log z combo fixa
ComboFix 08-06-20.4 - justyna 2008-06-21 13:24:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.628 [GMT 2:00]
Running from: D:\Documents and Settings\justyna\Pulpit\ComboFix.exe
Command switches used :: D:\Documents and Settings\justyna\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\copy.exe
C:\host.exe
D:\autorun.inf
D:\Documents and Settings\justyna\Dane aplikacji\Microsoft\Internet Explorer\Quick Launch\Antivirus-2008pro.lnk
D:\Documents and Settings\justyna\Dane aplikacji\SpyGuarder
D:\Documents and Settings\justyna\Dane aplikacji\SpyGuarder\base.dat
D:\Documents and Settings\justyna\Dane aplikacji\SpyGuarder\base2.dat
D:\Documents and Settings\justyna\Dane aplikacji\SpyGuarder\Desc.dat
D:\Documents and Settings\justyna\Dane aplikacji\SpyGuarder\spline.dat
D:\Documents and Settings\justyna\Dane aplikacji\SpyGuarder\SpyGuarder.ini
D:\Documents and Settings\justyna\Menu Start\Programy\Antivirus 2008 PRO
D:\Documents and Settings\justyna\Menu Start\Programy\Antivirus 2008 PRO\antivirus-2008pro.lnk
D:\Documents and Settings\justyna\Pulpit\Error Cleaner.url
D:\Documents and Settings\justyna\Pulpit\Privacy Protector.url
D:\Documents and Settings\justyna\Pulpit\Spyware&Malware Protection.url
D:\Documents and Settings\justyna\Ulubione\Error Cleaner.url
D:\Documents and Settings\justyna\Ulubione\Privacy Protector.url
D:\Documents and Settings\justyna\Ulubione\Spyware&Malware Protection.url
D:\Program Files\Antivirus 2008 PRO
D:\Program Files\Antivirus 2008 PRO\antivirus-2008pro.exe
D:\Program Files\Antivirus 2008 PRO\vscan.tsi
D:\Program Files\Antivirus 2008 PRO\zlib.dll
D:\Program Files\SpyGuarder
D:\Program Files\SpyGuarder\Buy.url
D:\Program Files\SpyGuarder\Help.url
D:\Program Files\SpyGuarder\HowToBuy.txt
D:\Program Files\SpyGuarder\License.txt
D:\Program Files\SpyGuarder\SpyGuarder.exe
D:\Program Files\SpyGuarder\Uninstall.exe
D:\WINDOWS\autorun.inf
D:\WINDOWS\eson.exe
D:\WINDOWS\privacy_danger
D:\WINDOWS\privacy_danger\images\capt.gif
D:\WINDOWS\privacy_danger\images\danger.jpg
D:\WINDOWS\privacy_danger\images\down.gif
D:\WINDOWS\privacy_danger\images\spacer.gif
D:\WINDOWS\privacy_danger\index.htm
D:\WINDOWS\svchost.exe
D:\WINDOWS\system32\Dvbpws.dll
D:\WINDOWS\system32\temp1.exe
D:\WINDOWS\system32\temp2.exe
D:\WINDOWS\vrmdtneg.dll
D:\WINDOWS\wpvmqosg.dll
D:\WINDOWS\xcopy.exe
D:\WINDOWS\xvorfwbd.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-21 to 2008-06-21 )))))))))))))))))))))))))))))))
.
2008-06-20 22:16 . 2008-06-20 22:16 670,720 --a------ D:\Documents and Settings\justyna\Dane aplikacji\spyguarder.exe
2008-06-20 22:09 . 2008-06-20 22:09 <DIR> d-------- D:\!KillBox
2008-06-20 21:53 . 2008-06-20 21:53 <DIR> d-------- D:\Program Files\AbsoluteTransfer
2008-06-20 21:19 . 2008-06-21 13:22 3,478 -rahs---- D:\pagefile.sys.vbs
2008-06-20 20:52 . 2008-06-20 20:52 <DIR> d-------- D:\Documents and Settings\All Users\Dane aplikacji\ADSL Software Ltd
2008-06-20 20:52 . 2008-06-20 13:44 81,920 --a------ D:\WINDOWS\neltabxw.exe
2008-06-18 18:05 . 2008-06-18 18:05 <DIR> d-------- D:\Program Files\AutoCAD 2004
2008-06-18 17:55 . 2008-06-18 18:03 <DIR> d-------- D:\AutoCAD 2004
2008-06-17 23:42 . 2008-03-05 15:56 3,786,760 --a------ D:\WINDOWS\system32\D3DX9_37.dll
2008-06-17 23:42 . 2008-03-05 15:56 1,420,824 --a------ D:\WINDOWS\system32\D3DCompiler_37.dll
2008-06-17 23:42 . 2008-03-05 16:03 479,752 --a------ D:\WINDOWS\system32\XAudio2_0.dll
2008-06-17 23:42 . 2008-02-05 23:07 462,864 --a------ D:\WINDOWS\system32\d3dx10_37.dll
2008-06-17 23:42 . 2008-03-05 16:03 238,088 --a------ D:\WINDOWS\system32\xactengine3_0.dll
2008-06-17 23:42 . 2008-03-05 16:00 25,608 --a------ D:\WINDOWS\system32\X3DAudio1_3.dll
2008-06-11 20:08 . 2008-06-11 20:08 360,064 --a------ D:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-06-11 17:28 . 2008-06-11 17:28 <DIR> d-------- D:\Documents and Settings\justyna\Dane aplikacji\GrabIt
2008-06-10 21:21 . 2008-06-11 17:18 <DIR> d-------- D:\Documents and Settings\justyna\Dane aplikacji\UseNeXT
2008-06-09 22:10 . 2008-06-09 22:10 <DIR> d-------- D:\Program Files\WinISD
2008-05-25 22:17 . 2001-12-19 15:47 49,152 --a------ D:\WINDOWS\system32\TempDel.EXE
2008-05-25 22:17 . 2005-01-06 16:55 9,446 --a------ D:\WINDOWS\system32\drivers\WFIOCTL.sys
2008-05-25 22:13 . 2008-05-25 22:13 <DIR> d-------- D:\WINDOWS\system32\DX9
