Problem opisany w temacie
http://forum.instalki.pl/viewtopic.php?t=10797
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.Prawda
* Created a new restore point
((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-30 )))))))))))))))))))))))))))))))
2007-07-30 19:36 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-29 11:36 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2007-07-28 18:32 442,368 -ra------ C:\WINDOWS\system32\vp6vfw.dll
2007-07-28 18:32 <DIR> d-------- C:\Program Files\EA GAMES
2007-07-22 10:32 <DIR> d-------- C:\DOCUME~1\PAULIN~1\DANEAP~1\Leadertech
2007-07-19 19:19 <DIR> d-------- C:\DOCUME~1\PAULIN~1\DANEAP~1\.BitTornado
2007-07-19 19:06 <DIR> d-------- C:\Program Files\BitTorrent
2007-07-19 19:06 <DIR> d-------- C:\DOCUME~1\PAULIN~1\DANEAP~1\BitTorrent
2007-07-15 00:33 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-07-11 18:12 <DIR> d-------- C:\DOCUME~1\PAULIN~1\DANEAP~1\AdobeUM
2007-07-11 18:09 60,800 -ra------ C:\WINDOWS\system32\drivers\w300bus.sys
2007-07-11 18:09 5,840 -ra------ C:\WINDOWS\system32\drivers\w300whnt.sys
2007-07-11 18:09 5,840 -ra------ C:\WINDOWS\system32\drivers\w300wh.sys
2007-07-11 18:09 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-07-11 18:08 <DIR> d-------- C:\DOCUME~1\PAULIN~1\DANEAP~1\Teleca
2007-07-11 18:07 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-07-11 18:06 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2007-06-28 19:09 0 --a------ C:\WINDOWS\PowerReg.dat
2007-06-10 23:18 <DIR> d-------- C:\Program Files\Google
2007-06-10 23:18 <DIR> d-------- C:\DOCUME~1\PAULIN~1\DANEAP~1\Google
2007-06-10 23:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Google
2007-06-08 23:25 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\DANEAP~1\TEMP
2007-06-07 23:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Windows Genuine Advantage
2007-06-07 20:02 <DIR> d-------- C:\eMule
2007-06-07 12:17 <DIR> d-------- C:\DOCUME~1\PAULIN~1\DANEAP~1\Skype
2007-06-07 12:16 <DIR> d-------- C:\Program Files\Skype
2007-06-07 12:16 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-06-07 12:16 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Skype
2007-06-06 20:13 95,872 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-06-06 20:13 94,552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-06-06 20:13 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-06-06 20:13 745,600 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-06-06 20:13 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-06-06 20:13 26,888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-06-06 20:13 23,416 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-06-06 20:13 <DIR> d-------- C:\Program Files\Alwil Software
2007-06-05 11:22 <DIR> d---s---- C:\DOCUME~1\PAULIN~1\UserData
2007-06-04 22:40 <DIR> d-------- C:\Program Files\adni18
2007-06-04 22:28 <DIR> d-------- C:\Program Files\Gadu-Gadu
2007-06-04 22:28 <DIR> d-------- C:\DOCUME~1\PAULIN~1\Gadu-Gadu
2007-06-04 22:27 1,520 --a------ C:\WINDOWS\unins000.dat
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-28 20:23 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-19 19:19 --------- d-------- C:\DOCUME~1\PAULIN~1\DANEAP~1\.BitTornado
2007-07-10 22:41 3825 --a------ C:\Program Files\INSTALL.LOG
2007-06-06 19:59 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-06-06 11:06 68752 --a------ C:\WINDOWS\system32\perfc015.dat
2007-06-06 11:06 439776 --a------ C:\WINDOWS\system32\perfh015.dat
2007-05-16 17:18 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-04-29 16:36 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
