
jak się odpali chodzi w miarę szybko, ale najgorszy ten rozruch.
ComboFix 09-02-02.02 - Dom 2009-02-02 20:14:37.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.254.63 [GMT 1:00]
Uruchomiony z: c:\program files\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090202-0] *On-access scanning disabled* (Updated)
AV: AVG Internet Security *On-access scanning disabled* (Updated)
FW: AVG Firewall *disabled*
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((( Pliki utworzone od 2009-01-02 do 2009-02-02 )))))))))))))))))))))))))))))))
.
2009-02-02 16:51 . 2009-02-02 16:51 <DIR> d--h----- c:\windows\PIF
2009-01-28 21:22 . 2009-01-28 21:22 <DIR> d-------- c:\program files\CCleaner
2009-01-17 15:30 . 2009-01-17 17:29 <DIR> d-------- c:\documents and settings\Dom\Dane aplikacji\Nowe Gadu-Gadu
2009-01-15 19:07 . 2009-01-15 19:07 <DIR> d-------- c:\windows\msagent
2009-01-15 18:56 . 2009-02-02 15:38 0 --a------ c:\windows\win.ini
2009-01-15 18:56 . 2009-02-02 20:18 0 --a------ c:\windows\system.ini
2009-01-14 18:20 . 2009-01-30 17:18 2,381 --a------ c:\windows\WINCMD.INI
2009-01-10 22:21 . 2009-01-10 22:21 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\BufferZone
2009-01-09 11:16 . 2009-01-09 11:16 <DIR> d-------- c:\documents and settings\Dom\Dane aplikacji\23doors
2009-01-05 22:58 . 2009-01-05 22:58 29,886,752 --a------ c:\program files\setuppol.exe
2009-01-05 17:07 . 2009-02-02 20:12 3,185,523 -ra------ c:\program files\ComboFix.exe
2009-01-03 15:51 . 2009-01-03 15:50 121,184 -r-hs---- C:\wqesvxa.exe
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-28 21:34 --------- d-----w c:\program files\Nokia
2009-01-28 20:51 --------- d-----w c:\documents and settings\Dom\Dane aplikacji\Nokia
2009-01-26 18:24 --------- d-----w c:\documents and settings\Dom\Dane aplikacji\skypePM
2009-01-25 15:56 --------- d-----w c:\documents and settings\Dom\Dane aplikacji\Skype
2009-01-23 16:03 --------- d-----w c:\documents and settings\Dom\Dane aplikacji\Tlen.pl
2009-01-19 17:54 --------- d-----w c:\program files\eMule
2009-01-19 17:31 --------- d-----w c:\program files\Tlen.pl
2009-01-14 17:52 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-09 13:29 --------- d-----w c:\documents and settings\Dom\Dane aplikacji\Nokia Multimedia Player
2009-01-05 22:52 --------- d-----w c:\program files\Alwil Software
2008-12-29 14:44 --------- d-----w c:\program files\Lavasoft
2008-12-29 14:43 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-29 12:57 --------- d-----w c:\program files\Free Audio Pack
2008-12-28 22:45 --------- d-----w c:\program files\SkanerOnline
2008-12-20 11:23 --------- d-----w c:\documents and settings\Dom\Dane aplikacji\Tibia
2008-12-18 22:02 --------- d-----w c:\program files\Google
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-11-17 18:26 7,217,599 ----a-w c:\program files\odk11.3.0808setup.exe
2008-10-21 11:23 13,824 ----a-w c:\program files\RemoveWGA.exe
2008-09-16 16:58 13,135,464 ----a-w c:\program files\MPsetup.exe
2008-05-29 18:07 36,125,344 ----a-w c:\program files\Nero-6.6.1.15d_wch.exe
2008-05-29 17:46 1,251,248 ----a-w c:\program files\Nero-6.6.1.15_plk.exe
2008-05-11 15:42 295,936 ----a-w c:\windows\inf\isprnt.exe
2008-03-31 17:54 32 ----a-w c:\documents and settings\All Users\Dane aplikacji\ezsid.dat
2008-03-05 16:30 9,347,728 ----a-w c:\program files\winamp552_full_pl-pl.exe
2008-03-04 19:57 4,349,168 ----a-w c:\program files\gg77.exe
2008-09-14 14:10 16,384 --sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
2008-09-14 14:10 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
2008-09-14 14:09 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\MSHist012008091420080915\index.dat
2008-09-14 14:10 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2008-05-29 57344]
[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-18 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-11-02 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-02 126976]
