ComboFix 10-08-17.03 - jendru 2010-08-18 14:48:43.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.2046.1418 [GMT 2:00] Uruchomiony z: c:\documents and settings\jendru\Pulpit\ComboFix.exe AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !! . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\jendru\Dane aplikacji\avdrn.dat c:\documents and settings\jendru\Menu Start\Programy\Autostart\winiyw32.exe C:\Thumbs.db c:\windows\settings.reg c:\windows\system32\Data c:\windows\system32\fjhdyfhsn.bat H:\Autorun.inf . ((((((((((((((((((((((((( Pliki utworzone od 2010-07-18 do 2010-08-18 ))))))))))))))))))))))))))))))) . 2010-08-18 12:58 . 2010-08-18 13:01 -------- d-----w- c:\windows\LastGood 2010-08-18 12:02 . 2010-08-18 12:34 -------- d-----w- c:\windows\system32\NtmsData 2010-08-18 08:42 . 2010-08-18 08:42 -------- d-----w- c:\windows\system32\CatRoot_bak 2010-08-17 21:34 . 2008-04-13 22:50 90313 -c--a-w- c:\windows\system32\dllcache\ndis.sys 2010-08-17 21:26 . 2010-08-18 08:42 -------- d-----w- c:\documents and settings\jendru\Dane aplikacji\WinMount 2010-08-17 21:26 . 2010-08-18 08:42 -------- d-----w- c:\program files\WinMount 2010-08-17 21:26 . 2010-08-17 21:26 67336 ----a-w- c:\windows\system32\drivers\WMDrive.sys 2010-08-17 21:20 . 2010-08-17 21:20 -------- d-----w- c:\windows\system32\wbem\Repository 2010-08-17 20:35 . 2010-08-18 08:42 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Microsoft 2010-08-17 20:35 . 2010-08-18 08:42 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne 2010-08-17 20:35 . 2010-08-18 08:42 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji 2010-08-17 20:35 . 2010-08-18 08:41 -------- d-----w- c:\documents and settings\Administrator\Szablony 2010-08-17 20:35 . 2010-04-07 18:15 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Google 2010-08-17 20:35 . 2010-03-08 09:31 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Adobe 2010-08-17 20:35 . 2010-03-03 22:03 -------- d-----w- c:\documents and settings\Administrator\IETldCache 2010-08-17 20:35 . 2010-08-18 08:42 -------- d-s---w- c:\documents and settings\Administrator 2010-08-17 19:40 . 2010-08-18 08:42 -------- d-----w- c:\program files\Windows Doctor 2010-08-17 17:02 . 2010-08-17 17:02 33792 ----a-w- c:\windows\system32\config\systemprofile\voflmvyns.exe 2010-08-17 17:02 . 2010-08-17 17:02 33792 ----a-w- c:\windows\system32\voflmvyns.exe 2010-08-17 11:10 . 2010-08-17 11:10 585504 ----a-w- c:\windows\system32\drivers\mqgmu.sys 2010-08-04 16:09 . 2010-08-04 16:09 664 ----a-w- c:\windows\system32\d3d9caps.dat . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-08-18 13:04 . 2010-03-03 22:18 585504 ----a-w- c:\windows\system32\drivers\aec.sys 2010-08-18 11:30 . 2010-03-04 13:33 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab 2010-08-18 08:42 . 2010-06-17 09:25 -------- d-----w- c:\program files\SpeedFan 2010-08-17 20:15 . 2010-03-04 10:25 -------- d-----w- c:\program files\REALTEK 2010-08-17 20:15 . 2010-03-03 22:14 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-08-17 19:58 . 2010-03-04 09:31 -------- d-----w- c:\documents and settings\jendru\Dane aplikacji\Winamp 2010-08-17 17:02 . 2010-08-14 10:27 20 ----a-w- c:\documents and settings\NetworkService\Dane aplikacji\txvcpz.dat 2010-08-17 11:10 . 2010-08-17 11:10 20 ----a-w- c:\documents and settings\LocalService\Dane aplikacji\txvcpz.dat 2010-07-26 07:09 . 2010-06-14 17:32 188152 ------w- c:\documents and settings\jendru\Dane aplikacji\Mozilla\Firefox\Profiles\m3iz3fm9.default\FlashGot.exe 2010-07-26 07:06 . 2010-03-08 09:27 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\NOS 2010-07-23 19:15 . 2010-03-05 22:43 -------- d-----w- c:\program files\JDownloader 2010-07-18 16:39 . 2010-07-18 16:39 -------- d-----w- c:\documents and settings\jendru\Dane aplikacji\MPEG Streamclip 2010-07-16 07:42 . 2010-07-16 07:42 88600707 ------w- C:\Chris Cornell.zip 2010-07-08 07:25 . 2010-03-04 10:53 -------- d-----w- c:\program files\Microsoft Silverlight 2010-07-07 23:42 . 