Część II:
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-25 14:17 . 2009-10-20 14:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-25 14:17 . 2009-10-20 14:19 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-25 06:59 . 2001-10-26 16:15 49492 ----a-w- c:\windows\system32\perfc015.dat
2009-10-25 06:59 . 2001-10-26 16:15 355486 ----a-w- c:\windows\system32\perfh015.dat
2009-10-20 15:49 . 2009-10-20 15:49 -------- d-----w- c:\program files\Nowe Gadu-Gadu
2009-10-20 15:43 . 2009-10-20 15:43 -------- d-----w- c:\program files\Topsevenreviews
2009-10-20 15:20 . 2009-10-20 15:20 -------- d-----w- c:\program files\uTorrent
2009-10-20 15:16 . 2009-10-20 15:16 -------- d-----w- c:\program files\Winamp
2009-10-20 14:47 . 2009-10-20 14:47 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\NVIDIA Corporation
2009-10-20 14:47 . 2009-10-20 14:46 -------- d-----w- c:\program files\NVIDIA Corporation
2009-10-20 14:37 . 2009-10-20 14:37 -------- d-----w- c:\program files\AbiWord
2009-10-20 14:23 . 2009-10-20 14:22 -------- d-----w- c:\program files\Gadu-Gadu
2009-10-20 14:22 . 2009-10-20 14:22 -------- d-----w- c:\program files\Opera
2009-10-20 14:20 . 2009-10-20 14:19 -------- d-----w- c:\program files\Analog Devices
2009-10-20 14:10 . 2009-10-20 14:10 -------- d-----w- c:\program files\Alwil Software
2009-10-20 14:03 . 2009-10-20 14:03 -------- d-----w- c:\program files\Usługi online
2009-10-20 14:02 . 2009-10-20 14:02 21856 ----a-w- c:\windows\system32\emptyregdb.dat
2009-10-20 14:02 . 2009-10-20 14:02 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-27 16:19 . 2009-09-27 16:19 3674112 ----a-w- c:\windows\system32\nvwssr.dll
2009-09-27 14:12 . 2009-09-27 14:12 888832 ----a-w- c:\windows\system32\nvapi.dll
2009-09-27 14:12 . 2009-09-27 14:12 7655872 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-09-27 14:12 . 2009-09-27 14:12 5900416 ----a-w- c:\windows\system32\nv4_disp.dll
2009-09-27 14:12 . 2009-09-27 14:12 2194024 ----a-w- c:\windows\system32\nvcuvid.dll
2009-09-27 14:12 . 2009-09-27 14:12 2007040 ----a-w- c:\windows\system32\nvcuda.dll
2009-09-27 14:12 . 2009-09-27 14:12 1714792 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-09-27 14:12 . 2009-09-27 14:12 170600 ----a-w- c:\windows\system32\nvcodins.dll
2009-09-27 14:12 . 2009-09-27 14:12 170600 ----a-w- c:\windows\system32\nvcod.dll
2009-09-27 14:12 . 2009-09-27 14:12 1604482 ----a-w- c:\windows\system32\nvdata.bin
2009-09-27 14:12 . 2009-09-27 14:12 10756096 ----a-w- c:\windows\system32\nvoglnt.dll
2009-09-15 10:59 . 2009-10-20 14:10 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-09-15 10:56 . 2009-10-20 14:10 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-09-15 10:56 . 2009-10-20 14:10 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-09-15 10:55 . 2009-10-20 14:10 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-09-15 10:55 . 2009-10-20 14:10 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-09-15 10:54 . 2009-10-20 14:10 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-09-15 10:54 . 2009-10-20 14:10 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-09-15 10:53 . 2009-10-20 14:10 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-09-15 10:53 . 2009-10-20 14:10 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-09-11 14:19 . 2008-04-14 20:50 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:05 . 2008-04-14 20:50 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:31 . 2008-03-01 14:02 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:30 . 2008-05-02 06:47 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:30 . 2008-05-02 06:47 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-26 08:02 . 2008-04-14 20:50 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-21 19:15 . 2009-08-21 19:15 557568 ----a-w- c:\windows\system32\B4FM.dll
2009-08-05 09:01 . 2008-04-14 20:50 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 17:29 . 2008-04-14 19:59 2146816 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:29 . 2008-04-14 21:59 2025472 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-29 04:37 . 2008-04-14 20:50 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2008-04-14 20:50 81920 ----a-w- c:\windows\system32\fontsub.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
2009-10-23 16:07 815104 ----a-w- c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll" [2009-10-23 815104]
[HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll" [2009-10-23 815104]
[HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-10-20 289072]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2009-06-04 869888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-23 149280]
"Salmosa"="c:\program files\Razer\Salmosa\razerhid.exe" [2008-08-21 139264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-08-29 124928]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
"c:\\Documents and Settings\\Główny\\Pulpit\\utorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\red orchestra\\steamapps\\zimek91\\counter-strike\\hl.exe"=
"d:\\red orchestra\\steamapps\\zimek91\\condition zero\\hl.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-10-20 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-10-20 20560]
R3 Salmosa03;Razer Salmosa USB Filter Driver;c:\windows\system32\drivers\Salmosa.sys [2009-10-25 9344]
--- Inne Usługi/Sterowniki w Pamięci ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Zawartość folderu 'Zaplanowane zadania'
2009-10-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-10-21 20:18]
.
.
------- Skan uzupełniający -------
.
uStart Page = about:blank
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
.
- - - - USUNIĘTO PUSTE WPISY - - - -
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - c:\program files\AskBarDis\bar\bin\askBar.dll
HKLM-Run-nwiz - c:\program files\NVIDIA Corporation\nView\nwiz.exe
AddRemove-NVIDIA nView Desktop Manager - c:\program files\NVIDIA Corporation\nView\nViewSetup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Element ukryty. Rejestracja zajmie tylko minutę!
Rootkit scan 2009-10-26 15:36
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2009-10-26 15:37
ComboFix-quarantined-files.txt 2009-10-26 14:37
Przed: 2*668*867*584 bajtów wolnych
Po: 2*644*701*184 bajtów wolnych
- - End Of File - - EDDBEE254777C8B724233EE4A0724D4F