Logi niedawno miałem 3 trojany wykryte przez kasperskiego czy 2 mniejsza z tym.
Oto logi
Combo
ComboFix 08-07-17.4 - Murarz 2008-07-18 18:43:03.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1250.1.1045.18.1266 [GMT 2:00]
Running from: C:\Users\Murarz\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\cef\M9FFXTBR.JAR
C:\Program Files\myglobalsearch\bar\cef\M9FFXTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\cef\M9NTSTBR.JAR
C:\Program Files\myglobalsearch\bar\cef\M9NTSTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\cef\M9PLUGIN.DLL
C:\Program Files\myglobalsearch\bar\cef\MGSBAR.DLL
C:\Program Files\myglobalsearch\bar\History\search
C:\Windows\system32\X86
C:\Windows\system32\X86\License.rtf
C:\Windows\system32\X86\Readme.txt
C:\Windows\system32\X86\setup.exe
.
((((((((((((((((((((((((( Files Created from 2008-06-18 to 2008-07-18 )))))))))))))))))))))))))))))))
.
2008-07-18 06:47 . 2008-07-18 06:47 <DIR> d-------- C:\Users\All Users\ConeXware
2008-07-18 06:47 . 2008-07-18 06:47 <DIR> d-------- C:\ProgramData\ConeXware
2008-07-18 06:47 . 2008-07-18 06:51 <DIR> d-------- C:\Program Files\PowerArchiver
2008-07-18 06:27 . 2008-07-18 06:27 <DIR> d-------- C:\Users\All Users\WinZip
2008-07-18 06:27 . 2008-07-18 06:27 <DIR> d-------- C:\ProgramData\WinZip
2008-07-17 16:12 . 1998-10-07 12:54 327,168 --a------ C:\Windows\IsUn0415.exe
2008-07-17 11:13 . 2008-07-17 11:14 <DIR> d-------- C:\Program Files\SkanerOnline
2008-07-17 10:21 . 2008-07-17 10:30 <DIR> d-------- C:\Windows\BDOSCAN8
2008-07-16 19:50 . 2008-07-16 19:50 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\Megaupload
2008-07-16 19:49 . 2008-07-16 19:49 <DIR> d-------- C:\Program Files\Megaupload
2008-07-16 13:15 . 2008-07-16 13:15 <DIR> d-------- C:\Program Files\SubEdit-Player
2008-07-16 13:06 . 2008-07-16 13:06 <DIR> d-------- C:\Program Files\NAPI-PROJEKT
2008-07-16 11:59 . 2008-07-16 11:59 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\MegauploadToolbar
2008-07-16 11:59 . 2008-07-16 19:49 <DIR> d-------- C:\Program Files\MegauploadToolbar
2008-07-16 11:54 . 2008-07-17 10:55 <DIR> d-a------ C:\Users\All Users\TEMP
2008-07-16 11:54 . 2008-07-17 10:55 <DIR> d-a------ C:\ProgramData\TEMP
2008-07-16 11:54 . 2008-07-17 11:01 <DIR> d-------- C:\Program Files\DAP
2008-07-16 01:36 . 2008-07-16 01:36 <DIR> d-------- C:\Program Files\System Stability Tester
2008-07-16 01:17 . 2008-07-16 01:17 <DIR> d-------- C:\Program Files\Budzik
2008-07-15 22:02 . 2008-07-15 22:02 268 --ah----- C:\sqmdata03.sqm
2008-07-15 22:02 . 2008-07-15 22:02 244 --ah----- C:\sqmnoopt03.sqm
2008-07-15 20:31 . 2008-07-15 20:31 268 --ah----- C:\sqmdata02.sqm
2008-07-15 20:31 . 2008-07-15 20:31 244 --ah----- C:\sqmnoopt02.sqm
2008-07-15 05:39 . 2008-07-15 05:39 268 --ah----- C:\sqmdata01.sqm
2008-07-15 05:39 . 2008-07-15 05:39 244 --ah----- C:\sqmnoopt01.sqm
2008-07-15 04:42 . 2008-07-15 04:42 268 --ah----- C:\sqmdata00.sqm
2008-07-15 04:42 . 2008-07-15 04:42 244 --ah----- C:\sqmnoopt00.sqm
2008-07-15 03:11 . 2008-07-15 03:11 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\GHISLER
2008-07-15 03:11 . 2008-07-15 03:14 <DIR> d-------- C:\totalcmd
2008-07-15 03:11 . 2008-04-22 07:03 545 --a------ C:\Windows\UC.PIF
2008-07-15 03:11 . 2008-04-22 07:03 545 --a------ C:\Windows\RAR.PIF
2008-07-15 03:11 . 2008-04-22 07:03 545 --a------ C:\Windows\PKZIP.PIF
2008-07-15 03:11 . 2008-04-22 07:03 545 --a------ C:\Windows\PKUNZIP.PIF
