2008-09-10 16:36 <DIR> d--h----- C:\Documents and Settings\Administrator\Szablony
2008-09-10 17:51 . 2008-09-10 17:31 <DIR> d-------- C:\Documents and Settings\Administrator\Pulpit
2008-09-10 17:51 . 2008-09-10 17:31 <DIR> d-------- C:\Documents and Settings\Administrator\Moje dokumenty
2008-09-10 17:51 . 2008-09-10 17:31 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Start
2008-09-10 17:51 . 2008-09-10 17:31 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dane aplikacji
2008-09-10 17:51 . 2008-09-10 17:51 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-10 17:49 . 2008-09-16 14:27 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-09-10 17:47 . 2008-09-10 17:47 <DIR> d-------- C:\Documents and Settings\LocalService\Menu Start
2008-09-10 17:46 . 2008-09-12 14:09 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-09-10 17:44 . 2008-09-10 18:03 5,604 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-09-10 17:40 . 2008-09-10 17:40 <DIR> d-------- C:\WINDOWS\provisioning
2008-09-10 17:40 . 2008-09-10 17:53 <DIR> d-------- C:\WINDOWS\peernet
2008-09-10 17:36 . 2008-09-10 17:39 <DIR> d-------- C:\Documents and Settings\r0tfl\Dane aplikacji\GetRightToGo
2008-09-10 17:34 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\[u]0[/u]02278_.tmp
2008-09-10 17:33 . 2004-08-03 22:43 15,872 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-09-10 17:33 . 2001-08-17 22:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-09-10 17:31 . 2008-09-16 16:11 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-09-10 17:31 . 2008-09-10 17:31 <DIR> dr-h----- C:\Documents and Settings\Default User\Ustawienia lokalne
2008-09-10 17:31 . 2008-09-10 17:31 <DIR> d-------- C:\Documents and Settings\Default User\Ulubione
2008-09-10 17:31 . 2008-09-10 16:36 <DIR> d--h----- C:\Documents and Settings\Default User\Szablony
2008-09-10 17:31 . 2008-09-10 17:31 <DIR> d-------- C:\Documents and Settings\Default User\Pulpit
2008-09-10 17:31 . 2008-09-10 17:31 <DIR> d-------- C:\Documents and Settings\Default User\Moje dokumenty
2008-09-10 17:31 . 2008-09-10 17:31 <DIR> dr------- C:\Documents and Settings\Default User\Menu Start
2008-09-10 17:31 . 2008-09-10 17:31 <DIR> dr-h----- C:\Documents and Settings\Default User\Dane aplikacji
2008-09-10 17:31 . 2008-09-10 17:31 <DIR> d-------- C:\Documents and Settings\All Users\Ulubione
2008-09-10 17:31 . 2008-09-11 21:46 <DIR> d--h----- C:\Documents and Settings\All Users\Szablony
2008-09-10 17:31 . 2008-09-16 14:28 <DIR> d-------- C:\Documents and Settings\All Users\Pulpit
2008-09-10 17:31 . 2008-09-12 19:23 <DIR> dr------- C:\Documents and Settings\All Users\Menu Start
2008-09-10 17:31 . 2008-09-10 17:47 <DIR> dr------- C:\Documents and Settings\All Users\Dokumenty
2008-09-10 17:31 . 2008-09-12 20:03 <DIR> dr-h----- C:\Documents and Settings\All Users\Dane aplikacji
2008-09-10 17:30 . 2008-09-12 19:11 <DIR> d--h----- C:\Documents and Settings\Default User
2008-09-10 17:29 . 2008-09-10 17:53 <DIR> d-------- C:\WINDOWS\EHome
2008-09-10 17:28 . 2008-09-10 17:29 <DIR> d-------- C:\Program Files\ATI Technologies
2008-09-10 17:20 . 2008-09-10 17:20 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-09-10 17:20 . 2008-09-10 17:20 <DIR> d-------- C:\WINDOWS\Profiles
2008-09-10 17:20 . 2008-09-10 17:20 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-09-10 17:20 . 2008-09-10 17:20 <DIR> d-------- C:\Documents and Settings\r0tfl\Dane aplikacji\InterTrust
