tak wygląda mój nowy log po ponownym przeskanowaniu komputera ComboFix'em
ComboFix 08-04-06.1 - Anna 2008-04-17 21:38:30.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.578 [GMT 2:00]
Running from: C:\Documents and Settings\Anna\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\Anna\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-17 to 2008-04-17 )))))))))))))))))))))))))))))))
.
2008-04-07 00:00 . 2008-04-07 00:00 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-04-07 00:00 . 2008-04-07 00:03 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-04-06 23:59 . 2008-04-07 00:00 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-04-06 23:59 . 2008-04-07 00:00 60,808 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-04-06 23:59 . 2008-04-07 00:00 10,652 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-04-06 23:59 . 2008-04-07 00:00 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-04-06 23:21 . 2008-04-06 23:21 <DIR> d-------- C:\Program Files\Winamp Toolbar
2008-04-06 23:21 . 2008-04-06 23:21 <DIR> d-------- C:\Program Files\Winamp Remote
2008-04-06 23:21 . 2008-04-06 23:21 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Winamp Toolbar
2008-04-06 23:21 . 2008-04-06 23:21 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\OrbNetworks
2008-04-06 23:16 . 2008-04-06 23:24 <DIR> d-------- C:\Program Files\Winamp
2008-04-06 23:16 . 2008-04-06 23:26 <DIR> d-------- C:\Documents and Settings\Anna\Dane aplikacji\Winamp
2008-03-26 00:25 . 2006-10-04 16:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-03-26 00:25 . 2006-10-04 16:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-03-26 00:25 . 2006-10-04 16:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-03-26 00:24 . 2008-03-26 00:24 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-03-26 00:22 . 2008-03-26 00:22 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-03-26 00:22 . 2008-03-26 00:23 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-03-26 00:05 . 2008-03-26 00:06 37,228,360 --a------ C:\Program Files\sp32646.exe
2008-03-25 23:57 . 2008-03-25 23:57 7,199,800 --a------ C:\Program Files\sp37155.exe
2008-03-23 15:26 . 2008-03-23 15:26 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-03-23 15:26 . 2008-03-23 15:26 1,406 --a------ C:\WINDOWS\system32\Help.ico
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-17 19:30 --------- d-----w C:\Program Files\neostrada tp
2008-04-07 14:20 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-06 22:02 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Symantec
2008-04-06 22:00 --------- d-----w C:\Program Files\Symantec
2008-04-06 21:09 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-03-25 22:21 --------- d-----w C:\Program Files\Windows Media Connect
2008-03-23 23:53 10,022 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-03-20 13:50 --------- d-----w C:\Program Files\Odkurzacz
2008-03-15 14:07 --------- d-----w C:\Program Files\Avira
2008-03-15 13:24 --------- d-----w C:\Program Files\Programy
2008-03-07 15:11 --------- d-----w C:\Program Files\Kaspersky Lab
2008-03-06 22:13 65,024 ----a-w C:\WINDOWS\IFinst26.exe
2008-03-06 22:13 --------- d-----w C:\Program Files\Lame MP3 Codec
2008-03-06 22:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-06 22:12 --------- d-----w C:\Program Files\Samsung
2008-03-06 22:12 --------- d-----w C:\Program Files\MarkAny
2008-03-06 22:12 --------- d-----w C:\Documents and Settings\Anna\Dane aplikacji\DataCast
2008-03-06 22:11 --------- d-----w C:\Documents and Settings\Anna\Dane aplikacji\InstallShield
2008-03-02 15:34 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-03-02 15:08 --------- d-----w C:\Program Files\Java
2007-07-15 15:31 1,164,456 ----a-w C:\Program Files\install_flash_player.exe
2007-07-08 18:39 15,324,000 ----a-w C:\Program Files\setuppol-avast.exe
2007-05-25 20:13 6,820,536 ----a-w C:\Program Files\FirefoxGoogleToolbarSetup.exe
.
