
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:01:52, on 2008-10-20
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\spioch\Pulpit\net\hijackthis.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINNT\TEMP\E_SE7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
--
End of file - 5275 bytes
- Kod: Zaznacz wszystko
ComboFix 08-10-11.01 - spioch 2008-10-20 15:04:18.3 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.12 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\spioch\Pulpit\net\ComboFix.exe
[color=RED][b]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/b][/color]
.
- TRYB ZREDUKOWANEJ FUNKCJONALNOŚCI -
.
((((((((((((((((((((((((( Pliki utworzone od 2008-09-20 do 2008-10-20 )))))))))))))))))))))))))))))))
.
2008-10-20 01:01 . 2008-10-20 01:01 <DIR> d-------- C:\Program Files\Lavalys
2008-10-19 16:52 . 2008-10-19 16:52 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-10-19 16:29 . 2008-10-19 16:29 <DIR> d-------- C:\WINNT\system32\pl-pl
2008-10-19 16:05 . 2008-10-19 16:05 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\DeskSoft
2008-10-19 16:04 . 2008-10-19 16:04 <DIR> d-------- C:\Program Files\BWMeter
2008-10-19 16:04 . 2008-10-19 16:04 <DIR> d-------- C:\Documents and Settings\spioch\Dane aplikacji\DeskSoft
2008-10-19 16:04 . 2008-10-19 16:04 26,920 --a------ C:\WINNT\system32\drivers\dsnpfd.sys
2008-10-19 14:46 . 2008-10-19 14:46 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\MailFrontier
2008-10-19 14:45 . 2004-04-27 04:40 11,264 --a------ C:\WINNT\system32\SpOrder.dll
2008-10-19 14:45 . 2008-10-19 14:49 4,212 ---h----- C:\WINNT\system32\zllictbl.dat
2008-10-19 14:43 . 2008-10-19 14:43 <DIR> d-------- C:\WINNT\Internet Logs
2008-10-19 11:42 . 2008-10-19 11:42 <DIR> d-------- C:\Program Files\CCleaner
2008-10-17 15:05 . 2008-10-17 15:05 <DIR> d-------- C:\Program Files\Network Stumbler
2008-10-12 11:55 . 2008-10-12 11:55 51,232 --a------ C:\wwdc.exe
2008-10-12 09:31 . 2008-10-12 09:31 <DIR> d-------- C:\WINNT\system32\xircom
2008-10-12 09:31 . 2008-10-12 09:31 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-10-11 19:43 . 2008-10-11 19:43 <DIR> d-------- C:\Program Files\SkanerOnline
2008-10-05 21:47 . 2008-10-05 21:47 <DIR> d-------- C:\Program Files\Hamachi
2008-09-26 13:50 . 2008-09-26 13:50 <DIR> d--hs---- C:\FOUND.006
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-10 20:26 25,280 ----a-w C:\WINNT\system32\drivers\hamachi.sys
2008-09-17 14:40 --------- d-----w C:\Program Files\Mp3 Knife
2008-09-03 13:12 --------- d-----w C:\Program Files\Soulseek
2008-09-02 20:23 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Last.fm
2008-09-02 20:22 --------- d-----w C:\Program Files\Last.fm
2008-08-20 22:47 --------- d-----w C:\Program Files\7-Zip
.
