
Mam od wczoraj problem z neostradą. Gdy internet sie włączy za minute lub dwie następuje restart neostrady, dioda na modemie zaczyna migac (błąd 680) i dzieje się tak w kółko. Miałem Kasperskiego, ale go usunąłem bo myslałem, ze to moze byc jego wina i jednak nie pomogło. Skanowałem kompa przed usunięciem i nic nie wykrył

DSS:
- Kod: Zaznacz wszystko
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-06-23 17:56:54
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
17: 2008-06-23 15:56:57 UTC - RP73 - Deckard's System Scanner Restore Point
16: 2008-06-23 14:06:03 UTC - RP72 - Usunięty Kaspersky Anti-Virus 2009.
15: 2008-06-22 17:58:06 UTC - RP71 - Punkt kontrolny systemu
14: 2008-06-21 15:03:22 UTC - RP70 - Installed Pro Evolution Soccer 2008
13: 2008-06-21 15:03:01 UTC - RP69 - Installed Pro Evolution Soccer 2008
-- First Restore Point --
1: 2008-06-08 18:57:48 UTC - RP57 - Punkt kontrolny systemu
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Administrator.exe) ---------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:57:59, on 2008-06-23
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20583)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AutoConnect\AutoConnect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Opera\Opera.exe
C:\Documents and Settings\Administrator\Pulpit\DSS.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by Godzilla
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [AutoConnect] C:\Program Files\AutoConnect\AutoConnect.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
--
End of file - 5107 bytes
-- File Associations -----------------------------------------------------------
[COLOR=red].cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*[/COLOR]
[COLOR=red].cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*[/COLOR]
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 AFPAnsi (Alfa File Protector Ansi) - c:\windows\system32\drivers\afpansi.sys <Not Verified; Alfa Corporation; AlfaFP (TM) 2003 Ansi Build for Windows NT/2K>
R0 Si3112 - c:\windows\system32\drivers\si3112.sys <Not Verified; Silicon Image, Inc.; SiI 3112 SATALink controller>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R2 PLFlash DeviceIoControl Service - c:\windows\system32\ioctlsvc.exe <Not Verified; Prolific Technology Inc.; IoctlSvc Application>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Kontroler przerwań systemowych
Device ID: PCI\VEN_1106&DEV_5336&SUBSYS_00000000&REV_00\3&267A616A&0&05
Manufacturer:
Name: Kontroler przerwań systemowych
PNP Device ID: PCI\VEN_1106&DEV_5336&SUBSYS_00000000&REV_00\3&267A616A&0&05
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Kontroler RAID
Device ID: PCI\VEN_1106&DEV_3349&SUBSYS_81B51043&REV_00\3&267A616A&0&78
Manufacturer:
Name: Kontroler RAID
PNP Device ID: PCI\VEN_1106&DEV_3349&SUBSYS_81B51043&REV_00\3&267A616A&0&78
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
-- Files created between 2008-05-23 and 2008-06-23 -----------------------------
2008-06-27 13:06:44 0 d-------- C:\Program Files\Prawo Jazdy 2006
2008-06-23 17:52:11 0 d-------- C:\Program Files\Trend Micro
2008-06-21 17:04:23 0 d-------- C:\Program Files\KONAMI
2008-06-15 14:34:38 0 d-------- C:\USDownloader
2008-06-04 22:54:19 0 d-------- C:\Program Files\NetProject
2008-05-31 13:22:28 0 d--h----- C:\ckis
2008-05-29 23:05:26 0 d-------- C:\Program Files\Smart PC Solutions
-- Find3M Report ---------------------------------------------------------------
2008-06-23 17:45:51 0 d-------- C:\Program Files\AutoConnect
2008-06-21 17:10:57 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-21 16:40:57 0 d-------- C:\Program Files\totalcmd
2008-06-13 14:14:51 0 d-------- C:\Program Files\Kaspersky Lab
2008-06-08 23:07:52 0 dr------- C:\Documents and Settings\Administrator\Dane aplikacji\Brother
2008-05-23 10:50:47 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Adobe