2008-07-15 03:11 . 2008-04-22 07:03 545 --a------ C:\Windows\NOCLOSE.PIF
2008-07-15 03:11 . 2008-04-22 07:03 545 --a------ C:\Windows\LHA.PIF
2008-07-15 03:11 . 2008-04-22 07:03 545 --a------ C:\Windows\ARJ.PIF
2008-07-14 19:54 . 2008-07-15 03:14 <DIR> d-------- C:\Program Files\AnyReader
2008-07-14 09:51 . 2008-03-20 18:46 334,792 --a------ C:\Windows\System32\_AxShlEx.dll
2008-07-14 08:10 . 2008-07-14 08:10 <DIR> d-------- C:\Program Files\Smart Projects
2008-07-14 08:05 . 2008-07-14 08:05 <DIR> d-------- C:\Users\All Users\InstallShield
2008-07-14 08:05 . 2008-07-14 08:05 <DIR> d-------- C:\ProgramData\InstallShield
2008-07-14 07:30 . 2008-07-14 07:30 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-07-13 23:46 . 2008-07-14 00:02 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\Systweak
2008-07-13 23:33 . 2008-07-13 23:33 <DIR> d-------- C:\Program Files\Yahoo!
2008-07-13 23:33 . 2008-07-13 23:33 <DIR> d-------- C:\Program Files\CCleaner
2008-07-13 23:15 . 2008-07-13 23:27 <DIR> d-------- C:\Program Files\Odkurzacz
2008-07-13 23:13 . 2008-07-13 23:13 <DIR> d-------- C:\Users\All Users\Diskeeper Corporation
2008-07-13 23:13 . 2008-07-13 23:13 <DIR> d-------- C:\ProgramData\Diskeeper Corporation
2008-07-12 22:31 . 2008-07-12 22:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-12 12:20 . 2008-07-12 12:29 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\Winamp
2008-07-12 12:20 . 2008-07-12 22:28 <DIR> d-------- C:\Program Files\Winamp
2008-07-12 12:20 . 2007-03-08 01:51 129,784 --------- C:\Windows\System32\pxafs.dll
2008-07-12 11:24 . 2000-08-23 17:00 33,280 --a------ C:\Windows\System32\HUFFYUV.DLL
2008-07-11 03:40 . 2008-07-11 03:41 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-07-11 03:29 . 2008-07-11 03:29 <DIR> d-------- C:\Program Files\Secunia
2008-07-08 17:01 . 2008-07-08 17:01 <DIR> d-------- C:\Program Files\directx
2008-07-07 22:42 . 2008-07-07 22:42 <DIR> d-------- C:\Program Files\Ares
2008-07-07 20:01 . 2008-07-07 20:01 621,056 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
2008-07-07 20:01 . 2008-07-07 20:01 36,864 --a------ C:\Windows\System32\cdd.dll
2008-07-07 16:03 . 2008-07-07 16:03 65,536 --------- C:\Windows\SPInstall.etl
2008-07-07 01:26 . 2008-07-07 01:26 <DIR> d-------- C:\Program Files\Opera
2008-07-06 22:30 . 2008-07-07 03:52 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\LimeWire
2008-07-06 22:25 . 2008-07-11 03:19 <DIR> d-------- C:\Program Files\Java
2008-07-06 22:21 . 2008-07-06 22:21 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-06 13:48 . 2008-07-06 13:48 <DIR> d-------- C:\Program Files\MarBit
2008-07-06 13:45 . 2008-07-06 13:45 <DIR> d-------- C:\Program Files\ffdshow
2008-07-06 13:45 . 2008-06-08 23:58 60,273 --a------ C:\Windows\System32\pthreadGC2.dll
2008-07-06 13:45 . 2008-06-12 20:36 7,680 --a------ C:\Windows\System32\ff_vfw.dll
2008-07-06 13:45 . 2008-06-12 20:37 6,144 --a------ C:\Windows\System32\ff_acm.acm
2008-07-06 13:45 . 2007-07-10 18:10 547 --a------ C:\Windows\System32\ff_vfw.dll.manifest
2008-07-06 02:51 . 2008-07-06 02:51 <DIR> d-------- C:\Program Files\COD4 Quick Launcher
2008-07-06 00:51 . 2008-07-12 22:01 <DIR> d-------- C:\My Downloads
2008-07-05 02:56 . 2008-05-02 18:31 731,352 -ra------ C:\Windows\System32\drivers\cfosspeed.sys
2008-07-05 02:55 . 2008-07-18 18:45 <DIR> d-------- C:\Program Files\cFosSpeed
