kula1576 utworzono 8 października 2009 utworzono 8 października 2009 (edytowane) Jaki skrypt mam utworzyć do tego loga? [log] ComboFix 09-10-07.02 - PC 2009-10-08 14:29.7.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3326.2808 [GMT 2:00] Uruchomiony z: g:\programy\ComboFix.exe Użyto następujących komend :: d:\documents and settings\PC\Pulpit\CFScript.txt AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !! . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . d:\windows\AhnRpta.exe . ((((((((((((((((((((((((( Pliki utworzone od 2009-09-08 do 2009-10-08 ))))))))))))))))))))))))))))))) . 2009-10-07 07:30 . 2009-10-07 07:30 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\0148 2009-10-06 11:37 . 2009-10-06 11:37 -------- d-----w- d:\documents and settings\PC\Ustawienia lokalne\Dane aplikacji\Symantec 2009-10-06 11:36 . 2005-05-13 17:50 91856 ----a-w- d:\windows\system32\S32EVNT1.DLL 2009-10-06 11:36 . 2005-05-13 17:50 123488 ----a-w- d:\windows\system32\drivers\SYMEVENT.SYS 2009-10-06 11:36 . 2009-10-06 11:36 -------- d-----w- d:\program files\Symantec 2009-10-06 11:36 . 2009-10-08 12:17 -------- d-----w- d:\program files\Symantec AntiVirus 2009-10-06 11:34 . 2009-10-06 11:34 -------- d-----w- d:\program files\antywirus 2009-10-04 16:05 . 2009-10-04 16:05 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\2K Sports 2009-09-30 19:55 . 2009-09-30 19:55 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Sports Interactive 2009-09-30 19:53 . 2009-09-30 19:53 -------- d--h--w- d:\program files\Zero G Registry 2009-09-30 19:52 . 2009-09-30 19:52 -------- d--h--w- d:\documents and settings\PC\InstallAnywhere . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-08 10:51 . 2001-10-26 17:15 49712 ----a-w- d:\windows\system32\perfc015.dat 2009-10-08 10:51 . 2001-10-26 17:15 355830 ----a-w- d:\windows\system32\perfh015.dat 2009-10-06 12:37 . 2009-06-20 09:52 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\uTorrent 2009-10-06 12:11 . 2009-06-09 11:56 -------- d-----w- d:\program files\Common Files\Symantec Shared 2009-10-06 11:36 . 2009-06-09 12:01 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Symantec 2009-09-15 20:22 . 2009-06-09 14:36 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu 2009-09-08 16:55 . 2009-06-09 13:36 -------- d-----w- d:\program files\AGEIA Technologies 2009-09-05 21:05 . 2009-06-14 18:23 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\BESTplayer 2009-09-04 09:07 . 2009-06-09 14:36 -------- d-----w- d:\program files\Nowe Gadu-Gadu 2009-08-28 12:56 . 2009-08-28 12:56 -------- d-----w- d:\program files\Half-Life Model Viewer 2009-08-22 21:49 . 2009-06-09 13:03 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Test Drive Unlimited 2009-07-27 17:27 . 2009-06-09 11:58 107888 ----a-w- d:\windows\system32\CmdLineExt.dll . ((((((((((((((((((((((((((((( SnapShot@2009-10-06_11.31.31 ))))))))))))))))))))))))))))))))))))))))) . + 2001-08-17 22:30 . 2009-10-08 10:51 40128 d:\windows\system32\perfc009.dat - 2001-08-17 22:30 . 2009-10-06 08:26 40128 d:\windows\system32\perfc009.dat + 2005-06-23 17:29 . 2005-06-23 17:29 71416 d:\windows\system32\pds.dll + 2005-06-23 17:29 . 2005-06-23 17:29 83704 d:\windows\system32\nts.dll + 2005-06-23 17:27 . 2005-06-23 17:27 43712 d:\windows\system32\NavLogon.dll + 2005-06-23 17:29 . 2005-06-23 17:29 46848 d:\windows\system32\msgsys.dll + 2005-06-23 17:29 . 2005-06-23 17:29 83648 d:\windows\system32\loc32vc0.dll + 2005-04-22 10:03 . 2005-04-22 10:03 17976 d:\windows\system32\drivers\symredrv.sys + 2005-04-22 10:02 . 2005-04-22 10:02 47192 d:\windows\system32\drivers\symndis.sys + 2005-04-22 10:02 . 2005-04-22 10:02 36984 d:\windows\system32\drivers\symids.sys + 2005-04-22 10:02 . 2005-04-22 10:02 11512 d:\windows\system32\drivers\symdns.sys + 2005-06-23 17:28 . 2005-06-23 17:28 34552 d:\windows\system32\cba.dll + 2003-03-18 18:05 . 2003-03-18 18:05 89088 d:\windows\system32\atl71.dll + 2009-10-06 11:37 . 2009-10-06 11:37 40960 d:\windows\Installer\{3248E093-5288-4CA9-B3AB-11A675FEA1F9}\NewShortcut1.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe + 2009-10-06 11:37 . 2009-10-06 11:37 25214 d:\windows\Installer\{3248E093-5288-4CA9-B3AB-11A675FEA1F9}\ARPPRODUCTICON.exe + 2005-04-22 10:03 . 2005-04-22 10:03 132824 d:\windows\system32\SymRedir.dll + 2005-04-22 10:03 . 2005-04-22 10:03 517848 d:\windows\system32\SymNeti.dll - 2001-08-17 22:30 . 2009-10-06 08:26 311740 d:\windows\system32\perfh009.dat + 2001-08-17 22:30 . 2009-10-08 10:51 311740 d:\windows\system32\perfh009.dat + 2005-04-22 10:03 . 2005-04-22 10:03 267192 d:\windows\system32\drivers\symtdi.sys + 2005-04-22 10:02 . 2005-04-22 10:02 173208 d:\windows\system32\drivers\symfw.sys + 2003-03-18 20:12 . 2003-03-18 20:12 1047552 d:\windows\system32\mfc71u.dll + 2009-10-06 11:37 . 2009-10-06 11:37 5502464 d:\windows\Installer\4b351.msi . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144] "SunJavaUpdateSched"="d:\program files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 36975] "NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016] "ccApp"="d:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752] "vptray"="d:\progra~1\SYMANT~1\VPTray.exe" [2005-06-23 85696] "RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.exe [2008-05-14 16862720] "nwiz"="nwiz.exe" - d:\windows\system32\nwiz.exe [2008-10-07 1630208] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{BD344AF4-67AB-4E19-A630-7435587D320B}"= "d:\windows\system32\ahndoor0.dll" [2008-04-14 63554] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Talisman.lnk] path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Talisman.lnk backup=d:\windows\pss\Talisman.lnkStartup [HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Yahoo! Widget Engine.lnk] path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Yahoo! Widget Engine.lnk backup=d:\windows\pss\Yahoo! Widget Engine.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "g:\\Gry\\Test Drive Unlimited\\TestDriveUnlimited.exe"= "d:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"= "g:\\Gry\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "d:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"= "d:\\Program Files\\Ares\\Ares.exe"= "d:\\Program Files\\uTorrent\\uTorrent.exe"= "d:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"= "d:\\Program Files\\Ares\\chatServer.exe"= "c:\\Program Files\\The All-Seeing Eye\\eye.exe"= "g:\\Gry\\Stronghold 2\\Stronghold2.exe"= "g:\\Gry\\PES09\\pes2009.exe"= "g:\\Gry\\Q U A K E II\\r1q2.exe"= "g:\\Gry\\Valve\\SteamApps\\kula_1576\\counter-strike\\hl.exe"= "g:\\Gry\\Fotbal Menager 2008\\fm.exe"= R0 sojubus;sojubus;d:\windows\system32\drivers\sojubus.sys [2003-10-05 123520] R0 sojuscsi;sojuscsi;d:\windows\system32\drivers\sojuscsi.sys [2003-09-28 5504] S2 gupdate1ca0016106c1b22;Usługa Google Update (gupdate1ca0016106c1b22);d:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 133104] S3 SavRoam;SAVRoam;d:\program files\Symantec AntiVirus\SavRoam.exe [2005-06-23 124608] --- Inne Usługi/Sterowniki w Pamięci --- *Deregistered* - EraserUtilDrvI9 . Zawartość folderu 'Zaplanowane zadania' 2009-10-08 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job - d:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 21:50] 2009-10-08 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job - d:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 21:50] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://search.bearshare.com/ uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com IE: E&ksport do programu Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 FF - ProfilePath - d:\documents and settings\PC\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\ FF - prefs.js: browser.startup.homepage - hxxp://google.pl FF - plugin: d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu\_userdata\npgg.1.dll FF - plugin: d:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava11.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava12.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava13.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava14.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava32.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-08 14:31 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów ... skanowanie ukrytych wpisów autostartu ... skanowanie ukrytych plików ... skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- [HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID] @Denied: (Full) (LocalSystem) [HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:a6,7d,1d,90,39,09,ad,46,99,fe,17,b8,16,6f,7f,0b,be,77,2e,c8,07,81,27, 3f,75,79,8f,5a,76,d4,12,5a,f4,0a,60,db,5a,2a,57,cc,ca,e9,89,35,11,a2,a6,72,\ "??"=hex:a0,87,12,9e,a4,06,2f,b5,52,62,2b,d2,0b,43,9d,7b [HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\License information*] "datasecu"=hex:03,ca,b9,2d,48,91,81,3c,29,08,70,54,2c,bf,3a,61,4a,d0,87,92,99, ed,7e,57,ba,05,a0,3b,26,14,09,29,be,d4,de,78,8d,b6,40,81,a7,af,1e,0e,ba,3e,\ "rkeysecu"=hex:94,94,3a,05,62,40,36,54,f0,6a,81,57,71,86,8d,50 . Czas ukończenia: 2009-10-08 14:32 ComboFix-quarantined-files.txt 2009-10-08 12:31 ComboFix2.txt 2009-10-08 12:14 ComboFix3.txt 2009-10-08 11:59 ComboFix4.txt 2009-10-08 09:54 ComboFix5.txt 2009-10-08 12:28 Przed: 17 741 246 464 bajtów wolnych Po: 17 734 914 048 bajtów wolnych 178 [/log]
Psycholandia komentarz 8 października 2009 komentarz 8 października 2009 Daj loga z OTL: http://www.forumpc.pl/index.php?showtopic=104338 Logów z Combofixa nie dajemy od tak sobie, zapoznaj się z regulaminem działu bezpieczeństwo.
