Kod:
ComboFix 08-12-28.03 - Paweł Zwoliński 2008-12-29 14:37:18.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.2046.1559 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Paweł Zwoliński\Moje dokumenty\ComboFix.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\hpowiax4.dll
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-28 do 2008-12-29 )))))))))))))))))))))))))))))))
.
2008-12-29 14:01 . 2008-12-29 14:01 <DIR> d-------- c:\windows\LastGood
2008-12-29 13:40 . 2008-12-29 13:40 <DIR> d-------- c:\documents and settings\Paweł Zwoliński\Dane aplikacji\Windows Search
2008-12-29 13:27 . 2008-12-29 13:27 <DIR> d-------- c:\windows\system32\GroupPolicy
2008-12-29 13:27 . 2008-12-29 13:27 <DIR> d-------- c:\program files\Windows Desktop Search
2008-12-29 13:27 . 2008-12-29 13:27 <DIR> d-------- c:\documents and settings\Paweł Zwoliński\Dane aplikacji\Windows Desktop Search
2008-12-29 13:27 . 2008-03-07 18:02 192,000 -----c--- c:\windows\system32\dllcache\offfilt.dll
2008-12-29 13:27 . 2008-03-07 18:02 98,304 -----c--- c:\windows\system32\dllcache\nlhtml.dll
2008-12-29 13:27 . 2008-03-07 18:02 29,696 -----c--- c:\windows\system32\dllcache\mimefilt.dll
2008-12-29 13:03 . 2008-12-29 13:03 <DIR> d-------- c:\program files\Windows Media Connect 2
2008-12-29 13:02 . 2008-12-29 13:02 <DIR> d-------- c:\windows\system32\LogFiles
2008-12-29 13:02 . 2008-12-29 13:02 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-12-29 13:01 . 2008-12-29 13:01 <DIR> d-------- c:\windows\system32\URTTEMP
2008-12-29 12:54 . 2008-12-29 14:33 <DIR> d-------- c:\program files\Mozilla Thunderbird
2008-12-29 12:54 . 2008-12-29 12:54 <DIR> d-------- c:\documents and settings\Paweł Zwoliński\Dane aplikacji\Thunderbird
2008-12-29 12:54 . 2008-12-29 12:54 0 --a------ c:\windows\nsreg.dat
2008-12-29 09:18 . 2008-12-29 09:18 <DIR> d-------- c:\windows\system32\VIRepair
2008-12-29 09:15 . 2008-12-29 09:15 <DIR> d-------- c:\documents and settings\Paweł Zwoliński\Dane aplikacji\ViStart
2008-12-29 09:12 . 2008-12-29 09:12 <DIR> d-------- c:\program files\ViSplore
2008-12-29 09:12 . 2008-12-29 09:12 <DIR> d-------- c:\program files\TrueTransparency
2008-12-29 09:10 . 2008-12-29 09:19 <DIR> d-------- c:\windows\system32\VITrans
2008-12-29 09:10 . 2008-12-29 09:15 <DIR> d-------- C:\VTPFiles
2008-12-29 09:10 . 2006-12-03 17:15 111,104 --a------ c:\windows\system32\Uharc.exe
2008-12-29 09:10 . 2004-11-27 19:00 94,208 --a------ c:\windows\system32\pskill.exe
2008-12-29 09:10 . 2008-12-29 09:10 78,942 --a------ c:\windows\Icon_1.ico
2008-12-29 09:10 . 2006-12-03 17:15 69,632 --a------ c:\windows\system32\moveex.exe
2008-12-29 09:10 . 2006-12-03 17:15 19,968 --a------ c:\windows\system32\reico.exe
2008-12-29 09:10 . 2006-12-03 17:14 8,636 --a------ c:\windows\system32\modifype.exe
2008-12-29 09:07 . 2008-11-11 23:22 20,480 --a------ c:\windows\system32\scrnrdr.exe
2008-12-28 23:26 . 2008-12-28 23:26 <DIR> d-------- c:\program files\MSXML 4.0
2008-12-28 22:36 . 2008-12-28 22:36 <DIR> d-------- c:\windows\Google Earth Pro 4.2
2008-12-28 22:36 . 2008-12-28 22:36 <DIR> d-------- c:\program files\Google Earth Pro 4.2
2008-12-28 22:35 . 2008-12-28 22:35 <DIR> d-------- c:\program files\SubEdit-Player
2008-12-28 22:34 . 2008-12-28 22:34 <DIR> d-------- c:\windows\system32\Adobe
2008-12-28 22:23 . 2008-12-28 22:23 0 --a------ c:\windows\qfe35.tmp
2008-12-28 22:22 . 2008-12-28 22:22 0 --a------ c:\windows\qfe33.tmp
2008-12-28 22:18 . 2008-12-29 13:13 9,964 --ah----- c:\windows\system32\mlfcache.dat
