
- Kod: Zaznacz wszystko
ComboFix 09-03-02.03 - Ninka 2009-03-03 23:55:53.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1045.18.2046.1052 [GMT 1:00]
Uruchomiony z: c:\users\Ninka\Downloads\ComboFix.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((( Pliki utworzone od 2009-02-03 do 2009-03-03 )))))))))))))))))))))))))))))))
.
2009-03-03 23:45 . 2009-03-04 00:03 235,133,036 --a------ c:\windows\MEMORY.DMP
2009-03-03 21:27 . 2009-03-03 21:28 <DIR> d-------- c:\users\Ninka\AppData\Roaming\otoMoto
2009-02-19 21:21 . 2009-02-19 21:21 <DIR> d-------- c:\users\Ninka\AppData\Roaming\InstallShield
2009-02-19 21:21 . 2009-02-19 21:21 <DIR> d-------- c:\program files\SAGEM
2009-02-16 16:39 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-16 16:39 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-16 16:39 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-16 16:39 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-16 16:39 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-13 10:52 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-13 10:52 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-10 10:44 . 2009-02-10 10:44 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-02-08 23:19 . 2008-04-26 09:26 891,448 --a------ c:\windows\System32\drivers\tcpip.sys
2009-02-08 23:19 . 2008-04-12 04:32 784,896 --a------ c:\windows\System32\rpcrt4.dll
2009-02-08 23:19 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2009-02-08 23:19 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
2009-02-08 23:19 . 2008-04-05 02:21 72,192 --a------ c:\windows\System32\drivers\pacer.sys
2009-02-08 23:19 . 2008-04-05 04:34 15,360 --a------ c:\windows\System32\pacerprf.dll
2009-02-07 22:27 . 2009-02-07 22:27 <DIR> d-------- C:\PerfLogs
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-03 23:06 --------- d-----w c:\users\Ninka\AppData\Roaming\Skype
2009-03-03 23:00 --------- d-----w c:\users\Ninka\AppData\Roaming\skypePM
2009-02-28 20:39 27,335 ----a-w c:\users\Ninka\AppData\Roaming\nvModes.dat
2009-02-26 21:39 --------- d-----w c:\program files\DivX
2009-02-19 20:21 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-14 18:20 --------- d-----w c:\program files\Windows Mail
2009-02-08 09:47 --------- d-----w c:\programdata\NVIDIA
2009-02-08 09:45 174 --sha-w c:\program files\desktop.ini
2009-02-07 21:28 --------- d-----w c:\program files\Windows Sidebar
2009-02-07 21:28 --------- d-----w c:\program files\Windows Photo Gallery
2009-02-07 21:28 --------- d-----w c:\program files\Windows Journal
2009-02-07 21:28 --------- d-----w c:\program files\Windows Defender
2009-02-07 21:28 --------- d-----w c:\program files\Windows Collaboration
2009-02-07 21:28 --------- d-----w c:\program files\Windows Calendar
2009-01-26 17:38 --------- d-----w c:\program files\Google
2008-12-14 09:27 390 ----a-w c:\users\Ninka\AppData\Roaming\wklnhst.dat
2008-03-25 10:53 3,858,985 ----a-w c:\users\Ninka\eMule0.48a-Installer.exe
2008-03-25 10:17 172,032 ----a-w c:\users\Ninka\gg77.exe
2008-03-25 10:12 32 ----a-w c:\programdata\ezsid.dat
2008-03-24 18:25 25,072,608 ----a-w c:\users\Ninka\AVSDVDPlayer.exe
2008-03-24 16:30 2,719,216 ----a-w c:\users\Ninka\cleaner.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-03-19 1267040]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-02-06 21898024]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2007-11-14 2131392]
"Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" [2008-03-25 507904]
"ares"="c:\program files\Ares\Ares.exe" [2007-11-23 962560]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2007-05-13 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-16 218408]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2007-09-20 671744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-09-05 727592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
"msacm.divxa32"= divxa32.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2326920186-639083783-118934040-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{25A58860-6C8E-4A69-BF35-778A6D081443}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{16B07B60-C5D7-47F6-97AE-A2883122FD96}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{892252E1-8DF3-4900-9E79-E8FBD5AD791A}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{60C74E47-EF7E-4117-BE83-1D330F2B5CDD}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{9A922F22-A599-4247-AA63-75095D7A7756}c:\\program files\\gadu-gadu\\gg.exe"= UDP:c:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program główny
