Zaraz bede skanował . Nie działa ani EPilog Ani Freya ani Interlude ....
ComboFix 11-08-30.02 - JOoKeR 11-08-31 18:37:52.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.1023.696 [GMT 2:00]
Uruchomiony z: c:\documents and settings\JOoKeR\Moje dokumenty\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\JOoKeR\Dane aplikacji\EurekaLog
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\1.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\a.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\b.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\c.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\d.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\e.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\f.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\g.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\h.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\i.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\J.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\k.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\l.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\m.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\mru.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\n.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\o.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\p.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\q.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\r.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\s.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\t.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\u.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\v.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\w.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\x.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\y.xml
c:\documents and settings\JOoKeR\Dane aplikacji\PriceGong\Data\z.xml
c:\windows\ehome\medctrro.exe
c:\windows\system32\drivers\str.sys
.
.
((((((((((((((((((((((((( Pliki utworzone od 2011-07-28 do 2011-08-31 )))))))))))))))))))))))))))))))
.
.
2011-08-31 07:43 . 2011-08-31 07:43 -------- d-----w- c:\windows\LastGood.Tmp
2011-08-17 15:27 . 2011-08-17 15:27 -------- d-----w- c:\windows\system32\XPSViewer
2011-08-17 15:27 . 2007-03-22 18:24 28160 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-08-17 15:26 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2011-08-17 12:33 . 2011-08-17 12:33 -------- d-----w- c:\program files\Microsoft Silverlight
2011-08-17 12:33 . 2011-08-17 12:33 -------- d-----w- c:\program files\Microsoft Synchronization Services
2011-08-17 12:33 . 2011-08-17 12:33 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-08-17 12:32 . 2011-08-17 12:32 112832 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Microsoft\VCExpress\10.0\1033\ResourceCache.dll
2011-08-17 12:25 . 2011-08-17 12:25 -------- d-----w- c:\windows\symbols
2011-08-17 12:24 . 2011-08-17 15:27 -------- d-----w- c:\program files\MSBuild
2011-08-17 12:24 . 2011-08-17 12:27 -------- d-----w- c:\program files\Microsoft Visual Studio 10.0
2011-08-17 12:24 . 2011-08-17 12:24 -------- d-----w- c:\program files\Microsoft SDKs
2011-08-17 12:24 . 2011-08-17 12:24 -------- d-----w- c:\program files\Microsoft Help Viewer
2011-08-17 12:24 . 2011-08-17 12:24 -------- d-----w- c:\program files\Common Files\Merge Modules
2011-08-17 12:23 . 2011-08-17 12:23 -------- d-----w- c:\program files\Reference Assemblies
2011-08-17 11:58 . 2011-08-17 12:26 -------- d-----w- c:\program files\Microsoft.NET
2011-08-17 10:10 . 2009-04-06 08:08 5174 ----a-w- c:\windows\system32\nppt9x.vxd
2011-08-17 10:10 . 2009-04-06 08:08 4682 ----a-w- c:\windows\system32\npptNT2.sys
2011-08-17 09:17 . 2011-08-17 09:17 -------- d-----w- c:\program files\NCsoft
2011-08-10 12:36 . 2011-08-10 12:36 -------- d-----w- c:\program files\EA GAMES
2011-08-10 12:30 . 2002-12-11 22:14 46592 ----a-w- c:\windows\system32\dxdllreg.exe
2011-08-10 12:20 . 2011-08-10 12:20 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-08-10 12:19 . 2011-08-10 12:22 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-08-08 20:15 . 2011-08-08 20:15 -------- d-----w- c:\program files\Conduit
2011-08-08 20:15 . 2011-08-08 20:15 -------- d-----w- c:\documents and settings\JOoKeR\Ustawienia lokalne\Dane aplikacji\Softonic-Polska
2011-08-08 20:14 . 2011-08-08 20:14 -------- d-----w- c:\program files\Softonic-Polska
.
.
