Wszystko zrobiłem w/g wskazówek,mam pytanie czy możliwe jest przejście wirusów z jednego systemu na drugi,gdyż mam też viste zainstalowaną.
Oto log HJT po restarcie:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:17:19, on 2008-04-12
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\programy\nero 8\Nero\Nero8\Nero BackItUp\NBService.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\IoctlSvc.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\programy\cursor powre pack\CursorXP.exe
C:\programy\zegarynka\Zegarynka.exe
C:\programy\brio pack\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\programy\clock\Atomic Alarm Clock\Atomic Alarm Clock\AtomicAlarmClock.exe
C:\programy\ObjectDock\ObjectDock\ObjectDock.exe
C:\programy\brio pack\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
D:\WINDOWS\system32\wuauclt.exe
C:\programy\hijack\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\programy\spybot\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AVP] "D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CursorXP] C:\programy\cursor powre pack\CursorXP.exe
O4 - HKCU\..\Run: [Zegarynka] C:\programy\zegarynka\Zegarynka.exe
O4 - HKCU\..\Run: [RocketDock] "C:\programy\brio pack\Vista Inspirat 2\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [SkinClock] C:\programy\clock\Atomic Alarm Clock\Atomic Alarm Clock\AtomicAlarmClock.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: RocketDock.lnk = C:\programy\brio pack\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\programy\ObjectDock\ObjectDock\ObjectDock.exe
O4 - Startup: UberIcon.lnk = C:\programy\brio pack\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O8 - Extra context menu item: Dodaj do blokowanych banerów - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Statystyki dla ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\programy\spybot\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\programy\spybot\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windows ... 4212869562
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microso ... 4233101984
O20 - AppInit_DLLs: wbsys.dll,D:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\programy\nero 8\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - D:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - D:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 5663 bytes
Z COMBOFIX powstały dwa logi
1:
- Kod:
2004-08-04 00:44 54784 --a------ D:\Qoobox\Quarantine\D\WINDOWS\system32\vfwwdm32.dll.vir
2005-04-30 12:46 102400 --a------ D:\Qoobox\Quarantine\D\WINDOWS\VM303Cap.exe.vir
2006-06-28 11:54 49152 --a------ D:\Qoobox\Quarantine\D\WINDOWS\Domino.EXE.vir
2006-08-30 04:58 49152 --a------ D:\Qoobox\Quarantine\D\WINDOWS\VMSnap3.EXE.vir
2007-06-17 00:11 51200 --a------ D:\Qoobox\Quarantine\D\WINDOWS\nircmd.exe.vir
Zmienna PATH folderu
Numer seryjny woluminu: 90F5-D3F2
D:\QOOBOX
\---Quarantine
+---D
| \---WINDOWS
| | Domino.EXE.vir
| | nircmd.exe.vir
| | VM303Cap.exe.vir
| | VMSnap3.EXE.vir
| |
| \---system32
| vfwwdm32.dll.vir
|
\---Registry_backups
2:
ComboFix 07-07-30.2 - "van Helsing" 2008-04-12 19:06:59.2 [GMT 2:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.Prawda
Command switches used :: C:\programy\hijack\CFScript.txt
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
D:\WINDOWS\Domino.EXE
D:\WINDOWS\nircmd.exe
D:\WINDOWS\system32\vfwwdm32.dll
D:\WINDOWS\VM303Cap.exe
D:\WINDOWS\VMSnap3.EXE
