
- Kod: Zaznacz wszystko
ComboFix 08-08-14.05 - Maria 2008-08-15 17:51:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.426 [GMT 2:00]
Running from: C:\Documents and Settings\Maria\Pulpit\ComboFix.exe
* Resident AV is active
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\hosts
.
((((((((((((((((((((((((( Files Created from 2008-07-15 to 2008-08-15 )))))))))))))))))))))))))))))))
.
2008-08-14 14:38 . 2008-08-14 14:38 <DIR> d-------- C:\Program Files\Photo!
2008-08-05 15:27 . 2008-08-05 15:27 <DIR> d-------- C:\Documents and Settings\Maria\Dane aplikacji\Nowe Gadu-Gadu
2008-07-21 23:39 . 2008-07-21 23:39 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\FLEXnet
2008-07-21 23:32 . 2008-07-21 23:32 <DIR> d-------- C:\Program Files\Bonjour
2008-07-21 23:25 . 2008-07-21 23:25 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-07-18 08:00 . 2008-07-18 08:00 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.Vsys
2008-07-18 08:00 . 2008-07-18 08:00 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.Vsys
2008-07-16 16:47 . 2008-07-16 16:47 <DIR> d-------- C:\Documents and Settings\Maria\Dane aplikacji\Inkscape
2008-07-16 16:42 . 2008-07-16 16:44 <DIR> d-------- C:\Program Files\Inkscape
2008-07-16 11:21 . 2008-07-16 11:21 <DIR> d-------- C:\Program Files\Zinio
2008-07-16 11:21 . 2008-07-16 11:21 <DIR> d-------- C:\Program Files\Common Files\Zinio
2008-07-16 11:21 . 2008-07-31 21:31 <DIR> d-------- C:\Documents and Settings\Maria\Dane aplikacji\ContentGuard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-15 15:53 --------- d-----w C:\Documents and Settings\Maria\Dane aplikacji\Skype
2008-08-15 15:52 --------- d-----w C:\Documents and Settings\Maria\Dane aplikacji\skypePM
2008-08-14 13:21 --------- d-----w C:\Documents and Settings\Maria\Dane aplikacji\OpenOffice.ux.pl2
2008-08-13 11:17 --------- d-----w C:\Documents and Settings\Maria\Dane aplikacji\POP Peeper
2008-08-11 08:28 --------- d-----w C:\Program Files\ESET
2008-08-06 15:41 --------- d-----w C:\Documents and Settings\Maria\Dane aplikacji\GanymedeNet
2008-08-06 15:17 --------- d-----w C:\Program Files\Ganymede
2008-08-06 08:37 --------- d-----w C:\Program Files\POP Peeper
2008-08-05 08:13 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-07-21 21:33 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-21 18:31 --------- d-----w C:\Program Files\DivX
2008-07-21 18:29 --------- d-----w C:\Program Files\Adibu
2008-07-19 18:33 --------- d-----w C:\Program Files\Winamp
2008-07-13 18:33 --------- d-----w C:\Program Files\Yahoo!
2008-07-13 18:30 --------- d-----w C:\Program Files\Java
2008-06-20 17:31 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-06-20 17:31 --------- d-----r C:\Program Files\Skype
2008-06-20 17:30 --------- d-----w C:\Program Files\Common Files\Skype
2007-11-16 19:43 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2007-06-07 11:21 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe" [2005-03-29 08:13 258048]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 21:03 68856]
"POP Peeper"="C:\Program Files\POP Peeper\POPPeeper.exe" [2008-07-18 09:40 1437696]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 17:46 1460560]
"Odkurzacz-MCD"="C:\Program Files\Odkurzacz\odk_mcd.exe" [2008-03-03 15:44 266240]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:44 15360]
"Zinio DLM"="C:\Program Files\Zinio\ZinioDeliveryManager.exe" [2006-12-13 19:47 1003590]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2006-10-31 18:58 921600]
"QuickTime Task"="C:\Program Files\QuickTime Alternative\qttask.exe" [2007-04-27 09:41 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-04-27 11:25 257088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"PD0620 STISvc"="P0620Pin.dll" [2005-05-10 19:03 36864 C:\WINDOWS\system32\P0620Pin.dll]
"SoundMan"="SOUNDMAN.EXE" [2004-01-09 03:54 65536 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:44 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Mawi_BDE_monitor.exe [2004-01-20 16:59:10 540160]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= E:\WINDOWS\system32\l3codeca.acm
"aux"= ctwdm32.dll
"msacm.iac2"= E:\WINDOWS\system32\iac25_32.ax
"aux1"= ctwdm32.dll
"msacm.l3codec"= l3codecp.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Mawi_BDE_monitor.exe]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Mawi_BDE_monitor.exe
backup=C:\WINDOWS\pss\Mawi_BDE_monitor.exeCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Maria^Menu Start^Programy^Autostart^OpenOffice.ux.pl 2.0.3.lnk]
path=C:\Documents and Settings\Maria\Menu Start\Programy\Autostart\OpenOffice.ux.pl 2.0.3.lnk
backup=C:\WINDOWS\pss\OpenOffice.ux.pl 2.0.3.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2007-02-18 23:30 969728 C:\Program Files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
--a------ 2007-07-09 09:39 2119104 C:\Program Files\Gadu-Gadu\gg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2007-10-23 23:18 443968 C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
--a------ 2006-12-28 17:09 4579328 C:\Program Files\VIA\RAID\raid_tool.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-07-01 20:46 25504040 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-04-01 20:49 36352 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zinio DLM]
--a------ 2006-12-13 19:47 1003590 C:\Program Files\Zinio\ZinioDeliveryManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\INTERIAPL\\Stefan\\Stefan.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\ESET\\nod32.exe"=
"C:\\Program Files\\ESET\\nod32kui.exe"=
"C:\\Program Files\\POP Peeper\\POPPeeper.exe"=
"C:\\Program Files\\123 Free Solitaire\\123FreeSolitaire.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"42141:TCP"= 42141:TCP:AresChatServer
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 21:22]
.
Contents of the 'Scheduled Tasks' folder
2008-08-14 C:\WINDOWS\Tasks\rpc.job
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
HKU-Default-Run-PcSync - C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
MSConfigStartUp-PCSuiteTrayApplication - C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Maria\Dane aplikacji\Mozilla\Firefox\Profiles\eldbvw43.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.onet.pl/
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-15 17:53:45
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-15 17:54:51
ComboFix-quarantined-files.txt 2008-08-15 15:54:35
Pre-Run: 66,044,850,176 bajtów wolnych
Post-Run: 66,036,441,088 bajtów wolnych
159 --- E O F --- 2007-06-30 05:51:26
Edit by Mike013
Następnym razem wstawiaj logi zgodnie z reguleminem