2008-05-18 21:43:12 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Dev-Cpp
2008-05-18 20:36:02 0 d-------- C:\Program Files\Real Desktop
2008-05-18 12:29:14 0 d-------- C:\Program Files\ALCAM
2008-05-17 00:30:52 436940 --a------ C:\WINDOWS\system32\perfh015.dat
2008-05-17 00:30:52 66944 --a------ C:\WINDOWS\system32\perfc015.dat
2008-05-10 11:36:27 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Real
2008-05-05 19:54:53 0 d-------- C:\Program Files\Microsoft Works
2008-05-05 19:54:43 0 d-------- C:\Program Files\MSBuild
2008-05-05 19:54:24 0 d-------- C:\Program Files\Common Files
2008-05-05 19:53:39 0 d-------- C:\Program Files\Microsoft.NET
2008-05-04 22:29:37 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Media Player Classic
2008-05-04 22:01:00 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-04 22:00:57 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-05-04 22:00:37 62 --ahs---- C:\Documents and Settings\Administrator\Dane aplikacji\desktop.ini
2008-05-04 21:36:05 50 --a------ C:\WINDOWS\system32\bridf06a.dat
2008-05-04 21:35:57 0 d-------- C:\Program Files\Brother
2008-05-04 21:35:30 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-04 21:33:45 0 d-------- C:\Program Files\Common Files\ScanSoft Shared
2008-05-04 21:33:42 0 d-------- C:\Program Files\ScanSoft
2008-05-04 21:16:36 0 d-------- C:\Program Files\EA Sports
2008-05-04 20:55:51 0 d-------- C:\Program Files\DAEMON Tools Pro
2008-05-04 20:55:10 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\DAEMON Tools Pro
2008-05-04 20:49:50 0 --a------ C:\WINDOWS\system32\bn.dll
2008-05-04 20:45:26 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Google
2008-05-04 20:45:11 0 d-------- C:\Program Files\Google
2008-05-04 20:45:10 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Macromedia
2008-05-04 20:44:53 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Gadu-Gadu
2008-05-04 20:44:42 0 d-------- C:\Program Files\Gadu-Gadu
2008-05-04 20:43:51 0 d-------- C:\Program Files\Lavalys
2008-05-04 20:43:32 0 d-------- C:\Program Files\DVD Decrypter
2008-05-04 20:43:01 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-05-04 20:42:25 0 d-------- C:\Program Files\SopCast
2008-05-04 20:41:41 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\TVU Networks
2008-05-04 20:41:38 0 d-------- C:\Program Files\TVUPlayer
2008-05-04 20:41:23 0 d-------- C:\Program Files\TVAnts
2008-05-04 20:41:06 0 d-------- C:\Program Files\PPStream
2008-05-04 20:41:02 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\ppstream
2008-05-04 20:40:47 0 d-------- C:\Program Files\PPLive
2008-05-04 20:40:47 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\PPLive
2008-05-04 20:40:10 0 d-------- C:\Program Files\PPMate
2008-05-04 20:40:02 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\PPMate
2008-05-04 20:40:00 0 d-------- C:\Program Files\Common Files\Synacast
2008-05-04 20:39:42 0 d-------- C:\Program Files\uusee
2008-05-04 20:38:33 89 --a------ C:\WINDOWS\system32\vbxtreg32.dll
2008-05-04 20:38:33 89 --a------ C:\WINDOWS\system32\vbxtct32.dll
2008-05-04 20:37:45 0 d-------- C:\Program Files\XP Tools
2008-05-04 20:35:59 0 d-------- C:\Program Files\Analog Devices
2008-05-04 20:33:11 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\CyberLink
2008-05-04 20:32:54 0 d-------- C:\Program Files\CyberLink
2008-05-04 20:32:49 0 d-------- C:\Program Files\Common Files\CyberLink
2008-05-04 20:31:41 0 d-------- C:\Program Files\MarBit
2008-05-04 20:31:03 0 d-------- C:\Program Files\Alcohol Soft
2008-05-04 20:30:30 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-04 20:29:12 0 d-------- C:\Program Files\NeroInstall.bak
2008-05-04 20:28:43 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Nero
2008-05-04 20:28:09 0 d-------- C:\Program Files\Common Files\Nero
2008-05-04 20:27:24 0 d-------- C:\Program Files\Nero
