
Mam problem komputer się czasami wiesza..
Z góry dziękuję za pomoc.
- Kod: Zaznacz wszystko
ComboFix 08-09-13.05 - Gosiaa Kuczera 2008-09-14 15:59:24.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.268 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\Gosiaa Kuczera\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
[color=red][b]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\hosts
.
((((((((((((((((((((((((( Pliki utworzone od 2008-08-14 do 2008-09-14 )))))))))))))))))))))))))))))))
.
2008-09-13 09:41 . 1998-10-07 12:54 327,168 --a------ C:\WINDOWS\IsUn0415.exe
2008-09-11 21:50 . 2008-09-11 21:50 <DIR> d-------- C:\Program Files\Realtek AC97
2008-09-07 17:25 . 2008-09-07 20:27 304,160 --a------ C:\SPC220NC.DAT
2008-09-07 17:14 . 2008-09-07 17:14 <DIR> d-------- C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\ArcSoft
2008-09-07 17:14 . 2008-04-13 20:46 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-09-07 17:14 . 2008-04-13 20:46 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-09-07 17:14 . 2008-04-13 20:39 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-09-07 17:14 . 2008-04-13 20:39 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
2008-09-07 17:12 . 2008-09-07 17:12 <DIR> d-------- C:\Program Files\Philips
2008-09-07 17:12 . 2008-09-07 17:12 <DIR> d-------- C:\Program Files\ArcSoft
2008-09-07 17:12 . 2007-01-09 17:59 507,136 --a------ C:\WINDOWS\system32\drivers\SPC220NC.SYS
2008-09-07 17:12 . 1995-08-01 04:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2008-09-07 17:12 . 2007-01-04 17:34 119,808 --a------ C:\WINDOWS\system32\SPC220NC.AX
2008-09-07 17:12 . 2006-11-20 09:04 6,656 --a------ C:\WINDOWS\system32\CoInst.dll
2008-09-07 17:12 . 2006-12-07 17:01 518 --a------ C:\WINDOWS\system32\SPC220NC.INI
2008-09-07 17:10 . 2008-09-07 17:10 <DIR> d-------- C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\InstallShield
2008-09-04 07:06 . 2008-09-04 07:06 <DIR> d-------- C:\Documents and Settings\Gosiaa Kuczera\EurekaLog
2008-09-03 13:47 . 2008-09-03 13:47 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-09-03 10:39 . 2008-09-03 10:49 <DIR> d-------- C:\Program Files\FlashFXP
2008-09-03 10:39 . 2008-09-03 10:39 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\FlashFXP
2008-09-03 10:20 . 2008-09-03 10:20 <DIR> d-------- C:\WINDOWS\system32\pl
2008-09-03 10:20 . 2008-09-03 10:20 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-03 10:20 . 2008-09-03 10:20 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-03 10:18 . 2008-09-03 10:20 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-03 07:19 . 2008-09-03 10:08 <DIR> d-------- C:\WINDOWS\EHome
2008-09-03 07:10 . 2004-08-04 00:35 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-08-29 21:09 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2008-08-29 21:09 . 2006-09-28 16:05 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
2008-08-29 21:09 . 2006-07-28 09:30 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2008-08-29 21:09 . 2006-09-28 16:04 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll
2008-08-29 21:09 . 2006-07-28 09:30 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2008-08-29 21:09 . 2006-09-28 16:03 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2008-08-28 21:18 . 2008-08-28 21:18 <DIR> d-------- C:\Program Files\Apple Software Update
2008-08-28 21:16 . 2008-08-29 19:02 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-27 16:13 . 2008-08-28 21:17 <DIR> d-------- C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\Apple Computer
2008-08-27 16:13 . 2008-08-27 16:13 52,836 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-08-27 16:00 . 2008-08-27 16:00 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple
2008-08-27 15:59 . 2008-08-27 15:59 0 --a------ C:\WINDOWS\netscape.INI
2008-08-27 15:56 . 1999-06-04 08:21 701,992 --a------ C:\WINDOWS\cd32.exe
2008-08-27 15:56 . 2008-08-27 15:56 76,800 --a------ C:\WINDOWS\RAUNINST.exe
2008-08-27 15:56 . 1999-03-04 07:14 61,952 --a------ C:\WINDOWS\system32\nabapi32.dll
2008-08-27 15:55 . 2008-08-27 15:55 <DIR> d-------- C:\Documents and Settings\Gosiaa Kuczera\WINDOWS