2008-12-28 22:06 . 2008-12-28 22:32 <DIR> d-------- c:\documents and settings\Paweł Zwoliński\Dane aplikacji\GetRightToGo
2008-12-28 21:47 . 2008-12-29 13:27 <DIR> d-------- c:\windows\system32\pl-pl
2008-12-28 21:47 . 2008-12-28 21:47 <DIR> d-------- c:\windows\system32\pl
2008-12-28 21:47 . 2008-12-28 21:47 <DIR> d-------- c:\windows\system32\bits
2008-12-28 21:47 . 2008-12-28 21:47 <DIR> d-------- c:\windows\l2schemas
2008-12-28 21:45 . 2008-12-28 21:47 <DIR> d-------- c:\windows\ServicePackFiles
2008-12-28 21:41 . 2008-12-28 21:41 <DIR> d-------- c:\windows\EHome
2008-12-28 21:36 . 2008-12-28 21:36 <DIR> d---s---- c:\documents and settings\Paweł Zwoliński\UserData
2008-12-28 21:36 . 2008-12-28 21:36 <DIR> d---s---- c:\documents and settings\Paweł Zwoliński\UserData
2008-12-28 20:55 . 2008-12-28 20:55 <DIR> d-------- c:\program files\Trend Micro
2008-12-28 20:18 . 2004-08-04 00:35 327,040 --------- c:\windows\system32\drivers\ati2mtaa.sys
2008-12-28 20:01 . 2008-06-14 18:36 273,024 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-28 20:01 . 2008-08-14 11:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-12-28 19:58 . 2008-10-16 02:02 1,499,136 -----c--- c:\windows\system32\dllcache\shdocvw.dll
2008-12-28 19:58 . 2008-10-16 02:02 668,672 -----c--- c:\windows\system32\dllcache\wininet.dll
2008-12-28 19:58 . 2008-10-16 02:02 619,520 -----c--- c:\windows\system32\dllcache\urlmon.dll
2008-12-28 19:58 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-12-28 19:55 . 2008-09-15 16:27 1,846,656 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-12-28 19:54 . 2008-12-12 18:03 3,088,896 -----c--- c:\windows\system32\dllcache\mshtml.dll
2008-12-28 19:54 . 2008-08-14 14:26 2,190,464 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-28 19:54 . 2008-08-14 14:26 2,146,816 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-28 19:54 . 2008-08-14 14:26 2,067,328 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-28 19:54 . 2008-08-14 14:26 2,025,472 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-28 19:53 . 2008-04-11 20:06 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-12-28 19:53 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-28 19:53 . 2008-05-01 15:37 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2008-12-28 19:53 . 2008-05-08 15:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2008-12-28 19:52 . 2008-09-04 18:17 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-12-28 19:52 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-12-28 19:37 . 2008-12-28 19:37 <DIR> d-------- c:\program files\Safari
2008-12-28 19:37 . 2008-12-28 19:37 <DIR> d-------- c:\program files\Apple Software Update
2008-12-28 19:37 . 2008-12-28 19:37 <DIR> d-------- c:\documents and settings\Paweł Zwoliński\Dane aplikacji\Apple Computer
2008-12-28 19:37 . 2008-12-28 19:37 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Apple
2008-12-28 19:23 . 2008-12-28 19:23 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Symantec
2008-12-28 19:22 . 2008-12-29 09:19 <DIR> d-------- c:\windows\system32\drivers\NAV
2008-12-28 19:22 . 2008-12-28 19:22 <DIR> d-------- c:\program files\Windows Sidebar
2008-12-28 19:22 . 2008-12-28 19:22 <DIR> d-------- c:\program files\Symantec
2008-12-28 19:22 . 2008-12-28 19:22 <DIR> d-------- c:\program files\Norton AntiVirus
2008-12-28 19:22 . 2008-12-28 22:47 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2008-12-28 19:22 . 2008-12-28 19:22 124,464 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2008-12-28 19:22 . 2008-12-28 19:22 60,808 --a------ c:\windows\system32\S32EVNT1.DLL
