UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.1.18) Gecko/20081029 Firefox/2.0.0.18
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.1.18) Gecko/20081029 Firefox/2.0.0.18
ComboFix 08-11-13.01 - Czarek 2008-11-15 14:34:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1250.1.1045.18.129 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Czarek\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2008-10-15 do 2008-11-15 )))))))))))))))))))))))))))))))
.
2008-11-15 13:48 . 2008-11-15 13:48 <DIR> d-------- c:\windows\OPTIONS
2008-11-15 13:48 . 2001-10-26 16:47 36,224 --a------ c:\windows\system32\drivers\isapnp.sys
2008-11-15 13:48 . 2001-10-26 16:47 36,224 --a--c--- c:\windows\system32\dllcache\isapnp.sys
2008-11-15 13:48 . 2001-08-23 21:03 25,434 --a------ c:\windows\system32\drivers\RTL8139.sys
2008-11-15 13:48 . 2001-08-23 21:03 25,434 --a--c--- c:\windows\system32\dllcache\rtl8139.sys
2008-11-15 13:48 . 2001-10-18 13:00 6,144 -ra------ c:\windows\system32\drivers\viaidexp.sys
2008-11-15 13:47 . 2008-11-15 13:47 <DIR> d-------- c:\documents and settings\Czarek\WINDOWS
2008-11-15 13:47 . 2001-12-05 16:36 306,688 --a------ c:\windows\IsUninst.exe
2008-11-15 13:47 . 2001-12-18 15:45 3,279 --a------ c:\windows\system32\drivers\VIAPFD.SYS
2008-11-15 12:52 . 2008-11-15 12:53 <DIR> d-------- c:\documents and settings\Czarek\Dane aplikacji\Winamp
2008-11-15 11:28 . 2008-11-15 11:29 <DIR> d-------- c:\program files\Winamp
2008-11-15 11:28 . 2008-11-15 11:29 <DIR> d-------- c:\documents and settings\Iza\Dane aplikacji\Winamp
2008-11-15 11:28 . 2007-03-08 00:51 129,784 --------- c:\windows\system32\pxafs.dll
2008-11-15 11:28 . 2007-03-08 00:51 43,528 --------- c:\windows\system32\drivers\PxHelp20.sys
2008-11-15 11:28 . 2007-03-08 00:51 9,464 --------- c:\windows\system32\drivers\cdralw2k.sys
2008-11-15 11:28 . 2007-03-08 00:51 9,336 --------- c:\windows\system32\drivers\cdr4_xp.sys
2008-11-15 11:27 . 2008-11-15 11:27 <DIR> d-------- c:\documents and settings\Czarek\Dane aplikacji\Gadu-Gadu
2008-11-15 11:02 . 2008-11-15 11:02 <DIR> d-------- c:\program files\KaraFun
2008-11-15 11:02 . 2008-11-15 11:02 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Recisio
2008-11-14 20:40 . 2008-11-14 21:05 <DIR> d---s---- C:\Muzyka
2008-11-14 20:11 . 2003-03-18 21:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2008-11-14 20:11 . 2003-03-18 20:14 499,712 --a------ c:\windows\system32\MSVCP71.dll
2008-11-14 20:10 . 2008-11-14 20:10 <DIR> d-------- c:\program files\Alwil Software
2008-11-14 19:30 . 2008-11-15 13:30 <DIR> d-------- c:\program files\Valve
2008-11-14 18:20 . 2000-06-26 07:45 1,134,864 --a------ c:\windows\system\WMVCORE.DLL
2008-11-14 18:18 . 2004-11-18 10:42 22,752 --a------ c:\windows\system32\spupdsvc.exe
2008-11-14 17:56 . 2000-06-26 07:45 1,134,864 --a------ c:\windows\WMVCORE.DLL
2008-11-14 08:26 . 2008-11-14 08:26 <DIR> d-------- c:\documents and settings\Iza\Dane aplikacji\Gadu-Gadu
2008-11-14 08:05 . 2008-11-14 08:06 <DIR> d-------- c:\documents and settings\Iza\Gadu-Gadu
2008-11-13 19:10 . 2008-11-13 19:10 <DIR> d-------- c:\program files\Karasoft
2008-11-13 17:42 . 2008-11-15 14:35 <DIR> d--h----- c:\documents and settings\Iza\Ustawienia lokalne
2008-11-13 17:42 . 2008-11-14 08:05 <DIR> dr------- c:\documents and settings\Iza\Ulubione
2008-11-13 17:42 . 2008-11-13 13:57 <DIR> d--h----- c:\documents and settings\Iza\Szablony
2008-11-13 17:42 . 2008-11-15 11:28 <DIR> d-------- c:\documents and settings\Iza\Pulpit
2008-11-13 17:42 . 2008-11-14 08:05 <DIR> dr------- c:\documents and settings\Iza\Moje dokumenty
2008-11-13 17:42 . 2008-11-13 13:35 <DIR> dr------- c:\documents and settings\Iza\Menu Start
2008-11-13 17:42 . 2008-11-15 11:28 <DIR> dr-h----- c:\documents and settings\Iza\Dane aplikacji
2008-11-13 17:42 . 2008-11-14 08:05 <DIR> d-------- c:\documents and settings\Iza