2008-08-27 15:55 . 1997-04-18 11:52 298,496 --a------ C:\WINDOWS\unin0415.exe
2008-08-27 15:49 . 2008-08-27 15:49 <DIR> d-------- C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\Netscape
2008-08-25 22:23 . 2008-08-26 17:20 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\TrackMania
2008-08-25 18:57 . 2008-08-26 20:59 <DIR> d-------- C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\IEPro
2008-08-24 20:07 . 2008-08-24 20:07 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-08-21 12:12 . 2008-07-09 10:05 421,888 --a------ C:\WINDOWS\system32\ac3filter.acm
2008-08-20 23:47 . 2008-08-20 23:47 <DIR> d-------- C:\WINDOWS\speech
2008-08-20 23:47 . 2008-08-20 23:50 <DIR> d-------- C:\WINDOWS\Lhsp
2008-08-20 16:45 . 2008-08-20 16:46 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Ad Muncher
2008-08-19 16:54 . 2008-08-19 16:55 <DIR> d-------- C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\Media Player Classic
2008-08-19 15:30 . 2008-08-19 15:35 286,720 --------- C:\WINDOWS\Setup1.exe
2008-08-19 15:30 . 2008-08-19 15:35 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2008-08-19 09:18 . 2008-08-27 15:59 27,662 --a------ C:\WINDOWS\nsreg.dat
2008-08-17 18:11 . 2008-08-17 18:11 <DIR> d-------- C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\teamspeak2
2008-08-17 18:11 . 2008-08-17 18:11 34,064 --a------ C:\WINDOWS\system32\lhacm.acm
2008-08-16 21:47 . 2008-08-16 21:47 <DIR> d-------- C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\streamripper
2008-08-14 20:13 . 2008-09-14 10:42 <DIR> d-a------ C:\Documents and Settings\All Users\Dane aplikacji\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-14 14:02 3,136 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-14 14:02 294,944 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-14 14:02 25,060 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-14 14:02 2,935,328 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-14 14:01 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\DMCache
2008-09-13 18:54 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\Skype
2008-09-13 07:49 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\skypePM
2008-09-07 15:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-07 15:12 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-06 17:12 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-08-29 16:48 --------- d-----w C:\Program Files\Bonjour
2008-08-26 15:10 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\IDM
2008-08-24 18:06 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-17 10:31 16,827 ----a-w C:\WINDOWS\system32\drivers\hosts
2008-08-13 11:55 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-08-13 11:54 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\DAEMON Tools
2008-08-11 12:16 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-08-11 12:14 --------- d-----w C:\Program Files\MSBuild
2008-08-11 12:14 --------- d-----w C:\Program Files\Microsoft Works
2008-08-11 12:12 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-09 22:24 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\Uniblue
2008-08-08 15:42 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\Gadu-Gadu
2008-08-08 15:27 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\iolo
2008-08-08 15:27 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\iolo
2008-08-08 15:26 --------- d-----w C:\Documents and Settings\LocalService\Dane aplikacji\iolo
2008-08-08 14:36 74,703 ----a-w C:\WINDOWS\system32\mfc45.dll
2008-08-08 12:08 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-08 12:08 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-08-08 10:11 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-08-08 09:47 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\FLEXnet
2008-08-08 09:43 286,720 ----a-w C:\WINDOWS\iun506.exe
2008-08-08 09:05 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-08-08 08:54 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\ACD Systems
2008-08-08 08:53 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-08-08 08:53 --------- d-----w C:\Program Files\ACD Systems
