
Zaniepokoiły mnie problemy z mozilla firefox (windows 7), która wyłączała się, jak wchodziłam na różne strony www. Po skanie dysku przez mks online okazało się, że mój komputer jest zainfekowany Heur.Win32 i Heur.W32. Jestem totalnym laikiem w sprawach komputerów, dlatego bardzo proszę o pomoc! Postępowałam zgodnie z zasadami, jakie zamieszczono na forum (generowanie logów itp). Poniżej zamieszczam logi wygenerowane przez polecane przez Was programy:
Attach DDS: http://www.wklej.org/id/378713/
OTL Extras: http://www.wklej.org/id/378717/
DDS: http://www.wklej.org/id/378716/
OTL log: http://www.wklej.org/id/378719/
Combofix: http://www.wklej.org/id/378715/
Gmer: http://www.wklej.org/id/378721/
Pozbyłam się programu emulującego (daemon), ale nie miałam zainstalowanego sptd.sys.
Bardzo proszę o pomoc!
Dodano Dzisiaj, 22:42:
logi w CODE:
gmer:
- Kod: Zaznacz wszystko
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-18 21:19:48
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\Ola\AppData\Local\Temp\fxtdapog.sys
---- System - GMER 1.0.15 ----
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323DAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323D104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323D3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83225634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83225898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323D1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323D958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323D6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323DF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323E1A8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82E56599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E7AF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\windows\system32\DRIVERS\atikmdag.sys section is writeable [0x90E09000, 0x2D4FC0, 0xE8000020]
.text C:\windows\system32\DRIVERS\lirsgt.sys section is writeable [0x969AF300, 0x1B7E, 0xE8000020]
.text peauth.sys GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-18 21:19:48
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\Ola\AppData\Local\Temp\fxtdapog.sys
---- System - GMER 1.0.15 ----
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323DAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323D104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323D3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83225634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83225898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323D1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323D958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323D6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323DF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8323E1A8
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82E56599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E7AF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\windows\system32\DRIVERS\atikmdag. 9C22FC9D 28 Bytes [8F, 9B, 03, 18, 3B, 74, 06, ...]
.text peauth.sys 9C22FCC1 28 Bytes [8F, 9B, 03, 18, 3B, 74, 06, ...]
PAGE peauth.sys 9C235B9B 72 Bytes [A0, 3E, 7A, AE, A9, 91, D3, ...]
PAGE peauth.sys 9C235BEC 111 Bytes [2E, 88, 5B, EF, 28, DE, 4E, ...]
PAGE peauth.sys 9C235E20 101 Bytes [64, 83, 8D, EC, D5, 98, 19, ...]
PAGE ...
? C:\Users\Ola\AppData\Local\Temp\catchme.sys Nie można odnaleźć określonego pliku. !
? C:\windows\system32\Drivers\PROCEXP113.SYS Nie można odnaleźć określonego pliku. !
? C:\Users\Ola\AppData\Local\Temp\mbr.sys Nie można odnaleźć określonego pliku. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!UnhookWindowsHookEx 7695CC7B 5 Bytes JMP 6A69835E C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!CallNextHookEx 7695CC8F 5 Bytes JMP 6A679D5C C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!CreateWindowExW 76960E51 5 Bytes JMP 6A688157 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!SetWindowsHookExW 7696210A 5 Bytes JMP 6A634633 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!DialogBoxIndirectParamW 76984AA7 5 Bytes JMP 6A7AF970 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!DialogBoxParamW 7698564A 5 Bytes JMP 6A5A4BA7 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!DialogBoxParamA 7699CF6A 5 Bytes JMP 6A7AF90D C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!DialogBoxIndirectParamA 7699D29C 5 Bytes JMP 6A7AF9D3 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!MessageBoxIndirectA 