wklejam log z combofix-a
ComboFix 08-07-26.1 - Stubby 2008-07-27 17:06:29.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.585 [GMT 2:00]
Running from: C:\Documents and Settings\Stubby\Pulpit\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-27 to 2008-07-27 )))))))))))))))))))))))))))))))
.
2008-07-24 23:23 . 2008-07-24 23:23 <DIR> d-------- C:\Documents and Settings\Stubby\Dane aplikacji\Gadu-Gadu
2008-07-18 23:39 . 2008-07-18 23:39 <DIR> d-------- C:\usr
2008-07-11 12:58 . 2008-07-11 12:58 0 --a------ C:\t9peum02.exe
2008-07-11 12:21 . 2008-07-11 12:21 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-07-03 12:14 . 2008-07-03 12:14 <DIR> d-------- C:\Documents and Settings\Stubby\WINDOWS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-27 14:41 14 ----a-w C:\Documents and Settings\Stubby\getfile.dat
2008-07-23 09:50 --------- d-----w C:\Program Files\Java
2008-07-18 10:11 --------- d-----w C:\Program Files\Betsson Poker
2008-06-13 11:14 --------- d-----w C:\Program Files\AWS
2008-06-13 11:14 --------- d-----w C:\Documents and Settings\Stubby\Dane aplikacji\ArcaBit
2008-06-10 21:49 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-06-01 17:58 --------- d-----w C:\Documents and Settings\Stubby\Dane aplikacji\Autodesk
2008-06-01 17:56 54,784 ----a-w C:\WINDOWS\system32\drivers\CDAC11BA.EXE
2008-06-01 17:56 12,464 ----a-w C:\WINDOWS\system32\drivers\CDAC15BA.SYS
2008-06-01 17:56 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-06-01 17:56 --------- d-----w C:\Program Files\Autodesk
2008-06-01 17:55 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-06-01 17:55 --------- d-----w C:\Program Files\AnswerWorks 4.0
2008-06-01 17:54 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Autodesk
2008-03-30 21:15 22,328 ----a-w C:\Documents and Settings\Stubby\Dane aplikacji\PnkBstrK.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]
"DAEMON Tools Pro Agent"="D:\Programy\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
"Gadu-Gadu"="D:\Programy\Gadu-Gadu\gg.exe" [2008-07-25 23:57 2130434]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDMCon"="C:\Program Files\Softwin\BitDefender8\bdmcon.exe" [2008-06-11 14:56 430450]
"BDNewsAgent"="C:\Program Files\Softwin\BitDefender8\bdnagent.exe" [2005-05-09 12:19 8192]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-15 00:37 295300]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"WinampAgent"="D:\Programy\Winamp\winampa.exe" [2008-01-16 00:54 37376]
"UnlockerAssistant"="D:\Programy\Unlocker\UnlockerAssistant.exe" [2008-05-06 22:13 24434]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 15:03 16125440 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 18:04 2879488 C:\WINDOWS\SkyTel.exe]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:44 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 38519]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= divxa32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Programy\\Gadu-Gadu\\gg.exe"=
"D:\\Programy\\RivChat2\\RivChat.exe"=
"D:\\Programy\\strong dc\\StrongDC.exe"=
"D:\\Programy\\wincmd\\WINCMD32.EXE"=
"D:\\Programy\\SopCast\\SopCast.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"E:\\Supreme Commander\\Supreme Commander\\bin\\SupremeCommander.exe"=
"E:\\Supreme Commander\\GPGNet\\GPG.Multiplayer.Client.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"D:\\Programy\\SopCast\\adv\\SopAdver.exe"=
"C:\\usr\\apache\\Apache.exe"=
"C:\\usr\\SMTP Server\\localsrv.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20f42138-41ee-11dd-8c04-00044b072639}]
\Shell\AutoRun\command - I:\6x8be16.cmd
\Shell\explore\Command - I:\6x8be16.cmd
\Shell\open\Command - I:\6x8be16.cmd
.
Contents of the 'Scheduled Tasks' folder
2008-06-24 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - s!+:C:\Program Files\Apple Software Update\SoftwareUpdate.exe-taskSYSTEM0+ []
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page =
hxxp://www.google.pl/
O8 -: E&ksport do programu Microsoft Excel - D:\Programy\Office\OFFICE11\EXCEL.EXE/3000
O16 -: {82202BE7-C56A-487E-9E55-D84BDC1A5776} -
hxxp://install.anark.com/client/version ... Client.cab
C:\WINDOWS\Downloaded Program Files\InstallClient.inf
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-27 17:07:25
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySql]
"ImagePath"="c:\usr/MYSQL/bin/mysqld.exe"
.
Completion time: 2008-07-27 17:07:49
ComboFix-quarantined-files.txt 2008-07-27 15:07:46
ComboFix2.txt 2008-07-24 21:57:36
ComboFix3.txt 2008-06-11 15:35:58
Pre-Run: 22,085,050,368 bajtów wolnych
Post-Run: 22,130,302,976 bajtów wolnych
111 --- E O F --- 2007-12-16 11:06:43