
- Kod: Zaznacz wszystko
ComboFix 09-01-08.05 - GodslikE 2009-01-09 15:57:33.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.2047.1631 [GMT 1:00]
Uruchomiony z: c:\documents and settings\GodslikE\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\svchost.exe
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_POWERMANAGER
-------\Service_PowerManager
((((((((((((((((((((((((( Pliki utworzone od 2008-12-09 do 2009-01-09 )))))))))))))))))))))))))))))))
.
2009-01-08 16:38 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2009-01-08 16:37 . 2009-01-08 16:37 <DIR> d-------- c:\program files\Microsoft Works
2009-01-08 16:33 . 2009-01-08 16:34 <DIR> d-------- c:\windows\SHELLNEW
2009-01-08 16:33 . 2009-01-08 16:33 <DIR> dr-h----- C:\MSOCache
2009-01-08 16:33 . 2009-01-08 17:00 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2009-01-08 16:12 . 2009-01-08 16:12 <DIR> d-------- c:\windows\Vbox
2009-01-08 16:12 . 2009-01-08 16:12 <DIR> d-------- c:\program files\TI Education
2009-01-08 15:03 . 2009-01-08 15:03 <DIR> d-------- c:\program files\Ganymede
2009-01-06 20:26 . 2009-01-08 14:45 <DIR> d-------- c:\program files\IDoser v4
2009-01-05 21:34 . 2009-01-05 21:34 <DIR> d-------- c:\documents and settings\LocalService\Dane aplikacji\Xfire Plus
2009-01-05 20:34 . 2009-01-05 20:34 <DIR> d-------- C:\Smily
2009-01-04 21:00 . 2009-01-04 21:00 <DIR> d-------- C:\SOULMU
2009-01-04 20:00 . 2009-01-04 20:00 <DIR> d-------- c:\program files\mIRC
2009-01-04 17:49 . 2009-01-04 17:49 <DIR> d-------- c:\documents and settings\GodslikE\Shaders
2009-01-04 17:41 . 2009-01-04 17:41 <DIR> d-------- c:\program files\Rockstar Games
2009-01-03 12:43 . 2005-04-24 22:43 13,225 --a------ c:\windows\system32\drivers\Razerlow.sys
2009-01-01 22:49 . 2009-01-01 22:49 <DIR> d-------- c:\documents and settings\GodslikE\metin2 multiversion trainer
2009-01-01 19:56 . 2009-01-03 09:00 <DIR> d-------- c:\documents and settings\GodslikE\Dane aplikacji\U3
2009-01-01 19:56 . 2008-04-14 00:15 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2009-01-01 16:21 . 2009-01-01 22:50 <DIR> d-------- c:\program files\Metin2_PL
2008-12-31 23:21 . 2009-01-08 14:47 <DIR> d-------- c:\program files\Little Fighter 2.5 - v2.0
2008-12-30 20:20 . 2008-12-30 20:20 <DIR> d-------- c:\program files\Ventrilo
2008-12-28 22:18 . 2008-12-28 22:18 <DIR> d-------- c:\program files\Xfire Plus
2008-12-28 22:18 . 2008-12-28 22:18 <DIR> d-------- c:\documents and settings\GodslikE\Dane aplikacji\Xfire Plus
2008-12-26 21:08 . 2009-01-01 22:49 <DIR> d-------- C:\overviews
2008-12-26 21:08 . 2008-12-26 21:08 <DIR> d-------- C:\maps
2008-12-26 20:54 . 2008-12-29 22:15 38 --a------ c:\windows\wcx_ftp.ini
2008-12-26 20:53 . 2008-12-26 20:53 <DIR> d-------- C:\totalcmd
2008-12-26 20:53 . 2008-12-29 22:16 1,447 --a------ c:\windows\wincmd.ini
2008-12-26 20:53 . 2008-08-08 07:04 545 --a------ c:\windows\UC.PIF
2008-12-26 20:53 . 2008-08-08 07:04 545 --a------ c:\windows\RAR.PIF
2008-12-26 20:53 . 2008-08-08 07:04 545 --a------ c:\windows\PKZIP.PIF
2008-12-26 20:53 . 2008-08-08 07:04 545 --a------ c:\windows\PKUNZIP.PIF
2008-12-26 20:53 . 2008-08-08 07:04 545 --a------ c:\windows\NOCLOSE.PIF
2008-12-26 20:53 . 2008-08-08 07:04 545 --a------ c:\windows\LHA.PIF
2008-12-26 20:53 . 2008-08-08 07:04 545 --a------ c:\windows\ARJ.PIF
2008-12-25 19:29 . 2008-12-25 21:27 <DIR> d-------- c:\documents and settings\GodslikE\Dane aplikacji\Ventrilo
2008-12-25 19:22 . 2008-12-25 19:22 6,503 --a------ c:\windows\system32\spupdsvc.inf
2008-12-25 19:20 . 2008-12-25 19:20 <DIR> d-------- c:\windows\ServicePackFiles
