
Combofix
- Kod: Zaznacz wszystko
ComboFix 08-12-28.03 - User 2008-12-29 14:03:41.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.2047.1472 [GMT 1:00]
Uruchomiony z: c:\documents and settings\User\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\fnpnmgjs.dll
c:\windows\system32\iysgto.dll
c:\windows\system32\khfCvUkI.dll
c:\windows\system32\mlJAtTmN.dll
c:\windows\system32\NmTtAJlm.ini
c:\windows\system32\NmTtAJlm.ini2
c:\windows\system32\sjgmnpnf.ini
c:\windows\system32\woqkquun.dll
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-28 do 2008-12-29 )))))))))))))))))))))))))))))))
.
2008-12-26 22:52 . 2008-12-29 00:42 <DIR> d-------- c:\documents and settings\User\Dane aplikacji\GanymedeNet
2008-12-26 22:51 . 2008-12-26 22:51 <DIR> d-------- c:\program files\Ganymede
2008-12-24 15:16 . 2005-06-23 13:56 48,384 --------- c:\windows\system32\drivers\ser2pl.sys
2008-12-24 15:14 . 2008-12-24 15:14 <DIR> d-------- c:\program files\PC Connectivity Solution
2008-12-24 15:14 . 2008-12-24 15:14 <DIR> d-------- c:\program files\Common Files\PCSuite
2008-12-24 15:14 . 2008-12-24 15:14 <DIR> d-------- c:\program files\Common Files\Nokia
2008-12-24 15:14 . 2008-08-26 09:26 18,816 --a------ c:\windows\system32\drivers\pccsmcfd.sys
2008-12-22 11:23 . 2008-12-22 11:24 <DIR> d-------- c:\program files\A4Tech
2008-12-22 11:19 . 2001-10-26 14:57 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-12-22 11:19 . 2001-10-26 14:57 12,160 --a------ c:\windows\system32\dllcache\mouhid.sys
2008-12-20 14:44 . 2008-12-20 14:51 <DIR> d-------- c:\program files\AAPDA
2008-12-20 14:44 . 2001-04-05 19:43 1,009,336 --a------ c:\windows\system32\mschrt20.ocx
2008-12-20 14:44 . 2004-08-04 09:56 741,376 --a------ c:\windows\system32\sapi.dll
2008-12-20 14:44 . 1998-04-24 03:00 368,912 --a------ c:\windows\system32\vbar332.dll
2008-12-20 14:44 . 2003-03-03 16:29 258,048 --a------ c:\windows\system32\ctList.ocx
2008-12-20 14:44 . 2000-05-22 17:58 244,416 --a------ c:\windows\system32\MsFlxGrd.ocx
2008-12-20 14:44 . 2008-03-31 21:20 166,400 --a------ c:\windows\system32\mschrt20.oca
2008-12-20 14:44 . 2001-03-13 14:49 140,288 --a------ c:\windows\system32\COMDLG32.OCX
2008-12-20 14:44 . 2003-07-31 18:59 97,792 --a------ c:\windows\system32\TSRemote.dll
2008-12-20 14:44 . 1998-06-26 02:00 2,496 --a------ c:\windows\system32\Mschrt20.dep
2008-12-20 14:44 . 1998-06-03 02:00 111 --a------ c:\windows\system32\Mschrt20.srg
2008-12-18 14:11 . 2008-12-25 01:35 <DIR> d-------- c:\documents and settings\User\Dane aplikacji\temp
2008-12-11 21:37 . 2008-12-11 21:37 42,320 --a------ c:\windows\system32\xfcodec.dll
2008-12-10 18:21 . 2008-12-10 18:21 <DIR> d-------- c:\windows\system32\xircom
2008-12-10 18:21 . 2008-12-10 18:21 <DIR> d-------- c:\windows\system32\oobe
2008-12-10 18:21 . 2008-12-10 18:21 <DIR> d-------- c:\windows\srchasst
2008-12-10 18:21 . 2008-12-10 18:21 <DIR> d-------- c:\windows\msagent
2008-12-10 18:21 . 2008-12-10 18:21 <DIR> d-------- c:\program files\microsoft frontpage
2008-12-10 18:02 . 2008-12-10 18:02 <DIR> d-------- c:\program files\Nvidia Omega Drivers
2008-12-07 19:10 . 2004-03-22 14:17 24,816 --a------ c:\windows\system32\mdimon.dll
2008-12-07 19:10 . 2008-12-07 19:10 421 --a------ c:\windows\ODBC.INI
2008-12-07 19:07 . 2008-12-07 19:07 <DIR> d-------- c:\program files\Microsoft Works
2008-12-07 19:06 . 2008-12-07 19:06 <DIR> d-------- c:\windows\SHELLNEW
2008-12-07 19:06 . 2008-12-07 19:06 <DIR> d-------- c:\program files\Microsoft.NET
2008-12-05 23:32 . 2008-12-05 23:32 546,304 --a------ c:\windows\system32\hhctrl.ocx
2008-12-05 23:29 . 2008-12-05 23:29 <DIR> d-------- c:\program files\Emapa
2008-12-05 23:27 . 2008-12-05 23:27 <DIR> d-------- c:\program files\Cartall
2008-12-05 23:27 . 2008-12-05 23:27 <DIR> d-------- c:\program files\Borland
2008-12-05 23:27 . 2008-12-05 23:27 <DIR> d-------- c:\documents and settings\User\WINDOWS
2008-12-05 23:27 . 1999-03-23 10:12 299,520 --a------ c:\windows\uninst.exe
2008-12-05 23:22 . 2008-12-05 23:22 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\LightScribe
2008-11-30 19:02 . 2008-11-30 19:02 <DIR> d-------- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 13:12 --------- d-----w c:\program files\cFosSpeed
2008-12-28 23:29 --------- d-----w c:\documents and settings\User\Dane aplikacji\AIMP
