ComboFix 08-10-30.13 - Paweł 2008-10-31 19:02:46.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.581 [GMT 1:00]
Uruchomiony z: C:\Documents and Settings\Paweł\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2008-09-28 do 2008-10-31 )))))))))))))))))))))))))))))))
.
2008-10-31 18:27 . 2008-10-31 18:35 <DIR> d-------- C:\Program Files\Nowe Gadu-Gadu
2008-10-31 18:27 . 2008-10-31 18:28 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\Nowe Gadu-Gadu
2008-10-30 17:51 . 2008-10-30 18:01 <DIR> d-------- C:\Program Files\Miranda IM
2008-10-30 17:51 . 2008-10-30 17:51 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\Miranda
2008-10-29 21:31 . 2008-10-29 21:31 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-10-26 22:22 . 2008-10-15 17:36 337,408 -----c--- C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-19 12:42 . 2008-10-19 12:42 <DIR> dr-hs---- C:\RESTORE
2008-10-18 14:06 . 2008-10-31 17:51 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\skypePM
2008-10-18 14:06 . 2008-10-18 14:06 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-10-18 14:03 . 2008-10-18 14:03 <DIR> d-------- C:\Program Files\Skype
2008-10-18 14:03 . 2008-10-18 14:03 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-10-18 14:03 . 2008-10-31 19:06 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\Skype
2008-10-18 14:03 . 2008-10-18 14:03 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-10-18 11:13 . 2008-10-18 11:16 <DIR> d-------- C:\Program Files\Tlen.pl
2008-10-18 11:13 . 2008-10-18 11:14 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\Tlen.pl
2008-10-17 13:09 . 2008-04-14 18:20 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-10-17 10:50 . 2008-10-17 13:08 49 --a------ C:\WINDOWS\NeroDigital.ini
2008-10-17 08:33 . 2007-09-26 18:37 3,036,456 --a------ C:\WINDOWS\system32\BCGCBPRO860u80.dll
2008-10-17 08:33 . 2007-09-26 18:37 33,576 --a------ C:\WINDOWS\system32\BCGPOleAcc.dll
2008-10-16 23:15 . 2008-10-16 23:15 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\Media Player Classic
2008-10-16 14:44 . 2008-10-16 14:44 <DIR> d-------- C:\Program Files\Java
2008-10-16 14:44 . 2008-06-10 01:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-16 14:34 . 2008-10-17 08:34 <DIR> d-------- C:\Program Files\Nero
2008-10-16 14:24 . 2008-10-16 14:24 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\Ahead
2008-10-16 14:20 . 2008-10-16 14:34 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-10-16 14:19 . 2008-10-16 14:34 <DIR> d-------- C:\Program Files\Ahead
2008-10-16 14:14 . 2006-03-17 11:45 1,757,184 --a------ C:\WINDOWS\system32\imagX7.dll
2008-10-16 14:14 . 2008-06-23 16:36 773,120 --a------ C:\WINDOWS\system32\NEROINSTAEC43759.DB
2008-10-16 14:14 . 2006-03-17 11:45 497,296 --a------ C:\WINDOWS\system32\imagXpr7.dll
2008-10-15 22:10 . 2008-10-18 14:09 <DIR> d-------- C:\Program Files\EWB512
2008-10-15 22:10 . 2008-10-15 22:10 216,064 --a------ C:\WINDOWS\iun3405.exe
2008-10-15 12:52 . 2008-10-15 12:52 <DIR> d-------- C:\Program Files\Common Files\Java
2008-10-15 11:30 . 2008-10-15 21:23 <DIR> d-------- C:\Program Files\SopCast
2008-10-15 06:43 . 2008-08-14 14:26 2,190,464 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 06:43 . 2008-08-14 14:26 2,146,816 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 06:43 . 2008-08-14 14:26 2,067,328 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 06:43 . 2008-08-14 14:26 2,025,472 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 06:43 . 2008-09-15 16:27 1,846,656 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 06:43 . 2008-09-08 11:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-13 19:17 . 2008-10-13 19:17 13,646 --a------ C:\WINDOWS\system32\wpa.bak
2008-10-13 19:06 . 2008-10-13 19:06 <DIR> d-------- C:\Documents and Settings\LocalService\Pulpit
2008-10-13 17:28 . 2008-10-13 17:28 <DIR> d-------- C:\WINDOWS\system32\pl
2008-10-13 17:28 . 2008-10-13 17:28 <DIR> d-------- C:\WINDOWS\system32\bits
2008-10-13 17:28 . 2008-10-13 17:28 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-13 17:26 . 2008-10-13 17:26 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-10-13 12:35 . 2008-10-13 12:35 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-10-13 12:35 . 2003-06-19 00:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-10-13 12:35 . 2008-10-13 12:35 421 --a------ C:\WINDOWS\ODBC.INI
2008-10-13 12:34 . 2008-10-13 12:35 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-10-13 12:26 . 2008-10-13 17:28 <DIR> d-------- C:\WINDOWS\system32\pl-pl
