
Ostatnio musiałem przenieść coś z laptopa na stacjonarny i ku swemu zdumieniu AVG na stacjonarnym wskazał mi wirusa, choć pen-drive został sfortmatowany przed przenoszeniem. Zrobiłem format, z powrotem wetknąłem pendriva do laptopa i wróciłem na stacjonarny... niespodzianka, znowu wirus. Oto logi:
- Kod: Zaznacz wszystko
ComboFix 09-01-05.02 - Piotr 2009-01-05 23:18:50.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.3070.2393 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Piotr\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((( Pliki utworzone od 2008-12-05 do 2009-01-05 )))))))))))))))))))))))))))))))
.
2009-01-05 22:52 . 2009-01-05 23:12 <DIR> d-------- C:\HijackThis
2009-01-05 20:44 . 2009-01-05 20:49 <DIR> d-------- C:\C4
2009-01-05 20:33 . 2002-12-08 16:29 208,896 --a------ c:\windows\system32\HDK3CTNT.dll
2009-01-05 20:33 . 1994-12-05 22:00 188,960 --a------ c:\windows\system32\WINGDE.DLL
2009-01-05 20:33 . 2002-07-11 16:17 173,056 --a------ c:\windows\system32\cncs32.dll
2009-01-05 20:33 . 2003-03-21 18:27 133,200 --a------ c:\windows\system32\CNCS.dll
2009-01-05 20:33 . 2002-12-08 16:29 114,176 --a------ c:\windows\system32\HDK3ANIM.dll
2009-01-05 20:33 . 1994-12-05 22:00 92,208 --a------ c:\windows\system32\WING.DLL
2009-01-05 20:33 . 1994-12-05 22:00 12,800 --a------ c:\windows\system32\WING32.DLL
2009-01-05 20:33 . 1994-12-05 22:00 6,736 --a------ c:\windows\system32\WINGDIB.DRV
2009-01-05 20:33 . 2002-12-08 16:29 5,647 --a------ c:\windows\system32\HDK3CRYP.dll
2009-01-05 20:33 . 1994-12-05 22:00 5,024 --a------ c:\windows\system32\WINGPAL.WND
2009-01-05 18:20 . 2009-01-05 18:20 <DIR> d-------- c:\program files\Fantasy Grounds II
2009-01-02 12:20 . 2009-01-02 12:36 <DIR> d-------- C:\Fraps
2009-01-02 12:20 . 2009-01-02 13:06 <DIR> d-a------ c:\documents and settings\All Users\Dane aplikacji\TEMP
2009-01-01 17:54 . 2009-01-01 17:54 <DIR> d-------- c:\windows\A7E07C2B2220441587E3784D5814BC93.TMP
2009-01-01 17:53 . 2009-01-01 17:55 <DIR> d-------- c:\windows\NV36043136.TMP
2009-01-01 17:53 . 2008-12-08 17:42 201,616 --a------ c:\windows\system32\nvapps.nvb
2008-12-30 14:14 . 2008-12-30 14:14 <DIR> d-------- C:\Freelancer
2008-12-27 18:51 . 2008-04-14 18:20 221,184 --a------ c:\windows\system32\wmpns.dll
2008-12-25 21:53 . 2008-12-25 21:53 <DIR> d-------- c:\program files\Common Files\BioWare
2008-12-25 21:32 . 2008-12-25 21:54 <DIR> d-------- C:\Mass Effect
2008-12-25 15:12 . 2008-12-25 15:18 8 --a------ c:\windows\system32\nvModes.dat
2008-12-25 15:00 . 2008-12-25 15:00 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\nView_Profiles
2008-12-21 20:44 . 2008-12-21 20:44 37 --a------ c:\windows\Viewer.ini
2008-12-21 20:02 . 2008-12-23 22:59 <DIR> d-------- C:\CSTORM
2008-12-20 22:47 . 2008-12-20 22:47 <DIR> d-------- c:\program files\Sony
2008-12-20 18:22 . 2008-12-20 19:07 <DIR> d-------- C:\C4_manual
2008-12-17 22:01 . 2008-12-17 22:01 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\MiKTeX
2008-12-17 21:57 . 2008-12-17 22:00 <DIR> d-------- c:\program files\MiKTeX 2.7
2008-12-17 21:27 . 2008-12-17 21:32 <DIR> d-------- C:\LaTeX
2008-12-16 15:51 . 2008-12-16 15:52 <DIR> d-------- c:\windows\system32\NtmsData
2008-12-15 17:52 . 2008-12-15 17:52 <DIR> d-------- c:\program files\GoldWave
2008-12-15 17:48 . 2008-12-15 17:48 0 --a------ c:\windows\sam7_E.INI
2008-12-14 19:55 . 2008-12-14 19:55 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Avg8
2008-12-14 15:25 . 2009-01-03 19:57 <DIR> d-------- C:\Original War
2008-12-08 22:05 . 2008-12-08 22:35 <DIR> d-------- c:\documents and settings\Piotr\Dane aplikacji\Mount&Blade
2008-12-08 22:03 . 2008-12-08 22:06 <DIR> d-------- C:\Mount&Blade
2008-12-08 22:02 . 2008-11-03 19:10 399,385,059 --a------ C:\mountandblade_1011_setup.exe
2008-12-07 21:13 . 2008-12-07 21:13 <DIR> d-------- c:\documents and settings\Piotr\Dane aplikacji\Datarescue
2008-12-07 21:09 . 2008-12-07 21:10 <DIR> d-------- c:\program files\IDA
2008-12-07 17:41 . 2009-01-05 21:34 <DIR> d-------- C:\Czarek - Piotrek - Jedi
2008-12-07 14:00 . 2008-12-07 14:22 31 --a------ c:\windows\progress
2008-12-05 23:45 . 2008-12-07 13:38 <DIR> d-------- c:\program files\Common Files\Real
2008-12-05 15:50 . 2008-12-05 15:50 <DIR> d-------- c:\program files\Guitar Pro 5
2008-12-05 15:04 . 2008-10-27 18:37 4,499,280 --a------ c:\windows\system32\D3dx9d_40.dll
2008-12-05 15:04 . 2008-10-27 18:37 906,576 --a------ c:\windows\system32\xaudioD2_3.dll