2008-12-28 20:55 202,352 ----a-w c:\windows\system32\PnkBstrB.exe
2008-12-28 20:55 138,624 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-12-28 13:28 --------- d-----w c:\documents and settings\User\Dane aplikacji\teamspeak2
2008-12-28 00:43 --------- d-----w c:\documents and settings\User\Dane aplikacji\Xfire
2008-12-24 14:16 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-24 14:14 --------- d-----w c:\program files\Nokia
2008-12-24 14:13 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Installations
2008-12-24 00:27 --------- d-----w c:\program files\America's Army
2008-12-18 11:28 --------- d-----w c:\program files\Real Alternative
2008-12-14 11:51 --------- d-----w c:\documents and settings\User\Dane aplikacji\mIRC
2008-12-12 17:01 --------- d-----w c:\program files\AviSynth 2.5
2008-12-12 17:01 --------- d-----w c:\program files\Avi2Dvd
2008-12-12 17:00 --------- d-----w c:\program files\OpenOffice.org 2.4
2008-12-12 16:42 --------- d-----w c:\program files\Gabest
2008-12-10 17:02 472,576 ----a-w c:\windows\Nvidia Omega Drivers v2.169.21 Uninstall.exe
2008-12-07 01:04 --------- d-----w c:\documents and settings\User\Dane aplikacji\OpenOffice.org2
2008-12-05 22:22 --------- d-----w c:\documents and settings\User\Dane aplikacji\Ahead
2008-11-22 18:45 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-22 18:45 --------- d-----w c:\program files\AGEIA Technologies
2008-11-22 13:17 --------- d-----w c:\program files\AA Watcher
2008-11-22 11:41 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Skype
2008-11-20 18:57 --------- d-----w c:\program files\Alcohol Soft
2008-11-20 18:10 --------- d-----w c:\program files\Open Office
2008-11-20 15:23 --------- d-----w c:\program files\Xvid
2008-11-20 13:49 --------- d-----w c:\program files\Common Files\LightScribe
2008-11-20 13:49 --------- d-----w c:\program files\Common Files\Ahead
2008-11-20 13:46 --------- d-----w c:\program files\Nero
2008-11-20 13:46 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Nero
2008-11-19 21:50 --------- d-----w c:\documents and settings\User\Dane aplikacji\Media Player Classic
2008-11-18 13:50 --------- d-----w c:\documents and settings\User\Dane aplikacji\skypePM
2008-11-17 22:01 --------- d-----w c:\program files\Headshot Player
2008-11-17 16:57 --------- d-----w c:\program files\America's Army Deploy Client
2008-11-15 14:15 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\America's Army Deploy Client
2008-11-11 19:04 --------- d-----w c:\program files\SopCast
2008-11-11 18:57 --------- d--h--w c:\documents and settings\All Users\Dane aplikacji\CanonBJ
2008-11-11 13:26 22,328 ----a-w c:\documents and settings\User\Dane aplikacji\PnkBstrK.sys
2008-11-11 13:26 2,250,024 ----a-w c:\windows\system32\pbsvc.exe
2008-11-08 21:14 --------- d-----w c:\program files\NAPI-PROJEKT
2008-11-08 17:15 --------- d-----w c:\documents and settings\User\Dane aplikacji\Talkback
2008-11-08 11:49 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2008-11-08 11:13 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-07 21:10 --------- d-----w c:\documents and settings\LocalService\Dane aplikacji\Xfire
2008-11-07 21:09 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-07 19:49 --------- d-----w c:\documents and settings\User\Dane aplikacji\FastStone
2008-11-07 19:05 --------- d-----w c:\documents and settings\NetworkService\Dane aplikacji\Xfire
2008-11-07 18:59 --------- d-----w c:\documents and settings\User\Dane aplikacji\PC Suite
2008-11-07 18:59 --------- d-----w c:\documents and settings\User\Dane aplikacji\Nokia
2008-11-07 18:59 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\PC Suite
2008-11-07 18:57 --------- d-----w c:\program files\DIFX
2008-11-07 17:00 --------- d-----w c:\documents and settings\User\Dane aplikacji\Leadertech
2008-11-07 16:43 --------- d-----w c:\program files\DAEMON Tools Toolbar
2008-11-07 16:40 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2008-11-07 16:40 --------- d-----w c:\documents and settings\User\Dane aplikacji\DAEMON Tools
2008-11-07 16:32 --------- d-----w c:\program files\Foxit Software
2008-11-07 16:31 410,976 ----a-w c:\windows\system32\deploytk.dll
2008-11-07 16:31 --------- d-----w c:\program files\Java
2008-11-07 16:24 --------- d-----w c:\documents and settings\User\Dane aplikacji\Winamp
