ComboFix 12-12-04.01 - ASIA 2012-12-06 0:19.1.2 - x86 NETWORK Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.48.1045.18.3068.2100 [GMT 1:00] Uruchomiony z: c:\users\ASIA\Downloads\ComboFix.exe AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Utworzono nowy punkt przywracania . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\fakturka c:\fakturka\faktura.frf c:\fakturka\fakturanetto.frf c:\fakturka\Fakturka.exe c:\fakturka\Fakturka.ini c:\fakturka\KONTRAH.CDX c:\fakturka\KONTRAH.DBF c:\fakturka\koperta_c5.frf c:\fakturka\nota.frf c:\fakturka\PLIKI.DBF c:\fakturka\POZYCJEFAK.DBF c:\fakturka\PRZELEW.FRF c:\fakturka\przelew_calosc.frf c:\fakturka\rachunek.frf c:\fakturka\REJESTR.CDX c:\fakturka\REJESTR.DBF c:\fakturka\SDE50.DLL c:\fakturka\SDECDX50.dll c:\fakturka\TOWARY.CDX c:\fakturka\TOWARY.DBF c:\fakturka\unins000.dat c:\fakturka\unins000.exe c:\fakturka\wplata.frf c:\fakturka\wplatabankowa.frf c:\fakturka\wplatabankowa_calosc.frf c:\fakturka\wydruki.txt c:\fakturka\Wydruki\02-09-2010_BUK_Faktura_52_08_2010.frp c:\fakturka\Wydruki\02-09-2010_MARYSIA_Faktura_51_08_2010.frp c:\fakturka\Wydruki\02-09-2010_NOWALIJKA_Faktura_50_08_3020.frp c:\fakturka\Wydruki\02-12-2010_MALE_SPA_Faktura_68_11_2010.frp c:\fakturka\Wydruki\02-12-2010_ŁUCZAK_Faktura_67_11_2010.frp c:\fakturka\Wydruki\03-01-2011_FHU_Faktura_72_12_2010.frp c:\fakturka\Wydruki\03-01-2011_HANDEL_Faktura_71_12_2010.frp c:\fakturka\Wydruki\03-01-2011_NOWALIJKA_Faktura_75_12_2010.frp c:\fakturka\Wydruki\03-01-2011_RYCH BUD_Faktura_74_12_2010.frp c:\fakturka\Wydruki\03-01-2011_ŁUCZAK_Faktura_73_12_2010.frp c:\fakturka\Wydruki\03-02-2011_CAŁEW_Faktura_01_01_2011.frp c:\fakturka\Wydruki\03-08-2010_MALE_SPA_Faktura_44_07_2010.frp c:\fakturka\Wydruki\03-08-2010_NOWALIJKA_Faktura_43_07_2010.frp c:\fakturka\Wydruki\03-08-2010_RAFIX_Faktura_46_07_2010.frp c:\fakturka\Wydruki\03-08-2010_RÓLSKA_Faktura_47_07_2010.frp c:\fakturka\Wydruki\03-08-2010_TOMAX_Faktura_42_07_2010.frp c:\fakturka\Wydruki\03-08-2010_ŁUCZAK_Faktura_45_07_2010.frp c:\fakturka\Wydruki\03-11-2010_NOWALIJKA_Faktura_62_10_2010.frp c:\fakturka\Wydruki\03-11-2010_ZIELINSKI_Faktura_61_10_2010.frp c:\fakturka\Wydruki\04-02-2011_HANDEL_Faktura_05_01_2011.frp c:\fakturka\Wydruki\04-02-2011_KADAR_Faktura_02_01_2011.frp c:\fakturka\Wydruki\04-02-2011_MALE_SPA_Faktura_04_01_2011.frp c:\fakturka\Wydruki\04-02-2011_NOWALIJKA_Faktura_03_01_2011.frp c:\fakturka\Wydruki\04-08-2010_MALE_SPA_Faktura_44_07_2010.frp c:\fakturka\Wydruki\04-08-2010_MARYSIA_Faktura_48_07_2010.frp c:\fakturka\Wydruki\04-08-2010_RÓLSKA_Faktura_47_07_2010.frp c:\fakturka\Wydruki\04-08-2010_RYCH BUD_Faktura_49_08_2010.frp c:\fakturka\Wydruki\04-08-2010_TOMAX_Faktura_42_07_2010.frp c:\fakturka\Wydruki\04-09-2010_BUK_Faktura_52_08_2010.frp c:\fakturka\Wydruki\05-02-2011_CAŁEW_Faktura_01_01_2011.frp c:\fakturka\Wydruki\05-02-2011_MALE_SPA_Faktura_04_01_2011.frp c:\fakturka\Wydruki\05-02-2011_NOWALIJKA_Faktura_03_01_2011.frp c:\fakturka\Wydruki\05-11-2010_ZIELINSKI_Faktura_61_10_2010.frp c:\fakturka\Wydruki\08-12-2010_NOWALIJKA_Faktura_69_11_2010.frp c:\fakturka\Wydruki\09-08-2010_MBP_Faktura_49_08_2010.frp c:\fakturka\Wydruki\12-11-2010_KANCELARIA_Faktura_63_11_2010.frp c:\fakturka\Wydruki\12-11-2010_MBP_Faktura_64_11_2010.frp c:\fakturka\Wydruki\13-10-2010_KANCELARIA_Faktura_59_10_2010.frp c:\fakturka\Wydruki\15-11-2010_TUMASZ_Faktura_65_11_2010.frp c:\fakturka\Wydruki\22-10-2010_MBP_Faktura_60_10_2010.frp c:\fakturka\Wydruki\23-05-2010_1_Faktura_.frp c:\fakturka\Wydruki\26-11-2010_FUH NOWAK_Faktura_66_11_2010.frp c:\fakturka\Wydruki\30-12-2010_MARYSIA_Faktura_70_12_2010.frp c:\fakturka\Wydruki\ostatni.frf c:\programdata\0tbpw.pad c:\programdata\Microsoft\Windows\Start Menu\Programs\Fakturka c:\programdata\Microsoft\Windows\Start Menu\Programs\Fakturka\Fakturka.lnk c:\users\ASIA\AppData\Roaming\.