Share Pastebin
Guest
Public paste!

Untitled

By: a guest | Feb 9th, 2010 | Syntax: None | Size: 10.55 KB | Hits: 9 | Expires: Never
Copy text to clipboard
  1. ComboFix 10-02-09.01 - MiChAł 2010-02-09  21:39:44.1.2 - x86
  2. Microsoft Windows XP Professional  5.1.2600.3.1250.48.1045.18.2047.1667 [GMT 1:00]
  3. Uruchomiony z: f:\download\ComboFix.exe
  4. AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
  5.  * Rezydentny antywirus jest aktywny
  6.  
  7. .
  8.  
  9. (((((((((((((((((((((((((((((((((((((((   Usunięto   )))))))))))))))))))))))))))))))))))))))))))))))))
  10. .
  11.  
  12. c:\program files\Adobe\Photoshop.exe
  13. c:\windows\system32\twain_32.dll
  14.  
  15. .
  16. (((((((((((((((((((((((((   Pliki utworzone od 2010-01-09 do 2010-02-09  )))))))))))))))))))))))))))))))
  17. .
  18.  
  19. 2010-02-09 20:21 . 2010-02-09 20:21     --------        d-----w-        c:\windows\ERUNT
  20. 2010-02-09 20:18 . 2010-02-09 20:27     --------        d-----w-        C:\SDFix
  21. 2010-02-09 19:49 . 2010-01-07 15:07     38224   ----a-w-        c:\windows\system32\drivers\mbamswissarmy.sys
  22. 2010-02-09 19:49 . 2010-02-09 19:49     --------        d-----w-        c:\documents and settings\All Users\Dane aplikacji\Malwarebytes
  23. 2010-02-09 19:49 . 2010-01-07 15:07     19160   ----a-w-        c:\windows\system32\drivers\mbam.sys
  24. 2010-02-09 19:49 . 2010-02-09 19:49     --------        d-----w-        c:\program files\Malwarebytes' Anti-Malware
  25. 2010-02-09 13:18 . 2010-02-09 13:18     --------        d-----w-        c:\program files\Lavalys
  26. 2010-02-08 22:14 . 2010-02-08 22:14     --------        d-----w-        c:\documents and settings\All Users\Dane aplikacji\AVS4YOU
  27. 2010-02-07 11:44 . 2010-02-07 11:44     --------        d-----w-        c:\program files\SubEdit-Player
  28. 2010-02-07 11:37 . 2010-02-07 11:39     --------        d-----w-        c:\program files\URUSoft
  29. 2010-01-29 19:01 . 2010-01-29 19:17     --------        d-----w-        c:\documents and settings\All Users\Dane aplikacji\Blizzard Entertainment
  30. 2010-01-23 11:40 . 2010-01-23 11:44     --------        d-----w-        c:\program files\Foxit Software
  31. 2010-01-13 13:08 . 2010-01-13 13:08     --------        d-----w-        c:\program files\Hamachi
  32. 2010-01-12 18:49 . 2010-01-16 18:20     --------        d-----w-        c:\documents and settings\LocalService\Ustawienia lokalne\Dane aplikacji\LogMeIn Hamachi
  33.  
  34. .
  35. ((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
  36. .
  37. 2010-02-01 21:41 . 2009-07-21 21:32     2568    --sha-w-        c:\windows\system32\KGyGaAvL.sys
  38. 2010-02-01 15:12 . 2009-11-02 17:17     --------        d-----w-        c:\program files\Nowe Gadu-Gadu
  39. 2010-01-22 15:56 . 2009-11-21 23:05     --------        d-----w-        c:\documents and settings\All Users\Dane aplikacji\BioWare
  40. 2010-01-16 18:27 . 2008-08-20 18:28     --------        d-----w-        c:\program files\Odkurzacz
  41. 2010-01-13 13:08 . 2009-09-23 08:41     25280   ----a-w-        c:\windows\system32\drivers\hamachi.sys
  42. 2009-12-16 13:42 . 2009-12-16 13:34     --------        d-----w-        c:\program files\Opera
  43. 2009-12-15 12:22 . 2009-12-15 12:22     --------        d-----w-        c:\program files\PDFArea
  44. 2009-11-21 22:09 . 2001-10-26 16:15     89036   ----a-w-        c:\windows\system32\perfc015.dat
  45. 2009-11-21 22:09 . 2001-10-26 16:15     499854  ----a-w-        c:\windows\system32\perfh015.dat
  46. 2009-07-21 21:32 . 2009-07-21 21:32     88      --sh--r-        c:\windows\system32\5471A9B09A.sys
  47. .