2008-11-07 16:03 --------- d-----w c:\program files\Analog Devices
2008-11-07 16:02 --------- d-----w c:\documents and settings\User\Dane aplikacji\Gadu-Gadu
2008-11-07 15:47 --------- d-----w c:\documents and settings\User\Dane aplikacji\Thunderbird
2008-11-07 15:40 --------- d-----w c:\program files\Thomson
2008-11-07 15:33 --------- d-----w c:\program files\Agnitum
2008-11-07 15:33 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Agnitum
2008-11-07 15:31 --------- d-----w c:\program files\ESET
2008-11-07 15:31 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\ESET
2008-11-07 15:21 --------- d-----w c:\program files\Realtek
2008-11-07 15:21 --------- d-----w c:\documents and settings\User\Dane aplikacji\InstallShield
2008-11-07 15:18 --------- d-----w c:\program files\Intel
2008-11-07 15:06 --------- d-----w c:\program files\Usługi online
2008-11-07 15:04 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-27 09:04 70,992 ----a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 09:04 514,384 ----a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 09:04 235,856 ----a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 09:04 23,376 ----a-w c:\windows\system32\X3DAudio1_5.dll
2008-10-10 03:52 452,440 ----a-w c:\windows\system32\d3dx10_40.dll
2008-10-10 03:52 4,379,984 ----a-w c:\windows\system32\D3DX9_40.dll
2008-10-10 03:52 2,036,576 ----a-w c:\windows\system32\D3DCompiler_40.dll
.
------- Sigcheck -------
2007-07-10 18:06 642560 ce594e18fe0d0af804f1f3694921ce62 c:\windows\system32\user32.dll
2008-06-16 02:28 361344 030dc4d48cc2b894fee2f390d8e66ad5 c:\windows\system32\drivers\tcpip.sys
2008-06-16 02:28 549888 335813eacd16e84f3047a3326f6e5473 c:\windows\system32\winlogon.exe
2008-07-07 22:43 2032128 2bc05e243b86aa8e569ee3c5d8b3c424 c:\windows\system32\ntkrnlpa.exe
2008-07-06 22:44 2153472 04404b7f25984558ad3390bf84c4eb95 c:\windows\system32\ntoskrnl.exe
2008-06-27 04:36 1424896 4ec7ed41d95d18b3cd1a2bd9dfefb591 c:\windows\explorer.exe
2001-02-20 12:09 8192 d36a33c21eeed5a6c1daecb7c80a1909 c:\windows\system32\CTFMON.EXE
2008-06-16 02:28 112128 37ed43f3dec4400586554d61c3129478 c:\windows\system32\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="d:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"AutoConnect"="d:\program files\AutoConnect\AutoConnect.exe" [2006-12-03 310784]
"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-01 222592]
"ctfmon.exe"="ctfmon.exe" [2001-02-20 c:\windows\system32\CTFMON.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-09-16 1447168]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2008-07-15 883528]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall Pro\feedback.exe" [2008-08-05 435528]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"cFosSpeed"="c:\program files\cFosSpeed\cFosSpeed.exe" [2008-07-18 867544]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2007-05-15 204800]
"nwiz"="nwiz.exe" [2007-12-05 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2008-06-16 c:\windows\system32\advpack.dll]
c:\documents and settings\User\Menu Start\Programy\Autostart\
Xfire.lnk - d:\program files\Xfire\xfire.exe [2008-12-11 2990416]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=iysgto.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^User^Menu Start^Programy^Autostart^cFos Speed Updater.exe]
path=c:\documents and settings\User\Menu Start\Programy\Autostart\cFos Speed Updater.exe
backup=c:\windows\pss\cFos Speed Updater.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^User^Menu Start^Programy^Autostart^lsass.exe]
path=c:\documents and settings\User\Menu Start\Programy\Autostart\lsass.exe
backup=c:\windows\pss\lsass.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-12-23 18:05 143360 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a--c--- 2008-07-24 16:02 490952 d:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
--a------ 2008-11-10 15:07 1253376 c:\program files\Nokia\Nokia PC Suite 7\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 06:41 8523776 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 06:41 81920 c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 2008-12-03 12:47 1205760 c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--------- 2006-07-13 07:12 729088 c:\program files\Analog Devices\SoundMAX\SMax4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
