
Wklejam logo i będę baaardzo wdzięczna za pomoc!
- Kod: Zaznacz wszystko
ComboFix 08-11-10.01 - Magda 2008-11-11 22:23:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.557 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Magda.MAGDALENA\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
.
/wow section - STAGE 10
Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny proces.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\bartek\Dane aplikacji\BITS
c:\documents and settings\bartek\Dane aplikacji\BITS\BITS.ini
c:\documents and settings\bartek\Dane aplikacji\BITS\DHTTable.dat
c:\documents and settings\bartek\Dane aplikacji\BITS\ProxyList.ini
c:\documents and settings\bartek\Dane aplikacji\BITS\Torrent\20081105194916.torrent
c:\documents and settings\bartek\Dane aplikacji\BITS\Torrent\20081105194916.torrent.~tmp
c:\documents and settings\bartek\Dane aplikacji\BITS\Torrent\20081105194916.torrent.bits
c:\documents and settings\bartek\Dane aplikacji\BITS\Torrent\20081105194916.torrent.filelist
c:\documents and settings\bartek\Dane aplikacji\BITS\Torrent\20081105194916.torrent.seeds
c:\documents and settings\bartek\Dane aplikacji\BITS\UPnP.ini
c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\BITS
c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\BITS\BITS.ini
c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\BITS\DHTTable.dat
c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\BITS\ProxyList.ini
c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\BITS\Torrent\20080902154742.torrent
c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\BITS\Torrent\20080902154742.torrent.~tmp
c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\BITS\Torrent\20080902154742.torrent.bits
c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\BITS\Torrent\20080902154742.torrent.filelist
c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\BITS\UPnP.ini
C:\ntde1ect.com
c:\windows\hosts
c:\windows\system32\amvo.exe
c:\windows\system32\amvo0.dll
c:\windows\system32\avpo0.dll
c:\windows\system32\ckvo.exe
c:\windows\system32\ckvo0.dll
c:\windows\system32\nScan
c:\windows\system32\nScan\ecls.exe
c:\windows\system32\nScan\ekrn.exe
c:\windows\system32\nScan\ekrnAmon.dll
c:\windows\system32\nScan\ekrnEmon.dll
c:\windows\system32\nScan\ekrnEpfw.dll
c:\windows\system32\nScan\ekrnScan.dll
c:\windows\system32\nScan\em000_32.dat
c:\windows\system32\nScan\em001_32.dat
c:\windows\system32\nScan\em002_32.dat
c:\windows\system32\nScan\em003_32.dat
c:\windows\system32\nScan\em004_32.dat
c:\windows\system32\nScan\em005_32.dat
c:\windows\system32\nScan\em006_32.dat
c:\windows\system32\nScan\mod_comp.dat
c:\windows\system32\splm
F:\Autorun.inf
F:\nq0cq.cmd
F:\ntde1ect.com
F:\xih9.cmd
.
((((((((((((((((((((((((( Pliki utworzone od 2008-10-11 do 2008-11-11 )))))))))))))))))))))))))))))))
.