kula1576 komentarz 8 października 2009 Autor komentarz 8 października 2009 (edytowane) Sorki ja nowicjusz oto log z OTL [log]OTL logfile created on: 2009-10-08 15:00:41 - Run 1 OTL by OldTimer - Version 3.0.18.4 Folder = D:\Documents and Settings\PC\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 100,00% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free Paging file location(s): D:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9,90 Gb Total Space | 1,28 Gb Free Space | 12,96% Space Free | Partition Type: FAT32 Drive D: | 29,29 Gb Total Space | 16,53 Gb Free Space | 56,41% Space Free | Partition Type: NTFS Drive E: | 13,79 Gb Total Space | 3,41 Gb Free Space | 24,72% Space Free | Partition Type: FAT32 Drive F: | 13,55 Gb Total Space | 3,39 Gb Free Space | 25,05% Space Free | Partition Type: FAT32 Drive G: | 97,65 Gb Total Space | 18,08 Gb Free Space | 18,52% Space Free | Partition Type: NTFS Drive H: | 171,13 Gb Total Space | 22,97 Gb Free Space | 13,42% Space Free | Partition Type: NTFS Drive I: | 3,58 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Drive K: | 3,48 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: KUL Current User Name: PC Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2005-06-02 09:21:46 | 00,161,392 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe PRC - [2005-06-02 09:21:40 | 00,185,968 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe PRC - [2008-05-14 03:50:46 | 16,862,720 | R--- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\RTHDCPL.EXE PRC - [2005-06-02 09:21:38 | 00,048,752 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccApp.exe PRC - [2005-06-23 19:27:36 | 00,085,696 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\VPTray.exe PRC - [2005-06-23 19:27:18 | 00,019,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\DefWatch.exe PRC - [2008-10-07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\nvsvc32.exe PRC - [2009-06-11 15:57:29 | 00,075,064 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrA.exe PRC - [2009-07-09 11:24:20 | 00,189,072 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrB.exe PRC - [2005-06-23 19:27:28 | 01,715,904 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Rtvscan.exe PRC - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wdfmgr.exe PRC - [2008-04-14 22:51:18 | 01,035,264 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe PRC - [2009-09-10 16:13:00 | 00,307,704 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009-10-08 15:00:24 | 00,520,704 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2005-06-02 09:21:40 | 00,185,968 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [Auto | Running]) SRV - [2005-06-02 09:21:46 | 00,083,568 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc [On_Demand | Stopped]) SRV - [2005-06-02 09:21:46 | 00,161,392 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running]) SRV - [2005-06-23 19:27:18 | 00,019,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running]) SRV - [2009-07-08 23:50:07 | 00,133,104 | ---- | M] (Google Inc.) -- D:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1ca0016106c1b22 [Auto | Stopped]) SRV - [2008-04-14 22:50:46 | 00,038,400 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running]) SRV - [2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped]) SRV - [2008-10-07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running]) SRV - [2003-07-28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) SRV - [2009-06-11 15:57:29 | 00,075,064 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrA.exe -- (PnkBstrA [Auto | Running]) SRV - [2009-07-09 11:24:20 | 00,189,072 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrB.exe -- (PnkBstrB [Auto | Running]) SRV - [2005-06-23 19:27:30 | 00,124,608 | ---- | M] (symantec) -- D:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam [On_Demand | Stopped]) SRV - [2005-04-22 12:03:28 | 00,206,552 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [On_Demand | Stopped]) SRV - [2005-03-30 21:48:22 | 00,992,864 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc [On_Demand | Stopped]) SRV - [2005-06-23 19:27:28 | 01,715,904 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus [Auto | Running]) SRV - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running]) SRV - [2004-08-04 02:44:16 | 00,006,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wuauserv.dll -- (wuauserv [Auto | Running]) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2006-07-01 23:32:26 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- D:\WINDOWS\System32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running]) DRV - File not found -- -- (catchme [On_Demand | Running]) DRV - [2009-09-17 08:53:46 | 00,371,248 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl [System | Running]) DRV - [2009-06-09 13:55:32 | 00,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- D:\WINDOWS\gdrv.sys -- (gdrv [On_Demand | Stopped]) DRV - [2008-04-13 22:06:06 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- D:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running]) DRV - [2008-05-15 02:03:12 | 04,742,144 | R--- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\System32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running]) DRV - [2009-09-17 08:53:46 | 00,084,912 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\VirusDefs\20091007.002\NAVENG.SYS -- (NAVENG [On_Demand | Running]) DRV - [2009-09-17 08:53:46 | 01,323,568 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\VirusDefs\20091007.002\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running]) DRV - [2003-04-02 09:54:16 | 00,020,648 | R--- | M] (Thomson Inc.) -- D:\WINDOWS\System32\DRIVERS\netrcacm.sys -- (netrcacm [On_Demand | Running]) DRV - [2008-10-07 13:33:00 | 06,133,856 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running]) DRV - [2008-04-14 00:26:08 | 00,088,320 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx [Auto | Running]) DRV - [2001-08-18 00:54:18 | 00,063,232 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnknb.sys -- (NwlnkNb [Auto | Running]) DRV - [2001-08-18 00:54:18 | 00,055,936 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx [Auto | Running]) DRV - [2008-04-14 00:04:14 | 00,163,584 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwrdr.sys -- (NWRDR [On_Demand | Stopped]) DRV - [2009-07-09 11:24:29 | 00,138,920 | ---- | M] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys -- (PnkBstrK [On_Demand | Stopped]) DRV - [2001-08-18 00:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- D:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running]) DRV - [2008-01-04 08:10:16 | 00,105,856 | R--- | M] (Realtek Semiconductor Corporation ) -- D:\WINDOWS\System32\DRIVERS\Rtenicxp.sys -- (RTLE8023xp [On_Demand | Stopped]) DRV - [2005-02-04 20:14:30 | 00,324,232 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT [System | Running]) DRV - [2005-02-04 20:14:32 | 00,053,896 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL [System | Running]) DRV - [2008-04-13 22:09:18 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- D:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped]) DRV - [2003-10-05 10:41:14 | 00,123,520 | ---- | M] ( ) -- D:\WINDOWS\system32\DRIVERS\sojubus.sys -- (sojubus [Boot | Running]) DRV - [2003-09-28 10:57:52 | 00,005,504 | ---- | M] ( ) -- D:\WINDOWS\system32\DRIVERS\sojuscsi.sys -- (sojuscsi [Boot | Running]) DRV - [2005-03-30 21:48:20 | 00,372,832 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv [On_Demand | Stopped]) DRV - [2005-05-13 19:50:10 | 00,123,488 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running]) DRV - [2005-04-22 12:03:00 | 00,017,976 | ---- | M] (Symantec Corporation) -- D:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV [On_Demand | Running]) DRV - [2005-04-22 12:03:02 | 00,267,192 | ---- | M] (Symantec Corporation) -- D:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI [System | Running]) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://google.pl" FF - prefs.js..extensions.enabledItems: anycolor.pavlos256@gmail.com:0.3.0 FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.2 FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:3.2.8 FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.1 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14 FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2009-09-10 16:13:03 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2009-10-04 19:46:11 | 00,000,000 | ---D | M] [2009-06-09 13:31:44 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Extensions [2009-06-09 13:31:44 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009-10-08 13:27:48 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions [2009-07-09 00:36:32 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2009-07-09 14:14:16 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{64161300-e22b-11db-8314-0800200c9a66} [2009-07-08 23:26:05 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE} [2009-08-14 13:06:23 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009-06-27 12:52:28 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{eaf8a4ef-d221-45ca-9deb-d0934b45fa34} [2009-07-08 23:33:43 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} [2009-07-08 23:20:28 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\anycolor.pavlos256@gmail.com [2009-06-20 12:32:59 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions [2009-09-10 16:13:00 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009-09-10 16:13:00 | 00,023,032 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009-09-10 16:13:00 | 00,134,648 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\brwsrcmp.dll [2007-04-30 16:29:22 | 00,049,152 | ---- | M] (Adobe Systems, Inc.) -- D:\Program Files\mozilla firefox\plugins\np32dsw.dll [2009-09-10 16:13:02 | 00,065,528 | ---- | M] (mozilla.org) -- D:\Program Files\mozilla firefox\plugins\npnul32.dll [2003-07-15 06:56:52 | 00,013,888 | ---- | M] (Microsoft Corporation) -- D:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL [2009-07-25 21:28:08 | 00,002,767 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2009-06-13 11:07:49 | 00,001,406 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2009-06-13 11:07:49 | 00,001,706 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\google.xml [2009-06-13 11:07:49 | 00,000,917 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2009-06-13 11:07:49 | 00,000,858 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2009-06-13 11:07:49 | 00,001,183 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2009-06-13 11:07:49 | 00,001,683 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: (27 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (no name) - @!22BF9-DF26-493f-B0DA-6D2FC5E6429E} - No CLSID value found. O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - D:\Documents and Settings\PC\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.) O2 - BHO: (no name) - Ř?!ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found. O2 - BHO: (no name) - X@!C7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - D:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O3 - HKCU\..\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - D:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O4 - HKLM..\Run: [ccApp] D:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] D:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [RTHDCPL] D:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_02\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [vptray] D:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: E&ksport do programu Microsoft Excel - D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll (Sun Microsystems, Inc.) O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Java Plug-in 1.5.0_02) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Java Plug-in 1.5.0_02) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.172.224.160 89.228.6.21 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter: - text/xml - D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\NavLogon: DllName - D:\WINDOWS\system32\NavLogon.dll - D:\WINDOWS\System32\NavLogon.dll (Symantec Corporation) O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - CLSID or File not found. O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O28 - HKLM ShellExecuteHooks: {BD344AF4-67AB-4E19-A630-7435587D320B} - D:\WINDOWS\System32\ahndoor0.dll () O30 - LSA: Authentication Packages - (nwprovau) - D:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-11-11 11:04:46 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ] O32 - AutoRun File - [2008-10-24 14:30:24 | 00,837,392 | R--- | M] () - I:\Autorun.exe -- [ CDFS ] O32 - AutoRun File - [2007-01-25 11:51:25 | 00,000,172 | R--- | M] () - I:\Autorun.inf -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\AutoRun.exe -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\Autorun.exe -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:41 | 03,460,608 | R--- | M] () - K:\autorun.dat -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:22 | 00,000,139 | R--- | M] () - K:\autorun.inf -- [ CDFS ] O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - D:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found O35 - comfile [open] -- "%1" %* File not found O35 - exefile [open] -- "%1" %* File not found [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [6 D:\WINDOWS\*.tmp files] [2009-10-07 09:30:00 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\0148 [2009-10-04 18:05:26 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Dane aplikacji\2K Sports [2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Dane aplikacji\Sports Interactive [2009-10-06 13:37:14 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Symantec [2009-10-06 13:34:59 | 00,000,000 | ---D | C] -- D:\Program Files\antywirus [2009-10-06 13:36:32 | 00,000,000 | ---D | C] -- D:\Program Files\Symantec [2009-10-06 13:36:24 | 00,000,000 | ---D | C] -- D:\Program Files\Symantec AntiVirus [2009-10-08 14:48:22 | 00,000,000 | ---D | C] -- D:\Program Files\trend micro [2009-09-30 21:53:26 | 00,000,000 | -H-D | C] -- D:\Program Files\Zero G Registry [2009-10-08 15:00:19 | 00,520,704 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe [2009-10-08 14:48:22 | 00,000,000 | ---D | C] -- D:\rsit [2009-10-08 14:43:20 | 00,000,000 | -HSD | C] -- D:\RECYCLER [2009-10-08 14:32:04 | 00,000,000 | ---D | C] -- D:\WINDOWS\temp [2009-10-08 14:28:43 | 00,000,000 | ---D | C] -- D:\ComboFix [2009-10-06 13:36:36 | 00,123,488 | ---- | C] (Symantec Corporation) -- D:\WINDOWS\System32\drivers\SYMEVENT.SYS [2009-10-06 13:36:36 | 00,091,856 | ---- | C] (Symantec Corporation) -- D:\WINDOWS\System32\S32EVNT1.DLL [2009-10-06 13:25:41 | 00,000,000 | ---D | C] -- D:\Qoobox [2009-10-05 11:59:07 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Pulpit\xxx [2009-10-04 19:51:37 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\NBA LIVE 08 [2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\Sports Interactive [2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dokumenty\Sports Interactive [2009-09-29 20:42:42 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\NBA LIVE 06 [2009-09-12 10:13:47 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Pulpit\kwie [2003-10-05 10:41:14 | 00,123,520 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\sojubus.sys [2003-09-28 10:57:52 | 00,005,504 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\sojuscsi.sys [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [5 D:\WINDOWS\System32\*.tmp files] [6 D:\WINDOWS\*.tmp files] [2009-10-08 15:00:24 | 00,520,704 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe [2009-10-08 14:47:50 | 00,781,909 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\RSIT.exe [2009-10-08 14:32:02 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT [2009-10-08 14:31:24 | 00,000,246 | ---- | M] () -- D:\WINDOWS\system.ini [2009-10-08 14:17:21 | 00,195,356 | ---- | M] () -- D:\WINDOWS\System32\nvapps.xml [2009-10-08 14:17:20 | 00,001,032 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2009-10-08 14:17:16 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat [2009-10-08 14:16:07 | 04,314,060 | -H-- | M] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\IconCache.db [2009-10-08 14:07:00 | 00,001,036 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2009-10-08 13:46:37 | 00,002,596 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT [2009-10-08 12:51:16 | 00,763,990 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI [2009-10-08 12:51:16 | 00,355,830 | ---- | M] () -- D:\WINDOWS\System32\perfh015.dat [2009-10-08 12:51:16 | 00,311,740 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat [2009-10-08 12:51:16 | 00,049,712 | ---- | M] () -- D:\WINDOWS\System32\perfc015.dat [2009-10-08 12:51:16 | 00,040,128 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat [2009-10-08 12:02:44 | 00,000,000 | ---- | M] () -- D:\WINDOWS\VPC32.INI [2009-10-06 20:17:39 | 00,000,591 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\NBA LIVE 06.lnk [2009-10-06 14:38:11 | 00,000,573 | ---- | M] () -- D:\WINDOWS\win.ini [2009-10-06 13:31:15 | 00,000,027 | ---- | M] () -- D:\WINDOWS\System32\drivers\etc\hosts [2009-10-04 19:55:28 | 00,011,264 | ---- | M] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009-10-04 19:50:12 | 00,001,471 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\EA SPORTS™ NBA LIVE 08.lnk [2009-10-04 18:26:10 | 00,000,510 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\NBA 2K9.exe.lnk [2009-10-04 18:02:49 | 26,271,866 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\spolszczenie_2k9.rar [2009-10-04 18:01:40 | 00,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl [2009-10-02 19:39:08 | 07,524,224 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\Inna - Deja vu(1).mp3 [2009-09-30 21:54:20 | 00,000,556 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Football Manager 2008.lnk [2009-09-24 16:22:25 | 03,122,605 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\rihanna - push up on me.mp31253803802_[mp3.teledyski.info].mp3 [2009-09-14 02:12:36 | 00,229,888 | ---- | M] () -- D:\WINDOWS\PEV.exe [color=#E56717]========== Files - No Company Name ==========[/color] [2009-10-08 14:47:39 | 00,781,909 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\RSIT.exe [2009-10-08 12:02:44 | 00,000,000 | ---- | C] () -- D:\WINDOWS\VPC32.INI [2009-10-04 19:50:12 | 00,001,471 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\EA SPORTS™ NBA LIVE 08.lnk [2009-10-04 18:26:10 | 00,000,510 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\NBA 2K9.exe.lnk [2009-10-04 17:48:20 | 26,271,866 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\spolszczenie_2k9.rar [2009-10-02 19:39:33 | 07,524,224 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\Inna - Deja vu(1).mp3 [2009-09-30 21:54:20 | 00,000,556 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\Football Manager 2008.lnk [2009-09-29 20:32:37 | 00,000,591 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\NBA LIVE 06.lnk [2009-09-24 16:30:37 | 03,122,605 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\rihanna - push up on me.mp31253803802_[mp3.teledyski.info].mp3 [2009-07-09 22:42:17 | 04,314,060 | -H-- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\IconCache.db [2009-06-24 00:05:28 | 00,168,448 | ---- | C] () -- D:\WINDOWS\System32\unrar.dll [2009-06-20 15:01:29 | 00,354,816 | ---- | C] () -- D:\WINDOWS\System32\psisdecd.dll [2009-06-19 14:07:50 | 00,076,407 | ---- | C] () -- D:\Documents and Settings\PC\Dane aplikacji\Smiley.ico [2009-06-13 14:34:41 | 00,000,421 | ---- | C] () -- D:\WINDOWS\ODBC.INI [2009-06-11 15:57:43 | 00,138,920 | ---- | C] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys [2009-06-09 22:10:06 | 00,000,298 | ---- | C] () -- D:\WINDOWS\game.ini [2009-06-09 14:49:10 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\All Users\Dane aplikacji\desktop.ini [2009-06-09 13:27:41 | 00,011,264 | ---- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009-06-09 13:25:04 | 00,042,944 | ---- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT [2009-06-09 13:03:24 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\PC\Dane aplikacji\desktop.ini [2008-06-25 21:57:00 | 01,703,936 | ---- | C] () -- D:\WINDOWS\System32\nvwdmcpl.dll [2008-06-25 21:57:00 | 01,486,848 | ---- | C] () -- D:\WINDOWS\System32\nview.dll [2008-06-25 21:57:00 | 01,019,904 | ---- | C] () -- D:\WINDOWS\System32\nvwimg.dll [2008-06-25 21:57:00 | 00,466,944 | ---- | C] () -- D:\WINDOWS\System32\nvshell.dll [2008-06-25 21:57:00 | 00,286,720 | ---- | C] () -- D:\WINDOWS\System32\nvnt4cpl.