od dwóch dni mam problem z internetem. generalnie strasznie się on muli. Zawsze ściągałam z torrentów, teraz maksymalnie pobiera sie 3kb/s.
Nie rozumiem co się dzieje. skanowałam dysk antywirusem, instalowałam ponownie st. do karty sieciowej. Nie mam więcej pomysłów co zrobić.
Wklejam loga z combofix, może to pomoże..
ComboFix 09-11-15.01 - Tofik 2009-11-15 14:11.2.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1045.18.3067.2516 [GMT 1:00]
Uruchomiony z: d:\documents and settings\Tofik\Moje dokumenty\Pobieranie\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((( Pliki utworzone od 2009-10-15 do 2009-11-15 )))))))))))))))))))))))))))))))
.
2009-11-15 13:07 . 2009-11-15 13:07 395776 ----a-w- d:\windows\system32\CF5554.exe
2009-11-15 12:34 . 2009-11-15 12:34 -------- d-----w- d:\program files\Atheros WLAN Client
2009-11-15 12:34 . 2008-06-27 15:40 1315776 ----a-w- d:\windows\system32\drivers\athw.sys
2009-11-15 12:34 . 2009-11-15 12:34 -------- d-----w- d:\documents and settings\Tofik\Dane aplikacji\InstallShield
2009-11-15 12:31 . 2009-10-21 19:03 245760 ----a-w- d:\program files\Uninstall Ask Toolbar.dll
2009-11-15 12:28 . 2009-11-15 12:28 -------- d--h--r- d:\documents and settings\All Users\Dane aplikacji\Atheros
2009-11-15 12:28 . 2009-11-15 12:34 -------- d-----w- d:\windows\LastGood
2009-11-15 11:16 . 2009-11-15 11:21 -------- d-----w- d:\program files\BitComet
2009-11-10 20:04 . 2004-08-03 23:44 21504 -c--a-w- d:\windows\system32\dllcache\hidserv.dll
2009-11-10 20:04 . 2004-08-03 23:44 21504 ----a-w- d:\windows\system32\hidserv.dll
2009-11-05 19:22 . 2009-11-05 19:22 -------- d-----w- d:\documents and settings\Tofik\Dane aplikacji\Media Player Classic
2009-11-04 21:56 . 2009-11-04 21:56 -------- d-----w- d:\program files\D-Tools
2009-11-04 21:56 . 2004-08-22 15:31 5248 ----a-w- d:\windows\system32\drivers\d347prt.sys
2009-11-04 21:56 . 2004-08-22 15:31 155136 ----a-w- d:\windows\system32\drivers\d347bus.sys
2009-11-04 21:56 . 2009-11-04 21:56 -------- d-----w- d:\windows\Downloaded Installations
2009-11-04 21:40 . 2009-11-04 21:40 -------- d-----w- d:\program files\Astroburn Toolbar
2009-11-04 21:40 . 2009-11-04 21:40 -------- d-----w- d:\documents and settings\Tofik\Dane aplikacji\Astroburn Lite
2009-11-04 21:40 . 2009-11-04 21:50 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Astroburn Lite
2009-11-04 21:25 . 2009-11-04 21:25 107888 ----a-w- d:\windows\system32\CmdLineExt.dll
2009-11-04 21:25 . 2009-11-04 21:25 -------- d--h--r- d:\documents and settings\Tofik\Dane aplikacji\SecuROM
2009-11-04 21:25 . 2009-11-04 21:25 -------- d-----w- d:\program files\Hasbro
2009-11-04 11:58 . 2009-11-04 11:58 691696 ----a-w- d:\windows\system32\drivers\sptd.sys
2009-11-04 11:58 . 2009-11-04 12:00 -------- d-----w- d:\program files\DAEMON Tools Lite
2009-11-04 11:57 . 2009-11-04 12:03 -------- d-----w- d:\documents and settings\Tofik\Dane aplikacji\DAEMON Tools Lite
2009-11-04 11:57 . 2009-11-04 11:57 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\DAEMON Tools Lite
2009-11-02 01:25 . 2009-11-02 01:25 -------- d-----w- d:\program files\Real Alternative
2009-11-02 01:25 . 2009-11-02 01:25 -------- d-----w- d:\documents and settings\Tofik\Ustawienia lokalne\Dane aplikacji\Real
2009-11-02 01:25 . 2003-03-19 03:14 499712 ----a-w- d:\windows\system32\msvcp71.dll
2009-10-31 13:39 . 2009-10-31 13:39 -------- d-----w- d:\documents and settings\Tofik\Dane aplikacji\iPlus
2009-10-31 12:13 . 2009-10-31 12:13 -------- dc----w- d:\windows\system32\DRVSTORE
