
ComboFix 09-04-28.05 - bata 2009-04-29 15:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.2046.1359 [GMT 2:00]
Uruchomiony z: c:\documents and settings\bata\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\pthreadGC2.dll
.
((((((((((((((((((((((((( Pliki utworzone od 2009-05-28 do 2009-4-29 )))))))))))))))))))))))))))))))
.
2009-04-29 12:45 . 2001-05-16 15:54 309616 ----a-w c:\windows\system32\wmv8dmod.dll
2009-04-29 12:45 . 2001-05-11 11:18 420240 ----a-w c:\windows\system32\mpg4c32.dll
2009-04-29 12:44 . 2009-04-29 12:52 -------- d-----w c:\program files\Game Cam
2009-04-28 08:54 . 2009-04-28 08:54 -------- d-----w c:\documents and settings\bata\Ustawienia lokalne\Dane aplikacji\AeroSnapApp
2009-04-28 08:54 . 2009-04-28 08:54 -------- d-----w c:\documents and settings\bata\Dane aplikacji\AeroSnapApp
2009-04-28 08:53 . 2009-04-28 08:53 -------- d-----w c:\program files\AeroSnap
2009-04-26 10:48 . 2009-04-26 10:48 -------- d-----w c:\documents and settings\bata\Ustawienia lokalne\Dane aplikacji\MiTAC_International_Corpo
2009-04-26 10:42 . 2009-04-26 10:42 -------- d-----w c:\program files\Mio Technology
2009-04-26 10:41 . 2009-04-26 10:41 -------- d-----w c:\program files\Microsoft ActiveSync
2009-04-26 08:25 . 2009-04-27 17:26 -------- d-----w c:\program files\UltraStar Deluxe
2009-04-25 12:32 . 2009-04-25 12:32 -------- d-----w c:\documents and settings\bata\Ustawienia lokalne\Dane aplikacji\Stardock
2009-04-25 12:29 . 2009-04-25 12:29 46522 ----a-w c:\windows\BricoPackUninst.cmd
2009-04-25 12:27 . 2009-04-25 12:29 2145 ----a-w c:\windows\BricoPackFoldersDelete.cmd
2009-04-25 12:27 . 2009-04-25 12:27 -------- d-----w c:\windows\BricoPacks
2009-04-24 10:31 . 2009-04-24 10:31 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Electronic Arts
2009-04-24 09:58 . 2009-04-24 09:58 -------- d-----w c:\documents and settings\bata\Ustawienia lokalne\Dane aplikacji\Criterion Games
2009-04-24 07:33 . 2009-04-24 07:33 -------- d-----w c:\documents and settings\bata\Dane aplikacji\Ashampoo
2009-04-24 07:33 . 2009-04-24 07:33 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\ashampoo
2009-04-24 06:39 . 2009-04-24 06:39 -------- d-----w c:\documents and settings\bata\Dane aplikacji\Foxit
2009-04-24 06:39 . 2009-04-24 06:39 -------- d-----w c:\program files\Foxit Software
2009-04-23 15:39 . 2009-04-23 15:39 -------- d-----w C:\RRTVAULT
2009-04-23 15:38 . 2001-07-13 11:56 14976 ----a-w c:\windows\system32\drivers\SBKUPNT.SYS
2009-04-23 15:38 . 1997-02-08 15:11 13312 ----a-w c:\windows\system32\DEVLOAD.EXE
2009-04-23 15:38 . 1998-10-29 14:45 384512 ----a-w c:\windows\IsUninst.exe
2009-04-23 13:13 . 2009-04-23 13:13 -------- d-----w c:\program files\NAPI-PROJEKT
2009-04-21 14:50 . 2009-04-21 14:50 -------- d-----w c:\documents and settings\bata\Dane aplikacji\FreeStone Group
2009-04-21 14:50 . 2009-04-21 14:50 -------- d-----w c:\program files\Video Card Stability Test
2009-04-21 10:17 . 2005-08-25 23:50 77312 ----a-w c:\windows\system32\ztvunace26.dll
2009-04-21 10:17 . 2006-05-25 13:52 162304 ----a-w c:\windows\system32\ztvunrar36.dll
2009-04-21 10:17 . 2006-06-19 11:01 69632 ----a-w c:\windows\system32\ztvcabinet.dll
2009-04-21 10:17 . 2002-03-05 23:00 75264 ----a-w c:\windows\system32\unacev2.dll
2009-04-21 10:17 . 2003-02-02 18:06 153088 ----a-w c:\windows\system32\UNRAR3.dll
2009-04-21 10:17 . 2009-04-21 10:17 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Simply Super Software