2008-10-13 12:26 . 2008-10-03 18:26 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-10-13 12:26 . 2007-04-17 10:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-10-13 12:26 . 2007-03-08 06:11 1,036,288 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-10-13 12:26 . 2008-08-26 09:26 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-10-13 12:26 . 2008-08-26 09:26 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-10-13 12:26 . 2008-08-26 09:26 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-10-13 12:26 . 2008-08-26 09:26 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-10-13 12:26 . 2008-08-26 09:26 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-10-13 12:26 . 2008-08-25 09:38 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-10-10 12:21 . 2008-10-10 12:21 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-10-10 08:28 . 2008-10-10 08:28 <DIR> d-------- C:\Program Files\Common Files\EZB Systems
2008-10-10 08:27 . 2008-10-10 08:28 <DIR> d-------- C:\Program Files\UltraISO
2008-10-10 08:00 . 2008-10-10 08:11 <DIR> d-------- C:\Program Files\CubeDesktop
2008-10-10 08:00 . 2008-10-10 08:00 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\Thinking Minds Budiling Bytes
2008-10-10 07:55 . 2008-10-10 07:56 <DIR> d-a------ C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-10-10 07:47 . 2008-10-10 07:47 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\OtakuSoftware
2008-10-10 07:36 . 2008-10-31 18:51 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2008-10-10 07:36 . 2008-10-10 07:36 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\Thunderbird
2008-10-10 07:36 . 2008-10-10 07:36 0 --a------ C:\WINDOWS\nsreg.dat
2008-10-09 22:29 . 2004-05-06 11:11 40,448 --a------ C:\Documents and Settings\Paweł\trial_setup.exe
2008-10-09 22:29 . 2004-05-06 11:11 40,448 --a------ C:\Documents and Settings\Paweł\trial_setup.exe
2008-10-09 22:22 . 2008-10-09 22:22 <DIR> d-------- C:\Program Files\PowerISO
2008-10-09 20:42 . 2008-10-31 18:47 <DIR> d-------- C:\Program Files\Kalendarz XP
2008-10-09 20:36 . 2008-10-09 20:36 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\Nero
2008-10-09 20:33 . 2008-10-16 14:15 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-10-09 20:33 . 2008-10-16 14:15 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Nero
2008-10-09 20:11 . 2008-05-22 23:22 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-10-09 20:11 . 2008-07-04 07:34 860,160 --a------ C:\WINDOWS\system32\lameACM.acm
2008-10-09 20:11 . 2008-01-10 13:15 755,027 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-10-09 20:11 . 2008-05-31 00:22 683,520 --a------ C:\WINDOWS\system32\divx.dll
2008-10-09 20:11 . 2004-01-25 17:18 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-10-09 20:11 . 2007-09-04 17:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-10-09 20:11 . 2008-01-10 13:16 159,839 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-10-09 20:11 . 2007-09-21 01:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm
2008-10-09 20:11 . 2008-05-22 23:19 81,920 --a------ C:\WINDOWS\system32\dpl100.dll
2008-10-09 20:11 . 2007-10-03 16:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2008-10-09 20:10 . 2008-10-14 23:37 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-10-09 20:10 . 2004-01-11 23:00 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-10-09 20:10 . 2008-06-12 19:36 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-10-09 20:10 . 2007-07-10 17:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-10-09 20:08 . 2008-10-14 23:40 <DIR> d-------- C:\Program Files\NAPI-PROJEKT
2008-10-09 20:08 . 2008-10-14 23:38 <DIR> d-------- C:\Program Files\ALLPlayer
2008-10-09 16:59 . 2008-10-09 16:59 <DIR> d---s---- C:\Documents and Settings\Paweł\UserData
2008-10-09 16:59 . 2008-10-09 16:59 <DIR> d---s---- C:\Documents and Settings\Paweł\UserData
2008-10-09 16:44 . 2008-10-09 16:44 <DIR> d-------- C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar
2008-10-09 16:44 . 2008-10-09 16:44 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar
2008-10-09 16:43 . 2008-10-09 16:47 <DIR> d-------- C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>
2008-10-09 16:43 . 2008-10-09 16:47 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>
2008-10-09 16:41 . 2008-10-31 18:31 <DIR> d-------- C:\Program Files\ESET
2008-10-09 16:41 . 2008-10-09 16:41 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ESET
2008-10-09 15:29 . 2006-06-27 04:40 12,800 -----c--- C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-10-09 15:29 . 2006-06-27 04:40 3,584 -----c--- C:\WINDOWS\system32\dllcache\WgaLogon.dll
2008-10-09 15:11 . 2004-08-03 23:35 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-10-09 15:06 . 2008-04-11 20:06 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-10-09 15:06 . 2008-06-14 18:36 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-10-09 15:06 . 2008-06-14 18:36 273,024 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-10-09 15:06 . 2008-05-08 15:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-10-09 14:58 . 2008-10-09 14:58 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\Gadu-Gadu
2008-10-09 14:57 . 2008-10-09 14:57 <DIR> d-------- C:\Program Files\Gadu-Gadu
