

- Kod: Zaznacz wszystko
ComboFix 08-11-13.01 - admin 2008-11-15 16:19:20.9 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.671 [GMT 1:00]
Uruchomiony z: c:\documents and settings\admin\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((( Pliki utworzone od 2008-10-15 do 2008-11-15 )))))))))))))))))))))))))))))))
.
Nie utworzono żadnych nowych plików w tym okresie
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-15 15:27 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab
2008-11-15 15:24 417,824 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-15 15:24 4,604 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-15 15:24 3,064,352 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-15 15:24 29,212 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-04 20:27 --------- d-----w c:\program files\Monkey's Audio
2008-10-24 10:45 --------- d-----w c:\program files\PCFriendly
2008-10-16 19:22 --------- d-----w c:\program files\Lx_cats
2008-10-15 17:00 332,800 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 17:26 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
2008-09-23 20:22 --------- d-----w c:\documents and settings\admin\Dane aplikacji\Skype
2008-09-23 17:34 --------- d-----w c:\documents and settings\admin\Dane aplikacji\skypePM
2008-09-18 19:39 --------- d-----w c:\program files\Winamp
2008-09-17 17:35 --------- d-----w c:\program files\7-Zip
2008-09-15 15:40 1,846,272 ----a-w c:\windows\system32\win32k.sys
2008-09-15 15:40 1,846,272 ------w c:\windows\system32\dllcache\win32k.sys
2008-08-29 20:05 3,894 ----a-w c:\windows\system32\tmp.reg
2008-08-28 10:04 333,056 ------w c:\windows\system32\dllcache\srv.sys
2008-08-27 13:17 87,040 ----a-w c:\windows\system32\VACFix.exe
2008-08-27 09:27 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-08-26 19:42 737,280 ----a-w c:\windows\iun6002.exe
2008-08-26 18:19 88,576 ----a-w c:\windows\system32\AntiXPVSTFix.exe
2008-08-26 08:27 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-26 08:27 826,368 ----a-w c:\windows\system32\dllcache\wininet.dll
2008-08-26 08:27 671,232 ----a-w c:\windows\system32\dllcache\mstime.dll
2008-08-26 08:27 477,696 ----a-w c:\windows\system32\dllcache\mshtmled.dll
2008-08-26 08:27 44,544 ----a-w c:\windows\system32\dllcache\pngfilt.dll
2008-08-26 08:27 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
2008-08-26 08:27 193,024 ----a-w c:\windows\system32\dllcache\msrating.dll
2008-08-26 08:27 105,984 ------w c:\windows\system32\dllcache\url.dll
2008-08-26 08:27 102,912 ------w c:\windows\system32\dllcache\occache.dll
2008-08-26 08:27 1,159,680 ----a-w c:\windows\system32\dllcache\urlmon.dll
2008-08-25 08:42 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-08-25 08:38 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-08-23 05:56 635,848 ------w c:\windows\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2008-08-18 10:19 82,432 ----a-w c:\windows\system32\404Fix.exe
2004-09-28 02:00 26,240 ----a-w c:\windows\inf\RAMDSK.SYS
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"USDownloader"="c:\documents and settings\admin\Pulpit\PULPIT1\USDownloader135\USDownloader.exe" [2008-06-24 531456]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2007-11-14 2131392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="/install" [X]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2002-03-26 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2002-03-26 106496]
"Smapp"="c:\program files\Analog Devices\SoundMAX\Smtray.exe" [2002-06-07 90112]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-01-10 4239360]
"LXBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2004-11-02 69632]
"TV Card Remote Control Device Monitor"="c:\windows\713xRMTMon.exe" [2006-10-11 352256]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-07 180269]
"KMCONFIG"="c:\program files\Keyboard & Mouse Driver\StartAutorun.exe" [2007-03-06 212992]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 201992]
"PROMon.exe"="PROMon.exe" [2002-04-18 c:\windows\system32\PROMon.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.321\\Polish\\setup.exe"=
"c:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Polish\\setup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R0 pnpshark;pnpshark;c:\windows\system32\DRIVERS\pnpshark.sys [2003-10-02 119552]
R0 st3shark;st3shark;c:\windows\system32\DRIVERS\st3shark.sys [2003-09-27 5504]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\DRIVERS\SAA713x.sys [2006-10-11 279552]
R2 bDriver;bDriver;c:\windows\system32\drivers\bDriver.sys [2008-05-06 8105]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Keyboard & Mouse Driver\KMWDSrv.exe [2007-04-05 208896]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2006-10-11 25984]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S3 KS-959;MA-620 USB Infrared Adapter;c:\windows\system32\DRIVERS\KS-959.sys [2005-10-22 19034]
S3 usbscan;Sterownik skanera USB;c:\windows\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Sterownik magazynu masowego USB;c:\windows\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
*Newly Created Service* - NMSCFG
.