2009-10-31 12:13 . 2009-10-31 12:13 -------- d-----w- d:\program files\iPlus
2009-10-25 17:56 . 2004-08-03 22:44 221184 ----a-w- d:\windows\system32\wmpns.dll
2009-10-24 13:44 . 2009-10-24 13:44 -------- d-----w- d:\program files\Marvell
2009-10-24 13:44 . 2009-10-24 13:44 -------- d-----w- d:\documents and settings\Tofik\Dane aplikacji\TMP
2009-10-23 21:51 . 2009-10-23 21:51 -------- d-----w- d:\documents and settings\Tofik\Ustawienia lokalne\Dane aplikacji\Help
2009-10-23 21:48 . 2004-08-03 22:44 25600 ----a-w- d:\documents and settings\LocalService\Dane aplikacji\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-10-23 21:35 . 2009-10-23 21:35 -------- d-----w- d:\windows\system32\AlertModule
2009-10-23 21:35 . 2005-10-06 12:55 36864 ----a-w- d:\windows\system32\IfHelper.dll
2009-10-23 21:35 . 2004-08-23 11:49 40960 ----a-w- d:\windows\system32\FTRTSVC.exe
2009-10-23 21:34 . 2009-10-23 21:53 -------- d-----w- d:\program files\neostrada tp
2009-10-23 21:31 . 2009-10-23 21:31 -------- d-sh--w- d:\windows\ftpcache
2009-10-22 00:47 . 2009-10-22 00:47 -------- d-----w- d:\program files\Lexmark
2009-10-22 00:37 . 2009-10-22 00:37 -------- d-----w- d:\windows\Sun
2009-10-22 00:36 . 2009-10-22 00:36 411368 ----a-w- d:\windows\system32\deploytk.dll
2009-10-22 00:36 . 2009-10-22 00:36 -------- d-----w- d:\program files\Java
2009-10-22 00:35 . 2009-10-22 00:35 152576 ----a-w- d:\documents and settings\Tofik\Dane aplikacji\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-21 19:24 . 2009-10-21 19:31 -------- d-----w- d:\documents and settings\Tofik\Dane aplikacji\Nero
2009-10-21 19:22 . 2009-11-15 12:39 -------- d-----w- d:\program files\Common Files\Nero
2009-10-21 19:22 . 2009-11-15 12:38 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Nero
2009-10-21 19:03 . 2009-10-22 00:37 -------- d-----w- d:\program files\AskTBar
2009-10-20 20:51 . 2009-10-20 20:51 -------- d--h--w- d:\windows\PIF
2009-10-20 17:29 . 2009-10-20 17:29 -------- d-----w- d:\documents and settings\Tofik\Ustawienia lokalne\Dane aplikacji\Adobe
2009-10-20 17:27 . 2009-10-21 15:05 -------- d-----w- d:\program files\lx_cats
2009-10-20 17:27 . 2006-03-21 09:42 303104 ----a-w- d:\windows\system32\lxcrcoin.dll
2009-10-20 17:27 . 2006-02-20 13:06 393216 ----a-w- d:\windows\system32\lxcriesc.dll
2009-10-20 17:27 . 2006-02-20 13:03 409600 ----a-w- d:\windows\system32\lxcrinpa.dll
2009-10-20 17:27 . 2005-07-08 02:11 40960 ----a-w- d:\windows\system32\lxcrvs.dll
2009-10-18 21:01 . 2009-10-18 21:01 724992 ----a-w- d:\windows\iun6002.exe
2009-10-18 21:01 . 2006-10-26 17:56 32592 ----a-w- d:\windows\system32\msonpmon.dll
2009-10-18 21:00 . 2009-10-18 21:00 -------- d-----w- d:\program files\Microsoft Works
2009-10-18 21:00 . 2009-10-18 21:00 -------- d-----w- d:\program files\MSBuild
2009-10-18 20:57 . 2009-10-18 21:00 -------- d-----w- d:\windows\SHELLNEW
2009-10-18 20:57 . 2009-10-18 20:57 -------- d-----w- d:\documents and settings\Tofik\Ustawienia lokalne\Dane aplikacji\Microsoft Help
2009-10-18 20:57 . 2009-10-18 21:01 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Microsoft Help
2009-10-18 20:57 . 2009-10-18 20:57 -------- d-----r- D:\MSOCache
2009-10-17 01:13 . 2009-10-20 17:29 -------- d-----w- d:\program files\Common Files\Adobe
2009-10-17 01:12 . 2009-10-17 01:12 -------- d-----w- d:\windows\Cache
2009-10-17 00:57 . 2009-10-21 19:24 68456 ----a-w- d:\documents and settings\Tofik\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-10-17 00:34 . 2004-08-03 21:08 26496 -c--a-w- d:\windows\system32\dllcache\usbstor.sys