((((((((((((((((((((((((( Files Created from 2008-03-12 to 2008-04-12 )))))))))))))))))))))))))))))))
2008-04-09 05:01 176,128 -ra------ D:\WINDOWS\amcap.exe
2008-04-09 05:00 81,920 -ra------ D:\WINDOWS\system32\VM303STI.dll
2008-04-09 05:00 392,058 -ra------ D:\WINDOWS\system32\drivers\usbVM303.sys
2008-04-09 04:54 36,864 --a------ D:\WINDOWS\system32\KRCapture.dll
2008-04-09 04:54 32,768 --a------ D:\WINDOWS\system32\KRProcess.dll
2008-04-09 04:54 32,768 --a------ D:\WINDOWS\system32\KRDetector.dll
2008-04-08 22:38 91,700 --a------ D:\WINDOWS\system32\drivers\klin.dat
2008-04-08 22:38 85,860 --a------ D:\WINDOWS\system32\drivers\klick.dat
2008-04-08 22:37 5,492,512 --ahs---- D:\WINDOWS\system32\drivers\fidbox.dat
2008-04-08 22:37 112,928 --ahs---- D:\WINDOWS\system32\drivers\fidbox2.dat
2008-04-08 22:37 <DIR> d-------- D:\Program Files\Kaspersky Lab
2008-04-08 18:17 <DIR> d-------- D:\DOCUME~1\VANHEL~1\DANEAP~1\ESET
2008-04-08 17:58 <DIR> d-------- D:\DOCUME~1\VANHEL~1\DANEAP~1\Symantec
2008-04-08 17:56 <DIR> d-------- D:\Program Files\Symantec
2008-04-08 17:56 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\DANEAP~1\Symantec
2008-04-08 17:55 <DIR> d-------- D:\Program Files\Common Files\Symantec Shared
2008-04-08 17:54 73,216 --a------ D:\WINDOWS\ST6UNST.EXE
2008-04-08 17:54 249,856 --------- D:\WINDOWS\Setup1.exe
2008-04-07 08:58 <DIR> d-------- D:\Program Files\ScanSoft
2008-04-06 21:20 <DIR> d-------- D:\Program Files\USDownloader
2008-04-06 11:56 413,696 --a------ D:\WINDOWS\system32\wrap_oal.dll
2008-04-06 11:56 110,592 --a------ D:\WINDOWS\system32\OpenAL32.dll
2008-04-06 11:56 <DIR> d-------- D:\Program Files\OpenAL
2008-04-06 11:51 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\DANEAP~1\Powerboat GT
2008-04-05 13:02 <DIR> d-------- D:\DOCUME~1\VANHEL~1\DANEAP~1\Disney Interactive Studios
2008-04-05 05:55 5,504 --a------ D:\WINDOWS\system32\drivers\MSTEE.sys
2008-04-05 05:55 15,360 --a------ D:\WINDOWS\system32\drivers\StreamIP.sys
2008-04-05 05:55 11,136 --a------ D:\WINDOWS\system32\drivers\SLIP.sys
2008-04-05 05:55 10,880 --a------ D:\WINDOWS\system32\drivers\NdisIP.sys
2008-04-05 05:54 85,376 --a------ D:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-04-05 05:54 19,328 --a------ D:\WINDOWS\system32\drivers\WSTCODEC.SYS
2008-04-05 05:54 17,024 --a------ D:\WINDOWS\system32\drivers\CCDECODE.sys
2008-04-05 05:53 54,784 --a------ D:\WINDOWS\system32\vfwwdm32.dll
2008-04-05 05:45 428,160 -ra------ D:\WINDOWS\system32\drivers\vmfilter303.sys
2008-04-05 05:45 40,960 -ra------ D:\WINDOWS\system32\setupfilter.exe
2008-04-05 05:44 <DIR> d-------- D:\WINDOWS\EffectResources
2008-04-03 18:05 71,832 --a------ D:\WINDOWS\system32\drivers\e4ldrx64.sys
2008-04-03 18:05 69,656 --a------ D:\WINDOWS\system32\drivers\e4ldr.sys
2008-04-03 18:05 58,264 --a------ D:\WINDOWS\system32\drivers\adildrx64.sys
2008-04-03 18:05 56,088 --a------ D:\WINDOWS\system32\drivers\adildr.sys
2008-04-03 18:05 46,892 --a------ D:\WINDOWS\system32\ADADIX16.DLL
2008-04-03 18:05 4,981 --a------ D:\WINDOWS\system32\ADADIX2K.DLL
2008-04-03 18:05 316,416 --a------ D:\WINDOWS\system32\unaddrv.x64.exe
2008-04-03 18:05 253,008 --a------ D:\WINDOWS\adirasx64.exe
2008-04-03 18:05 24,576 --a------ D:\WINDOWS\enddisk32.exe
2008-04-03 18:05 22,395 --a------ D:\WINDOWS\system32\drivers\fpga.bin
2008-04-03 18:05 212,992 --a------ D:\WINDOWS\system32\unaddrv.exe