2008-05-04 20:19:46 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Opera
2008-05-04 20:19:41 0 d-------- C:\Program Files\Opera
2008-05-04 20:17:55 0 d-------- C:\Program Files\SAGEM
2008-05-04 20:17:54 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\InstallShield
2008-05-04 20:17:22 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\WinRAR
2008-05-04 20:16:21 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Winamp
2008-05-04 20:15:39 0 d-------- C:\Program Files\Winamp
2008-05-04 20:08:34 0 d-------- C:\Program Files\Real Alternative
2008-05-04 20:08:27 0 d-------- C:\Program Files\QuickTime Alternative
2008-05-04 20:08:14 0 d-------- C:\Program Files\Java
2008-05-04 20:08:03 0 d-------- C:\Program Files\Common Files\Java
2008-05-04 20:07:53 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Sun
2008-05-04 20:07:17 0 -rahs---- C:\MSDOS.SYS
2008-05-04 20:07:17 0 -rahs---- C:\IO.SYS
2008-05-04 20:07:17 0 --a------ C:\CONFIG.SYS
2008-05-04 20:07:17 0 --a------ C:\AUTOEXEC.BAT
2008-05-04 20:05:50 0 d-------- C:\Program Files\Common Files\MSSoap
2008-05-04 20:05:46 0 d-------- C:\Program Files\Movie Maker
2008-05-04 20:05:04 21856 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-04 20:04:38 0 d-------- C:\Program Files\Windows Media Connect 2
2008-05-04 20:04:30 0 d-------- C:\Program Files\MSN Gaming Zone
2008-05-04 20:04:18 0 d-------- C:\Program Files\Windows NT
2008-04-22 07:03:00 545 --a------ C:\WINDOWS\UC.PIF
2008-04-22 07:03:00 545 --a------ C:\WINDOWS\RAR.PIF
2008-04-22 07:03:00 545 --a------ C:\WINDOWS\PKZIP.PIF
2008-04-22 07:03:00 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2008-04-22 07:03:00 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2008-04-22 07:03:00 545 --a------ C:\WINDOWS\LHA.PIF
2008-04-22 07:03:00 545 --a------ C:\WINDOWS\ARJ.PIF
2008-03-31 23:25:46 682496 --a------ C:\WINDOWS\system32\divx.dll <Not Verified; DivX, Inc.; DivX®>
2008-03-28 19:41:32 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoConnect"="C:\Program Files\AutoConnect\AutoConnect.exe" [2006-12-03 01:14]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-11-14 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:44]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nltide_2"=regsvr32 /s /n /i:U shell32
"nltide_3"=rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"=1 (0x1)
"NoSMConfigurePrograms"=1 (0x1)
"NoSMHelp"=1 (0x1)
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoStartBanner"=1 (0x1)
"NoLowDiskSpaceChecks"=1 (0x1)
"NoResolveTrack"=1 (0x1)
"LinkResolveIgnoreLinkInfo"=1 (0x1)
"NoResolveSearch"=1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"=1 (0x1)
"NoSMConfigurePrograms"=1 (0x1)
"NoSMHelp"=1 (0x1)
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoStartBanner"=1 (0x1)
"NoLowDiskSpaceChecks"=1 (0x1)
"NoResolveTrack"=1 (0x1)
"LinkResolveIgnoreLinkInfo"=1 (0x1)
"NoResolveSearch"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DSLMON.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk
backup=C:\WINDOWS\pss\DSLMON.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
C:\Program Files\Cyberlink\Shared Files\brs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
"C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MS32DLL]
C:\WINDOWS\MS32DLL.dll.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
"C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
"C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
"C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefPrt]
C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"C:\Program Files\Winamp\winampa.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XP Tools]
C:\Program Files\XP Tools\xptools.exe /min
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService WebClient LmHosts upnphost SSDPSRV
-- End of Deckard's System Scanner: finished at 2008-06-23 17:58:32 ------------
ComboFix:
- Kod: Zaznacz wszystko
