gemms
Topic Starter
hi.
My computer was working very slowly… so I found that topic…
http://forums.whatthetech.com/Win32_PornPo…re_t112471.html
I've done everything as the administrator said. (installed all the programs - malwarebytes, aft cleaner, tdsskiller and finally combofix)) But now, I don't know how to remove combofix:/ I heard that I have to re-enable my emulation drivers after I finish scanning the system with combofix. Can anyone help me? Please!
And another question is… is the log ok? Did the programme find anything bad?
ComboFix 10-08-09.03 - anonymus 2010-08-10 13:10:40.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.502.130 [GMT 1:00]
Uruchomiony z: c:\documents and settings\anonymus\Pulpit\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100809-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Pliki utworzone od 2010-07-10 do 2010-08-10 )))))))))))))))))))))))))))))))
.
2010-08-10 11:18 . 2010-08-10 11:18 ——– d—–w- c:\documents and settings\anonymus\Dane aplikacji\Malwarebytes
2010-08-10 11:18 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-10 11:18 . 2010-08-10 11:18 ——– d—–w- c:\documents and settings\All Users\Dane aplikacji\Malwarebytes
2010-08-10 11:18 . 2010-08-10 11:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-10 11:18 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-10 10:05 . 2010-07-12 08:55 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-08-07 16:29 . 2010-08-09 23:46 ——– d—a-w- c:\documents and settings\All Users\Dane aplikacji\TEMP
2010-08-07 16:28 . 2010-08-09 23:48 ——– d—–w- c:\documents and settings\All Users\Dane aplikacji\SpeedBit
2010-08-07 16:28 . 2010-08-09 23:50 ——– d—–w- c:\program files\DAP
2010-08-07 11:48 . 2010-08-07 11:48 503808 —-a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-657cf1df-n\msvcp71.dll
2010-08-07 11:48 . 2010-08-07 11:48 499712 —-a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-657cf1df-n\jmc.dll
2010-08-07 11:48 . 2010-08-07 11:48 348160 —-a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-657cf1df-n\msvcr71.dll
2010-08-07 11:48 . 2010-08-07 11:48 61440 —-a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5a2ffb76-n\decora-sse.dll
2010-08-07 11:48 . 2010-08-07 11:48 12800 —-a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5a2ffb76-n\decora-d3d.dll
2010-08-06 23:17 . 2010-07-12 08:55 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-08-06 23:03 . 2010-08-06 23:03 ——– d—–w- c:\documents and settings\anonymus\Ustawienia lokalne\Dane aplikacji\Sunbelt Software
2010-08-06 23:02 . 2010-08-06 23:02 ——– dc-h–w- c:\documents and settings\All Users\Dane aplikacji\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
2010-08-06 23:02 . 2010-07-12 08:56 2979280 -c–a-w- c:\documents and settings\All Users\Dane aplikacji\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
2010-08-03 22:45 . 2010-08-03 22:45 ——– d—–w- c:\documents and settings\anonymus\WapSter
2010-08-03 22:45 . 2010-08-03 22:45 ——– d—–w- c:\program files\WapSter
2010-08-03 22:34 . 2010-08-03 22:34 ——– d—–w- c:\documents and settings\All Users\Dane aplikacji\LightScribe
2010-07-30 02:40 . 2010-07-30 02:40 ——– d—–w- c:\program files\Damian Pasternak
2010-07-27 15:28 . 2010-07-27 15:28 ——– d—–w- c:\program files\Common Files\Skype
2010-07-27 12:08 . 2010-07-27 12:08 ——– d—–w- c:\documents and settings\anonymus\.dsig
2010-07-14 10:03 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-11 15:58 . 2008-04-13 18:47 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2010-07-11 15:58 . 2008-04-13 18:47 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-09 21:46 . 2010-02-12 19:29 ——– d—–w- c:\documents and settings\anonymus\Dane aplikacji\vlc
2010-08-09 18:50 . 2009-10-08 20:45 ——– d—–w- c:\program files\Hotspot Shield
2010-08-06 23:01 . 2010-03-15 23:25 ——– d—–w- c:\program files\Lavasoft
2010-08-06 23:01 . 2009-10-11 01:18 ——– d—–w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft
2010-07-28 11:48 . 2009-10-01 18:57 ——– d—–w- c:\documents and settings\anonymus\Dane aplikacji\Skype
2010-07-27 15:22 . 2009-10-01 18:58 ——– d—–w- c:\documents and settings\anonymus\Dane aplikacji\skypePM
2010-06-18 21:47 . 2004-08-04 12:00 67496 —-a-w- c:\windows\system32\perfc015.dat
2010-06-18 21:47 . 2004-08-04 12:00 436560 —-a-w- c:\windows\system32\perfh015.dat
2010-06-16 20:33 . 2009-09-15 20:04 37376 —-a-w- c:\windows\system32\drivers\hssdrv.sys