2008-12-28 19:22 . 2008-12-12 04:08 36,272 -ra------ c:\windows\system32\drivers\SymIM.sys
2008-12-28 19:22 . 2008-12-28 19:22 10,635 --a------ c:\windows\system32\drivers\SYMEVENT.CAT
2008-12-28 19:22 . 2008-12-28 19:22 806 --a------ c:\windows\system32\drivers\SYMEVENT.INF
2008-12-28 19:21 . 2008-12-28 19:21 <DIR> d-------- c:\program files\NortonInstaller
2008-12-28 19:21 . 2008-12-28 19:21 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\NortonInstaller
2008-12-28 19:21 . 2008-12-28 22:46 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Norton
2008-12-28 17:32 . 2008-12-28 17:32 <DIR> d-------- c:\documents and settings\Paweł Zwoliński\Dane aplikacji\HP
2008-12-28 16:03 . 2008-12-28 16:03 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\WEBREG
2008-12-28 16:02 . 2008-12-28 16:02 <DIR> d-------- c:\documents and settings\LocalService\Dane aplikacji\HP
2008-12-28 16:00 . 2008-12-28 16:00 <DIR> d-------- c:\program files\Hewlett-Packard
2008-12-28 16:00 . 2008-12-28 16:01 <DIR> d-------- c:\program files\Common Files\HP
2008-12-28 16:00 . 2008-12-28 16:00 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2008-12-28 16:00 . 2008-12-28 16:00 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\HPSSUPPLY
2008-12-28 16:00 . 2008-12-28 16:00 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\HP
2008-12-28 15:59 . 2008-12-28 16:01 <DIR> d-------- c:\program files\HP
2008-12-28 15:56 . 2006-12-06 07:02 16,496 -ra------ c:\windows\system32\drivers\HPZipr12.sys
2008-12-28 15:55 . 2008-12-28 15:55 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-12-28 15:55 . 2008-12-28 15:55 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Hewlett-Packard
2008-12-28 15:55 . 2006-12-15 17:36 258,048 -ra------ c:\windows\system32\hpzids01.dll
2008-12-28 15:55 . 2008-12-28 16:03 140,655 --a------ c:\windows\hpoins13.dat
2008-12-28 15:55 . 2006-12-29 09:57 117,760 --a------ c:\windows\system32\hpz3l4v2.dll
2008-12-28 15:55 . 2006-12-06 07:02 49,920 -ra------ c:\windows\system32\drivers\HPZid412.sys
2008-12-28 15:55 . 2008-04-13 19:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-12-28 15:55 . 2006-12-06 07:02 21,568 -ra------ c:\windows\system32\drivers\HPZius12.sys
2008-12-28 15:55 . 2007-01-22 17:05 811 --------- c:\windows\hpomdl13.dat
2008-12-28 15:54 . 2006-12-06 06:50 892,928 -ra------ c:\windows\system32\hpotiop4.dll
2008-12-28 15:54 . 2006-12-06 07:02 364,544 -ra------ c:\windows\system32\hppldcoi.dll
2008-12-28 15:54 . 2006-12-06 07:02 309,760 -ra------ c:\windows\system32\difxapi.dll
2008-12-28 15:54 . 2006-12-06 06:50 294,912 -ra------ c:\windows\system32\hpovst11.dll
2008-12-28 15:54 . 2008-04-13 19:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-12-28 15:48 . 2008-04-13 19:45 32,128 --a------ c:\windows\system32\drivers\usbccgp.sys
2008-12-28 15:23 . 2007-11-14 00:18 553 --a------ c:\windows\USetup.iss
2008-12-28 15:08 . 2008-12-28 15:08 13,646 --a------ c:\windows\system32\wpa.bak
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-28 21:38 --------- d-----w c:\documents and settings\Paweł Zwoliński\Dane aplikacji\Winamp
2008-12-28 21:35 --------- d-----w c:\program files\Common Files\Adobe
2008-12-28 14:23 319,488 ----a-w c:\windows\HideWin.exe
2008-12-28 13:54 --------- d-----w c:\program files\SIW
2008-12-28 13:43 15,600 ----a-w c:\windows\gdrv.sys
2008-12-28 13:40 --------- d-----w c:\program files\Yahoo!