2009-10-17 00:28 . 2007-01-09 13:22 50752 ----a-r- d:\windows\agrsmdel.exe
2009-10-17 00:28 . 2006-11-28 15:11 1161888 ----a-r- d:\windows\system32\drivers\AGRSM.sys
2009-10-17 00:28 . 2006-10-05 12:10 9216 ----a-r- d:\windows\system32\agrsmsvc.exe
2009-10-17 00:28 . 2006-09-11 14:34 13312 ----a-r- d:\windows\system32\agrscoin.dll
2009-10-17 00:28 . 2009-10-17 00:28 -------- d-----w- d:\documents and settings\Tofik\Dane aplikacji\Gadu-Gadu
2009-10-17 00:24 . 2004-08-03 21:15 60800 ----a-w- d:\windows\system32\drivers\sysaudio.sys
2009-10-17 00:22 . 2009-10-17 00:22 -------- d-----w- d:\program files\SubEdit-Player
2009-10-17 00:21 . 2008-09-16 19:23 168448 ----a-w- d:\windows\system32\unrar.dll
2009-10-17 00:21 . 2008-12-07 18:08 795648 ----a-w- d:\windows\system32\xvidcore.dll
2009-10-17 00:21 . 2008-12-07 18:08 130048 ----a-w- d:\windows\system32\xvidvfw.dll
2009-10-17 00:21 . 2004-01-25 16:18 217088 ----a-w- d:\windows\system32\yv12vfw.dll
2009-10-17 00:21 . 2008-12-11 00:33 86016 ----a-w- d:\windows\system32\dpl100.dll
2009-10-17 00:21 . 2008-11-06 16:37 3596288 ----a-w- d:\windows\system32\qt-dx331.dll
2009-10-17 00:21 . 2008-11-06 16:33 684032 ----a-w- d:\windows\system32\divx.dll
2009-10-17 00:21 . 2009-02-09 18:56 67584 ----a-w- d:\windows\system32\ff_vfw.dll
2009-10-17 00:21 . 2009-10-17 00:22 -------- d-----w- d:\program files\K-Lite Codec Pack
2009-10-17 00:21 . 2004-01-11 22:00 348160 ----a-w- d:\windows\system32\msvcr71.dll
2009-10-17 00:20 . 2009-10-26 18:14 -------- d-----w- d:\documents and settings\Tofik\Gadu-Gadu
2009-10-17 00:20 . 2009-10-22 06:03 -------- d-----w- d:\program files\Gadu-Gadu
2009-10-17 00:02 . 2009-10-17 00:02 -------- d-----w- d:\documents and settings\Tofik\Ustawienia lokalne\Dane aplikacji\GHISLER
2009-10-17 00:01 . 2009-09-24 05:50 545 ----a-w- d:\windows\UC.PIF
2009-10-17 00:01 . 2009-09-24 05:50 545 ----a-w- d:\windows\RAR.PIF
2009-10-17 00:01 . 2009-09-24 05:50 545 ----a-w- d:\windows\PKZIP.PIF
2009-10-17 00:01 . 2009-09-24 05:50 545 ----a-w- d:\windows\PKUNZIP.PIF
2009-10-17 00:01 . 2009-09-24 05:50 545 ----a-w- d:\windows\NOCLOSE.PIF
2009-10-17 00:01 . 2009-09-24 05:50 545 ----a-w- d:\windows\LHA.PIF
2009-10-17 00:01 . 2009-09-24 05:50 545 ----a-w- d:\windows\ARJ.PIF
2009-10-17 00:01 . 2009-10-17 00:02 -------- d-----w- d:\program files\totalcmd
2009-10-17 00:01 . 2009-10-17 00:01 -------- d-----w- d:\documents and settings\Tofik\Dane aplikacji\GHISLER
2009-10-16 23:48 . 2009-07-28 14:33 55656 ----a-w- d:\windows\system32\drivers\avgntflt.sys
2009-10-16 23:48 . 2009-03-30 08:33 96104 ----a-w- d:\windows\system32\drivers\avipbb.sys
2009-10-16 23:48 . 2009-02-13 10:29 22360 ----a-w- d:\windows\system32\drivers\avgntmgr.sys
2009-10-16 23:48 . 2009-02-13 10:17 45416 ----a-w- d:\windows\system32\drivers\avgntdd.sys
2009-10-16 23:48 . 2009-10-16 23:48 -------- d-----w- d:\program files\Avira
2009-10-16 23:48 . 2009-10-16 23:48 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Avira
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-15 13:08 . 2009-10-16 21:32 -------- d-----w- d:\documents and settings\Tofik\Dane aplikacji\uTorrent
2009-11-15 12:34 . 2009-10-16 20:55 -------- d--h--w- d:\program files\InstallShield Installation Information
2009-11-15 11:16 . 2006-09-18 05:57 2560 ----a-w- d:\windows\system32\BitCometRes.dll
2009-10-27 21:32 . 2002-09-28 22:00 51166 ----a-w- d:\windows\system32\perfc015.dat
2009-10-27 21:32 . 2002-09-28 22:00 359416 ----a-w- d:\windows\system32\perfh015.dat