2009-04-21 10:17 . 2009-04-21 10:17 -------- d-----w c:\program files\Trojan Remover
2009-04-21 10:17 . 2009-04-21 10:17 -------- d-----w c:\documents and settings\bata\Dane aplikacji\Simply Super Software
2009-04-21 09:47 . 2009-04-21 09:47 -------- d-----w c:\program files\Fic_Products
2009-04-20 15:48 . 2009-04-29 13:04 -------- d---a-w c:\documents and settings\All Users\Dane aplikacji\TEMP
2009-04-20 15:48 . 2009-04-29 13:02 -------- d-----w C:\Fraps
2009-04-20 14:29 . 2009-04-20 14:30 -------- d-----w c:\program files\RivaTuner v2.24
2009-04-20 14:17 . 2009-04-06 20:43 875040 ----a-w c:\windows\system32\nvcplui.exe
2009-04-20 14:17 . 2009-04-06 20:43 466944 ----a-w c:\windows\system32\nvshell.dll
2009-04-20 14:17 . 2009-04-07 02:30 453152 ----a-w c:\windows\system32\nvudisp.exe
2009-04-20 14:07 . 2009-04-20 14:07 -------- d-----w C:\XP_Dox_18084
2009-04-20 13:53 . 2006-08-02 04:02 49152 ----a-w c:\windows\system32\ChCfg.exe
2009-04-20 13:53 . 2006-07-22 05:14 167936 ----a-w c:\windows\SoundMan.exe
2009-04-20 13:53 . 2007-05-08 07:51 1904640 ----a-w c:\windows\SkyTel.exe
2009-04-20 13:53 . 2007-01-16 23:39 1191936 ----a-w c:\windows\RtlUpd.exe
2009-04-20 13:53 . 2007-03-24 08:19 9715200 ----a-w c:\windows\RTLCPL.exe
2009-04-20 13:53 . 2007-05-11 07:28 4419584 ----a-w c:\windows\system32\drivers\RtkHDAud.sys
2009-04-20 13:53 . 2007-05-11 07:08 16342528 ----a-w c:\windows\RTHDCPL.exe
2009-04-20 13:53 . 2007-04-26 05:55 2162688 ----a-w c:\windows\MicCal.exe
2009-04-20 13:53 . 2006-05-05 05:26 2808832 ----a-w c:\windows\alcwzrd.exe
2009-04-20 13:53 . 2005-05-04 07:43 147456 ----a-w c:\windows\Alcmtr.exe
2009-04-20 13:53 . 2009-04-20 13:53 -------- d-----w c:\program files\Realtek
2009-04-20 13:53 . 2007-01-13 05:54 520192 ----a-w c:\windows\RtlExUpd.dll
2009-04-20 13:29 . 2009-04-07 02:30 1502234 ----a-w c:\windows\system32\nvdata.bin
2009-04-20 10:56 . 2009-04-20 10:56 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Broadcom
2009-04-20 10:56 . 2009-04-20 10:56 -------- d-----w c:\documents and settings\bata\Dane aplikacji\InstallShield
2009-04-20 09:17 . 2009-04-20 09:17 -------- d-----w c:\documents and settings\bata\Dane aplikacji\PlayFirst
2009-04-20 09:17 . 2009-04-20 09:17 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\PlayFirst
2009-04-19 17:30 . 2009-04-19 17:30 129 ----a-w c:\documents and settings\bata\Ustawienia lokalne\Dane aplikacji\fusioncache.dat
2009-04-19 17:30 . 2009-04-29 12:46 -------- d-----w c:\documents and settings\bata\Ustawienia lokalne\Dane aplikacji\ApplicationHistory
2009-04-19 17:29 . 2009-04-19 17:29 -------- d-----w c:\windows\system32\URTTEMP
2009-04-19 17:19 . 2007-03-06 12:58 57344 ----a-w c:\windows\system32\acpimof.dll
2009-04-19 17:18 . 2007-12-10 15:59 8704 ----a-w c:\windows\system32\drivers\TVicPort64.sys
2009-04-19 17:18 . 2007-12-10 15:59 14544 ----a-w c:\windows\system32\drivers\TVicPort.sys
2009-04-19 17:18 . 2007-12-10 15:59 6080 ----a-w c:\windows\system32\drivers\zntport.sys
2009-04-19 17:18 . 2007-12-10 15:59 6144 ----a-w c:\windows\system32\drivers\zntport64.sys
2009-04-19 17:18 . 2007-12-10 15:59 14120 ----a-w c:\windows\system32\drivers\int15.sys
2009-04-19 17:18 . 2007-12-10 15:59 8704 ----a-w c:\windows\system32\drivers\int15_64.sys
2009-04-19 17:18 . 2006-02-22 09:19 69632 ----a-w c:\windows\system32\eRecUtil.dll
2009-04-19 17:10 . 2006-02-22 09:19 1047552 ----a-w c:\windows\system32\mfc71u.dll
