Po tym skanowaniu ComboFix z dysku C usunięto te wszystkie pliku. Ale w procesach cały czas jakieś gówna są. Oto log z C_F:
ComboFix 08-03-05.3 - Admin 2008-03-06 14:40:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.69 [GMT 1:00]
Running from: C:\Documents and Settings\Admin\Pulpit\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\NoDNS
C:\Program Files\Temporary
C:\Program Files\Temporary\InsiDERInst.exe
C:\WINDOWS\BMff146fe3.xml
C:\WINDOWS\hosts
C:\WINDOWS\pskt.ini
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\abehspig.dll
C:\WINDOWS\system32\byxxv.dll
C:\WINDOWS\system32\cirasyvl.dll
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\system32\fccccda.dll
C:\WINDOWS\system32\hpkoodeq.dll
C:\WINDOWS\system32\mmttkpfk.dll
C:\WINDOWS\system32\qomjggd.dll
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\tuqdcjsx.ini
C:\WINDOWS\system32\vxxyb.ini
C:\WINDOWS\system32\vxxyb.ini2
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\wpioedpn.dll
C:\WINDOWS\system32\xsjcdqut.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DHLP
-------\LEGACY_MHIW57
((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.
2008-03-06 14:16 . 2008-03-06 14:16 56,576 --a------ C:\WINDOWS\system32\drivers\nkv2.sys
2008-03-05 18:46 . 2008-03-05 18:46 190,728 --a------ C:\Documents and Settings\Admin\Dane aplikacji\install_en[1].exe
2008-03-05 18:45 . 2008-03-06 14:16 11,776 --a------ C:\WINDOWS\system32\WLCtrl32.dl_
2008-03-05 14:51 . 2008-03-05 14:51 <DIR> d--hs---- C:\NoWayVirus
2008-03-05 14:47 . 2008-03-05 14:47 <DIR> d-------- C:\Documents and Settings\Admin\Dane aplikacji\NoWayVirus
2008-03-05 14:42 . 2004-10-07 13:39 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2008-03-05 14:42 . 2004-10-07 13:39 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-03-05 14:42 . 2004-10-07 13:39 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-03-05 14:42 . 2004-10-07 13:39 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2008-03-05 14:42 . 2001-03-08 18:30 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-03-05 14:27 . 2008-03-06 14:36 28,612 ---hs---- C:\WINDOWS\system32\mmttkpfk.dllbox
2008-03-05 13:42 . 2008-03-05 13:42 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-05 12:25 . 2008-03-05 12:25 <DIR> d-------- C:\Documents and Settings\Admin\Dane aplikacji\OczyszczaczKomputerza
2008-03-05 12:20 . 2008-03-05 12:20 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\OczyszczaczKomputerza
2008-03-05 10:22 . 2008-03-05 13:17 20,612 ---hs---- C:\WINDOWS\system32\wvxozjrw.dllbox
2008-03-04 22:09 . 2008-03-04 22:09 29 --a------ C:\WINDOWS\system32\eppdorru.tmp
2008-03-04 22:08 . 2008-03-04 22:08 167,936 --a------ C:\WINDOWS\system32\drivers\Mhiw57.sys
2008-03-04 22:07 . 2008-03-06 14:16 26,496 --a------ C:\WINDOWS\system32\drivers\Esy40.sys
2008-03-04 22:07 . 2008-03-04 22:07 26,240 --a------ C:\WINDOWS\system32\drivers\Esy40(4).sys
2008-03-04 22:07 . 2008-03-05 07:45 26,240 --a------ C:\WINDOWS\system32\drivers\Esy40(3).sys
2008-03-04 22:07 . 2008-03-05 08:42 26,240 --a------ C:\WINDOWS\system32\drivers\Esy40(2).sys
2008-03-04 22:07 . 2008-03-06 14:51 11,776 --a------ C:\WINDOWS\system32\WLCtrl32.dll
2008-03-04 22:06 . 2008-03-04 22:06 37,376 --a------ C:\WINDOWS\mrofinu1535.exe.tmp
2008-03-04 22:06 . 2008-03-04 22:08 37,376 --a------ C:\WINDOWS\mrofinu1535.exe
2008-03-04 21:02 . 2008-03-04 21:16 <DIR> d-------- C:\Babcia
2008-03-02 17:26 . 2008-03-02 15:26 73,728 --a------ C:\WINDOWS\b153.exe
2008-03-02 14:03 . 2008-03-02 14:03 26,752 --a------ C:\Documents and Settings\Admin\Dane aplikacji\GDIPFONTCACHEV1.DAT
2008-03-01 21:20 . 2008-03-01 21:20 118,784 --a------ C:\WINDOWS\SeaMonkeyUninstall.exe
2008-03-01 21:19 . 2008-03-01 21:20 <DIR> d-------- C:\Program Files\SeaMonkey
2008-03-01 21:19 . 2008-03-01 21:19 <DIR> d-------- C:\Program Files\Common Files\mozilla.org
2008-03-01 21:19 . 2008-03-01 21:19 118,784 --a------ C:\WINDOWS\GREUninstall.exe