"UDP Query User{EA3CA9D7-4D14-408F-AADB-42A5538659A8}c:\\program files\\gadu-gadu\\gg.exe"= TCP:c:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program główny
"TCP Query User{5696B277-82F1-4DB7-A8EB-04662AFEFCAE}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{45F91325-50A7-4202-8531-B61E3753515A}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{A4E2C271-7141-4928-BF01-77E6D60E019B}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{9B0F9E74-0B43-4BBC-86B0-BFAB2203AEB0}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{E2785F21-AF29-4697-9B0B-302EE5C42888}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{EF7065CC-ED76-456C-B5FE-45A8B83FAA6E}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{0610D535-F2E8-4EDB-A52F-D1B2E51204BB}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{6641CB89-E207-4306-B68C-D0865DE6A576}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{C89FD4F3-081F-475D-8807-EAAFE1284006}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{B6F5C443-C7E4-4743-81B7-B99016CE18DE}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{B8F63D04-7556-4AE8-B7A9-721500BAB1EB}"= UDP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{87579504-DFF3-4B59-A45C-32B5BDBB4BA7}"= TCP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{7D553F03-6B65-402A-BAB4-CCEE71244359}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{90F7EF8E-DB21-4B70-BB5F-84C622B06B93}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{E3A97CDE-BB3F-4DF4-9996-DCD535DFFC63}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{0B86D5B7-9123-4E29-B3F4-CB0C8055E1B9}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{5D99DB8C-9170-4D87-B458-C5F12EE5EDAB}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{4311B0C7-2F40-4DB8-AD85-5AC7500296ED}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{1B3AE15A-4244-4D4A-BB55-8E38D4C791B3}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{2CFCF0AE-0F83-4372-B7C5-BADDA90A2F16}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{36FBF41E-4A24-43BB-9D2C-D4E1A8FEFFD4}c:\\program files\\gadu-gadu\\gg.exe"= UDP:c:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program główny
"UDP Query User{C1325C93-A379-4019-AD66-2F2FA02DBE3D}c:\\program files\\gadu-gadu\\gg.exe"= TCP:c:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program główny
"TCP Query User{7E406FDF-1368-47AC-A363-E2DA61215271}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{6538D5D8-6E52-4905-89A1-C5F4171BCE56}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{CAB80963-C9F0-47C3-80F4-859F518908E7}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{62FEFD65-DAC1-49C6-9F3A-5CB7F92D0698}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
R3 athrusb;Atheros Wireless LAN USB device driver;c:\windows\System32\drivers\athrusb.sys [2009-01-30 449536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{48daf605-f5c2-11dc-9652-806e6f6e6963}]
\shell\AutoRun\command - E:\livebox_tp.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68afe179-fc6b-11dd-9c82-001e37b395f6}]
\shell\AutoRun\command - F:\11rhbu.cmd
\shell\open\Command - F:\11rhbu.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e46a5db9-0672-11dd-800b-001e68192f8f}]
\shell\AutoRun\command - H:\2u.com
\shell\explore\Command - H:\2u.com
\shell\open\Command - H:\2u.com
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
HKCU-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://pudelek.pl/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_pl&c=81&bd=Pavilion&pf=laptop
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksport do programu Microsoft Excel - d:\office11\EXCEL.EXE/3000
IE: Wyślij obraz do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Wyślij stronę do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-04 00:04:47
Windows 6.0.6001 Service Pack 1 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'lsass.exe'(652)
c:\windows\system32\DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(2768)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\windows\system32\btmmhook.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\System32\audiodg.exe
c:\windows\System32\wlanext.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\System32\IoctlSvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\program files\Internet Explorer\ieuser.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Winamp Toolbar\winampTbServer.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Czas ukończenia: 2009-03-04 0:11:42 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-03-03 23:11:32
Przed: 174 417 776 640 bajtów wolnych
Po: 174,302,724,096 bajtów wolnych
225 --- E O F --- 2009-03-03 22:52:11