2009-04-19 17:07 . 2009-04-19 17:07 -------- dc----w c:\windows\system32\DRVSTORE
2009-04-19 17:07 . 2009-04-19 17:07 -------- d-----w c:\program files\Intel
2009-04-19 17:06 . 2009-04-19 17:06 -------- d-----w C:\Intel
2009-04-19 17:00 . 2008-04-14 20:50 21504 -c--a-w c:\windows\system32\dllcache\hidserv.dll
2009-04-19 17:00 . 2008-04-14 20:50 21504 ----a-w c:\windows\system32\hidserv.dll
2009-04-19 15:59 . 2009-04-19 17:04 22528 ----a-w c:\windows\system32\drivers\nhcDriver.sys
2009-04-19 15:50 . 2009-04-19 15:56 -------- d-----w c:\program files\Notebook Hardware Control
2009-04-19 15:38 . 2009-04-19 15:38 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-04-19 15:34 . 2004-07-19 11:10 4096 ----a-w c:\windows\system32\drivers\epm-psd.sys
2009-04-19 15:34 . 2005-04-07 16:08 78208 ----a-w c:\windows\system32\drivers\epm-shd.sys
2009-04-19 15:34 . 2009-04-19 17:09 -------- d-----w C:\Acer
2009-04-19 15:34 . 2006-02-16 13:39 45056 ----a-w c:\windows\system32\Epm-Po.dll
2009-04-19 14:35 . 2009-04-19 14:37 -------- d-----w c:\program files\Counter-Strike 1.6
2009-04-19 10:44 . 2009-04-19 10:44 -------- d-----w c:\program files\InCode Solutions
2009-04-19 09:39 . 2009-04-19 09:39 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Trymedia
2009-04-19 09:37 . 2009-04-24 20:15 -------- d-----w c:\program files\MCF Ravenhearst
2009-04-19 08:42 . 2009-04-19 14:57 -------- d-----w c:\documents and settings\bata\Ustawienia lokalne\Dane aplikacji\The Witcher
2009-04-19 07:36 . 2009-04-19 07:36 -------- d-----w c:\program files\7-Zip
2009-04-18 18:25 . 2009-04-18 18:25 -------- d-----w c:\program files\SystemRequirementsLab
2009-04-18 18:24 . 2009-04-18 18:25 -------- d-----w c:\documents and settings\bata\SystemRequirementsLab
2009-04-18 18:05 . 2009-04-18 18:05 -------- d-----w c:\documents and settings\bata\.jpi_cache
2009-04-18 18:05 . 2009-04-18 18:05 -------- d-----w c:\documents and settings\bata\.java
2009-04-18 14:46 . 2009-04-18 14:46 4096 ----a-w c:\windows\d3dx.dat
2009-04-18 13:52 . 2009-04-18 14:46 -------- d-----w c:\program files\Cinemaware
2009-04-18 13:51 . 2009-04-18 13:51 -------- d-----w c:\documents and settings\bata\Dane aplikacji\DAEMON Tools
2009-04-18 13:51 . 2009-04-18 13:51 -------- d-----w c:\documents and settings\bata\Dane aplikacji\DAEMON Tools Pro
2009-04-18 13:50 . 2009-04-18 13:50 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\DAEMON Tools Lite
2009-04-18 13:50 . 2009-04-18 13:50 -------- d-----w c:\program files\DAEMON Tools Lite
2009-04-18 13:44 . 2009-04-18 13:44 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-04-18 13:44 . 2009-04-18 13:44 -------- d-----w c:\documents and settings\bata\Dane aplikacji\DAEMON Tools Lite
2009-04-17 16:32 . 2009-04-29 08:16 -------- d-----w c:\documents and settings\bata\Dane aplikacji\AIMP
2009-04-17 12:40 . 2009-04-17 12:40 -------- d-----w c:\windows\4 Elements
2009-04-17 12:40 . 2009-04-17 12:41 -------- d-----w c:\program files\4 Elements
2009-04-16 19:06 . 2008-04-14 20:51 221184 ----a-w c:\windows\system32\wmpns.dll
2009-04-16 15:47 . 2009-04-25 12:40 -------- d-----w c:\documents and settings\bata\Dane aplikacji\gtk-2.0
2009-04-16 15:45 . 2009-04-16 15:45 -------- d-----w c:\documents and settings\bata\.thumbnails
2009-04-16 15:45 . 2009-04-25 12:44 -------- d-----w c:\documents and settings\bata\.gimp-2.6
2009-04-16 15:45 . 2009-04-16 15:45 -------- d-----w c:\documents and settings\bata\.gegl-0.0