((((((((((((((((((((((((((((( snapshot@2008-10-12_ 2.06.46,61 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-06-30 08:39:58 128,256 ----a-w C:\WINNT\Downloaded Program Files\as2stubie.dll
+ 2004-08-03 22:43:52 61,440 ------w C:\WINNT\ie7\admparse.dll
+ 2004-08-03 22:43:52 100,864 ------w C:\WINNT\ie7\advpack.dll
+ 2006-03-04 03:01:28 1,022,976 ------w C:\WINNT\ie7\browseui.dll
+ 2004-08-03 22:43:56 35,328 ------w C:\WINNT\ie7\corpol.dll
+ 2004-08-03 22:43:58 357,888 ------w C:\WINNT\ie7\dxtmsft.dll
+ 2006-03-04 03:01:28 205,312 ------w C:\WINNT\ie7\dxtrans.dll
+ 2006-03-04 03:01:28 55,808 ------w C:\WINNT\ie7\extmgr.dll
+ 2004-08-03 23:44:00 38,912 ------w C:\WINNT\ie7\hmmapi.dll
+ 2004-08-03 22:44:22 34,304 ------w C:\WINNT\ie7\ie4uinit.exe
+ 2004-08-03 22:44:00 139,264 ------w C:\WINNT\ie7\ieakeng.dll
+ 2004-08-03 22:44:00 219,648 ------w C:\WINNT\ie7\ieaksie.dll
+ 2001-10-26 17:28:02 237,568 ------w C:\WINNT\ie7\ieakui.dll
+ 2004-08-03 22:44:00 323,584 ------w C:\WINNT\ie7\iedkcs32.dll
+ 2006-03-04 00:34:42 18,432 ------w C:\WINNT\ie7\iedw.exe
+ 2004-08-03 22:44:00 81,920 ------w C:\WINNT\ie7\ieencode.dll
+ 2006-03-04 03:01:28 251,904 ------w C:\WINNT\ie7\iepeers.dll
+ 2004-08-03 22:44:00 48,640 ------w C:\WINNT\ie7\iernonce.dll
+ 2004-08-03 22:44:00 63,488 ------w C:\WINNT\ie7\iesetup.dll
+ 2004-08-03 23:44:22 93,184 ------w C:\WINNT\ie7\iexplore.exe
+ 2004-08-03 22:44:00 35,840 ------w C:\WINNT\ie7\imgutil.dll
+ 2006-03-04 03:01:28 96,768 ------w C:\WINNT\ie7\inseng.dll
+ 2004-08-03 22:44:02 450,560 ------w C:\WINNT\ie7\jscript.dll
+ 2004-08-03 22:44:02 15,872 ------w C:\WINNT\ie7\jsproxy.dll
+ 2004-08-03 22:44:02 22,016 ------w C:\WINNT\ie7\licmgr10.dll
+ 2004-08-03 22:44:24 29,184 ------w C:\WINNT\ie7\mshta.exe
+ 2006-04-10 02:22:10 3,077,120 ------w C:\WINNT\ie7\mshtml.dll
+ 2006-03-04 03:01:30 448,512 ------w C:\WINNT\ie7\mshtmled.dll
+ 2004-08-03 22:42:58 57,344 ------w C:\WINNT\ie7\mshtmler.dll
+ 2001-10-26 17:26:58 146,432 ------w C:\WINNT\ie7\msls31.dll
+ 2006-03-04 03:01:30 146,432 ------w C:\WINNT\ie7\msrating.dll
+ 2006-03-04 03:01:32 532,480 ------w C:\WINNT\ie7\mstime.dll
+ 2004-08-03 22:44:08 97,280 ------w C:\WINNT\ie7\occache.dll
+ 2006-03-04 03:01:32 39,424 ------w C:\WINNT\ie7\pngfilt.dll
+ 2006-03-30 08:29:58 1,495,040 ------w C:\WINNT\ie7\shdocvw.dll
+ 2006-03-04 03:01:32 474,112 ------w C:\WINNT\ie7\shlwapi.dll
+ 2007-09-27 14:05:44 33,472 ------w C:\WINNT\ie7\spuninst\iecustom.dll
+ 2007-09-27 14:03:44 66,048 ----a-w C:\WINNT\ie7\spuninst\ieResetIcons.exe
+ 2006-09-06 15:43:48 216,288 ------w C:\WINNT\ie7\spuninst\spuninst.exe