# c:\users\ASIA\Documents\Downloads\CT2776682_BrotherSoft_Extreme.exe c:\windows\IsUn0415.exe c:\windows\security\Database\tmp.edb . . ((((((((((((((((((((((((( Pliki utworzone od 2012-11-05 do 2012-12-05 ))))))))))))))))))))))))))))))) . . 2012-12-05 23:28 . 2012-12-05 23:28 -------- d-----w- c:\users\ASIA\AppData\Local\temp 2012-12-05 23:28 . 2012-12-05 23:28 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-12-03 21:56 . 2012-12-03 21:56 -------- d-----w- c:\program files\CARSOFT 2012-12-03 21:56 . 2012-12-03 21:56 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2012-12-03 15:03 . 2012-12-03 15:03 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5BD2D21A-FBCC-43DE-A958-0EB6ABF6DBBD}\offreg.dll 2012-12-03 15:00 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5BD2D21A-FBCC-43DE-A958-0EB6ABF6DBBD}\mpengine.dll 2012-12-03 13:55 . 2011-09-09 10:50 89856 ----a-w- c:\windows\system32\drivers\ew_jucdcacm.sys 2012-12-03 13:55 . 2011-09-09 10:50 73984 ----a-w- c:\windows\system32\drivers\ew_jubusenum.sys 2012-12-03 13:55 . 2011-09-09 10:50 66688 ----a-w- c:\windows\system32\drivers\ew_jucdcecm.sys 2012-12-03 13:55 . 2011-09-09 10:50 26624 ----a-w- c:\windows\system32\drivers\ew_juextctrl.sys 2012-12-03 13:55 . 2010-10-08 15:55 25856 ----a-w- c:\windows\system32\drivers\ewdcsc.sys 2012-12-03 13:55 . 2010-09-26 17:09 19200 ----a-w- c:\windows\system32\drivers\ew_hwupgrade.sys 2012-12-03 13:55 . 2010-08-06 06:42 861696 ----a-w- c:\windows\system32\drivers\mod7700.sys 2012-12-03 13:55 . 2011-10-24 15:31 239488 ----a-w- c:\windows\system32\drivers\ewusbnet.sys 2012-12-03 13:55 . 2011-08-16 16:17 195200 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys 2012-12-03 13:55 . 2010-07-27 08:52 102784 ----a-w- c:\windows\system32\drivers\ew_hwusbdev.sys 2012-12-03 13:55 . 2010-03-20 11:06 11136 ----a-w- c:\windows\system32\drivers\ew_usbenumfilter.sys 2012-12-03 13:53 . 2012-12-03 13:57 -------- d-----w- c:\program files\PLAY Web partner 2012-11-27 20:54 . 2012-11-27 20:54 -------- d-----w- C:\inpa_5_0_2_10.0.0.4 2012-11-13 21:57 . 2012-11-13 21:57 -------- d-----w- c:\users\ASIA\GIPSY_moje 2012-11-13 18:06 . 2012-11-14 10:22 -------- d-----w- c:\users\ASIA\AppData\Roaming\FileZilla . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-11-10 22:10 . 2012-08-17 07:15 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-11-10 22:10 . 2011-10-15 23:32 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-30 22:51 . 2011-06-16 18:47 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2012-10-30 22:51 . 2009-03-06 18:47 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2012-10-30 22:51 . 2009-03-06 18:47 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2012-10-30 22:51 . 2009-03-06 18:47 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys 2012-10-30 22:51 . 2009-03-06 18:47 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-10-30 22:51 . 2009-03-06 18:47 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-10-30 22:51 . 2010-07-27 15:25 41224 ----a-w- c:\windows\avastSS.scr 2012-10-30 22:50 . 2009-03-06 18:47 227648 ----a-w- c:\windows\system32\aswBoot.exe 2012-09-24 13:32 . 2012-08-01 07:04 477168 ----a-w- c:\windows\system32\npdeployJava1.dll 2012-09-24 13:32 . 2010-04-18 09:23 473072 ----a-w- c:\windows\system32\deployJava1.dll 2012-12-01 08:55 . 2012-12-01 08:55 262112 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{DFEFCDEE-CF1A-4FC8-88AD-18272BE37E29}"= "c:\users\ASIA\AppData\Roaming\xplugin\toolbar.dll" [2011-09-30 633344] . [HKEY_CLASSES_ROOT\clsid\{dfefcdee-cf1a-4fc8-88ad-18272be37e29}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-10-30 22:50 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Mobile Partner"="c:\program files\PLAY Web partner\PLAY Web partner" [X] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "Gadu-Gadu 10"="c:\program files\Gadu-Gadu 10\gg.exe" [2011-07-04 13374048] "BatteryCare"="f:\batterycare\BatteryCare.exe" [2012-09-23 738304] "HW_OPENEYE_OUC_PLAY ONLINE"="c:\program files\PLAY ONLINE\UpdateDog\ouc.exe" [2009-04-14 