2008-09-10 17:20 . 1998-10-29 15:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-09-10 17:20 . 2001-10-16 10:23 163,840 --a------ C:\WINDOWS\system32\PhotoImpression Screen Saver.scr
2008-09-10 17:20 . 2001-12-12 11:46 131,072 --a------ C:\WINDOWS\system32\Epcmlib.dll
2008-09-10 17:19 . 2008-09-10 17:19 <DIR> d-------- C:\Program Files\ArcSoft
2008-09-10 17:19 . 1999-05-26 09:46 212,480 --a------ C:\WINDOWS\pcdlib32.dll
2008-09-10 17:18 . 2008-09-10 17:18 <DIR> d-------- C:\Program Files\Common Files\Python
2008-09-10 17:18 . 2001-10-19 12:18 708,696 --a------ C:\WINDOWS\system32\python21.dll
2008-09-10 17:18 . 2001-10-19 12:18 290,919 --a------ C:\WINDOWS\system32\pythoncom21.dll
2008-09-10 17:18 . 2001-10-19 12:19 57,344 --a------ C:\WINDOWS\system32\PyWinTypes21.dll
2008-09-10 17:16 . 2002-05-10 19:56 122,880 --a------ C:\WINDOWS\system32\EEBAPI.dll
2008-09-10 17:16 . 2002-05-10 19:56 102,400 --a------ C:\WINDOWS\system32\EEBDSCVR.dll
2008-09-10 17:16 . 1999-06-15 11:31 96,768 --a------ C:\WINDOWS\SlantAdj.dll
2008-09-10 17:16 . 1999-12-07 02:03 73,216 --a------ C:\WINDOWS\ADE.DLL
2008-09-10 17:16 . 2002-01-10 19:05 65,536 --a------ C:\WINDOWS\system32\EEBUtil.dll
2008-09-10 17:16 . 2002-01-29 13:33 65,536 --a------ C:\WINDOWS\system32\EBAPI.dll
2008-09-10 17:16 . 2001-08-21 01:00 54,272 --a------ C:\WINDOWS\system32\EEBSDKIF.dll
2008-09-10 17:16 . 1999-04-27 00:17 3,136 --a------ C:\WINDOWS\Ade001.bin
2008-09-10 17:16 . 2000-09-08 13:31 72 -ra------ C:\WINDOWS\system32\epDPE.ini
2008-09-10 17:15 . 2008-09-10 17:15 <DIR> d-------- C:\Program Files\Common Files\EPSON
2008-09-10 17:15 . 2001-08-23 01:04 139,264 --a------ C:\WINDOWS\system32\EBAPI2.dll
2008-09-10 17:13 . 2008-09-10 17:20 <DIR> d-------- C:\Program Files\EPSON
2008-09-10 17:13 . 2002-09-23 20:40 70,924 --a------ C:\WINDOWS\system32\EBPMON2.DLL
2008-09-10 17:13 . 2002-09-23 20:39 56,832 --a------ C:\WINDOWS\system32\ECBTEG.DLL
2008-09-10 17:13 . 2002-09-23 20:40 34,304 --a------ C:\WINDOWS\system32\EBPCHP.DLL
2008-09-10 17:13 . 2008-09-10 17:15 12,198 --a------ C:\WINDOWS\EPSTPLOG.BAK
2008-09-10 17:13 . 2002-09-23 20:45 182 --a------ C:\WINDOWS\system32\EBPPORT.DAT
2008-09-10 17:12 . 2008-09-10 17:12 <DIR> d-------- C:\WUTemp
2008-09-10 17:12 . 2008-09-10 17:12 <DIR> d-------- C:\EPSON
2008-09-10 17:12 . 2002-06-05 00:00 184,320 --a------ C:\WINDOWS\system32\esdtr.dll
2008-09-10 17:12 . 2003-08-25 18:06 182,880 --a------ C:\WINDOWS\system32\iuenginenew.dll
2008-09-10 17:12 . 2002-02-08 00:00 90,112 --a------ C:\WINDOWS\system32\epcomdd.dll
2008-09-10 17:12 . 2002-06-17 00:00 86,016 --a------ C:\WINDOWS\system32\epfb5cpl.dll
2008-09-10 17:12 . 2000-10-11 00:00 53,248 --a------ C:\WINDOWS\system32\esicm.dll
2008-09-10 17:12 . 2001-11-15 00:00 47,104 --a------ C:\WINDOWS\system32\escimgd.dll
2008-09-10 17:12 . 2002-06-20 00:00 32,256 --a------ C:\WINDOWS\system32\escwiad.dll
2008-09-10 17:12 . 2002-06-20 00:00 22,528 --a------ C:\WINDOWS\system32\esccmd.dll
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-10 19:05 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-09-10 17:05 --------- d-----w C:\Program Files\Common Files\Softwin
2008-09-10 16:56 --------- d-----w C:\Program Files\Softwin