ComboFix 08-06-20.4 - Administrator 2008-06-23 18:00:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.673 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Pulpit\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\NetProject
C:\Program Files\NetProject\scu.exe
C:\Program Files\uusee
C:\Program Files\uusee\AD\UUAD_Banner.html
C:\Program Files\uusee\AD\UUAD_Banner.swf
C:\Program Files\uusee\AD\UUAD_Buffering.html
C:\Program Files\uusee\AD\UUAD_Buffering.swf
C:\Program Files\uusee\AD\UUAD_TextLink_0.xml
C:\Program Files\uusee\ARMP.ocx
C:\Program Files\uusee\in_psp.dll
C:\Program Files\uusee\MultiVMR9.dll
C:\Program Files\uusee\out_mmshttp.dll
C:\Program Files\uusee\patch_cmd.exe
C:\Program Files\uusee\u264Dec.ax
C:\Program Files\uusee\UFDeMux.ax
C:\Program Files\uusee\uninst.exe
C:\Program Files\uusee\updateC2.ocx
C:\Program Files\uusee\UUPlayer.dll
C:\Program Files\uusee\UUPlayer.exe
C:\Program Files\uusee\UUPlayer.ocx
C:\Program Files\uusee\UUPlayer.skn
C:\Program Files\uusee\UURecorder.exe
C:\Program Files\uusee\UUSee.url
C:\Program Files\uusee\uusee_video.dll
C:\Program Files\uusee\UUSEEAudioDec.ax
C:\Program Files\uusee\UUSeePlayer.exe
C:\Program Files\uusee\UUTV.xml
C:\Program Files\uusee\vermini.ini
C:\Program Files\uusee\vermini_x.ini
C:\Program Files\uusee\vermini_x1.ini
C:\WINDOWS\system32\bn.dll
C:\WINDOWS\system32\vbxtct32.dll
C:\WINDOWS\system32\vbxtreg32.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-23 to 2008-06-23 )))))))))))))))))))))))))))))))
.
2008-06-27 13:06 . 2008-06-27 13:07 <DIR> d-------- C:\Program Files\Prawo Jazdy 2006
2008-06-23 17:56 . 2008-06-23 17:56 <DIR> d-------- C:\Deckard
2008-06-23 17:52 . 2008-06-23 17:52 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-21 17:04 . 2008-06-21 17:04 <DIR> d-------- C:\Program Files\KONAMI
2008-06-21 16:41 . 2008-06-21 16:41 173,937 ---h----- C:\treeinfo.wc
2008-06-15 14:34 . 2008-06-19 23:53 <DIR> d-------- C:\USDownloader
2008-06-11 13:08 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-08 23:07 . 2008-06-08 23:07 <DIR> dr------- C:\Documents and Settings\Administrator\Dane aplikacji\Brother
2008-06-06 09:57 . 2008-06-06 09:57 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-06 09:57 . 2008-06-06 09:57 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-31 13:22 . 2008-02-07 17:10 <DIR> d--h----- C:\ckis
2008-05-29 23:05 . 2008-05-29 23:05 <DIR> d-------- C:\Program Files\Smart PC Solutions
2008-05-27 22:48 . 2008-06-23 12:48 38 --a------ C:\WINDOWS\avisplitter.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-23 15:45 --------- d-----w C:\Program Files\AutoConnect
2008-06-21 15:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-21 14:40 --------- d-----w C:\Program Files\totalcmd
2008-06-13 12:14 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-13 12:13 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-05-18 19:43 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Dev-Cpp
2008-05-18 18:36 --------- d-----w C:\Program Files\Real Desktop
2008-05-18 10:29 --------- d-----w C:\Program Files\ALCAM
2008-05-05 17:56 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-05-05 17:54 --------- d-----w C:\Program Files\MSBuild
2008-05-05 17:54 --------- d-----w C:\Program Files\Microsoft Works
2008-05-05 17:53 --------- d-----w C:\Program Files\Microsoft.NET
2008-05-04 20:29 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Media Player Classic
2008-05-04 19:35 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-04 19:35 --------- d-----w C:\Program Files\Brother
2008-05-04 19:33 --------- d-----w C:\Program Files\ScanSoft
2008-05-04 19:33 --------- d-----w C:\Program Files\Common Files\ScanSoft Shared
2008-05-04 19:33 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ScanSoft
2008-05-04 19:33 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\InstallShield
2008-05-04 19:33 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Brother