2009-04-16 15:45 . 2009-04-16 15:45 -------- d-----w c:\program files\Gimp-2.0
2009-04-16 14:18 . 2009-04-18 11:27 -------- d-----w c:\program files\Gameforge4D
2009-04-16 12:06 . 2009-02-09 11:26 2190336 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-16 12:06 . 2009-02-09 11:26 2146816 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-16 12:06 . 2009-02-09 11:26 2025472 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-16 12:05 . 2008-06-14 17:36 273024 -c----w c:\windows\system32\dllcache\bthport.sys
2009-04-16 12:05 . 2008-06-14 17:36 273024 ------w c:\windows\system32\drivers\bthport.sys
2009-04-16 12:05 . 2008-10-24 11:21 455296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-16 11:59 . 2009-04-16 11:59 -------- d-----w c:\documents and settings\bata\Ustawienia lokalne\Dane aplikacji\Identities
2009-04-15 21:11 . 2009-04-15 21:11 -------- d-----w c:\documents and settings\bata\Ustawienia lokalne\Dane aplikacji\Help
2009-04-15 21:05 . 2003-10-16 16:07 32768 ----a-w c:\windows\system32\WooDial2000.dll
2009-04-15 21:04 . 2002-11-01 18:15 41068 ------w c:\windows\system32\ActPanel.dll
2009-04-15 21:04 . 2009-04-15 21:04 -------- d-----w c:\program files\Java
2009-04-15 21:02 . 2009-04-22 16:44 -------- d-----w c:\program files\Neostrada TP
2009-04-15 21:01 . 2009-04-15 21:01 -------- d-----w c:\documents and settings\backa\Ustawienia lokalne\Dane aplikacji\Help
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-29 12:52 . 2009-04-14 15:32 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-26 10:53 . 2009-04-14 15:32 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-25 12:29 . 2008-04-14 20:50 219648 ----a-w c:\windows\system32\uxtheme.dll
2009-04-24 07:33 . 2009-04-14 15:30 -------- d-----w c:\program files\Ashampoo
2009-04-20 13:46 . 2001-10-26 18:15 79920 ----a-w c:\windows\system32\perfc015.dat
2009-04-20 13:46 . 2001-10-26 18:15 458146 ----a-w c:\windows\system32\perfh015.dat
2009-04-20 10:57 . 2009-04-20 10:57 -------- d-----w c:\program files\Broadcom
2009-04-19 07:34 . 2009-04-14 15:29 -------- d-----w c:\program files\Gadu-Gadu
2009-04-15 20:53 . 2009-04-15 20:52 23 ----a-w c:\windows\system32\drivers\adidsl.cfg
2009-04-15 16:45 . 2009-04-14 15:18 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-14 20:57 . 2009-04-14 15:28 -------- d-----w c:\program files\SubEdit-Player
2009-04-14 15:31 . 2009-04-14 15:31 12328 ----a-w c:\documents and settings\bata\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-04-14 15:29 . 2009-04-14 15:29 -------- d-----w c:\program files\AIMP2
2009-04-14 15:29 . 2009-04-14 15:28 -------- d-----w c:\program files\K-Lite Codec Pack
2009-04-14 15:19 . 2009-04-14 15:19 -------- d-----w c:\program files\microsoft frontpage
2009-04-14 15:18 . 2001-07-22 00:36 67 --sha-w c:\windows\Fonts\desktop.ini
2009-04-14 15:17 . 2009-04-14 15:17 -------- d-----w c:\program files\Usługi online
2009-04-14 15:15 . 2009-04-14 15:15 21856 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-14 14:14 . 2009-04-14 14:14 603904 ----a-w c:\windows\system32\TUProgSt.exe
2009-04-14 14:14 . 2009-04-14 14:14 360192 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-04-14 14:14 . 2009-04-14 14:14 -------- d-----w c:\program files\TuneUp Utilities 2009
2009-04-14 14:06 . 2009-04-14 14:06 -------- d-----w c:\program files\uTorrent
2009-04-14 14:04 . 2009-04-14 14:04 315392 ----a-w c:\windows\HideWin.exe