2008-12-25 19:20 . 2008-04-14 22:51 294,912 -----c--- c:\windows\system32\dllcache\dlimport.exe
2008-12-25 19:18 . 2008-12-25 19:18 <DIR> d-------- c:\windows\EHome
2008-12-24 23:14 . 2008-12-24 23:14 <DIR> dr-h----- c:\documents and settings\GodslikE\Dane aplikacji\SecuROM
2008-12-24 22:17 . 2009-01-04 20:00 <DIR> d-------- c:\documents and settings\GodslikE\Dane aplikacji\mIRC
2008-12-24 21:57 . 2008-12-24 21:57 <DIR> d-------- c:\program files\Teamspeak2_RC2
2008-12-24 21:57 . 2008-12-24 21:57 <DIR> d-------- c:\documents and settings\GodslikE\Dane aplikacji\teamspeak2
2008-12-24 21:57 . 2008-12-24 21:57 34,064 --a------ c:\windows\system32\lhacm.acm
2008-12-24 21:54 . 2008-12-24 21:54 <DIR> d-------- c:\windows\system32\AGEIA
2008-12-24 21:54 . 2008-12-24 21:54 <DIR> d-------- c:\program files\Deep Silver
2008-12-24 21:54 . 2008-12-30 20:20 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-24 21:54 . 2008-12-24 21:54 <DIR> d-------- c:\program files\AGEIA Technologies
2008-12-24 20:17 . 2009-01-03 12:43 <DIR> d-------- c:\program files\Razer
2008-12-24 20:17 . 2008-12-24 20:17 <DIR> d-------- c:\documents and settings\GodslikE\Dane aplikacji\InstallShield
2008-12-24 20:17 . 2007-06-29 16:44 73,728 --a------ c:\windows\system32\diamondback.cpl
2008-12-24 20:17 . 2005-04-24 22:43 13,225 --a------ c:\windows\system32\drivers\DB3G.sys
2008-12-24 14:41 . 2008-12-24 14:41 <DIR> d-------- c:\program files\A4Tech
2008-12-24 13:49 . 2008-12-24 13:49 <DIR> d-------- c:\documents and settings\GodslikE\Dane aplikacji\Gadu-Gadu
2008-12-24 13:27 . 2008-12-24 13:27 <DIR> d-------- c:\program files\Valve
2008-12-24 13:01 . 2008-12-24 13:01 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-23 23:24 . 2008-12-23 23:24 <DIR> d-------- c:\program files\p-nand-q.com
2008-12-23 23:24 . 2002-12-29 01:14 81,920 --a------ c:\windows\system32\Startup.cpl
2008-12-23 23:20 . 2008-12-23 23:20 <DIR> d-------- c:\program files\KONAMI
2008-12-23 23:11 . 2008-12-23 23:11 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-12-23 23:08 . 2008-12-23 23:08 <DIR> d-------- c:\documents and settings\GodslikE\Dane aplikacji\DAEMON Tools
2008-12-23 23:07 . 2008-12-24 13:55 <DIR> d-------- c:\program files\Winamp
2008-12-23 23:07 . 2008-12-28 17:46 <DIR> d-------- c:\documents and settings\GodslikE\Dane aplikacji\Winamp
2008-12-23 21:33 . 2008-12-23 21:33 0 --a------ c:\windows\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 16:20 --------- d-----w c:\documents and settings\GodslikE\Dane aplikacji\Xfire
2009-01-08 13:35 --------- d-s---w c:\program files\Xfire
2009-01-04 19:32 196,608 ----a-w c:\windows\system32\drivers\nVivid.bin
2009-01-04 16:49 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-23 22:08 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2008-12-23 19:53 --------- d-----w c:\program files\My Company Name
2008-12-23 19:53 --------- d-----w c:\program files\ASUS
2008-12-23 19:52 --------- d-----w c:\documents and settings\NetworkService\Dane aplikacji\Xfire
2008-12-23 19:52 --------- d-----w c:\documents and settings\LocalService\Dane aplikacji\Xfire
2008-12-23 19:48 --------- d-----w c:\program files\Gadu-Gadu
2008-12-23 19:47 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-23 19:13 --------- d-----w c:\program files\Analog Devices
2008-12-23 19:09 --------- d-----w c:\program files\DIFX
2008-12-23 19:06 --------- d-----w c:\program files\NVIDIA Corporation
2008-12-23 18:49 --------- d-----w c:\program files\microsoft frontpage
2008-12-23 18:48 --------- d-----w c:\program files\Usługi online
.