2008-07-05 02:55 . 2008-05-02 18:30 285,912 --a------ C:\Windows\System32\cfosspeed.dll
2008-07-04 23:22 . 2008-04-07 10:24 553 -r------- C:\Windows\USetup.iss
2008-07-04 22:40 . 2008-07-04 22:40 <DIR> d-------- C:\Users\Murarz\{dabe884a-2ad3-4172-9527-a431fb1b39eb}
2008-07-04 22:40 . 2008-07-04 22:40 <DIR> d-------- C:\Program Files\ATI Technologies
2008-07-04 19:18 . 2008-07-04 19:18 <DIR> d-------- C:\Program Files\Intel
2008-07-04 19:18 . 2008-07-04 19:18 <DIR> d-------- C:\Intel
2008-07-04 19:17 . 2008-03-31 13:20 118,784 --a------ C:\Windows\System32\drivers\Rtlh86.sys
2008-07-04 19:16 . 2008-07-04 19:16 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\InstallShield
2008-07-04 19:16 . 2008-07-04 23:21 <DIR> d-------- C:\Program Files\Realtek
2008-07-04 14:41 . 2008-07-17 14:39 136,888 --a------ C:\Windows\System32\drivers\PnkBstrK.sys
2008-07-04 14:41 . 2008-07-17 14:39 111,928 --a------ C:\Windows\System32\PnkBstrB.exe
2008-07-04 14:41 . 2008-07-04 23:27 66,872 --a------ C:\Windows\System32\PnkBstrA.exe
2008-07-04 14:41 . 2008-07-04 21:51 22,328 --a------ C:\Users\Murarz\AppData\Roaming\PnkBstrK.sys
2008-07-04 14:41 . 2008-07-04 21:51 274 --a------ C:\Windows\game.ini
2008-07-03 21:59 . 2008-07-03 21:59 <DIR> d-------- C:\Program Files\Sunrise Vista Konfigurator
2008-07-03 20:42 . 2007-07-19 18:14 3,727,720 --a------ C:\Windows\System32\d3dx9_35.dll
2008-07-03 20:42 . 2007-07-19 18:14 1,358,192 --a------ C:\Windows\System32\D3DCompiler_35.dll
2008-07-03 20:42 . 2007-05-16 16:45 1,124,720 --a------ C:\Windows\System32\D3DCompiler_34.dll
2008-07-03 20:42 . 2007-07-19 18:14 444,776 --a------ C:\Windows\System32\d3dx10_35.dll
2008-07-03 20:42 . 2007-05-16 16:45 443,752 --a------ C:\Windows\System32\d3dx10_34.dll
2008-07-03 20:42 . 2007-07-20 00:57 267,112 --a------ C:\Windows\System32\xactengine2_9.dll
2008-07-03 20:42 . 2007-06-20 20:46 266,088 --a------ C:\Windows\System32\xactengine2_8.dll
2008-07-03 20:42 . 2007-07-20 00:54 18,280 --a------ C:\Windows\System32\x3daudio1_2.dll
2008-07-03 20:27 . 2008-07-03 20:37 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\DAEMON Tools Pro
2008-07-03 20:25 . 2008-07-14 08:02 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
2008-07-03 18:10 . 2008-07-03 18:10 <DIR> d-------- C:\Program Files\Jufsoft
2008-07-03 17:03 . 2008-07-03 17:03 <DIR> d-------- C:\Program Files\Mplayer
2008-07-03 17:00 . 1999-10-09 17:30 305,152 --a------ C:\Windows\IsUninst.exe
2008-07-03 17:00 . 2008-07-03 17:07 525 --a------ C:\Windows\QIII.INI
2008-07-02 23:11 . 2008-07-02 23:11 858,112 --a------ C:\Windows\System32\RacEngn.dll
2008-07-02 23:11 . 2008-07-02 23:11 8,830 --a------ C:\Windows\System32\RacUR.xml
2008-07-02 23:11 . 2008-07-02 23:11 153 --a------ C:\Windows\System32\RacUREx.xml
2008-07-02 22:46 . 2008-07-02 22:46 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\AdobeUM
2008-07-02 22:36 . 2008-07-02 22:36 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-07-02 22:35 . 2008-07-02 22:35 229,888 --a------ C:\Windows\System32\msshsq.dll
2008-07-02 22:34 . 2008-07-02 22:34 <DIR> d-------- C:\Program Files\BitLocker
2008-07-02 22:34 . 2008-07-02 22:34 1,171,848 --a------ C:\Windows\System32\SecureKeyBackupCPL.dll
2008-07-02 22:34 . 2008-07-02 22:34 711 --a------ C:\Windows\System32\CPSOKBTasks.xml
2008-07-02 22:33 . 2008-07-02 22:33 678,408 --a------ C:\Windows\System32\gpprefcl.dll