2008-09-10 16:37 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-09-10 15:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-10 14:51 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-10 14:40 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-10 14:38 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((( snapshot@2008-09-15_21.02.56.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-10-26 17:29:26 179,712 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\cewmdm.dll
+ 2001-10-26 17:29:36 175,104 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSP.dll
+ 2001-10-26 17:29:36 245,760 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MSSCP.dll
+ 2001-10-26 17:29:36 155,648 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MSWMDM.dll
+ 2001-10-26 17:29:46 22,528 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\WMDMLOG.dll
+ 2001-10-26 17:29:46 20,480 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\WMDMPS.dll
+ 2005-01-28 11:44:28 164,864 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\cewmdm.dll
+ 2005-01-28 11:44:28 25,088 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll
+ 2005-01-28 11:44:28 173,568 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSP.dll
+ 2005-01-28 11:44:28 364,784 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MSSCP.dll
+ 2005-01-28 11:44:28 315,904 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MSWMDM.dll
+ 2005-01-28 11:44:28 28,160 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\WMDMLOG.dll
+ 2005-01-28 11:44:28 33,792 ----a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\WMDMPS.dll
+ 2005-01-28 11:44:28 47,104 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\uwdf.exe
+ 2005-01-28 11:44:28 15,872 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wdfapi.dll
+ 2005-01-28 11:44:28 38,912 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wdfmgr.exe
+ 2005-01-28 11:44:28 38,912 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpd_ci.dll
+ 2005-01-28 11:44:28 61,952 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdconns.dll
+ 2005-01-28 11:44:28 114,176 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtp.dll
+ 2005-01-28 11:44:28 331,776 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtpdr.dll
+ 2005-01-28 11:44:28 66,560 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtpus.dll
+ 2005-01-28 11:44:28 331,264 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdsp.dll
+ 2005-01-28 11:44:28 10,752 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdtrace.dll
+ 2005-01-28 11:44:28 18,944 ----a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdusb.sys
+ 2001-10-26 17:29:46 184,320 ----a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmadmod.dll
+ 2001-10-26 17:29:46 110,592 ----a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmsdmod.dll
+ 2001-10-26 17:29:46 294,912 ----a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmvdmod.dll
+ 2005-01-28 11:44:28 396,528 ----a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmadmod.dll
+ 2005-01-28 11:44:28 774,904 ----a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmsdmod.dll
+ 2005-01-28 11:44:28 413,944 ----a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmspdmod.dll
+ 2005-01-28 11:44:28 1,218,808 ----a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmvadvd.dll
+ 2005-01-28 11:44:28 895,736 ----a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmvdmod.dll
+ 2001-10-26 17:29:32 6,656 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\laprxy.dll
+ 2001-10-26 17:29:56 24,576 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\logagent.exe