769AE8C9 5 Bytes JMP 6A7AF8A2 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!MessageBoxIndirectW 769AE9C3 5 Bytes JMP 6A7AF837 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!MessageBoxExA 769AEA29 5 Bytes JMP 6A7AF7D5 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] USER32.dll!MessageBoxExW 769AEA4D 5 Bytes JMP 6A7AF773 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] ole32.dll!OleLoadFromStream 77315B88 5 Bytes JMP 6A7AFCCE C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] ole32.dll!CoCreateInstance 773657FC 5 Bytes JMP 6A688C45 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] ws2_32.DLL!closesocket 76AA3BED 5 Bytes JMP 6B3441DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] ws2_32.DLL!socket 76AA3F00 5 Bytes JMP 6B34354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] ws2_32.DLL!recv 76AA47DF 5 Bytes JMP 6B344549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] ws2_32.DLL!connect 76AA48BE 5 Bytes JMP 6B3435DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] ws2_32.DLL!getaddrinfo 76AA6737 5 Bytes JMP 6B343704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2188] ws2_32.DLL!send 76AAC4C8 5 Bytes JMP 6B343B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!UnhookWindowsHookEx 7695CC7B 5 Bytes JMP 6A69835E C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!CallNextHookEx 7695CC8F 5 Bytes JMP 6A679D5C C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!CreateWindowExW 76960E51 5 Bytes JMP 6A688157 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!SetWindowsHookExW 7696210A 5 Bytes JMP 6A634633 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!DialogBoxIndirectParamW 76984AA7 5 Bytes JMP 6A7AF970 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!DialogBoxParamW 7698564A 5 Bytes JMP 6A5A4BA7 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!DialogBoxParamA 7699CF6A 5 Bytes JMP 6A7AF90D C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!DialogBoxIndirectParamA 7699D29C 5 Bytes JMP 6A7AF9D3 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!MessageBoxIndirectA 769AE8C9 5 Bytes JMP 6A7AF8A2 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!MessageBoxIndirectW 769AE9C3 5 Bytes JMP 6A7AF837 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!MessageBoxExA 769AEA29 5 Bytes JMP 6A7AF7D5 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] USER32.dll!MessageBoxExW 769AEA4D 5 Bytes JMP 6A7AF773 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] ole32.dll!OleLoadFromStream 77315B88 5 Bytes JMP 6A7AFCCE C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] ole32.dll!CoCreateInstance 773657FC 5 Bytes JMP 6A688C45 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] ws2_32.DLL!closesocket 76AA3BED 5 Bytes JMP 6B3441DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] ws2_32.DLL!socket 76AA3F00 5 Bytes JMP 6B34354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] ws2_32.DLL!recv 76AA47DF 5 Bytes JMP 6B344549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] ws2_32.DLL!connect 76AA48BE 5 Bytes JMP 6B3435DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] ws2_32.DLL!getaddrinfo 76AA6737 5 Bytes JMP 6B343704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3680] ws2_32.DLL!send 76AAC4C8 5 Bytes JMP 6B343B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!UnhookWindowsHookEx 7695CC7B 5 Bytes JMP 6A69835E C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!CallNextHookEx 7695CC8F 5 Bytes JMP 6A679D5C C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!CreateWindowExW 76960E51 5 Bytes JMP 6A688157 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!SetWindowsHookExW 7696210A 5 Bytes JMP 6A634633 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!DialogBoxIndirectParamW 76984AA7 5 Bytes JMP 6A7AF970 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!DialogBoxParamW 7698564A 5 Bytes JMP 6A5A4BA7 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!DialogBoxParamA 7699CF6A 5 Bytes JMP 6A7AF90D C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!DialogBoxIndirectParamA 7699D29C 5 Bytes JMP 6A7AF9D3 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!MessageBoxIndirectA 769AE8C9 5 Bytes JMP 6A7AF8A2 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!MessageBoxIndirectW 769AE9C3 5 Bytes JMP 6A7AF837 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!MessageBoxExA 769AEA29 5 Bytes JMP 6A7AF7D5 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] USER32.dll!MessageBoxExW 