Log z ComboFix
- Kod: Zaznacz wszystko
ComboFix 08-04-04.1 - user 2008-04-06 12:02:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1621 [GMT 2:00]
Running from: C:\Documents and Settings\user\Pulpit\z firefoxa\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\OPTIONS\CABS\_desktop.ini
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-03-06 to 2008-04-06 )))))))))))))))))))))))))))))))
.
2008-04-05 20:52 . 2008-04-05 20:53 <DIR> d-------- C:\Milionerzy
2008-04-05 20:51 . 2008-04-05 20:51 103,463 -r-hs---- C:\m9j.com
2008-04-05 14:59 . 2008-04-05 14:59 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-04-05 14:32 . 2008-04-05 14:32 <DIR> d-------- C:\Program Files\MoorHunt
2008-04-04 18:58 . 2008-04-04 18:58 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-04-04 18:34 . 2008-04-04 18:34 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-04 18:34 . 2008-04-04 18:34 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\Tibia
2008-04-04 18:21 . 2008-04-04 18:22 <DIR> d-------- C:\Program Files\Tibia
2008-04-03 20:23 . 2008-04-03 20:22 102,407 -r-hs---- C:\gy.cmd
2008-04-02 20:53 . 2008-04-02 20:53 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-04-02 20:53 . 2003-06-19 01:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-04-02 20:53 . 2008-04-02 20:53 421 --a------ C:\WINDOWS\ODBC.INI
2008-04-02 20:52 . 2008-04-02 20:52 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-04-02 19:33 . 2008-04-02 19:33 22,328 --a------ C:\Documents and Settings\user\Dane aplikacji\PnkBstrK.sys
2008-04-02 19:33 . 2008-04-02 19:33 319 --a------ C:\WINDOWS\game.ini
2008-04-02 18:26 . 2008-04-02 18:26 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-02 18:26 . 2008-04-05 08:57 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-04-02 18:26 . 2008-04-02 21:56 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-04-02 18:26 . 2008-04-05 08:57 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-02 18:20 . 2008-04-02 18:20 <DIR> d-------- C:\Documents and Settings\LocalService\Dane aplikacji\Xfire
2008-04-02 18:17 . 2008-04-02 18:17 <DIR> d-------- C:\Documents and Settings\NetworkService\Dane aplikacji\Xfire
2008-04-02 18:16 . 2008-04-05 08:56 <DIR> d-------- C:\Program Files\Xfire
2008-04-02 18:16 . 2008-04-05 09:18 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\Xfire
2008-04-02 17:45 . 2008-04-02 19:26 <DIR> d-------- C:\Program Files\Activision
2008-04-02 17:44 . 2008-04-02 17:44 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-04-02 17:42 . 2008-04-02 17:42 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-04-02 17:40 . 2008-04-02 17:40 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\DAEMON Tools
2008-04-02 17:40 . 2008-04-02 17:40 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-04-02 16:36 . 2008-04-02 16:36 103,810 -r-hs---- C:\qwc.exe
2008-04-02 16:32 . 2008-04-02 21:20 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-04-01 22:55 . 2008-04-01 22:55 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\Gadu-Gadu
2008-04-01 21:19 . 2008-04-01 21:19 <DIR> d-------- C:\Program Files\MarBit
2008-04-01 21:02 . 2008-04-01 21:02 <DIR> d-------- C:\Program Files\Ares
2008-04-01 20:44 . 2008-04-01 20:44 1,158 --a------ C:\WINDOWS\mozver.dat
2008-04-01 20:32 . 2008-04-01 20:32 <DIR> d-------- C:\Program Files\Gadu-Gadu
2008-04-01 20:32 . 2008-04-01 20:33 <DIR> d-------- C:\Documents and Settings\user\Gadu-Gadu
2008-04-01 20:30 . 2008-04-01 20:31 103,084 -r-hs---- C:\6l6w8.com
2008-04-01 20:29 . 2008-04-01 20:29 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-01 20:17 . 2008-04-01 20:17 <DIR> d-------- C:\Program Files\Alwil Software
2008-04-01 20:07 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-01 20:07 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-04-01 20:07 . 2008-04-01 20:07 800 --a------ C:\WINDOWS\hpinfo.lnk
2008-04-01 20:07 . 2008-04-01 20:07 740 --a------ C:\WINDOWS\reg.prm
