
- Kod: Zaznacz wszystko
- ComboFix 08-06-20.4 - O 2008-07-01 12:36:17.1 - NTFSx86
 Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.455 [GMT 2:00]
 Running from: D:\pobieranie\ComboFix.exe
 * Created a new restore point
 [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
 .
 ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
 .
 C:\autorun.inf
 C:\WINDOWS\system32\kavo.exe
 C:\WINDOWS\system32\kavo0.dll
 C:\WINDOWS\system32\kavo1.dll
 D:\Autorun.inf
 .
 ((((((((((((((((((((((((( Files Created from 2008-06-01 to 2008-07-01 )))))))))))))))))))))))))))))))
 .
 2008-06-19 07:04 . 2008-06-19 07:04 128,288 -r-hs---- C:\n.com
 2008-06-11 07:14 . 2008-06-14 20:01 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys
 2008-06-11 07:14 . 2008-06-14 20:01 273,024 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
 2008-06-09 13:04 . 2008-07-01 11:14 151 --a------ C:\WINDOWS\PhotoSnapViewer.INI
 .
 (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 2008-06-30 08:52 --------- d-----w C:\Documents and Settings\O\Dane aplikacji\Image Zone Express
 2008-06-26 07:12 --------- d-----w C:\Program Files\Common Files\VULCAN
 2008-06-26 07:12 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\VULCAN
 2008-06-09 09:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
 2008-05-20 07:35 --------- d-----w C:\Program Files\Komputer Świat Rocznik 2007
 2008-05-19 12:37 1,916,951 ----a-w C:\WINDOWS\system32\ComboFix.exe
 2008-05-19 09:16 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
 2008-05-19 09:01 --------- d-----w C:\Program Files\Spybot - Search & Destroy
 2008-05-19 08:59 --------- d-----w C:\Program Files\Doradca BHP
 2008-05-19 08:59 --------- d-----w C:\Documents and Settings\O\Dane aplikacji\XnView
 2008-05-14 07:23 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ArcaBit
 2008-05-12 11:47 --------- d-----w C:\Documents and Settings\O\Dane aplikacji\U3
 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
 2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
 2008-04-23 07:20 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
 .
 ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 *Note* empty entries & legit default entries are not shown
 REGEDIT4
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
 "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04 139264]
 "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
 "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-14 13:19 68856]
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-28 07:55 98304]
 "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-28 07:52 77824]
 "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-28 07:55 118784]
 "SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
 "RTHDCPL"="RTHDCPL.EXE" [2006-11-14 11:21 16270848 C:\WINDOWS\RTHDCPL.exe]
 "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-12-15 11:18 49152]
 "ABRegmon"="C:\Program Files\ArcaBit\ArcaVir\ABregmon.exe" [2007-07-12 10:40 303104]
 "AvMenu"="C:\Program Files\ArcaBit\ArcaVir\AVMenu.exe" [2008-01-29 16:12 481800]
 "ArcaCheck"="C:\Program Files\ArcaBit\ArcaVir\ArcaCheck.exe" [2007-07-27 13:57 836912]
 "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
 [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
 "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
 C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
 HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 11:40:44 282624]
 Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 17:23:32 74308]
 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TS_LogonListener]
 TS_LogonListener.dll 2007-01-12 16:41 101376 C:\WINDOWS\system32\TS_LogonListener.dll
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kava]
 C:\WINDOWS\system32\kavo.exe
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
 --a------ 2006-01-12 15:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
 --a------ 2007-09-14 13:19 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
 "EnableFirewall"= 0 (0x0)
 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
 "%windir%\\system32\\sessmgr.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
 "C:\\Program Files\\Dom Wydawniczy ABC\\Prawo\\LPLocal.exe"=
 "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
 R1 ABTDI;ABTDI;C:\Program Files\ArcaBit\ArcaVir\ABTDI.sys [2007-05-08 14:45]
 R2 ABFileMon;ArcaBit FileMonitor;"C:\Program Files\ArcaBit\ArcaVir\FileMonSV.exe" [2007-10-10 06:55]
 R2 ArcaBit.TaskScheduler;ArcaBit.TaskScheduler;"C:\Program Files\ArcaBit\Common\TaskScheduler.exe" [2007-01-12 16:42]