+ 2002-12-11 22:14:32 173,056 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\qasf.dll
+ 2001-10-26 17:29:46 442,398 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmadmoe.dll
+ 2001-10-26 17:29:46 274,432 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmasf.dll
+ 2001-10-26 17:29:46 253,952 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmnetmgr.dll
+ 2001-10-26 17:29:46 1,216,512 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmvcore.dll
+ 2005-01-28 11:44:28 6,656 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\laprxy.dll
+ 2005-01-28 11:44:28 96,768 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\logagent.exe
+ 2005-01-28 11:44:28 221,184 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\qasf.dll
+ 2005-01-28 11:44:28 716,288 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmadmoe.dll
+ 2005-01-28 11:44:28 224,768 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmasf.dll
+ 2005-01-28 11:44:28 335,872 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMDRMdev.dll
+ 2005-01-28 11:44:28 290,816 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMDRMNet.dll
+ 2005-01-28 11:44:28 150,016 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmidx.dll
+ 2005-01-28 11:44:28 1,027,072 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmnetmgr.dll
+ 2005-01-28 11:44:28 1,119,744 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmsdmoe2.dll
+ 2005-01-28 11:44:28 940,544 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmspdmoe.dll
+ 2005-01-28 11:44:28 1,512,448 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMVADVE.DLL
+ 2005-01-28 11:44:28 2,370,296 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmvcore.dll
+ 2005-01-28 11:44:28 1,003,008 ----a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmvdmoe2.dll
+ 2001-10-26 17:29:26 204,800 ----a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\blackbox.dll
+ 2001-10-26 17:29:28 258,048 ----a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmclien.dll
+ 2001-10-26 17:29:28 76,830 ----a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmstor.dll
+ 2001-10-26 17:29:28 589,824 ----a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmv2clt.dll
+ 2001-10-26 17:29:36 174,592 ----a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\msnetobj.dll
+ 2005-01-28 11:44:28 294,912 ----a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\blackbox.dll
+ 2005-01-28 11:44:28 258,296 ----a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmclien.dll
+ 2005-01-28 11:44:28 96,768 ----a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmstor.dll
+ 2005-01-28 11:44:28 502,272 ----a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmv2clt.dll
+ 2005-01-28 11:44:28 142,336 ----a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\msnetobj.dll
- 2001-10-26 17:29:26 204,800 ----a-w C:\WINDOWS\system32\blackbox.dll
+ 2005-01-28 11:44:28 294,912 ----a-w C:\WINDOWS\system32\blackbox.dll
- 2001-10-26 17:29:26 179,712 ----a-w C:\WINDOWS\system32\cewmdm.dll
+ 2005-01-28 11:44:28 164,864 ----a-w C:\WINDOWS\system32\cewmdm.dll
- 2001-10-26 17:29:26 204,800 -c--a-w C:\WINDOWS\system32\dllcache\blackbox.dll
+ 2005-01-28 11:44:28 294,912 -c--a-w C:\WINDOWS\system32\dllcache\blackbox.dll
- 2001-10-26 17:29:26 179,712 -c--a-w C:\WINDOWS\system32\dllcache\cewmdm.dll
+ 2005-01-28 11:44:28 164,864 -c--a-w C:\WINDOWS\system32\dllcache\cewmdm.dll
