Z góry dziekuje i pozdrawiam.
- Kod: Zaznacz wszystko
ComboFix 08-07-11.1 - izabella 2008-07-12 20:23:37.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1273 [GMT 2:00]
Running from: C:\Documents and Settings\izabella\Pulpit\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\izabella\Dane aplikacji\inst.exe
F:\Autorun.inf
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-06-12 to 2008-07-12 )))))))))))))))))))))))))))))))
.
2008-07-12 20:21 . 2008-07-12 20:21 <DIR> d-------- C:\Documents and Settings\izabella\Dane aplikacji\TrojanHunter
2008-07-12 19:36 . 2008-07-12 19:36 <DIR> d-------- C:\Program Files\TrojanHunter 5.0
2008-07-08 21:11 . 2008-07-08 21:11 <DIR> d-------- C:\Program Files\uTorrent
2008-07-08 21:11 . 2008-07-12 17:32 <DIR> d-------- C:\Documents and Settings\izabella\Dane aplikacji\uTorrent
2008-07-08 20:53 . 2008-07-10 09:37 <DIR> d-------- C:\Program Files\Mininova
2008-07-08 20:53 . 2008-07-10 09:37 <DIR> d-------- C:\Program Files\Conduit
2008-06-22 00:07 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-06-22 00:07 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-06-22 00:07 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-06-21 15:06 . 2008-06-21 15:06 <DIR> d-------- C:\Program Files\Windows Live
2008-06-21 15:06 . 2008-06-21 15:15 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-21 15:06 . 2008-06-21 15:06 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\WLInstaller
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-12 19:10 --------- d-----w C:\Documents and Settings\izabella\Dane aplikacji\Skype
2008-07-12 18:23 --------- d-----w C:\Program Files\Neostrada TP
2008-07-12 14:08 --------- d-----w C:\Documents and Settings\izabella\Dane aplikacji\skypePM
2008-07-10 07:40 --------- d-----w C:\Program Files\Yahoo!
2008-07-09 21:25 --------- d-----w C:\Program Files\eMule
2008-06-23 17:25 --------- d-----w C:\Program Files\Microsoft Works
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 17:30 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-19 17:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-14 18:01 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-08 19:12 --------- d-----w C:\Program Files\CCleaner
2008-06-05 22:16 --------- d-----w C:\Documents and Settings\izabella\Dane aplikacji\XnView
2008-06-02 22:36 --------- d-----w C:\Program Files\Flash Slideshow Maker Professional
2008-04-29 06:13 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-04-29 05:52 47,360 ----a-w C:\Documents and Settings\izabella\Dane aplikacji\pcouffin.sys
2008-02-27 17:58 2,293,848 ----a-w C:\Program Files\FLV PlayerFCSetup.exe
2008-02-27 17:56 3,955,352 ----a-w C:\Program Files\FLV PlayerRCATSetup.exe
2008-02-27 17:54 411,248 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
2008-01-23 12:18 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2007-12-08 16:59 90,112 ----a-w C:\Program Files\gg77.exe
2007-03-09 07:12 27,648 --sha-w C:\WINDOWS\system32\AVSredirect.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-11-14 12:54 2131392]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-12-12 16:23 21686568]
"EXPLORER.EXE"="EXPLORER.EXE" [2007-06-13 15:23 1034752 C:\WINDOWS\explorer.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 16:10 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 23:55 54832]
"WooCnxMon"="C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [2003-10-16 19:07 24576]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2003-09-05 07:59 878080]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 19:07 20480]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"WOOTASKBARICON"="C:\Program Files\Neostrada TP\taskbaricon.exe" [2003-10-16 19:07 53248]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 10:12 90112]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-16 00:54 37376]
"ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2006-07-14 17:24 49152]
"Domino"="C:\WINDOWS\Domino.exe" [2006-07-04 08:16 49152]
"SearchSettings"="C:\Program Files\Search Settings\SearchSettings.exe" [2008-02-06 18:47 1036640]
"THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2008-07-09 18:54 1056928]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 09:03 16125440 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= C:\PROGRA~1\REPLAY~2\iac25_32.ax
"vidc.xvid"= xvid.dll
"msacm.divxa32"= DivXa32.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\eMule\\eMule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\XSI_6.02\\Application\\bin\\XSI.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 gearsec;gearsec;C:\WINDOWS\system32\gearsec.exe [2005-11-30 12:43]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ff60e14c-a421-11dc-85d3-001b249c604a}]
\Shell\AutoRun\command - d.cmd
\Shell\explore\Command - d.cmd
\Shell\open\Command - d.cmd
.
Contents of the 'Scheduled Tasks' folder
"2008-07-10 05:45:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-wsctf.exe - wsctf.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-12 21:10:34
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\spm\spmdib.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-07-12 21:15:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-12 19:14:59
Pre-Run: 6,885,810,176 bajtów wolnych
Post-Run: 6,954,237,952 bajt˘w wolnych
145 --- E O F --- 2008-07-12 13:51:14