((((((((((((((((((((((((( Pliki utworzone od 2008-08-19 do 2008-09-19 )))))))))))))))))))))))))))))))
.
2008-09-19 10:41 . 2008-09-19 10:51 <DIR> d----c--- C:\Program Files\Deutsch Translator 2
2008-09-17 11:13 . 2008-09-17 11:13 754 --a--c--- C:\WINDOWS\WORDPAD.INI
2008-09-16 22:51 . 2008-05-09 12:56 512,000 -----c--- C:\WINDOWS\system32\dllcache\jscript.dll
2008-09-16 22:51 . 2008-05-09 12:56 430,080 -----c--- C:\WINDOWS\system32\dllcache\vbscript.dll
2008-09-16 22:51 . 2008-05-09 12:56 180,224 -----c--- C:\WINDOWS\system32\dllcache\scrobj.dll
2008-09-16 22:51 . 2008-05-09 12:56 172,032 -----c--- C:\WINDOWS\system32\dllcache\scrrun.dll
2008-09-16 22:51 . 2008-05-08 13:24 155,648 -----c--- C:\WINDOWS\system32\dllcache\wscript.exe
2008-09-16 22:51 . 2008-05-10 01:26 135,168 -----c--- C:\WINDOWS\system32\dllcache\wshom.ocx
2008-09-16 22:51 . 2008-05-07 11:07 135,168 -----c--- C:\WINDOWS\system32\dllcache\cscript.exe
2008-09-16 22:51 . 2008-05-09 12:56 90,112 -----c--- C:\WINDOWS\system32\dllcache\wshext.dll
2008-09-15 22:02 . 2008-09-15 22:06 151 --a--c--- C:\WINDOWS\PhotoSnapViewer.INI
2008-09-15 08:49 . 2008-09-15 08:49 <DIR> d----c--- C:\Program Files\Alwil Software
2008-09-14 19:53 . 2008-09-14 19:53 <DIR> d----c--- C:\WINDOWS\system32\pl
2008-09-14 19:53 . 2008-09-14 19:53 <DIR> d----c--- C:\WINDOWS\system32\bits
2008-09-14 19:53 . 2008-09-14 19:53 <DIR> d----c--- C:\WINDOWS\l2schemas
2008-09-14 19:51 . 2008-09-14 19:51 <DIR> d----c--- C:\WINDOWS\ServicePackFiles
2008-09-14 17:52 . 2008-09-14 17:52 <DIR> d----c--- C:\Documents and Settings\WIESIEK DOROTA\Dane aplikacji\Media Player Classic
2008-09-14 17:51 . 2008-09-14 17:51 <DIR> d----c--- C:\Program Files\Recode Media
2008-09-14 17:37 . 2008-09-14 17:37 <DIR> d----c--- C:\Documents and Settings\WIESIEK DOROTA\Dane aplikacji\Ahead
2008-09-14 17:36 . 2008-09-14 19:25 116 --a--c--- C:\WINDOWS\NeroDigital.ini
2008-09-14 17:35 . 2005-04-20 13:32 2,916,352 -----c--- C:\WINDOWS\UNNMP.exe
2008-09-14 17:35 . 2006-03-22 13:55 47,867 -----c--- C:\WINDOWS\UNNMP.cfg
2008-09-14 17:33 . 2001-07-09 10:50 155,648 --a--c--- C:\WINDOWS\system32\NeroCheck.exe
2008-09-14 17:32 . 2008-09-14 17:32 <DIR> d----c--- C:\Program Files\Common Files\Nero
2008-09-14 17:31 . 2005-07-29 17:12 2,977,792 -----c--- C:\WINDOWS\UNNeroVision.exe
2008-09-14 17:31 . 2006-03-22 13:55 179,261 -----c--- C:\WINDOWS\UNNeroVision.cfg
2008-09-14 17:31 . 2001-03-08 18:30 24,064 -----c--- C:\WINDOWS\system32\msxml3a.dll
2008-09-14 17:30 . 2008-09-14 17:30 <DIR> d----c--- C:\Program Files\Common Files\Ahead
2008-09-14 17:30 . 2008-09-14 17:35 <DIR> d----c--- C:\Program Files\Ahead
2008-09-14 17:30 . 2008-09-14 17:30 <DIR> d----c--- C:\Documents and Settings\All Users\Dane aplikacji\Ahead
2008-09-14 17:30 . 2004-07-26 16:16 1,568,768 -----c--- C:\WINDOWS\system32\ImagX7.dll
2008-09-14 17:30 . 2004-07-26 16:16 476,320 -----c--- C:\WINDOWS\system32\ImagXpr7.dll
2008-09-14 17:30 . 2004-07-26 16:16 471,040 -----c--- C:\WINDOWS\system32\ImagXRA7.dll
2008-09-14 17:30 . 2004-07-09 08:43 364,544 -----c--- C:\WINDOWS\system32\TwnLib4.dll
2008-09-14 17:30 . 2004-07-26 16:16 262,144 -----c--- C:\WINDOWS\system32\ImagXR7.dll
2008-09-14 17:30 . 2000-06-26 10:45 106,496 --a--c--- C:\WINDOWS\system32\TwnLib20.dll
