ComboFix 12-03-30.06 - Mariusz 2012-03-30 19:06:51.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.48.1045.18.2047.760 [GMT 2:00] Uruchomiony z: c:\users\Mariusz\Desktop\ComboFix.exe AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Mariusz\AppData\Local\unins000.exe c:\users\Mariusz\AppData\Roaming\antivirus protection 2012 c:\users\Mariusz\AppData\Roaming\antivirus protection 2012\IcoActivate.ico c:\users\Mariusz\AppData\Roaming\antivirus protection 2012\IcoHelp.ico c:\users\Mariusz\AppData\Roaming\antivirus protection 2012\IcoUninstall.ico c:\users\Mariusz\AppData\Roaming\KBDIRZ.dll c:\users\Mariusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection 2012 c:\users\Mariusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection 2012\Help Antivirus Protection 2012.lnk c:\users\Mariusz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection 2012\How to Activate Antivirus Protection 2012.lnk c:\windows\IsUn0415.exe c:\windows\UA000088.DLL . . ((((((((((((((((((((((((( Pliki utworzone od 2012-02-28 do 2012-03-30 ))))))))))))))))))))))))))))))) . . 2012-03-30 17:18 . 2012-03-30 17:18 -------- d-----w- c:\users\Mariusz\AppData\Local\temp 2012-03-30 14:16 . 2012-03-30 14:16 -------- d-----w- c:\users\Mariusz\DoctorWeb 2012-03-30 13:57 . 2012-03-30 13:57 -------- d-----w- c:\users\Mariusz\AppData\Roaming\Malwarebytes 2012-03-30 13:57 . 2012-03-30 13:57 -------- d-----w- c:\programdata\Malwarebytes 2012-03-30 13:57 . 2012-03-30 14:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-03-30 13:57 . 2011-12-10 13:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-03-29 19:35 . 2012-03-29 20:13 -------- d-----w- c:\program files\Common Files\PC Tools 2012-03-29 19:35 . 2012-02-24 08:36 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys 2012-03-29 19:35 . 2012-03-29 19:59 -------- d-----w- c:\programdata\PC Tools 2012-03-29 19:35 . 2012-03-29 19:35 -------- d-----w- c:\users\Mariusz\AppData\Roaming\TestApp 2012-03-29 17:49 . 2012-03-29 17:49 -------- d-----w- c:\program files\Common Files\Java 2012-03-29 17:48 . 2012-03-29 17:48 -------- d-----w- c:\program files\Java 2012-03-28 03:46 . 2012-03-14 02:15 6582328 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8FC2E654-5F3B-48F9-8753-E4B6C9838931}\mpengine.dll 2012-03-19 04:52 . 2012-03-19 04:52 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll 2012-03-19 04:52 . 2012-03-19 04:52 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll 2012-03-17 15:58 . 2012-03-17 15:58 -------- d-----w- c:\users\Mariusz\AppData\Roaming\Ubisoft 2012-03-16 17:02 . 2008-07-12 07:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll 2012-03-16 17:02 . 2008-07-12 07:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll 2012-03-16 17:02 . 2008-07-12 07:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll 2012-03-14 04:40 . 2012-02-02 15:16 2044416 ----a-w- c:\windows\system32\win32k.sys 2012-03-14 04:40 . 2012-02-14 15:45 219648 ----a-w- c:\windows\system32\d3d10_1core.dll 2012-03-14 04:40 . 2012-02-13 14:12 1172480 ----a-w- c:\windows\system32\d3d10warp.dll 2012-03-14 04:40 . 2012-02-13 13:44 1068544 ----a-w- c:\windows\system32\DWrite.dll 2012-03-14 04:40 . 2012-02-14 15:45 160768 ----a-w- c:\windows\system32\d3d10_1.dll 2012-03-14 04:40 . 2012-02-13 13:47 683008 ----a-w- c:\windows\system32\d2d1.dll 2012-03-14 04:40 . 2012-01-31 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat 2012-03-14 04:40 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll 2012-03-14 04:40 . 2012-01-09 13:58 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-13 17:02 . 2012-03-14 16:41 -------- d-----w- c:\program files\Square Enix 2012-03-13 01:21 . 2010-02-18 11:28 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys 2012-03-13 01:21 . 2010-02-18 13:30 200704 ----a-w- c:\windows\system32\iphlpsvc.dll 2012-03-12 19:10 . 2012-03-12 19:10 -------- d-----w- c:\users\Mariusz\AppData\Roaming\Auslogics 2012-03-12 19:09 . 2012-03-12 19:09 -------- d-----w- c:\program files\Auslogics 2012-03-05 14:48 . 2012-03-12 15:18 -------- d-----w- c:\program files\Microids 2012-03-05 14:47 . 2001-09-05 02:18 77824 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll 2012-03-05 14:47 . 2001-09-05 02:18 225280 ------w- c:\program files\Common Files\InstallShield\IScript\iscript.dll 2012-03-05 14:47 . 