2008-11-11 20:29 . 2008-11-11 20:26 109,736 -r-hs---- C:\lky.exe
2008-11-11 20:27 . 2008-11-11 20:26 109,736 -r-hs---- c:\windows\system32\kamsoft.exe
2008-11-11 20:25 . 2008-11-08 19:27 108,973 -r-hs---- C:\sq.com
2008-11-10 03:43 . 2004-08-04 13:00 13,463,552 --a------ c:\windows\system32\dllcache\hwxjpn.dll
2008-11-09 14:24 . 2008-11-11 22:26 <DIR> d--h----- c:\documents and settings\Administrator\Ustawienia lokalne
2008-11-09 14:24 . 2008-02-09 15:59 <DIR> d-------- c:\documents and settings\Administrator\Ulubione
2008-11-09 14:24 . 2008-02-09 15:14 <DIR> d--h----- c:\documents and settings\Administrator\Szablony
2008-11-09 14:24 . 2008-02-09 15:59 <DIR> d-------- c:\documents and settings\Administrator\Pulpit
2008-11-09 14:24 . 2008-02-09 15:59 <DIR> d-------- c:\documents and settings\Administrator\Moje dokumenty
2008-11-09 14:24 . 2008-02-09 15:59 <DIR> dr------- c:\documents and settings\Administrator\Menu Start
2008-11-09 14:24 . 2008-11-09 14:31 <DIR> dr-h----- c:\documents and settings\Administrator\Dane aplikacji
2008-11-09 14:24 . 2008-11-09 14:24 <DIR> d-------- c:\documents and settings\Administrator
2008-11-09 14:13 . 2008-11-09 14:13 <DIR> d-------- c:\program files\Avira
2008-11-09 14:13 . 2008-11-09 14:13 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Avira
2008-11-09 13:53 . 2008-11-09 14:01 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-09 13:53 . 2008-11-09 13:54 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-11-05 17:13 . 2008-11-05 17:13 <DIR> d-------- c:\documents and settings\bartek\Dane aplikacji\Apple Computer
2008-11-05 11:20 . 2008-11-06 07:33 108,223 -r-hs---- C:\nq0cq.cmd
2008-11-05 00:21 . 2008-11-05 00:21 <DIR> d-------- c:\program files\Alwil Software
2008-11-04 21:12 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2008-11-04 21:10 . 2008-11-04 21:10 <DIR> d-------- c:\program files\Panda Security
2008-11-02 18:00 . 2008-11-04 21:07 107,342 -r-hs---- C:\xih9.cmd
2008-11-01 00:47 . 2008-11-01 00:47 468 --a------ c:\windows\system32\acdb.err
2008-10-29 19:19 . 2008-10-30 23:59 <DIR> d-------- c:\program files\iTunes
2008-10-29 19:19 . 2008-10-29 19:19 <DIR> d-------- c:\program files\iPod
2008-10-29 19:19 . 2008-10-29 19:21 <DIR> d-------- c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\Apple Computer
2008-10-29 19:19 . 2008-10-29 19:19 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-29 19:19 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-10-29 19:19 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-10-29 19:18 . 2008-10-29 19:18 <DIR> d-------- c:\program files\Bonjour
2008-10-29 19:16 . 2008-10-29 19:16 54,156 --ah----- c:\windows\QTFont.qfn
2008-10-29 19:16 . 2008-10-29 19:16 1,409 --a------ c:\windows\QTFont.for
2008-10-29 19:14 . 2008-10-29 19:15 <DIR> d-------- c:\program files\Apple Software Update
2008-10-29 19:14 . 2008-10-01 13:01 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys
2008-10-29 19:13 . 2008-10-29 19:17 <DIR> d-------- c:\program files\Common Files\Apple
2008-10-29 19:13 . 2008-10-29 19:13 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Apple
2008-10-27 22:38 . 2008-10-27 22:38 38 --a------ c:\windows\avisplitter.INI
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-09 13:07 --------- d-----w c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\OpenOffice.ux.pl2
2008-11-09 12:40 --------- d-----w c:\documents and settings\bartek\Dane aplikacji\Hamachi
2008-11-05 21:09 --------- d-----w c:\documents and settings\bartek\Dane aplikacji\Skype
2008-11-05 16:07 --------- d-----w c:\documents and settings\bartek\Dane aplikacji\skypePM
2008-11-05 02:02 --------- d-----w c:\program files\Norton AntiVirus
2008-11-05 02:02 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-05 02:02 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Symantec
2008-11-04 23:17 --------- d-----w c:\program files\Symantec
2008-11-04 12:46 --------- d-----w c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\Skype
2008-11-04 10:13 --------- d-----w c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\skypePM
2008-11-03 20:26 --------- d-----w c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\uTorrent
2008-10-29 18:19 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Apple Computer
2008-10-29 18:18 --------- d-----w c:\program files\QuickTime
2008-10-21 18:58 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-03 12:34 --------- d-----w c:\program files\Lexmark X1100 Series
2008-09-22 12:49 --------- d-----w c:\documents and settings\bartek\Dane aplikacji\Winamp
2008-09-21 08:21 --------- d-----w c:\documents and settings\bartek\Dane aplikacji\uTorrent
