Microsoft Windows XP Professional 5.1.2600.0.1250.1.1045.18.279 [GMT 1:00]
Running from: C:\Documents and Settings\Karol\Pulpit\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\History\search
C:\windows\system32\a.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_npf
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-29 )))))))))))))))))))))))))))))))
.
2008-03-28 22:57 . 2008-03-28 22:57 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-17 16:42 . 2001-01-12 19:47 122,884 --a------ C:\WINDOWS\UnGins.exe
2008-03-13 18:47 . 2008-03-13 18:47 <DIR> d-------- C:\Program Files\Kubus3d
2008-03-11 20:35 . 2008-03-11 20:35 <DIR> d-------- C:\Program Files\Dream Day Wedding
2008-03-11 18:45 . 2008-03-11 18:45 <DIR> d-------- C:\Documents and Settings\Karol\Dane aplikacji\Total Eclipse
2008-03-11 18:43 . 2008-03-16 20:38 <DIR> d-------- C:\Program Files\Fashion Boutique
2008-03-10 19:59 . 2008-03-24 22:43 <DIR> d-------- C:\Program Files\Cradle Of Rome
2008-03-10 15:30 . 2008-03-10 15:30 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\TERMINAL Studio
2008-03-09 19:46 . 2008-03-24 22:43 <DIR> d-------- C:\Program Files\Sallys Salon
2008-03-09 19:46 . 2008-03-09 19:46 4,096 --a------ C:\WINDOWS\d3dx.dat
2008-03-09 18:55 . 2008-03-09 18:55 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Gogii
2008-03-09 16:46 . 2008-03-26 16:27 <DIR> d-------- C:\Program Files\Fashion Craze
2008-03-09 14:34 . 2008-03-26 16:27 <DIR> d-------- C:\Program Files\Wedding Dash
2008-03-09 14:34 . 2008-03-09 14:34 <DIR> d-------- C:\Documents and Settings\Karol\Dane aplikacji\PlayFirst
2008-03-09 14:34 . 2008-03-09 14:34 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\PlayFirst
2008-03-05 09:30 . 2008-03-05 09:30 268 --ah----- C:\sqmdata19.sqm
2008-03-05 09:30 . 2008-03-05 09:30 244 --ah----- C:\sqmnoopt19.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-29 09:23 --------- d-----w C:\Program Files\Neostrada TP
2008-03-26 15:24 --------- d-----w C:\Program Files\Różowa Pantera
2008-03-25 18:55 --------- d-----w C:\Program Files\BSplayer Pro
2008-03-19 10:10 --------- d-----w C:\Program Files\T-Media
2002-01-04 17:14 92,064 ----a-w C:\Documents and Settings\Karol\mqdmmdm.sys
2002-01-04 17:14 9,232 ----a-w C:\Documents and Settings\Karol\mqdmmdfl.sys
2002-01-04 17:14 79,328 ----a-w C:\Documents and Settings\Karol\mqdmserd.sys
2002-01-04 17:14 66,656 ----a-w C:\Documents and Settings\Karol\mqdmbus.sys
2002-01-04 17:14 6,208 ----a-w C:\Documents and Settings\Karol\mqdmcmnt.sys
2002-01-04 17:14 5,936 ----a-w C:\Documents and Settings\Karol\mqdmwhnt.sys
2002-01-04 17:14 4,048 ----a-w C:\Documents and Settings\Karol\mqdmcr.sys
2002-01-04 17:14 25,600 ----a-w C:\Documents and Settings\Karol\usbsermptxp.sys
2002-01-04 17:14 22,768 ----a-w C:\Documents and Settings\Karol\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 21:06 1135968 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2007-10-04 21:06 1135968]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 21:06 1135968]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\windows\System32\ctfmon.exe" [2001-10-26 18:29 13312]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 16:25 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS Probe"="C:\Program Files\ASUS\Probe\AsusProb.exe" [2002-12-06 15:07 617984]
"CnxDslTaskBar"="C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" [2005-07-21 21:52 278528]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2005-07-21 07:33 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2005-07-21 07:33 53248]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 19:24 32768]
"KE9801"="C:\PROGRA~1\T-Media\MMHotKey.EXE" [2001-11-19 16:27 77824]
"NeroFilterCheck"="C:\windows\System32\NeroCheck.exe" [2001-07-09 10:50 155648]
"smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 08:57 143360]
"NvCplDaemon"="C:\windows\System32\NvCpl.dll" [2005-02-24 16:32 5537792]
"nwiz"="nwiz.exe" [2005-02-24 16:32 1495040 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\windows\System32\NvMcTray.dll" [2005-02-24 16:32 86016]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-26 18:29 13312]
"Microsoft Windows Driver"="C:\windows\rundll32.exe" [ ]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - E:\Program Files\Reader\reader_sl.exe [2004-12-14 14:44:06 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56 65588]
VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [2001-12-31 20:13:55 565248]
R0 viasraid;viasraid;C:\windows\System32\DRIVERS\viasraid.sys [2003-09-05 03:25]
R3 CnxEtP;ZTE ZXDSL852 Adapter Filter Driver;C:\windows\System32\DRIVERS\CnxEtP.sys [2005-05-20 19:27]
R3 CnxEtU;ZTE ZXDSL852 Interface Device Driver;C:\windows\System32\DRIVERS\CnxEtU.sys [2005-05-20 19:27]
R3 CnxTgNW;ZTE ZXDSL852 WAN PPPoA Adapter Driver;C:\windows\System32\DRIVERS\CnxTgNW.sys [2005-05-20 19:28]
S3 siusbmod;siusbmod;C:\windows\System32\DRIVERS\siusbmod.sys []
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-29 10:27:59
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\windows\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\windows\System32\RUNDLL32.EXE
C:\windows\System32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-03-29 10:29:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-29 09:29:43
Pre-Run: 3,928,285,184 bajtów wolnych
Post-Run: 3,877,838,848 bajt˘w wolnych




Moja zawartość
Nie podano

