ComboFix 12-07-21.01 - Wlasciciel 2012-07-21 11:48:48.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.2037.591 [GMT 2:00] Uruchomiony z: c:\documents and settings\Wlasciciel\Moje dokumenty\ComboFix.exe AV: ESET NOD32 Antivirus 5.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Dane aplikacji\ircoppfstwepkcd c:\windows\Installer\{489531a0-1bcc-938a-af75-51d5187cb4b5}\@ c:\windows\Installer\{489531a0-1bcc-938a-af75-51d5187cb4b5}\U\00000001.@ c:\windows\pkunzip.pif c:\windows\pkzip.pif . . ((((((((((((((((((((((((( Pliki utworzone od 2012-06-21 do 2012-07-21 ))))))))))))))))))))))))))))))) . . 2012-07-20 12:27 . 2012-07-20 12:27 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\fzgxakhnbfvolfv 2012-06-29 17:58 . 2012-06-29 17:58 -------- d-----w- c:\program files\ESET 2012-06-29 17:58 . 2012-06-29 17:58 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\ESET 2012-06-22 06:25 . 2012-06-22 06:25 770384 ----a-w- c:\program files\Mozilla Firefox\msvcr100.dll 2012-06-22 06:25 . 2012-06-22 06:25 421200 ----a-w- c:\program files\Mozilla Firefox\msvcp100.dll . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-11 18:54 . 2012-06-02 16:57 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-07-11 18:54 . 2012-06-02 16:57 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-06-13 13:55 . 2008-04-15 12:00 1866368 ----a-w- c:\windows\system32\win32k.sys 2012-06-05 15:49 . 2008-04-15 12:00 1372672 ----a-w- c:\windows\system32\msxml6.dll 2012-06-05 15:49 . 2008-04-15 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll 2012-06-04 04:32 . 2008-04-15 12:00 152576 ----a-w- c:\windows\system32\schannel.dll 2012-06-02 13:19 . 2011-11-30 13:13 329240 ----a-w- c:\windows\system32\wucltui.dll 2012-06-02 13:19 . 2011-11-30 13:13 210968 ----a-w- c:\windows\system32\wuweb.dll 2012-06-02 13:19 . 2011-11-30 13:13 219160 ----a-w- c:\windows\system32\wuaucpl.cpl 2012-06-02 13:19 . 2009-08-06 18:24 15896 ----a-w- c:\windows\system32\wuapi.dll.mui 2012-06-02 13:19 . 2009-08-06 18:24 24088 ----a-w- c:\windows\system32\wucltui.dll.mui 2012-06-02 13:19 . 2011-11-30 13:13 53784 ----a-w- c:\windows\system32\wuauclt.exe 2012-06-02 13:19 . 2011-11-30 13:13 35864 ----a-w- c:\windows\system32\wups.dll 2012-06-02 13:19 . 2009-08-06 18:24 45080 ----a-w- c:\windows\system32\wups2.dll 2012-06-02 13:19 . 2008-04-15 12:00 97304 ----a-w- c:\windows\system32\cdm.dll 2012-06-02 13:19 . 2009-08-06 18:24 16408 ----a-w- c:\windows\system32\wuaucpl.cpl.mui 2012-06-02 13:19 . 2011-11-30 13:13 577048 ----a-w- c:\windows\system32\wuapi.dll 2012-06-02 13:19 . 2011-11-30 13:13 1933848 ----a-w- c:\windows\system32\wuaueng.dll 2012-06-02 13:19 . 2009-08-06 18:23 18968 ----a-w- c:\windows\system32\wuaueng.dll.mui 2012-06-02 13:18 . 2012-05-15 06:27 275696 ----a-w- c:\windows\system32\mucltui.dll 2012-06-02 13:18 . 2012-05-15 06:27 214256 ----a-w- c:\windows\system32\muweb.dll 2012-06-02 13:18 . 2012-05-15 06:27 18160 ----a-w- c:\windows\system32\mucltui.dll.mui 2012-05-31 13:22 . 2008-04-15 12:00 602624 ----a-w- c:\windows\system32\crypt32.dll 2012-05-16 15:09 . 2008-04-15 12:00 916992 ----a-w- c:\windows\system32\wininet.dll 2012-05-11 14:44 . 2008-04-15 12:00 43520 ------w- c:\windows\system32\licmgr10.dll 2012-05-11 14:44 . 2008-04-15 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2012-05-11 11:39 . 2008-04-15 12:00 385024 ------w- c:\windows\system32\html.iec 2012-05-05 03:14 . 2008-04-15 12:00 2149888 ----a-w- c:\windows\system32\ntoskrnl.exe 2012-05-05 03:14 . 2008-04-14 21:59 2028032 ----a-w- c:\windows\system32\ntkrnlpa.exe 2012-05-02 13:47 . 2011-11-30 13:11 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys 2012-06-22 06:25 . 