2008-09-20 21:10 --------- d-----w c:\documents and settings\bartek\Dane aplikacji\Sahmon Games
2008-09-12 20:34 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Last.fm
2008-09-12 15:30 --------- d-----w c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\Tlen.pl
2008-09-11 16:52 --------- d-----w c:\program files\Winamp Toolbar
2008-09-11 16:52 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Winamp Toolbar
2008-09-11 16:49 --------- d-----w c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\Winamp
2008-07-20 14:00 22,328 ----a-w c:\documents and settings\bartek\Dane aplikacji\PnkBstrK.sys
2008-02-10 13:55 32 -c--a-w c:\documents and settings\All Users\Dane aplikacji\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Komunikator"="f:\instalki\Tlen.pl\tlen.exe" [2008-01-15 6290944]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2007-12-30 1365504]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"nwiz"="nwiz.exe" [2006-02-08 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2006-04-19 12:08 49152 c:\program files\Softex\OmniPass\OPXPGina.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BTTray.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Monitor podłączenia telefonu.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Monitor podłączenia telefonu.lnk
backup=c:\windows\pss\Monitor podłączenia telefonu.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Przyspieszenie uruchomienia programu AutoCAD.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Przyspieszenie uruchomienia programu AutoCAD.lnk
backup=c:\windows\pss\Przyspieszenie uruchomienia programu AutoCAD.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^bartek^Menu Start^Programy^Autostart^hamachi.lnk]
path=c:\documents and settings\bartek\Menu Start\Programy\Autostart\hamachi.lnk
backup=c:\windows\pss\hamachi.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Magda.MAGDALENA^Menu Start^Programy^Autostart^OpenOffice.ux.pl 2.3.1.lnk]
path=c:\documents and settings\Magda.MAGDALENA\Menu Start\Programy\Autostart\OpenOffice.ux.pl 2.3.1.lnk
backup=c:\windows\pss\OpenOffice.ux.pl 2.3.1.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
--a------ 2008-05-16 01:19 79224 c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
--------- 2005-08-25 06:21 53248 c:\program files\Realtek\InstallShield\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-11-16 19:04 139264 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 13:00 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EOUApp]
--a------ 2006-04-14 11:56 569413 c:\program files\Intel\Wireless\Bin\EOUWiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashGet]
--------- 2008-08-19 08:47 1795656 f:\instalki\FlashGet universal\flashget.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2006-04-14 11:52 602182 c:\program files\Intel\Wireless\Bin\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 2006-04-14 11:51 667718 c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-08-11 16:30 249856 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-08-11 16:30 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 18:57 289576 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KTPWare]
-ra------ 2006-03-28 11:36 512000 c:\program files\Elantech\Ktp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
--a------ 2003-08-19 16:09 57344 c:\program files\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 17:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2006-01-12 15:40 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-02-08 22:06 7405568 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPass]
--a------ 2006-04-19 12:12 2084864 c:\program files\Softex\OmniPass\scureapp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2std]
--a------ 2006-05-15 15:52 675840 c:\windows\vsnp2std.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2005-10-26 15:17 159744 c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-12-14 03:42 144784 c:\program files\Java\jre1.6.0_04\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp2std]
--a------ 2006-06-14 19:20 331776 c:\windows\system32\tsnp2std.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WengoPhoneNG]
--a------ 2007-08-22 16:26 4964352 c:\program files\WengoPhone\qtwengophone.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-07-09 22:33 36352 f:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
-ra------ 2005-12-12 06:50 88204 c:\windows\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 10:43 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EXPLORER.EXE]
--a------ 2007-06-13 14:23 1034752 c:\windows\explorer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2006-04-17 07:34 16143872 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Tlen.pl\\tlen.exe"=