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-15 13:29 . 2004-08-03 21:15 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2001-08-17 23:55 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2010-11-16 16:31 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-21 18:18 . 2004-08-03 22:44 669696 ----a-w- c:\windows\system32\wininet.dll
2011-06-21 18:18 . 2004-08-03 22:44 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-06-21 18:18 . 2004-08-03 20:59 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-06-21 18:16 . 2004-08-03 22:36 370688 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2004-08-03 22:44 293888 ----a-w- c:\windows\system32\winsrv.dll
2011-06-06 11:35 . 2004-08-03 22:37 1859200 ----a-w- c:\windows\system32\win32k.sys
2011-06-03 15:34 . 2011-06-03 15:34 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
.
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-03-18 2471240]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTo2.dll" [2011-03-28 176936]
"{c86eb8a9-ccc2-4b6c-b75d-73576ed591bf}"= "c:\program files\Softonic-Polska\tbSoft.dll" [2010-11-13 3913000]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{c86eb8a9-ccc2-4b6c-b75d-73576ed591bf}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-04-03 08:27 254760 ----a-w- c:\documents and settings\JOoKeR\Ustawienia lokalne\Dane aplikacji\ConduitEngine\ldrConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2011-02-08 17:22 721840 ----a-w- c:\progra~1\BEARSH~2\MediaBar\Datamngr\IEBHO.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-03-18 07:11 2471240 ----a-w- c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-03-28 16:22 176936 ----a-w- c:\program files\uTorrentBar\prxtbuTo2.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}]
2011-01-18 13:05 87480 ----a-w- c:\progra~1\BEARSH~2\MediaBar\ToolBar\bsdtxmltbpi.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c86eb8a9-ccc2-4b6c-b75d-73576ed591bf}]
2010-11-13 19:58 3913000 ----a-w- c:\program files\Softonic-Polska\tbSoft.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTo2.dll" [2011-03-28 176936]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-03-18 2471240]
"{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}"= "c:\progra~1\BEARSH~2\MediaBar\ToolBar\bsdtxmltbpi.dll" [2011-01-18 87480]
"{c86eb8a9-ccc2-4b6c-b75d-73576ed591bf}"= "c:\program files\Softonic-Polska\tbSoft.dll" [2010-11-13 3913000]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CLASSES_ROOT\clsid\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}]
.
[HKEY_CLASSES_ROOT\clsid\{c86eb8a9-ccc2-4b6c-b75d-73576ed591bf}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-03-18 2471240]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\prxtbuTo2.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2005-08-30 1708032]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-04-18 15146376]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-01-07 2747744]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-22 275768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11-08-10 14:20 691696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [10-03-18 13:16 130384]
S2 gupdate;Usługa Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11-04-18 19:22 136176]
S3 gupdatem;Usługa Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [11-04-18 19:22 136176]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [10-03-18 13:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPService REG_MULTI_SZ HPSLPSVC
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Zawartość folderu 'Zaplanowane zadania'
.
2011-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-18 17:22]
.
2011-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-18 17:22]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
mStart Page = hxxp://www.bigseekpro.com/acala3gp/{942A62E8-CE80-4E3D-9752-A8D9C84EA505}
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://search.bearshare.com/sidebar.html?src=ssb&sysid=2
TCP: DhcpNameServer = 62.21.99.95
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
- - - - USUNIĘTO PUSTE WPISY - - - -
.
BHO-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - (no file)
Toolbar-{0974BA1E-64EC-11DE-B2A5-E43756D89593} - (no file)
Toolbar-10 - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-31 18:46
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
.
skanowanie ukrytych procesów ...
.
skanowanie ukrytych wpisów autostartu ...
.
skanowanie ukrytych plików ...
.
skanowanie pomyślnie ukończone
ukryte pliki: 0
.
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
.
- - - - - - - > 'explorer.exe'(3824)
c:\windows\system32\msi.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\SOUNDMAN.EXE
c:\progra~1\BEARSH~2\MediaBar\Datamngr\DATAMN~1.EXE
c:\program files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
.
**************************************************************************
.
Czas ukończenia: 2011-08-31 18:53:15 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2011-08-31 16:52
.
Przed: 12 415 774 720 bajtów wolnych
Po: 12 595 312 640 bajtów wolnych
.
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 08AF62B1B386F26BD639A48A4988406B
Działa już dziekuje ... :]]