2010-06-15 11:36 -------- d-----w- c:\documents and settings\jendru\Dane aplikacji\FileZilla 2010-07-07 08:51 . 2010-03-03 23:03 -------- d-----w- c:\program files\CDex_150 2010-06-28 09:02 . 2010-06-28 08:57 -------- d-----w- c:\documents and settings\jendru\Dane aplikacji\Apple Computer 2010-06-27 07:40 . 2010-06-27 07:40 -------- d-----w- c:\program files\OrangeBS 2010-06-27 07:34 . 2010-06-27 07:34 -------- d-----w- c:\program files\Common Files\France Telecom 2010-06-27 07:32 . 2010-06-27 07:32 -------- d-----w- c:\program files\CardDetector 2010-06-22 21:14 . 2010-03-08 09:30 -------- d-----w- c:\program files\Common Files\Adobe 2010-06-21 07:33 . 2010-03-04 09:30 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\FLEXnet 2010-06-20 12:38 . 2010-03-14 12:54 -------- d-----w- c:\program files\ALLPlayer 2010-06-20 12:38 . 2010-03-14 12:54 -------- d-----w- c:\program files\NAPI-PROJEKT 2010-06-17 12:03 . 2010-01-21 22:47 50968 ----a-w- c:\windows\system32\perfc015.dat 2010-06-17 12:03 . 2010-01-21 22:47 359178 ----a-w- c:\windows\system32\perfh015.dat 2010-06-15 18:01 . 2010-06-15 18:01 865792 ------w- c:\documents and settings\jendru\Dane aplikacji\Mozilla\Firefox\Profiles\m3iz3fm9.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\WINNT_x86-msvc\components\pagespeed.dll 2010-03-04 13:41 . 2010-03-04 13:41 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat . ------- Sigcheck ------- [-] 2008-04-13 22:50 . B1ABE70CF1D867257B87D3260C53E8E2 . 90313 . . [------] . . c:\windows\system32\dllcache\ndis.sys [-] 2010-01-21 . C8BDAD4065118558B3DC360FC96D81DB . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll [-] 2010-08-18 13:07 . !HASH: COULD NOT OPEN FILE !!!!! . 585504 . . [------] . . c:\windows\system32\drivers\aec.sys [-] 2008-04-13 20:09 . !HASH: COULD NOT OPEN FILE !!!!! . 142592 . . [------] . . c:\windows\system32\dllcache\aec.sys c:\windows\System32\drivers\ndis.sys ... - brak elementu !! . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MountOverlayIcon] @="{0F49CF41-FD97-4942-9F2A-35E8B489E7FB}" [HKEY_CLASSES_ROOT\CLSID\{0F49CF41-FD97-4942-9F2A-35E8B489E7FB}] 2010-07-19 08:39 204288 ----a-w- c:\program files\WinMount\WinMTExt.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2010-03-23 1432064] "Gadu-Gadu 10"="c:\program files\Gadu-Gadu 10\gg.exe" [2010-01-20 12067432] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344] "P17Helper"="P17.dll" [2005-05-03 64512] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-01-12 37888] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832] "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-11-02 2508104] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-17 7700480] "nwiz"="nwiz.exe" [2006-11-17 1622016] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-17 86016] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888] "CardDetectorICON515_UCAN"="c:\program files\CardDetector\ICON515_UCAN\CardDetector.exe" [2009-10-14 282624] "BEWINTERNET-PLSessionManager"="c:\program files\OrangeBS\BEWInternet-PL\SessionManager\SessionManager.exe" [2009-10-14 140016] "voflmvyns"="c:\windows\System32\voflmvyns.exe" [2010-08-17 33792] "avp"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-07-03 303376] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2010-01-21 15360] c:\documents and settings\All Users\Menu Start\Programy\Autostart\ REALTEK RTL8187B Wireless LAN Utility.lnk - c:\program files\REALTEK\RTL8187B Wireless LAN Utility\RtWLan.exe [2010-3-4 966656] Send Crash Reports to FotoWare.lnk - c:\windows\Installer\{B52C1A3B-A9FC-49EF-909A-3373A21BC610}\NewShortcut1.CC6BC988_E897_4B98_94B4_10417EFCE47E.exe [2010-3-4 45056] [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\REALTEK\\RTL8187B Wireless LAN Utility\\RtWLan.exe"= "c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= "c:\\Program Files\\Gadu-Gadu 10\\gg.exe"= "c:\\totalcmd\\TOTALCMD.EXE"= "c:\\Program Files\\OrangeBS\\BEWInternet-PL\\Connectivity\\ConnectivityManager.