"arp"="c:\ARP.EXE" [2008-04-17 45056]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Tlen.pl\\tlen.exe"=
"c:\\Program Files\\gg77.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Documents and Settings\\Dom\\Moje dokumenty\\Klaudia\\Nowe Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20947:TCP"= 20947:TCP:BitComet 20947 TCP
"20947:UDP"= 20947:UDP:BitComet 20947 UDP
"26203:TCP"= 26203:TCP:BitComet 26203 TCP
"26203:UDP"= 26203:UDP:BitComet 26203 UDP
"17658:TCP"= 17658:TCP:BitComet 17658 TCP
"17658:UDP"= 17658:UDP:BitComet 17658 UDP
"8303:TCP"= 8303:TCP:BitComet 8303 TCP
"8303:UDP"= 8303:UDP:BitComet 8303 UDP
"18160:TCP"= 18160:TCP:BitComet 18160 TCP
"18160:UDP"= 18160:UDP:BitComet 18160 UDP
"7343:TCP"= 7343:TCP:BitComet 7343 TCP
"7343:UDP"= 7343:UDP:BitComet 7343 UDP
"8461:TCP"= 8461:TCP:GoD High Port
"8462:TCP"= 8462:TCP:GoD Low Port
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-05 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-05 20560]
R3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\drivers\snp325.sys [2008-03-12 10343168]
S0 AvgRkx86;avgrkx86.sys;c:\windows\system32\Drivers\avgrkx86.sys --> c:\windows\system32\Drivers\avgrkx86.sys [?]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys --> c:\windows\system32\Drivers\avgldx86.sys [?]
S2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys --> c:\windows\system32\Drivers\avgtdix.sys [?]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\DRIVERS\avgfwdx.sys --> c:\windows\system32\DRIVERS\avgfwdx.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwdx.sys --> c:\windows\system32\DRIVERS\avgfwdx.sys [?]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [2008-03-24 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [2008-03-24 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [2008-03-24 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [2008-03-24 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [2008-03-24 83344]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0edfd2f-d1ca-11dd-8797-c15d2e970835}]
\Shell\AutoRun\command - wqesvxa.exe
\Shell\open\Command - wqesvxa.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe9f3dd1-ed14-11dc-8457-0007e992ab10}]
\Shell\AutoRun\command - xlu8a8sy.exe
\Shell\explore\Command - xlu8a8sy.exe
\Shell\open\Command - xlu8a8sy.exe
.
Zawartość folderu 'Zaplanowane zadania'
2009-02-02 c:\windows\Tasks\User_Feed_Synchronization-{545855CE-75B6-4EAE-B92E-5049C185CAE9}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:36]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.wp.pl/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} - hxxp://arcaonline.arcabit.com/ArcaOnline.cab
DPF: {68282C51-9459-467B-95BF-3C0E89627E55} - hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
DPF: {E23FABEE-12E3-33DA-DA12-195DAC123984} - hxxp://67.15.101.33/g_bin/pl/mahjong_2_0_0_31.cab
FF - ProfilePath - c:\documents and settings\Dom\Dane aplikacji\Mozilla\Firefox\Profiles\ycjv3o38.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.wp.pl/
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMAHJONG.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-02 20:17:49
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_LOCAL_MACHINE\software\BufferZone\Virtual\Untrusted\Machine\Software\Microsoft\Windows NT\CurrentVersion\Windows]
@Denied: (Full) (Everyone)
@Denied: (Full) (Everyone)
"VRegSpecialValueName"=dword:000000aa
"AppInit_DLLs"=""
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
.
Czas ukończenia: 2009-02-02 20:20:50
ComboFix-quarantined-files.txt 2009-02-02 19:20:43
ComboFix2.txt 2009-01-15 17:24:28
Przed: 31,384,739,840 bajtów wolnych
Po: 31,377,776,640 bajtów wolnych
170 --- E O F --- 2009-01-16 10:29:45
Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0edfd2f-d1ca-11dd-8797-c15d2e970835}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe9f3dd1-ed14-11dc-8457-0007e992ab10}]
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 4 gości