2009-10-24 13:44 . 2009-10-17 00:23 -------- d-----w- d:\program files\Common Files\InstallShield
2009-10-23 21:36 . 2009-10-23 21:35 184 ----a-w- d:\program files\neostrada
2009-10-23 21:36 . 2009-10-23 21:36 33 ----a-w- d:\windows\system32\drivers\adidsl.cfg
2009-10-23 21:36 . 2009-10-23 21:36 -------- d-----w- d:\program files\SAGEM
2009-10-20 17:26 . 2009-10-20 17:26 -------- d-----w- d:\program files\Lexmark 2400 Series
2009-10-20 17:26 . 2009-10-20 17:26 -------- d-----w- d:\program files\Lexmark Toolbar
2009-10-18 15:47 . 2009-10-16 20:31 86327 ----a-w- d:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-17 00:23 . 2009-10-17 00:23 -------- d-----w- d:\program files\Realtek
2009-10-17 00:23 . 2009-10-17 00:22 -------- d-----w- d:\program files\Winamp3
2009-10-16 22:55 . 2009-10-16 22:55 0 ----a-w- d:\windows\nsreg.dat
2009-10-16 21:46 . 2009-10-16 21:46 -------- d-----w- d:\program files\uTorrent
2009-10-16 21:03 . 2009-10-16 21:03 -------- d-----w- d:\program files\Unlocker
2009-10-16 20:55 . 2009-10-16 20:55 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\WLAN
2009-10-16 20:53 . 2009-10-16 20:53 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard
2009-10-16 20:32 . 2009-10-16 20:32 -------- d-----w- d:\program files\microsoft frontpage
2009-10-16 20:31 . 2009-10-16 20:31 -------- d-----w- d:\program files\Usługi online
2009-10-16 20:22 . 2009-10-16 20:22 21856 ----a-w- d:\windows\system32\emptyregdb.dat
2009-08-21 11:17 . 2009-10-16 20:52 485920 ----a-w- d:\windows\system32\NVUNINST.EXE
2009-08-19 13:40 . 2009-08-19 13:40 458752 ----a-w- d:\windows\system32\nvmccssr.dll
2009-08-19 13:40 . 2009-08-19 13:40 1282048 ----a-w- d:\windows\system32\nvmobls.dll
2009-08-19 13:40 . 2009-08-19 13:40 188416 ----a-w- d:\windows\system32\nvmccss.dll
2009-08-19 13:40 . 2009-08-19 13:40 4407296 ----a-w- d:\windows\system32\nvgamesr.dll
2009-08-19 13:40 . 2009-08-19 13:40 3510272 ----a-w- d:\windows\system32\nvgames.dll
2009-08-19 13:40 . 2009-08-19 13:40 6074368 ----a-w- d:\windows\system32\nvdispsr.dll
2009-08-19 13:40 . 2009-08-19 13:40 4018176 ----a-w- d:\windows\system32\nvdisps.dll
2009-08-19 13:40 . 2009-08-19 13:40 86016 ----a-w- d:\windows\system32\nvmctray.dll
2009-08-19 13:40 . 2009-08-19 13:40 168004 ----a-w- d:\windows\system32\nvsvc32.exe
2009-08-19 13:40 . 2009-08-19 13:40 229376 ----a-w- d:\windows\system32\nvmccs.dll
2009-08-19 13:40 . 2009-08-19 13:40 13762560 ----a-w- d:\windows\system32\nvcpl.dll
2009-08-19 11:35 . 2009-10-16 20:52 485920 ----a-w- d:\windows\system32\nvudisp.exe
2009-08-19 11:35 . 2009-08-19 11:35 815104 ----a-w- d:\windows\system32\nvapi.dll
2009-08-19 11:35 . 2009-08-19 11:35 7968448 ----a-w- d:\windows\system32\drivers\nv4_mini.sys
2009-08-19 11:35 . 2009-08-19 11:35 678432 ----a-w- d:\windows\system32\nvcuvid.dll
2009-08-19 11:35 . 2009-08-19 11:35 5957120 ----a-w- d:\windows\system32\nv4_disp.dll
2009-08-19 11:35 . 2009-08-19 11:35 1757184 ----a-w- d:\windows\system32\nvcuda.dll
2009-08-19 11:35 . 2009-08-19 11:35 1580550 ----a-w- d:\windows\system32\nvdata.bin
2009-08-19 11:35 . 2009-08-19 11:35 155648 ----a-w- d:\windows\system32\nvcodins.dll
2009-08-19 11:35 . 2009-08-19 11:35 155648 ----a-w- d:\windows\system32\nvcod.dll
2009-08-19 11:35 . 2009-08-19 11:35 1317408 ----a-w- d:\windows\system32\nvcuvenc.dll
2009-08-19 11:35 . 2009-08-19 11:35 10039296 ----a-w- d:\windows\system32\nvoglnt.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WiseStubReboot"="MSIEXEC" [X]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2009-08-19 86016]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2009-08-19 13762560]