1998-04-30 14:56 129024 --a------ C:\Program Files\UNWISE.EXE
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-12-11 22:05]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-17 01:32]
"Toshiba Hotkey Utility"="C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" [2006-01-28 06:13]
"TPSMain"="TPSMain.exe" [2005-08-04 15:16 C:\WINDOWS\system32\TPSMain.exe]
"NDSTray.exe"="NDSTray.exe" []
"SmoothView"="C:\Program Files\TOSHIBA\Program narzędziowy TOSHIBA Zooming Utility\SmoothView.exe" []
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-12-22 16:34]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-11 20:44]
"CFSServ.exe"="CFSServ.exe" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" []
"DAEMON Tools-1033"="C:\Documents and Settings\paulina frączyk\Pulpit\sims 2\daemon.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-12 13:04]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-24 21:31]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-03-02 01:11]
C:\Documents and Settings\paulina\Menu Start\Programy\Autostart\
Szybkie uruchamianie programu Microsoft Office OneNote 2003.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2005-03-17 15:06:14]
R0 pnpshark;pnpshark;C:\WINDOWS\system32\DRIVERS\pnpshark.sys
R0 st3shark;st3shark;C:\WINDOWS\system32\DRIVERS\st3shark.sys
R0 zmNTMon;zmNTMon;C:\WINDOWS\system32\drivers\zmNTMon.sys
R1 DLACDBHM;DLACDBHM;C:\WINDOWS\system32\Drivers\DLACDBHM.SYS
R1 DLARTL_N;DLARTL_N;C:\WINDOWS\system32\Drivers\DLARTL_N.SYS
R2 DLABOIOM;DLABOIOM;C:\WINDOWS\system32\DLA\DLABOIOM.SYS
R2 DLADResN;DLADResN;C:\WINDOWS\system32\DLA\DLADResN.SYS
R2 DLAIFS_M;DLAIFS_M;C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
R2 DLAOPIOM;DLAOPIOM;C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
R2 DLAPoolM;DLAPoolM;C:\WINDOWS\system32\DLA\DLAPoolM.SYS
R2 DLAUDF_M;DLAUDF_M;C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
R2 DLAUDFAM;DLAUDFAM;C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
R2 DRVNDDM;DRVNDDM;C:\WINDOWS\system32\Drivers\DRVNDDM.SYS
R2 Netdevio;TOSHIBA Network Device Usermode I/O Protocol;C:\WINDOWS\system32\DRIVERS\netdevio.sys
R3 BoiHwsetup;Access 32bits INT15 routine;C:\WINDOWS\system32\drivers\BoiHwSetup.sys
R3 CAMCAUD;Conexant AMC 3D Environmental Audio;C:\WINDOWS\system32\drivers\camc6aud.sys
R3 CAMCHALA;CAMCHALA;C:\WINDOWS\system32\drivers\camc6hal.sys
R3 HSF_DPV;HSF_DPV;C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys
R3 Iviaspi;IVI ASPI Shell;C:\WINDOWS\system32\drivers\iviaspi.sys
R3 qkbfiltr;Quanta HotKey Keyboard Filter Driver;C:\WINDOWS\system32\drivers\qkbfiltr.sys
R3 qmofiltr;Quanta HotKey Mouse Filter Driver;C:\WINDOWS\system32\drivers\qmofiltr.sys
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver;C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
R3 SynTP;Synaptics TouchPad Driver;C:\WINDOWS\system32\DRIVERS\SynTP.sys
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys
S3 zmNTZip;zmNTZip;\??\C:\MS Office\Zip Magic\zmNTZip.sys
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-30 19:39:35
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\D\n\21]
"DisplayName"="\xb973\x7791"
"DeviceDesc"="\xb973\x7791"
"ProviderName"="\x27fc\21\xee18\x7c90\x286c\21\b"
"MFG"="\xc1bf\b\xe12b\x1803\x6d8"
"ReinstallString"=".10.1000.5"
"DeviceInstanceIds"=str(7):"c:\toolscd\display driver\sbdrv\smbus\smbusati.inf"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c]
"Order"=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,..
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-30 19:40:12
--- E O F ---