ComboFix 08-10-24.02 - mariusz chłopek 2008-10-26 15:51:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1604 [GMT 1:00]
Uruchomiony z: C:\Documents and Settings\mariusz chłopek\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2008-09-26 do 2008-10-26 )))))))))))))))))))))))))))))))
.
Nie utworzono żadnych nowych plików w tym okresie
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 14:40 --------- d-----w C:\Program Files\Google
2008-10-26 11:16 --------- d-----w C:\Program Files\Crawler
2008-10-04 08:22 60,273 ----a-w C:\WINDOWS\system32\pthreadGC2.dll
2008-09-15 15:40 1,846,272 ----a-w C:\WINDOWS\system32\win32k.sys
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-26 19:11 987,136 ----a-w C:\WINDOWS\system32\VSFilter.dll
2008-08-26 08:27 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 21:00 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-08-14 13:46 2,137,600 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:46 2,017,280 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-02 18:40 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-08-02 18:33 558,142 ----a-w C:\WINDOWS\java\Packages\5r93p7l7.zip
2008-08-02 18:33 155,995 ----a-w C:\WINDOWS\java\Packages\oyxb753f.zip
2008-07-31 08:41 68,616 ----a-w C:\WINDOWS\system32\XAPOFX1_1.dll
2008-07-31 08:41 238,088 ----a-w C:\WINDOWS\system32\xactengine3_2.dll
2008-07-31 08:40 509,448 ----a-w C:\WINDOWS\system32\XAudio2_2.dll
.
((((((((((((((((((((((((((((( snapshot@2008-10-26_13.08.00.40 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-19 14:43:08 1,163,960 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-07-19 15:43:08 1,163,960 ----a-w C:\WINDOWS\system32\aswBoot.exe
- 2008-07-19 14:30:53 94,392 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-07-19 15:30:53 94,392 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-10-26 12:15:17 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NtUser.dat
- 2008-07-19 14:32:15 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-07-19 15:32:15 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-07-19 15:37:42 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
- 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-01-17 17:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
- 2008-07-19 14:37:21 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-07-19 15:37:21 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
- 2008-07-19 14:33:42 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-07-19 15:33:42 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
- 2008-07-19 14:35:18 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-07-19 15:35:18 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
- 2008-07-19 14:32:36 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-07-19 15:32:36 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
- 2008-03-25 03:21:18 2,889,088 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2008-10-05 03:24:02 3,695,008 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
- 2008-03-25 03:21:20 218,496 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-10-05 03:24:04 235,936 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
- 2008-08-02 20:38:11 70,264 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-10-26 12:22:29 84,661 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-08-12 12:51:00 40,836 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-10-26 12:25:16 40,836 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-12 12:51:00 50,748 ----a-w C:\WINDOWS\system32\perfc015.dat
+ 2008-10-26 12:25:16 50,748 ----a-w C:\WINDOWS\system32\perfc015.dat
- 2008-08-12 12:51:00 314,508 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-10-26 12:25:16 314,508 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-08-12 12:51:00 358,834 ----a-w C:\WINDOWS\system32\perfh015.dat
+ 2008-10-26 12:25:16 358,834 ----a-w C:\WINDOWS\system32\perfh015.dat
.
-- Migawka wyzerowana --
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 15360]
"Gadu-Gadu"="E:\Programy\GG\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"Picasa Media Detector"="E:\Programy\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
"BitComet"="E:\Programy\BitComet\BitComet.exe" [2008-08-22 2567992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-03-23 888832]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"BearShare"="C:\Program Files\BearShare\BearShare.exe" [2006-08-01 3313664]
"Gainward"="C:\Program Files\VDOTool\TBPanel.exe" [2007-11-27 2169368]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-28 8523776]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-11-28 81920]
"nwiz"="nwiz.exe" [2007-11-28 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= L3codecp.acm
"msacm.avis"= ff_acm.acm
"msacm.ac3filter"= ac3filter.acm
"msacm.divxa32"= DivXa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
--a------ 2008-02-22 12:30 217544 C:\Program Files\Alcohol Soft\Alcohol 120\AxCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
--a------ 2008-08-22 07:07 2567992 E:\Programy\BitComet\BitComet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
--a------ 2008-03-20 11:04 2127296 E:\Programy\GG\Gadu-Gadu\gg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-08-04 00:02 36352 E:\Programy\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\Programy\\GG\\Gadu-Gadu\\gg.exe"=
"E:\\Programy\\BitComet\\BitComet.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\BearShare\\BearShare.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23389:TCP"= 23389:TCP:BitComet 23389 TCP
"23389:UDP"= 23389:UDP:BitComet 23389 UDP
R3 usbstor;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\mariusz chłopek\Dane aplikacji\Mozilla\Firefox\Profiles\
04b3jqlg.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://en-us.start.mozilla.com/firefox? ... S:official.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-26 15:52:36
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-10-26 15:53:01
ComboFix-quarantined-files.txt 2008-10-26 14:52:59
ComboFix2.txt 2008-10-26 12:08:17
Przed: 13 838 856 192 bajtów wolnych
Po: 13,827,932,160 bajtów wolnych
140 --- E O F --- 2008-10-26 12:02:44