ComboFix 08-09-28.01 - Jacek 2008-09-29 17:32:32.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.565 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\Jacek\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
.
((((((((((((((((((((((((( Pliki utworzone od 2008-08-28 do 2008-09-29 )))))))))))))))))))))))))))))))
.
2008-09-29 15:25 . 2008-09-29 15:25 <DIR> d-------- C:\Program Files\uTorrent
2008-09-29 15:25 . 2008-09-29 15:31 <DIR> d-------- C:\Documents and Settings\Jacek\Dane aplikacji\uTorrent
2008-09-29 15:19 . 2008-09-29 15:19 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-09-29 15:17 . 2008-09-29 15:17 <DIR> d-------- C:\WINDOWS\Cache
2008-09-29 13:25 . 2008-09-29 15:28 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-09-29 12:36 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-09-29 12:36 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-09-29 11:59 . 2008-09-29 11:59 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-09-29 11:59 . 2008-09-29 11:59 <DIR> d-------- C:\Program Files\Ahead
2008-09-29 11:59 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2008-09-29 11:59 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2008-09-29 11:59 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2008-09-29 11:59 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2008-09-29 11:59 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-09-29 11:59 . 2004-03-02 17:37 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
2008-09-29 11:59 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-09-29 11:59 . 2004-03-02 17:37 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
2008-09-29 11:54 . 2008-09-29 11:54 <DIR> d-------- C:\Program Files\Common Files\HP
2008-09-29 11:54 . 2008-09-29 11:54 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\HP
2008-09-29 11:50 . 2008-09-29 11:50 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-09-29 11:47 . 2008-09-29 11:47 <DIR> d-------- C:\Program Files\Burn4Free Toolbar
2008-09-29 11:47 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-09-29 11:47 . 2004-09-29 12:12 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll
2008-09-29 11:47 . 2008-09-29 11:47 232,075 --a------ C:\WINDOWS\Burn4Free_Toolbar_Uninstaller_4515.exe
2008-09-29 11:47 . 2004-09-29 12:15 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2008-09-29 11:47 . 2004-09-29 12:09 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2008-09-29 11:47 . 2004-09-29 12:14 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe
2008-09-29 11:47 . 2004-09-29 12:08 61,440 --a------ C:\WINDOWS\system32\HPZinw12.exe
2008-09-29 11:47 . 2004-09-29 12:09 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2008-09-29 11:46 . 2008-09-29 11:57 <DIR> d-------- C:\Program Files\Burn4Free
2008-09-29 11:36 . 2008-09-29 12:38 113,661 --a------ C:\WINDOWS\hpoins07.dat
2008-09-29 11:36 . 2005-05-24 10:22 21,124 --------- C:\WINDOWS\hpomdl07.dat
2008-09-29 11:35 . 2008-09-29 11:35 <DIR> d-------- C:\Documents and Settings\Jacek\Dane aplikacji\HP
2008-09-29 11:21 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-09-29 11:21 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-09-29 11:18 . 2008-09-29 11:20 <DIR> d-------- C:\Temp\HP_WebRelease
2008-09-29 11:18 . 2008-09-29 11:18 <DIR> d-------- C:\Temp
2008-09-29 10:57 . 2008-09-29 10:57 <DIR> d-------- C:\Documents and Settings\Jacek\Dane aplikacji\ACD Systems
2008-09-29 10:56 . 2008-09-29 10:56 <DIR> d-------- C:\Program Files\ACD Systems
2008-09-29 10:56 . 2008-09-29 10:56 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ACD Systems
2008-09-29 09:30 . 2008-09-29 10:56 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-09-29 09:30 . 2008-09-29 09:30 10,368 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-09-29 09:28 . 2008-09-29 09:28 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-09-29 08:53 . 2008-09-29 08:53 <DIR> d-------- C:\WINDOWS\Sun
2008-09-29 00:23 . 2008-09-29 17:34 <DIR> d--h----- C:\Documents and Settings\Administrator\Ustawienia lokalne
2008-09-29 00:23 . 2008-09-28 19:03 <DIR> d-------- C:\Documents and Settings\Administrator\Ulubione