2012-06-20 20:24 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IGagnant"="c:\documents and settings\Wlasciciel\Pulpit\LaBarre-Gagnante(3).exe" [2011-12-03 200704] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-11-05 1505144] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 3117344] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360] . c:\documents and settings\All Users\Menu Start\Programy\Autostart\ 20Dollars2Surf.lnk - c:\program files\20Dollars2Surf\20dollars2surf.exe [2011-12-3 89088] Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2011-12-2 67128] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-01-03 13:10 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2012-04-04 05:53 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] 2008-04-15 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] 2009-01-21 03:20 166912 ----a-w- c:\windows\system32\hkcmd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2007-10-14 20:17 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] 2009-01-21 03:20 134656 ----a-w- c:\windows\system32\igfxtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel] 2007-05-15 16:12 484904 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager] 2007-07-25 15:02 563984 ----a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon] 2007-07-25 15:06 2027792 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-14 21:51 1695232 ------w- c:\program files\Messenger\msmsgs.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence] 2009-01-21 03:18 134656 ----a-w- c:\windows\system32\igfxpers.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] 2011-08-17 09:09 20064872 ----a-w- c:\windows\RTHDCPL.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2012-02-29 06:55 17148552 ----a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] 2009-03-05 15:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2012-01-17 09:07 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] 2011-07-11 21:47 74752 ----a-w- c:\program files\Winamp\winampa.exe . R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2011-08-04 120152] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2011-08-04 104160] R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2012-03-07 913144] S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-07-13 158856] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-02 250056] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-12-01 1691480] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-20 113120] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2007-05-15 16:08 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Zawartość folderu 'Zaplanowane zadania' . 2012-07-21 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-02 18:54] . . ------- Skan uzupełniający ------- . uDefault_Search_URL = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = hxxp://ui.skype.com/ui/0/5.5.0.124.259/pl/go/help.faq.installer?LastError=1618 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{C86328B3-5D7B-4EC0-8902-D85A104E855A}: NameServer = 87.204.204.204,62.233.233.233 Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll FF - ProfilePath - c:\documents and settings\Wlasciciel\Dane aplikacji\Mozilla\Firefox\Profiles\ed0wcfmo.default\ FF - prefs.js: browser.startup.homepage - hxxp://poczta10.o2.pl/?id=0&o=0&view=inbox|http://www.mlody1313.republika.pl/linki.html|http://autosurf.kasa-bez-wysilku.pl/logowanie.php . - - - - USUNIĘTO PUSTE WPISY - - - - . MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe MSConfigStartUp-Gadu-Gadu 10 - c:\program files\Gadu-Gadu 10\gg.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-07-21 11:54 Windows 5.1.2600 Dodatek Service Pack 3 NTFS . skanowanie ukrytych procesów ... . skanowanie ukrytych wpisów autostartu ... . skanowanie ukrytych plików ... . skanowanie pomyślnie ukończone ukryte pliki: 0 . ************************************************************************** . Czas ukończenia: 2012-07-21 11:55:36 ComboFix-quarantined-files.txt 2012-07-21 09:55 . Przed: 29 512 560 640 bajtów wolnych Po: 30 666 956 800 bajtów wolnych . WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect [spybotsd] timeout.old=30 . - - End Of File - - 0CDB1528B753657E768E8115D2140B23