2008-10-09 14:57 . 2008-10-09 14:58 <DIR> d-------- C:\Documents and Settings\Paweł\Gadu-Gadu
2008-10-09 14:57 . 2008-10-09 14:58 <DIR> d-------- C:\Documents and Settings\Paweł\Gadu-Gadu
2008-10-09 14:51 . 2008-10-09 14:51 <DIR> d-------- C:\Program Files\Opera
2008-10-09 13:57 . 2008-10-09 13:57 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-10-09 13:57 . 2008-10-09 13:57 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-10-09 13:56 . 2007-12-19 10:11 180,224 -ra------ C:\WINDOWS\system32\igfxres.dll
2008-10-09 13:54 . 2008-10-09 13:54 <DIR> d-------- C:\WINDOWS\OPTIONS
2008-10-09 13:54 . 2008-10-09 13:54 <DIR> d-------- C:\Documents and Settings\Paweł\Dane aplikacji\InstallShield
2008-10-09 13:54 . 2007-11-14 14:18 553 -r------- C:\WINDOWS\USetup.iss
2008-10-09 13:52 . 2008-10-09 13:52 <DIR> d-------- C:\Program Files\Realtek
2008-10-09 13:52 . 2008-10-20 17:16 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-10-09 13:52 . 2008-10-15 21:23 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-10-07 13:00 . 2008-04-13 19:45 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-07 13:00 . 2008-04-14 18:20 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-10-07 13:00 . 2008-04-14 17:20 14,720 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-09 12:52 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-10-07 11:49 --------- d-----w C:\Program Files\microsoft frontpage
2008-10-07 11:48 --------- d-----w C:\Program Files\Usługi online
2008-09-15 15:27 1,846,656 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-15 15:27 1,846,656 ----a-w C:\WINDOWS\system32\win32k(2).sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-26 08:27 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:26 2,146,816 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:26 2,025,472 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-21 22:14 9,728 ----a-r C:\WINDOWS\system32\RtNicProp32.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-03 14:51 16,876,032 ------r C:\WINDOWS\RTHDCPL.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\winamptb.dll" [2008-07-16 1266992]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-19 131072]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>Agent"="C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>\winampa.exe" [2008-08-04 36352]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-03 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Kalendarz XP.lnk - C:\Program Files\Kalendarz XP\Kalendarz.exe [2008-10-09 882176]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Opera\\opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"E:\\pes\\PES2008.exe"=
"C:\\Program Files\\Miranda IM\\miranda32.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-07-01 34312]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}]
C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\lin32.exe
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-DeskSpace - C:\Program Files\DeskSpace\deskspace.exe
HKCU-Run-Komunikator - C:\Program Files\Tlen.pl\tlen.exe
HKCU-Run-CubeDesktop - (no file)
.
------- Skan uzupełniający -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.pl/
O8 -: &<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Search - C:\Documents and Settings\All Users\Dane aplikacji\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\ieToolbar\resources\en-US\local\search.html
O8 -: E&ksport do programu Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-31 19:06:39
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-10-31 19:07:18
ComboFix-quarantined-files.txt 2008-10-31 18:07:16
Przed: 11,244,982,272 bajtów wolnych
Po: 12,368,084,992 bajtów wolnych
225 --- E O F --- 2008-10-26 22:19:46Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:09:50, on 2008-10-31
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>\winampa.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Kalendarz XP\Kalendarz.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Opera\Opera\profile\cache4\temporary_download\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: <a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\winamptb.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: <a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\winamptb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: <a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\winamptb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>Agent] "C:\Program Files\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a>\winampa.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Kalendarz XP.lnk = C:\Program Files\Kalendarz XP\Kalendarz.exe
O8 - Extra context menu item: &<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Search - C:\Documents and Settings\All Users\Dane aplikacji\<a href="http://www.download.net.pl/1/Winamp/">Winamp</a> Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
--
End of file - 5861 bytes




Moja zawartość
Nie podano

