
- Kod: Zaznacz wszystko
ComboFix 08-12-15.05 - Komputer 2008-12-16 17:37:41.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.2047.1579 [GMT 1:00]
Uruchomiony z: e:\z internetu programy\ComboFix.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-16 do 2008-12-16 )))))))))))))))))))))))))))))))
.
2008-12-16 17:13 . 2008-12-16 17:15 <DIR> d-------- C:\Downloads
2008-12-16 16:52 . 2008-12-16 17:12 <DIR> d-------- C:\totalcmd
2008-12-16 16:52 . 2008-12-16 16:57 730 --a------ c:\windows\wincmd.ini
2008-12-16 16:52 . 2008-08-08 07:04 545 --a------ c:\windows\UC.PIF
2008-12-16 16:52 . 2008-08-08 07:04 545 --a------ c:\windows\RAR.PIF
2008-12-16 16:52 . 2008-08-08 07:04 545 --a------ c:\windows\PKZIP.PIF
2008-12-16 16:52 . 2008-08-08 07:04 545 --a------ c:\windows\PKUNZIP.PIF
2008-12-16 16:52 . 2008-08-08 07:04 545 --a------ c:\windows\NOCLOSE.PIF
2008-12-16 16:52 . 2008-08-08 07:04 545 --a------ c:\windows\LHA.PIF
2008-12-16 16:52 . 2008-08-08 07:04 545 --a------ c:\windows\ARJ.PIF
2008-12-16 16:41 . 2008-12-16 16:41 85,504 -r-hs---- c:\windows\system32\vbsdfe1.dll
2008-12-16 15:38 . 2008-12-16 15:38 <DIR> d-------- c:\documents and settings\Komputer\Dane aplikacji\Ventrilo
2008-12-16 15:36 . 2008-12-16 15:36 <DIR> d-------- c:\program files\Ventrilo
2008-12-16 15:36 . 2008-12-16 15:36 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-16 14:45 . 2008-12-16 14:45 <DIR> d-------- c:\program files\Alwil Software
2008-12-16 14:45 . 2003-03-18 21:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2008-12-16 14:44 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-12-16 14:41 . 2008-12-16 14:41 <DIR> d-------- c:\program files\ABBYY FineReader 5.0 Sprint
2008-12-16 14:38 . 2008-12-16 14:38 100 --a------ c:\windows\lexstat.ini
2008-12-16 14:37 . 2008-12-16 14:39 <DIR> d-------- c:\program files\Lexmark 2200 Series
2008-12-16 14:37 . 2008-12-16 14:37 <DIR> d-------- c:\documents and settings\Komputer\WINDOWS
2008-12-16 14:36 . 2008-12-16 14:36 <DIR> d--h----- c:\windows\msdownld.tmp
2008-12-16 14:35 . 2008-12-16 14:36 <DIR> d-------- c:\windows\system32\pl-pl
2008-12-16 14:30 . 2008-10-16 21:33 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-12-16 14:30 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-12-16 14:30 . 2007-03-08 06:11 1,036,288 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-16 14:30 . 2008-10-16 21:33 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-12-16 14:30 . 2008-10-16 21:33 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-12-16 14:30 . 2008-10-16 21:33 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-12-16 14:30 . 2008-10-16 21:33 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-12-16 14:30 . 2008-10-16 21:33 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-16 14:30 . 2008-10-16 14:11 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-12-16 14:28 . 2008-12-16 14:28 <DIR> d-------- c:\program files\Windows Media Connect 2
2008-12-16 14:27 . 2008-12-16 14:27 <DIR> d-------- c:\windows\system32\LogFiles
2008-12-16 14:27 . 2008-12-16 14:27 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-12-16 14:27 . 2006-09-25 17:58 23,856 --a------ c:\windows\system32\spupdsvc.exe
2008-12-16 14:21 . 2008-12-16 14:21 <DIR> d-------- c:\program files\WinLock
2008-12-16 14:18 . 2008-12-16 14:20 <DIR> d-------- c:\program files\Winamp
2008-12-16 14:18 . 2008-12-16 14:19 <DIR> d-------- c:\documents and settings\Komputer\Dane aplikacji\Winamp
2008-12-16 14:17 . 2008-12-16 17:38 <DIR> d-------- c:\documents and settings\Komputer\Dane aplikacji\Skype
2008-12-16 14:13 . 2008-12-16 14:13 <DIR> d-------- c:\program files\Skype
2008-12-16 14:07 . 2008-12-16 14:07 <DIR> d-------- c:\program files\K-Lite Codec Pack
2008-12-16 14:07 . 2008-09-16 01:14 3,596,288 --a------ c:\windows\system32\qt-dx331.dll
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-16 16:32 --------- d-----w c:\program files\FlashGet
