


UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
ComboFix 08-12-15.01 - pol 2008-12-15 21:07:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.3070.2486 [GMT 1:00]
Uruchomiony z: g:\programy\ComboFix.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-15 do 2008-12-15 )))))))))))))))))))))))))))))))
.
2008-12-15 18:20 . 2008-12-15 18:20 <DIR> d-------- c:\windows\LastGood
2008-12-15 15:36 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-12-15 15:36 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-12-14 12:23 . 2008-12-14 12:23 <DIR> d-------- c:\program files\Windows Defender
2008-12-14 12:03 . 2008-12-14 12:04 <DIR> d-------- c:\windows\NV39241672.TMP
2008-12-14 12:03 . 2008-09-17 23:55 201,050 --a------ c:\windows\system32\nvapps.nvb
2008-12-14 11:42 . 2008-10-16 21:33 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-12-14 11:42 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-12-14 11:42 . 2007-03-08 06:11 1,036,288 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-14 11:42 . 2008-10-16 21:33 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-12-14 11:42 . 2008-10-16 21:33 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-12-14 11:42 . 2008-10-16 21:33 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-12-14 11:42 . 2008-10-16 21:33 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-12-14 11:42 . 2008-10-16 21:33 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-14 11:42 . 2008-10-16 14:11 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-12-13 16:18 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-12-13 16:18 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-12-13 16:18 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2008-12-13 16:18 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-12-13 16:18 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-12-13 16:18 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-12-13 15:42 . 2008-12-15 20:02 116 --a------ c:\windows\NeroDigital.ini
2008-12-13 14:28 . 2008-04-14 22:51 221,184 --a------ c:\windows\system32\wmpns.dll
2008-12-13 14:07 . 2008-12-14 11:42 <DIR> d-------- c:\windows\system32\pl-pl
2008-12-13 14:06 . 2008-04-14 22:51 294,912 -----c--- c:\windows\system32\dllcache\dlimport.exe
2008-12-13 14:03 . 2008-12-13 14:03 <DIR> d-------- c:\windows\EHome
2008-12-13 11:48 . 2008-12-14 16:31 <DIR> d--hs---- c:\documents and settings\pol\UserData
2008-12-13 09:56 . 2008-06-14 18:36 273,024 --------- c:\windows\system32\drivers\bthport.sys
2008-12-13 09:56 . 2008-06-14 18:36 273,024 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-13 09:56 . 2008-08-14 11:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-12-13 09:55 . 2008-10-17 02:03 3,593,216 -----c--- c:\windows\system32\dllcache\mshtml.dll
2008-12-13 09:55 . 2008-08-14 14:26 2,190,464 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-13 09:55 . 2008-08-14 14:26 2,146,816 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-13 09:55 . 2008-08-14 14:26 2,067,328 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-13 09:55 . 2008-08-14 14:26 2,025,472 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-13 09:55 . 2008-09-15 16:27 1,846,656 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-12-13 09:55 . 2008-10-16 02:02 1,499,136 -----c--- c:\windows\system32\dllcache\shdocvw.dll
2008-12-13 09:55 . 2008-10-16 21:33 1,160,192 -----c--- c:\windows\system32\dllcache\urlmon.dll
2008-12-13 09:55 . 2008-10-16 21:33 826,368 -----c--- c:\windows\system32\dllcache\wininet.dll
2008-12-13 09:55 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-13 09:55 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-12-13 09:55 . 2008-05-08 15:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2008-12-13 09:54 . 2008-04-11 20:06 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-12-13 09:54 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-12-13 09:36 . 2008-12-13 09:36 <DIR> d-------- c:\program files\Microsoft.NET
2008-12-13 09:36 . 2003-06-19 01:31 17,920 --a------ c:\windows\system32\mdimon.dll
2008-12-13 09:36 . 2008-12-13 09:36 421 --a------ c:\windows\ODBC.INI
2008-12-13 09:35 . 2008-12-13 09:36 <DIR> d-------- c:\windows\SHELLNEW
2008-12-12 22:27 . 2008-04-14 00:15 32,128 --a------ c:\windows\system32\drivers\usbccgp.sys
2008-12-12 22:27 . 2008-04-14 22:50 21,504 --a------ c:\windows\system32\hidserv.dll
2008-12-12 22:27 . 2008-04-14 21:50 14,720 --a------ c:\windows\system32\drivers\kbdhid.sys
2008-12-12 22:26 . 2008-12-12 22:26 <DIR> d--h----- c:\documents and settings\All Users\Dane aplikacji\CanonBJ
2008-12-12 22:22 . 2008-12-12 22:22 <DIR> d-------- c:\documents and settings\pol\WINDOWS