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "1542:TCP"= 1542:TCP:Realtek WPS TCP Prot "1542:UDP"= 1542:UDP:Realtek WPS UDP Prot "53:UDP"= 53:UDP:Realtek AP UDP Prot "5353:TCP"= 5353:TCP:Adobe CSI CS4 R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-12-15 33808] R0 Si3124;Si3124;c:\windows\system32\drivers\si3124.sys [2010-01-22 69248] R0 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [2010-01-22 212520] R1 WMDrive;WMDrive;c:\windows\system32\drivers\WMDrive.sys [2010-08-17 67336] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-05-16 19472] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-15 135664] S3 GTUHSBUS;GT UHS BUS;c:\windows\system32\drivers\gtuhsbus.sys [2010-06-27 66560] S3 GTUHSNDISIPXP;GT UHS IP NDIS;c:\windows\system32\drivers\gtuhs51.sys [2010-06-27 107520] S3 GTUHSSER;GT UHS SER;c:\windows\system32\drivers\gtuhsser.sys [2010-06-27 8064] S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-05-13 31760] S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [2010-03-04 340736] . Zawartość folderu 'Zaplanowane zadania' 2010-08-10 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34] 2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-03-15 10:01] 2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-03-15 10:01] . . ------- Skan uzupełniający ------- . IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\jendru\Dane aplikacji\Mozilla\Firefox\Profiles\m3iz3fm9.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2405723&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ig FF - component: c:\documents and settings\jendru\Dane aplikacji\Mozilla\Firefox\Profiles\m3iz3fm9.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\WINNT_x86-msvc\components\pagespeed.dll FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff36\gears.dll FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll FF - plugin: c:\documents and settings\jendru\Dane aplikacji\Gadu-Gadu 10\_userdata\npgg.2.dll FF - plugin: c:\documents and settings\jendru\Dane aplikacji\Gadu-Gadu 10\_userdata\nppl3260.dll FF - plugin: c:\documents and settings\jendru\Dane aplikacji\Gadu-Gadu 10\_userdata\nprpjplug.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll FF - plugin: c:\program files\Photodex Presenter\npPxPlay.dll ---- FIREFOX - SPOSÓB POSTĘPOWANIA ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . - - - - USUNIĘTO PUSTE WPISY - - - - HKCU-Run-AdobeBridge - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-08-18 15:00 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów ... skanowanie ukrytych wpisów autostartu ... skanowanie ukrytych plików ... skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aec] "ImagePath"="system32\drivers\aec.sys" . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- - - - - - - - > 'winlogon.exe'(268) c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll - - - - - - - > 'explorer.exe'(2576) c:\windows\system32\WININET.dll c:\program files\WinMount\WinMTExt.dll c:\program files\WinMount\ShlExt\BrowserExt.dll c:\program files\WinMount\ShlExt\MountExt.dll c:\windows\system32\webcheck.dll c:\windows\system32\wpdshserviceobj.dll c:\windows\system32\portabledevicetypes.dll c:\windows\system32\portabledeviceapi.dll . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Google\Update\1.2.183.23\GoogleCrashHandler.exe c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe c:\windows\system32\nvsvc32.exe c:\program files\Photodex\ProShowProducer\ScsiAccess.exe c:\windows\system32\wbem\wmiapsrv.exe c:\windows\system32\wscntfy.exe c:\windows\system32\Rundll32.exe c:\windows\system32\dwwin.exe c:\windows\system32\dwwin.exe c:\program files\Gadu-Gadu 10\CrashReporter.exe . ************************************************************************** . Czas ukończenia: 2010-08-18 15:08:26 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2010-08-18 13:08 Przed: 1 587 314 688 bajtów wolnych Po: 6 920 900 608 bajtów wolnych - - End Of File - - 408BE5519EF7AC0345730718A31DB674