  48.  
  49. ------- Sigcheck -------
  50.  
  51. [-] 2008-05-08 . ACCF5A9A1FFAA490F33DBA1C632B95E1 . 361344 . . [5.1.2600.5512] . . c:\windows\system32\drivers\tcpip.sys
  52.  
  53. [-] 2008-04-14 . E1A9A883950ADB8F0536E2201A3C2A00 . 101888 . . [5.4.3790.5512] . . c:\windows\system32\wuauclt.exe
  54. [-] 2008-04-14 . E1A9A883950ADB8F0536E2201A3C2A00 . 101888 . . [5.4.3790.5512] . . c:\windows\system32\dllcache\wuauclt.exe
  55.  
  56. [-] 2008-05-08 . 1B70DB042A98B52BBBFEA5CBF8AF3FD2 . 3851264 . . [7.00.5730.13] . . c:\windows\system32\mshtml.dll
  57. [-] 2008-05-08 . 1B70DB042A98B52BBBFEA5CBF8AF3FD2 . 3851264 . . [7.00.5730.13] . . c:\windows\system32\dllcache\mshtml.dll
  58.  
  59. [-] 2008-05-08 . F284A6225A3057A1E19985E1D4B47ADA . 809472 . . [7.00.5730.13] . . c:\windows\system32\wininet.dll
  60. [-] 2008-05-08 . F284A6225A3057A1E19985E1D4B47ADA . 809472 . . [7.00.5730.13] . . c:\windows\system32\dllcache\wininet.dll
  61.  
  62. [-] 2008-04-14 . F042E3426D45D86D9BB55F6A79AB441A . 977408 . . [6.00.2900.5512] . . c:\windows\explorer.exe
  63. [-] 2008-04-14 . F042E3426D45D86D9BB55F6A79AB441A . 977408 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\explorer.exe
  64.  
  65. [-] 2008-05-08 . 9F02C1CF7C3100E4AEA7DD8B6A86A01B . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
  66. .
  67. (((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))
  68. .
  69. .
  70. *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane  
  71. REGEDIT4
  72.  
  73. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  74. "Start WingMan Profiler"="c:\program files\Logitech\Profiler\lwemon.exe" [2005-04-18 73728]
  75. "DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
  76. "zaian"="c:\documents and settings\MiChAł\zaian.exe" [2010-02-09 102400]
  77.  
  78. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  79. "RTHDCPL"="RTHDCPL.EXE" [2006-05-27 16208384]
  80. "SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
  81. "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 49152]
  82. "CHotkey"="mHotkey.exe" [2004-12-08 550912]
  83. "ShowWnd"="ShowWnd.exe" [2003-09-18 36864]
  84. "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
  85. "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
  86. "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 1443072]
  87. "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-25 13680640]
  88. "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-25 86016]
  89. "Corel File Shell Monitor"="c:\program files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe" [2008-01-15 16200]
  90.  
  91. [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
  92. "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
  93.  
  94. [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
  95. "nltide_2"="shell32" [X]
  96.  
  97. c:\documents and settings\MiChAˆ\Menu Start\Programy\Autostart\
  98. RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-3-18 630784]
  99. TransBar.lnk - c:\windows\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-6-1 65536]
  100. UberIcon.lnk - c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-5-21 180224]
  101. Y'z Shadow.lnk - c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-5-21 155648]
  102.  
  103. c:\documents and settings\All Users\Menu Start\Programy\Autostart\
  104. Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-8-20 434176]
  105.  