2008-05-04 19:16 --------- d-----w C:\Program Files\EA Sports
2008-05-04 18:55 --------- d-----w C:\Program Files\DAEMON Tools Pro
2008-05-04 18:55 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Pro
2008-05-04 18:55 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\DAEMON Tools Pro
2008-05-04 18:48 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-05-04 18:45 --------- d-----w C:\Program Files\Google
2008-05-04 18:44 --------- d-----w C:\Program Files\Gadu-Gadu
2008-05-04 18:44 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Gadu-Gadu
2008-05-04 18:43 --------- d-----w C:\Program Files\Lavalys
2008-05-04 18:43 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-05-04 18:43 --------- d-----w C:\Program Files\DVD Decrypter
2008-05-04 18:42 --------- d-----w C:\Program Files\SopCast
2008-05-04 18:42 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Office Genuine Advantage
2008-05-04 18:41 --------- d-----w C:\Program Files\TVUPlayer
2008-05-04 18:41 --------- d-----w C:\Program Files\TVAnts
2008-05-04 18:41 --------- d-----w C:\Program Files\PPStream
2008-05-04 18:41 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\TVU Networks
2008-05-04 18:41 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\TVU Networks
2008-05-04 18:41 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\ppstream
2008-05-04 18:40 --------- d-----w C:\Program Files\PPMate
2008-05-04 18:40 --------- d-----w C:\Program Files\PPLive
2008-05-04 18:40 --------- d-----w C:\Program Files\Common Files\Synacast
2008-05-04 18:40 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\PPMate
2008-05-04 18:40 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\PPLive
2008-05-04 18:37 --------- d-----w C:\Program Files\XP Tools
2008-05-04 18:35 --------- d-----w C:\Program Files\Analog Devices
2008-05-04 18:33 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\CyberLink
2008-05-04 18:32 505,128 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-05-04 18:32 49,448 ----a-w C:\WINDOWS\system32\msxml3r.dll
2008-05-04 18:32 353,576 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-05-04 18:32 29,480 ----a-w C:\WINDOWS\system32\msxml3a.dll
2008-05-04 18:32 1,241,896 ----a-w C:\WINDOWS\system32\msxml3.dll
2008-05-04 18:32 --------- d-----w C:\Program Files\CyberLink
2008-05-04 18:32 --------- d-----w C:\Program Files\Common Files\CyberLink
2008-05-04 18:32 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\CyberLink
2008-05-04 18:31 --------- d-----w C:\Program Files\MarBit
2008-05-04 18:31 --------- d-----w C:\Program Files\Alcohol Soft
2008-05-04 18:30 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-04 18:29 --------- d-----w C:\Program Files\NeroInstall.bak
2008-05-04 18:28 --------- d-----w C:\Program Files\Common Files\Nero
2008-05-04 18:28 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Nero
2008-05-04 18:27 --------- d-----w C:\Program Files\Nero
2008-05-04 18:27 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Nero
2008-05-04 18:19 --------- d-----w C:\Program Files\Opera
2008-05-04 18:18 32 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-05-04 18:17 --------- d-----w C:\Program Files\SAGEM
2008-05-04 18:17 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\InstallShield
2008-05-04 18:16 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Winamp
2008-05-04 18:15 --------- d-----w C:\Program Files\Winamp
2008-05-04 18:08 --------- d-----w C:\Program Files\Real Alternative
2008-05-04 18:08 --------- d-----w C:\Program Files\QuickTime Alternative
2008-05-04 18:08 --------- d-----w C:\Program Files\Java
2008-05-04 18:08 --------- d-----w C:\Program Files\Common Files\Java
2008-05-04 18:08 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2008-05-04 18:04 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2008-03-28 17:41 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
.