2008-12-16 16:22 85,504 --sh--r c:\windows\system32\vbsdfe0.dll
2008-12-16 15:41 113,878 --sh--r c:\windows\system32\vamsoft.exe
2008-12-16 12:41 --------- d-----w c:\documents and settings\Komputer\Dane aplikacji\Gadu-Gadu
2008-12-16 12:40 --------- d-----w c:\program files\Gadu-Gadu
2008-12-16 12:39 --------- d-----w c:\program files\A4Tech
2008-12-16 12:33 --------- d-----w c:\program files\Microsoft.NET
2008-12-16 12:30 --------- d-----w c:\program files\Common Files\Adobe
2008-12-16 12:29 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-16 12:29 --------- d-----w c:\program files\CyberLink
2008-12-16 12:29 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\CyberLink
2008-12-16 12:28 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-16 12:26 --------- d-----w c:\program files\NeroInstall.bak
2008-12-16 12:26 --------- d-----w c:\documents and settings\Komputer\Dane aplikacji\Nero
2008-12-16 12:25 --------- d-----w c:\program files\Nero
2008-12-16 12:25 --------- d-----w c:\program files\Common Files\Nero
2008-12-16 12:25 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Nero
2008-12-16 12:11 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Creative
2008-12-16 12:09 --------- d-----w c:\program files\Creative
2008-12-16 12:02 --------- d-----w c:\program files\SAGEM
2008-12-16 12:02 --------- d-----w c:\documents and settings\Komputer\Dane aplikacji\InstallShield
2008-12-16 11:23 --------- d-----w c:\program files\microsoft frontpage
2008-12-16 11:22 --------- d-----w c:\program files\Usługi online
2008-10-16 20:33 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-02 09:07 453,152 ----a-w c:\windows\system32\NVUNINST.EXE
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\divx.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
"vamsoft"="c:\windows\system32\vamsoft.exe" [2008-12-16 113878]
"CreativeTaskScheduler"="c:\program files\Creative\Shared Files\CTSched.exe" [2006-11-17 53341]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"Google Update"="c:\documents and settings\Komputer\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe" [2008-12-16 133104]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2006-11-24 20058152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2006-02-17 163840]
"Flashget"="c:\program files\FlashGet\FlashGet.exe" [2007-09-25 2007088]
"0wl"="c:\program files\WinLock\winlock.exe" [2006-03-30 1747968]
"Lexmark 2200 Series"="c:\program files\Lexmark 2200 Series\lxbvbmgr.exe" [2004-02-13 57344]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]
"P17Helper"="P17.dll" [2005-05-03 c:\windows\system32\P17.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-16 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-16 20560]
R3 MouseCap;MouseCapture Driver;c:\windows\system32\Drivers\MouseCap.sys [2005-08-08 6640]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys []
.
Zawartość folderu 'Zaplanowane zadania'
2008-12-16 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Komputer\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2008-12-16 13:31]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.google.pl/
mStart Page = hxxp://www.idg.pl
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Komputer\Dane aplikacji\Mozilla\Firefox\Profiles\ur1txij1.default\
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-16 17:38:26
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-12-16 17:38:50
ComboFix-quarantined-files.txt 2008-12-16 16:38:45
Przed: 11,223,896,064 bajtów wolnych
Po: 11,222,491,136 bajtów wolnych
161
Chodzi o to że po zaznaczeniu w opcjach folderów POKAŻ UKRYTE PLIKI I FOLDERY wchodze tam gdzie sa i dalej i ch nie ma a gdy wracam do opcji jest z powrotem zaznaczona opcja NIE POKAZUJ UKRYTYCH......Co mam zrobić?
Dodano Dzisiaj, 18:06:
W razie szybszych odpowiedzi prosze pisac na numer GG 9064700