Zrobiłem skan ComboFix i wyczyścił mi system ale wyskoczył mi Log.txt. Kumpel powiedział mi żebym wrzucił to na forum to podadzą mi co mam dalej zrobić. Tak z góry wielkie dzięki z pomoc. Oto log:
ComboFix 09-10-17.01 - komputer 2009-10-18 13:15.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.223.92 [GMT 2:00]
Uruchomiony z: c:\documents and settings\komputer\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\2sm66r.exe
C:\autorun.inf
c:\documents and settings\komputer\Dane aplikacji\BITS
c:\documents and settings\komputer\Dane aplikacji\BITS\BITS.ini
c:\documents and settings\komputer\Dane aplikacji\BITS\DHTTable.dat
c:\documents and settings\komputer\Dane aplikacji\BITS\ProxyList.ini
c:\documents and settings\komputer\Dane aplikacji\BITS\UPnP.ini
C:\hm1bfpuj.exe
C:\log.tmp
c:\program files\FlashGet Network
c:\program files\FlashGet Network\FlashGet universal\dbtrans_verbose.log
c:\program files\FlashGet Network\FlashGet universal\fgoption.ini
c:\program files\FlashGet Network\FlashGet universal\P2PCfg.ini
c:\program files\FlashGet Network\FlashGet universal\p2spmgr.ini
c:\program files\FlashGet Network\FlashGet universal\p4spmgr.ini
c:\program files\FlashGet Network\FlashGet universal\Profiles\config.dat
c:\program files\FlashGet Network\FlashGet universal\Profiles\tasks.dat
c:\program files\FlashGet Network\FlashGet universal\transaction.log
C:\s3ek.exe
C:\vlvtdflx.exe
c:\windows\AhnRpta.exe
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000013_.tmp.dll
D:\Autorun.inf
D:\hm1bfpuj.exe
D:\s3ek.exe
D:\vlvtdflx.exe
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Pliki utworzone od 2009-09-18 do 2009-10-18 )))))))))))))))))))))))))))))))
.
2009-10-18 00:16 . 2009-10-18 00:16 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\McAfee Security Scan
2009-10-18 00:16 . 2009-10-18 00:16 -------- d-----w- c:\program files\McAfee Security Scan
2009-10-13 18:39 . 2008-04-14 19:50 14720 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-10-13 18:39 . 2008-04-14 19:50 14720 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-10-08 14:52 . 2009-09-15 10:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-10-08 14:52 . 2009-09-15 10:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-10-08 14:52 . 2009-09-15 10:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-10-08 14:52 . 2009-09-15 10:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-10-08 14:52 . 2009-09-15 10:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-10-08 14:52 . 2009-09-15 10:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-10-08 14:52 . 2009-09-15 10:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-10-08 14:52 . 2009-09-15 10:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-10-08 14:51 . 2009-09-15 10:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-10-08 14:51 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-10-08 14:51 . 2003-03-18 19:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2009-10-08 14:51 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2009-10-06 18:17 . 2005-02-25 20:49 45056 ----a-w- c:\windows\Bs350u2r.exe
2009-10-06 18:17 . 2005-01-14 11:47 180224 ----a-w- c:\windows\system\StillDrv.dll
2009-10-06 18:17 . 2004-06-16 18:38 3031 ----a-w- c:\windows\system32\drivers\C10F0110.bin
2009-10-06 18:17 . 2004-06-16 18:38 3031 ----a-w- c:\windows\system32\drivers\C10H0110.bin
2009-10-06 18:17 . 2005-02-17 17:03 638720 ----a-w- c:\windows\system32\drivers\Bs350u2.sys
2009-10-06 18:17 . 2005-01-27 09:38 118784 ----a-w- c:\windows\system\vfwExtC.dll
2009-10-06 18:17 . 2005-01-27 09:38 122880 ----a-w- c:\windows\system\FiltProp.dll
2009-10-06 18:17 . 2009-10-06 18:17 -------- d-----w- c:\windows\Bs350u2
2009-10-04 08:32 . 2009-10-04 08:32 -------- d-----w- c:\program files\CONEXANT
2009-10-03 22:22 . 2009-10-03 22:25 -------- dc-h--w- c:\windows\ie8
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-06 19:58 . 2008-11-16 18:50 -------- d-----w- c:\documents and settings\komputer\Dane aplikacji\Skype
2009-10-06 18:28 . 2008-11-16 18:54 -------- d-----w- c:\documents and settings\komputer\Dane aplikacji\skypePM
