
ComboFix 08-12-15.08 - snajper 2008-12-16 20:25:49.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.2047.1278 [GMT 1:00]
Uruchomiony z: c:\documents and settings\walek\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
[color=RED][b]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/b][/color]
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-16 do 2008-12-16 )))))))))))))))))))))))))))))))
.
2008-12-16 19:42 . 2008-12-16 19:42 <DIR> d-------- c:\windows\LastGood
2008-12-16 19:38 . 2008-12-16 19:42 <DIR> d-------- c:\program files\EsetOnlineScanner
2008-11-28 21:13 . 2008-11-28 21:13 <DIR> d-------- c:\program files\Microsoft.NET
2008-11-26 14:03 . 2008-11-26 14:03 <DIR> d-------- c:\program files\SAMSUNG
2008-11-26 14:03 . 2005-08-17 08:46 93,872 --a------ c:\windows\system32\drivers\sscdmdm.sys
2008-11-26 14:03 . 2005-08-17 08:45 58,352 --a------ c:\windows\system32\drivers\sscdbus.sys
2008-11-26 14:03 . 2005-08-17 08:46 8,272 --a------ c:\windows\system32\drivers\sscdmdfl.sys
2008-11-26 14:03 . 2005-08-17 08:47 6,176 --a------ c:\windows\system32\drivers\sscdcmnt.sys
2008-11-26 14:03 . 2005-08-17 08:47 6,176 --a------ c:\windows\system32\drivers\sscdcm.sys
2008-11-26 14:03 . 2005-08-17 08:44 5,840 --a------ c:\windows\system32\drivers\sscdwhnt.sys
2008-11-26 14:03 . 2005-08-17 08:44 5,840 --a------ c:\windows\system32\drivers\sscdwh.sys
2008-11-25 21:49 . 2008-11-25 21:49 <DIR> d-------- c:\program files\Windows Media Connect 2
2008-11-25 21:43 . 2008-11-25 21:43 <DIR> d-------- c:\windows\system32\LogFiles
2008-11-25 21:43 . 2008-11-25 21:46 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-11-25 21:15 . 2008-12-06 13:14 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-11-25 21:14 . 2008-11-25 21:14 <DIR> d-------- c:\program files\Windows Mobile Device Handbook
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-15 17:57 --------- d-----w c:\documents and settings\snajper\Dane aplikacji\foobar2000
2008-12-14 10:58 31,504 ----a-w c:\windows\system32\drivers\cmdhlp.sys
2008-12-14 10:58 147,192 ----a-w c:\windows\system32\guard32.dll
2008-12-14 10:57 101,776 ----a-w c:\windows\system32\drivers\cmdguard.sys
2008-12-03 22:10 --------- d-----w c:\documents and settings\snajper\Dane aplikacji\OpenOffice.org2
2008-11-25 22:47 --------- d-----w c:\documents and settings\snajper\Dane aplikacji\uTorrent
2008-11-11 20:13 --------- d-----w c:\documents and settings\snajper\Dane aplikacji\Skype
2008-11-11 18:07 --------- d-----w c:\documents and settings\snajper\Dane aplikacji\skypePM
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:42 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:33 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-03 10:04 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-04-21 08:41 32 ----a-w c:\documents and settings\All Users\Dane aplikacji\ezsid.dat
2008-05-08 19:03 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\MSHist012008050820080509\index.dat
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="d:\peerguardian2\pg2.exe" [2005-09-18 1421824]
"AutoConnect"="d:\autoconnect\AutoConnect.exe" [2004-08-28 295424]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Gadu-Gadu"="d:\gadu-gadu\gg.exe" [2005-03-31 790528]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"COMODO Firewall Pro"="d:\comodo\Firewall\cfp.exe" [2008-12-14 1797880]
"avgnt"="d:\avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-17 262401]
"BtTray"="d:\bs\BtTray.exe" [2007-09-10 258134]
"Adobe Reader Speed Launcher"="d:\acrobate\Reader\Reader_sl.exe" [2008-01-11 39792]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-23 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"BOC-427"="d:\boclean\BOC427.exe" [2008-07-14 351480]
"COMODO Internet Security"="d:\comodo\Firewall\cfp.exe" [2008-12-14 1797880]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 c:\windows\RTHDCPL.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-03-16 962660]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKLM\~\startupfolder\C:^Documents and Settings^snajper^Menu Start^Programy^Autostart^konnekt.lnk]
path=c:\documents and settings\snajper\Menu Start\Programy\Autostart\konnekt.lnk
backup=c:\windows\pss\konnekt.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 39792 d:\acrobate\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-05-08 20:10 289088 c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-14 21:51 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator]
--a------ 2008-01-15 16:09 6290944 d:\tlen.pl\tlen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 01:41 1626112 c:\windows\system32\nwiz.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2008-03-16 101776]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2008-03-16 31504]
R2 BOCore;BOCore;d:\boclean\BOCORE.exe [2008-03-16 73472]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1ff00899-271c-11dd-bbec-4d6564696130}]
\Shell\Auto\command - J:\wupdmgr.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wupdmgr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d73a81f7-6fc7-11dd-bc73-4d6564696130}]
\Shell\Auto\command - I:\wupdmgr.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wupdmgr.exe
*Newly Created Service* - PGFILTER
*Newly Created Service* - PROCEXP90
.
- - - - USUNIĘTO PUSTE WPISY - - - -
MSConfigStartUp-Alcmtr - ALCMTR.EXE
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.google.pl/
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
TCP: {09064AF1-34FF-4AFC-BA7E-451A1EFECC9B} = 194.204.159.1 217.98.63.164
FF - ProfilePath - c:\documents and settings\snajper\Dane aplikacji\Mozilla\Firefox\Profiles\uklka42p.default\
FF - prefs.js: browser.startup.homepage - forum.programosy.pl|forum.centrumse.pl|egielda.com.pl/|skforum.nazwa.pl/|google.pl
FF - plugin: c:\program files\DNA\plugins\npbtdna.dll
FF - plugin: d:\acrobate\Reader\browser\nppdf32.dll
FF - plugin: d:\real alternative\browser\plugins\nppl3260.dll
FF - plugin: d:\real alternative\browser\plugins\nprpjplug.dll
.
.
------- Skojarzenia plików -------
.
txtfile=c:\windows\NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-16 20:26:47
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'lsass.exe'(908)
c:\windows\system32\nvappfilter.dll
.
Czas ukończenia: 2008-12-16 20:27:19
ComboFix-quarantined-files.txt 2008-12-16 19:27:14
Przed: 11 176 710 144 bajtów wolnych
Po: 11,301,556,224 bajtów wolnych
174 --- E O F --- 2008-12-11 21:43:38
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 7 gości