"c:\\Program Files\\WengoPhone\\qtwengophone.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Java\\jre1.6.0_04\\bin\\javaw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"f:\\Instalki\\PPMate\\ppmate.exe"=
"f:\\Instalki\\PPMate\\ppamnet.exe"=
"f:\\Program Files\\Intuwave Ltd\\Shared\\mRouterRunTime\\mRouterRuntime.exe"=
"f:\\Program Files\\Bin32\\Crysis.exe"=
"f:\\Program Files\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"f:\\Instalki\\Tlen.pl\\tlen.exe"=
"f:\\Instalki\\SoulseekNS\\slsk.exe"=
"c:\\progra~1\\mozill~1\\firefox.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"f:\\Instalki\\FlashGet universal\\FlashGet.exe"=
"f:\\Instalki\\Extreme Racers.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-05-16 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-05-16 20560]
R3 IFXTPM;IFXTPM;c:\windows\system32\DRIVERS\IFXTPM.SYS [2005-10-21 36352]
R3 Ktp;Elantech Touchpad;c:\windows\system32\DRIVERS\Ktp.sys [2006-03-17 27904]
R3 SNP2STD;USB2.0 PC Camera (SNP2STD);c:\windows\system32\DRIVERS\snp2sxp.sys [2006-05-23 10304384]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;c:\windows\system32\NSNDIS5.SYS [2004-03-24 17280]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e077184-572a-11dd-862c-0016d4d82f69}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1b510f92-87d6-11dd-8690-0016d4d82f69}]
\Shell\AutoRun\command - sq.com
\Shell\explore\Command - sq.com
\Shell\open\Command - sq.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c2b8100-f5ae-11dc-84f3-0016d4d82f69}]
\Shell\AutoRun\command - J:\xn1i9x.com
\Shell\explore\Command - J:\xn1i9x.com
\Shell\open\Command - J:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5efe333e-f41d-11dc-84e6-0016d4d82f69}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5efe333f-f41d-11dc-84e6-0016d4d82f69}]
\Shell\AutoRun\command - J:\ntde1ect.com
\Shell\explore\Command - J:\ntde1ect.com
\Shell\open\Command - J:\ntde1ect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{88cdf70c-4290-11dd-85f8-0016d4d82f69}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{89f81d91-dba8-11dc-8481-0016d4d82f69}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a99521de-edbb-11dc-84c9-0016d4d82f69}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6476868-0481-11dd-851a-0016d4d82f69}]
\Shell\AutoRun\command - I:\q.com
\Shell\explore\Command - I:\q.com
\Shell\open\Command - I:\q.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce51fd3c-dbe2-11dc-8484-0016d4d82f69}]
\Shell\Auto\command - setup.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc078f33-f4be-11dc-84ea-0016d4d82f69}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de126c72-3604-11dd-85cf-0016d4d82f69}]
\Shell\AutoRun\command - I:\EXPLORER.EXE
\Shell\explore\Command - I:\EXPLORER.EXE
\Shell\open\Command - I:\EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e038db8d-022a-11dd-8513-0016d4d82f69}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e038db8e-022a-11dd-8513-0016d4d82f69}]
\Shell\AutoRun\command - 32e2.com
\Shell\explore\Command - 32e2.com
\Shell\open\Command - 32e2.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4b86d0a-abec-11dd-86e6-0016d4d82f69}]
\Shell\AutoRun\command - I:\nq0cq.cmd
\Shell\explore\Command - I:\nq0cq.cmd
\Shell\open\Command - I:\nq0cq.cmd
.
Zawartość folderu 'Zaplanowane zadania'
2008-11-11 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKU-Default-RunOnce-<NO NAME> - (no file)
Notify-dimsntfy - (no file)
MSConfigStartUp-kamsoft - c:\windows\system32\ckvo.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
MSConfigStartUp-wsctf - wsctf.exe
.
------- Skan uzupełniający -------
.
FireFox -: Profile - c:\documents and settings\Magda.MAGDALENA\Dane aplikacji\Mozilla\Firefox\Profiles\d9yynjcg.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
.
.
------- Skojarzenia plików -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-11 22:31:25
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
PROCES: c:\windows\system32\winlogon.exe
-> c:\program files\Softex\OmniPass\opxpgina.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\Windows Defender\MsMpEng.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Softex\OmniPass\OmniServ.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
.
**************************************************************************
.
Czas ukończenia: 2008-11-11 22:36:27 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-11-11 21:36:25
Przed: 5 554 241 536 bajtów wolnych
Po: 6,513,479,680 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
384 --- E O F --- 2008-11-11 02:44:58