110592] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-15 178712] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-23 468264] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032] "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-15 442433] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-01-13 37888] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696] "Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2007-01-03 520192] "DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2009-12-01 842816] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2012-10-30 4297136] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896] "iPlusManager"="c:\program files\iPlus\iPlusChecker.exe" [2010-11-25 468288] . c:\users\ASIA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ runctf.lnk - c:\windows\System32\rundll32.exe [2006-11-2 44544] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-1-16 727592] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli DPPWDFLT . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe [x] . . --- Inne Usługi/Sterowniki w Pamięci --- . *NewlyCreated* - ECACHE . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . Zawartość folderu 'Zaplanowane zadania' . 2012-12-05 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-17 22:10] . 2012-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cce7d9a069d829.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-25 21:20] . 2012-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cce7d9a09e7cb9.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-08-25 21:20] . 2011-12-26 c:\windows\Tasks\User_Feed_Synchronization-{0CE93EB7-B4E8-460F-BC2C-197DC723AA5B}.job - c:\windows\system32\msfeedssync.exe [2012-06-14 03:24] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_pl&c=83&bd=Pavilion&pf=cnnb mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pl_pl&c=83&bd=Pavilion&pf=cnnb IE: &Wyszukiwarka na pasku narzędzi AOL - c:\programdata\AOL\ieToolbar\resources\pl-PL\local\search.html IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Wyślij obraz do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Wyślij stronę do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.1.1 192.168.1.1 FF - ProfilePath - c:\users\ASIA\AppData\Roaming\Mozilla\Firefox\Profiles\szyna106.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: keyword.URL - hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q= FF - ExtSQL: !HIDDEN! 2010-07-24 15:43; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF - ExtSQL: !HIDDEN! 2011-06-19 11:15; otis@digitalpersona.com; c:\program files\DigitalPersona\Bin\FirefoxExt FF - user.js: browser.search.selectedEngine - Suche FF - user.js: browser.search.order.1 - Suche FF - user.js: browser.search.defaultenginename - Suche FF - user.js: keyword.URL - hxxp://www.finduny.com?client=mozilla-firefox&cd=UTF-8&search=1&q= FF - user.js: privacy.item.cookies - false FF - user.js: privacy.sanitize.promptOnSanitize - false . - - - - USUNIĘTO PUSTE WPISY - - - - . SafeBoot-Wdf01000.sys AddRemove-Fakturka_is1 - c:\fakturka\unins000.exe AddRemove-Szkoła podstawowa klasa 4 - Wczoraj i dziś - c:\windows\IsUn0415.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-12-06 00:28 Windows 6.0.6002 Service Pack 2 NTFS . skanowanie ukrytych procesów ... . skanowanie ukrytych wpisów autostartu ... . skanowanie ukrytych plików ... . skanowanie pomyślnie ukończone ukryte pliki: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}] "ImagePath"="\??\c:\program files\HP\QuickPlay\000.fcl" . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . --------------------- Pliki DLL ładowane pod uruchomionymi procesami --------------------- . - - - - - - - > 'lsass.exe'(568) c:\windows\system32\DPPWDFLT.dll . Czas ukończenia: 2012-12-06 00:30:28 ComboFix-quarantined-files.txt 2012-12-05 23:30 . Przed: 26 029 887 488 bajtów wolnych Po: 26 517 979 136 bajtów wolnych . - - End Of File - - D283F117CEBFB60D401F6E700B1E49E6