 R2 AVUpdate;ArcaBit Update Service;C:\Program Files\ArcaBit\ArcaUpdate\update.exe [2007-02-26 16:04]
 R3 ABFLT;ArcaBit File Monitor Driver;C:\PROGRA~1\ArcaBit\ArcaVir\ABFLT.sys [2007-09-12 14:37]
 R3 ArcaBit.Core.Configurator;ArcaBit.Core.Configurator;"C:\Program Files\ArcaBit\Common\ArcaBit.Core.Configurator2.exe" [2007-01-11 16:01]
 R3 ArcaBit.Core.LoggingService;ArcaBit.Core.LoggingService;"C:\Program Files\ArcaBit\Common\ArcaBit.Core.LoggingService.exe" [2007-01-11 16:03]
 S3 ps_drv;ps_drv;C:\Documents and Settings\O\ps_drv.sys []
 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3be05a83-5cfd-11dc-aa96-001a4d2ed472}]
 \Shell\AutoRun\command - F:\vmhr.bat
 \Shell\explore\Command - F:\vmhr.bat
 \Shell\open\Command - F:\vmhr.bat
 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b3c58b2-9276-11dc-aad5-001a4d2ed472}]
 \Shell\AutoRun\command - F:\LaunchU3.exe -a
 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b3c58b3-9276-11dc-aad5-001a4d2ed472}]
 \Shell\AutoRun\command - G:\ka1nk.bat
 \Shell\explore\Command - G:\ka1nk.bat
 \Shell\open\Command - G:\ka1nk.bat
 *Newly Created Service* - CATCHME
 .
 **************************************************************************
 catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
 Rootkit scan 2008-07-01 12:37:44
 Windows 5.1.2600 Dodatek Service Pack 2 NTFS
 scanning hidden processes ...
 scanning hidden autostart entries ...
 scanning hidden files ...
 scan completed successfully
 hidden files: 0
 **************************************************************************
 .
 Completion time: 2008-07-01 12:38:09
 ComboFix-quarantined-files.txt 2008-07-01 10:38:05
 Pre-Run: 53,050,019,840 bajtów wolnych
 Post-Run: 53,039,714,304 bajtów wolnych
 128 --- E O F --- 2008-06-20 06:00:51
i
- Kod: Zaznacz wszystko
- Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 12:39:32, on 2008-07-01
 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16674)
 Boot mode: Normal
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\ArcaBit\Common\ArcaBit.Core.Configurator2.exe
 C:\Program Files\ArcaBit\ArcaUpdate\update.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
 C:\WINDOWS\system32\HPZipm12.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\ArcaBit\ArcaVir\FileMonSV.exe
 C:\Program Files\ArcaBit\ArcaVir\NetMonSV.exe
 C:\Program Files\ArcaBit\Common\TaskScheduler.exe
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\WINDOWS\system32\igfxpers.exe
 C:\WINDOWS\RTHDCPL.EXE
 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 C:\Program Files\ArcaBit\ArcaVir\ABregmon.exe
 C:\Program Files\ArcaBit\ArcaVir\AVMenu.exe
 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
 C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
 C:\Program Files\ArcaBit\Common\ArcaBit.Core.LoggingService.exe
 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
 C:\WINDOWS\system32\notepad.exe
 C:\WINDOWS\explorer.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wp.pl/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
 O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
 O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
 O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
 O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
 O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [ABRegmon] C:\Program Files\ArcaBit\ArcaVir\ABregmon.exe
 O4 - HKLM\..\Run: [AvMenu] C:\Program Files\ArcaBit\ArcaVir\AVMenu.exe
 O4 - HKLM\..\Run: [ArcaCheck] C:\Program Files\ArcaBit\ArcaVir\ArcaCheck.exe /startup
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
 O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
 O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
 O17 - HKLM\System\CCS\Services\Tcpip\..\{FF077B50-42A5-418E-8834-B7178CFC82EF}: NameServer = 194.204.159.1,194.204.152.34
 O20 - Winlogon Notify: TS_LogonListener - C:\WINDOWS\SYSTEM32\TS_LogonListener.dll
 O23 - Service: ArcaBit FileMonitor (ABFileMon) - ArcaBit - C:\Program Files\ArcaBit\ArcaVir\FileMonSV.exe
 O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit - C:\Program Files\ArcaBit\ArcaVir\NetMonSV.exe
 O23 - Service: ArcaBit.Core.Configurator - ArcaBit - C:\Program Files\ArcaBit\Common\ArcaBit.Core.Configurator2.exe
 O23 - Service: ArcaBit.Core.LoggingService - ArcaBit - C:\Program Files\ArcaBit\Common\ArcaBit.Core.LoggingService.exe
 O23 - Service: ArcaBit.TaskScheduler - ArcaBit sp. z o.o. - C:\Program Files\ArcaBit\Common\TaskScheduler.exe
 O23 - Service: ArcaBit Update Service (AVUpdate) - ArcaBit - C:\Program Files\ArcaBit\ArcaUpdate\update.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
 --
 End of file - 7203 bytes


 
	
 
 


 
  