2008-03-01 21:19 . 2008-03-01 21:20 7,457 --a------ C:\WINDOWS\mozver.dat
2008-02-25 16:00 . 2008-02-25 14:00 81,920 --a------ C:\WINDOWS\b154.exe
2008-02-24 20:09 . 2008-02-24 20:09 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-02-24 12:46 . 2008-02-24 12:48 <DIR> d-------- C:\Program Files\Ad-Aware SE Personal
2008-02-23 21:39 . 2000-07-14 23:00 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2008-02-21 10:17 . 2008-02-24 14:02 <DIR> d-------- C:\Program Files\Soldat+
2008-02-21 02:57 . 2008-02-21 02:57 54,608 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-02-20 17:05 . 2008-02-20 17:06 <DIR> d-------- C:\Documents and Settings\Admin\Dane aplikacji\REAPER
2008-02-20 14:15 . 2004-08-04 00:44 4,274,816 --a------ C:\WINDOWS\system32\drivers\nv4_disp.dll
2008-02-20 14:15 . 2001-10-26 17:29 1,738,496 --a------ C:\WINDOWS\system32\drivers\nv4.dll
2008-02-17 16:02 . 2008-02-17 16:02 <DIR> d-------- C:\Documents and Settings\Admin\Contacts
2008-02-17 15:43 . 2008-02-17 16:01 <DIR> d-------- C:\Program Files\MSN Messenger
2008-02-13 21:23 . 2008-03-01 21:20 335 --a------ C:\WINDOWS\nsreg.dat
2008-02-10 15:56 . 2008-02-24 20:11 <DIR> d-------- C:\WINDOWS\system32\pl-pl
2008-02-10 15:53 . 2001-10-30 13:00 68,608 --a------ C:\WINDOWS\system32\plugin.ocx
2008-02-10 15:53 . 2001-10-30 13:00 68,608 --a------ C:\WINDOWS\system32\dllcache\plugin.ocx
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-05 12:20 --------- d-----w C:\Program Files\Trojan Remover
2008-03-05 12:18 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\uTorrent
2008-03-04 21:11 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-03-02 20:00 --------- d-----w C:\Program Files\uTorrent
2008-02-27 15:37 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-02-27 14:14 --------- d-----w C:\Program Files\Xfire
2008-02-26 20:00 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\mIRC
2008-02-26 19:59 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\Xfire
2008-02-26 15:52 --------- d-----w C:\Program Files\mIRC
2008-02-24 19:15 --------- d-----w C:\Program Files\Avast4
2008-02-24 19:07 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-02-24 12:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-24 11:47 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\Lavasoft
2008-02-20 17:47 --------- d-----w C:\Program Files\FinePixViewer
2008-02-20 16:08 --------- d-----w C:\Program Files\Winamp 5.52
2008-02-13 20:34 --------- d-----w C:\Program Files\Gadu-Gadu
2008-02-12 11:52 --------- d-----w C:\Program Files\The GodFather
2008-02-02 15:49 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Simply Super Software
2008-02-02 15:49 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\Simply Super Software
2008-02-01 21:31 --------- d-----w C:\Program Files\Neostrada TP
2008-02-01 20:38 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\teamspeak2
2008-01-28 16:52 --------- d-----w C:\Program Files\MagicISO
2008-01-27 18:28 --------- d-----w C:\Program Files\McFunSoft Video Solution
2008-01-25 23:18 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-01-20 11:12 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\WebCompiler3
2008-01-20 10:26 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\Winamp 5.52
2008-01-08 17:33 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Bluetooth
2008-01-08 17:25 --------- d-----w C:\Program Files\IVT Corporation
2008-01-08 17:04 --------- d--h--r C:\Documents and Settings\Admin\Dane aplikacji\SecuROM
2007-11-10 14:13 81,920 ----a-w C:\Documents and Settings\Admin\Dane aplikacji\ezpinst.exe
2007-11-10 14:13 47,360 ----a-w C:\Documents and Settings\Admin\Dane aplikacji\pcouffin.sys
2001-01-11 14:02 794,624 ----a-w C:\WINDOWS\inf\OTHER\audio3d.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2fc5363f-63fd-4fc5-938a-d887d8f26373}]