"avgnt"="d:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"lxcrmon.exe"="d:\program files\Lexmark 2400 Series\lxcrmon.exe" [2006-03-06 286720]
"EzPrint"="d:\program files\Lexmark 2400 Series\ezprint.exe" [2006-02-06 98304]
"LXCRCATS"="d:\windows\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll" [2006-02-24 65536]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-10-22 149280]
"iPlusManager"="d:\program files\iPlus\iPlusChecker.exe" [2008-05-30 409600]
"DAEMON Tools-1033"="d:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"nwiz"="nwiz.exe" - d:\windows\system32\nwiz.exe [2009-08-19 1657376]
"RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.EXE [2009-07-20 18670592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
d:\documents and settings\All Users\Menu Start\Programy\Autostart\
DSLMON.lnk - d:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2009-10-23 839680]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\BitComet\\BitComet.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20649:TCP"= 20649:TCP:BitComet 20649 TCP
"20649:UDP"= 20649:UDP:BitComet 20649 UDP
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\program files\Avira\AntiVir Desktop\sched.exe [2009-10-17 108289]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc --> RUNDLL32.EXE ykx32coinst,serviceStartProc [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;d:\windows\system32\drivers\nvhda32.sys [2008-05-14 38176]
S3 Ambfilt;Ambfilt;d:\windows\system32\drivers\Ambfilt.sys [2009-10-17 1684736]
--- Inne Usługi/Sterowniki w Pamięci ---
*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.astroburn-search.com/startpage
uSearchURL,(Default) = hxxp://www.searchgateway.net/search/%s
IE: Download all links using BitComet - d:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Download all videos using BitComet - d:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: Download link using &BitComet - d:\program files\BitComet\BitComet.exe/AddLink.htm
IE: E&ksportuj do programu Microsoft Excel - d:\progra~1\Microsoft Office\Office12\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\Tofik\Dane aplikacji\Mozilla\Firefox\Profiles\7f5a5u2i.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.pl/
FF - prefs.js: network.proxy.type - 4
---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKLM-Run-autoclk - autoclk.exe
HKLM-Run-adiras - adiras.exe
AddRemove-{1f68297d-1506-4cc1-9a6b-51b0b12eea3f} - d:\program files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-15 14:14
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCRCATS = rundll32 d:\windows\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x89F88438]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi

Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_USERS\S-1-5-21-789336058-602162358-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c0,8a,df,93,9f,42,d9,d8,93,0c,65,7a,c5,ed,7c,a1,be,73,4e,5b,8f,b5,b8,
ae,53,8a,ea,40,d4,0a,fe,13,be,13,f9,e3,bc,dc,6e,51,69,e9,70,36,b5,6e,5f,a8,\
"??"=hex:ff,9f,f0,1d,27,87,64,82,f5,64,2f,39,cf,1e,6d,7a
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'explorer.exe'(2192)
d:\windows\system32\msi.dll
.
Czas ukończenia: 2009-11-15 14:15
ComboFix-quarantined-files.txt 2009-11-15 13:15
Przed: 2 821 890 048 bajtów wolnych
Po: 3 209 347 072 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(3)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 8E2F2CF4ECAEC352A6EE673504D7A2A7
tulaski..