2010-06-14 14:31 . 2009-09-28 22:47 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-28 01:32 . 2010-05-28 01:32 95232 -c–a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-05-28 01:32 . 2010-05-28 01:32 61440 -c–a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-05-28 01:32 . 2010-05-28 01:32 10240 -c–a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-05-28 01:32 . 2010-05-28 01:32 8192 -c–a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-05-28 01:31 . 2010-05-28 01:33 34760920 —-a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_pol_web.exe
2010-05-23 22:35 . 2010-05-23 22:35 503808 -c–a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50673647-n\msvcp71.dll
2010-05-23 22:35 . 2010-05-23 22:35 499712 -c–a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50673647-n\jmc.dll
2010-05-23 22:35 . 2010-05-23 22:35 348160 -c–a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50673647-n\msvcr71.dll
2010-05-23 22:35 . 2010-05-23 22:35 61440 -c–a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-689a5023-n\decora-sse.dll
2010-05-23 22:35 . 2010-05-23 22:35 12800 -c–a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-689a5023-n\decora-d3d.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2010-06-23 02:49 230448 —-a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2006-04-19 65536]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-05-04 86016]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"SMSERIAL"="sm56hlpr.exe" [2006-01-20 544768]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-21 761946]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-06-11 20:43 640376 -c–a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2008-06-12 00:25 37232 -c–a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-08-23 15:36 455968 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 —-a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 00:54 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\WapSter\\WapSter AQQ\\AQQ.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-08-07 64288]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-09-29 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-09-29 20560]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS –> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-07-12 1352832]
S1 mailKmd;mailKmd; [x]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-09-29 691696]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 15:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Zawartość folderu 'Zaplanowane zadania'
2010-08-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 08:55]
.
.
——- Skan uzupełniający ——-
.
uStart Page = hxxp://google.pl/
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\anonymus\Dane aplikacji\Mozilla\Firefox\Profiles\f85cui42.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.pl
FF - prefs.js: keyword.URL -
FF - plugin: c:\documents and settings\All Users\Dane aplikacji\Gadu-Gadu 10\_userdata\npgg.2.dll
FF - plugin: c:\documents and settings\anonymus\Dane aplikacji\Gadu-Gadu 10\_userdata\npgg.2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
—- FIREFOX - SPOSÓB POSTĘPOWANIA —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKLM-Run-LMgrVolOSD - c:\program files\Launch Manager\OSD.exe
HKLM-Run-LMgrOSD - c:\program files\Launch Manager\OSDCtrl.exe
HKLM-Run-CtrlVol - c:\program files\Launch Manager\CtrlVol.exe
MSConfigStartUp-PC Suite Tray - c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-10 13:21
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów …
skanowanie ukrytych wpisów autostartu …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CtrlVol = c:\program files\Launch Manager\CtrlVol.exe?????\??????|x??|????q??|?j?wQj?w????????,??? ???????????????d??????|????????p?????@?&???????0y?w,??????????????sx??s@??????????????|h??st??????????s?????????????????C?sc"?sx??s???????w??@?N'?s?I9? :@??I9????????
skanowanie ukrytych plików …
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
——————— Pliki DLL ładowane pod uruchomionymi procesami ———————
- - - - - - - > 'winlogon.exe'(1032)
c:\windows\system32\igfxdev.dll
.
Czas ukończenia: 2010-08-10 13:25:46
ComboFix-quarantined-files.txt 2010-08-10 12:25
Przed: 9 460 953 088 bajtów wolnych
Po: 9 439 850 496 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 87DEA8ADEF3FBA222E8E23B9A05DFDDE
Thanks for help!