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelTraditionalChinese.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSwedish.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSpanish.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelPortugese.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelKorean.dll [2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelJapanese.dll [2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelGerman.dll [2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelFrench.dll [2008-06-05 08:58:26 | 00,197,912 | ---- | C] () -- D:\WINDOWS\System32\physxcudart_20.dll [2004-09-01 17:49:17 | 03,375,104 | ---- | C] () -- D:\WINDOWS\System32\qt-mt331.dll [2004-08-04 02:44:20 | 00,063,554 | ---- | C] () -- D:\WINDOWS\System32\ahndoor0.dll [2003-04-08 11:40:22 | 00,005,679 | ---- | C] () -- D:\WINDOWS\System32\OUTLPERF.INI [2001-07-22 01:16:20 | 00,000,573 | ---- | C] () -- D:\WINDOWS\win.ini [2001-07-22 01:15:52 | 00,000,246 | ---- | C] () -- D:\WINDOWS\system.ini < End of report >[/log]
Psycholandia komentarz 8 października 2009 komentarz 8 października 2009 Loga nie ma, wklej jeszcze raz
kula1576 komentarz 8 października 2009 Autor komentarz 8 października 2009 (edytowane) Dałem bez spacji ale już poprawiłem :]
Psycholandia komentarz 8 października 2009 komentarz 8 października 2009 W okienko OTL wklej poniższy skrypt i klik na Run Fix: [code]:Processes explorer.exe :OTL O2 - BHO: (no name) - @!22BF9-DF26-493f-B0DA-6D2FC5E6429E} - No CLSID value found. O2 - BHO: (no name) - Ř?!ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found. O2 - BHO: (no name) - X@!C7F02-6F4E-4462-B5B1-394A57FD3E0D} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - D:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O3 - HKCU\..\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - D:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - CLSID or File not found. O32 - AutoRun File - [2008-10-24 14:30:24 | 00,837,392 | R--- | M] () - I:\Autorun.exe -- [ CDFS ] O32 - AutoRun File - [2007-01-25 11:51:25 | 00,000,172 | R--- | M] () - I:\Autorun.inf -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\AutoRun.exe -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\Autorun.exe -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:41 | 03,460,608 | R--- | M] () - K:\autorun.dat -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:22 | 00,000,139 | R--- | M] () - K:\autorun.inf -- [ CDFS ] :Files D:\Program Files\BearShare Applications\BearShare MediaBar D:\RECYCLER D:\Qoobox D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job D:\WINDOWS\PEV.exe D:\WINDOWS\System32\unrar.dll :Commands [emptytemp] [start explorer] [Reboot][/code] Otwórz notatnik tekstowy i wklej do niego poniższy tekst: [code]Windows Registry Editor Version 5.00 [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2] [/code] Zapisz jako->Wybierz [b]Wszystkie pliki[/b]->wpisz [b]Fix.reg[/b]->Następnie kliknij na zapisany plik i uruchom komputer ponownie. Przeskanuj komputer tym: [url="http://www.programosy.pl/program,malwarebytes-anti-malware.html"]Malware[/url] usuń wszystko co znajdzie i daj loga po kasowaniu (loga z Malware)
kula1576 komentarz 8 października 2009 Autor komentarz 8 października 2009 Trwa pełne skanowanie tym Malware a chciałem spytać przy okazji o ten wpis który się pokazał w tym pierwszym logu z Combofixa: d:\windows\AhnRpta.exe Cały czas mam to uruchomione w menadżerze zadań..
Psycholandia komentarz 8 października 2009 komentarz 8 października 2009 Po skanowaniu Malware usuniesz wszystko co znajdzie + dasz loga po usuwaniu + nowego loga z OTL
kula1576 komentarz 8 października 2009 Autor komentarz 8 października 2009 Log po skanowaniu i usuwaniu z Malware: [log] Malwarebytes' Anti-Malware 1.41 Wersja bazy definicji: 2775 Windows 5.1.2600 Dodatek Service Pack 3 2009-10-08 16:27:23 mbam-log-2009-10-08 (16-27-23).txt Typ skanowania: Pełne skanowanie (C:\|D:\|E:\|F:\|G:\|H:\|) Przeskanowane obiekty: 298210 Upłynęło: 47 minute(s), 41 second(s) Zainfekowane procesy w pamięci: 1 Zainfekowane moduły pamięci: 0 Zainfekowane klucze rejestru: 0 Zainfekowane wartości rejestru: 0 Zainfekowane pliki rejestru: 1 Zainfekowane foldery: 0 Zainfekowane pliki: 1 Zainfekowane procesy w pamięci: D:\WINDOWS\AhnRpta.exe (Trojan.Backdoor) -> Unloaded process successfully. Zainfekowane moduły pamięci: (Nie wykryto groźnych plików) Zainfekowane klucze rejestru: (Nie wykryto groźnych plików) Zainfekowane wartości rejestru: (Nie wykryto groźnych plików) Zainfekowane pliki rejestru: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Zainfekowane foldery: (Nie wykryto groźnych plików) Zainfekowane pliki: D:\WINDOWS\AhnRpta.exe (Trojan.Backdoor) -> Quarantined and deleted successfully. [/log] Log po ponownym skanowaniu OTL: [log] OTL logfile created on: 2009-10-08 16:30:22 - Run 2 OTL by OldTimer - Version 3.0.18.4 Folder = D:\Documents and Settings\PC\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 100,00% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free Paging file location(s): D:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 9,90 Gb Total Space | 1,28 Gb Free Space | 12,96% Space Free | Partition Type: FAT32 Drive D: | 29,29 Gb Total Space | 16,51 Gb Free Space | 56,38% Space Free | Partition Type: NTFS Drive E: | 13,79 Gb Total Space | 3,41 Gb Free Space | 24,72% Space Free | Partition Type: FAT32 Drive F: | 13,55 Gb Total Space | 3,39 Gb Free Space | 25,05% Space Free | Partition Type: FAT32 Drive G: | 97,65 Gb Total Space | 18,08 Gb Free Space | 18,52% Space Free | Partition Type: NTFS Drive H: | 171,13 Gb Total Space | 22,97 Gb Free Space | 13,42% Space Free | Partition Type: NTFS Drive I: | 3,58 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Drive K: | 3,48 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: KUL Current User Name: PC Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2005-06-02 09:21:46 | 00,161,392 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe PRC - [2005-06-02 09:21:40 | 00,185,968 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe PRC - [2008-04-14 22:51:18 | 01,035,264 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Explorer.EXE PRC - [2008-05-14 03:50:46 | 16,862,720 | R--- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\RTHDCPL.EXE PRC - [2005-06-02 09:21:38 | 00,048,752 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccApp.exe PRC - [2005-06-23 19:27:36 | 00,085,696 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\VPTray.exe PRC - [2005-06-23 19:27:18 | 00,019,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\DefWatch.exe PRC - [2008-10-07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\nvsvc32.exe PRC - [2009-06-11 15:57:29 | 00,075,064 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrA.exe PRC - [2009-07-09 11:24:20 | 00,189,072 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrB.exe PRC - [2008-04-14 22:51:32 | 00,070,144 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\AhnRpta.exe PRC - [2009-07-08 23:50:07 | 00,133,104 | ---- | M] (Google Inc.) -- D:\Program Files\Google\Update\GoogleUpdate.exe PRC - [2005-06-23 19:27:28 | 01,715,904 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Rtvscan.exe PRC - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wdfmgr.exe PRC - [2008-04-14 22:51:52 | 00,013,824 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wscntfy.exe PRC - [2009-10-08 15:00:24 | 00,520,704 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2005-06-02 09:21:40 | 00,185,968 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [Auto | Running]) SRV - [2005-06-02 09:21:46 | 00,083,568 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc [On_Demand | Stopped]) SRV - [2005-06-02 09:21:46 | 00,161,392 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running]) SRV - [2005-06-23 19:27:18 | 00,019,648 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running]) SRV - [2009-07-08 23:50:07 | 00,133,104 | ---- | M] (Google Inc.) -- D:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1ca0016106c1b22 [Auto | Stopped]) SRV - [2008-04-14 22:50:46 | 00,038,400 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running]) SRV - [2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped]) SRV - [2008-10-07 13:33:00 | 00,163,908 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running]) SRV - [2003-07-28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) SRV - [2009-06-11 15:57:29 | 00,075,064 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrA.exe -- (PnkBstrA [Auto | Running]) SRV - [2009-07-09 11:24:20 | 00,189,072 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrB.exe -- (PnkBstrB [Auto | Running]) SRV - [2005-06-23 19:27:30 | 00,124,608 | ---- | M] (symantec) -- D:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam [On_Demand | Stopped]) SRV - [2005-04-22 12:03:28 | 00,206,552 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [On_Demand | Stopped]) SRV - [2005-03-30 21:48:22 | 00,992,864 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc [On_Demand | Stopped]) SRV - [2005-06-23 19:27:28 | 01,715,904 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus [Auto | Running]) SRV - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running]) SRV - [2004-08-04 02:44:16 | 