+ 2006-09-06 15:43:48 386,784 ------w C:\WINNT\ie7\spuninst\updspapi.dll
+ 2004-08-03 22:44:14 37,888 ------w C:\WINNT\ie7\url.dll
+ 2006-03-18 10:07:58 615,424 ------w C:\WINNT\ie7\urlmon.dll
+ 2004-08-03 22:44:14 417,792 ------w C:\WINNT\ie7\vbscript.dll
+ 2004-08-03 23:44:14 848,384 ------w C:\WINNT\ie7\vgx.dll
+ 2004-08-03 22:44:14 279,552 ------w C:\WINNT\ie7\webcheck.dll
+ 2006-03-04 03:01:32 666,112 ------w C:\WINNT\ie7\wininet.dll
- 2004-08-03 22:43:52 61,440 ----a-w C:\WINNT\system32\admparse.dll
+ 2007-08-13 16:39:20 71,680 ----a-w C:\WINNT\system32\admparse.dll
- 2004-08-03 22:43:52 100,864 ----a-w C:\WINNT\system32\advpack.dll
+ 2007-08-13 16:39:00 123,904 ----a-w C:\WINNT\system32\advpack.dll
- 2006-03-04 03:01:28 1,022,976 ----a-w C:\WINNT\system32\browseui.dll
+ 2006-09-23 11:13:00 1,022,976 ----a-w C:\WINNT\system32\browseui.dll
- 2004-08-03 22:43:56 35,328 ----a-w C:\WINNT\system32\corpol.dll
+ 2007-08-13 16:42:54 17,408 ----a-w C:\WINNT\system32\corpol.dll
+ 2007-08-13 16:39:20 71,680 ------w C:\WINNT\system32\dllcache\admparse.dll
+ 2007-08-13 16:39:00 123,904 ------w C:\WINNT\system32\dllcache\advpack.dll
+ 2006-09-23 11:13:00 1,022,976 ------w C:\WINNT\system32\dllcache\browseui.dll
+ 2007-08-13 16:42:54 17,408 ------w C:\WINNT\system32\dllcache\corpol.dll
+ 2007-08-13 16:54:10 33,792 ------w C:\WINNT\system32\dllcache\custsat.dll
+ 2007-08-13 16:35:46 346,624 ------w C:\WINNT\system32\dllcache\dxtmsft.dll
+ 2007-08-13 16:35:38 214,528 ------w C:\WINNT\system32\dllcache\dxtrans.dll
+ 2007-08-13 16:54:10 131,584 ------w C:\WINNT\system32\dllcache\extmgr.dll
+ 2007-08-13 16:18:02 60,416 ------w C:\WINNT\system32\dllcache\hmmapi.dll
+ 2007-08-13 16:39:06 54,784 ------w C:\WINNT\system32\dllcache\ie4uinit.exe
+ 2007-08-13 16:39:26 152,064 ------w C:\WINNT\system32\dllcache\ieakeng.dll
+ 2007-08-13 16:39:54 229,376 ------w C:\WINNT\system32\dllcache\ieaksie.dll
+ 2007-08-13 15:56:54 161,792 ------w C:\WINNT\system32\dllcache\ieakui.dll
+ 2007-08-13 16:39:50 382,976 ------w C:\WINNT\system32\dllcache\iedkcs32.dll
+ 2007-08-13 16:44:02 69,120 ------w C:\WINNT\system32\dllcache\iedw.exe
+ 2007-08-13 16:45:18 78,336 ------w C:\WINNT\system32\dllcache\ieencode.dll
+ 2007-08-13 16:54:10 191,488 ------w C:\WINNT\system32\dllcache\iepeers.dll
+ 2007-08-13 16:39:10 43,008 ------w C:\WINNT\system32\dllcache\iernonce.dll
+ 2007-08-13 16:39:12 55,296 ------w C:\WINNT\system32\dllcache\iesetup.dll
+ 2007-08-13 16:43:56 622,080 ------w C:\WINNT\system32\dllcache\iexplore.exe
+ 2007-08-13 16:36:06 36,352 ------w C:\WINNT\system32\dllcache\imgutil.dll
