
Prosze o sprawdzenie loga
HijackThis
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:57:17, on 2009-04-22
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\cFosSpeed\cFosSpeed.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\cFosSpeed\spd.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Opera\opera.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [cFosSpeed] C:\Program Files\cFosSpeed\cFosSpeed.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: cFosSpeed System Service (cFosSpeedS) - cFos Software GmbH - C:\Program Files\cFosSpeed\spd.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 4584 bytes
Combofix
- Kod: Zaznacz wszystko
ComboFix 09-04-22.A0 - Gruby 2009-04-22 10:59.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.2046.1449 [GMT 2:00]
Uruchomiony z: c:\documents and settings\Gruby\Pulpit\Logi\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\pthreadGC2.dll
.
((((((((((((((((((((((((( Pliki utworzone od 2009-03-22 do 2009-04-22 )))))))))))))))))))))))))))))))
.
2009-04-19 09:48 . 2009-04-19 09:48 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\nView_Profiles
2009-04-15 12:56 . 2009-04-15 12:56 -------- d-----w c:\documents and settings\Gruby\Ustawienia lokalne\Dane aplikacji\Ahead
2009-04-14 19:10 . 2009-04-14 19:10 21035 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-04-14 19:10 . 2006-11-15 14:23 38144 ----a-w c:\windows\system32\drivers\EAPPkt.sys
2009-04-14 18:53 . 2009-03-06 14:22 285696 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-14 18:53 . 2009-02-09 11:25 111104 -c----w c:\windows\system32\dllcache\services.exe
2009-04-14 18:53 . 2009-02-09 10:53 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-14 18:53 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-14 18:53 . 2009-02-09 10:53 731136 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-14 18:53 . 2009-02-09 10:53 686592 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-14 18:53 . 2009-02-09 10:53 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-14 18:53 . 2009-02-09 10:53 722944 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-14 18:53 . 2009-02-09 10:53 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-14 18:51 . 2009-03-27 06:58 1203922 -c----w c:\windows\system32\dllcache\sysmain.sdb
2009-04-14 18:51 . 2008-04-21 21:16 218112 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 08:25 . 2009-04-14 08:25 2422 ----a-w c:\windows\system32\wpa.bak
2009-04-11 10:30 . 2009-04-11 10:30 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Nokia
2009-04-11 10:30 . 2008-02-01 13:17 8320 ----a-w c:\windows\system32\drivers\nmwcdnsuc.sys
2009-04-11 10:30 . 2008-02-01 13:17 138112 ----a-w c:\windows\system32\drivers\nmwcdnsu.sys
2009-04-10 15:55 . 2008-04-13 22:15 26368 -c--a-w c:\windows\system32\dllcache\usbstor.sys
2009-04-10 08:48 . 2009-04-10 08:53 -------- d-----w C:\RECYCLER(2)
2009-04-07 09:05 . 2009-04-07 09:05 -------- d-----w c:\documents and settings\Gruby\Dane aplikacji\Gadu-Gadu
2009-04-06 09:20 . 2009-04-06 12:26 69 ----a-w c:\windows\NeroDigital.ini
2009-04-05 15:28 . 2009-04-05 15:28 -------- d-----w c:\documents and settings\Gruby\Dane aplikacji\AdobeUM
2009-04-05 15:28 . 2009-04-05 15:28 -------- d-----w c:\documents and settings\Gruby\Ustawienia lokalne\Dane aplikacji\Adobe
2009-04-05 15:27 . 2009-04-05 15:27 -------- d-----w c:\windows\Cache
2009-04-05 10:49 . 2009-04-05 10:49 -------- d-----w c:\documents and settings\Gruby\Dane aplikacji\NCH Swift Sound
2009-04-05 10:49 . 2009-04-05 10:49 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\NCH Swift Sound