2008-09-29 00:23 . 2008-09-28 17:18 <DIR> d--h----- C:\Documents and Settings\Administrator\Szablony
2008-09-29 00:23 . 2008-09-28 17:33 <DIR> d-------- C:\Documents and Settings\Administrator\Pulpit
2008-09-29 00:23 . 2008-09-28 19:03 <DIR> d-------- C:\Documents and Settings\Administrator\Moje dokumenty
2008-09-29 00:23 . 2008-09-28 19:03 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Start
2008-09-29 00:23 . 2008-09-28 19:03 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dane aplikacji
2008-09-29 00:23 . 2008-09-29 00:24 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-28 20:29 . 2008-09-28 20:29 <DIR> d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Talkback
2008-09-28 20:27 . 2008-09-28 20:27 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-28 19:58 . 2004-08-04 00:44 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-09-28 19:58 . 2004-08-04 00:44 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-09-28 19:57 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-09-28 19:57 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-09-28 19:57 . 2004-08-04 00:38 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-09-28 19:57 . 2004-08-04 00:38 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-09-28 19:28 . 2008-09-29 15:50 <DIR> d-------- C:\Documents and Settings\Jacek\Dane aplikacji\Skype
2008-09-28 19:28 . 2008-09-28 19:28 <DIR> d-------- C:\Documents and Settings\Jacek\Dane aplikacji\ATI
2008-09-28 19:28 . 2008-09-28 19:28 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ATI
2008-09-28 19:22 . 2008-09-28 19:22 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-09-28 19:19 . 2008-09-28 19:22 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-09-28 19:18 . 2005-11-10 13:03 49,265 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2008-09-28 19:17 . 2008-09-28 19:17 <DIR> d-------- C:\Program Files\Real Alternative
2008-09-28 19:17 . 2008-09-28 19:17 <DIR> d-------- C:\Program Files\Media Player Classic
2008-09-28 19:17 . 2004-01-25 17:49 303,104 --a------ C:\WINDOWS\system32\RealMediaSplitter.ax
2008-09-28 19:11 . 2001-10-26 18:57 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-09-28 19:11 . 2001-08-18 00:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-09-28 19:10 . 2001-08-17 23:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-09-28 19:09 . 2004-08-04 02:35 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-09-28 19:08 . 2004-08-04 00:31 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys
2008-09-28 19:08 . 2004-08-04 01:07 14,080 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys
2008-09-28 19:08 . 2001-08-17 23:57 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys
2008-09-28 19:08 . 2001-08-17 23:58 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys
2008-09-28 19:07 . 2004-08-04 02:44 77,312 --a------ C:\WINDOWS\system32\usbui.dll
2008-09-28 19:07 . 2004-08-04 01:07 8,832 --a------ C:\WINDOWS\system32\drivers\wmiacpi.sys
2008-09-28 19:06 . 2008-09-28 18:01 63,240 --a------ C:\WINDOWS\system32\drivers\Si3112r.PNF
2008-09-28 19:06 . 2008-09-28 19:06 20,152 --a------ C:\WINDOWS\system32\drivers\INFCACHE.1
2008-09-28 19:06 . 2008-09-28 18:01 12,432 --a------ C:\WINDOWS\system32\drivers\adpu320.PNF
2008-09-28 19:06 . 2008-09-28 18:01 12,204 --a------ C:\WINDOWS\system32\drivers\nvraid.PNF
2008-09-28 19:06 . 2008-09-28 18:01 10,828 --a------ C:\WINDOWS\system32\drivers\iaAHCI.PNF
2008-09-28 19:06 . 2008-09-28 18:01 9,388 --a------ C:\WINDOWS\system32\drivers\iaStor.PNF
2008-09-28 19:06 . 2008-09-28 18:01 7,280 --a------ C:\WINDOWS\system32\drivers\viamraid.PNF
2008-09-28 19:06 . 2008-09-28 18:01 6,984 --a------ C:\WINDOWS\system32\drivers\SiSRaid.PNF
2008-09-28 19:04 . 2008-09-28 19:04 <DIR> d-------- C:\Program Files\Avira
2008-09-28 19:04 . 2008-09-28 19:04 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-09-28 19:03 . 2008-09-29 12:36 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-09-28 19:03 . 2008-09-28 19:03 <DIR> dr-h----- C:\Documents and Settings\Default User\Ustawienia lokalne
2008-09-28 19:03 . 2008-09-28 19:03 <DIR> d-------- C:\Documents and Settings\Default User\Ulubione
2008-09-28 19:03 . 2008-09-28 17:18 <DIR> d--h----- C:\Documents and Settings\Default User\Szablony