2008-08-08 08:53 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ACD Systems
2008-08-08 08:47 --------- d-----w C:\Program Files\Macromedia
2008-08-08 08:43 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-08-07 21:17 --------- d-----w C:\Program Files\Skype
2008-08-07 21:17 --------- d-----w C:\Program Files\Common Files\Skype
2008-08-07 21:17 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-08-07 20:13 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\FlashFXP
2008-08-07 19:46 --------- d-----w C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\Winamp
2008-08-07 19:26 --------- d-----w C:\Program Files\Java
2008-08-07 19:18 319,488 ----a-w C:\WINDOWS\HideWin.exe
2008-08-07 18:53 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-07 18:52 --------- d-----w C:\Program Files\Common Files\Java
2008-08-07 18:48 --------- d-----w C:\Program Files\Usługi online
2008-07-28 11:40 1,003,520 ----a-w C:\WINDOWS\system32\VSFilter.dll
2008-07-24 16:02 4,749,824 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-07-23 14:51 16,804,864 ----a-w C:\WINDOWS\RTHDCPL.exe
2008-07-15 11:58 524,288 ----a-w C:\WINDOWS\RtlExUpd.dll
2008-07-15 11:47 1,196,032 ----a-w C:\WINDOWS\RtlUpd.exe
2008-07-09 14:34 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-05 10:14 456,192 ----a-w C:\WINDOWS\system32\libmplayer.dll
2008-07-05 10:14 3,591,168 ----a-w C:\WINDOWS\system32\libavcodec.dll
2008-07-05 10:13 708,096 ----a-w C:\WINDOWS\system32\ff_x264.dll
2008-06-24 16:46 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:12 295,936 ----a-w C:\WINDOWS\system32\wmpeffects.dll
2008-06-23 16:42 826,368 ----a-w C:\WINDOWS\system32\WININET.DLL
2008-06-22 16:34 177,664 ----a-w C:\WINDOWS\system32\ff_theora.dll
2008-06-20 17:48 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-19 14:42 2,808,832 ----a-w C:\WINDOWS\alcwzrd.exe
2008-06-19 14:27 9,715,200 ----a-w C:\WINDOWS\RTLCPL.exe
2008-06-19 14:20 57,344 ----a-w C:\WINDOWS\Alcmtr.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"SpeedX"="D:\PROGRA~1\Speed-X\SpeedX.exe" [2006-06-27 46718]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 86016]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiscSpaceChecks"= 000000000000f03f
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"VIDC.ACDV"= ACDV.dll
"msacm.ac3filter"= ac3filter.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^TrayMin220.lnk]
backup=C:\WINDOWS\pss\TrayMin220.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Gosiaa Kuczera^Menu Start^Programy^Autostart^Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk]
backup=C:\WINDOWS\pss\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Monitor]
--a------ 2006-11-03 11:01 319488 C:\WINDOWS\Philips\SPC220NC\Monitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
--a------ 2007-05-09 10:41 2299400 D:\Programy Files\Registry Mechanic\RegMech.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-05-16 14:01 1630208 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Programy Files\\AQQ\\AQQ.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"D:\\Programy Files\\Mozilla\\firefox.exe"=
"D:\\Programy Files\\IEPro\\MiniDM.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"D:\\PROGRA~1\\AQQ\\AQQ.exe"=
"C:\\WINDOWS\\Programy\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S3 SPC220NC;Philips SPC220NC Webcam;C:\WINDOWS\system32\DRIVERS\SPC220NC.SYS [2007-01-09 507136]
.
Zawartość folderu 'Zaplanowane zadania'
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\Gosiaa Kuczera\Dane aplikacji\Mozilla\Firefox\Profiles\xwsl4s8j.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.pl
FF -: plugin - D:\Programy Files\Mozilla\plugins\npnul32.dll
FF -: plugin - D:\Programy Files\Operaa\program\plugins\npdsplay.dll
FF -: plugin - D:\Programy Files\Operaa\program\plugins\npwmsdrm.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-14 16:03:23
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Czas ukończenia: 2008-09-14 16:12:03 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-09-14 14:11:06
Przed: 26,206,162,944 bajt˘w wolnych
Po: 26,326,982,656 bajt˘w wolnych
238 --- E O F --- 2008-09-10 04:14:14