2009-04-05 10:42 . 2008-04-13 22:15 26112 -c--a-w c:\windows\system32\dllcache\usbser.sys
2009-04-05 10:42 . 2008-04-13 22:15 26112 ----a-w c:\windows\system32\drivers\usbser.sys
2009-04-05 10:42 . 2009-04-05 10:42 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-04-05 10:42 . 2009-04-05 10:42 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-04-05 10:42 . 2008-03-21 11:57 14640 ------w c:\windows\system32\spmsgXP_2k3.dll
2009-04-05 10:41 . 2009-04-11 10:10 -------- d-----w c:\documents and settings\Gruby\Dane aplikacji\Nokia
2009-04-05 10:41 . 2009-04-14 10:59 -------- d-----w c:\documents and settings\Gruby\Dane aplikacji\PC Suite
2009-04-05 10:41 . 2009-04-05 10:41 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\PC Suite
2009-04-05 10:40 . 2008-08-26 07:26 18816 ----a-w c:\windows\system32\drivers\pccsmcfd.sys
2009-04-05 10:40 . 2008-09-15 05:56 8064 ----a-w c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-04-05 10:40 . 2008-09-15 05:56 8064 ----a-w c:\windows\system32\drivers\usbser_lowerflt.sys
2009-04-05 10:40 . 2008-09-15 05:56 22016 ----a-w c:\windows\system32\drivers\ccdcmbo.sys
2009-04-05 10:40 . 2009-04-11 10:30 -------- dc----w c:\windows\system32\DRVSTORE
2009-04-05 10:40 . 2008-09-15 05:56 659968 ----a-w c:\windows\system32\nmwcdcocls.dll
2009-04-05 10:40 . 2008-09-15 05:56 17664 ----a-w c:\windows\system32\drivers\ccdcmb.sys
2009-04-05 10:40 . 2008-09-15 05:29 1112288 ----a-w c:\windows\system32\wdfcoinstaller01007.dll
2009-04-05 10:40 . 2008-02-01 13:17 90624 ----a-w c:\windows\system32\nmwcdcls.dll
2009-04-05 10:36 . 2009-04-11 10:30 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Installations
2009-04-03 11:38 . 2009-04-03 11:38 -------- d-----w c:\documents and settings\Gruby\Dane aplikacji\DAEMON Tools Pro
2009-04-03 11:38 . 2009-04-03 11:38 -------- d-----w c:\documents and settings\Gruby\Dane aplikacji\DAEMON Tools
2009-04-03 11:38 . 2009-04-03 11:38 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\DAEMON Tools Lite
2009-04-03 11:35 . 2009-04-03 11:35 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-04-03 11:35 . 2009-04-03 11:39 -------- d-----w c:\documents and settings\Gruby\Dane aplikacji\DAEMON Tools Lite
2009-03-30 08:55 . 2008-05-08 14:02 203136 -c----w c:\windows\system32\dllcache\rmcast.sys
2009-03-30 07:10 . 2009-04-22 08:49 -------- d--h--w C:\$AVG8.VAULT$
2009-03-29 22:09 . 2008-06-14 17:36 273024 -c----w c:\windows\system32\dllcache\bthport.sys
2009-03-29 22:08 . 2009-02-10 17:09 2067328 -c----w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-29 22:08 . 2009-02-09 11:26 2025472 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-29 22:08 . 2009-02-09 11:26 2146816 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-29 22:08 . 2009-02-09 11:26 2190336 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-29 22:08 . 2008-10-24 11:21 455296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-03-29 22:08 . 2008-12-11 10:57 333952 -c----w c:\windows\system32\dllcache\srv.sys
2009-03-29 22:08 . 2008-05-01 14:37 331776 -c----w c:\windows\system32\dllcache\msadce.dll
2009-03-29 22:08 . 2008-04-11 19:06 691712 -c----w c:\windows\system32\dllcache\inetcomm.dll
2009-03-29 22:08 . 2008-09-04 17:17 1106944 -c----w c:\windows\system32\dllcache\msxml3.dll
2009-03-29 22:05 . 2008-12-05 06:57 144896 -c----w c:\windows\system32\dllcache\schannel.dll
2009-03-29 22:05 . 2009-02-20 08:12 668672 -c----w c:\windows\system32\dllcache\wininet.dll
2009-03-29 22:05 . 2009-03-02 23:11 1499136 -c----w c:\windows\system32\dllcache\shdocvw.dll
