
- Kod: Zaznacz wszystko
ComboFix 08-10-22.05 - DAREK 2008-10-23 10:57:30.11 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.58 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\DAREK\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
[color=RED][b]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((( Pliki utworzone od 2008-09-23 do 2008-10-23 )))))))))))))))))))))))))))))))
.
2008-10-23 09:55 . 2008-10-22 23:40 262,144 --a------ C:\Program Files\Uninstall Spy Blocker.dll
2008-10-23 00:24 . 2008-10-23 00:24 0 --a------ C:\rollback.ini
2008-10-22 23:36 . 2008-10-22 23:36 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\MailFrontier
2008-10-22 23:35 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-10-22 23:35 . 2008-10-23 09:26 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-10-22 23:31 . 2008-10-23 10:02 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-10-18 19:51 . 2005-07-20 12:48 59,904 --a------ C:\WINDOWS\system32\zlib.dll
2008-10-12 20:29 . 2008-10-12 20:32 32 --a------ C:\WINDOWS\NSGSLampPost.INI
2008-09-27 21:22 . 2008-09-27 21:22 <DIR> d-------- C:\Documents and Settings\DAREK\Dane aplikacji\Reflexive
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-23 09:03 196 ----a-w C:\WINDOWS\system32\drivers\ALCICH.DAT
2008-10-18 18:00 --------- d-----w C:\Program Files\Gadu-Gadu
2008-10-12 18:26 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP
2008-10-05 18:56 --------- d-----w C:\Program Files\Opera
2008-09-04 09:12 225,280 ----a-w C:\Program Files\Uninstall My Global Search Bar.dll
2008-09-01 18:03 --------- d-----w C:\Program Files\Enigma Software Group
2008-08-30 19:26 --------- d-----w C:\Program Files\Avira
2007-04-30 14:51 55 ----a-w C:\Documents and Settings\DAREK\FIX.BAT
2006-03-05 17:13 5 --sha-w C:\WINDOWS\DLLArchive\25EB09FD_bfcbdeafcbd_k.dll
2006-10-07 21:43 21 --sha-w C:\WINDOWS\DLLArchive\25EB09FD_dpwttaxp.dll
2006-10-07 21:43 14 --sha-w C:\WINDOWS\DLLArchive\25EB09FD_mswtpaxp.dll
2006-10-07 22:00 2 --sha-w C:\WINDOWS\DLLArchive\25EB09FD_verwttxp.dll
2006-10-07 21:43 14 --sha-w C:\WINDOWS\DLLArchive\80045267_mswtpdxp.dll
2006-10-07 22:00 21 --sha-w C:\WINDOWS\DLLArchive\80045267_prwttrxp.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"AtiPTA"="atiptaxx.exe" [2001-09-14 C:\WINDOWS\system32\atiptaxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rfagent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
--a------ 2008-09-22 15:56 1849032 C:\Program Files\Gadu-Gadu\gg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\PROGRAMY\\Emule\\emule.exe"=
"D:\\Teresa\\KAPITAN PAZUR\\CLAW.EXE"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"D:\\PROGRAMY\\Bear share\\BearShare.exe"=
"C:\\Program Files\\Opera\\Opera.exe"=
S0 IoloFilter;IoloFilter;C:\WINDOWS\system32\drivers\IoloFltr.sys [ ]
S3 KS-959;MA-620 USB Infrared Adapter;C:\WINDOWS\system32\DRIVERS\KS-959.sys [2005-10-22 19034]
S3 ptiusbf;PTI USB Filter;C:\WINDOWS\system32\DRIVERS\PTIUSBF.SYS [2001-04-14 22474]
.
Zawartość folderu 'Zaplanowane zadania'
2008-09-26 C:\WINDOWS\Tasks\1-Click Maintenance.job
- D:\PROGRAMY\TUNE UP\SystemOptimizer.exe [2005-09-21 22:35]
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\DAREK\Dane aplikacji\Mozilla\Firefox\Profiles\frlusp7z.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.onet.pl/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-23 11:05:35
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\D-Link AirPlus\AIRPLUS.EXE
.
**************************************************************************
.
Czas ukończenia: 2008-10-23 11:14:01 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-10-23 09:13:34
ComboFix2.txt 2008-09-26 17:53:01
Przed: 4,843,200,512 bajtów wolnych
Po: 4,818,518,016 bajtów wolnych
113 --- E O F --- 2008-08-13 09:07:08
- Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 11:32, on 2008-10-23
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\D-Link AirPlus\AirPlus.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\Opera.exe
D:\PROGRAMY\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - D:\PROGRAMY\TUNE UP\WinStylerThemeSvc.exe
Witam-prosze o sprawdzenie loga z comboFix-a-ostatnio cos komp. mi spowolnil prace i czyscilem rejestr roznymi progr. oraz uruchomilem combofix-prosze o odpowiedz czy wszystko ok oraz ew. podpowiedzi co ew. usunac i jak-Dzieki za pomoc i pozdrawiam