2008-09-14 17:30 . 2001-06-26 07:15 38,912 -----c--- C:\WINDOWS\system32\picn20.dll
2008-09-13 23:10 . 2008-09-13 23:10 <DIR> d----c--- C:\Program Files\Edgard
2008-09-13 22:06 . 2008-09-14 17:44 <DIR> d----c--- C:\Program Files\Windows Media Lite
2008-09-03 05:02 . 2004-08-03 22:41 1,041,536 -----c--- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-09-03 05:02 . 2004-08-03 22:41 685,056 -----c--- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2008-09-03 05:02 . 2004-08-03 22:41 220,032 -----c--- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2008-09-03 05:02 . 2004-07-17 22:55 129,045 -----c--- C:\WINDOWS\system32\drivers\cxthsfs2.cty
2008-09-03 05:02 . 2004-08-03 22:41 11,868 -----c--- C:\WINDOWS\system32\drivers\mdmxsdk.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-19 12:22 --------- dc----w C:\Documents and Settings\All Users\Dane aplikacji\SeekmoSA
2008-09-19 12:17 --------- dc----w C:\Documents and Settings\WIESIEK DOROTA\Dane aplikacji\Skype
2008-09-19 08:17 --------- dc----w C:\Documents and Settings\WIESIEK DOROTA\Dane aplikacji\skypePM
2008-09-19 06:36 --------- dc----w C:\Documents and Settings\WIESIEK DOROTA\Dane aplikacji\ShoppingReport
2008-09-17 08:20 --------- dc----w C:\Program Files\Common Files\Adobe
2008-09-10 12:29 --------- dc----w C:\Program Files\Winamp Remote
2008-08-21 23:26 --------- dc----w C:\Program Files\HP
2008-08-02 18:05 --------- dc----w C:\Documents and Settings\All Users\Dane aplikacji\OrbNetworks
2008-08-02 17:57 --------- dc----w C:\Program Files\Sun
2008-08-02 17:57 --------- dc----w C:\Program Files\Java
2008-07-21 21:39 --------- dc----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-02 68856]
"ccleaner"="D:\Program Files\CCleaner\CCleaner.exe" [2008-04-23 1189104]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 C:\WINDOWS\system32\HdAShCut.exe]
"MsmqIntCert"="mqrt.dll" [2008-04-14 C:\WINDOWS\system32\mqrt.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Usuä (Rozumienie ze suchu i Konwersacje DEMO).lnk - C:\Program Files\Edgard\Profesor Klaus 5.0 DEMO\unins000.exe [2001-07-13 72880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"D:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{27354c20-75ce-11dd-94c8-001404406c53}]
\Shell\AutoRun\command - H:\n1deiect.com
\Shell\explore\Command - H:\n1deiect.com
\Shell\open\Command - H:\n1deiect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e3b4d5c-3e14-11dd-9450-000000000000}]
\Shell\AutoRun\command - H:\n1deiect.com
\Shell\explore\Command - H:\n1deiect.com
\Shell\open\Command - H:\n1deiect.com
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\WIESIEK DOROTA\Dane aplikacji\Mozilla\Firefox\Profiles\ydmzjq38.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.onet.pl/FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npclntax_SeekmoSA.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-19 15:06:24
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\WINDOWS\system32\WgaTray.exe
C:\ComboFix\pv.cfexe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Czas ukończenia: 2008-09-19 15:08:09 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-09-19 13:08:05
Przed: 29,933,187,072 bajt˘w wolnych
Po: 30,048,735,232 bajt˘w wolnych
935 --- E O F --- 2008-09-17 00:15:13