2008-04-03 18:05 200,704 --a------ D:\WINDOWS\system32\coclassfast.dll
2008-04-03 18:05 194,128 --a------ D:\WINDOWS\adiras.exe
2008-04-03 18:05 176,128 --a------ D:\WINDOWS\autoclk.exe
2008-04-03 18:05 169,496 --a------ D:\WINDOWS\system32\drivers\adiusbawx64.sys
2008-04-03 18:05 155,648 --a------ D:\WINDOWS\system32\adadix32.dll
2008-04-03 18:05 152,308 --a------ D:\WINDOWS\system32\drivers\L1E4I2.BIN
2008-04-03 18:05 152,306 --a------ D:\WINDOWS\system32\drivers\L1E4I1.BIN
2008-04-03 18:05 152,306 --a------ D:\WINDOWS\system32\drivers\L1E4I0.BIN
2008-04-03 18:05 152,146 --a------ D:\WINDOWS\system32\drivers\L1E4P2.BIN
2008-04-03 18:05 152,145 --a------ D:\WINDOWS\system32\drivers\L1E4P1.BIN
2008-04-03 18:05 152,145 --a------ D:\WINDOWS\system32\drivers\L1E4P0.BIN
2008-04-03 18:05 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9P2.BIN
2008-04-03 18:05 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9P1.BIN
2008-04-03 18:05 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9P0.BIN
2008-04-03 18:05 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9I2.BIN
2008-04-03 18:05 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9I1.BIN
2008-04-03 18:05 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9I0.BIN
2008-04-03 18:05 152,036 --a------ D:\WINDOWS\system32\drivers\L1E4D2.BIN
2008-04-03 18:05 152,034 --a------ D:\WINDOWS\system32\drivers\L1E4D1.BIN
2008-04-03 18:05 152,034 --a------ D:\WINDOWS\system32\drivers\L1E4D0.BIN
2008-04-03 18:05 146,968 --a------ D:\WINDOWS\system32\drivers\e4usbawx64.sys
2008-04-03 18:05 127,456 --a------ D:\WINDOWS\system32\IPDETECT.EXE
2008-04-03 18:05 118,552 --a------ D:\WINDOWS\system32\drivers\adiusbaw.sys
2008-04-03 18:05 104,344 --a------ D:\WINDOWS\system32\drivers\e4usbaw.sys
2008-04-03 18:05 <DIR> d-------- D:\Program Files\SAGEM
2008-04-03 18:05 <DIR> d-------- D:\DOCUME~1\VANHEL~1\DANEAP~1\InstallShield
2008-04-02 09:47 <DIR> d-------- D:\Program Files\AutoConnect
2008-04-02 09:17 32,000 --a------ D:\WINDOWS\system32\drivers\stppp.sys
2008-04-02 09:17 30,464 --a------ D:\WINDOWS\system32\drivers\st330.sys
2008-04-02 09:17 16,128 --a------ D:\WINDOWS\system32\drivers\lpwdm.sys
2008-04-02 09:17 12,672 --a------ D:\WINDOWS\system32\drivers\stbus.sys
2008-03-16 19:40 <DIR> d-------- D:\Program Files\NeroInstall.bak
2008-03-16 19:36 <DIR> d-------- D:\Program Files\Common Files\Nero
2008-03-13 05:26 <DIR> d-------- D:\WINDOWS\Cache
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-04-12 19:01 --------- d-------- D:\Program Files\Mozilla Firefox 3 Beta 2
2008-04-12 18:10 84140 --ahs---- D:\WINDOWS\system32\drivers\fidbox.idx
2008-04-12 18:10 15524 --ahs---- D:\WINDOWS\system32\drivers\fidbox2.idx
2008-04-08 22:52 --------- d--h----- D:\Program Files\InstallShield Installation Information
2008-04-05 05:44 --------- d-------- D:\Program Files\Common Files\InstallShield
2008-04-03 18:06 33 --a------ D:\WINDOWS\system32\drivers\adidsl.cfg
2008-03-30 12:28 88946 --a------ D:\WINDOWS\system32\perfc015.dat
2008-03-30 12:28 500482 --a------ D:\WINDOWS\system32\perfh015.dat
2008-03-28 17:02 --------- d-------- D:\DOCUME~1\VANHEL~1\DANEAP~1\winamp
2008-03-20 10:09 1845504 --a------ D:\WINDOWS\system32\win32k.sys
2008-03-05 17:03 479752 --a------ D:\WINDOWS\system32\XAudio2_0.dll
2008-03-05 17:03 238088 --a------ D:\WINDOWS\system32\xactengine3_0.dll
2008-03-05 17:00 25608 --a------ D:\WINDOWS\system32\X3DAudio1_3.dll
