Mam chyba coś gorszego, ponieważ COMBOFIX wiesza się w momencie gdy chce resetować windowsa - prosi czekać i nic, mimo że system jako tako działa i nawet da się go czasami zamknąć.
Próbowałem wyłączać wszystkie programy, odinstalowałem wszystkie antyviry, nawet logowałem się na innego admina.
Jeszcze gorsze jest to, że nie chce pobrać mi programu KVRT (google nie wyszukują strony jak podam nazwę i link bezpośredni do ściągnięcia nie otwiera mi się).
Zgłupiałem doszczętnie. Błagam o pomoc, bo formatowanie nie wchodzi w grę - mam zbyt dużo dokumentów.
Dodano Dzisiaj, 10:20:Acha, COMBOFIX jeszcze w niedzielę stworzył mi log'a, a teraz nie chce.
Loga tego zrobiłem bez parametru
Folder::
C:\DOCUME~1\Vader\USTAWI~1\Temp
Log poniżej:
- Kod: Zaznacz wszystko
ComboFix 08-11-14.01 - Vader 2008-11-16 9:45:01.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.849 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Vader\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.
((((((((((((((((((((((((( Pliki utworzone od 2008-10-16 do 2008-11-16 )))))))))))))))))))))))))))))))
.
2008-11-15 22:22 . 2008-11-15 22:23 <DIR> d-------- c:\program files\Counter-Strike
2008-11-15 18:01 . 2008-11-15 18:01 <DIR> d-------- c:\program files\EA GAMES
2008-11-12 09:47 . 2008-11-12 09:47 197 --a------ c:\windows\system32\MRT.INI
2008-11-12 09:43 . 2008-11-12 09:43 1,393 --a------ c:\windows\imsins.BAK
2008-11-12 09:41 . 2008-09-04 18:17 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 09:41 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 14:00 . 2008-11-11 14:00 <DIR> dr------- c:\documents and settings\NetworkService\Ulubione
2008-11-11 13:08 . 2008-11-11 13:08 58,368 --a------ c:\windows\system32\a74LJ7bQ.exe
2008-11-11 12:41 . 2008-11-11 12:41 <DIR> d-------- c:\program files\CCleaner
2008-11-10 18:00 . 2008-11-10 18:00 <DIR> d-------- c:\documents and settings\Renia\Dane aplikacji\McAfee.com Personal Firewall
2008-11-09 20:31 . 2008-11-09 20:31 <DIR> d-------- C:\DoctorWeb
2008-11-09 20:30 . 2008-11-09 20:30 0 --a------ c:\windows\system32\setup_XP.ini
2008-11-09 19:36 . 2008-04-14 18:20 1,689,088 ---h---t- c:\windows\system32\d422ea0.dll
2008-11-09 19:36 . 2008-04-14 18:20 82,432 ---h---t- c:\windows\system32\cf17fa2.dll
2008-11-09 19:36 . 2008-04-14 18:20 82,432 ---h---t- c:\windows\system32\158b75f8.dll
2008-11-09 19:35 . 2008-04-14 18:20 1,689,088 ---h---t- c:\windows\system32\2072f028.dll
2008-11-09 16:49 . 2008-11-09 16:49 <DIR> d-------- c:\documents and settings\Vader\Dane aplikacji\McAfee.com Personal Firewall
2008-11-09 13:49 . 2008-11-09 17:41 <DIR> d-------- c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP
2008-11-09 13:29 . 2008-11-09 13:29 <DIR> d-------- c:\documents and settings\LocalService\Dane aplikacji\McAfee.com Personal Firewall
2008-11-09 13:28 . 2008-11-11 11:22 8,256 --a------ c:\windows\system32\Status.MPF
2008-11-09 12:03 . 2008-11-09 12:03 <DIR> d-------- c:\program files\McAfee.com
2008-11-09 12:03 . 2008-11-09 12:03 <DIR> d-------- c:\documents and settings\Mikis\Dane aplikacji\McAfee.com Personal Firewall
2008-11-08 21:16 . 2008-11-08 21:16 <DIR> d-------- c:\documents and settings\Mikis\DoctorWeb
2008-11-08 20:21 . 2008-11-08 20:21 <DIR> d-------- c:\program files\SkanerOnline
2008-11-08 14:55 . 2008-11-08 14:55 <DIR> d-------- c:\documents and settings\Mikis\Dane aplikacji\Mikrotik
2008-11-08 13:58 . 2008-11-15 16:19 363 --a------ c:\windows\gmer.ini
2008-11-08 10:55 . 2008-11-08 10:55 <DIR> d-------- c:\program files\Trend Micro
2008-11-08 10:52 . 2008-11-08 10:52 <DIR> d-------- c:\program files\SpywareBlaster
2008-11-08 10:52 . 2008-11-08 10:52 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\TEMP
2008-11-08 10:48 . 2008-11-08 10:48 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-08 10:48 . 2008-11-08 13:41 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-11-07 22:24 . 2008-11-07 22:24 <DIR> d-------- c:\program files\Lavasoft
2008-11-07 22:24 . 2008-11-09 13:49 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-07 22:24 . 2008-11-07 22:24 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Lavasoft
2008-11-07 14:20 . 2008-11-07 14:20 <DIR> d--h----- c:\windows\system32\GroupPolicy
2008-11-04 11:23 . 2008-11-04 11:39 <DIR> d-------- C:\Instalki 2
