
Log z Combofix:
- Kod: Zaznacz wszystko
ComboFix 09-02-06.01 - a 2009-02-06 20:26:37.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.447.150 [GMT 1:00]
Uruchomiony z: c:\documents and settings\a\Pulpit\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Utworzono nowy punkt przywracania
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
.
((((((((((((((((((((((((( Pliki utworzone od 2009-01-06 do 2009-02-06 )))))))))))))))))))))))))))))))
.
2009-02-06 20:18 . 2009-02-06 20:18 <DIR> d-------- c:\program files\MoorHunt
2009-02-06 20:16 . 2009-02-06 20:16 <DIR> d-------- c:\windows\system32\pl-PL
2009-02-06 20:14 . 2009-02-06 20:14 <DIR> d-------- c:\windows\system32\XPSViewer
2009-02-06 20:14 . 2009-02-06 20:14 <DIR> d-------- c:\program files\Reference Assemblies
2009-02-06 20:14 . 2009-02-06 20:14 <DIR> d-------- c:\program files\MSBuild
2009-02-06 20:13 . 2009-02-06 20:14 <DIR> d-------- c:\windows\system32\DllCache
2009-02-06 20:13 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2009-02-06 20:11 . 2009-02-06 20:11 <DIR> d-------- c:\program files\MSXML 6.0
2009-02-06 20:10 . 2009-02-06 20:10 <DIR> d-------- c:\program files\K-Lite Codec Pack
2009-02-06 20:06 . 2009-02-06 20:06 <DIR> d-------- c:\program files\NAPI-PROJEKT
2009-02-06 20:06 . 2009-02-06 20:06 <DIR> d-------- c:\program files\ALLPlayer
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-06 19:25 --------- d-----w c:\program files\neostrada tp
2009-02-06 18:47 --------- d-----w c:\program files\Gadu-Gadu
2009-02-06 18:47 --------- d-----w c:\documents and settings\a\Dane aplikacji\Skype
2009-02-06 18:47 --------- d-----w c:\documents and settings\a\Dane aplikacji\Gadu-Gadu
2009-02-06 18:44 --------- d-----w c:\program files\7-Zip
2009-02-06 18:41 --------- d-----w c:\program files\Winamp
2009-02-06 18:38 --------- d-----w c:\program files\Common Files\Skype
2009-02-06 18:38 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Skype
2009-02-06 18:38 --------- d-----r c:\program files\Skype
2009-02-06 18:26 --------- d-----w c:\program files\ESET
2009-02-06 18:26 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\ESET
2009-02-06 18:15 33 ----a-w c:\windows\system32\drivers\adidsl.cfg
2009-02-06 18:15 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-06 18:15 --------- d-----w c:\program files\SAGEM
2009-02-06 18:14 --------- d-----w c:\program files\Java
2009-02-06 18:14 --------- d-----w c:\program files\Common Files\InstallShield
2009-02-06 18:10 14,656 ----a-w c:\windows\gdrv.sys
2009-02-06 18:08 315,392 ----a-w c:\windows\HideWin.exe
2009-02-06 18:08 --------- d-----w c:\program files\Realtek
2009-02-06 18:06 --------- d-----w c:\program files\DIFX
2009-02-06 18:02 --------- d-----w c:\documents and settings\a\Dane aplikacji\InstallShield
2009-02-06 17:55 --------- d-----w c:\program files\Usługi online
2006-12-13 03:12 66,648 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2006-12-13 03:12 54,352 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2006-12-13 03:12 34,928 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2006-12-13 03:12 46,696 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2006-12-13 03:12 172,120 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2008-11-24 869888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-31 86016]
"WOOWATCH"="c:\progra~1\NEOSTR~1\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="c:\progra~1\NEOSTR~1\GestMaj.exe" [2004-10-14 32768]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"nwiz"="nwiz.exe" [2006-10-31 c:\windows\system32\nwiz.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-07-01 34312]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-07-01 468224]
R3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\drivers\e4usbaw.sys [2009-02-06 116992]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [2009-02-06 64000]
--- Inne Usługi/Sterowniki w Pamięci ---
*NewlyCreated* - UMWDF
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.neostrada.pl
IE: { - c:\program files\Messenger\msmsgs.exe
FF - ProfilePath - c:\documents and settings\a\Dane aplikacji\Mozilla\Firefox\Profiles\xvbi6c2g.default\
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 20:27:23
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2009-02-06 20:28:08
ComboFix-quarantined-files.txt 2009-02-06 19:28:06
Przed: 13 746 388 992 bajtów wolnych
Po: 13,832,265,728 bajtów wolnych
106