Po skanowaniu polecanym przez was programem Combofix:
ComboFix 12-07-26.03 - Marcin Zalewski 2012-07-25 17:34:33.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.48.1045.18.1014.361 [GMT 2:00]
Uruchomiony z: c:\documents and settings\Marcin Zalewski\Moje dokumenty\Downloads\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Outdated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
* Utworzono nowy punkt przywracania
.
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Marcin Zalewski\Dane aplikacji\.#
c:\program files\iplus
c:\program files\iplus\commanderFix.exe
c:\program files\iplus\countries.eng
c:\program files\iplus\countries.pl
c:\program files\iplus\Drivers\difxapi.dll
c:\program files\iplus\Drivers\Driver\GTHSxPA\GT50Ip.sys
c:\program files\iplus\Drivers\Driver\GTHSxPA\GT51Ip.sys
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72mdm.cat
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72mdm.inf
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72ndis.cat
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72ndis.inf
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72sc.cat
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72sc.inf
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72ser.cat
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72ser.inf
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72ubus.cat
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72ubus.inf
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72ubus.sys
c:\program files\iplus\Drivers\Driver\GTHSxPA\gt72ubus2k.sys
c:\program files\iplus\Drivers\Driver\GTHSxPA\GtDetectSc.exe
c:\program files\iplus\Drivers\Driver\GTHSxPA\gtfubus.cat
c:\program files\iplus\Drivers\Driver\GTHSxPA\GtFubus.inf
c:\program files\iplus\Drivers\Driver\GTHSxPA\gtptser.sys
c:\program files\iplus\Drivers\Driver\GTHSxPA\gtscser.sys
c:\program files\iplus\Drivers\driverInstallation.log
c:\program files\iplus\Drivers\driverInstaller.exe
c:\program files\iplus\Drivers\GTM380-drivers-list-vista.txt
c:\program files\iplus\en\iplus.mo
c:\program files\iplus\eng.lang
c:\program files\iplus\help\IPlus_Manager_User_Manual.pdf
c:\program files\iplus\help\Podrecznik_Uzytkownika_IPlus_Manager.pdf
c:\program files\iplus\iPlusChecker.exe
c:\program files\iplus\iPlusManager.exe
c:\program files\iplus\iPlusManager.ini
c:\program files\iplus\license.rtf
c:\program files\iplus\log\openssl.exe
c:\program files\iplus\log\plus.pem
c:\program files\iplus\NDISAPI.dll
c:\program files\iplus\networks.dat
c:\program files\iplus\PaseczekControlAPI.dll
c:\program files\iplus\pl.lang
c:\program files\iplus\pl\iplus.mo
c:\program files\iplus\resources.dat
c:\program files\iplus\tools.exe
c:\program files\iplus\unins000.dat
c:\program files\iplus\unins000.exe
c:\program files\iplus\uninstallTool.exe
c:\program files\iplus\update.exe
c:\program files\iplus\update\update.ini
c:\program files\iplus\userPrefs.def
.
.
((((((((((((((((((((((((( Pliki utworzone od 2012-06-25 do 2012-07-25 )))))))))))))))))))))))))))))))
.
.
2012-07-21 18:18 . 2012-07-21 18:18 388096 ----a-r- c:\documents and settings\Marcin Zalewski\Dane aplikacji\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-07-21 18:18 . 2012-07-21 18:18 -------- d-----w- c:\program files\Trend Micro
2012-07-21 17:58 . 2012-07-21 17:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-07-21 17:58 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-21 08:25 . 2012-07-21 08:25 -------- d-----w- c:\program files\Conduit
2012-07-21 08:25 . 2012-07-21 08:25 -------- d-----w- c:\documents and settings\Marcin Zalewski\Ustawienia lokalne\Dane aplikacji\Softonic_Deutsch_FF
2012-07-21 08:25 . 2012-07-21 08:25 -------- d-----w- c:\documents and settings\Marcin Zalewski\Ustawienia lokalne\Dane aplikacji\ConduitEngine
2012-07-21 08:25 . 2012-07-21 08:25 -------- d-----w- c:\program files\Softonic_Deutsch_FF
2012-07-20 16:39 . 2012-07-20 16:39 97961 ----a-w- c:\windows\system32\drivers\klick.dat
2012-07-20 16:39 . 2012-07-20 16:39 115369 ----a-w- c:\windows\system32\drivers\klin.dat
2012-07-20 16:37 . 2012-07-24 14:44 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab
2012-07-20 16:37 . 2012-07-20 16:37 -------- d-----w- c:\program files\Kaspersky Lab
2012-07-19 16:09 . 2012-07-19 16:09 -------- d-----w- c:\documents and settings\Marcin Zalewski\Dane aplikacji\Malwarebytes
2012-07-19 16:09 . 2012-07-19 16:09 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Malwarebytes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-13 13:55 . 2009-09-25 00:53 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:49 . 2009-09-25 00:52 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2009-09-25 00:52 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2009-09-25 00:52 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2009-09-24 15:09 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2009-09-24 15:09 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2009-09-24 15:09 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2009-08-06 17:24 15896 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2009-08-06 17:24 24088 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2009-09-25 00:52 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2009-09-24 15:09 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2009-09-24 15:09 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2009-08-06 17:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2009-08-06 17:24 16408 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2009-09-24 15:09 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2009-09-24 15:09 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:19 . 