2008-04-01 20:06 . 2008-04-01 20:06 376 --a------ C:\WINDOWS\mozregistry.dat
2008-04-01 20:05 . 2008-04-01 20:07 <DIR> d-------- C:\Program Files\hp deskjet 656c series
2008-04-01 20:05 . 2008-04-01 20:06 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-04-01 20:04 . 2008-04-01 20:04 <DIR> d-------- C:\Program Files\SAGEM
2008-04-01 20:04 . 2005-11-04 16:55 126,976 --a------ C:\WINDOWS\system32\coclassfast.dll
2008-04-01 20:02 . 2008-04-04 18:57 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-04-01 14:12 . 2008-04-01 14:12 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\CyberLink
2008-04-01 14:11 . 2008-04-01 14:12 <DIR> d-------- C:\Program Files\CyberLink
2008-04-01 14:10 . 2008-04-02 16:37 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2008-04-01 14:09 . 2008-04-01 14:09 <DIR> d-------- C:\Documents and Settings\user\Dane aplikacji\Ahead
2008-04-01 14:08 . 2008-04-01 14:08 <DIR> d-------- C:\Program Files\Nero
2008-04-01 14:08 . 2008-04-01 14:10 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-04-01 14:08 . 2008-04-01 14:08 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Nero
2008-04-01 14:05 . 2008-04-01 14:05 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-04-01 14:05 . 2008-04-01 14:05 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-04-01 14:05 . 2008-04-01 14:05 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-03-14 01:05 . 2008-03-14 01:05 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-02 17:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-01 12:11 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-01 12:00 15,600 ----a-w C:\WINDOWS\gdrv.sys
2008-04-01 11:57 --------- d-----w C:\Program Files\My Company Name
2008-04-01 11:49 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-04-01 11:49 --------- d-----w C:\Program Files\Realtek
2008-04-01 11:49 --------- d-----w C:\Documents and Settings\user\Dane aplikacji\InstallShield
2008-04-01 11:47 --------- d-----w C:\Program Files\Intel
2008-04-01 11:39 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-01 11:38 --------- d-----w C:\Program Files\Usługi online
2008-03-29 17:45 1,146,232 ----a-w C:\WINDOWS\system32\aswBoot.exe
2008-03-29 17:35 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-29 17:35 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-03-29 17:31 75,856 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
2008-03-29 17:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-29 17:27 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-29 17:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-29 17:23 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2008-03-04 10:33 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2008-01-10 11:16 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll
2008-01-10 11:15 755,027 ----a-w C:\WINDOWS\system32\xvidcore.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 18:05 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-07 07:51 8523776]
"nwiz"="nwiz.exe" [2007-12-07 07:51 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-07 07:51 81920]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 11:33 16132608 C:\WINDOWS\RTHDCPL.exe]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-12 11:16 196608]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
"VIDC.YV12"= yv12vfw.dll
"msacm.ac3acm"= ac3acm.acm
"msacm.lameacm"= lameACM.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2008-04-01 14:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a16cf428-ffee-11dc-81bd-806d6172696f}]
\Shell\AutoRun\command - F:\6l6w8.com
\Shell\explore\Command - F:\6l6w8.com
\Shell\open\Command - F:\6l6w8.com
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-06 12:02:47
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-06 12:02:57
ComboFix-quarantined-files.txt 2008-04-06 10:02:55
Pre-Run: 80,475,918,336 bajtów wolnych
Post-Run: 80,503,476,224 bajtów wolnych
.
2008-04-02 19:20:53 --- E O F ---