+ 2007-08-13 16:39:02 92,672 ------w C:\WINNT\system32\dllcache\inseng.dll
+ 2007-08-13 16:38:04 491,520 ------w C:\WINNT\system32\dllcache\jscript.dll
+ 2007-08-13 16:54:10 27,136 ------w C:\WINNT\system32\dllcache\jsproxy.dll
+ 2007-08-13 16:44:18 40,960 ------w C:\WINNT\system32\dllcache\licmgr10.dll
+ 2007-08-13 16:32:30 45,568 ------w C:\WINNT\system32\dllcache\mshta.exe
+ 2007-08-13 16:54:12 3,578,368 ------w C:\WINNT\system32\dllcache\mshtml.dll
+ 2007-08-13 16:54:10 475,648 ------w C:\WINNT\system32\dllcache\mshtmled.dll
+ 2007-08-13 16:01:12 48,128 ------w C:\WINNT\system32\dllcache\mshtmler.dll
+ 2007-08-13 16:54:10 156,160 ------w C:\WINNT\system32\dllcache\msls31.dll
+ 2007-08-13 16:44:26 192,000 ------w C:\WINNT\system32\dllcache\msrating.dll
+ 2007-08-13 16:54:10 670,720 ------w C:\WINNT\system32\dllcache\mstime.dll
+ 2007-08-13 16:44:06 101,376 ------w C:\WINNT\system32\dllcache\occache.dll
+ 2007-08-13 16:36:12 44,544 ------w C:\WINNT\system32\dllcache\pngfilt.dll
+ 2006-09-23 11:13:02 1,497,088 ------w C:\WINNT\system32\dllcache\shdocvw.dll
+ 2006-09-23 11:13:02 474,112 ------w C:\WINNT\system32\dllcache\shlwapi.dll
+ 2007-08-13 16:44:30 105,984 ------w C:\WINNT\system32\dllcache\url.dll
+ 2007-08-13 16:54:10 1,162,240 ------w C:\WINNT\system32\dllcache\urlmon.dll
+ 2007-08-13 16:54:10 413,696 ------w C:\WINNT\system32\dllcache\vbscript.dll
+ 2007-08-13 16:54:10 765,952 ------w C:\WINNT\system32\dllcache\VGX.dll
+ 2007-08-13 16:54:10 231,424 ------w C:\WINNT\system32\dllcache\webcheck.dll
+ 2007-08-13 16:54:10 818,688 ------w C:\WINNT\system32\dllcache\wininet.dll
- 2004-08-03 22:43:58 357,888 ----a-w C:\WINNT\system32\dxtmsft.dll
+ 2007-08-13 16:35:46 346,624 ----a-w C:\WINNT\system32\dxtmsft.dll
- 2006-03-04 03:01:28 205,312 ----a-w C:\WINNT\system32\dxtrans.dll
+ 2007-08-13 16:35:38 214,528 ----a-w C:\WINNT\system32\dxtrans.dll
- 2006-03-04 03:01:28 55,808 ----a-w C:\WINNT\system32\extmgr.dll
+ 2007-08-13 16:54:10 131,584 ----a-w C:\WINNT\system32\extmgr.dll
+ 2007-08-13 16:36:26 61,952 ------w C:\WINNT\system32\icardie.dll
+ 2006-06-29 06:05:44 26,112 ------w C:\WINNT\system32\idndl.dll
- 2004-08-03 22:44:22 34,304 ----a-w C:\WINNT\system32\ie4uinit.exe
+ 2007-08-13 16:39:06 54,784 ----a-w C:\WINNT\system32\ie4uinit.exe
- 2004-08-03 22:44:00 139,264 ----a-w C:\WINNT\system32\ieakeng.dll
+ 2007-08-13 16:39:26 152,064 ----a-w C:\WINNT\system32\ieakeng.dll
- 2004-08-03 22:44:00 219,648 ----a-w C:\WINNT\system32\ieaksie.dll
+ 2007-08-13 16:39:54 229,376 ----a-w C:\WINNT\system32\ieaksie.dll