2008-12-12 22:22 . 1998-01-23 14:15 304,640 --a------ c:\windows\IsUn0415.exe
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-15 18:56 --------- d-----w c:\program files\DC++
2008-12-15 16:26 --------- d-----w c:\program files\Odkurzacz
2008-12-14 16:08 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-14 10:24 --------- d-----w c:\documents and settings\pol\Dane aplikacji\Creative
2008-12-13 14:45 --------- d-----w c:\documents and settings\pol\Dane aplikacji\Winamp
2008-12-13 08:49 --------- d-----w c:\program files\Winamp
2008-12-12 20:56 --------- d-----w c:\program files\Common Files\Nero
2008-12-12 20:56 --------- d-----w c:\program files\Ahead
2008-12-12 20:55 --------- d-----w c:\program files\Common Files\Ahead
2008-12-12 20:52 --------- d--h--w c:\program files\CanonBJ
2008-12-12 20:41 --------- d-----w c:\program files\Java
2008-12-12 20:41 --------- d-----w c:\program files\Common Files\Java
2008-12-12 20:35 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Creative
2008-12-12 20:33 --------- d-----w c:\program files\Creative
2008-12-12 20:32 --------- d--h--w c:\program files\Creative Installation Information
2008-12-12 20:31 --------- d-----w c:\program files\Common Files\Creative
2008-12-12 20:24 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-12 20:24 --------- d-----w c:\program files\AGEIA Technologies
2008-12-12 20:19 --------- d-----w c:\program files\Picasa2
2008-12-12 20:17 --------- d-----w c:\program files\Gadu-Gadu
2008-12-12 20:15 98,304 ----a-w c:\windows\system32\qttask.exe
2008-12-12 20:15 --------- d-----w c:\program files\ACE Mega CoDecS Pack
2008-12-12 20:12 --------- d-----w c:\program files\Common Files\Adobe
2008-12-12 20:00 --------- d-----w c:\program files\Alwil Software
2008-12-12 19:55 --------- d-----w c:\program files\Realtek
2008-12-12 19:55 --------- d-----w c:\documents and settings\pol\Dane aplikacji\InstallShield
2008-12-12 19:54 16,608 ----a-w c:\windows\gdrv.sys
2008-12-12 19:53 315,392 ----a-w c:\windows\HideWin.exe
2008-12-12 19:53 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-12 19:45 --------- d-----w c:\program files\microsoft frontpage
2008-12-12 19:44 --------- d-----w c:\program files\Usługi online
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:42 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:33 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:07 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 10:04 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-15 15:27 1,846,656 ----a-w c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Odkurzacz-MCD"="c:\program files\Odkurzacz\odk_mcd.exe" [2008-12-12 263714]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 42881]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 737287]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= c:\progra~1\ACEMEG~1\SystemS\Intel\iac25_32.ax
"msacm.sl_anet"= c:\progra~1\ACEMEG~1\SystemS\sl_anet.acm
"vidc.yv12"= c:\progra~1\ACEMEG~1\SystemS\ATI\atiyuv12.DLL
"vidc.divx"= c:\progra~1\ACEMEG~1\SystemS\DivX\DivX520.dll
"vidc.iyuv"= c:\progra~1\ACEMEG~1\SystemS\Intel\iyuv_32.dll
"vidc.yvu9"= c:\progra~1\ACEMEG~1\SystemS\Intel\Iyvu9_32.dll
"vidc.uyvy"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yuy2"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yvyu"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"msacm.msaudio1"= c:\progra~1\ACEMEG~1\SystemS\MICROS~1\msaud32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-12 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-12 20560]
R2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
*Newly Created Service* - PROCEXP90
.
Zawartość folderu 'Zaplanowane zadania'
2008-12-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.onet.pl/
uInternet Connection Wizard,ShellNext = hxxp://www.onet.pl/
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
c:\windows\system32\ArcaMicroScanUpdater.exe - c:\windows\system32\ArcaOnlineUninstall.exe
c:\windows\system32\ArcaOnline.dll
O16 -: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D}
hxxp://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
c:\windows\Downloaded Program Files\ArcaOnline.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-15 21:07:46
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-12-15 21:08:10
ComboFix-quarantined-files.txt 2008-12-15 20:08:01
Przed: 23 108 464 640 bajtów wolnych
Po: 23,381,540,864 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut
188 --- E O F --- 2008-12-15 16:00:34
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
UA: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
UA: Opera/9.62 (Windows NT 5.1; U; pl) Presto/2.1.1
Zarejestrowani użytkownicy: Bing [Bot]