oto log z combofixa:
ComboFix 08-05-07.1 - zogert 2008-05-08 13:14:27.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1549 [GMT 2:00]
Running from: D:\Nowy folder (3)\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-08 to 2008-05-08 )))))))))))))))))))))))))))))))
.
2008-05-06 19:08 . 2008-05-06 19:08 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-05-06 19:07 . 2008-05-06 19:08 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-05-06 19:07 . 2007-06-24 13:18 250,880 --a------ C:\WINDOWS\system32\hpzc35hg.dll
2008-05-06 19:06 . 2008-05-06 19:06 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-05-06 19:06 . 2008-05-06 19:06 1,984 --a------ C:\WINDOWS\sounder.his
2008-05-06 19:05 . 2008-05-06 19:06 824 --a------ C:\WINDOWS\hpntwksetup.ini
2008-05-06 19:03 . 2008-05-06 19:08 <DIR> d-------- C:\Documents and Settings\zogert\Dane aplikacji\HP
2008-04-22 10:58 . 2007-03-08 01:51 43,528 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-04-22 10:58 . 2007-03-08 01:51 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-04-22 10:58 . 2007-03-08 01:51 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-04-22 10:57 . 2008-04-22 11:03 <DIR> d-------- C:\Program Files\Winamp
2008-04-22 10:57 . 2008-04-22 10:57 <DIR> d-------- C:\Program Files\PDFCreator
2008-04-22 10:57 . 2008-04-22 11:06 <DIR> d-------- C:\Documents and Settings\zogert\Dane aplikacji\Winamp
2008-04-22 10:51 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-08 11:02 --------- d-----w C:\Documents and Settings\zogert\Dane aplikacji\OpenOfficeT72
2008-04-22 09:17 --------- d-----w C:\Program Files\Java
2008-04-07 15:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-07 15:15 --------- d-----w C:\Program Files\Contex
2008-04-07 15:02 --------- d-----w C:\Program Files\Common Files\ctx
2008-04-07 14:51 5,542 ----a-w C:\ctx.reg
2008-04-07 14:51 --------- d-----w C:\Documents and Settings\zogert\Dane aplikacji\InstallShield
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 13:03 --------- d-----w C:\Program Files\MSXML 4.0
2008-03-19 07:46 --------- d-----w C:\Documents and Settings\zogert\Dane aplikacji\Gadu-Gadu
2008-03-19 07:45 --------- d-----w C:\Program Files\Gadu-Gadu
2008-03-19 06:28 --------- d-----w C:\Documents and Settings\zogert\Dane aplikacji\AdobeUM
2008-03-18 18:03 --------- d-----w C:\Documents and Settings\zogert\Dane aplikacji\MfcEmbed
2008-03-18 17:33 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
2008-03-18 17:18 --------- d-----w C:\Documents and Settings\zogert\Dane aplikacji\Contex
2008-03-18 16:58 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-03-18 16:58 --------- d-----w C:\Documents and Settings\zogert\Dane aplikacji\Minolta
2008-03-18 16:57 --------- d-----w C:\Program Files\KONICA MINOLTA
2008-03-18 16:53 --------- d-----w C:\Program Files\OpenOfficeT7 2.3.1
2008-03-18 16:53 --------- d-----w C:\Program Files\Common Files\Java
2008-03-18 16:49 --------- d-----w C:\Program Files\Ahead
2008-03-18 16:48 --------- d-----w C:\Program Files\Common Files\Nero
2008-03-18 16:47 --------- d-----w C:\Program Files\Common Files\Ahead
2008-03-18 16:47 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Ahead
2008-03-18 16:46 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Contex
2008-03-18 16:44 --------- d-----w C:\Program Files\Alwil Software
2008-03-18 16:44 --------- d-----w C:\Documents and Settings\zogert\Dane aplikacji\Corel
2008-03-18 16:36 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-18 16:15 --------- d-----w C:\Documents and Settings\zogert\Dane aplikacji\InsERT GT
2008-03-18 16:13 --------- d-----w C:\Program Files\Common Files\InsERT
2008-03-18 16:12 --------- d-----w C:\Program Files\InsERT
2008-03-18 16:06 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Corel
2008-03-18 16:03 --------- d-----w C:\Program Files\Common Files\Corel
2008-03-18 16:02 --------- d-----w C:\Program Files\Corel
2008-03-18 15:43 --------- d-----w C:\Program Files\RW-240