2009-04-14 13:36 . 2009-04-14 13:36 0 ----a-w c:\windows\nsreg.dat
2009-04-07 02:30 . 2009-04-20 14:16 9986048 ----a-w c:\windows\system32\nvoglnt.dll
2009-04-07 02:30 . 2009-04-20 14:16 659456 ----a-w c:\windows\system32\nvcuvid.dll
2009-04-07 02:30 . 2009-04-20 14:16 802816 ----a-w c:\windows\system32\nvapi.dll
2009-04-07 02:30 . 2009-04-20 14:16 1720320 ----a-w c:\windows\system32\nvcuda.dll
2009-04-07 02:30 . 2009-04-20 14:16 139264 ----a-w c:\windows\system32\nvcodins.dll
2009-04-07 02:30 . 2009-04-20 14:16 139264 ----a-w c:\windows\system32\nvcod.dll
2009-04-07 02:30 . 2009-04-20 14:16 1310720 ----a-w c:\windows\system32\nvcuvenc.dll
2009-04-07 02:30 . 2009-04-14 15:26 8030624 ----a-w c:\windows\system32\drivers\nv4_mini.sys
2009-04-07 02:30 . 2009-04-14 15:25 5882496 ----a-w c:\windows\system32\nv4_disp.dll
2009-04-06 20:43 . 2009-04-20 14:16 4038656 ----a-w c:\windows\system32\nvvitvs.dll
2009-04-06 20:43 . 2009-04-20 14:16 168004 ----a-w c:\windows\system32\nvsvc32.exe
2009-04-06 20:43 . 2009-04-20 14:16 1282048 ----a-w c:\windows\system32\nvmobls.dll
2009-04-06 20:43 . 2009-04-20 14:16 3510272 ----a-w c:\windows\system32\nvgames.dll
2009-04-06 20:43 . 2009-04-20 14:16 188416 ----a-w c:\windows\system32\nvmccss.dll
2009-04-06 20:43 . 2009-04-20 14:16 4014080 ----a-w c:\windows\system32\nvdisps.dll
2009-04-06 20:43 . 2009-04-20 14:16 86016 ----a-w c:\windows\system32\nvmctray.dll
2009-04-06 20:43 . 2009-04-20 14:16 13750272 ----a-w c:\windows\system32\nvcpl.dll
2009-04-06 20:43 . 2009-04-20 14:16 229376 ----a-w c:\windows\system32\nvmccs.dll
2009-03-27 06:14 . 2009-04-20 14:16 526880 ----a-w c:\windows\system32\NVUNINST.EXE
2009-03-16 12:18 . 2009-04-14 18:06 69448 ----a-w c:\windows\system32\XAPOFX1_3.dll
2009-03-16 12:18 . 2009-04-14 18:06 517448 ----a-w c:\windows\system32\XAudio2_4.dll
2009-03-16 12:18 . 2009-04-14 18:06 235352 ----a-w c:\windows\system32\xactengine3_4.dll
2009-03-16 12:18 . 2009-04-14 18:06 22360 ----a-w c:\windows\system32\X3DAudio1_6.dll
2009-03-09 13:27 . 2009-04-14 18:06 453456 ----a-w c:\windows\system32\d3dx10_41.dll
2009-03-09 13:27 . 2009-04-14 18:06 1846632 ----a-w c:\windows\system32\D3DCompiler_41.dll
2009-03-09 13:27 . 2009-04-14 18:06 4178264 ----a-w c:\windows\system32\D3DX9_41.dll
2009-03-06 14:22 . 2008-04-14 20:50 285696 ----a-w c:\windows\system32\pdh.dll
2009-03-02 18:10 . 2009-04-14 15:28 67584 ----a-w c:\windows\system32\ff_vfw.dll
2009-02-20 08:12 . 2008-04-14 20:50 1228288 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:11 . 2008-04-14 20:50 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 14:07 . 2008-04-14 19:35 1847040 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:26 . 2008-04-14 21:59 2025472 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:26 . 2008-04-14 19:59 2146816 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:25 . 2008-04-14 20:51 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:53 . 2008-04-14 20:50 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:53 . 2008-04-14 20:50 731136 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2008-04-14 20:50 686592 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:53 . 2008-04-14 20:49 722944 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 10:39 . 2001-10-26 19:30 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:58 . 2008-04-14 20:50 56832 ----a-w c:\windows\system32\secur32.dll
.