00,006,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wuauserv.dll -- (wuauserv [Auto | Running]) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2006-07-01 23:32:26 | 00,043,520 | ---- | M] (Advanced Micro Devices) -- D:\WINDOWS\System32\DRIVERS\AmdK8.sys -- (AmdK8 [System | Running]) DRV - [2009-09-17 08:53:46 | 00,371,248 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl [System | Running]) DRV - [2009-06-09 13:55:32 | 00,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- D:\WINDOWS\gdrv.sys -- (gdrv [On_Demand | Stopped]) DRV - [2008-04-13 22:06:06 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) -- D:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running]) DRV - [2008-05-15 02:03:12 | 04,742,144 | R--- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\System32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running]) DRV - [2009-09-17 08:53:46 | 00,084,912 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\VirusDefs\20091007.002\NAVENG.SYS -- (NAVENG [On_Demand | Running]) DRV - [2009-09-17 08:53:46 | 01,323,568 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\VirusDefs\20091007.002\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running]) DRV - [2003-04-02 09:54:16 | 00,020,648 | R--- | M] (Thomson Inc.) -- D:\WINDOWS\System32\DRIVERS\netrcacm.sys -- (netrcacm [On_Demand | Running]) DRV - [2008-10-07 13:33:00 | 06,133,856 | ---- | M] (NVIDIA Corporation) -- D:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running]) DRV - [2008-04-14 00:26:08 | 00,088,320 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx [Auto | Running]) DRV - [2001-08-18 00:54:18 | 00,063,232 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnknb.sys -- (NwlnkNb [Auto | Running]) DRV - [2001-08-18 00:54:18 | 00,055,936 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwlnkspx.sys -- (NwlnkSpx [Auto | Running]) DRV - [2008-04-14 00:04:14 | 00,163,584 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\System32\DRIVERS\nwrdr.sys -- (NWRDR [On_Demand | Stopped]) DRV - [2009-07-09 11:24:29 | 00,138,920 | ---- | M] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys -- (PnkBstrK [On_Demand | Stopped]) DRV - [2001-08-18 00:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- D:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running]) DRV - [2008-01-04 08:10:16 | 00,105,856 | R--- | M] (Realtek Semiconductor Corporation ) -- D:\WINDOWS\System32\DRIVERS\Rtenicxp.sys -- (RTLE8023xp [On_Demand | Stopped]) DRV - [2005-02-04 20:14:30 | 00,324,232 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT [System | Running]) DRV - [2005-02-04 20:14:32 | 00,053,896 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL [System | Running]) DRV - [2008-04-13 22:09:18 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- D:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped]) DRV - [2003-10-05 10:41:14 | 00,123,520 | ---- | M] ( ) -- D:\WINDOWS\system32\DRIVERS\sojubus.sys -- (sojubus [Boot | Running]) DRV - [2003-09-28 10:57:52 | 00,005,504 | ---- | M] ( ) -- D:\WINDOWS\system32\DRIVERS\sojuscsi.sys -- (sojuscsi [Boot | Running]) DRV - [2005-03-30 21:48:20 | 00,372,832 | ---- | M] (Symantec Corporation) -- D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv [On_Demand | Stopped]) DRV - [2005-05-13 19:50:10 | 00,123,488 | ---- | M] (Symantec Corporation) -- D:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running]) DRV - [2005-04-22 12:03:00 | 00,017,976 | ---- | M] (Symantec Corporation) -- D:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV [On_Demand | Running]) DRV - [2005-04-22 12:03:02 | 00,267,192 | ---- | M] (Symantec Corporation) -- D:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI [System | Running]) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://google.pl" FF - prefs.js..extensions.enabledItems: anycolor.pavlos256@gmail.com:0.3.0 FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.2 FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:3.2.8 FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.1 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14 FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2009-09-10 16:13:03 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2009-10-04 19:46:11 | 00,000,000 | ---D | M] [2009-06-09 13:31:44 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Extensions [2009-06-09 13:31:44 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009-10-08 13:27:48 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions [2009-07-09 00:36:32 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2009-07-09 14:14:16 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{64161300-e22b-11db-8314-0800200c9a66} [2009-07-08 23:26:05 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE} [2009-08-14 13:06:23 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009-06-27 12:52:28 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{eaf8a4ef-d221-45ca-9deb-d0934b45fa34} [2009-07-08 23:33:43 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a} [2009-07-08 23:20:28 | 00,000,000 | ---D | M] -- D:\Documents and Settings\PC\Dane aplikacji\mozilla\Firefox\Profiles\28s2bwxy.default\extensions\anycolor.pavlos256@gmail.com [2009-06-20 12:32:59 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions [2009-09-10 16:13:00 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009-09-10 16:13:00 | 00,023,032 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009-09-10 16:13:00 | 00,134,648 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\brwsrcmp.dll [2007-04-30 16:29:22 | 00,049,152 | ---- | M] (Adobe Systems, Inc.) -- D:\Program Files\mozilla firefox\plugins\np32dsw.dll [2009-09-10 16:13:02 | 00,065,528 | ---- | M] (mozilla.org) -- D:\Program Files\mozilla firefox\plugins\npnul32.dll [2003-07-15 06:56:52 | 00,013,888 | ---- | M] (Microsoft Corporation) -- D:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL [2009-07-25 21:28:08 | 00,002,767 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2009-06-13 11:07:49 | 00,001,406 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2009-06-13 11:07:49 | 00,001,706 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\google.xml [2009-06-13 11:07:49 | 00,000,917 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2009-06-13 11:07:49 | 00,000,858 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2009-06-13 11:07:49 | 00,001,183 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2009-06-13 11:07:49 | 00,001,683 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: (27 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - D:\Documents and Settings\PC\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.) O4 - HKLM..\Run: [ccApp] D:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] D:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [RTHDCPL] D:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_02\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [vptray] D:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: E&ksport do programu Microsoft Excel - D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll (Sun Microsystems, Inc.) O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Java Plug-in 1.5.0_02) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Java Plug-in 1.5.0_02) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.172.224.160 89.228.6.21 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter: - text/xml - D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\NavLogon: DllName - D:\WINDOWS\system32\NavLogon.dll - D:\WINDOWS\System32\NavLogon.dll (Symantec Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O28 - HKLM ShellExecuteHooks: {BD344AF4-67AB-4E19-A630-7435587D320B} - D:\WINDOWS\System32\ahndoor0.dll () O30 - LSA: Authentication Packages - (nwprovau) - D:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-11-11 11:04:46 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ] O32 - AutoRun File - [2008-10-24 14:30:24 | 00,837,392 | R--- | M] () - I:\Autorun.exe -- [ CDFS ] O32 - AutoRun File - [2007-01-25 11:51:25 | 00,000,172 | R--- | M] () - I:\Autorun.inf -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\AutoRun.exe -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:43 | 00,402,696 | R--- | M] (Electronic Arts) - K:\Autorun.exe -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:41 | 03,460,608 | R--- | M] () - K:\autorun.dat -- [ CDFS ] O32 - AutoRun File - [2007-08-18 04:49:22 | 00,000,139 | R--- | M] () - K:\autorun.inf -- [ CDFS ] O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - D:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found O35 - comfile [open] -- "%1" %* File not found O35 - exefile [open] -- "%1" %* File not found [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2009-10-07 09:30:00 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\0148 [2009-10-08 15:38:09 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes [2009-10-04 18:05:26 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Dane aplikacji\2K Sports [2009-10-08 15:38:14 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Dane aplikacji\Malwarebytes [2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Dane aplikacji\Sports Interactive [2009-10-06 13:37:14 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Symantec [2009-10-06 13:34:59 | 00,000,000 | ---D | C] -- D:\Program Files\antywirus [2009-10-08 15:38:09 | 00,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware [2009-10-06 13:36:32 | 00,000,000 | ---D | C] -- D:\Program Files\Symantec [2009-10-06 13:36:24 | 00,000,000 | ---D | C] -- D:\Program Files\Symantec AntiVirus [2009-10-08 14:48:22 | 00,000,000 | ---D | C] -- D:\Program Files\trend micro [2009-09-30 21:53:26 | 00,000,000 | -H-D | C] -- D:\Program Files\Zero G Registry [2009-10-08 16:29:06 | 00,070,144 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\AhnRpta.exe [2009-10-08 15:38:10 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009-10-08 15:38:09 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys [2009-10-08 15:37:04 | 04,045,528 | ---- | C] (Malwarebytes Corporation ) -- D:\Documents and Settings\PC\Pulpit\mbam-setup.exe [2009-10-08 15:22:38 | 00,000,000 | -HSD | C] -- D:\RECYCLER [2009-10-08 15:22:33 | 00,000,000 | ---D | C] -- D:\_OTL [2009-10-08 15:00:19 | 00,520,704 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe [2009-10-08 14:48:22 | 00,000,000 | ---D | C] -- D:\rsit [2009-10-08 14:32:04 | 00,000,000 | ---D | C] -- D:\WINDOWS\temp [2009-10-08 14:28:43 | 00,000,000 | ---D | C] -- D:\ComboFix [2009-10-06 13:36:36 | 00,123,488 | ---- | C] (Symantec Corporation) -- D:\WINDOWS\System32\drivers\SYMEVENT.SYS [2009-10-06 13:36:36 | 00,091,856 | ---- | C] (Symantec Corporation) -- D:\WINDOWS\System32\S32EVNT1.DLL [2009-10-05 11:59:07 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Pulpit\xxx [2009-10-04 19:51:37 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\NBA LIVE 08 [2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\Sports Interactive [2009-09-30 21:55:10 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dokumenty\Sports Interactive [2009-09-29 20:42:42 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Moje dokumenty\NBA LIVE 06 [2009-09-12 10:13:47 | 00,000,000 | ---D | C] -- D:\Documents and Settings\PC\Pulpit\kwie [2003-10-05 10:41:14 | 00,123,520 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\sojubus.sys [2003-09-28 10:57:52 | 00,005,504 | ---- | C] ( ) -- D:\WINDOWS\System32\drivers\sojuscsi.sys [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2009-10-08 16:29:00 | 00,195,356 | ---- | M] () -- D:\WINDOWS\System32\nvapps.xml [2009-10-08 16:28:58 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT [2009-10-08 16:28:56 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat [2009-10-08 15:38:13 | 00,000,700 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk [2009-10-08 15:37:45 | 04,045,528 | ---- | M] (Malwarebytes Corporation ) -- D:\Documents and Settings\PC\Pulpit\mbam-setup.exe [2009-10-08 15:34:09 | 00,000,126 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\Fix.reg [2009-10-08 15:00:24 | 00,520,704 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\PC\Pulpit\OTL.exe [2009-10-08 14:47:50 | 00,781,909 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\RSIT.exe [2009-10-08 14:31:24 | 00,000,246 | ---- | M] () -- D:\WINDOWS\system.ini [2009-10-08 14:16:07 | 04,314,060 | -H-- | M] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\IconCache.db [2009-10-08 13:46:37 | 00,002,596 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT [2009-10-08 12:51:16 | 00,763,990 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI [2009-10-08 12:51:16 | 00,355,830 | ---- | M] () -- D:\WINDOWS\System32\perfh015.dat [2009-10-08 12:51:16 | 00,311,740 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat [2009-10-08 12:51:16 | 00,049,712 | ---- | M] () -- D:\WINDOWS\System32\perfc015.dat [2009-10-08 12:51:16 | 00,040,128 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat [2009-10-08 12:02:44 | 00,000,000 | ---- | M] () -- D:\WINDOWS\VPC32.INI [2009-10-06 20:17:39 | 00,000,591 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\NBA LIVE 06.lnk [2009-10-06 14:38:11 | 00,000,573 | ---- | M] () -- D:\WINDOWS\win.ini [2009-10-06 13:31:15 | 00,000,027 | ---- | M] () -- D:\WINDOWS\System32\drivers\etc\hosts [2009-10-04 19:55:28 | 00,011,264 | ---- | M] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009-10-04 19:50:12 | 00,001,471 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\EA SPORTS™ NBA LIVE 08.lnk [2009-10-04 18:26:10 | 00,000,510 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\NBA 2K9.exe.lnk [2009-10-04 18:02:49 | 26,271,866 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\spolszczenie_2k9.rar [2009-10-04 18:01:40 | 00,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl [2009-10-02 19:39:08 | 07,524,224 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\Inna - Deja vu(1).mp3 [2009-09-30 21:54:20 | 00,000,556 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Football Manager 2008.lnk [2009-09-24 16:22:25 | 03,122,605 | ---- | M] () -- D:\Documents and Settings\PC\Pulpit\rihanna - push up on me.mp31253803802_[mp3.teledyski.info].mp3 [2009-09-10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009-09-10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys [color=#E56717]========== Files - No Company Name ==========[/color] [2009-10-08 15:38:13 | 00,000,700 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk [2009-10-08 15:34:09 | 00,000,126 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\Fix.reg [2009-10-08 14:47:39 | 00,781,909 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\RSIT.exe [2009-10-08 12:02:44 | 00,000,000 | ---- | C] () -- D:\WINDOWS\VPC32.INI [2009-10-04 19:50:12 | 00,001,471 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\EA SPORTS™ NBA LIVE 08.lnk [2009-10-04 18:26:10 | 00,000,510 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\NBA 2K9.exe.lnk [2009-10-04 17:48:20 | 26,271,866 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\spolszczenie_2k9.rar [2009-10-02 19:39:33 | 07,524,224 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\Inna - Deja vu(1).mp3 [2009-09-30 21:54:20 | 00,000,556 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\Football Manager 2008.lnk [2009-09-29 20:32:37 | 00,000,591 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\NBA LIVE 06.lnk [2009-09-24 16:30:37 | 03,122,605 | ---- | C] () -- D:\Documents and Settings\PC\Pulpit\rihanna - push up on me.mp31253803802_[mp3.teledyski.info].mp3 [2009-07-09 22:42:17 | 04,314,060 | -H-- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\IconCache.db [2009-06-20 15:01:29 | 00,354,816 | ---- | C] () -- D:\WINDOWS\System32\psisdecd.dll [2009-06-19 14:07:50 | 00,076,407 | ---- | C] () -- D:\Documents and Settings\PC\Dane aplikacji\Smiley.ico [2009-06-13 14:34:41 | 00,000,421 | ---- | C] () -- D:\WINDOWS\ODBC.INI [2009-06-11 15:57:43 | 00,138,920 | ---- | C] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys [2009-06-09 22:10:06 | 00,000,298 | ---- | C] () -- D:\WINDOWS\game.ini [2009-06-09 14:49:10 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\All Users\Dane aplikacji\desktop.ini [2009-06-09 13:27:41 | 00,011,264 | ---- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009-06-09 13:25:04 | 00,042,944 | ---- | C] () -- D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT [2009-06-09 13:03:24 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\PC\Dane aplikacji\desktop.ini [2008-06-25 21:57:00 | 01,703,936 | ---- | C] () -- D:\WINDOWS\System32\nvwdmcpl.dll [2008-06-25 21:57:00 | 01,486,848 | ---- | C] () -- D:\WINDOWS\System32\nview.dll [2008-06-25 21:57:00 | 01,019,904 | ---- | C] () -- D:\WINDOWS\System32\nvwimg.dll [2008-06-25 21:57:00 | 00,466,944 | ---- | C] () -- D:\WINDOWS\System32\nvshell.dll [2008-06-25 21:57:00 | 00,286,720 | ---- | C] () -- D:\WINDOWS\System32\nvnt4cpl.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelTraditionalChinese.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSwedish.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSpanish.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelPortugese.dll [2008-06-11 09:02:34 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelKorean.dll [2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelJapanese.dll [2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelGerman.dll [2008-06-11 09:02:32 | 00,058,648 | ---- | C] () -- D:\WINDOWS\System32\AgCPanelFrench.dll [2008-06-05 08:58:26 | 00,197,912 | ---- | C] () -- D:\WINDOWS\System32\physxcudart_20.dll [2004-09-01 17:49:17 | 03,375,104 | ---- | C] () -- D:\WINDOWS\System32\qt-mt331.dll [2004-08-04 02:44:20 | 00,063,554 | ---- | C] () -- D:\WINDOWS\System32\ahndoor0.dll [2003-04-08 11:40:22 | 00,005,679 | ---- | C] () -- D:\WINDOWS\System32\OUTLPERF.INI [2001-07-22 01:16:20 | 00,000,573 | ---- | C] () -- D:\WINDOWS\win.ini [2001-07-22 01:15:52 | 00,000,246 | ---- | C] () -- D:\WINDOWS\system.ini < End of report > [/log]
Psycholandia komentarz 8 października 2009 komentarz 8 października 2009 W okienko OTL wklej poniższy skrypt i klik na Run Fix: [code]:Processes explorer.exe :Files D:\WINDOWS\AhnRpta.exe :Commands [emptytemp] [start explorer] [Reboot][/code] I dajesz nowego loga z OTL.
kula1576 komentarz 8 października 2009 Autor komentarz 8 października 2009 nowy Log OTL [log] All processes killed ========== PROCESSES ========== Process explorer.exe killed successfully! ========== FILES ========== D:\WINDOWS\AhnRpta.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. D:\Documents and Settings\LocalService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33075 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: PC ->Temp folder emptied: 915400 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Java cache emptied: 0 bytes File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\XUL.mfl scheduled to be deleted on reboot. ->FireFox cache emptied: 33225897 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 32,62 mb OTL by OldTimer - Version 3.0.18.4 log created on 10082009_164132 Files\Folders moved on Reboot... D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_001_ moved successfully. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_002_ moved successfully. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_003_ moved successfully. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\Cache\_CACHE_MAP_ moved successfully. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\urlclassifier3.sqlite moved successfully. D:\Documents and Settings\PC\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\XUL.mfl moved successfully. Registry entries deleted on Reboot... [/log]
Psycholandia komentarz 8 października 2009 komentarz 8 października 2009 Uruchamiasz OTL i klikasz na CleanUp. Czysto.
kula1576 komentarz 8 października 2009 Autor komentarz 8 października 2009 Zrobiłem wszystko ale dalej mam ten proces uruchomiony w menadżerze zadań..