Zawartość folderu 'Zaplanowane zadania'
2006-04-18 c:\windows\Tasks\Przypomnienie o rejestracji 1.job
- c:\windows\System32\OOBE\oobebaln.exe [2004-08-03 23:44]
2006-04-18 c:\windows\Tasks\Przypomnienie o rejestracji 2.job
- c:\windows\System32\OOBE\oobebaln.exe [2004-08-03 23:44]
2006-04-18 c:\windows\Tasks\Przypomnienie o rejestracji 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2004-08-03 23:44]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-PhotoShow Deluxe Media Manager - //~c:\progra~1\ahead\neroph~2\data\xtras\mssysmgr.exe
HKCU-Run-Skype - files\skype\phone\skype.exe
HKLM-Run-RemoteControl - files\cyberlink\powerdvd\pdvdserv.exe
HKLM-Run-DAEMON Tools-1033 - files\d-tools\daemon.exe
HKLM-Run-Adobe Reader Speed Launcher - files\adobe\reader 8.0\reader\reader_sl.exe
HKLM-Run-QuickTime Task - files\quicktime\qttask.exe
HKLM-Run-PCSuiteTrayApplication - files\nokia\nokia pc suite 6\launchapplication.exe
HKLM-Run-NeroFilterCheck - //~c:\windows\system32\nerocheck.exe
HKLM-Run-lxbumon.exe - files\lexmark 6200 series\lxbumon.exe
HKLM-Run-EzPrint - files\lexmark 6200 series\ezprint.exe
HKLM-Run-UC_SMB - (no file)
.
------- Skan uzupełniający -------
.
FireFox -: Profile - c:\documents and settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\ce0w2e99.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-15 16:27:18
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TV Card Remote Control Device Monitor = c:\windows\713xRMTMon.exe?RtlDllShutdownInProgress???????s??????????8??????????????????????????|???|???????|???|???????????|??6~-?6~????????????P?????????????????????6~??????;~??????????e?8t??????,?????;~4?????6~????????????P???????|???E?6~??????????????A????
skanowanie ukrytych plików ...
c:\windows\TEMP\cch~19d7a744.htp
c:\windows\TEMP\cch~19d850b1.htp
skanowanie pomyślnie ukończone
ukryte pliki: 2
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\NMSSvc.Exe
c:\program files\Keyboard & Mouse Driver\KMCONFIG.exe
c:\program files\Keyboard & Mouse Driver\KMProcess.exe
c:\windows\713xRMT.exe
.
**************************************************************************
.
Czas ukończenia: 2008-11-15 16:33:08 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-11-15 15:32:39
Przed: 1 746 497 536 bajtów wolnych
Po: 1,784,954,880 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Home Edition" /fastdetect /NoExecute=OptIn
161 --- E O F --- 2008-11-04 20:58:06
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:00:20, on 2008-11-15
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Keyboard & Mouse Driver\KMWDSrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PROMon.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\713xRMTMon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Keyboard & Mouse Driver\StartAutorun.exe
C:\Program Files\Keyboard & Mouse Driver\KMConfig.exe
C:\Program Files\Keyboard & Mouse Driver\KMProcess.exe
C:\WINDOWS\713xRMT.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\admin\Pulpit\PULPIT1\USDownloader135\USDownloader.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\admin\Pulpit\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] //~nwiz.exe /install
O4 - HKLM\..\Run: [RemoteControl] //~c:\program files\cyberlink\powerdvd\pdvdserv.exe
O4 - HKLM\..\Run: [LXBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMTMon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Keyboard & Mouse Driver\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] //~c:\program files\d-tools\daemon.exe -lang 1033
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] //~c:\program files\adobe\reader 8.0\reader\reader_sl.exe
O4 - HKLM\..\Run: [QuickTime Task] //~c:\program files\quicktime\qttask.exe -atboottime
O4 - HKLM\..\Run: [PCSuiteTrayApplication] //~c:\program files\nokia\nokia pc suite 6\launchapplication.exe -startup
O4 - HKLM\..\Run: [NeroFilterCheck] //~c:\windows\system32\nerocheck.exe
O4 - HKLM\..\Run: [lxbumon.exe] //~c:\program files\lexmark 6200 series\lxbumon.exe
O4 - HKLM\..\Run: [EzPrint] //~c:\program files\lexmark 6200 series\ezprint.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] //~c:\progra~1\ahead\neroph~2\data\xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Skype] //~c:\program files\skype\phone\skype.exe /nosplash /minimized
O4 - HKCU\..\Run: [USDownloader] "C:\Documents and Settings\admin\Pulpit\PULPIT1\USDownloader135\USDownloader.exe"
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] E:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Statystyki ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mks.com.pl
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Keyboard & Mouse Driver\KMWDSrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbu_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbucoms.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 6878 bytes
z góry wielkie dzięki