------- Sigcheck -------
[7] 2009-02-20 07:59 670208 34C7AEEA309028BF0230666E7C35252B c:\windows\$hf_mig$\KB963027\SP3QFE\wininet.dll
[-] 2009-02-20 08:12 1228288 1A18DADF07F09A39CB52BE0832692D89 c:\windows\system32\wininet.dll
[-] 2009-02-20 08:12 1228288 1A18DADF07F09A39CB52BE0832692D89 c:\windows\system32\dllcache\wininet.dll
[-] 2008-04-14 20:51 1883648 362927970E571D832AC7BB49A702F687 c:\windows\explorer.exe
[-] 2008-04-14 20:51 1883648 362927970E571D832AC7BB49A702F687 c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\progra~1\MICROS~2\wcescomm.exe" [2006-11-13 1358632]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Acer Empowering Technology.lnk - c:\acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2009-4-19 126976]
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2009-4-15 966756]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"d:\\PES 2009\\pes2009.exe"=
"c:\\Program Files\\InCode Solutions\\RemoveIT Pro v4 - SE\\removeit.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"d:\\PES 2009\\kitserver\\setup.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\ComboFix\\NirCmd.cfexe"=
"c:\\PROGRA~1\\NEOSTR~1\\CnxMon.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 Notebook Hardware Control Service;Notebook Hardware Control Service; [x]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2009-04-14 603904]
R3 zlportio;zlportio; [x]
S2 AASW2_Service;Ashampoo AntiSpyWare 2 Service;c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWareService.exe [2008-11-04 749400]
S2 SBKUPNT;SBKUPNT;c:\windows\system32\Drivers\SBKUPNT.SYS [2001-07-13 14976]
S3 abp470n5;abp470n5; [x]
--- Inne Usługi/Sterowniki w Pamięci ---
*NewlyCreated* - UMWDF
*Deregistered* - mchInjDrv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Zawartość folderu 'Zaplanowane zadania'
2009-04-29 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.neostrada.pl
IE: { - c:\program files\Messenger\msmsgs.exe
TCP: {A15B0A41-FCA2-4317-ADB5-AC68E5BBA9F8} = 194.204.159.1 217.98.63.164
FF - ProfilePath - c:\documents and settings\bata\Dane aplikacji\Mozilla\Firefox\Profiles\owcovtjp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.1stpage.pl/
FF - plugin: c:\program files\Java\j2re1.4.0_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.0_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.0_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.0_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.0_03\bin\NPJPI140_03.dll
FF - plugin: c:\program files\Java\j2re1.4.0_03\bin\NPOJI610.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava11.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava12.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJPI140_03.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPOJI610.dll
---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-29 15:17
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(996)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
- - - - - - - > 'lsass.exe'(1068)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
- - - - - - - > 'explorer.exe'(2920)
c:\windows\system32\SHDOCVW.dll
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\stobject.dll
- - - - - - - > 'csrss.exe'(840)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWare2Guard.exe
c:\progra~1\NEOSTR~1\CnxMon.exe
c:\progra~1\NEOSTR~1\TaskBarIcon.exe
c:\windows\RTHDCPL.exe
c:\documents and settings\bata\Moje dokumenty\Downloads\Remove.Restrictions.Tool.v4.8.0.1[r0uter]\RRT.exe
c:\docume~1\bata\USTAWI~1\Temp\RtkBtMnt.exe
.
**************************************************************************
.
Czas ukończenia: 2009-04-29 15:20 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-04-29 13:20
Przed: 28 712 210 432 bajtów wolnych
Po: 28 552 708 096 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
354 --- E O F --- 2009-04-20 21:39
oto moj log prosze o pomoc...