769AEA4D 5 Bytes JMP 6A7AF773 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] ole32.dll!OleLoadFromStream 77315B88 5 Bytes JMP 6A7AFCCE C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] ole32.dll!CoCreateInstance 773657FC 5 Bytes JMP 6A688C45 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] ws2_32.DLL!closesocket 76AA3BED 5 Bytes JMP 6B3441DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] ws2_32.DLL!socket 76AA3F00 5 Bytes JMP 6B34354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] ws2_32.DLL!recv 76AA47DF 5 Bytes JMP 6B344549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] ws2_32.DLL!connect 76AA48BE 5 Bytes JMP 6B3435DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] ws2_32.DLL!getaddrinfo 76AA6737 5 Bytes JMP 6B343704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3764] ws2_32.DLL!send 76AAC4C8 5 Bytes JMP 6B343B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3912] USER32.dll!CreateWindowExW 76960E51 5 Bytes JMP 6A688157 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3912] USER32.dll!DialogBoxIndirectParamW 76984AA7 5 Bytes JMP 6A7AF970 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3912] USER32.dll!DialogBoxParamW 7698564A 5 Bytes JMP 6A5A4BA7 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3912] USER32.dll!DialogBoxParamA 7699CF6A 5 Bytes JMP 6A7AF90D C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3912] USER32.dll!DialogBoxIndirectParamA 7699D29C 5 Bytes JMP 6A7AF9D3 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3912] USER32.dll!MessageBoxIndirectA 769AE8C9 5 Bytes JMP 6A7AF8A2 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3912] USER32.dll!MessageBoxIndirectW 769AE9C3 5 Bytes JMP 6A7AF837 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3912] USER32.dll!MessageBoxExA 769AEA29 5 Bytes JMP 6A7AF7D5 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3912] USER32.dll!MessageBoxExW 769AEA4D 5 Bytes JMP 6A7AF773 C:\windows\system32\IEFRAME.dll (Przeglądarka internetowa/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\00000058 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{0686B6A5-FE02-44FF-8DAA-741BF4CC411F}\Connection@Name isatap.{DB698578-E6DA-4631-8814-1134AAF0D67B}
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Bind \Device\{F0E15EB3-054F-419A-B800-8F6C587A0124}?\Device\{1CDBE6CF-E205-4CC4-A1ED-CC4B8073F480}?\Device\{0686B6A5-FE02-44FF-8DAA-741BF4CC411F}?\Device\{6AB088F3-5922-425E-9668-4BA236C14A3E}?\Device\{4EA882DE-3378-4372-8B06-6921C0C1C70D}?\Device\{B32DACFC-6F50-4F3E-AC8B-BC85964DDC5D}?\Device\{76F3A7C4-E594-48AB-9753-7A381C4AB87F}?\Device\{B93CB312-D202-4984-AB38-86B59492A297}?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Route "{F0E15EB3-054F-419A-B800-8F6C587A0124}"?"{1CDBE6CF-E205-4CC4-A1ED-CC4B8073F480}"?"{0686B6A5-FE02-44FF-8DAA-741BF4CC411F}"?"{6AB088F3-5922-425E-9668-4BA236C14A3E}"?"{4EA882DE-3378-4372-8B06-6921C0C1C70D}"?"{B32DACFC-6F50-4F3E-AC8B-BC85964DDC5D}"?"{76F3A7C4-E594-48AB-9753-7A381C4AB87F}"?"{B93CB312-D202-4984-AB38-86B59492A297}"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{6B683E0E-1505-488C-8053-3C1301924246}\Linkage@Export \Device\TCPIP6TUNNEL_{F0E15EB3-054F-419A-B800-8F6C587A0124}?\Device\TCPIP6TUNNEL_{1CDBE6CF-E205-4CC4-A1ED-CC4B8073F480}?\Device\TCPIP6TUNNEL_{0686B6A5-FE02-44FF-8DAA-741BF4CC411F}?\Device\TCPIP6TUNNEL_{6AB088F3-5922-425E-9668-4BA236C14A3E}?\Device\TCPIP6TUNNEL_{4EA882DE-3378-4372-8B06-6921C0C1C70D}?\Device\TCPIP6TUNNEL_{B32DACFC-6F50-4F3E-AC8B-BC85964DDC5D}?\Device\TCPIP6TUNNEL_{76F3A7C4-E594-48AB-9753-7A381C4AB87F}?\Device\TCPIP6TUNNEL_{B93CB312-D202-4984-AB38-86B59492A297}?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002185f1860f
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{0686B6A5-FE02-44FF-8DAA-741BF4CC411F}@InterfaceName isatap.{DB698578-E6DA-4631-8814-1134AAF0D67B}
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{0686B6A5-FE02-44FF-8DAA-741BF4CC411F}@ReusableType 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x86 0x34 0x5B 0x91 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x48 0x96 0x48 0x3E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x03 0xFD 0x52 0xDF ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002185f1860f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x86 0x34 0x5B 0x91 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x48 0x96 0x48 0x3E ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x03 0xFD 0x52 0xDF ...