2008-07-02 20:00 . 2008-07-02 20:00 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\DAEMON Tools
2008-07-02 20:00 . 2008-07-02 20:00 717,296 --a------ C:\Windows\System32\drivers\sptd.sys
2008-07-02 18:18 . 2008-07-18 18:37 <DIR> d-------- C:\Users\Murarz\AppData\Roaming\uTorrent
2008-07-02 18:18 . 2008-07-02 18:18 <DIR> d-------- C:\Program Files\uTorrent
2008-07-02 18:12 . 2008-07-02 18:12 <DIR> d-------- C:\Program Files\Diskeeper Corporation
2008-07-02 17:41 . 2008-07-02 17:41 1,152,000 --a------ C:\Windows\System32\themecpl.dll
2008-07-02 17:41 . 2008-07-02 17:41 233,888 --a------ C:\Windows\System32\DreamScene.dll
2008-07-02 17:29 . 2004-06-16 06:03 73,728 --a------ C:\Windows\System32\ISUSPM.cpl
2008-07-02 17:24 . 2008-07-03 20:42 278,984 --a------ C:\Windows\System32\drivers\atksgt.sys
2008-07-02 17:24 . 2008-07-02 17:24 18,048 --a------ C:\Windows\System32\drivers\lirsgt.sys
2008-07-02 17:14 . 2008-07-16 19:49 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-07-02 17:11 . 2008-07-14 08:22 <DIR> d-------- C:\Program Files\Common Files\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-13 03:14 --------- d-----w C:\Program Files\Windows Sidebar
2008-07-13 03:14 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-07-13 03:14 --------- d-----w C:\Program Files\Windows Mail
2008-07-13 03:14 --------- d-----w C:\Program Files\Windows Journal
2008-07-13 03:14 --------- d-----w C:\Program Files\Windows Defender
2008-07-13 03:14 --------- d-----w C:\Program Files\Windows Collaboration
2008-07-13 03:14 --------- d-----w C:\Program Files\Windows Calendar
2008-07-09 01:14 174 --sha-w C:\Program Files\desktop.ini
2008-07-04 21:21 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-07-04 21:21 315,392 ----a-w C:\Windows\HideWin.exe
2008-07-03 12:13 --------- d-----w C:\Program Files\Microsoft Games
2008-07-02 13:14 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-07-02 13:14 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2008-07-02 13:14 542,720 ----a-w C:\Windows\System32\sysmain.dll
2008-07-02 13:14 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2008-07-02 13:14 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2008-07-02 13:14 297,984 ----a-w C:\Windows\System32\wlansec.dll
2008-07-02 13:14 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2008-07-02 13:14 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-07-02 13:14 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2008-07-02 13:14 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-07-02 13:14 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-07-02 13:06 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2008-07-02 13:06 8,704 ----a-w C:\Windows\System32\hccoin.dll
2008-07-02 13:06 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2008-07-02 13:06 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2008-07-02 13:06 25,600 ----a-w C:\Windows\System32\LangCleanupSysprepAction.dll
2008-07-02 13:06 23,552 ----a-w C:\Windows\System32\lpremove.exe
2008-07-02 13:06 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2008-07-02 13:06 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2008-07-02 13:06 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2008-07-02 13:06 166,912 ----a-w C:\Windows\System32\lpksetup.exe
2008-07-02 13:06 10,240 ----a-w C:\Windows\System32\MUILanguageCleanup.dll