2008-09-28 19:03 . 2008-09-28 17:33 <DIR> d-------- C:\Documents and Settings\Default User\Pulpit
2008-09-28 19:03 . 2008-09-28 19:03 <DIR> d-------- C:\Documents and Settings\Default User\Moje dokumenty
2008-09-28 19:03 . 2008-09-28 19:03 <DIR> dr------- C:\Documents and Settings\Default User\Menu Start
2008-09-28 19:03 . 2008-09-28 19:03 <DIR> dr-h----- C:\Documents and Settings\Default User\Dane aplikacji
2008-09-28 19:03 . 2008-09-28 19:03 <DIR> d-------- C:\Documents and Settings\All Users\Ulubione
2008-09-28 19:03 . 2008-09-28 19:03 <DIR> d--h----- C:\Documents and Settings\All Users\Szablony
2008-09-28 19:03 . 2008-09-29 15:31 <DIR> d-------- C:\Documents and Settings\All Users\Pulpit
2008-09-28 19:03 . 2008-09-29 11:52 <DIR> dr------- C:\Documents and Settings\All Users\Menu Start
2008-09-28 19:03 . 2008-09-28 17:20 <DIR> dr------- C:\Documents and Settings\All Users\Dokumenty
2008-09-28 19:03 . 2008-09-29 15:19 <DIR> dr-h----- C:\Documents and Settings\All Users\Dane aplikacji
2008-09-28 19:02 . 2008-09-28 17:33 <DIR> d--h----- C:\Documents and Settings\Default User
2008-09-28 19:02 . 2008-09-28 17:24 <DIR> d-------- C:\Documents and Settings\All Users
2008-09-28 19:02 . 2008-09-29 00:23 <DIR> d-------- C:\Documents and Settings
2008-09-28 19:01 . 2008-09-28 17:36 237 --a------ C:\WINDOWS\system32\$winnt$.inf
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-29 09:54 --------- d-----w C:\Program Files\Hewlett-Packard
2008-09-29 09:47 --------- d-----w C:\Program Files\Hp
2008-09-28 17:48 --------- d-----w C:\Program Files\SubEdit-Player
2008-09-28 17:18 --------- d-----w C:\Program Files\Java
2008-09-28 17:16 --------- d-----w C:\Program Files\ATI Technologies
2008-09-28 17:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-28 17:14 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-28 16:24 --------- d-----w C:\Documents and Settings\Jacek\Dane aplikacji\AVGTOOLBAR
2008-09-28 16:14 --------- d-----w C:\Program Files\Skype
2008-09-28 16:14 --------- d-----w C:\Program Files\Common Files\Skype
2008-09-28 16:14 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-09-28 16:13 --------- d-----w C:\Program Files\Winamp
2008-09-28 16:09 --------- d-----w C:\Documents and Settings\Jacek\Dane aplikacji\Gadu-Gadu
2008-09-28 16:08 --------- d-----w C:\Program Files\Gadu-Gadu
2008-09-28 16:07 --------- d-----w C:\Program Files\CDex_150
2008-09-28 16:01 87,328 ----a-w C:\WINDOWS\system32\bcmwlcoi.dll
2008-09-28 16:01 1,287,552 ----a-w C:\WINDOWS\system32\drivers\BCMWL5.SYS
2008-09-28 16:01 --------- d-----w C:\Program Files\NetWaiting
2008-09-28 16:01 --------- d-----w C:\Program Files\CONEXANT
2008-09-28 16:01 --------- d-----w C:\Program Files\Broadcom
2008-09-28 15:57 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-28 15:57 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2008-09-28 15:57 --------- d-----w C:\Program Files\HPQ
2008-09-28 15:55 --------- d-----w C:\Program Files\DIFX
2008-09-28 15:55 --------- d-----w C:\Documents and Settings\Jacek\Dane aplikacji\InstallShield
2008-09-28 15:33 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-28 15:31 --------- d-----w C:\Program Files\Common Files\Java
2008-09-28 15:23 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
2008-09-29 11:47 806912 --a------ C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll" [2008-09-29 806912]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"QlbCtrl.exe"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-10-19 202032]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 231424]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc43a4cd-8df3-11dd-aba8-0014a57bf806}]
\Shell\AutoRun\command - jopnqbe2.com
\Shell\explore\Command - jopnqbe2.com
\Shell\open\Command - jopnqbe2.com
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\Jacek\Dane aplikacji\Mozilla\Firefox\Profiles\w0qt5qza.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-29 17:34:26
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-09-29 17:35:22
ComboFix-quarantined-files.txt 2008-09-29 15:35:19
Przed: 19˙834˙064˙896 bajt˘w wolnych
Po: 19,839,447,040 bajt˘w wolnych
223