- 2001-10-26 17:29:28 258,048 -c--a-w C:\WINDOWS\system32\dllcache\drmclien.dll
+ 2005-01-28 11:44:28 258,296 -c--a-w C:\WINDOWS\system32\dllcache\drmclien.dll
- 2001-10-26 17:29:28 76,830 -c--a-w C:\WINDOWS\system32\dllcache\drmstor.dll
+ 2005-01-28 11:44:28 96,768 -c--a-w C:\WINDOWS\system32\dllcache\drmstor.dll
- 2001-10-26 17:29:28 589,824 -c--a-w C:\WINDOWS\system32\dllcache\drmv2clt.dll
+ 2005-01-28 11:44:28 502,272 -c--a-w C:\WINDOWS\system32\dllcache\drmv2clt.dll
- 2001-10-26 17:29:32 6,656 -c--a-w C:\WINDOWS\system32\dllcache\laprxy.dll
+ 2005-01-28 11:44:28 6,656 -c--a-w C:\WINDOWS\system32\dllcache\laprxy.dll
- 2001-10-26 17:29:56 24,576 -c--a-w C:\WINDOWS\system32\dllcache\logagent.exe
+ 2005-01-28 11:44:28 96,768 -c--a-w C:\WINDOWS\system32\dllcache\logagent.exe
- 2001-10-26 17:29:36 174,592 -c--a-w C:\WINDOWS\system32\dllcache\msnetobj.dll
+ 2005-01-28 11:44:28 142,336 -c--a-w C:\WINDOWS\system32\dllcache\msnetobj.dll
- 2001-10-26 17:29:36 175,104 -c--a-w C:\WINDOWS\system32\dllcache\mspmsp.dll
+ 2005-01-28 11:44:28 173,568 -c--a-w C:\WINDOWS\system32\dllcache\mspmsp.dll
- 2001-10-26 17:29:36 245,760 -c--a-w C:\WINDOWS\system32\dllcache\msscp.dll
+ 2005-01-28 11:44:28 364,784 -c--a-w C:\WINDOWS\system32\dllcache\msscp.dll
- 2001-10-26 17:29:36 155,648 -c--a-w C:\WINDOWS\system32\dllcache\mswmdm.dll
+ 2005-01-28 11:44:28 315,904 -c--a-w C:\WINDOWS\system32\dllcache\mswmdm.dll
- 2002-12-11 22:14:32 173,056 -c--a-w C:\WINDOWS\system32\dllcache\qasf.dll
+ 2005-01-28 11:44:28 221,184 -c--a-w C:\WINDOWS\system32\dllcache\qasf.dll
- 2001-10-26 17:29:46 184,320 -c--a-w C:\WINDOWS\system32\dllcache\wmadmod.dll
+ 2005-01-28 11:44:28 396,528 -c--a-w C:\WINDOWS\system32\dllcache\wmadmod.dll
- 2001-10-26 17:29:46 442,398 -c--a-w C:\WINDOWS\system32\dllcache\wmadmoe.dll
+ 2005-01-28 11:44:28 716,288 -c--a-w C:\WINDOWS\system32\dllcache\wmadmoe.dll
- 2001-10-26 17:29:46 274,432 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
+ 2005-01-28 11:44:28 224,768 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
- 2001-10-26 17:29:46 22,528 -c--a-w C:\WINDOWS\system32\dllcache\wmdmlog.dll
+ 2005-01-28 11:44:28 28,160 -c--a-w C:\WINDOWS\system32\dllcache\wmdmlog.dll
- 2001-10-26 17:29:46 20,480 -c--a-w C:\WINDOWS\system32\dllcache\wmdmps.dll
+ 2005-01-28 11:44:28 33,792 -c--a-w C:\WINDOWS\system32\dllcache\wmdmps.dll
- 2001-10-26 17:29:46 253,952 -c--a-w C:\WINDOWS\system32\dllcache\wmnetmgr.dll
+ 2005-01-28 11:44:28 1,027,072 -c--a-w C:\WINDOWS\system32\dllcache\wmnetmgr.dll
- 2001-10-26 17:29:46 110,592 -c--a-w C:\WINDOWS\system32\dllcache\wmsdmod.dll
+ 2005-01-28 11:44:28 774,904 -c--a-w C:\WINDOWS\system32\dllcache\wmsdmod.dll
- 2001-10-26 17:29:46 1,216,512 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
+ 2005-01-28 11:44:28 2,370,296 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
- 2001-10-26 17:29:46 294,912 -c--a-w C:\WINDOWS\system32\dllcache\wmvdmod.dll
+ 2005-01-28 11:44:28 895,736 -c--a-w C:\WINDOWS\system32\dllcache\wmvdmod.dll
+ 2005-01-28 11:44:28 18,944 ----a-w C:\WINDOWS\system32\drivers\wpdusb.sys
- 2001-10-26 17:29:28 258,048 ----a-w C:\WINDOWS\system32\drmclien.dll
+ 2005-01-28 11:44:28 258,296 ----a-w C:\WINDOWS\system32\drmclien.dll
- 2001-10-26 17:29:28 76,830 ----a-w C:\WINDOWS\system32\drmstor.dll
+ 2005-01-28 11:44:28 96,768 ----a-w C:\WINDOWS\system32\drmstor.dll
- 2001-10-26 17:29:28 589,824 ----a-w C:\WINDOWS\system32\drmv2clt.dll