2009-03-29 22:05 . 2009-02-20 08:12 619520 -c----w c:\windows\system32\dllcache\urlmon.dll
2009-03-29 22:05 . 2009-02-20 08:12 3089408 -c----w c:\windows\system32\dllcache\mshtml.dll
2009-03-29 17:42 . 2008-10-15 16:36 337408 -c----w c:\windows\system32\dllcache\netapi32.dll
2009-03-29 17:41 . 2009-03-29 17:41 584 ----a-w c:\windows\system32\settingsbkup.sfm
2009-03-29 17:41 . 2009-03-29 17:41 584 ----a-w c:\windows\system32\settings.sfm
2009-03-29 17:24 . 2008-04-14 20:50 32285 ------w c:\windows\system32\hsfcisp2.dll
2009-03-29 17:23 . 2009-03-29 17:23 -------- d-----w c:\windows\ServicePackFiles
2009-03-29 17:23 . 2008-04-14 20:51 294912 -c----w c:\windows\system32\dllcache\dlimport.exe
2009-03-29 17:20 . 2009-03-29 17:20 -------- d-----w c:\windows\EHome
2009-03-29 17:06 . 2009-03-05 10:16 967896 ----a-w c:\windows\system32\drivers\cfosspeed.sys
2009-03-29 17:06 . 2009-03-05 10:16 290008 ----a-w c:\windows\system32\cfosspeed.dll
2009-03-29 17:02 . 2009-03-29 17:02 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-03-29 17:02 . 2009-03-29 17:02 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-03-29 17:02 . 2009-03-29 17:02 325640 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-29 17:02 . 2009-04-22 07:33 -------- d-----w c:\windows\system32\drivers\Avg
2009-03-29 17:02 . 2009-03-29 17:02 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\avg8
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-22 08:59 . 2009-03-29 17:06 -------- d-----w c:\program files\cFosSpeed
2009-04-22 08:57 . 2009-04-22 08:57 -------- d-----w c:\program files\Trend Micro
2009-04-19 11:22 . 2009-04-19 11:22 -------- d-----w c:\program files\CCleaner
2009-04-19 09:48 . 2009-03-29 12:20 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-18 23:23 . 2009-04-18 23:23 271360 ----a-w c:\windows\system32\drivers\atksgt.sys
2009-04-18 23:23 . 2009-04-18 23:23 18048 ----a-w c:\windows\system32\drivers\lirsgt.sys
2009-04-18 23:23 . 2009-04-18 23:23 -------- d-----w c:\program files\AGEIA Technologies
2009-04-18 23:22 . 2009-04-18 23:22 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-14 19:07 . 2006-03-02 12:00 49712 ----a-w c:\windows\system32\perfc015.dat
2009-04-14 19:07 . 2006-03-02 12:00 355830 ----a-w c:\windows\system32\perfh015.dat
2009-04-13 14:54 . 2009-03-29 12:19 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-12 09:06 . 2009-04-12 09:06 -------- d-----w c:\program files\MSXML 4.0
2009-04-11 10:30 . 2009-04-05 10:40 -------- d-----w c:\program files\Nokia
2009-04-11 10:30 . 2009-04-05 10:40 -------- d-----w c:\program files\Common Files\Nokia
2009-04-11 10:30 . 2009-04-11 10:30 -------- d-----w c:\program files\MSXML 6.0
2009-04-10 08:53 . 2009-04-10 08:53 -------- d-----w c:\program files\UltraVNC
2009-04-10 08:53 . 2009-04-10 08:49 -------- d-----w c:\program files\UltraVNC(2)
2009-04-05 15:28 . 2009-04-05 15:28 -------- d-----w c:\program files\Common Files\Adobe
2009-04-05 15:26 . 2009-03-29 12:16 14656 ----a-w c:\windows\gdrv.sys
2009-04-05 10:55 . 2009-04-05 10:55 -------- d-----w c:\program files\NCH Software
2009-04-05 10:49 . 2009-04-05 10:49 -------- d-----w c:\program files\NCH Swift Sound
2009-04-05 10:41 . 2009-04-05 10:41 -------- d-----w c:\program files\Common Files\PCSuite
2009-04-05 10:40 . 2009-04-05 10:40 -------- d-----w c:\program files\DIFX
2009-04-05 10:40 . 2009-04-05 10:40 -------- d-----w c:\program files\PC Connectivity Solution
2009-04-04 07:14 . 2009-04-03 11:37 -------- d-----w c:\program files\DAEMON Tools Lite