C:\WINDOWS\system32\abehspig.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{76B84644-34A1-42E8-9159-5CE5C6B0F12C}]
C:\WINDOWS\system32\byxxv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fc275c7f"="C:\WINDOWS\system32\xsjcdqut.dll" [ ]
"cwriter"="C:\Program Files\StorageProtector\ucookw.exe" [ ]
"BMff146fe3"="C:\WINDOWS\system32\hpkoodeq.dll" [ ]
"combofix"="C:\WINDOWS\system32\CF16013.exe" [2004-08-04 00:44 395776]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe,"
"UIHost"="logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mmttkpfk]
mmttkpfk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WLCtrl32]
WLCtrl32.dll 2008-03-06 14:51 11776 C:\WINDOWS\system32\WLCtrl32.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Aktywacja Testera.lnk]
backup=C:\WINDOWS\pss\Aktywacja Testera.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BlueSoleil.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BlueSoleil.lnk
backup=C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DSLMON.lnk]
backup=C:\WINDOWS\pss\DSLMON.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^ExifLauncher2.lnk]
backup=C:\WINDOWS\pss\ExifLauncher2.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2007-05-04 01:32 961024 C:\Program Files\Ares 2.0.9\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-10-23 14:18 202024 C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2004-08-04 00:44 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 00:44 15360 C:\WINDOWS\System32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus D88 Series]
--a------ 2005-01-27 14:00 98304 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABE.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:44 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-09-20 08:51 1836328 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 14:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
--------- 2002-02-04 22:32 53248 C:\Program Files\REGSHAVE\REGSHAVE.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SIGKreator]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
--a------ 2008-02-01 14:42 743504 C:\Program Files\Trojan Remover\Trjscan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon]
--a------ 2003-10-16 19:07 24576 C:\PROGRA~1\NEOSTR~1\CnxMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
--------- 2003-10-16 19:07 53248 C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
--------- 2003-10-16 19:07 20480 C:\PROGRA~1\NEOSTR~1\Watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"BthServ"=2 (0x2)
"BlueSoleil Hid Service"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
"aspnet_state"=3 (0x3)
"aawservice"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Ares 2.0.9\\Ares.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 Esy40;Esy40;C:\WINDOWS\system32\Drivers\Esy40.sys [2008-03-06 14:16]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);C:\WINDOWS\system32\DRIVERS\s115bus.sys [2007-04-23 15:54]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s115mdfl.sys [2007-04-23 15:54]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s115mdm.sys [2007-04-23 15:54]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s115mgmt.sys [2007-04-23 15:54]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s115obex.sys [2007-04-23 15:54]
S3 USB2_04;USB2_04 driver;C:\WINDOWS\system32\drivers\nkv2.sys [2008-03-06 14:16]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-28 16:45:28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-06 14:52:50
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\yutsubk]
"ImagePath"="\??\C:\WINDOWS\inf\yutsubk.cat"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\WLCtrl32.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\bgsvcgen.exe
.
**************************************************************************
.
Completion time: 2008-03-06 14:55:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-06 13:55:23
.
2007-12-10 16:33:04 --- E O F ---