2008-11-13 15:14 . 2008-11-13 15:14 <DIR> d---s---- c:\windows\system32\Microsoft
2008-11-13 15:12 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2008-11-13 15:11 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
2008-11-13 15:08 . 2008-11-13 15:08 <DIR> d-------- c:\windows\Logs
2008-11-13 15:08 . 2008-11-13 15:08 41 --a------ c:\windows\winampa.ini
2008-11-13 15:07 . 2008-11-13 15:07 <DIR> d-------- C:\DirectX
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-15 12:48 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-14 18:29 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-13 13:33 --------- d-----w c:\program files\AvRack
2008-11-13 13:33 --------- d-----w c:\program files\Avance Sound Manager
2008-11-13 13:31 98,304 ----a-w c:\windows\system32\qttask.exe
2008-11-13 13:30 --------- d-----w c:\program files\ACE Mega CoDecS Pack
2008-11-13 13:15 --------- d-----w c:\program files\Gadu-Gadu
2008-11-13 13:02 --------- d-----w c:\program files\microsoft frontpage
2008-11-13 13:01 558,142 ----a-w c:\windows\java\Packages\6L7JDBZ7.ZIP
2008-11-13 13:01 155,995 ----a-w c:\windows\java\Packages\TN3JX3BR.ZIP
2008-11-13 13:00 --------- d-----w c:\program files\Usługi online
2008-10-27 09:04 70,992 ----a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 09:04 514,384 ----a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 09:04 235,856 ----a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 09:04 23,376 ----a-w c:\windows\system32\X3DAudio1_5.dll
2008-10-27 08:48 80,896 ----a-w c:\windows\system32\dxdllreg.exe
2008-10-10 03:52 452,440 ----a-w c:\windows\system32\d3dx10_40.dll
2008-10-10 03:52 4,379,984 ----a-w c:\windows\system32\D3DX9_40.dll
2008-10-10 03:52 2,036,576 ----a-w c:\windows\system32\D3DCompiler_40.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\ctfmon.exe" [2002-09-28 13312]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2002-08-20 1511453]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2008-11-13 98304]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-09-12 36352]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-12 81000]
"SoundMan"="SOUNDMAN.EXE" [2002-02-05 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2002-09-28 13312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=NVDESK32.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.sl_anet"= c:\progra~1\ACEMEG~1\SystemS\sl_anet.acm
"vidc.yv12"= c:\progra~1\ACEMEG~1\SystemS\ATI\atiyuv12.DLL
"vidc.divx"= c:\progra~1\ACEMEG~1\SystemS\DivX\DivX520.dll
"vidc.iyuv"= c:\progra~1\ACEMEG~1\SystemS\Intel\iyuv_32.dll
"vidc.yvu9"= c:\progra~1\ACEMEG~1\SystemS\Intel\Iyvu9_32.dll
"vidc.uyvy"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yuy2"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yvyu"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"msacm.msaudio1"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msaud32.acm
"msacm.iac2"= c:\progra~1\ACEMEG~1\SystemS\Intel\iac25_32.ax
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2008-11-12 110160]
*Newly Created Service* - PROCEXP90
*Newly Created Service* - VIAPFD
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - c:\documents and settings\Czarek\Dane aplikacji\Mozilla\Firefox\Profiles\p2zxl493.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-15 14:35:58
Windows 5.1.2600 Dodatek Service Pack. 1 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-11-15 14:37:03
ComboFix-quarantined-files.txt 2008-11-15 13:36:55
Przed: 2 859 429 888 bajtów wolnych
Po: 3,244,736,512 bajtów wolnych
winxpsp1_pl_pro_bf.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect
134
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.1.18) Gecko/20081029 Firefox/2.0.0.18
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.1.18) Gecko/20081029 Firefox/2.0.0.18
Zarejestrowani użytkownicy: Google [Bot]