---- EOF - GMER 1.0.15 ----
combofix:
- Kod: Zaznacz wszystko
ComboFix 10-08-17.04 - Ola 2010-08-18 21:35:00.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.48.1045.18.3071.1978 [GMT 2:00]
Uruchomiony z: d:\ola\instale\ochrona\ComboFix.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2010-07-18 do 2010-08-18 )))))))))))))))))))))))))))))))
.
2010-08-18 19:40 . 2010-08-18 19:40 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-08-18 19:40 . 2010-08-18 19:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-18 18:35 . 2010-08-18 18:35 388096 ----a-r- c:\users\Ola\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-18 11:50 . 2010-06-22 02:47 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-18 11:50 . 2010-06-22 02:47 307200 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-18 11:50 . 2010-06-22 02:47 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-08-18 11:49 . 2010-06-30 06:25 978432 ----a-w- c:\windows\system32\wininet.dll
2010-08-18 11:48 . 2010-06-14 06:12 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-18 11:48 . 2010-07-29 06:30 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-08-18 11:48 . 2010-07-29 06:30 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-08-18 11:48 . 2010-06-19 06:23 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-08-18 11:48 . 2010-06-19 06:33 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-18 11:48 . 2010-06-19 06:33 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-08-18 11:48 . 2010-06-08 06:02 1233920 ----a-w- c:\windows\system32\msxml3.dll
2010-08-18 11:47 . 2010-08-18 11:47 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2010-08-18 11:47 . 2010-06-16 05:48 224256 ----a-w- c:\windows\system32\schannel.dll
2010-08-18 11:47 . 2010-06-19 04:07 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-08-18 11:47 . 2010-08-18 11:47 686400 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-08-03 12:42 . 2010-08-03 12:42 -------- d-----w- c:\program files\Common Files\Java
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-18 19:33 . 2009-09-29 07:19 691176 ----a-w- c:\windows\system32\perfh015.dat
2010-08-18 19:33 . 2009-09-29 07:19 132638 ----a-w- c:\windows\system32\perfc015.dat
2010-08-18 18:51 . 2010-01-17 23:05 -------- d-----w- c:\program files\pdfforge Toolbar
2010-08-18 18:30 . 2009-11-27 12:39 -------- d-----w- c:\users\Ola\AppData\Roaming\Winamp
2010-08-18 15:16 . 2009-12-11 12:14 -------- d-----w- c:\users\Ola\AppData\Roaming\BESTplayer
2010-08-18 11:55 . 2009-09-29 06:48 -------- d-----w- c:\programdata\Microsoft Help
2010-08-03 12:41 . 2009-12-28 00:55 -------- d-----w- c:\program files\Java
2010-07-30 09:03 . 2009-11-24 16:29 -------- d-----w- c:\users\Ola\AppData\Roaming\Azureus
2010-07-21 16:29 . 2010-02-03 15:48 -------- d-----w- c:\program files\Google
2010-07-17 13:51 . 2009-09-29 06:41 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-17 03:00 . 2010-05-10 20:21 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-05-31 18:59 . 2010-05-31 18:59 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-05-27 07:24 . 2010-06-09 10:36 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49 . 2010-06-09 10:36 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 11:14 . 2009-11-24 13:02 221568 ------w- c:\windows\system32\MpSigStub.exe
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-08-18_18.52.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-29 06:45 . 2010-08-18 19:30 37040 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-09-29 06:45 . 2010-08-18 14:55 37040 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-08-18 19:30 46784 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-11-24 12:11 . 2010-08-18 19:30 13626 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-526791697-3303795607-1652840347-1000_UserData.bin
- 2009-11-24 12:11 . 2010-08-18 12:35 13626 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-526791697-3303795607-1652840347-1000_UserData.bin
- 2009-11-24 12:14 . 2010-08-18 18:38 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-11-24 12:14 . 2010-08-18 19:30 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-11-24 12:14 . 2010-08-18 19:30 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-11-24 12:14 . 2010-08-18 18:38 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:41 . 2010-08-18 19:30 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2010-08-18 18:38 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-07 00:18 . 2010-08-18 19:30 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-07 00:18 . 2010-08-18 18:47 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-07 00:18 . 2010-08-18 19:30 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-07 00:18 . 2010-08-18 18:47 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-07 00:18 . 2010-08-18 19:30 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-07 00:18 . 2010-08-18 18:47 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-11-24 14:54 . 2010-08-18 19:30 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-24 14:54 . 2010-08-18 18:47 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-28 18:12 . 2010-08-18 18:13 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2009-11-28 18:12 . 2010-08-18 19:03 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2009-11-28 18:12 . 2010-08-18 19:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2009-11-28 18:12 . 2010-08-18 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2009-11-28 18:12 . 2010-08-18 18:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