2008-12-05 15:04 . 2008-10-27 18:36 496,464 --a------ c:\windows\system32\D3DX10d_40.dll
2008-12-05 15:04 . 2008-10-27 18:39 360,784 --a------ c:\windows\system32\XactEngineA3_3.dll
2008-12-05 15:04 . 2008-10-27 18:39 286,032 --a------ c:\windows\system32\XactEngineD3_3.dll
2008-12-05 15:04 . 2008-10-27 18:39 123,216 --a------ c:\windows\system32\XAPOFXD1_2.dll
2008-12-05 15:04 . 2008-10-27 18:38 47,440 --a------ c:\windows\system32\X3DAudioD1_5.dll
2008-12-05 15:03 . 2008-10-10 04:52 4,379,984 --a------ c:\windows\system32\D3DX9_40.dll
2008-12-05 15:03 . 2008-10-10 04:52 2,036,576 --a------ c:\windows\system32\D3DCompiler_40.dll
2008-12-05 15:03 . 2008-10-27 10:04 514,384 --a------ c:\windows\system32\XAudio2_3.dll
2008-12-05 15:03 . 2008-10-10 04:52 452,440 --a------ c:\windows\system32\d3dx10_40.dll
2008-12-05 15:03 . 2008-10-27 10:04 235,856 --a------ c:\windows\system32\xactengine3_3.dll
2008-12-05 15:03 . 2008-10-27 10:04 70,992 --a------ c:\windows\system32\XAPOFX1_2.dll
2008-12-05 15:03 . 2008-10-27 10:04 23,376 --a------ c:\windows\system32\X3DAudio1_5.dll
2008-12-05 15:01 . 2008-12-05 15:04 <DIR> d-------- c:\program files\Microsoft DirectX SDK (November 2008)
2008-12-05 15:01 . 2008-12-05 15:01 119,120 --a------ c:\windows\dxsdkuninst.exe
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-05 22:23 --------- d-----w c:\program files\DNA
2009-01-05 22:23 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\DNA
2009-01-05 22:02 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\Dropbox
2009-01-05 21:59 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\BitTorrent
2009-01-04 19:19 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\FileZilla
2009-01-01 16:54 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-01-01 15:27 --------- d-----w c:\program files\Diablo II
2008-12-26 19:51 --------- d-----w c:\program files\Winamp
2008-12-25 14:41 --------- d-----w c:\program files\Heroes Chronicles
2008-12-24 22:58 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\Thinstall
2008-12-23 15:50 --------- d-----w c:\program files\FXhome VisionLab Studio
2008-12-19 21:24 --------- d-----w c:\program files\Wiedźmin
2008-12-14 14:52 --------- d-----w c:\program files\Microsoft Silverlight
2008-12-08 16:42 6,179,744 ----a-w c:\windows\system32\drivers\nv4_mini.sys
2008-12-05 14:02 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2008-12-05 14:00 --------- d-----w c:\program files\AGEIA Technologies
2008-12-04 19:08 --------- d-----w c:\program files\Twierdza
2008-12-04 17:49 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-04 14:54 --------- d-----w c:\program files\RADVideo
2008-11-30 14:08 --------- d-----w c:\program files\eMule
2008-11-29 14:25 137,825,996 ----a-w C:\C4Manual.zip
2008-11-28 15:58 --------- d-----w c:\program files\MakeHuman 0.9.1 RC1
2008-11-28 15:52 --------- d-----w c:\program files\Java
2008-11-28 15:44 --------- d-----w c:\program files\Feeling Software
2008-11-28 13:56 --------- d-----w c:\program files\Common Files\Softimage
2008-11-28 13:56 --------- d-----w c:\program files\Common Files\Avid
2008-11-23 21:16 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Bimesoft
2008-11-22 19:50 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\Apple Computer
2008-11-22 19:45 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\World Machine 2 Basic
2008-11-22 19:06 --------- d-----w c:\program files\QuickTime
2008-11-22 19:06 --------- d-----w c:\program files\Common Files\Apple
2008-11-22 19:06 --------- d-----w c:\program files\Apple Software Update
2008-11-22 19:06 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Apple Computer
2008-11-22 19:06 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Apple
2008-11-20 22:00 --------- d-----w c:\program files\Spider-Man - Web of Shadows
2008-11-20 11:26 --------- d-----w c:\program files\DragonRiders
2008-11-17 15:05 --------- d-----w c:\program files\Heroes of Might and Magic III
2008-11-13 11:41 --------- d-----w c:\program files\Common Files\3DO Shared
2008-11-11 17:56 --------- d-----w c:\program files\FLV to AVI Converter
2008-11-11 17:50 --------- d-----w c:\program files\Free Video Converter
2008-11-11 17:39 --------- d-----w c:\program files\Flash Decompiler Trillix
2008-11-10 18:26 --------- d-----w c:\documents and settings\Piotr\Dane aplikacji\CyberLink
2008-11-10 18:25 --------- d-----w c:\program files\CyberLink
2008-11-10 18:25 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\CyberLink