((((((((((((((((((((((((((((( snapshot@2008-04-07_21.21.20.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-07 14:23:46 53,098 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-17 19:35:08 53,098 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-07 14:23:46 67,496 ----a-w C:\WINDOWS\system32\perfc015.dat
+ 2008-04-17 19:35:08 67,496 ----a-w C:\WINDOWS\system32\perfc015.dat
- 2008-04-07 14:23:46 380,684 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-17 19:35:08 380,684 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-04-07 14:23:46 436,560 ----a-w C:\WINDOWS\system32\perfh015.dat
+ 2008-04-17 19:35:08 436,560 ----a-w C:\WINDOWS\system32\perfh015.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2008-03-20 00:36 1267040 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-04-07 00:01 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-03-20 00:36 1267040]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:00 15360]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 17:51 57344]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-12 12:59 68856]
"Gadu-Gadu"="C:\Program Files\Programy\Gadu-Gadu\gg.exe" [2007-05-10 16:36 2111176]
"Odkurzacz-MCD"="C:\Program Files\Odkurzacz\odk_mcd.exe" [2008-02-04 19:13 266240]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-03-25 04:59 507904]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-12-01 12:46 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 10:11 925696]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-05-06 14:06 716800]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"PTHOSTTR"="C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.exe" [2006-02-14 11:56 122880]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-08-31 05:20 122940]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-10 20:04 761945]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 14:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 14:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 14:17 118784]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 10:49 454656]
"CognizanceTS"="C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 20:12 17920]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-02 15:39 131072]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2006-02-22 08:03 40960]
"Recguard"="C:\WINDOWS\Sminst\Recguard.exe" [2005-12-20 15:51 1187840]
"Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" [2006-01-23 16:11 802816]
"Scheduler"="C:\WINDOWS\SMINST\Scheduler.exe" [2006-02-15 15:43 892928]
"WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2005-11-08 12:59 184320]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-02 18:04 77824]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 17:50 40960]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2004-08-23 15:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\GestMaj.exe" [2004-10-14 17:55 32768]
"SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-02-23 17:32 126976]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-06 23:13 249896]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-08-24 23:07 51048]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-08-24 22:53 714608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 10:00 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-02-15 17:16:02 581693]
DVD Check.lnk - C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [2007-02-26 17:12:56 184320]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 17:51 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll 2005-07-25 20:41 40960 C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XVID"= xvid.dll
"msacm.ac3acm"= ac3acm.acm
"VIDC.wmv3"= wmv9vcm.dll
"VIDC.MJPG"= pvmjpg21.dll
"msacm.lameacm"= LameACM.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\SMINST\\Scheduler.exe"=
"C:\\Program Files\\Programy\\Gadu-Gadu\\gg.exe"=
"C:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\Polish\\setup.exe"=
"C:\\WINDOWS\\system32\\muzapp.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
R2 ASChannel;Local Communication Channel;C:\WINDOWS\System32\svchost.exe [2004-08-04 10:00]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-08-23 14:35]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-09-15 12:07]
S3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-09-19 12:03]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\system32\ZDCndis5.SYS []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASChannel
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a71d045-087d-11dc-8c3a-0018dec09b13}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12f7eaa4-80d0-11dc-8dd4-0018dec09b13}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1994f7ea-9de9-11dc-8df6-0018dec09b13}]
\Shell\AutoRun\command - y82td3td.com
\Shell\explore\Command - y82td3td.com
\Shell\open\Command - y82td3td.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22c2b928-9e7b-11dc-8df8-0018dec09b13}]
\Shell\Auto\command - activexdebugger32.exe f
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL activexdebugger32.exe f
\Shell\explore\Command - activexdebugger32.exe f
\Shell\open\Command - activexdebugger32.exe f
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26307d6c-12d9-11dc-8c5f-0018dec09b13}]
\Shell\AutoRun\command - v.com
\Shell\explore\Command - v.com
\Shell\open\Command - v.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4ee32591-d4ae-11db-8ba7-0018dec09b13}]
\Shell\AutoRun\command - G:\USBNB.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{892f22cc-ccc7-11db-8b98-0018dec09b13}]
\Shell\AutoRun\command - F:\oufddh.exe
\Shell\explore\Command - F:\oufddh.exe
\Shell\open\Command - F:\oufddh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{96ce8594-dbd5-11dc-8e96-0018dec09b13}]
\Shell\AutoRun\command - F:\ylr.exe
\Shell\explore\Command - F:\ylr.exe
\Shell\open\Command - F:\ylr.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-07 18:00:11 C:\WINDOWS\Tasks\Norton AntiVirus - Uruchom pełne skanowanie systemu - Anna.job"
- C:\Program Files\Norton AntiVirus\Navw32.exef/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-17 21:40:30
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ????P??????(?@???????@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-17 21:40:56
ComboFix-quarantined-files.txt 2008-04-17 19:40:52
ComboFix2.txt 2008-04-17 12:24:46
Pre-Run: 7,877,414,912 bajtów wolnych
Post-Run: 7,867,322,368 bajtów wolnych
.
2008-04-06 16:00:59 --- E O F ---