


Laptop to Toshiba Satelite A80-115 Model no PSA80E-02700GDU
ComboFix 08-04-13.1 - BATMAN 2008-04-13 22:42:03.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.693 [GMT 2:00]
Running from: C:\Documents and Settings\BATMAN\Pulpit\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-13 to 2008-04-13 )))))))))))))))))))))))))))))))
.
2008-04-13 22:38 . 2008-04-13 22:38 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-13 20:55 . 2004-08-04 14:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-13 20:37 . 2008-04-13 20:37 <DIR> d-------- C:\Documents and Settings\BATMAN\Dane aplikacji\Gadu-Gadu
2008-04-13 20:34 . 2008-04-13 20:37 <DIR> d-------- C:\Documents and Settings\BATMAN\Gadu-Gadu
2008-04-13 20:21 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-13 20:07 . 2008-04-13 20:07 13,646 --a------ C:\WINDOWS\system32\wpa.bak
2008-04-13 20:00 . 2008-04-13 21:39 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-04-13 20:00 . 2008-04-13 20:21 <DIR> d-------- C:\Program Files\Java
2008-04-13 20:00 . 2008-04-13 20:00 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-13 19:45 . 2008-04-13 19:49 <DIR> d-------- C:\Program Files\Opera
2008-04-13 19:30 . 2008-04-13 19:30 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-04-13 19:05 . 2005-07-19 21:14 3,289,088 --a------ C:\WINDOWS\system32\drivers\w29n51.sys
2008-04-13 19:05 . 2005-07-22 22:40 1,671,168 --a------ C:\WINDOWS\system32\W29MLRES.DLL
2008-04-13 19:05 . 2005-07-22 22:39 466,944 --a------ C:\WINDOWS\system32\w29NCPA.dll
2008-04-13 19:05 . 2005-08-11 10:27 13 --a------ C:\WINDOWS\system32\drivers\verfile.tic
2008-04-13 17:33 . 2008-04-13 22:42 <DIR> d-------- C:\Program Files\ESET
2008-04-13 17:33 . 2008-04-13 17:33 502,368 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-04-13 17:33 . 2008-04-13 17:33 270,336 --a------ C:\WINDOWS\system32\imon.dll
2008-04-13 17:24 . 2008-04-13 17:24 <DIR> d-------- C:\WINDOWS\tiinst
2008-04-13 17:22 . 2008-04-13 17:22 <DIR> d-------- C:\Program Files\Apoint2K
2008-04-13 17:22 . 2005-02-15 15:13 101,874 --a------ C:\WINDOWS\system32\drivers\Apfiltr.sys
2008-04-13 17:22 . 2005-02-15 15:14 87,865 --a------ C:\WINDOWS\system32\Vxdif.dll
2008-04-13 17:15 . 2004-04-09 21:34 28,672 --a------ C:\WINDOWS\system32\DelRunOnceReg.exe
2008-04-13 17:13 . 2008-04-13 17:13 <DIR> d-------- C:\Program Files\Intel
2008-04-13 17:12 . 2008-04-13 17:25 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-13 17:12 . 2008-04-13 17:30 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-04-13 17:11 . 2005-02-15 15:03 167,936 --a------ C:\WINDOWS\system32\igfxres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-13 16:59 --------- d-----w C:\Program Files\ltmoh
2008-04-13 14:38 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-13 14:36 --------- d-----w C:\Program Files\Usługi online
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-15 15:03 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-15 15:03 126976]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2005-02-15 15:13 196608]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-04-13 17:33 921600]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-01-03 17:37 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-02-15 15:09 88363 C:\WINDOWS\agrsmmsg.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\PROGRAMY\\BearShare\\BearShare.exe"=
"C:\\Program Files\\ESET\\nod32.exe"=
"C:\\Program Files\\Opera\\Opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2006-07-18 12:02]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2006-07-18 12:02]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-13 22:46:42
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
Completion time: 2008-04-13 22:48:20
ComboFix-quarantined-files.txt 2008-04-13 20:48:11
Pre-Run: 3,297,239,040 bajtów wolnych
Post-Run: 3,291,103,232 bajtów wolnych
.
2008-04-13 19:39:57 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:38:38, on 2008-04-13
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
--
End of file - 3802 bytes
keyboard generates is that the super functions on the Function keys no longer work (i.e those for changing the brightness of the screen) also during boot the keyboard generates keyboard buffer overflows
kahoona napisał(a):zaniedbał kilkukrotnego przeinstalowania sterowników
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 11 gości