Psycholandia komentarz 8 października 2009 komentarz 8 października 2009 Pobierz Avengera: http://swandog46.geekstogo.com/avenger.zip Wklej w okienko poniższy skrypt: [code]Files to delete: D:\WINDOWS\AhnRpta.exe[/code] I klik na [b]Execute[/b] Dajesz loga powstałego po usuwaniu i sprawdzasz czy proces nadal jest
kula1576 komentarz 8 października 2009 Autor komentarz 8 października 2009 Log po Avanger: [log] Logfile of The Avenger Version 2.0, (c) by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at D:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! File "D:\WINDOWS\AhnRpta.exe" deleted successfully. Completed script processing. ******************* Finished! Terminate. [/log] Niestety po restarcie proces się pokazał ponownie
Psycholandia komentarz 8 października 2009 komentarz 8 października 2009 Pobierz Combofixa: http://download.bleepingcomputer.com/sUBs/ComboFix.exe Otwierasz notatnik i wklejasz w nim: [code]File:: D:\WINDOWS\AhnRpta.exe[/code] następnie: plik -> zapisz jako ----> [b]CFScript.txt[/b]- przeciągasz i upuszczasz CFScript.txt na ikonkę Combofix.exe. Tak jak niżej. [URL=http://img5.imagebanana.com/][IMG]http://img5.imagebanana.com/img/8jtunobk/combofix_cfscript.gif[/IMG][/URL] Dajesz loga powstałego po usuwaniu + sprawdzasz czy proces istnieje.
kula1576 komentarz 8 października 2009 Autor komentarz 8 października 2009 (edytowane) Log z Combofixa: [log] ComboFix 09-10-07.05 - PC 2009-10-08 17:07.8.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3326.2683 [GMT 2:00] Uruchomiony z: d:\documents and settings\PC\Pulpit\ComboFix.exe Użyto następujących komend :: d:\documents and settings\PC\Pulpit\CFScript.txt AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !! FILE :: "d:\windows\AhnRpta.exe" . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . d:\windows\AhnRpta.exe . ((((((((((((((((((((((((( Pliki utworzone od 2009-09-08 do 2009-10-08 ))))))))))))))))))))))))))))))) . 2009-10-08 13:38 . 2009-10-08 13:38 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Malwarebytes 2009-10-08 13:38 . 2009-09-10 12:54 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys 2009-10-08 13:38 . 2009-10-08 13:38 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware 2009-10-08 13:38 . 2009-10-08 13:38 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Malwarebytes 2009-10-08 13:38 . 2009-09-10 12:53 19160 ----a-w- d:\windows\system32\drivers\mbam.sys 2009-10-08 12:48 . 2009-10-08 12:48 -------- d-----w- d:\program files\trend micro 2009-10-07 07:30 . 2009-10-07 07:30 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\0148 2009-10-06 11:37 . 2009-10-06 11:37 -------- d-----w- d:\documents and settings\PC\Ustawienia lokalne\Dane aplikacji\Symantec 2009-10-06 11:36 . 2005-05-13 17:50 91856 ----a-w- d:\windows\system32\S32EVNT1.DLL 2009-10-06 11:36 . 2005-05-13 17:50 123488 ----a-w- d:\windows\system32\drivers\SYMEVENT.SYS 2009-10-06 11:36 . 2009-10-06 11:36 -------- d-----w- d:\program files\Symantec 2009-10-06 11:36 . 2009-10-08 14:57 -------- d-----w- d:\program files\Symantec AntiVirus 2009-10-06 11:34 . 2009-10-06 11:34 -------- d-----w- d:\program files\antywirus 2009-10-04 16:05 . 2009-10-04 16:05 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\2K Sports 2009-09-30 19:55 . 2009-09-30 19:55 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Sports Interactive 2009-09-30 19:53 . 2009-09-30 19:53 -------- d--h--w- d:\program files\Zero G Registry 2009-09-30 19:52 . 2009-09-30 19:52 -------- d--h--w- d:\documents and settings\PC\InstallAnywhere . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-08 13:22 . 2009-06-19 12:07 -------- d-----w- d:\program files\BearShare Applications 2009-10-08 10:51 . 2001-10-26 17:15 49712 ----a-w- d:\windows\system32\perfc015.dat 2009-10-08 10:51 . 2001-10-26 17:15 355830 ----a-w- d:\windows\system32\perfh015.dat 2009-10-06 12:37 . 2009-06-20 09:52 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\uTorrent 2009-10-06 12:11 . 2009-06-09 11:56 -------- d-----w- d:\program files\Common Files\Symantec Shared 2009-10-06 11:36 . 2009-06-09 12:01 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Symantec 2009-09-15 20:22 . 2009-06-09 14:36 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu 2009-09-08 16:55 . 2009-06-09 13:36 -------- d-----w- d:\program files\AGEIA Technologies 2009-09-05 21:05 . 2009-06-14 18:23 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\BESTplayer 2009-09-04 09:07 . 2009-06-09 14:36 -------- d-----w- d:\program files\Nowe Gadu-Gadu 2009-08-28 12:56 . 2009-08-28 12:56 -------- d-----w- d:\program files\Half-Life Model Viewer 2009-08-22 21:49 . 2009-06-09 13:03 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Test Drive Unlimited 2009-07-27 17:27 . 2009-06-09 11:58 107888 ----a-w- d:\windows\system32\CmdLineExt.dll . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144] "SunJavaUpdateSched"="d:\program files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 36975] "NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016] "ccApp"="d:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752] "vptray"="d:\progra~1\SYMANT~1\VPTray.exe" [2005-06-23 85696] "Malwarebytes Anti-Malware (reboot)"="d:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.exe [2008-05-14 16862720] "nwiz"="nwiz.exe" - d:\windows\system32\nwiz.exe [2008-10-07 1630208] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{BD344AF4-67AB-4E19-A630-7435587D320B}"= "d:\windows\system32\ahndoor0.dll" [2008-04-14 63554] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Talisman.lnk] path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Talisman.lnk backup=d:\windows\pss\Talisman.lnkStartup [HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Yahoo! Widget Engine.lnk] path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Yahoo! Widget Engine.lnk backup=d:\windows\pss\Yahoo! Widget Engine.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "g:\\Gry\\Test Drive Unlimited\\TestDriveUnlimited.exe"= "d:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"= "g:\\Gry\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "d:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"= "d:\\Program Files\\Ares\\Ares.exe"= "d:\\Program Files\\uTorrent\\uTorrent.exe"= "d:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"= "d:\\Program Files\\Ares\\chatServer.exe"= "c:\\Program Files\\The All-Seeing Eye\\eye.exe"= "g:\\Gry\\Stronghold 2\\Stronghold2.exe"= "g:\\Gry\\PES09\\pes2009.exe"= "g:\\Gry\\Q U A K E II\\r1q2.exe"= "g:\\Gry\\Valve\\SteamApps\\kula_1576\\counter-strike\\hl.exe"= "g:\\Gry\\Fotbal Menager 2008\\fm.exe"= R0 sojubus;sojubus;d:\windows\system32\drivers\sojubus.sys [2003-10-05 123520] R0 sojuscsi;sojuscsi;d:\windows\system32\drivers\sojuscsi.sys [2003-09-28 5504] S2 gupdate1ca0016106c1b22;Usługa Google Update (gupdate1ca0016106c1b22);d:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 133104] S3 SavRoam;SAVRoam;d:\program files\Symantec AntiVirus\SavRoam.exe [2005-06-23 124608] --- Inne Usługi/Sterowniki w Pamięci --- *Deregistered* - EraserUtilDrvI9 . . ------- Skan uzupełniający ------- . uStart Page = hxxp://search.bearshare.com/ uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com IE: E&ksport do programu Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 FF - ProfilePath - d:\documents and settings\PC\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\ FF - prefs.js: browser.startup.homepage - hxxp://google.pl FF - plugin: d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu\_userdata\npgg.1.dll FF - plugin: d:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava11.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava12.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava13.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava14.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava32.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll . - - - - USUNIĘTO PUSTE WPISY - - - - AddRemove-BearShare MediaBar - d:\program files\BearShare Applications\BearShare MediaBar\Uninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-08 17:09 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów ... skanowanie ukrytych wpisów autostartu ... skanowanie ukrytych plików ... skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- [HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID] @Denied: (Full) (LocalSystem) [HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:a6,7d,1d,90,39,09,ad,46,99,fe,17,b8,16,6f,7f,0b,be,77,2e,c8,07,81,27, 3f,75,79,8f,5a,76,d4,12,5a,f4,0a,60,db,5a,2a,57,cc,ca,e9,89,35,11,a2,a6,72,\ "??"=hex:a0,87,12,9e,a4,06,2f,b5,52,62,2b,d2,0b,43,9d,7b [HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\License information*] "datasecu"=hex:03,ca,b9,2d,48,91,81,3c,29,08,70,54,2c,bf,3a,61,4a,d0,87,92,99, ed,7e,57,ba,05,a0,3b,26,14,09,29,be,d4,de,78,8d,b6,40,81,a7,af,1e,0e,ba,3e,\ "rkeysecu"=hex:94,94,3a,05,62,40,36,54,f0,6a,81,57,71,86,8d,50 . Czas ukończenia: 2009-10-08 17:10 ComboFix-quarantined-files.txt 2009-10-08 15:10 Przed: 17 784 393 728 bajtów wolnych Po: 17 768 587 264 bajtów wolnych 154 [/log] Niestety po restarcie znów się to pokazało. Nic się już więcej nie da zrobić? Nie da się tego usunąć? Ta cisza oznacza już brak możliwości? Kurka nie wieże od 9 rano z tym walczę...w każdym bądź razie bardzo dziękuje za pomoc!