2008-11-03 17:24 . 2008-11-03 17:24 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-11-03 17:23 . 2008-11-03 17:23 21,419 --a------ c:\windows\system32\drivers\AegisP.sys
2008-11-03 17:22 . 2008-11-03 17:22 <DIR> d-------- c:\program files\RALINK
2008-11-03 17:22 . 2006-11-02 17:12 348,416 --a------ c:\windows\system32\drivers\rt73.sys
2008-11-03 17:22 . 2006-06-20 22:53 319,488 --a------ c:\windows\system32\AegisI5.exe
2008-11-03 17:22 . 2006-06-17 12:29 295,018 --a------ c:\windows\system32\Install7x.dll
2008-11-03 17:22 . 2005-11-30 11:33 2,048 --a------ c:\windows\system32\drivers\rt73.bin
2008-11-03 17:22 . 2006-03-06 15:36 45 --a------ c:\windows\filespec7x
2008-11-02 10:44 . 2008-11-02 10:55 <DIR> d-------- C:\Ksiazki
2008-10-30 22:49 . 2008-10-31 16:24 <DIR> d-------- C:\temp dysk F
2008-10-30 12:44 . 2008-10-30 12:45 <DIR> d-------- C:\Music
2008-10-30 12:14 . 2008-10-30 12:14 <DIR> d-------- C:\Visio2000Technical
2008-10-30 11:40 . 2008-10-30 11:40 <DIR> d-------- C:\UZYTKI
2008-10-30 11:40 . 2008-10-30 11:40 <DIR> d-------- C:\TELEFONY
2008-10-30 11:17 . 2008-10-30 11:17 <DIR> d-------- c:\program files\MSXML 4.0
2008-10-30 02:24 . 2008-10-30 02:24 42,320 --a------ c:\windows\system32\xfcodec.dll
2008-10-28 22:09 . 2008-10-28 22:09 <DIR> d-------- c:\program files\Sony Ericsson
2008-10-28 22:09 . 2008-10-28 22:09 <DIR> d-------- c:\program files\Common Files\Teleca Shared
2008-10-28 22:09 . 2008-10-28 22:09 <DIR> d-------- c:\documents and settings\All Users\Documents
2008-10-28 22:09 . 2008-10-28 22:09 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Sony Ericsson
2008-10-24 13:43 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-17 19:56 . 2008-10-17 19:56 <DIR> d-------- c:\program files\MagicISO
2008-10-16 17:53 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-10-16 17:52 . 2008-08-14 14:26 2,190,464 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-16 17:52 . 2008-08-14 14:26 2,146,816 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-16 17:52 . 2008-08-14 14:26 2,067,328 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-16 17:52 . 2008-08-14 14:26 2,025,472 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-16 17:52 . 2008-09-15 16:27 1,846,656 -----c--- c:\windows\system32\dllcache\win32k.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-15 20:42 --------- d-----w c:\documents and settings\Mikis\Dane aplikacji\uTorrent
2008-11-15 17:52 --------- d-----w c:\documents and settings\Mikis\Dane aplikacji\Xfire
2008-11-15 17:01 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-15 09:25 --------- d-----w c:\program files\Mozilla Thunderbird
2008-11-12 21:01 --------- d-----w c:\program files\Xfire
2008-11-08 19:38 --------- d-----w c:\program files\Tlen.pl
2008-11-06 09:43 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab
2008-11-06 09:41 8,067,616 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-06 09:41 66,204 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-06 09:41 5,600 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-06 09:41 1,015,840 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-05 17:50 --------- d-----w c:\program files\Opera
2008-11-03 07:43 --------- d-----w c:\documents and settings\Vader\Dane aplikacji\Skype
2008-11-03 07:27 --------- d-----w c:\documents and settings\Vader\Dane aplikacji\skypePM
2008-10-30 15:42 --------- d-----w c:\program files\SuperMemo UX
2008-10-26 11:13 --------- d-----w c:\documents and settings\Mikis\Dane aplikacji\foobar2000
2008-10-25 21:34 --------- d-----w c:\documents and settings\Mikis\Dane aplikacji\Tlen.pl
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 18:05 182,928 ----a-w c:\windows\system32\PnkBstrB.exe
2008-10-22 18:05 159,992 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-10-17 19:07 --------- d-----w c:\program files\Common Files\Adobe
2008-10-17 13:28 --------- d-----w c:\program files\DC++
2008-10-12 18:20 --------- d-----w c:\program files\Rainlendar2
2008-10-12 17:11 724,992 ----a-w c:\windows\iun6002.exe
2008-10-12 14:21 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\PopCap Games
2008-10-12 11:51 --------- d-----w c:\program files\RocketDock
2008-10-12 11:33 --------- d-----w c:\program files\uTorrent
