Log z Combo fixa
Mam np takie coś że mi tapeta znika z pulpitu
ComboFix 08-08-04.06 - us 2008-08-05 17:55:55.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.171 [GMT 2:00]
Running from: C:\Documents and Settings\us\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\us\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-07-05 to 2008-08-05 )))))))))))))))))))))))))))))))
.
2008-08-03 22:07 . 2008-08-05 17:57 <DIR> d--h----- C:\Documents and Settings\GeorGe\Ustawienia lokalne
2008-08-03 22:07 . 2008-08-03 22:08 <DIR> dr------- C:\Documents and Settings\GeorGe\Ulubione
2008-08-03 22:07 . 2006-12-16 16:04 <DIR> d--h----- C:\Documents and Settings\GeorGe\Szablony
2008-08-03 22:07 . 2008-08-03 22:13 <DIR> d-------- C:\Documents and Settings\GeorGe\Pulpit
2008-08-03 22:07 . 2008-08-03 22:08 <DIR> dr------- C:\Documents and Settings\GeorGe\Moje dokumenty
2008-08-03 22:07 . 2006-01-01 02:40 <DIR> dr------- C:\Documents and Settings\GeorGe\Menu Start
2008-08-03 22:07 . 2008-08-03 22:14 <DIR> dr-h----- C:\Documents and Settings\GeorGe\Dane aplikacji
2008-08-03 22:07 . 2008-08-03 22:07 <DIR> d-------- C:\Documents and Settings\GeorGe
2008-08-01 00:12 . 2008-08-01 00:12 <DIR> d-------- C:\Program Files\Surreal
2008-07-29 21:53 . 2008-07-29 21:53 565 --a------ C:\WINDOWS\eReg.dat
2008-07-29 21:17 . 2008-07-29 21:17 <DIR> d-------- C:\Program Files\Maxis
2008-07-27 20:53 . 2008-07-27 20:56 <DIR> d-------- C:\Program Files\Kurka Wodna 3
2008-07-25 00:08 . 2008-07-25 00:24 <DIR> d-------- C:\Documents and Settings\us\Dane aplikacji\Hide IP NG
2008-07-21 10:34 . 2008-07-21 10:39 20 --a------ C:\sccfg.sys
2008-07-16 12:06 . 2008-07-16 12:11 <DIR> d-------- C:\Program Files\A4Proxy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-05 09:08 --------- d-----w C:\Program Files\eMule
2008-08-03 19:47 --------- d-----w C:\Program Files\Ubisoft
2008-08-03 19:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-31 21:31 --------- d-----w C:\Program Files\SpeedFan
2008-07-30 16:42 --------- d--h--w C:\Program Files\Valve
2008-07-25 19:40 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-07-21 18:28 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-02 21:41 2,211,328 ----a-w C:\WINDOWS\system32\kernel1.exe
2008-07-02 20:56 --------- d-----w C:\Program Files\OneStepSearch
2008-07-02 10:31 --------- d-----w C:\Program Files\SEGA
2008-07-01 12:43 --------- d-----w C:\Program Files\SubEdit-Player
2008-06-22 20:51 --------- d-----w C:\Program Files\3do
2008-06-22 20:49 --------- d-----w C:\Documents and Settings\us\Dane aplikacji\Corel
2008-06-22 20:43 --------- d-----w C:\Documents and Settings\us\Dane aplikacji\Gearbox Software
2008-06-20 17:37 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:44 360,960 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:32 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 18:01 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2008-03-25 18:36 88 --sh--r C:\Documents and Settings\All Users\Dane aplikacji\F68B7C3427.sys
2008-03-25 18:36 2,516 --sha-w C:\Documents and Settings\All Users\Dane aplikacji\KGyGaAvL.sys
2004-07-22 09:51 3,432,656 ----a-w C:\Program Files\ManagedDX.CAB
2004-07-19 21:58 1,156,363 ----a-w C:\Program Files\BDANT.cab
2004-07-19 21:53 976,020 ----a-w C:\Program Files\BDAXP.cab
2004-07-09 13:17 13,265,040 ----a-w C:\Program Files\dxnt.cab
2004-07-09 08:13 703,080 ----a-w C:\Program Files\BDA.cab
2004-07-09 08:13 15,493,481 ----a-w C:\Program Files\DirectX.cab
2004-07-09 03:08 472,576 ----a-w C:\Program Files\dxsetup.exe
2004-07-09 03:08 2,242,560 ----a-w C:\Program Files\dsetup32.dll
2004-07-09 02:03 62,976 ----a-w C:\Program Files\DSETUP.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-05-10 16:36 2111176]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 19:25 1961984]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 20:31 1372160]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-29 17:09 171464]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 16:57 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 16:38 78008]
"D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-07-22 10:42 1519616]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 17:49 49152]
C:\Documents and Settings\us\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50 113664]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\Program Files\\TGTSoft\\StyleXP\\Logon\\CurrentLogon.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
R2 AVKProxy;AVKProxy;C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe [2005-12-19 14:12]
R2 GDTdiInterceptor;GDTdiInterceptor;C:\WINDOWS\system32\drivers\GDTdiIcpt.sys [2007-05-06 13:57]
R3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
S3 GDInterceptor;GDInterceptor;C:\WINDOWS\system32\interceptor.sys [2007-05-06 13:57]
S3 Hl_mull;Hl_mull;C:\WINDOWS\system32\drivers\hl_mull.SYS [2003-10-10 17:15]
S3 HookCentre;HookCentre;C:\WINDOWS\system32\drivers\HookCentre.sys [2007-05-06 13:57]
S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a1233d2-02cb-11dc-afb6-00179a7be981}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - Recycled\ctfmon.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-05 17:57:46
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-05 17:58:32
ComboFix-quarantined-files.txt 2008-08-05 15:58:29
ComboFix2.txt 2008-08-05 15:54:06
Pre-Run: 16,528,834,560 bajtów wolnych
Post-Run: 16,522,883,072 bajtów wolnych
125 --- E O F --- 2008-08-04 16:48:51