((((((((((((((((((((((((((((( snapshot_2009-01-04_18.23.44.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-03 14:08:51 5,120 ----a-r c:\windows\Installer\{789289CA-F73A-4A16-A331-54D498CE069F}\Icon789289CA.exe
+ 2009-01-08 20:45:07 5,120 ----a-r c:\windows\Installer\{789289CA-F73A-4A16-A331-54D498CE069F}\Icon789289CA.exe
+ 2009-01-08 15:33:41 217,864 ----a-r c:\windows\Installer\{90120000-006E-0415-0000-0000000FF1CE}\misc.exe
+ 2009-01-08 15:38:09 20,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-01-08 15:38:09 184,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-01-08 15:38:09 217,864 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-01-08 15:38:09 18,704 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-01-08 15:38:09 35,088 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-01-08 15:38:09 922,384 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-01-08 15:38:09 888,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-01-08 15:38:09 1,172,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2006-10-26 13:10:08 1,190,688 ----a-w c:\windows\system32\FM20.DLL
+ 2006-10-26 12:10:06 33,088 ----a-w c:\windows\system32\FM20ENU.DLL
- 2008-12-25 18:24:26 96,664 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-01-09 14:25:20 150,792 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2006-10-26 12:45:04 207,360 ----a-w c:\windows\system32\INKED.DLL
+ 2006-07-24 09:50:38 125,744 ----a-w c:\windows\system32\MSSTDFMT.DLL
+ 2006-07-24 09:50:40 39,728 ----a-w c:\windows\system32\SCP32.DLL
+ 2006-10-26 18:56:16 864,080 ----a-w c:\windows\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2006-10-26 18:56:14 67,408 ----a-w c:\windows\system32\spool\drivers\w32x86\3\msonpui.dll
+ 2006-10-26 18:56:16 864,080 ----a-w c:\windows\system32\spool\drivers\w32x86\msonpdrv.dll
+ 2006-10-26 18:56:14 67,408 ----a-w c:\windows\system32\spool\drivers\w32x86\msonpui.dll
+ 2006-10-26 18:56:12 33,104 ----a-w c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
+ 2006-07-24 09:50:40 47,920 ----a-w c:\windows\system32\VBAME.DLL
+ 2006-10-26 12:45:04 293,376 ----a-w c:\windows\system32\WISPTIS.EXE
+ 1999-10-05 04:30:20 330,175 ----a-w c:\windows\Vbox\Common\vboxm430.dll
+ 1999-10-05 04:30:08 255,916 ----a-w c:\windows\Vbox\Common\vboxt430.dll
+ 2006-10-26 12:40:34 95,744 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2006-10-26 12:40:36 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2006-10-26 12:40:36 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2006-10-26 12:40:36 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2006-10-26 12:40:36 1,093,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2006-10-26 12:40:36 1,079,808 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2006-10-26 12:40:36 69,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2006-10-26 12:40:36 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2006-10-26 12:40:36 40,960 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2006-10-26 12:40:36 45,056 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2006-10-26 12:40:36 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2006-10-26 12:40:36 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2006-10-26 12:40:36 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2006-10-26 12:40:36 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2006-10-26 12:40:36 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2006-10-26 12:40:36 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2006-10-26 12:40:36 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
.