  106. [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
  107. "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
  108. "%windir%\\system32\\sessmgr.exe"=
  109. "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
  110. "c:\\Program Files\\uTorrent\\uTorrent.exe"=
  111. "d:\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\xrEngine.exe"=
  112. "d:\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\dedicated\\xrEngine.exe"=
  113. "c:\\WINDOWS\\system32\\dpvsetup.exe"=
  114. "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
  115. "c:\\WINDOWS\\system32\\PnkBstrA.exe"=
  116. "c:\\WINDOWS\\system32\\PnkBstrB.exe"=
  117. "d:\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
  118. "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
  119. "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
  120. "c:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
  121. "d:\\Activision\\Call of Duty Modern Warfare 2\\iw4mp.exe"=
  122. "c:\\Program Files\\Hamachi\\hamachi.exe"=
  123. "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
  124.  
  125. R1 appdrv01;Application Driver (01);c:\windows\system32\drivers\appdrv01.sys [2008-09-19 2915944]
  126. R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-03-13 33800]
  127. R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-03-13 472320]
  128. S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-08-20 685816]
  129. S2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc --> c:\windows\System32\appdrvrem01.exe svc [?]
  130. S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [2008-08-20 87824]
  131. S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [2008-08-20 85696]
  132. .
  133. .
  134. ------- Skan uzupełniający -------
  135. .
  136. uLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm
  137. uStart Page = about:blank
  138. uInternet Settings,ProxyOverride = *.local
  139. Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
  140. FF - ProfilePath - c:\documents and settings\MiChAł\Dane aplikacji\Mozilla\Firefox\Profiles\dq7hsb55.default\
  141. FF - prefs.js: browser.startup.homepage - hxxp://google.pl/
  142. .
  143.  
  144. **************************************************************************
  145.  
  146. catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
  147. Rootkit scan 2010-02-09 21:41
  148. Windows 5.1.2600 Dodatek Service Pack 3 NTFS
  149.  
  150. skanowanie ukrytych procesów ...  
  151.  
  152. skanowanie ukrytych wpisów autostartu ...
  153.  
  154. skanowanie ukrytych plików ...  
  155.  
  156. skanowanie pomyślnie ukończone
  157. ukryte pliki: 0
  158.  
  159. **************************************************************************
  160. .
  161. --------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
  162.  
  163. [HKEY_USERS\S-1-5-21-1482476501-1085031214-1417001333-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
  164. "??"=hex:e1,75,2c,1f,f4,b8,4d,a0,5c,80,29,f5,e9,5e,bf,e1,da,a9,4e,6e,4d,91,f1,
  165.    a3,ba,3f,3d,11,ca,cc,cf,81,55,3d,3e,86,c3,31,13,ca,c4,af,df,b3,86,a9,f5,e3,\
  166. "??"=hex:e6,80,e4,94,9b,2f,a8,0d,22,0a,08,5b,2b,4f,57,57
  167.  
  168. [HKEY_USERS\S-1-5-21-1482476501-1085031214-1417001333-1003\Software\SecuROM\License information*]
  169. "datasecu"=hex:2e,49,0a,3f,0f,2f,6d,20,68,6f,ad,2b,03,a1,74,4a,19,ad,07,d0,e9,
  170.    b9,e1,36,43,26,0d,40,2d,9b,de,95,87,2c,b5,f5,01,0e,ce,30,12,1a,f3,cb,57,6a,\
  171. "rkeysecu"=hex:c8,84,d4,c9,ee,66,76,4e,63,3b,9a,32,00,c8,07,f8
  172. .
  173. --------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
  174.  
  175. - - - - - - - > 'lsass.exe'(792)
  176. c:\windows\system32\scecli.dll
  177. .
  178. Czas ukończenia: 2010-02-09  21:42:44
  179. ComboFix-quarantined-files.txt  2010-02-09 20:42
  180.  
  181. Przed: 1 920 741 376 bajtów wolnych
  182. Po: 1 848 979 456 bajtów wolnych
  183.  
  184. WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
  185. [boot loader]
  186. timeout=2
  187. default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
  188. [operating systems]
  189. c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
  190. multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
  191.  
  192. - - End Of File - - 925B2561912D325160C54CE635A83E09