ComboFix 08-10-06.05 - X 2008-10-07 9:03:53.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.78 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\X\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
* Resident AV is active
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!.
((((((((((((((((((((((((( Pliki utworzone od 2008-09-07 do 2008-10-07 )))))))))))))))))))))))))))))))
.
2008-10-01 16:59 . 2008-10-01 16:59 <DIR> d-------- C:\Program Files\Croteam
2008-10-01 10:55 . 2008-10-01 10:55 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-10-01 10:53 . 2008-10-01 10:53 <DIR> d-------- C:\WINDOWS\Cache
2008-09-29 12:58 . 2008-09-29 12:58 <DIR> d-------- C:\Documents and Settings\X\Dane aplikacji\BESTplayer
2008-09-24 12:57 . 2008-09-24 12:58 1,160 --a------ C:\WINDOWS\mozver.dat
2008-09-21 12:32 . 2008-09-21 12:32 <DIR> d-------- C:\Program Files\NAPI-PROJEKT
2008-09-21 12:32 . 2008-09-21 12:32 <DIR> d-------- C:\Program Files\ALLPlayer
2008-09-21 12:16 . 2008-09-21 12:16 <DIR> d-------- C:\Documents and Settings\X\Dane aplikacji\GetRightToGo
2008-09-21 12:04 . 2008-09-21 12:06 1,226 --a------ C:\WINDOWS\bestplayer.ini
2008-09-21 12:04 . 2008-09-21 12:06 242 --a------ C:\WINDOWS\bestplayer.bbt
2008-09-21 12:04 . 2008-09-21 12:06 122 --a------ C:\WINDOWS\bestplayer.bpp
2008-09-21 12:03 . 2008-09-21 12:03 797 --a------ C:\WINDOWS\VPlayer.INI
2008-09-21 12:03 . 2008-09-21 12:03 21 --a------ C:\WINDOWS\VplayerINI.vpl
2008-09-21 10:49 . 2008-09-21 10:49 <DIR> d-------- C:\Documents and Settings\X\Dane aplikacji\Media Player Classic
2008-09-19 19:09 . 2008-09-19 19:09 <DIR> d-------- C:\Documents and Settings\X\Gadu-Gadu
2008-09-19 19:08 . 2008-09-19 19:08 <DIR> d-------- C:\Program Files\Gadu-Gadu
2008-09-15 15:09 . 2008-09-15 15:09 <DIR> d-------- C:\Documents and Settings\X\Dane aplikacji\Ahead
2008-09-15 10:29 . 2004-03-22 15:17 24,816 --a------ C:\WINDOWS\system32\mdimon.dll
2008-09-15 10:27 . 2008-09-15 10:27 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-09-13 20:28 . 2008-09-13 20:28 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-11 17:56 . 2008-09-15 10:30 556 --a------ C:\WINDOWS\ODBC.INI
2008-09-08 19:05 . 2008-09-08 19:05 <DIR> d-------- C:\My Downloads
2008-09-08 19:04 . 2008-09-08 19:04 <DIR> d-------- C:\Program Files\BearShare
2008-09-08 17:19 . 2008-09-08 17:19 <DIR> d-------- C:\Program Files\PhotoFiltre
2008-09-08 15:33 . 2008-09-08 15:33 <DIR> d-------- C:\Documents and Settings\LocalService\Menu Start
2008-09-08 15:20 . 2008-09-08 15:20 <DIR> d-------- C:\WINDOWS\provisioning
2008-09-08 15:17 . 2008-09-08 15:17 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-08 15:09 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\
002317_.tmp
2008-09-08 15:08 . 2004-08-03 22:43 15,872 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-09-08 15:04 . 2008-09-08 15:04 <DIR> d-------- C:\WINDOWS\EHome
2008-09-08 14:10 . 2008-09-08 14:10 <DIR> d-------- C:\Program Files\CCleaner
2008-09-08 14:03 . 2008-09-08 14:03 <DIR> d-------- C:\Program Files\Advanced Registry Doctor
2008-09-08 13:55 . 2008-09-08 13:55 <DIR> d-------- C:\Program Files\Unlocker
2008-09-08 13:44 . 2008-09-08 13:44 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-09-08 13:44 . 2008-09-08 13:44 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2008-09-08 13:44 . 2007-01-30 06:03 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-09-08 13:33 . 2008-09-08 13:33 <DIR> d---s---- C:\Documents and Settings\X\UserData
2008-09-08 13:29 . 2008-09-08 13:29 <DIR> d-------- C:\Program Files\ESET
2008-09-08 13:29 . 2008-09-08 13:29 502,208 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-09-08 13:29 . 2008-09-08 13:29 270,336 --a------ C:\WINDOWS\system32\imon.dll
2008-09-08 13:23 . 2008-09-08 13:23 <DIR> d-------- C:\Program Files\a-squared Free
2008-09-08 13:21 . 2008-09-08 13:21 <DIR> d-------- C:\Program Files\MyPortal
2008-09-08 13:21 . 2008-09-08 13:21 0 --ah----- C:\WINDOWS\system32\sx.inf
2008-09-08 12:43 . 2008-09-08 12:44 <DIR> d-------- C:\Documents and Settings\X\Dane aplikacji\MSN6
2008-09-08 12:43 . 2008-09-08 12:44 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\MSN6
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-17 10:20 167,424 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
2008-08-17 10:18 67,584 ----a-w C:\WINDOWS\system32\xanalyze.dll
2008-08-17 10:18 --------- d-----w C:\Program Files\Illustrate
2008-08-17 10:01 --------- d-----w C:\Program Files\Winamp
2008-08-10 08:44 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Bluetooth
2008-08-10 08:27 --------- d-----w C:\Program Files\Common Files\Ahead
2008-08-10 08:27 --------- d-----w C:\Program Files\Ahead
2008-08-07 17:13 --------- d-----w C:\Documents and Settings\X\Dane aplikacji\Teleca
2008-08-07 17:13 --------- d-----w C:\Documents and Settings\X\Dane aplikacji\Sony Ericsson
2008-08-07 17:10 --------- d-----w C:\Program Files\Sony Ericsson
2008-08-07 17:10 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-08-07 17:10 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Teleca
2008-08-07 17:10 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Sony Ericsson
2008-08-07 16:35 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-07 16:33 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-07 16:26 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-07 16:25 558,142 ----a-w C:\WINDOWS\java\Packages\WVLZPZT7.ZIP
2008-08-07 16:25 155,995 ----a-w C:\WINDOWS\java\Packages\DVD73357.ZIP
2008-08-07 16:21 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedX"="C:\PROGRA~1\MyPortal\Speed-X\SpeedX.exe" [2006-06-27 46718]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-09-08 917504]
"SoundMan"="SOUNDMAN.EXE" [2005-05-17 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BlueSoleil.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BlueSoleil.lnk
backup=C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:44 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2005-10-26 16:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 2006-09-07 19:19 15872 C:\Program Files\Unlocker\UnlockerAssistant.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\BearShare\\Bearshare.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]
*Newly Created Service* - PROCEXP90
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\X\Dane aplikacji\Mozilla\Firefox\Profiles\wiab3wjp.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-07 09:05:11
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
PROCES: C:\WINDOWS\system32\lsass.exe

C:\Program Files\Eset\pr_imon.dll
PROCES: C:\WINDOWS\explorer.exe

?:\WINDOWS\system32\comctl32.dll
.
Czas ukończenia: 2008-10-07 9:05:54
ComboFix-quarantined-files.txt 2008-10-07 07:05:52
Przed: 3 340 746 752 bajtów wolnych
Po: 3,436,085,248 bajtów wolnych
142