2008-03-18 15:38 --------- d-----w C:\Program Files\GIGABYTE
2008-03-18 15:38 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\InstallShield
2008-03-18 15:32 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-18 15:31 606,848 ----a-w C:\WINDOWS\flashax.exe
2008-03-18 15:31 12,288 ----a-w C:\WINDOWS\impborl.dll
2008-03-18 15:31 --------- d-----w C:\Program Files\AMD
2008-03-18 15:30 --------- d-----w C:\Program Files\Realtek AC97
2008-03-18 14:26 --------- d-----w C:\Program Files\microsoft frontpage
2008-03-18 14:25 --------- d-----w C:\Program Files\Usługi online
2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-11-14 12:54 2131392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsSetupTwo"="E:\Drivers\Chipset\WINXP_2K\SetupDriver.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2005-07-12 09:55 81920 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-11 00:03 8429568]
"nwiz"="nwiz.exe" [2007-05-11 00:03 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-05-11 00:03 81920]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 10:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 10:30 81920]
"CorelDRAW Graphics Suite 11b"="C:\Program Files\Corel\Corel Graphics 12\Languages\PL\Programs\Registration.exe" [2004-06-23 01:20 733184]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ezWTools"="ezWTools /install /bus /nologo" []
"ezConfig"="ezConfig.exe" [2007-04-26 06:35 360448 C:\WINDOWS\system32\ezConfig.exe]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-12-20 17:16 37376]
"PUStarter"="C:\Program Files\Common Files\Hewlett-Packard\HP Printer Utility DCS\Appinterfaces\HPPUDS.exe" [2007-05-31 16:15 81920]
"RunPUTasktray"="C:\Program Files\Hewlett-Packard\HP Printer Utility\HPPU.exe" [2007-05-31 16:19 68608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
C:\Documents and Settings\zogert\Menu Start\Programy\Autostart\
GIGABYTE VGA Utility.lnk - C:\Documents and Settings\zogert\Dane aplikacji\Microsoft\Installer\{D27BDB5D-3B4C-44F0-A648-BD00B0E79B39}\Utility.exe2_D27BDB5D3B4C44F0A648BD00B0E79B39.exe [2008-03-18 17:38:52 40960]
OpenOfficeT7 2.3.1.lnk - C:\Program Files\OpenOfficeT7 2.3.1\program\quickstart.exe [2007-12-08 02:06:24 393216]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 17:23:32 74308]
WIDEsystem.lnk - C:\Program Files\Contex\WIDEsystem\WS.exe [2008-03-18 18:36:33 393216]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\RW-240\\RW-240\\RW-240 PLOTBASE\\Program\\ADCAPServer.exe"=
"C:\\Program Files\\RW-240\\RW-240\\RW-240 PLOTBASE\\Program\\PBDBru.exe"=
"C:\\Program Files\\Contex\\WIDEsystem\\wsss.exe"=
"C:\\Program Files\\KONICA MINOLTA\\PSC2\\BinBasic\\MPSCFTPS.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\Hewlett-Packard\\HP Printer Utility\\HPPU.exe"=
R0 diskpws;Disk power system;C:\WINDOWS\system32\drivers\diskpws.sys [2007-05-29 08:47]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 MSSQL$INSERTGT;MSSQL$INSERTGT;C:\Program Files\Microsoft SQL Server\MSSQL$INSERTGT\Binn\sqlservr.exe [2002-12-17 17:26]
R2 MSSQL$MPSC_DB;MSSQL$MPSC_DB;C:\Program Files\Microsoft SQL Server\MSSQL$MPSC_DB\Binn\sqlservr.exe [2002-12-17 17:26]
R3 D2;D2 driver;C:\WINDOWS\system32\Drivers\D2.sys [2004-06-01 14:30]
R3 scsiscan;Sterownik skanera SCSI;C:\WINDOWS\system32\DRIVERS\scsiscan.sys [2001-08-17 21:53]
S3 SQLAgent$INSERTGT;SQLAgent$INSERTGT;C:\Program Files\Microsoft SQL Server\MSSQL$INSERTGT\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 SQLAgent$MPSC_DB;SQLAgent$MPSC_DB;C:\Program Files\Microsoft SQL Server\MSSQL$MPSC_DB\Binn\sqlagent.EXE [2002-12-17 17:23]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-08 13:15:09
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-08 13:15:31
ComboFix-quarantined-files.txt 2008-05-08 11:15:28
ComboFix2.txt 2008-05-08 11:08:31
ComboFix3.txt 2008-05-08 11:06:36
Pre-Run: 35,144,753,152 bajtów wolnych
Post-Run: 35,137,343,488 bajtów wolnych
146 --- E O F --- 2008-05-06 17:16:29