+ 2009-11-28 18:12 . 2010-08-18 19:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
+ 2009-11-24 14:54 . 2010-08-18 19:30 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-11-24 14:54 . 2010-08-18 18:47 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-11-24 14:54 . 2010-08-18 19:30 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-11-24 14:54 . 2010-08-18 18:47 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-08-18 18:44 . 2010-08-18 18:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-08-18 19:28 . 2010-08-18 19:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-08-18 18:44 . 2010-08-18 18:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-08-18 19:28 . 2010-08-18 19:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:05 . 2010-08-18 19:33 610094 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-08-18 18:49 610094 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-08-18 18:49 104412 c:\windows\System32\perfc009.dat
+ 2009-07-14 02:05 . 2010-08-18 19:33 104412 c:\windows\System32\perfc009.dat
- 2009-09-29 06:51 . 2010-08-18 18:38 262144 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-09-29 06:51 . 2010-08-18 19:27 262144 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 02:03 . 2010-08-18 18:54 7077888 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 02:03 . 2010-08-18 15:06 7077888 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2010-04-15 10:33 2515552 ----a-w- c:\program files\Vuze_Remote\tbVuze.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-14 7617056]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2009-07-22 83336]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-06-25 98304]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2010-01-08 974848]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
c:\users\Ola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Tworzenie wycink˘w ekranu i uruchamianie programu OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Aktywacja Testera.lnk - c:\program files\niem-pol\YDP\YdpDict\Watch.exe [2010-3-31 354816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MGSysCtrl]
2009-08-05 20:28 2072576 ----a-w- c:\program files\System Control Manager\MGSysCtrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2008-12-02 21:30 3882312 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-04 166912]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys [2010-03-25 31824]
R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-18 1343400]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-03-16 691696]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2010-03-25 123856]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2010-03-25 41680]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-13 176128]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
S2 Micro Star SCM;Micro Star SCM;c:\program files\System Control Manager\MSIService.exe [2009-07-09 160768]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2008-04-25 17920]
S3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28.sys [2009-08-04 616960]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSGB6.sys [2009-07-13 48128]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2010-03-25 99728]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2010-03-25 110608]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.google.pl/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Ola\AppData\Roaming\Mozilla\Firefox\Profiles\cg5h7cal.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\pdfforge Toolbar\SSFF\components\SearchSettingsFF.dll
FF - component: c:\users\Ola\AppData\Roaming\Mozilla\Firefox\Profiles\cg5h7cal.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
FF - component: c:\users\Ola\AppData\Roaming\Mozilla\Firefox\Profiles\cg5h7cal.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppstart.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Ola\AppData\Roaming\Gadu-Gadu 10\_userdata\npgg.2.dll
---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Czas ukończenia: 2010-08-18 21:43:08
ComboFix-quarantined-files.txt 2010-08-18 19:43
ComboFix2.txt 2010-08-18 18:55
Przed: 43 152 162 816 bajtów wolnych
Po: 42 998 882 304 bajtów wolnych
- - End Of File - - 37BFA815294E6B8859BBB2F6FB9DB510
Dodano Dzisiaj, 22:48:
więcej znaków nie mogę zamieścić w mojej wiadomości, dlatego reszta jest na stronie http://www.wklej.org/ (odnośniki wyżej)