+ 2005-01-28 11:44:28 502,272 ----a-w C:\WINDOWS\system32\drmv2clt.dll
- 2001-10-26 17:29:32 6,656 ----a-w C:\WINDOWS\system32\laprxy.dll
+ 2005-01-28 11:44:28 6,656 ----a-w C:\WINDOWS\system32\laprxy.dll
- 2001-10-26 17:29:56 24,576 ----a-w C:\WINDOWS\system32\logagent.exe
+ 2005-01-28 11:44:28 96,768 ----a-w C:\WINDOWS\system32\logagent.exe
- 2001-10-26 17:29:36 174,592 ----a-w C:\WINDOWS\system32\msnetobj.dll
+ 2005-01-28 11:44:28 142,336 ----a-w C:\WINDOWS\system32\msnetobj.dll
+ 2005-01-28 11:44:28 25,088 ----a-w C:\WINDOWS\system32\MsPMSNSv.dll
- 2001-10-26 17:29:36 175,104 ----a-w C:\WINDOWS\system32\mspmsp.dll
+ 2005-01-28 11:44:28 173,568 ----a-w C:\WINDOWS\system32\MsPMSP.dll
- 2001-10-26 17:29:36 245,760 ----a-w C:\WINDOWS\system32\msscp.dll
+ 2005-01-28 11:44:28 364,784 ----a-w C:\WINDOWS\system32\MSSCP.dll
- 2001-10-26 17:29:36 155,648 ----a-w C:\WINDOWS\system32\mswmdm.dll
+ 2005-01-28 11:44:28 315,904 ----a-w C:\WINDOWS\system32\MSWMDM.dll
+ 2007-03-07 23:51:00 547,576 ------w C:\WINDOWS\system32\px.dll
+ 2007-03-07 23:51:00 64,760 ------w C:\WINDOWS\system32\pxcpya64.exe
+ 2007-03-07 23:51:00 510,712 ------w C:\WINDOWS\system32\pxdrv.dll
+ 2007-03-07 23:51:00 72,440 ------w C:\WINDOWS\system32\pxhpinst.exe
+ 2007-03-07 23:51:00 64,760 ------w C:\WINDOWS\system32\pxinsa64.exe
+ 2007-03-07 23:51:00 187,128 ------w C:\WINDOWS\system32\pxmas.dll
+ 2007-03-07 23:51:00 1,628,920 ------w C:\WINDOWS\system32\pxsfs.dll
+ 2007-03-07 23:51:00 379,640 ------w C:\WINDOWS\system32\pxwave.dll
- 2002-12-11 22:14:32 173,056 ----a-w C:\WINDOWS\system32\qasf.dll
+ 2005-01-28 11:44:28 221,184 ----a-w C:\WINDOWS\system32\qasf.dll
+ 2005-01-28 11:44:28 47,104 ----a-w C:\WINDOWS\system32\uwdf.exe
+ 2007-03-07 23:51:00 39,672 ------w C:\WINDOWS\system32\vxblock.dll
+ 2005-01-28 11:44:28 15,872 ----a-w C:\WINDOWS\system32\wdfapi.dll
+ 2005-01-28 11:44:28 38,912 ----a-w C:\WINDOWS\system32\wdfmgr.exe
- 2001-10-26 17:29:46 184,320 ----a-w C:\WINDOWS\system32\wmadmod.dll
+ 2005-01-28 11:44:28 396,528 ----a-w C:\WINDOWS\system32\wmadmod.dll
- 2001-10-26 17:29:46 442,398 ----a-w C:\WINDOWS\system32\wmadmoe.dll
+ 2005-01-28 11:44:28 716,288 ----a-w C:\WINDOWS\system32\wmadmoe.dll
- 2001-10-26 17:29:46 274,432 ----a-w C:\WINDOWS\system32\wmasf.dll
+ 2005-01-28 11:44:28 224,768 ----a-w C:\WINDOWS\system32\wmasf.dll
- 2001-10-26 17:29:46 22,528 ----a-w C:\WINDOWS\system32\wmdmlog.dll
+ 2005-01-28 11:44:28 28,160 ----a-w C:\WINDOWS\system32\WMDMLOG.dll
- 2001-10-26 17:29:46 20,480 ----a-w C:\WINDOWS\system32\wmdmps.dll
+ 2005-01-28 11:44:28 33,792 ----a-w C:\WINDOWS\system32\WMDMPS.dll
+ 2005-01-28 11:44:28 335,872 ----a-w C:\WINDOWS\system32\WMDRMdev.dll
+ 2005-01-28 11:44:28 290,816 ----a-w C:\WINDOWS\system32\WMDRMNet.dll
+ 2005-01-28 11:44:28 150,016 ----a-w C:\WINDOWS\system32\wmidx.dll
- 2001-10-26 17:29:46 253,952 ----a-w C:\WINDOWS\system32\wmnetmgr.dll
+ 2005-01-28 11:44:28 1,027,072 ----a-w C:\WINDOWS\system32\wmnetmgr.dll
- 2001-10-26 17:29:46 110,592 ----a-w C:\WINDOWS\system32\wmsdmod.dll
+ 2005-01-28 11:44:28 774,904 ----a-w C:\WINDOWS\system32\wmsdmod.dll
+ 2005-01-28 11:44:28 1,119,744 ----a-w C:\WINDOWS\system32\wmsdmoe2.dll
+ 2005-01-28 11:44:28 413,944 ----a-w C:\WINDOWS\system32\wmspdmod.dll
+ 2005-01-28 11:44:28 940,544 ----a-w C:\WINDOWS\system32\wmspdmoe.dll
+ 2005-01-28 11:44:28 1,218,808 ----a-w C:\WINDOWS\system32\wmvadvd.dll
