
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.3327.2599 [GMT 1:00]
Uruchomiony z: c:\documents and settings\inventor\Pulpit\ratunek.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\atmapi.sys
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-18 do 2008-12-18 )))))))))))))))))))))))))))))))
.
2008-12-17 17:11 . 2008-12-17 17:11 <DIR> d-------- c:\program files\Common Files\Scanner
2008-12-16 17:48 . 2008-12-16 17:48 32,768 --a------ c:\windows\system32\zed.pa
2008-12-16 17:48 . 2008-12-16 17:48 32,768 --a------ c:\windows\system32\fkj.jee
2008-12-16 17:48 . 2008-12-16 17:48 24,576 --a------ c:\windows\system32\rgr6.pa
2008-12-16 17:47 . 2008-12-16 17:47 580,096 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-12-16 17:47 . 2008-12-15 11:47 163,840 --a------ c:\windows\system32\aston.mt
2008-12-16 17:47 . 2008-12-16 17:47 65,024 --a------ c:\windows\system32\r33.es
2008-12-16 17:47 . 2008-12-16 17:47 64,512 --a------ c:\windows\system32\efgop.ee
2008-12-16 17:47 . 2008-12-16 17:47 21,504 --a------ c:\windows\system32\v1.e2
2008-12-12 15:59 . 2007-02-09 11:39 10,752 --a------ c:\windows\system32\KOAZXJAL.DLL
2008-12-09 16:05 . 2008-12-09 16:05 <DIR> d-------- c:\windows\SQLTools9_KB948109_ENU
2008-12-09 16:03 . 2008-12-09 16:03 <DIR> d-------- c:\windows\SQL9_KB948109_ENU
2008-12-08 19:13 . 2008-12-08 19:13 <DIR> d-------- c:\program files\MSXML 6.0
2008-12-08 14:48 . 2008-12-17 16:17 <DIR> d-------- C:\skany
2008-12-05 08:54 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-12-05 08:54 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2008-12-05 08:54 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-12-05 08:48 . 2008-12-05 08:48 <DIR> d-------- c:\program files\Microsoft Works
2008-12-05 08:45 . 2008-12-05 08:45 <DIR> d-------- c:\windows\SHELLNEW
2008-12-05 08:44 . 2008-12-11 17:45 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2008-12-05 08:43 . 2008-12-05 08:43 <DIR> dr-h----- C:\MSOCache
2008-11-24 10:48 . 2008-11-24 10:48 23,558 --a------ C:\acadminidump.dmp
2008-11-24 10:48 . 2008-11-24 10:48 118 --a------ c:\windows\system32\AoVw2008.err
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-17 16:11 --------- d-----w c:\program files\CA
2008-12-16 16:47 580,096 ----a-w c:\windows\system32\user32.DLL
2008-12-09 15:05 --------- d-----w c:\program files\Microsoft SQL Server
2008-12-05 07:47 --------- d-----w c:\program files\Microsoft.NET
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:42 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-21 06:10 --------- d-----w c:\program files\Internet Download Manager
2008-10-21 06:10 --------- d-----w c:\documents and settings\inventor\Dane aplikacji\IDM
2008-10-21 06:08 --------- d-----w c:\documents and settings\inventor\Dane aplikacji\DMCache
2008-10-16 20:33 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-03 10:04 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2006-06-23 06:48 32,768 ----a-r c:\windows\inf\UpdateUSB.exe
2008-08-25 08:54 32,768 --sha-w c:\windows\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\MSHist012008082520080826\index.dat
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-05-15 484904]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"SoundMAX"="c:\program files\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 729088]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-03-21 1953792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2007-02-10 241664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-08-16 177416]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-04-30 230928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-17 7561216]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Przyspieszenie uruchomienia programu AutoCAD LT.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2007-02-13 11000]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R3 PPCtlPriv;PPCtlPriv;"c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" [2007-08-16 189704]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2007-09-28 176128]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys [2007-09-28 13532]
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Zawartość folderu 'Zaplanowane zadania'
2008-12-17 c:\windows\Tasks\CAAntiSpywareScan_Daily as inventor at 18 11.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-16 21:10]
.
.
------- Skan uzupełniający -------
.
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\VetRedir.dll
FF - ProfilePath - c:\documents and settings\inventor\Dane aplikacji\Mozilla\Firefox\Profiles\szfur7ll.default\
FF - prefs.js: browser.startup.homepage - http://www.onet.pl
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOggX.dll
ATTENTION: FIREFOX POLICES IS IN FORCE
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.rights.version", 3);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.rights.3.shown", false);
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-18 11:36:31
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(2040)
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
- - - - - - - > 'lsass.exe'(604)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
.
Czas ukończenia: 2008-12-18 11:37:54
ComboFix-quarantined-files.txt 2008-12-18 10:37:46
Przed: 125 698 060 288 bajtów wolnych
Po: 126,808,576,000 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional 3GB" /3GB /fastdetect
147 --- E O F --- 2008-12-18 09:46:12