My computer was working very slowly… so I found that topic…
http://forums.whatthetech.com/Win32_PornPo…re_t112471.html
I've done everything as the administrator said. (installed all the programs - malwarebytes, aft cleaner, tdsskiller and finally combofix)) But now, I don't know how to remove combofix:/ I heard that I have to re-enable my emulation drivers after I finish scanning the system with combofix. Can anyone help me? Please!
And another question is… is the log ok? Did the programme find anything bad?
ComboFix 10-08-09.03 - anonymus 2010-08-10 13:10:40.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.502.130 [GMT 1:00]
Uruchomiony z: c:\documents and settings\anonymus\Pulpit\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100809-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Pliki utworzone od 2010-07-10 do 2010-08-10 )))))))))))))))))))))))))))))))
.
2010-08-10 11:18 . 2010-08-10 11:18 ——– d—–w- c:\documents and settings\anonymus\Dane aplikacji\Malwarebytes
2010-08-10 11:18 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-10 11:18 . 2010-08-10 11:18 ——– d—–w- c:\documents and settings\All Users\Dane aplikacji\Malwarebytes
2010-08-10 11:18 . 2010-08-10 11:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-10 11:18 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-10 10:05 . 2010-07-12 08:55 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-08-07 16:29 . 2010-08-09 23:46 ——– d—a-w- c:\documents and settings\All Users\Dane aplikacji\TEMP
2010-08-07 16:28 . 2010-08-09 23:48 ——– d—–w- c:\documents and settings\All Users\Dane aplikacji\SpeedBit
2010-08-07 16:28 . 2010-08-09 23:50 ——– d—–w- c:\program files\DAP
2010-08-07 11:48 . 2010-08-07 11:48 503808 —-a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-657cf1df-n\msvcp71.dll
2010-08-07 11:48 . 2010-08-07 11:48 499712 —-a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-657cf1df-n\jmc.dll
2010-08-07 11:48 . 2010-08-07 11:48 348160 —-a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-657cf1df-n\msvcr71.dll
2010-08-07 11:48 . 2010-08-07 11:48 61440 —-a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5a2ffb76-n\decora-sse.dll
2010-08-07 11:48 . 2010-08-07 11:48 12800 —-a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-5a2ffb76-n\decora-d3d.dll
2010-08-06 23:17 . 2010-07-12 08:55 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-08-06 23:03 . 2010-08-06 23:03 ——– d—–w- c:\documents and settings\anonymus\Ustawienia lokalne\Dane aplikacji\Sunbelt Software
2010-08-06 23:02 . 2010-08-06 23:02 ——– dc-h–w- c:\documents and settings\All Users\Dane aplikacji\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
2010-08-06 23:02 . 2010-07-12 08:56 2979280 -c–a-w- c:\documents and settings\All Users\Dane aplikacji\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
2010-08-03 22:45 . 2010-08-03 22:45 ——– d—–w- c:\documents and settings\anonymus\WapSter
2010-08-03 22:45 . 2010-08-03 22:45 ——– d—–w- c:\program files\WapSter
2010-08-03 22:34 . 2010-08-03 22:34 ——– d—–w- c:\documents and settings\All Users\Dane aplikacji\LightScribe
2010-07-30 02:40 . 2010-07-30 02:40 ——– d—–w- c:\program files\Damian Pasternak
2010-07-27 15:28 . 2010-07-27 15:28 ——– d—–w- c:\program files\Common Files\Skype
2010-07-27 12:08 . 2010-07-27 12:08 ——– d—–w- c:\documents and settings\anonymus\.dsig
2010-07-14 10:03 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-11 15:58 . 2008-04-13 18:47 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2010-07-11 15:58 . 2008-04-13 18:47 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-09 21:46 . 2010-02-12 19:29 ——– d—–w- c:\documents and settings\anonymus\Dane aplikacji\vlc
2010-08-09 18:50 . 2009-10-08 20:45 ——– d—–w- c:\program files\Hotspot Shield
2010-08-06 23:01 . 2010-03-15 23:25 ——– d—–w- c:\program files\Lavasoft
2010-08-06 23:01 . 2009-10-11 01:18 ——– d—–w- c:\documents and settings\All Users\Dane aplikacji\Lavasoft
2010-07-28 11:48 . 2009-10-01 18:57 ——– d—–w- c:\documents and settings\anonymus\Dane aplikacji\Skype
2010-07-27 15:22 . 2009-10-01 18:58 ——– d—–w- c:\documents and settings\anonymus\Dane aplikacji\skypePM
2010-06-18 21:47 . 2004-08-04 12:00 67496 —-a-w- c:\windows\system32\perfc015.dat
2010-06-18 21:47 . 2004-08-04 12:00 436560 —-a-w- c:\windows\system32\perfh015.dat
2010-06-16 20:33 . 2009-09-15 20:04 37376 —-a-w- c:\windows\system32\drivers\hssdrv.sys
