ComboFix 09-03-22.01 - AsIuNiA 2009-03-23 22:47:55.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.1007.637 [GMT 1:00]
Uruchomiony z: e:\instalki\Dodatki\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\em8tqm.cmd
C:\jm3cx96.bat
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds1.dll
c:\windows\system32\olhrwef.exe
D:\Autorun.inf
D:\em8tqm.cmd
D:\jm3cx96.bat
E:\Autorun.inf
E:\em8tqm.cmd
E:\jm3cx96.bat
.
((((((((((((((((((((((((( Pliki utworzone od 2009-02-23 do 2009-03-23 )))))))))))))))))))))))))))))))
.
2009-03-23 22:34 . 2009-03-23 22:34 0 --a--c--- c:\windows\nsreg.dat
2009-03-23 21:08 . 2009-03-23 21:08 <DIR> d----c--- c:\windows\system32\Lang
2009-03-23 21:06 . 2009-03-23 21:06 <DIR> d----c--- c:\documents and settings\AsIuNiA\Dane aplikacji\Gadu-Gadu
2009-03-23 21:05 . 2009-03-23 21:06 <DIR> d----c--- c:\documents and settings\AsIuNiA\Gadu-Gadu
2009-03-23 20:32 . 2009-03-23 20:32 <DIR> d----c--- c:\program files\Avira
2009-03-23 20:32 . 2009-03-23 20:32 <DIR> d----c--- c:\documents and settings\All Users\Dane aplikacji\Avira
2009-03-23 20:32 . 2009-02-13 11:31 55,640 --a--c--- c:\windows\system32\drivers\avgntflt.sys
2009-03-23 20:31 . 2005-07-19 11:10 143,360 --a--c--- c:\windows\system32\igfxres.dll
2009-03-23 20:31 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-23 18:42 --------- dc-h--w c:\program files\InstallShield Installation Information
2009-03-23 18:39 --------- dc----w c:\program files\Intel
2009-03-23 18:38 --------- dc----w c:\program files\Synaptics
2009-03-23 18:36 --------- dc----w c:\program files\Realtek
2009-03-23 18:35 --------- dc----w c:\program files\Common Files\InstallShield
2009-03-23 18:31 9,388 -c--a-w c:\windows\system32\drivers\iaStor.PNF
2009-03-23 18:31 7,280 -c--a-w c:\windows\system32\drivers\viamraid.PNF
2009-03-23 18:31 63,240 -c--a-w c:\windows\system32\drivers\Si3112r.PNF
2009-03-23 18:31 6,984 -c--a-w c:\windows\system32\drivers\SiSRaid.PNF
2009-03-23 18:31 20,152 -c--a-w c:\windows\system32\drivers\INFCACHE.1
2009-03-23 18:31 12,204 -c--a-w c:\windows\system32\drivers\nvraid.PNF
2009-03-23 18:31 10,828 -c--a-w c:\windows\system32\drivers\iaAHCI.PNF
2009-03-23 18:30 12,432 -c--a-w c:\windows\system32\drivers\adpu320.PNF
2009-03-23 17:44 --------- dc----w c:\program files\microsoft frontpage
2009-03-23 17:43 --------- dc----w c:\program files\Java
2009-03-23 17:43 --------- dc----w c:\program files\Common Files\Java
2009-03-23 17:37 --------- dc----w c:\program files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 159744]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 13:00 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
--a--c--- 2008-03-20 11:04 2127296 d:\programy\Gadu-Gadu\gg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a--c--- 2005-07-19 11:06 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a--c--- 2005-07-19 11:10 114688 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a--c--- 2005-07-19 11:09 94208 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-10 13:03 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a--c--- 2005-04-15 08:48 708697 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a--c--- 2005-05-03 18:43 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
--a--c--- 2005-09-21 15:32 2807808 c:\windows\alcwzrd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skrót do strony właściwości High Definition Audio]
-----c--- 2005-01-07 17:07 61952 c:\windows\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a--c--- 2005-09-21 10:24 86016 c:\windows\SoundMan.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-23 108289]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5c63e06d-17d3-11de-80db-00166f4628f8}]
\Shell\AutoRun\command - G:\jm3cx96.bat
\Shell\open\Command - G:\jm3cx96.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92fe4d71-17e6-11de-80dc-00166f4628f8}]
\Shell\AutoRun\command - G:\em8tqm.cmd
\Shell\open\Command - G:\em8tqm.cmd
.
- - - - USUNIĘTO PUSTE WPISY - - - -
MSConfigStartUp-cdoosoft - c:\windows\system32\olhrwef.exe
.
------- Skan uzupełniający -------
.
FF - ProfilePath - c:\documents and settings\AsIuNiA\Dane aplikacji\Mozilla\Firefox\Profiles\f3pumg1c.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-23 22:50:19
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Czas ukończenia: 2009-03-23 22:51:38 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-03-23 21:51:34
Przed: 6 898 483 200 bajtów wolnych
Po: 6,995,222,528 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
139