-- Migawka wyzerowana --
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
"Steam"="c:\program files\valve\steam\steam.exe" [2008-12-24 1410296]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"AsusStartupHelp"="c:\program files\ASUS\AASP\1.00.16\AsRunHelp.exe" [2006-11-14 398336]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"ASUSGamerOSD"="c:\program files\ASUS\GamerOSD\GamerOSD.exe" [2007-07-12 380928]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2006-02-17 199168]
"Diamondback"="c:\program files\Razer\Diamondback\razerhid.exe" [2007-02-14 147456]
"Xfire Music"="c:\program files\Xfire\xfiremusic.exe" [2006-11-21 253650]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\GodslikE\Menu Start\Programy\Autostart\
WINAMP Updater.exe [2008-12-12 30046]
Xfire.lnk - c:\program files\Xfire\Xfire.exe [2008-12-11 2990416]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Deep Silver\\Sacred 2 - Fallen Angel\\system\\s2gs.exe"=
"c:\\Program Files\\Deep Silver\\Sacred 2 - Fallen Angel\\system\\sacred2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Valve\\Steam\\Steam.exe"=
"c:\\Program Files\\Metin2_PL\\metin2.bin"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\plexz\\counter-strike\\hl.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\drivers\DB3G.sys [2008-12-24 13225]
R3 Video3D;ASUS Video3D Service;c:\windows\system32\drivers\Video3D32.sys [2008-12-23 10752]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{596ff662-d82a-11dd-8bd5-001e8c1d1618}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
.
------- Skan uzupełniający -------
.
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\GodslikE\Dane aplikacji\Mozilla\Firefox\Profiles\66zra1k3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPBOARDS.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npganymedenet.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-09 15:59:47
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1957994488-1500820517-839522115-1004\Software\SecuROM\License information*NULL*]
"datasecu"=hex:ad,7a,2d,9a,21,b4,ca,30,0b,23,c9,35,7c,43,c2,de,d0,ca,68,ac,d3,
4c,49,09,4f,7d,1e,44,8c,e9,b3,9d,5a,8d,f5,de,53,e5,54,47,9d,18,2f,ad,61,33,\
"rkeysecu"=hex:63,0a,bf,15,5f,8f,03,08,87,50,54,9f,6b,ef,d7,38
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\rundll32.exe
c:\documents and settings\GodslikE\Menu Start\Programy\Autostart\WINAMP Updater.exe
c:\windows\ATKKBService.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\windows\system32\nvsvc32.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\windows\system32\wdfmgr.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Razer\Diamondback\razertra.exe
c:\program files\Razer\Diamondback\razerofa.exe
.
**************************************************************************
.
Czas ukończenia: 2009-01-09 16:01:04 - komputer został uruchomiony ponownie [GodslikE]
ComboFix-quarantined-files.txt 2009-01-09 15:01:02
ComboFix2.txt 2009-01-06 13:42:10
ComboFix3.txt 2009-01-04 17:24:04
ComboFix4.txt 2009-01-02 23:13:50
ComboFix5.txt 2009-01-09 14:27:21
Przed: 67 229 147 136 bajtów wolnych
Po: 67,218,780,160 bajtów wolnych
250
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:08:54, on 2009-01-09
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Razer\Diamondback\razerhid.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\GodslikE\Menu Start\Programy\Autostart\WINAMP Updater.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Razer\Diamondback\razertra.exe
C:\Program Files\Razer\Diamondback\razerofa.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.16\AsRunHelp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [Diamondback] C:\Program Files\Razer\Diamondback\razerhid.exe
O4 - HKLM\..\Run: [Xfire Music] "C:\Program Files\Xfire\xfiremusic.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: WINAMP Updater.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 5265 bytes
O to logi , komputer przymula i wszystko wolno się ładuje. Proszę o pomoc .