2009-10-06 18:17 . 2008-09-08 10:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-04 08:29 . 2008-12-21 09:28 30724 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-04 07:24 . 2008-09-08 10:26 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-03 22:51 . 2009-06-06 07:20 -------- d-----w- c:\program files\QuickTime
2009-10-03 22:41 . 2009-06-04 14:16 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-10-03 22:38 . 2009-06-04 17:48 -------- d-----w- c:\program files\Corel
2009-10-03 22:36 . 2008-09-08 10:28 -------- d-----w- c:\program files\InterActual
2009-10-03 22:36 . 2008-09-08 10:27 -------- d-----w- c:\program files\InterVideo
2009-10-03 22:35 . 2008-09-08 10:27 -------- d-----w- c:\program files\Common Files\InterVideo
2009-10-03 22:32 . 2009-06-09 20:19 -------- d-----w- c:\program files\OCAD
2009-10-03 22:19 . 2009-06-07 16:54 -------- d-----w- c:\documents and settings\komputer\Dane aplikacji\Samsung
2009-10-03 22:14 . 2009-01-11 17:13 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Ulead Systems
2009-10-02 18:55 . 2008-12-22 16:50 -------- d-----w- c:\program files\Valve
2009-09-13 20:24 . 2009-09-13 20:16 -------- d-----w- c:\documents and settings\komputer\Dane aplikacji\DAEMON Tools Lite
2009-09-13 20:22 . 2009-09-13 20:22 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\DAEMON Tools Lite
2009-09-13 20:22 . 2009-09-13 20:21 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-09-13 20:22 . 2009-09-13 20:20 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-09-13 20:16 . 2009-09-13 20:16 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-11 14:19 . 2008-04-14 20:50 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:05 . 2008-04-14 20:50 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-26 08:02 . 2008-04-14 20:50 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-05 09:01 . 2008-04-14 20:50 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 20:59 . 2008-04-14 20:00 2190464 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:29 . 2008-04-14 21:59 2067328 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-29 04:37 . 2008-04-14 20:50 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2008-04-14 20:50 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-05 02:01 . 2009-06-04 18:00 56 --sh--r- c:\windows\system32\3F50A24125.sys
2009-06-05 02:02 . 2009-06-04 17:50 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
------- Sigcheck -------
[-] 2008-05-08 . 9F02C1CF7C3100E4AEA7DD8B6A86A01B . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SoundMan.exe [2006-07-21 86016]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-02-16 49152]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-10-08 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-10-08 20560]
R3 HSFHWSIS;HSFHWSIS;c:\windows\system32\drivers\HSFHWSIS.sys [2005-06-22 216320]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [2008-09-08 140288]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2009-06-07 36608]
S3 ZDCndis5;ZDCndis5 Protocol Driver;\??\c:\windows\system32\ZDCndis5.SYS --> c:\windows\system32\ZDCndis5.SYS [?]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.google.pl/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Pobierz z USDownloaderem - c:\program files\USDownloader 1.3.5.1 PL - 03.09.08__up by AMH__\Ext\downloadie.html
FF - ProfilePath - c:\documents and settings\komputer\Dane aplikacji\Mozilla\Firefox\Profiles\px7qqykg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.pl/
FF - component: c:\documents and settings\komputer\Dane aplikacji\Mozilla\Firefox\Profiles\px7qqykg.default\extensions\[email protected]\components\DTToolbarFF.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-wsctf.exe - wsctf.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-18 13:26
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'explorer.exe'(2500)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\WgaTray.exe
c:\combofix\CF25317.exe
.
**************************************************************************
.
Czas ukończenia: 2009-10-18 13:30 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-10-18 11:30
Przed: 3 217 244 160 bajtów wolnych
Po: 4 357 308 416 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
208 --- E O F --- 2009-10-16 14:04