2001-09-05 02:14 176128 ------w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll 2012-03-05 14:47 . 2001-09-05 02:13 32768 ------w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll 2012-03-03 12:39 . 2012-03-03 12:39 -------- d-----w- c:\users\Mariusz\AppData\Roaming\Canneverbe Limited 2012-03-03 12:39 . 2012-03-03 12:39 -------- d-----w- c:\programdata\Canneverbe Limited 2012-03-03 12:38 . 2012-03-03 12:38 -------- d-----w- c:\program files\CDBurnerXP 2012-03-02 18:19 . 2012-03-02 18:23 -------- d-----w- c:\users\Mariusz\AppData\Local\Ubisoft Game Launcher 2012-03-02 18:16 . 2012-03-02 18:16 -------- d-----w- c:\programdata\Ubisoft 2012-03-02 16:50 . 2012-03-02 16:50 98304 ----a-w- c:\windows\system32\CmdLineExt.dll 2012-03-02 16:23 . 2012-03-02 18:10 -------- d-----w- c:\program files\Assasins Creed Revelations 2012-03-02 15:14 . 2012-03-02 15:14 -------- d-----w- c:\users\Mariusz\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1 2012-03-02 15:14 . 2012-03-02 15:14 -------- d-----w- c:\program files\e-Deklaracje 2012-03-02 15:13 . 2012-03-02 15:13 -------- d-----w- c:\program files\Common Files\Adobe AIR . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-29 17:48 . 2011-05-14 11:03 472808 ----a-w- c:\windows\system32\deployJava1.dll 2012-03-17 06:22 . 2011-05-14 09:10 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-23 08:18 . 2011-05-15 00:04 237072 ------w- c:\windows\system32\MpSigStub.exe 2012-01-24 20:18 . 2012-01-24 20:18 782608 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2012-03-19 04:52 . 2011-05-14 09:14 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-05-16 39408] "MzRamBooster"="c:\program files\MzRam\MzRamBooster.exe" [2009-05-15 194560] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-08-16 10820200] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] . . --- Inne Usługi/Sterowniki w Pamięci --- . *Deregistered* - pwriifod . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Zawartość folderu 'Zaplanowane zadania' . 2012-03-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-16 17:28] . 2012-03-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-05-16 17:28] . . ------- Skan uzupełniający ------- . uStart Page = my.daemon-search.com mStart Page = hxxp://www.google.com IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 212.76.34.50 212.76.34.49 FF - ProfilePath - c:\users\Mariusz\AppData\Roaming\Mozilla\Firefox\Profiles\suozdbjz.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/ FF - prefs.js: keyword.URL - hxxp://startsear.ch/?aff=1&q= . - - - - USUNIĘTO PUSTE WPISY - - - - . HKCU-Run-Ocgvvxpe - c:\users\Mariusz\AppData\Roaming\KBDIRZ.dll SafeBoot-WudfPf SafeBoot-WudfRd AddRemove-Poznaj angielski z SuperMemo - poziom podstawowy - c:\windows\IsUn0415.exe AddRemove-{81BF6353-3C5B-4E6E-A566-7E162A00BF72}_is1 - c:\users\Mariusz\AppData\Local\unins000.exe AddRemove-T-Mobile Ekstraklasa Patch - c:\users\Mariusz\Documents\fifa 12\FIFA-12-PC-PL\FIFA 12\TEK_Uninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-03-30 19:18 Windows 6.0.6002 Service Pack 2 NTFS . skanowanie ukrytych procesów ... . skanowanie ukrytych wpisów autostartu ... . skanowanie ukrytych plików ... . skanowanie pomyślnie ukończone ukryte pliki: 0 . ************************************************************************** . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_USERS\S-1-5-21-3053993808-794510318-3101872555-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}] @Denied: (Full) (Everyone) @Allowed: (Read) (RestrictedCode) "scansk"=hex(0):88,eb,8a,b0,4b,1a,dd,19,25,f1,6e,1e,cf,45,52,c7,ea,a0,1f,07,08, 6e,99,97,f6,8d,08,a7,35,c2,9e,88,ed,6e,2c,01,2f,a3,f8,a8,00,00,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-3053993808-794510318-3101872555-1000_Classes\CLSID\{872aca27-9d23-4f95-92c4-47bd356ddab2}] @Denied: (Full) (Everyone) @Allowed: (Read) (RestrictedCode) "Model"=dword:0000012f "Therad"=dword:0000001e "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26, 38,95,44,54,52,77,f6,32,01,f0,84,58,35,21,8e,0a,50,ea,d7,5e,4e,b2,52,3a,df,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Czas ukończenia: 2012-03-30 19:21:26 ComboFix-quarantined-files.txt 2012-03-30 17:21 . Przed: 67 146 080 256 bajtów wolnych Po: 67 125 223 424 bajtów wolnych . - - End Of File - - D9D146B6B27E0514F15D7C5B12A724F5