------- Sigcheck -------
2007-07-10 15:06 642560 ce594e18fe0d0af804f1f3694921ce62 C:\WINDOWS\system32\user32.dll
2007-07-14 00:56 814592 ce7193c5f7c01b19768e066087c1c919 C:\WINDOWS\system32\wininet.dll
2007-07-28 03:15 360576 0fb6743e937c7bb248b2530a5a77abc6 C:\WINDOWS\system32\drivers\tcpip.sys
2007-07-26 19:30 2067584 5362d54a6925afdcbbba53b43ee65774 C:\WINDOWS\system32\ntkrnlpa.exe
2007-07-26 19:31 2190464 9899bb89856e3bd4ef13e11ccee49b71 C:\WINDOWS\system32\ntoskrnl.exe
2007-07-14 00:42 974848 32f67215c57df2c401bf93b7ee65987f C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoConnect"="C:\Program Files\AutoConnect\AutoConnect.exe" [2006-12-03 01:14 310784]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-11-14 12:54 2131392]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:44 15360]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:44 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="regsvr32" []
"nltide_3"="advpack.dll" [2007-07-27 21:31 124928 C:\WINDOWS\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DSLMON.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk
backup=C:\WINDOWS\pss\DSLMON.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
--a------ 2008-03-21 10:21 91432 C:\Program Files\Cyberlink\Shared Files\brs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
-r------- 2006-03-28 15:48 622592 C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
--------- 2006-04-10 14:58 61440 C:\Program Files\Brother\ControlCenter3\brctrcen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 02:44 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
--a------ 2005-03-17 14:45 40960 C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2008-02-28 17:07 1828136 C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MS32DLL]
C:\WINDOWS\MS32DLL.dll.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2008-02-18 16:29 2221352 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2008-02-28 09:59 570664 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 01:41 81920 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--a------ 2005-03-17 14:25 57393 C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
--------- 2007-12-14 11:36 50472 C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
--------- 2008-03-20 20:23 83240 C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefPrt]
--a------ 2005-01-26 18:02 49152 C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XP Tools]
--a------ 2008-02-15 15:51 2084864 C:\Program Files\XP Tools\xptools.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"C:\\Program Files\\PPMate\\ppmate.exe"=
"C:\\Program Files\\PPLive\\PPLive.exe"=
"C:\\Program Files\\PPStream\\PPStream.exe"=
"C:\\Program Files\\PPStream\\PPSAP.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.321\\Polish\\setup.exe"=
"C:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Polish\\setup.exe"=
"C:\\Program Files\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
R0 AFPAnsi;Alfa File Protector Ansi;C:\WINDOWS\system32\Drivers\AFPAnsi.sys [2007-03-11 21:39]
R0 Si3112;Si3112;C:\WINDOWS\system32\drivers\Si3112.sys [2007-07-28 03:15]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};C:\Program Files\CyberLink\PowerDVD8\[u]0[/u]00.fcl [2008-02-01 17:24]
S2 ELOADER;General Purpose USB Driver (adildr.sys);C:\WINDOWS\system32\Drivers\adildr.sys [2007-02-07 16:50]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-23 18:01:07
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD8\[u]0[/u]00.fcl"
.
Completion time: 2008-06-23 18:01:28
ComboFix-quarantined-files.txt 2008-06-23 16:01:23
Pre-Run: 15,070,461,952 bajtów wolnych
Post-Run: 15,067,287,552 bajtów wolnych
264
HijackThis:
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:03:10, on 2008-06-23
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20583)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AutoConnect\AutoConnect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [AutoConnect] C:\Program Files\AutoConnect\AutoConnect.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
--
End of file - 4945 bytes