2008-07-02 12:59 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-07-02 12:59 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-02 12:59 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-07-02 12:59 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-02 12:59 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-02 12:56 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-07-02 12:56 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-07-02 12:56 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-07-02 12:56 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-06-16 08:31 7,808 ----a-w C:\Windows\system32\drivers\psi_mf.sys
2008-06-03 06:22 3,695,104 ----a-w C:\Windows\system32\drivers\atikmdag.sys
2008-06-03 03:35 413,696 ----a-w C:\Windows\System32\ATIDEMGX.dll
2008-06-03 03:35 327,680 ----a-w C:\Windows\System32\atipdlxx.dll
2008-06-03 03:35 159,744 ----a-w C:\Windows\System32\atitmmxx.dll
2008-06-03 03:34 43,520 ----a-w C:\Windows\System32\ati2edxx.dll
2008-06-03 03:34 266,240 ----a-w C:\Windows\System32\Ati2evxx.dll
2008-06-03 03:34 262,144 ----a-w C:\Windows\System32\Oemdspif.dll
2008-06-03 03:33 684,032 ----a-w C:\Windows\System32\Ati2evxx.exe
2008-06-03 03:19 3,401,216 ----a-w C:\Windows\System32\atiumdag.dll
2008-06-03 03:02 4,398,080 ----a-w C:\Windows\System32\atiumdva.dll
2008-06-03 02:50 49,664 ----a-w C:\Windows\System32\amdpcom32.dll
2008-06-03 02:49 32,256 ----a-w C:\Windows\System32\atiadlxx.dll
2008-06-03 02:48 10,043,392 ----a-w C:\Windows\System32\atioglxx.dll
2008-06-03 02:34 49,152 ----a-w C:\Windows\system32\drivers\ati2erec.dll
2008-04-25 16:22 206,088 ----a-w C:\Windows\System32\klogon.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:34 125440]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 06:03 221184]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 12:04 2127296]
"Speech Recognition"="C:\Windows\Speech\Common\sapisvr.exe" [2006-11-02 11:45 49664]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-07-14 09:51 6144]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:33 201728]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-05-04 02:32 961024]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:32 2159104 C:\Windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 18:21 201992]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 06:03 81920]
"cFosSpeed"="C:\Program Files\cFosSpeed\cFosSpeed.exe" [2008-05-02 18:30 863448]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-07-09 23:33 36352]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-07 10:24 5369856 C:\Windows\RtHDVCpl.exe]
C:\Users\Murarz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Budzik.lnk - C:\Program Files\Budzik\budzik.exe [2004-08-29 19:47:26 24576]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
"VIDC.HFYU"= huffyuv.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{47A5E0A7-972E-4C82-8E8F-5FF3078BED66}C:\\programdata\\kaspersky lab setup files\\kaspersky internet security 2009\\polish\\setup.exe"= UDP:C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\polish\setup.exe:Kaspersky Internet Security 2009 Setup
"UDP Query User{4F6E1397-0CB6-4D40-9A1E-6F49FD4B571A}C:\\programdata\\kaspersky lab setup files\\kaspersky internet security 2009\\polish\\setup.exe"= TCP:C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\polish\setup.exe:Kaspersky Internet Security 2009 Setup