+ 2005-01-28 11:44:28 1,512,448 ----a-w C:\WINDOWS\system32\WMVADVE.DLL
- 2001-10-26 17:29:46 1,216,512 ----a-w C:\WINDOWS\system32\wmvcore.dll
+ 2005-01-28 11:44:28 2,370,296 ----a-w C:\WINDOWS\system32\wmvcore.dll
- 2001-10-26 17:29:46 294,912 ----a-w C:\WINDOWS\system32\wmvdmod.dll
+ 2005-01-28 11:44:28 895,736 ----a-w C:\WINDOWS\system32\wmvdmod.dll
+ 2005-01-28 11:44:28 1,003,008 ----a-w C:\WINDOWS\system32\wmvdmoe2.dll
+ 2005-01-28 11:44:28 38,912 ----a-w C:\WINDOWS\system32\wpd_ci.dll
+ 2005-01-28 11:44:28 61,952 ----a-w C:\WINDOWS\system32\wpdconns.dll
+ 2005-01-28 11:44:28 114,176 ----a-w C:\WINDOWS\system32\wpdmtp.dll
+ 2005-01-28 11:44:28 331,776 ----a-w C:\WINDOWS\system32\wpdmtpdr.dll
+ 2005-01-28 11:44:28 66,560 ----a-w C:\WINDOWS\system32\wpdmtpus.dll
+ 2005-01-28 11:44:28 331,264 ----a-w C:\WINDOWS\system32\wpdsp.dll
+ 2005-01-28 11:44:28 10,752 ----a-w C:\WINDOWS\system32\wpdtrace.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-10-26 13312]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2001-08-02 1077277]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"BoostSpeed"="C:\Program Files\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe" [2008-04-29 1931376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 36352]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 227856]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-26 13312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2001-10-26 40448]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2003-09-12 21:10 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3200]
--a------ 2002-09-23 20:25 74752 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC2.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-07-07 09:42 2156368 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
R0 zjopg;zjopg;C:\WINDOWS\System32\drivers\hvlgky.sys []
R4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.syS []
S3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\r0tfl\Dane aplikacji\Mozilla\Firefox\Profiles\slvs0a6x.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npganymedenet.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPSNOOKER.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-16 16:15:50
Windows 5.1.2600 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
PROCES: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
.
**************************************************************************
.
Czas ukończenia: 2008-09-16 16:22:04 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-09-16 14:21:50
ComboFix2.txt 2008-09-15 19:04:45
ComboFix3.txt 2008-09-12 12:27:40
Przed: 48,165,236,736 bajt˘w wolnych
Po: 48,436,756,480 bajt˘w wolnych
402
HIjackThis.
- Kod: Zaznacz wszystko
[quote]Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:09:01, on 16/09/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [BoostSpeed] "C:\Program Files\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe" /Q
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-1715567821-1220945662-725345543-1003\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1715567821-1220945662-725345543-1003\..\Run: [BoostSpeed] "C:\Program Files\Auslogics\AusLogics BoostSpeed\BoostSpeed.exe" /Q (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
--
End of file - 5413 bytes
[/quote]
Gdy zrobię scana Combofixem mogę wkleić a po ponownym uruchomieniu komputera znów problem się powtarza.