- 2001-10-26 17:28:02 237,568 ----a-w C:\WINNT\system32\ieakui.dll
+ 2007-08-13 15:56:54 161,792 ----a-w C:\WINNT\system32\ieakui.dll
+ 2007-02-12 14:10:12 2,451,312 ------w C:\WINNT\system32\ieapfltr.dat
+ 2007-07-11 10:27:48 383,488 ------w C:\WINNT\system32\ieapfltr.dll
- 2004-08-03 22:44:00 323,584 ----a-w C:\WINNT\system32\iedkcs32.dll
+ 2007-08-13 16:39:50 382,976 ----a-w C:\WINNT\system32\iedkcs32.dll
- 2004-08-03 22:44:00 81,920 ----a-w C:\WINNT\system32\ieencode.dll
+ 2007-08-13 16:45:18 78,336 ----a-w C:\WINNT\system32\ieencode.dll
+ 2007-08-13 16:54:10 6,049,280 ------w C:\WINNT\system32\ieframe.dll
- 2006-03-04 03:01:28 251,904 ----a-w C:\WINNT\system32\iepeers.dll
+ 2007-08-13 16:54:10 191,488 ----a-w C:\WINNT\system32\iepeers.dll
- 2004-08-03 22:44:00 48,640 ----a-w C:\WINNT\system32\iernonce.dll
+ 2007-08-13 16:39:10 43,008 ----a-w C:\WINNT\system32\iernonce.dll
+ 2007-08-13 16:34:04 266,752 ------w C:\WINNT\system32\iertutil.dll
- 2004-08-03 22:44:00 63,488 ----a-w C:\WINNT\system32\iesetup.dll
+ 2007-08-13 16:39:12 55,296 ----a-w C:\WINNT\system32\iesetup.dll
+ 2007-08-13 16:39:10 13,312 ----a-w C:\WINNT\system32\ieudinit.exe
+ 2007-08-13 16:54:10 180,736 ------w C:\WINNT\system32\ieui.dll
- 2004-08-03 22:44:00 35,840 ----a-w C:\WINNT\system32\imgutil.dll
+ 2007-08-13 16:36:06 36,352 ----a-w C:\WINNT\system32\imgutil.dll
- 2006-03-04 03:01:28 96,768 ----a-w C:\WINNT\system32\inseng.dll
+ 2007-08-13 16:39:02 92,672 ----a-w C:\WINNT\system32\inseng.dll
- 2004-08-03 22:44:02 450,560 ----a-w C:\WINNT\system32\jscript.dll
+ 2007-08-13 16:38:04 491,520 ----a-w C:\WINNT\system32\jscript.dll
- 2004-08-03 22:44:02 15,872 ----a-w C:\WINNT\system32\jsproxy.dll
+ 2007-08-13 16:54:10 27,136 ----a-w C:\WINNT\system32\jsproxy.dll
- 2004-08-03 22:44:02 22,016 ----a-w C:\WINNT\system32\licmgr10.dll
+ 2007-08-13 16:44:18 40,960 ----a-w C:\WINNT\system32\licmgr10.dll
+ 2007-07-27 12:49:02 196,683 ----a-w C:\WINNT\system32\lnod32apiA.dll
+ 2007-07-27 12:49:02 225,355 ----a-w C:\WINNT\system32\lnod32apiW.dll
+ 2005-12-05 17:25:22 139,264 ----a-w C:\WINNT\system32\lnod32umc.dll
+ 2005-12-05 10:37:10 106,496 ----a-w C:\WINNT\system32\lnod32upd.dll
+ 2007-08-13 16:54:10 458,752 ------w C:\WINNT\system32\msfeeds.dll
+ 2007-08-13 16:54:10 50,688 ------w C:\WINNT\system32\msfeedsbs.dll
+ 2007-08-13 16:36:40 12,288 ------w C:\WINNT\system32\msfeedssync.exe
- 2004-08-03 22:44:24 29,184 ----a-w C:\WINNT\system32\mshta.exe
+ 2007-08-13 16:32:30 45,568 ----a-w C:\WINNT\system32\mshta.exe
- 2006-04-10 02:22:10 3,077,120 ----a-w C:\WINNT\system32\mshtml.dll