2008-11-08 18:24 --------- d-----w c:\program files\Microsoft SQL Server
2008-11-08 18:23 --------- d-----w c:\program files\Microsoft.NET
2008-11-08 18:16 --------- d-----w c:\program files\Microsoft Visual Studio 9.0
2008-11-08 18:15 --------- d-----w c:\program files\Microsoft Web Designer Tools
2008-11-07 16:28 2,829 ----a-w c:\windows\DIIUnin.pif
2008-11-07 16:28 106,496 ----a-w c:\windows\DIIUnin.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2008-09-07 08:20 143360 --a------ c:\program files\Dropbox\DropboxExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2008-09-07 08:20 143360 --a------ c:\program files\Dropbox\DropboxExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2008-09-07 08:20 143360 --a------ c:\program files\Dropbox\DropboxExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-03-28 18:59 2953216 --a------ c:\program files\Protector Suite QL\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-03-28 18:59 2953216 --a------ c:\program files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"AlcoholAutomount"="d:\alcohol soft\Alcohol 120\axcmd.exe" [2008-03-20 217544]
"Google Update"="c:\documents and settings\Piotr\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" [2008-11-14 133104]
"avp"="c:\recycler\S-1-5-21-7107284543-5583942833-164940287-3107\hdav.exe" [2008-12-15 72192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-08 13594624]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"WLSS"="c:\program files\Compal\Wireless Select Switch\WLSS.exe" [2007-04-23 190000]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2006-12-29 569344]
"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" [2007-03-28 49168]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-06-01 823296]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-06-01 974848]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 185896]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"NvMediaCenter"="c:\windows\system32\NVMCTRAY.DLL" [2008-12-08 86016]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-28 136600]
"nwiz"="nwiz.exe" [2008-12-08 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 c:\windows\RTHDCPL.exe]
c:\documents and settings\Piotr\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
Dropbox.lnk - c:\program files\Dropbox\Dropbox.exe [2008-09-26 24096981]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-12-11 561213]
Monitor Apache Servers.lnk - c:\program files\Apache Group\Apache2\bin\ApacheMonitor.exe [2008-01-17 41042]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2008-10-27 106496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-03-28 18:46 90112 c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"d:\\Programming\\zoidcom\\samples\\bin\\mingw\\ex00_connect_server.exe"=
"d:\\Programming\\zoidcom\\samples\\bin\\mingw\\ex01_lanbroadcast_server.exe"=
"d:\\Programming\\zoidcom\\samples\\bin\\mingw\\ex02_zoidlevel_server.exe"=
"d:\\Programming\\zoidcom\\samples\\bin\\mingw\\ex03_object_replication_server.exe"=
"d:\\Programming\\zoidcom\\samples\\bin\\mingw\\ex04_object_deletion_server.exe"=
"d:\\Programming\\zoidcom\\samples\\bin\\mingw\\ex08_file_transfer_server.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2009\\3dsmax.exe"=
"c:\\Program Files\\FantasyGrounds\\FantasyGrounds.exe"=
"e:\\ProjectsC#\\ServerConsole\\bin\\Release\\ServerConsole.exe"=
"e:\\ProjectsC#\\ChatTest\\bin\\Release\\ChatTest.exe"=
"d:\\Programming\\Delta3D\\build\\bin\\testEchoServer.exe"=
"d:\\Programming\\Delta3D\\build\\bin\\testNetwork.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Documents and Settings\\Piotr\\Ustawienia lokalne\\Dane aplikacji\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Piotr\\Ustawienia lokalne\\Dane aplikacji\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"e:\\Projects XNA\\lidgren-network\\Samples\\ChatServer\\bin\\Release\\ChatServer.exe"=
"e:\\Projects XNA\\lidgren-network\\Samples\\ImageServer\\bin\\Release\\ImageServer.exe"=
"e:\\Projects XNA\\lidgren-network\\Samples\\LargePacketServer\\bin\\Release\\LargePacketServer.exe"=
"e:\\Projects XNA\\Adventurer\\AdventurerMasterServer\\bin\\Release\\AdventurerMasterServer.exe"=
"e:\\Projects XNA\\lidgren-network\\Samples\\StressServer\\bin\\Release\\StressServer.exe"=
"c:\\Program Files\\Spider-Man - Web of Shadows\\image\\pc\\Spider-Man Web of Shadows.exe"=
"c:\\WinHTTrack\\WinHTTrack.exe"=
"d:\\Wesnoth\\wesnothd.exe"=