2008-03-05 16:56 3786760 --a------ D:\WINDOWS\system32\D3DX9_37.dll
2008-03-05 16:56 1420824 --a------ D:\WINDOWS\system32\D3DCompiler_37.dll
2008-03-04 14:32 --------- d-------- D:\Program Files\Realtek
2008-03-01 19:02 --------- d-------- D:\DOCUME~1\VANHEL~1\DANEAP~1\Media Player Classic
2008-02-28 18:38 972072 --a------ D:\WINDOWS\UNNeroMediaHome.exe
2008-02-28 10:31 --------- d-------- D:\Program Files\AviSynth 2.5
2008-02-26 23:41 78083 --a------ D:\WINDOWS\BricoPackUninst.cmd
2008-02-26 23:41 3407 --a------ D:\WINDOWS\BricoPackFoldersDelete.cmd
2008-02-26 23:29 --------- d-------- D:\Program Files\Movie Maker
2008-02-26 22:29 2560 --a------ D:\WINDOWS\_MSRSTRT.EXE
2008-02-26 21:38 211 --ah----- D:\WINDOWS\winshell.dat
2008-02-26 17:14 972072 --a------ D:\WINDOWS\UNRecode.exe
2008-02-20 08:51 282624 --a------ D:\WINDOWS\system32\gdi32.dll
2008-02-20 07:38 45568 --a------ D:\WINDOWS\system32\dnsrslvr.dll
2008-02-18 21:18 3451 --a------ D:\WINDOWS\unins000.dat
2008-02-18 21:13 691545 --a------ D:\WINDOWS\unins000.exe
2008-02-18 17:21 132904 --a------ D:\WINDOWS\system32\drivers\imagesrv.sys
2008-02-18 17:21 11304 --a------ D:\WINDOWS\system32\drivers\imagedrv.sys
2008-02-18 17:04 95600 --a------ D:\WINDOWS\system32\NeroCo.dll
2008-02-17 15:28 306432 --a------ D:\WINDOWS\system32\TuneUpDefragService.exe
2008-02-17 15:28 --------- d-------- D:\DOCUME~1\VANHEL~1\DANEAP~1\TuneUp Software
2008-02-17 15:27 --------- d-------- D:\Program Files\Common Files\Wise Installation Wizard
2008-02-17 14:06 --------- d-------- D:\DOCUME~1\VANHEL~1\DANEAP~1\GlobalSCAPE
2008-02-14 18:04 4676096 --a------ D:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-02-13 15:31 16857600 --a------ D:\WINDOWS\RTHDCPL.exe
2008-02-08 18:37 219664 --a------ D:\WINDOWS\system32\klogon.dll
2008-02-06 00:07 462864 --a------ D:\WINDOWS\system32\d3dx10_37.dll
2008-01-30 10:30 4212 ---h----- D:\WINDOWS\system32\zllictbl.dat
2006-05-03 09:06:54 163,328 --sh--r D:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 --sh--r D:\WINDOWS\system32\msfDX.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 15:31 D:\WINDOWS\RTHDCPL.exe]
"AVP"="D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2008-02-08 18:36]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorXP"="C:\programy\cursor powre pack\CursorXP.exe" [2005-01-19 17:34]
"Zegarynka"="C:\programy\zegarynka\Zegarynka.exe" [2005-02-25 23:02]
"RocketDock"="C:\programy\brio pack\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-19 00:05]
"SkinClock"="C:\programy\clock\Atomic Alarm Clock\Atomic Alarm Clock\AtomicAlarmClock.exe" [2007-08-13 12:25]
D:\Documents and Settings\van Helsing\Menu Start\Programy\Autostart\
RocketDock.lnk - C:\programy\brio pack\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 00:05:02]
Stardock ObjectDock.lnk - C:\programy\ObjectDock\ObjectDock\ObjectDock.exe [2007-12-04 16:05:25]
UberIcon.lnk - C:\programy\brio pack\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 09:43:08]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\programy\windowblinds\WindowBlinds\wbsrv.dll 2008-02-26 23:50 229376 C:\programy\windowblinds\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=wbsys.dll,D:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DSLMON.lnk]
backup=D:\WINDOWS\pss\DSLMON.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^van Helsing^Menu Start^Programy^Autostart^AntiCrash.lnk]