+ 2007-08-13 16:54:12 3,578,368 ----a-w C:\WINNT\system32\mshtml.dll
- 2006-03-04 03:01:30 448,512 ----a-w C:\WINNT\system32\mshtmled.dll
+ 2007-08-13 16:54:10 475,648 ----a-w C:\WINNT\system32\mshtmled.dll
- 2004-08-03 22:42:58 57,344 ----a-w C:\WINNT\system32\mshtmler.dll
+ 2007-08-13 16:01:12 48,128 ----a-w C:\WINNT\system32\mshtmler.dll
- 2001-10-26 17:26:58 146,432 ----a-w C:\WINNT\system32\msls31.dll
+ 2007-08-13 16:54:10 156,160 ----a-w C:\WINNT\system32\msls31.dll
- 2006-03-04 03:01:30 146,432 ----a-w C:\WINNT\system32\msrating.dll
+ 2007-08-13 16:44:26 192,000 ----a-w C:\WINNT\system32\msrating.dll
- 2006-03-04 03:01:32 532,480 ----a-w C:\WINNT\system32\mstime.dll
+ 2007-08-13 16:54:10 670,720 ----a-w C:\WINNT\system32\mstime.dll
+ 2006-06-29 06:05:44 23,552 ------w C:\WINNT\system32\normaliz.dll
+ 2004-03-24 02:12:34 17,280 ----a-w C:\WINNT\system32\nsndis5.sys
+ 2004-03-24 02:49:36 94,208 ----a-w C:\WINNT\system32\nsndis50.dll
- 2004-08-03 22:44:08 97,280 ----a-w C:\WINNT\system32\occache.dll
+ 2007-08-13 16:44:06 101,376 ----a-w C:\WINNT\system32\occache.dll
+ 2008-02-11 07:39:26 253,952 ----a-w C:\WINNT\system32\OnlineScannerDLLA.dll
+ 2008-02-11 07:39:18 237,568 ----a-w C:\WINNT\system32\OnlineScannerDLLW.dll
+ 2008-02-08 11:53:46 110,592 ----a-w C:\WINNT\system32\OnlineScannerLang.dll
+ 2008-02-05 06:48:04 77,824 ----a-w C:\WINNT\system32\OnlineScannerUninstaller.exe
- 2006-03-04 03:01:32 39,424 ----a-w C:\WINNT\system32\pngfilt.dll
+ 2007-08-13 16:36:12 44,544 ----a-w C:\WINNT\system32\pngfilt.dll
- 2006-03-30 08:29:58 1,495,040 ----a-w C:\WINNT\system32\shdocvw.dll
+ 2006-09-23 11:13:02 1,497,088 ----a-w C:\WINNT\system32\shdocvw.dll
- 2006-03-04 03:01:32 474,112 ----a-w C:\WINNT\system32\shlwapi.dll
+ 2006-09-23 11:13:02 474,112 ----a-w C:\WINNT\system32\shlwapi.dll
- 2006-05-24 10:32:48 14,048 ------w C:\WINNT\system32\spmsg.dll
+ 2006-09-06 15:43:48 16,096 ------w C:\WINNT\system32\spmsg.dll
- 2006-05-24 10:32:48 22,752 ----a-w C:\WINNT\system32\spupdsvc.exe
+ 2006-09-06 15:43:48 22,752 ----a-w C:\WINNT\system32\spupdsvc.exe
+ 2004-12-07 08:11:34 258,352 ----a-w C:\WINNT\system32\unicows.dll
- 2004-08-03 22:44:14 37,888 ----a-w C:\WINNT\system32\url.dll
+ 2007-08-13 16:44:30 105,984 ----a-w C:\WINNT\system32\url.dll
- 2006-03-18 10:07:58 615,424 ----a-w C:\WINNT\system32\urlmon.dll
+ 2007-08-13 16:54:10 1,162,240 ----a-w C:\WINNT\system32\urlmon.dll
- 2004-08-03 22:44:14 417,792 ----a-w C:\WINNT\system32\vbscript.dll
+ 2007-08-13 16:54:10 413,696 ----a-w C:\WINNT\system32\vbscript.dll
- 2004-08-03 22:44:14 279,552 ----a-w C:\WINNT\system32\webcheck.dll