"{317207CB-D3A7-48A5-BD29-8F1F304F40A0}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{DBFABB07-85FC-4DD7-A668-AB18DA4BCE88}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{132EECA7-3E67-4994-A4F1-53391CD7E96B}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{F637CE35-26D9-428B-80FF-A2FAAEF9D853}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{A4036D39-708F-4D7F-BD96-DB7CF0394327}"= UDP:D:\Nowy folder\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{61200157-3BEE-4CA6-861F-F75C64D641BD}"= TCP:D:\Nowy folder\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{95225771-E29A-44D0-AA15-FC020A8FE2C9}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{643E3991-C1B1-4917-B412-1B412CD15DA5}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{6E883C07-3998-406A-A47C-40B819EB5A99}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{BC94EA47-4F4D-4840-B7E8-6842EB76BA99}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{69113610-B5D7-4D59-BF5C-FB1B60B89367}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{42C1FE5B-D4E5-425F-B7A1-7CB87C20F0B2}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{A874FD39-2E46-4891-82C9-61A859549E9A}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{E2963232-1FED-43C9-BCB3-5F358A541A31}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{55EF7253-580C-4510-A00B-4AFBC259EFA2}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{17E46C4B-0965-4356-98D1-63832B5EE8B9}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{554F8986-21B2-44B6-93B8-8B21A6F8E5C6}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2008-06-03 08:22]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\Windows\system32\DRIVERS\klfltdev.sys [2008-03-13 19:02]
S0 OemBiosDevice;Royalty OEM Bios Extension;C:\Windows\system32\drivers\royal.sys [2003-02-01 15:07]
S3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys [2008-06-16 10:31]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34401817-4874-11dd-9153-001617d47d3f}]
\shell\AutoRun\command - K:\Autorun.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder
"2008-07-18 16:04:07 C:\Windows\Tasks\User_Feed_Synchronization-{D50C6F72-D000-4E6A-8E42-AB54B54C29C3}.job"
- C:\Windows\system32\msfeedssync.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DAEMON Tools Pro Agent - C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-18 18:45:17
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-18 18:46:39
ComboFix-quarantined-files.txt 2008-07-18 16:46:36
Pre-Run: 11,089,989,632 bajtów wolnych
Post-Run: 10,969,366,528 bajtów wolnych
299 --- E O F --- 2008-07-13 20:49:25
Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:43:11, on 2008-07-18
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\cFosSpeed\cfosspeed.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\conime.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Opera\Opera.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL (file missing)
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL (file missing)
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [cFosSpeed] C:\Program Files\cFosSpeed\cFosSpeed.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'USŁUGA SIECIOWA')
O4 - Startup: Budzik.lnk = C:\Program Files\Budzik\budzik.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Statystyki ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: cFosSpeed System Service (cFosSpeedS) - cFos Software GmbH - C:\Program Files\cFosSpeed\spd.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 6366 bytes


zapisz jako 