2009-04-03 11:37 . 2009-04-03 11:37 -------- d-----w c:\program files\DAEMON Tools Toolbar
2009-03-31 21:45 . 2009-03-31 21:45 -------- d-----w c:\program files\IrfanView
2009-03-31 17:56 . 2009-03-31 17:55 -------- d-----w c:\program files\NAPI-PROJEKT
2009-03-29 17:26 . 2009-03-29 11:47 76487 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-29 17:21 . 2006-03-02 12:00 251152 --sha-r C:\ntldr
2009-03-29 17:02 . 2009-03-29 17:02 -------- d-----w c:\program files\AVG
2009-03-29 13:27 . 2009-03-29 13:22 -------- d-----w c:\program files\Winamp
2009-03-29 13:19 . 2009-03-29 13:19 -------- d-----w c:\program files\Real Alternative
2009-03-29 13:18 . 2009-03-29 13:18 155648 ----a-w c:\windows\system32\libssl32.dll
2009-03-29 13:07 . 2009-03-29 13:05 -------- d-----w c:\program files\Creative
2009-03-29 13:06 . 2009-03-29 13:06 86016 ----a-w c:\windows\system32\OpenAL32.dll
2009-03-29 13:06 . 2009-03-29 13:06 405504 ----a-w c:\windows\system32\wrap_oal.dll
2009-03-29 12:55 . 2009-03-29 12:52 -------- d-----w c:\program files\Gadu-Gadu
2009-03-29 12:51 . 2009-03-29 12:45 -------- d-----w c:\documents and settings\Gruby\Dane aplikacji\Nowe Gadu-Gadu
2009-02-20 08:12 . 2006-03-02 12:00 668672 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:11 . 2006-03-02 12:00 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-16 21:17 . 2009-03-29 12:36 453152 ----a-w c:\windows\system32\NVUNINST.EXE
2009-02-09 14:07 . 2006-03-02 12:00 1847040 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:26 . 2004-08-04 00:39 2025472 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:26 . 2006-03-02 12:00 2146816 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:25 . 2006-03-02 12:00 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:53 . 2006-03-02 12:00 731136 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2006-03-02 12:00 686592 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:53 . 2006-03-02 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:53 . 2006-03-02 12:00 722944 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 10:39 . 2006-03-02 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:58 . 2006-03-02 12:00 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-31 36864]
"36X Raid Configurer"="c:\windows\system32\JMRaidSetup.exe" [2006-11-17 1953792]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2004-12-20 33792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-29 1932568]
"cFosSpeed"="c:\program files\cFosSpeed\cFosSpeed.exe" [2009-03-05 876760]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376]
"P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2006-03-17 81408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-29 17:02 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2008-02-01 138112]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2008-02-01 8320]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-29 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-03-29 108552]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-03-29 908056]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-29 298264]
S2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [2006-11-15 38144]
S3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [2006-03-20 1452032]
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-22 11:00
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2009-04-22 11:01
ComboFix-quarantined-files.txt 2009-04-22 09:01
ComboFix2.txt 2009-04-10 08:45
Przed: 13 285 093 376 bajtów wolnych
Po: 13 276 622 848 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
223 --- E O F --- 2009-04-14 18:57