+ 2007-08-13 16:54:10 231,424 ----a-w C:\WINNT\system32\webcheck.dll
+ 2007-08-13 16:45:16 206,336 ------w C:\WINNT\system32\WinFXDocObj.exe
- 2006-03-04 03:01:32 666,112 ----a-w C:\WINNT\system32\wininet.dll
+ 2007-08-13 16:54:10 818,688 ----a-w C:\WINNT\system32\wininet.dll
+ 2008-10-20 09:51:22 16,384 ----a-w C:\WINNT\Temp\Perflib_Perfdata_724.dat
.
-- Migawka wyzerowana --
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus DX7400 Series"="C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE" [2007-04-12 182272]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NeroCheck"="C:\WINNT\system32\NeroCheck.exe" [2001-07-09 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINNT\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="C:\WINNT\system32\tscupgrd.exe" [2004-08-04 44544]
C:\Documents and Settings\spioch\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Ralink Wireless Utility.lnk - C:\Program Files\RALINK\Common\RaUI.exe [2008-03-28 614400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\WinZip Quick Pick.lnk
backup=C:\WINNT\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-03-14 12:55 486856 C:\Program Files\DAEMON Tools Lite\daemon.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\Age2_X1\\age2_x1.Exe"=
"C:\\Program Files\\Gadu-Gadu\\GG.EXE"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Opera\\Opera.exe"=
"C:\\Program Files\\Hamachi\\hamachi.exe"=
"C:\\WINNT\\System32\\dplaysvr.exe"=
"C:\\Program Files\\Garena\\Garena.exe"=
R1 aswSP;avast! Self Protection;C:\WINNT\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINNT\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 dsnpfd;DeskSoft Service;C:\WINNT\system32\DRIVERS\dsnpfd.sys [2008-10-19 26920]
S2 Ca533av;Polaroid Digital Cam Video;C:\WINNT\system32\Drivers\Ca533av.sys [2002-10-20 515803]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINNT\system32\NSNDIS5.SYS [2004-03-24 17280]
S3 USBCamera;Icatch(IV) Still Camera Device;C:\WINNT\system32\Drivers\Bulk533.sys [2002-07-24 10986]
.
.
------- Skan uzupełniający -------
.
O16 -: {68282C51-9459-467B-95BF-3C0E89627E55} - hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
C:\WINNT\Downloaded Program Files\SkanerOnline.inf
C:\WINNT\system32\SkanerOnlineUninstall.exe
C:\WINNT\system32\SkanerOnline.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-20 15:05:07
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-10-20 15:07:26
ComboFix-quarantined-files.txt 2008-10-20 13:07:02
Przed: 12 110 823 424 bajtów wolnych
Po: 12,288,327,680 bajtów wolnych
306 --- E O F --- 2008-03-29 12:58:58