- Kod: Zaznacz wszystko
ComboFix 07-11-08.1 - Matush 2007-11-08 19:54:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.643 [GMT 1:00]
Running from: C:\Documents and Settings\Matush\Pulpit\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9PLUGIN.DLL
C:\Program Files\myglobalsearch\bar\1.bin\MGSBAR.DLL
C:\Program Files\myglobalsearch\bar\1.bin\NPMYGLSH.DLL
C:\Program Files\myglobalsearch\bar\Cache\[u]0[/u]00268E1
C:\Program Files\myglobalsearch\bar\Cache\[u]0[/u]0026C5C
C:\Program Files\myglobalsearch\bar\Cache\[u]0[/u]0026DE3.bin
C:\Program Files\myglobalsearch\bar\Cache\[u]0[/u]0027063.bin
C:\Program Files\myglobalsearch\bar\Cache\[u]0[/u]00272E4.bin
C:\Program Files\myglobalsearch\bar\Cache\files.ini
C:\Program Files\myglobalsearch\bar\History\search
C:\Program Files\myglobalsearch\bar\Settings\prevcfg.htm
.
((((((((((((((((((((((((( Files Created from 2007-10-08 to 2007-11-08 )))))))))))))))))))))))))))))))
.
2007-11-08 19:53 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-07 20:16 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
2007-11-04 20:03 <DIR> d-------- C:\Program Files\IrfanView
2007-11-04 13:11 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-11-04 13:11 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-11-04 13:11 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-11-04 13:11 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2007-11-04 13:11 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-11-04 13:11 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-11-04 13:11 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2007-11-04 13:11 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2007-11-04 10:10 <DIR> d-------- C:\Downloads
2007-11-03 11:11 <DIR> d-------- C:\Documents and Settings\Matush\Dane aplikacji\Azureus
2007-11-03 11:11 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Azureus
2007-10-27 18:32 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-10-27 18:32 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-10-27 18:32 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2007-10-27 18:32 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-10-27 18:32 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2007-10-27 18:32 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-10-23 15:24 <DIR> d-------- C:\WINDOWS\system32\Futuremark
2007-10-23 15:24 <DIR> d-------- C:\Program Files\Common Files\Futuremark Shared
2007-10-23 15:24 <DIR> d-------- C:\Documents and Settings\Matush\Dane aplikacji\InstallShield
2007-10-23 15:24 27,672 -ra------ C:\WINDOWS\system32\drivers\Entech.sys
2007-10-23 15:11 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\NVIDIA
2007-10-23 14:39 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2007-10-23 14:39 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-10-23 14:38 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-10-23 14:38 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2007-10-23 14:38 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-23 14:38 <DIR> d-------- C:\Program Files\AGEIA Technologies
2007-10-23 13:43 <DIR> d-------- C:\totalcmd
2007-10-23 13:43 545 --a------ C:\WINDOWS\UC.PIF
2007-10-23 13:43 545 --a------ C:\WINDOWS\RAR.PIF
2007-10-23 13:43 545 --a------ C:\WINDOWS\PKZIP.PIF
2007-10-23 13:43 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2007-10-23 13:43 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2007-10-23 13:43 545 --a------ C:\WINDOWS\LHA.PIF
2007-10-23 13:43 545 --a------ C:\WINDOWS\ARJ.PIF
2007-10-22 16:07 <DIR> d-------- C:\WINDOWS\system32\pl-pl
2007-10-18 18:58 <DIR> d-------- C:\Documents and Settings\Matush\Gadu-Gadu
2007-10-14 09:35 <DIR> d-------- C:\Program Files\AMD
2007-10-14 09:35 43,008 --a------ C:\WINDOWS\system32\drivers\AmdK8.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-08 17:24 --------- d-----w C:\Program Files\Neostrada TP
2007-11-04 11:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-03 21:07 --------- d-----w C:\Documents and Settings\Matush\Dane aplikacji\Skype
2007-11-03 10:01 --------- d-----w C:\Documents and Settings\Matush\Dane aplikacji\uTorrent
2007-10-20 11:36 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Test Drive Unlimited
2007-10-13 22:53 --------- d-----w C:\Program Files\KEMailKb
2007-10-08 15:18 12,528 ----a-w C:\windows\system32\drivers\secdrv.sys
2007-10-06 11:46 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-09-30 10:55 --------- d-----w C:\Program Files\Common Files\Adobe
2007-09-20 16:07 --------- d-----w C:\Program Files\Common Files\BinarySense
2007-09-20 13:30 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2007-09-19 18:38 --------- d-----w C:\Documents and Settings\Matush\Dane aplikacji\BinarySense
2007-09-16 17:57 28,672 ----a-w C:\windows\gscr.dll
2007-09-16 17:57 2,339,370 ----a-w C:\windows\NHscreen01.exe
2007-09-16 17:57 146,608 ----a-w C:\windows\NHscreen01.scr
2007-09-12 20:28 --------- d-----w C:\Program Files\Common Files\DirectX
2007-09-12 20:28 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Trymedia
2007-09-12 20:25 --------- d-----w C:\Program Files\Trymedia
2007-09-12 06:14 --------- d-----w C:\Documents and Settings\Matush\Dane aplikacji\Pioneer
2007-09-11 19:00 --------- d-----w C:\Program Files\uTorrent
2007-09-10 18:01 --------- d-----w C:\Documents and Settings\Matush\Dane aplikacji\CyberLink
2007-09-10 17:57 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\CyberLink
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 10:22]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 10:22 C:\WINDOWS\system32\nvmctray.dll]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 03:07]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\smax4.exe" [2006-04-10 08:19]
"KEMailKb"="C:\PROGRA~1\KEMailKb\KEMailKb.EXE" [2003-10-21 19:47]
"avast!"="E:\Avast\ashDisp.exe" [2007-09-06 11:06]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2006-03-02 13:00]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Matush^Menu Start^Programy^Autostart^HDDlife.lnk]
path=C:\Documents and Settings\Matush\Menu Start\Programy\Autostart\HDDlife.lnk
backup=C:\windows\pss\HDDlife.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
"C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\windows\system32\drivers\sfsync03.sys
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\windows\system32\DRIVERS\msikbd2k.sys
R1 sdpiosys;sdpiosys;C:\windows\system32\drivers\sdpiosys.sys
R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\windows\system32\Drivers\DKbFltr.sys
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-08 19:57:00
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************