--a------ 2004-01-26 11:38 866816 c:\program files\Thomson\SpeedTouch USB\dragdiag.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-11-07 17:31 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 06:41 1626112 c:\windows\system32\nwiz.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Pro.Evolution.Soccer.2009.Full-Rip.Skullptura\\PES 2009\\pes2009.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-08-18 34312]
R1 SandBox;SandBox;c:\windows\system32\DRIVERS\SandBox.sys [2008-11-07 673920]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [2008-11-07 390984]
R2 ekrn;Eset Service;"c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe" [2008-09-17 468224]
R3 afw;Agnitum firewall driver;c:\windows\system32\DRIVERS\afw.sys [2008-11-07 30864]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2008-11-07 234640]
R3 MouseCap;MouseCapture Driver;c:\windows\system32\Drivers\MouseCap.sys [2005-08-08 6640]
S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [2008-11-07 33408]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
BHO-{0f38b0d6-0fc3-4d5c-ad7a-004bcf28bc9d} - c:\windows\system32\iysgto.dll
BHO-{AE1A2884-8566-4826-B658-F0D89EE5A580} - c:\windows\system32\mlJAtTmN.dll
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.google.pl/
uInternet Connection Wizard,ShellNext = hxxp://www.wp.pl/
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: {C1186FF4-247D-437D-9679-7C10421FC398} = 194.204.159.1 217.98.63.164
FF - ProfilePath - c:\documents and settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\xwy82qvo.default\
FF - prefs.js: browser.startup.homepage - hxxp://wp.pl/
FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - plugin: c:\program files (x86)\Real Alternative\browser\plugins\nppl3260.dll
FF - plugin: c:\program files (x86)\Real Alternative\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npitunes.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npmozax.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 14:11:55
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\sfc_os.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(856)
c:\windows\system32\scecli.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\cFosSpeed\spd.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\rundll32.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Czas ukończenia: 2008-12-29 14:13:50 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-12-29 13:13:46
ComboFix2.txt 2008-12-10 17:24:33
Przed: 1 861 529 600 bajtów wolnych
Po: 1,922,371,584 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
310
HJT
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:16:19, on 2008-12-29
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\cFosSpeed\spd.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\cFosSpeed\cFosSpeed.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Program Files\Gadu-Gadu\gg.exe
D:\Program Files\AutoConnect\AutoConnect.exe
D:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
D:\Program Files\Xfire\xfire.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wp.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [OutpostFeedBack] "C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe" /dump:os_startup
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [cFosSpeed] C:\Program Files\cFosSpeed\cFosSpeed.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "D:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [AutoConnect] D:\Program Files\AutoConnect\AutoConnect.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O4 - Startup: Xfire.lnk = D:\Program Files\Xfire\xfire.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ustawienia Outpost Firewall Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall Pro\ie_bar.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1186FF4-247D-437D-9679-7C10421FC398}: NameServer = 194.204.159.1 217.98.63.164
O20 - AppInit_DLLs: iysgto.dll
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Usługa bramy warstwy aplikacji (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: cFosSpeed System Service (cFosSpeedS) - cFos Software GmbH - C:\Program Files\cFosSpeed\spd.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA-OMEGA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 6399 bytes