backup=D:\WINDOWS\pss\AntiCrash.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^van Helsing^Menu Start^Programy^Autostart^TransBar.lnk]
backup=D:\WINDOWS\pss\TransBar.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^van Helsing^Menu Start^Programy^Autostart^Y'z Shadow.lnk]
backup=D:\WINDOWS\pss\Y'z Shadow.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
"C:\programy\nero 8\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
D:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Registry Accelerator]
"C:\programy\naprawa rejestru\Professional Registry Doctor\rc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkinClock]
C:\programy\clock\Atomic Alarm Clock\Atomic Alarm Clock\AtomicAlarmClock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPRepairPro2007]
C:\programy\XP Repair Pro 2007\XPRepairPro.exe /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aawservice"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Domino"=D:\WINDOWS\Domino.EXE
"VMSnap3"=D:\WINDOWS\VMSnap3.EXE
R0 viamraid;viamraid;D:\WINDOWS\system32\DRIVERS\viamraid.sys
R0 videX32;videX32;D:\WINDOWS\system32\DRIVERS\videX32.sys
R1 AmdPPM;Sterownik procesora AMD HwPState;D:\WINDOWS\system32\DRIVERS\AmdPPM.sys
R2 atksgt;atksgt;D:\WINDOWS\system32\DRIVERS\atksgt.sys
R2 EIO;EIO;\??\D:\WINDOWS\system32\drivers\EIO.sys
R2 lirsgt;lirsgt;D:\WINDOWS\system32\DRIVERS\lirsgt.sys
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\programy\nero 8\Nero\Nero8\Nero BackItUp\NBService.exe
R2 UxTuneUp;TuneUp Theme Extension;D:\WINDOWS\System32\svchost.exe -k netsvcs
R3 e4usbaw;USB ADSL2 WAN Adapter;D:\WINDOWS\system32\DRIVERS\e4usbaw.sys
R3 klim5;Kaspersky Anti-Virus NDIS Filter;D:\WINDOWS\system32\DRIVERS\klim5.sys
R3 vmfilter303;vmfilter303;D:\WINDOWS\system32\drivers\vmfilter303.sys
R3 ZSMC303;X-calibur USB PC Camera (Vimicro301 Neptune);D:\WINDOWS\system32\Drivers\usbVM303.sys
S1 AmdK8;Sterownik procesora AMD;D:\WINDOWS\system32\DRIVERS\AmdK8.sys
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);D:\WINDOWS\system32\Drivers\e4ldr.sys
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0;D:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
S3 idsvc;Windows CardSpace;"D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver;D:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
S3 ST330;ST330;D:\WINDOWS\system32\drivers\st330.sys
S3 STBUS;STBUS;D:\WINDOWS\system32\drivers\stbus.sys
S3 stppp;Speedtouch PPP Adapter Adapter;D:\WINDOWS\system32\DRIVERS\stppp.sys
S3 SymIM;Symantec Network Security Intermediate Filter Service;D:\WINDOWS\system32\DRIVERS\SymIM.sys
S3 SymIMMP;SymIMMP;D:\WINDOWS\system32\DRIVERS\SymIM.sys
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;D:\WINDOWS\System32\TuneUpDefragService.exe
S3 USB_RNDIS;Arris Remote NDIS Network Device Driver;D:\WINDOWS\system32\DRIVERS\usb8023.sys
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;"D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
Contents of the 'Scheduled Tasks' folder
2008-04-12 16:13:38 D:\WINDOWS\Tasks\GlaryInitialize.job - C:\programy\glary utilites\Glary Utilities\initialize.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-12 19:09:53
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c]
"Order"=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,..
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2008-04-12 19:11:59
D:\ComboFix-quarantined-files.txt ... 2008-04-12 19:11
--- E O F ---