2009-08-06 17:23 18968 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:18 . 2010-09-09 07:38 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 13:18 . 2010-09-09 07:38 18160 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2010-09-09 07:38 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:22 . 2009-09-25 00:52 602624 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:09 . 2009-09-25 00:53 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-11 14:44 . 2009-09-25 00:52 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:44 . 2009-09-25 00:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:39 . 2009-09-25 00:52 385024 ----a-w- c:\windows\system32\html.iec
2012-05-05 03:14 . 2008-04-14 21:59 2149888 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2008-04-14 21:59 2028032 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:47 . 2009-09-24 15:08 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9d81af43-de53-48d0-a199-42c2a226b24c}"= "c:\program files\Softonic_Deutsch_FF\tbSoft.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{9d81af43-de53-48d0-a199-42c2a226b24c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9d81af43-de53-48d0-a199-42c2a226b24c}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\Softonic_Deutsch_FF\tbSoft.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9d81af43-de53-48d0-a199-42c2a226b24c}"= "c:\program files\Softonic_Deutsch_FF\tbSoft.dll" [2010-10-18 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-10-18 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{9d81af43-de53-48d0-a199-42c2a226b24c}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-07-12 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-18 178712]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-17 53248]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-15 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-15 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"PLFSetL"="c:\windows\PLFSetL.exe" [2008-07-03 94208]
"snp2uvc"="c:\windows\system32\csnp2uvc.dll" [2009-02-16 196608]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1430824]
"RTHDCPL"="RTHDCPL.EXE" [2009-08-24 18702336]
"PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704]
"OSSelectorReinstall"="c:\program files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe" [2007-02-22 2209224]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 202296]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
.
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-9-25 565248]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-5-8 607584]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Zdalne zarządzanie systemem Windows
.
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2011-03-04 11352]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-21 655944]
R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2009-09-25 237568]
R3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\drivers\Gt51Ip.sys [2009-03-06 106112]
R3 GT72UBUS;GT 72 U BUS;c:\windows\system32\drivers\gt72ubus.sys [2009-03-06 59008]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2011-03-10 34608]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-02 19472]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [2009-09-25 38912]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-21 22344]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-09-25 1684736]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTS5121.sys --> c:\windows\system32\Drivers\RTS5121.sys [?]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
.
Zawartość folderu 'Zaplanowane zadania'
.
2012-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3973020173-757298511-4166307882-1006Core.job
- c:\documents and settings\Marcin Zalewski\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2012-02-10 09:59]
.
2012-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3973020173-757298511-4166307882-1006UA.job
- c:\documents and settings\Marcin Zalewski\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe [2012-02-10 09:59]
.
.
------- Skan uzupełniający -------
.
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000&st=10
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Wyślij do interfejsu Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Wyślij do urządzenia &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 194.204.159.1 194.204.152.34
.
- - - - USUNIĘTO PUSTE WPISY - - - -
.
HKCU-Run-ABBYY Screenshot Reader Bonus - c:\program files\ABBYY PDF Transformer 3.0\Bonus.ScreenshotReader.exe
HKLM-Run-iPlusManager - c:\program files\iPlus\iPlusChecker.exe
AddRemove-iPlus manager_is1 - c:\program files\iPlus\unins000.exe
AddRemove-RealAlt_is1 - d:\real alternative\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-07-25 17:46
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
.
skanowanie ukrytych procesów ...
.
skanowanie ukrytych wpisów autostartu ...
.
skanowanie ukrytych plików ...
.
skanowanie pomyślnie ukończone
ukryte pliki: 0
.
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
.
- - - - - - - > 'winlogon.exe'(1592)
c:\windows\system32\igfxdev.dll
.
Czas ukończenia: 2012-07-25 17:52:02
ComboFix-quarantined-files.txt 2012-07-25 15:51
.
Przed: 27 109 560 320 bajtów wolnych
Po: 27 516 928 000 bajtów wolnych
.
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 88C947E9BE3F6B4B2DB5B5B6798D1A56