2008-10-12 11:01 --------- d-----w c:\program files\NeoTheme
2008-10-04 20:14 105,984 ----a-w c:\windows\system32\c_dll.dll
2008-10-03 06:40 --------- d-----w c:\documents and settings\Vader\Dane aplikacji\foobar2000
2008-09-30 19:00 --------- d-----w c:\program files\foobar2000
2008-09-30 18:35 --------- d-----w c:\documents and settings\Vader\Dane aplikacji\SpeedSim
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-28 13:04 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2008-09-23 17:18 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2008-09-22 19:38 --------- d-----w c:\documents and settings\Vader\Dane aplikacji\Xfire
2008-09-20 20:01 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-09-20 20:00 --------- d-----w c:\program files\Electronic Arts
2008-09-17 14:49 52,736 ----a-w c:\windows\ipuninst.exe
2008-09-15 15:27 1,846,656 ----a-w c:\windows\system32\win32k.sys
2008-09-14 15:35 19,344 ----a-w c:\windows\system32\ealregsnapshot1.reg
2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:17 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-26 08:27 826,368 ----a-w c:\windows\system32\wininet.dll
2007-12-15 18:40 32 ----a-w c:\documents and settings\All Users\Dane aplikacji\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-11-08_18.33.57.64 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-09 16:41:47 24,804 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCall.dll
+ 2008-11-09 16:41:49 121,465 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla.dll
+ 2008-11-09 12:49:12 121,465 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla.exe
+ 2008-11-09 16:41:47 120,965 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla10.dll
+ 2008-11-09 16:41:48 121,015 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla11.dll
+ 2008-11-09 16:41:48 121,119 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla12.dll
+ 2008-11-09 16:41:48 120,715 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla13.dll
+ 2008-11-09 16:41:48 120,664 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla14.dll
+ 2008-11-09 16:41:48 120,715 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla15.dll
+ 2008-11-09 16:41:48 120,662 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla16.dll
+ 2008-11-09 16:41:49 120,716 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla17.dll
+ 2008-11-09 16:41:48 120,660 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla18.dll
+ 2008-11-09 16:41:49 121,117 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla2.dll
+ 2008-11-09 16:41:48 136,000 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla21.dll
+ 2008-11-09 12:49:10 136,000 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla21.exe
+ 2008-11-09 16:41:48 120,737 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla24.dll
+ 2008-11-09 16:41:48 120,684 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla25.dll
+ 2008-11-09 16:41:49 129,846 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla26.dll
+ 2008-11-09 16:41:48 137,536 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla27.dll
+ 2008-11-09 16:41:48 127,798 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla28.dll
+ 2008-11-09 16:41:48 127,936 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla29.dll
+ 2008-11-09 12:49:10 127,936 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla29.exe
+ 2008-11-09 16:41:48 638,976 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla3.dll
+ 2008-11-09 16:41:49 120,945 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla30.dll
+ 2008-11-09 16:41:48 120,858 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla31.dll
+ 2008-11-09 16:41:48 136,000 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla32.dll
+ 2008-11-09 16:41:49 120,860 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla33.dll
+ 2008-11-09 16:41:49 155,648 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla34.dll
+ 2008-11-09 16:41:49 121,200 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla35.dll
+ 2008-11-09 16:41:47 128,191 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla36.dll
+ 2008-11-09 12:49:10 128,191 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla36.exe
+ 2008-11-09 16:41:48 128,005 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla37.dll