2008-12-28 13:38 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-28 13:38 --------- d-----w c:\program files\Realtek
2008-12-28 13:38 --------- d-----w c:\documents and settings\Paweł Zwoliński\Dane aplikacji\InstallShield
2008-12-28 13:31 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-28 13:29 --------- d-----w c:\documents and settings\Paweł Zwoliński\Dane aplikacji\ATI
2008-12-28 13:29 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\ATI
2008-12-28 13:15 --------- d-----w c:\program files\Winamp
2008-12-28 13:11 --------- d-----w c:\program files\Vtune ATI
2008-12-28 13:08 --------- d-----w c:\program files\Common Files\ATI Technologies
2008-12-28 13:08 --------- d-----w c:\program files\ATI Technologies
2008-12-28 12:48 --------- d-----w c:\program files\microsoft frontpage
2008-12-28 12:47 --------- d-----w c:\program files\Usługi online
2008-10-23 12:42 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:07 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 01:02 668,672 ----a-w c:\windows\system32\wininet.dll
2008-10-03 10:04 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"TBPanel"="c:\program files\Vtune ATI\TBPanel.exe" [2008-08-06 2281472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 c:\windows\RTHDCPL.exe]
"SoundMan"="SOUNDMAN.EXE" [2008-06-18 c:\windows\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 c:\windows\alcwzrd.exe]
"Skrót do strony właściwości High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 SymEFA;Symantec Extended File Attributes;\SystemRoot\\SystemRoot\System32\Drivers\NAV\1002000.007\SYMEFA.SYS []
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\Drivers\NAV\1002000.007\BHDrvx86.sys [2008-12-29 255536]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\Drivers\NAV\1002000.007\ccHPx86.sys [2008-12-29 362544]
R1 IDSxpx86;IDSxpx86;\??\c:\documents and settings\All Users\Dane aplikacji\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20081220.001\IDSxpx86.sys [2008-12-28 274808]
R2 Norton AntiVirus;Norton AntiVirus;"c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe" /s "Norton AntiVirus" /m "c:\program files\Norton AntiVirus\Engine\16.2.0.7\diMaster.dll" /prefetch:1 []
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-28 99376]
S2 .norton2009Reset;Norton 2009 Reset;c:\documents and settings\All Users\Dane aplikacji\Norton\Norton2009Reset.exe [2008-12-28 280833]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Zawartość folderu 'Zaplanowane zadania'
2008-12-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-LClock - c:\program files\LClock\lclock.exe
HKCU-Run-ViStart - c:\program files\ViStart\ViStart.exe
HKCU-Run-VisualTooltip - c:\program files\VisualTooltip\VisualToolTip.exe
HKLM-Run-DrvIcon - c:\program files\Vista Drive Icon\DrvIcon.exe
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 14:38:13
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.2.0.7\diMaster.dll\" /prefetch:1"
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(980)
c:\windows\system32\Ati2evxx.dll
.
Czas ukończenia: 2008-12-29 14:38:40
ComboFix-quarantined-files.txt 2008-12-29 13:38:38
ComboFix2.txt 2008-12-28 19:58:50
Przed: 19*451*363*328 bajtów wolnych
Po: 19,462,029,312 bajtów wolnych
231 --- E O F --- 2008-12-29 13:01:39
Mianowicie zamiast polecenia "Otwórz" na pierwszym miejscu mam "Wyszukaj". Jest tak w każdym folderze na każdym dysku...
Jakimś cudem foldery otwierają się teraz w osobnych oknach, ale to i tak mnie niepokoi...