"d:\\Softimage\\XSI_7.0\\Application\\bin\\XSI.exe"=
"d:\\Programming\\Esenthel\\EsenthelEngineSDK\\Tutorials\\Tutorials.exe"=
"c:\\Program Files\\IDA\\idag.exe"=
"c:\\Program Files\\IDA\\idag64.exe"=
"c:\\Original War\\OwarFull.dll"=
"c:\\Program Files\\Heroes of Might and Magic III\\Heroes3.exe"=
"c:\\CSTORM\\CSTORM.exe"=
"c:\\Mass Effect\\Binaries\\MassEffect.exe"=
"c:\\Mass Effect\\MassEffectLauncher.exe"=
"c:\\Program Files\\Fantasy Grounds II\\FantasyGrounds.exe"=
R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [2008-10-01 9856]
R4 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [2008-03-09 65536]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2008-07-11 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-07-10 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fbe46db5-da60-11dd-a1e7-001cbf1d9ff5}]
\Shell\AutoRun\command - G:\USBNB.exe
.
Zawartość folderu 'Zaplanowane zadania'
2009-01-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1482476501-839522115-1004.job
- c:\documents and settings\Piotr\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2008-11-14 23:23]
.
.
------- Skan uzupełniający -------
.
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Wyślij do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Piotr\Dane aplikacji\Mozilla\Firefox\Profiles\c2gkrnfg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/
FF - plugin: c:\documents and settings\Piotr\Dane aplikacji\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Piotr\Ustawienia lokalne\Dane aplikacji\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30401.0.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: d:\adobe\Reader 8.0\Reader\browser\nppdf32.dll
FF - plugin: d:\k-lite codec pack\Real\browser\plugins\nppl3260.dll
FF - plugin: d:\k-lite codec pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-05 23:23:35
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(920)
c:\windows\system32\vrlogon.dll
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homepass.dll
c:\program files\Protector Suite QL\bio.dll
c:\program files\Protector Suite QL\crypto.dll
c:\program files\Protector Suite QL\remote.dll
c:\windows\system32\tabhook.dll
- - - - - - - > 'lsass.exe'(976)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infra.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Apache Group\Apache2\bin\Apache.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Apache Group\Apache2\bin\Apache.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\spm\spmdib.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
d:\alcohol soft\Alcohol 52\StarWind\StarWindServiceAE.exe
c:\windows\system32\Tablet.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\Protector Suite QL\psqltray.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\spool\drivers\w32x86\3\WrtProc.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Czas ukończenia: 2009-01-05 23:26:37 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-01-05 22:26:34
Przed: 728 678 400 bajtów wolnych
Po: 1,681,588,224 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
d:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
330 --- E O F --- 2008-12-27 10:41:05
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:29:48, on 2009-01-05
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\spm\spmdib.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
D:\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Compal\Wireless Select Switch\WLSS.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Dropbox\Dropbox.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [WLSS] C:\Program Files\Compal\Wireless Select Switch\WLSS.exe
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [avp] C:\RECYCLER\S-1-5-21-7107284543-5583942833-164940287-3107\hdav.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Dropbox.lnk = C:\Program Files\Dropbox\Dropbox.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Wyślij do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Flash Decompiler Trillix\iebt.dll
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Flash Decompiler Trillix\iebt.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache2 - Apache Software Foundation - C:\Program Files\Apache Group\Apache2\bin\Apache.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit (mi-raysat_3dsMax2009_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\spm\spmdib.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
--
End of file - 9783 bytes