2010-06-14 14:31 . 2009-09-28 22:47 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-28 01:32 . 2010-05-28 01:32 95232 -c–a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-05-28 01:32 . 2010-05-28 01:32 61440 -c–a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-05-28 01:32 . 2010-05-28 01:32 10240 -c–a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-05-28 01:32 . 2010-05-28 01:32 8192 -c–a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-05-28 01:31 . 2010-05-28 01:33 34760920 —-a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_pol_web.exe
2010-05-23 22:35 . 2010-05-23 22:35 503808 -c–a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50673647-n\msvcp71.dll
2010-05-23 22:35 . 2010-05-23 22:35 499712 -c–a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50673647-n\jmc.dll
2010-05-23 22:35 . 2010-05-23 22:35 348160 -c–a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50673647-n\msvcr71.dll
2010-05-23 22:35 . 2010-05-23 22:35 61440 -c–a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-689a5023-n\decora-sse.dll
2010-05-23 22:35 . 2010-05-23 22:35 12800 -c–a-w- c:\documents and settings\anonymus\Dane aplikacji\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-689a5023-n\decora-d3d.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2010-06-23 02:49 230448 —-a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2006-04-19 65536]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-05-04 86016]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"SMSERIAL"="sm56hlpr.exe" [2006-01-20 544768]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-21 761946]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-06-11 20:43 640376 -c–a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2008-06-12 00:25 37232 -c–a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-08-23 15:36 455968 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 —-a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 00:54 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\WapSter\\WapSter AQQ\\AQQ.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-08-07 64288]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-09-29 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-09-29 20560]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS –> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-07-12 1352832]
S1 mailKmd;mailKmd; [x]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2009-09-29 691696]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 15:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Zawartość folderu 'Zaplanowane zadania'
2010-08-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 08:55]
.
.
——- Skan uzupełniający ——-
.
uStart Page = hxxp://google.pl/
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\anonymus\Dane aplikacji\Mozilla\Firefox\Profiles\f85cui42.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.pl
FF - prefs.js: keyword.URL -
FF - plugin: c:\documents and settings\All Users\Dane aplikacji\Gadu-Gadu 10\_userdata\npgg.2.dll
FF - plugin: c:\documents and settings\anonymus\Dane aplikacji\Gadu-Gadu 10\_userdata\npgg.2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
—- FIREFOX - SPOSÓB POSTĘPOWANIA —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKLM-Run-LMgrVolOSD - c:\program files\Launch Manager\OSD.exe
HKLM-Run-LMgrOSD - c:\program files\Launch Manager\OSDCtrl.exe
HKLM-Run-CtrlVol - c:\program files\Launch Manager\CtrlVol.exe
MSConfigStartUp-PC Suite Tray - c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-10 13:21
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów …
skanowanie ukrytych wpisów autostartu …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CtrlVol = c:\program files\Launch Manager\CtrlVol.exe?????\??????|x??|????q??|?j?wQj?w????????,??? ???????????????d??????|????????p?????@?&???????0y?w,??????????????sx??s@??????????????|h??st??????????s?????????????????C?sc"?sx??s???????w??@?N'?s?I9? :@??I9????????
skanowanie ukrytych plików …
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
——————— Pliki DLL ładowane pod uruchomionymi procesami ———————
- - - - - - - > 'winlogon.exe'(1032)
c:\windows\system32\igfxdev.dll
.
Czas ukończenia: 2010-08-10 13:25:46
ComboFix-quarantined-files.txt 2010-08-10 12:25
Przed: 9 460 953 088 bajtów wolnych
Po: 9 439 850 496 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 87DEA8ADEF3FBA222E8E23B9A05DFDDE
Thanks for help!