Gość komentarz 9 października 2009 komentarz 9 października 2009 (edytowane) Wklej do [b]Notatnika[/b] tekst który jest na tej stronie: http://wklej.org/id/169690/ [b]>>Plik>>Zapisz jako... >>>[/b] [b]CFScript[/b] Przeciągnij i upuść plik [b]CFScript.txt[/b] na plik [b]ComboFix.exe[/b] [color="blue"]-->[/color][url="http://imageshack.us"][img]http://img228.imageshack.us/img228/5796/cfscriptb5b4me3.gif[/img][/url] Ma się rozpocząć usuwanie. (i powstanie log).Daj ten log, który powstanie w trakcie usuwania. Jeśli pójdzie dobrze, to: [b]Po restarcie[/b] usuń ręcznie folder [b]C:\[/b][b]Qoobox.[/b] .
kula1576 komentarz 11 października 2009 Autor komentarz 11 października 2009 (edytowane) Zrobiłem tak jak w instrukcji wyżej i oto nowy log z Combofixa: [log] ComboFix 09-10-10.02 - PC 2009-10-11 11:18.12.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3326.2832 [GMT 2:00] Uruchomiony z: d:\documents and settings\PC\Pulpit\ComboFix.exe Użyto następujących komend :: d:\documents and settings\PC\Pulpit\CFScript.txt AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} FILE :: "d:\windows\system32\ahndoor0.dll" "d:\windows\system32\ahndoor1.dll" "d:\windows\system32\ahndoor2.dll" "d:\windows\system32\ahndoor3.dll" . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\vlvtdflx.exe d:\docume~1\PC\USTAWI~1\Temp\cvasds0.dll d:\docume~1\PC\USTAWI~1\Temp\cvasds1.dll D:\vlvtdflx.exe d:\windows\AhnRpta.exe d:\windows\system32\ahndoor0.dll E:\vlvtdflx.exe F:\vlvtdflx.exe G:\vlvtdflx.exe H:\vlvtdflx.exe . ((((((((((((((((((((((((( Pliki utworzone od 2009-09-11 do 2009-10-11 ))))))))))))))))))))))))))))))) . 2009-10-08 13:38 . 2009-10-08 13:38 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Malwarebytes 2009-10-08 13:38 . 2009-10-08 13:38 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Malwarebytes 2009-10-08 12:48 . 2009-10-08 12:48 -------- d-----w- d:\program files\trend micro 2009-10-07 07:30 . 2009-10-07 07:30 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\0148 2009-10-06 11:37 . 2009-10-06 11:37 -------- d-----w- d:\documents and settings\PC\Ustawienia lokalne\Dane aplikacji\Symantec 2009-10-06 11:36 . 2005-05-13 17:50 91856 ----a-w- d:\windows\system32\S32EVNT1.DLL 2009-10-06 11:36 . 2005-05-13 17:50 123488 ----a-w- d:\windows\system32\drivers\SYMEVENT.SYS 2009-10-06 11:36 . 2009-10-06 11:36 -------- d-----w- d:\program files\Symantec 2009-10-06 11:36 . 2009-10-11 09:20 -------- d-----w- d:\program files\Symantec AntiVirus 2009-10-06 11:34 . 2009-10-06 11:34 -------- d-----w- d:\program files\antywirus 2009-10-04 16:05 . 2009-10-04 16:05 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\2K Sports 2009-09-30 19:55 . 2009-09-30 19:55 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Sports Interactive 2009-09-30 19:53 . 2009-09-30 19:53 -------- d--h--w- d:\program files\Zero G Registry 2009-09-30 19:52 . 2009-09-30 19:52 -------- d--h--w- d:\documents and settings\PC\InstallAnywhere . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-08 13:22 . 2009-06-19 12:07 -------- d-----w- d:\program files\BearShare Applications 2009-10-08 10:51 . 2001-10-26 17:15 49712 ----a-w- d:\windows\system32\perfc015.dat 2009-10-08 10:51 . 2001-10-26 17:15 355830 ----a-w- d:\windows\system32\perfh015.dat 2009-10-06 12:37 . 2009-06-20 09:52 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\uTorrent 2009-10-06 12:11 . 2009-06-09 11:56 -------- d-----w- d:\program files\Common Files\Symantec Shared 2009-10-06 11:36 . 2009-06-09 12:01 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Symantec 2009-09-15 20:22 . 2009-06-09 14:36 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu 2009-09-08 16:55 . 2009-06-09 13:36 -------- d-----w- d:\program files\AGEIA Technologies 2009-09-05 21:05 . 2009-06-14 18:23 -------- d-----w- d:\documents and settings\PC\Dane aplikacji\BESTplayer 2009-09-04 09:07 . 2009-06-09 14:36 -------- d-----w- d:\program files\Nowe Gadu-Gadu 2009-08-28 12:56 . 2009-08-28 12:56 -------- d-----w- d:\program files\Half-Life Model Viewer 2009-08-22 21:49 . 2009-06-09 13:03 -------- d-----w- d:\documents and settings\All Users\Dane aplikacji\Test Drive Unlimited 2009-07-27 17:27 . 2009-06-09 11:58 107888 ----a-w- d:\windows\system32\CmdLineExt.dll . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144] "SunJavaUpdateSched"="d:\program files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 36975] "NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016] "ccApp"="d:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752] "vptray"="d:\progra~1\SYMANT~1\VPTray.exe" [2005-06-23 85696] "RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.exe [2008-05-14 16862720] "nwiz"="nwiz.exe" - d:\windows\system32\nwiz.exe [2008-10-07 1630208] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Talisman.lnk] path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Talisman.lnk backup=d:\windows\pss\Talisman.lnkStartup [HKLM\~\startupfolder\D:^Documents and Settings^PC^Menu Start^Programy^Autostart^Yahoo! Widget Engine.lnk] path=d:\documents and settings\PC\Menu Start\Programy\Autostart\Yahoo! Widget Engine.lnk backup=d:\windows\pss\Yahoo! Widget Engine.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "g:\\Gry\\Test Drive Unlimited\\TestDriveUnlimited.exe"= "d:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"= "g:\\Gry\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "d:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"= "d:\\Program Files\\Ares\\Ares.exe"= "d:\\Program Files\\uTorrent\\uTorrent.exe"= "d:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"= "d:\\Program Files\\Ares\\chatServer.exe"= "c:\\Program Files\\The All-Seeing Eye\\eye.exe"= "g:\\Gry\\Stronghold 2\\Stronghold2.exe"= "g:\\Gry\\PES09\\pes2009.exe"= "g:\\Gry\\Q U A K E II\\r1q2.exe"= "g:\\Gry\\Valve\\SteamApps\\kula_1576\\counter-strike\\hl.exe"= "g:\\Gry\\Fotbal Menager 2008\\fm.exe"= R0 sojubus;sojubus;d:\windows\system32\drivers\sojubus.sys [2003-10-05 123520] R0 sojuscsi;sojuscsi;d:\windows\system32\drivers\sojuscsi.sys [2003-09-28 5504] S2 gupdate1ca0016106c1b22;Usługa Google Update (gupdate1ca0016106c1b22);d:\program files\Google\Update\GoogleUpdate.exe [2009-07-08 133104] S3 SavRoam;SAVRoam;d:\program files\Symantec AntiVirus\SavRoam.exe [2005-06-23 124608] --- Inne Usługi/Sterowniki w Pamięci --- *Deregistered* - EraserUtilDrvI9 . . ------- Skan uzupełniający ------- . uStart Page = hxxp://search.bearshare.com/ uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com IE: E&ksport do programu Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 FF - ProfilePath - d:\documents and settings\PC\Dane aplikacji\Mozilla\Firefox\Profiles\28s2bwxy.default\ FF - prefs.js: browser.startup.homepage - hxxp://google.pl FF - plugin: d:\documents and settings\PC\Dane aplikacji\Nowe Gadu-Gadu\_userdata\npgg.1.dll FF - plugin: d:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava11.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava12.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava13.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava14.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJava32.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll FF - plugin: d:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-11 11:21 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów ... skanowanie ukrytych wpisów autostartu ... skanowanie ukrytych plików ... skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- [HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID] @Denied: (Full) (LocalSystem) [HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:a6,7d,1d,90,39,09,ad,46,99,fe,17,b8,16,6f,7f,0b,be,77,2e,c8,07,81,27, 3f,75,79,8f,5a,76,d4,12,5a,f4,0a,60,db,5a,2a,57,cc,ca,e9,89,35,11,a2,a6,72,\ "??"=hex:a0,87,12,9e,a4,06,2f,b5,52,62,2b,d2,0b,43,9d,7b [HKEY_USERS\S-1-5-21-789336058-162531612-839522115-1003\Software\SecuROM\License information*] "datasecu"=hex:03,ca,b9,2d,48,91,81,3c,29,08,70,54,2c,bf,3a,61,4a,d0,87,92,99, ed,7e,57,ba,05,a0,3b,26,14,09,29,be,d4,de,78,8d,b6,40,81,a7,af,1e,0e,ba,3e,\ "rkeysecu"=hex:94,94,3a,05,62,40,36,54,f0,6a,81,57,71,86,8d,50 . ------------------------ Pozostałe uruchomione procesy ------------------------ . d:\program files\Common Files\Symantec Shared\ccSetMgr.exe d:\program files\Common Files\Symantec Shared\ccEvtMgr.exe d:\program files\Symantec AntiVirus\DefWatch.exe d:\windows\system32\nvsvc32.exe d:\windows\system32\PnkBstrA.exe d:\windows\system32\rundll32.exe d:\windows\system32\PnkBstrB.exe d:\program files\Symantec AntiVirus\Rtvscan.exe d:\windows\system32\wdfmgr.exe d:\windows\system32\wscntfy.exe . ************************************************************************** . Czas ukończenia: 2009-10-11 11:23 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2009-10-11 09:22 ComboFix2.txt 2009-10-09 07:41 Przed: 17 485 537 280 bajtów wolnych Po: 17 444 581 376 bajtów wolnych 173 [/log] Po dodatkowym restarcie systemu zauważyłem ze proces w menadżerze który mnie tak nękał już się nie pojawił AhnRpta.exe wielkie dzięki za POMOC ! Jakby coś jeszcze w tym logu się znalazło to proszę o podpowiedź.
Gość komentarz 11 października 2009 komentarz 11 października 2009 Jak na moje tureckie oko - jest OK. Do poczytania/wykonania: http://www.forumpc.pl/index.php?showtopic=99378&st=0&p=695208&fromsearch=1&#entry695208 .
kula1576 komentarz 11 października 2009 Autor komentarz 11 października 2009 Wielkie DZIĘKI za POMOC ! Pozdrawiam
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.