ComboFix 08-11-14.01 - Malwina 2008-11-16 18:02:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.226 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Malwina\Pulpit\ComboFix.exe
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\myglobalsearch
c:\program files\myglobalsearch\bar\1.bin\M9FFXTBR.JAR
c:\program files\myglobalsearch\bar\1.bin\M9FFXTBR.MANIFEST
c:\program files\myglobalsearch\bar\1.bin\M9NTSTBR.JAR
c:\program files\myglobalsearch\bar\1.bin\M9NTSTBR.MANIFEST
c:\program files\myglobalsearch\bar\1.bin\M9PLUGIN.DLL
c:\program files\myglobalsearch\bar\1.bin\MGSBAR.DLL
c:\program files\myglobalsearch\bar\1.bin\NPMYGLSH.DLL
c:\program files\myglobalsearch\bar\Cache\
0001BD40
c:\program files\myglobalsearch\bar\Cache\
0003B632
c:\program files\myglobalsearch\bar\Cache\
003A2763.bin
c:\program files\myglobalsearch\bar\Cache\
003A2F24.bin
c:\program files\myglobalsearch\bar\Cache\
003A328F.bin
c:\program files\myglobalsearch\bar\Cache\files.ini
c:\program files\myglobalsearch\bar\History\search
c:\program files\myglobalsearch\bar\Settings\prevcfg.htm
.
((((((((((((((((((((((((( Pliki utworzone od 2008-10-16 do 2008-11-16 )))))))))))))))))))))))))))))))
.
2008-11-16 13:18 . 2008-11-16 13:18 <DIR> d-------- c:\program files\Trend Micro
2008-11-11 22:35 . 2008-11-11 22:35 <DIR> d-------- c:\documents and settings\Malwina\Dane aplikacji\muvee Technologies
2008-11-11 22:35 . 2008-11-11 22:35 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\muvee Technologies
2008-11-10 19:38 . 2008-11-12 10:22 20 ---h----- c:\documents and settings\All Users\Dane aplikacji\PKP_DLec.DAT
2008-11-10 19:36 . 2008-11-10 19:36 <DIR> d-------- c:\documents and settings\Malwina\Dane aplikacji\Apple Computer
2008-11-10 19:32 . 2008-11-10 19:32 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-10 19:31 . 2008-11-10 19:31 <DIR> d-------- c:\program files\Common Files\muvee Technologies
2008-11-10 19:31 . 2008-11-10 20:00 <DIR> d-------- c:\documents and settings\Malwina\Dane aplikacji\Nikon
2008-11-10 19:31 . 2008-11-10 19:38 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Ultima_T15
2008-11-10 19:31 . 2008-11-10 19:31 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Piano Med
2008-11-10 19:31 . 2008-11-10 19:31 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Nikon
2008-11-10 19:31 . 2008-11-10 19:38 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\EnterNHelp
2008-11-10 19:31 . 2008-11-12 10:22 20 ---h----- c:\documents and settings\All Users\Dane aplikacji\PKP_DLds.DAT
2008-11-10 19:30 . 2008-11-10 19:31 <DIR> d-------- c:\program files\Nikon
2008-11-10 19:30 . 2001-10-09 10:02 434,176 --a------ c:\windows\system32\DC120V15_32.DLL
2008-11-10 19:28 . 2008-11-10 19:29 <DIR> d-------- c:\program files\QuickTime
2008-11-10 19:28 . 2008-11-10 19:28 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Apple Computer
2008-11-10 19:25 . 2008-11-10 20:00 <DIR> d-------- c:\program files\Common Files\Nikon
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 18:31 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-10 18:27 --------- d-----w c:\program files\Common Files\InstallShield
2008-09-23 11:49 --------- d-----w c:\documents and settings\Malwina\Dane aplikacji\OpenOffice.org2
2008-09-15 15:40 1,846,272 ----a-w c:\windows\system32\win32k.sys
2008-08-20 05:38 662,016 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D023EBF-70B8-45A6-9ED5-556515FA0FE4}]
2008-04-17 08:44 398776 --a------ c:\program files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2006-09-08 1672904]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-08-16 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 79224]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-10 282624]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-16 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-11-10 118784]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\BearShare\\BearShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-05-20 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-05-20 20560]
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-16 18:04:27
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Czas ukończenia: 2008-11-16 18:05:04
ComboFix-quarantined-files.txt 2008-11-16 17:04:58
Przed: 7,172,194,304 bajtów wolnych
Po: 7,395,840,000 bajtów wolnych
105 --- E O F --- 2008-10-25 10:18:37