+ 2008-11-09 16:41:48 126,019 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla38.dll
+ 2008-11-09 16:41:47 122,373 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla4.dll
+ 2008-11-09 16:41:48 126,060 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla41.dll
+ 2008-11-09 12:49:10 126,060 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla41.exe
+ 2008-11-09 16:41:47 120,951 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla5.dll
+ 2008-11-09 16:41:47 120,664 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla6.dll
+ 2008-11-09 16:41:49 126,116 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla7.dll
+ 2008-11-09 16:41:48 120,942 ----a-w c:\windows\A239B0C1C4874BCFAE789B414ECBF7F3.TMP\WiseCustomCalla9.dll
- 2008-07-31 18:16:44 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-11-15 17:11:51 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2008-07-31 18:16:45 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-11-15 17:11:51 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2008-07-31 18:16:46 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-11-15 17:11:51 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2008-07-31 18:16:39 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-15 17:11:52 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-07-31 18:16:46 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-11-15 17:11:52 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2008-07-31 18:16:47 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-11-15 17:11:52 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2008-07-31 18:16:48 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-11-15 17:11:53 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2008-07-31 18:16:48 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-11-15 17:11:53 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2008-07-31 18:16:44 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-11-15 17:11:50 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-10-24 11:21:09 455,296 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2008-11-12 08:43:25 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
- 2005-03-18 15:23:10 53,248 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2005-03-18 16:23:10 53,248 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
- 2005-03-18 15:23:10 12,800 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
+ 2005-03-18 16:23:10 12,800 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
- 2005-03-18 15:23:14 473,600 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
+ 2005-03-18 16:23:14 473,600 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
- 2005-03-18 15:23:10 145,920 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
+ 2005-03-18 16:23:10 145,920 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
- 2005-03-18 15:23:10 159,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
+ 2005-03-18 16:23:10 159,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
- 2005-03-18 15:23:14 364,544 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
+ 2005-03-18 16:23:14 364,544 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
- 2005-03-18 15:23:12 178,176 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
+ 2005-03-18 16:23:12 178,176 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
- 2005-03-18 15:23:14 223,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2005-03-18 16:23:14 223,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
- 2008-04-14 17:20:39 1,306,624 -c----w c:\windows\system32\dllcache\msxml6.dll
+ 2008-09-10 01:15:56 1,307,648 -c----w c:\windows\system32\dllcache\msxml6.dll
- 2008-10-07 19:19:40 16,721,856 ----a-w c:\windows\system32\MRT.exe
+ 2008-11-04 00:10:25 17,396,160 ----a-w c:\windows\system32\MRT.exe
+ 2007-03-15 11:00:36 466,432 ----a-w c:\windows\system32\SkanerOnline.dll
+ 2007-01-19 08:40:42 89,088 ----a-w c:\windows\system32\SkanerOnlineUninstall.exe
- 2007-11-30 11:21:28 19,320 ------w c:\windows\system32\spmsg.dll
+ 2008-07-08 13:20:04 19,320 ------w c:\windows\system32\spmsg.dll
+ 2008-09-30 15:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-09-30 15:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
.
