ComboFix 08-10-25.01 - xp 2008-10-26 20:31:33.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.105 [GMT 1:00]
Uruchomiony z: C:\Program Files\ComboFix.exe
* Utworzono nowy punkt przywracania
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!.
((((((((((((((((((((((((( Pliki utworzone od 2008-09-26 do 2008-10-26 )))))))))))))))))))))))))))))))
.
2008-10-26 20:28 . 2008-10-26 20:25 2,995,771 -ra------ C:\Program Files\ComboFix.exe
2008-10-26 20:18 . 2008-10-26 20:18 <DIR> d-------- C:\!FixIEDef
2008-10-26 20:18 . 2008-10-26 20:18 478,719 --a------ C:\Program Files\FixIEDef.exe
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 19:21 6,967 ----a-w C:\Program Files\hijackthis.log
2008-10-26 17:18 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-10-25 06:01 --------- d-----w C:\Program Files\Odkurzacz
2008-10-16 20:33 --------- d-----w C:\Documents and Settings\xp\Dane aplikacji\Skype
2008-10-16 20:32 --------- d-----w C:\Documents and Settings\xp\Dane aplikacji\skypePM
2008-09-18 21:06 1,821,923 ----a-w C:\Program Files\IBANator.(
www.bwportal.pl).zip
2008-09-04 14:32 493 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-09-03 16:54 --------- d-----w C:\Program Files\Winamp
2008-09-02 20:13 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kazaa Lite
2008-07-25 13:54 1,330,904 ----a-w C:\Program Files\ZENStone_PCFW_US_1_06_01.exe
2008-07-25 13:51 13,048,400 ----a-w C:\Program Files\ZENStone_PCApp_CLE_L6_1_51_03.exe
2008-07-16 06:22 7,252,937 ----a-w C:\Program Files\odk11.2.0308setup_[www.programosy.pl].exe
2008-07-15 18:55 1,054,680 ----a-w C:\Program Files\KlipFolio-Install.exe
2008-06-18 18:35 881,896 ----a-w C:\Program Files\cafenews.exe
2008-06-17 21:08 22,411,048 ----a-w C:\Program Files\SkypeSetup.exe
2008-05-01 10:11 812,344 ----a-w C:\Program Files\HJTInstall.exe
2008-05-01 10:11 401,720 ----a-w C:\Program Files\HiJackThis.exe
2008-05-01 10:11 318,369 ----a-w C:\Program Files\HiJackThis.zip
2008-01-03 16:48 6,575,800 ----a-w C:\Program Files\Sunbelt-Personal-Firewall.exe
2007-11-21 19:14 38,899 ----a-w C:\Program Files\SeconfigXP.zip
2007-11-21 18:51 51,232 ----a-w C:\Program Files\wwdc.exe
2007-11-19 20:57 15,374,248 ----a-w C:\Program Files\sdstart.exe
2007-11-19 20:17 5,361,888 ----a-w C:\Program Files\kerio.exe
2007-11-16 12:52 7,037,304 ----a-w C:\Program Files\DjVuBrowserPlugin.exe
2007-11-05 15:39 4,346,704 ----a-w C:\Program Files\gg77.exe
2007-02-15 03:51 56 --sh--r C:\WINDOWS\system32\59C80DF989.sys
2007-02-15 03:51 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
------- Sigcheck -------
2004-08-03 22:14 359040 1745b00fc1141404b28f4b94f69a8871 C:\WINDOWS\system32\dllcache\tcpip.sys
2004-08-03 22:14 359040 1745b00fc1141404b28f4b94f69a8871 C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-14 68856]
"KlipFolio"="C:\Program Files\KlipFolio\KlipFolio.exe" [2008-07-15 1054680]
"Odkurzacz-MCD"="C:\Program Files\Odkurzacz\odk_mcd.exe" [2008-03-03 266240]
"CTZDetec.exe"="C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe" [2008-04-24 368640]
"SoftAuto.exe"="C:\Program Files\Creative\Software Update 3\SoftAuto.exe" [2008-05-28 401408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-08-23 110592]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 7561216]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-27 86016]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-21 761945]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 1065800]
"nwiz"="nwiz.exe" [2006-04-27 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 C:\WINDOWS\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2006-05-16 C:\WINDOWS\SkyTel.exe]
"SMSERIAL"="sm56hlpr.exe" [2006-01-20 C:\WINDOWS\sm56hlpr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 15360]
C:\DOCUME~1\ALLUSE~1\MENUST~1\Programy\AUTOST~1\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-02-15 278528]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xvid"= xvid.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 78416]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 302000]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 72624]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 20560]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 1234480]
R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\WINDOWS\system32\ASNDIS5.SYS [2002-09-09 16269]
R3 SynMini;USB2.0 1.3M Web Cam;C:\WINDOWS\system32\Drivers\SynMini.sys [2005-10-03 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys [2005-10-03 8278]
.
.
------- Skan uzupełniający -------
.
R0 -: HKCU-Main,Start Page = hxxp://onet.pl/
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} - hxxp://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
C:\WINDOWS\Downloaded Program Files\ArcaOnline.inf
C:\WINDOWS\system32\ArcaMicroScanUpdater.exe
C:\WINDOWS\system32\ArcaOnlineUninstall.exe
C:\WINDOWS\system32\ArcaOnline.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-26 20:36:15
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-10-26 20:38:44
ComboFix-quarantined-files.txt 2008-10-26 19:38:35
Przed: 19 334 369 280 bajtów wolnych
Po: 19,354,607,616 bajtów wolnych
123