-- Migawka wyzerowana --
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 93184]
"Spik"="c:\program files\Spik\Spik.exe" [2008-02-20 181736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 222608]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-10-26 229376]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 93184]
c:\documents and settings\Mikis\Menu Start\Programy\Autostart\
Xfire.lnk - c:\program files\Xfire\xfire.exe [2008-10-30 3173712]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 107520]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2008-11-03 745472]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.divxa32"= divxa32.acm
"VIDC.ACDV"= ACDV.dll
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\UnrealTournament\\NetGamesUSA.com\\ngWorldStats\\bin\\ngWorldStats.exe"=
"c:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\reader_sl.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\RocketDock\\RocketDock.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"=
"c:\\Program Files\\Spik\\Spik.exe"=
"c:\\Program Files\\RALINK\\Common\\RaUI.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\WINDOWS\\system32\\Ati2evxx.exe"=
"c:\\Program Files\\LClock\\lclock.exe"=
"c:\\Documents and Settings\\Mikis\\Pulpit\\gmer\\gmer.exe"=
"c:\\WINDOWS\\system32\\ctfmon.exe"=
"c:\\WINDOWS\\SOUNDMAN.EXE"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\opqmoj.sys []
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S0 St320hg;St320hg;c:\windows\system32\DRIVERS\st320hg.sys [2002-09-12 85696]
S3 SNPP106;PC Camera (6029 CIF);c:\windows\system32\DRIVERS\snpp106.sys [2008-02-21 239488]
.
Zawartość folderu 'Zaplanowane zadania'
2008-11-11 c:\windows\Tasks\At1.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-16 c:\windows\Tasks\At10.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At11.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-14 c:\windows\Tasks\At12.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At13.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At14.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At15.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At16.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At17.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At18.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At19.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-11 c:\windows\Tasks\At2.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At20.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At21.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At22.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At23.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-15 c:\windows\Tasks\At24.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-11 c:\windows\Tasks\At3.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-11 c:\windows\Tasks\At4.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-11 c:\windows\Tasks\At5.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-11 c:\windows\Tasks\At6.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-11 c:\windows\Tasks\At7.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-14 c:\windows\Tasks\At8.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
2008-11-14 c:\windows\Tasks\At9.job
- c:\windows\system32\a74LJ7bQ.exe [2008-11-11 13:08]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-Orb - c:\program files\Winamp Remote\bin\OrbTray.exe
.
------- Skan uzupełniający -------
.
FireFox -: Profile - c:\documents and settings\Vader\Dane aplikacji\Mozilla\Firefox\Profiles\cekm4dtp.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.onet.pl
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npcnmozillainterface.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npOggX.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npwpk.dll
FF -: plugin - c:\program files\Spik\mozilla\npwpk.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-16 09:48:54
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySql]
"ImagePath"="c:\program files\usr/MYSQL/bin/mysqld.exe"
.
Czas ukończenia: 2008-11-16 9:53:38
ComboFix-quarantined-files.txt 2008-11-16 08:52:39
ComboFix2.txt 2008-11-08 18:59:51
ComboFix3.txt 2008-11-08 17:35:28
Przed: 3 134 902 272 bajtów wolnych
Po: 3,471,503,360 bajtów wolnych
374 --- E O F --- 2008-11-12 08:47:49