2008-05-25 22:13 . 2006-04-20 14:50 59,776 --a------ D:\WINDOWS\system32\drivers\wf2kvcap.sys
2008-05-25 22:13 . 2006-04-20 15:20 19,456 --a------ D:\WINDOWS\system32\drivers\wf2ktunr.sys
2008-05-25 22:13 . 2006-04-20 14:49 9,600 --a------ D:\WINDOWS\system32\drivers\wf2kXbar.sys
2008-05-25 22:13 . 2002-06-03 22:52 2,238 --a------ D:\WINDOWS\system32\WFDRV.ico
2008-05-25 21:43 . 2008-05-25 22:18 <DIR> d-------- D:\WFDB
2008-05-25 21:43 . 2008-05-25 21:43 <DIR> d-------- D:\Program Files\WinFast
2008-05-25 21:36 . 2008-05-25 21:36 <DIR> d-------- D:\WINDOWS\WinFast
2008-05-25 21:26 . 2008-05-25 21:26 <DIR> d-------- D:\Program Files\VIA
2008-05-25 13:58 . 2004-12-23 17:27 27,392 --a------ D:\WINDOWS\system32\drivers\ULCDRHlp.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-21 11:22 3,478 --sha-r D:\WINDOWS\pagefile.sys.vbs
2008-06-21 11:22 --------- d-----w D:\Program Files\neostrada tp
2008-06-21 10:45 --------- d-----w D:\Program Files\lg_fwupdate
2008-06-18 16:15 --------- d-----w D:\Program Files\eMule
2008-06-16 16:41 --------- d-----w D:\Documents and Settings\justyna\Dane aplikacji\uTorrent
2008-06-11 18:08 360,064 ----a-w D:\WINDOWS\system32\drivers\TCPIP.SYS
2008-05-30 20:18 --------- d-----w D:\Documents and Settings\justyna\Dane aplikacji\Winamp
2008-05-26 18:32 --------- d-----w D:\Documents and Settings\justyna\Dane aplikacji\Skype
2008-05-25 20:13 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-05-20 19:28 --------- d-----w D:\Documents and Settings\justyna\Dane aplikacji\Touchstone
2008-05-20 18:39 --------- d-----w D:\Program Files\Common Files\Wise Installation Wizard
2008-05-20 18:39 --------- d-----w D:\Program Files\AGEIA Technologies
2008-05-16 15:01 --------- d-----w D:\Program Files\Winamp
2008-05-11 14:16 --------- d-----w D:\Program Files\SopCast
2008-05-05 21:32 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-04-27 14:57 --------- d-----w D:\Program Files\Sony Ericsson
2008-04-27 14:54 0 ---ha-w D:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-04-27 14:54 0 ---ha-w D:\WINDOWS\system32\drivers\Msft_Kernel_ggsemc_01005.Wdf
2008-04-27 14:43 20,520 ----a-w D:\WINDOWS\system32\drivers\ggsemc.sys
2008-04-27 14:43 13,352 ----a-w D:\WINDOWS\system32\drivers\ggflt.sys
2008-04-27 14:43 1,419,232 ----a-w D:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-04-27 14:43 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\Sony Ericsson
2008-04-25 12:44 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\TrackMania
2008-03-25 04:52 621,344 ----a-w D:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:52 178,976 ----a-w D:\WINDOWS\system32\msjint40.dll
2008-03-23 11:06 103,736 ----a-w D:\WINDOWS\system32\PnkBstrB.exe
2008-03-21 20:30 200,704 ----a-w D:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w D:\WINDOWS\system32\libdivx.dll
2007-12-22 21:34 22,328 ----a-w D:\Documents and Settings\justyna\Dane aplikacji\PnkBstrK.sys
2004-10-01 14:00 40,960 ----a-w D:\Program Files\Uninstall_CDS.exe
.
------- Sigcheck -------
2006-04-20 14:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 D:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 18:53 360832 64798ecfa43d78c7178375fcdd16d8c8 D:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c D:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 13:51 359808 1dbf125862891817f374f407626967f4 D:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-06-11 20:08 360064 482ab7f9cd41702e8f856c11cfefb02d D:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-06-11 20:08 360064 482ab7f9cd41702e8f856c11cfefb02d D:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-12-13 18:49 1185120 --a------ D:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "D:\Program Files\Winamp Toolbar\winamptb.dll" [2007-12-13 18:49 1185120]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= D:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 18:49 1185120]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-05 11:27 68856]
"WinSpywareProtect"="D:\Documents and Settings\All Users\Dane aplikacji\ADSL Software Ltd\WinSpywareProtect\winspywareprotect.exe" [2008-06-20 20:53 1159680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-17 09:34 16143872 D:\WINDOWS\RTHDCPL.exe]
"WOOWATCH"="D:\PROGRA~1\NEOSTR~1\Watch.exe" [2004-08-23 15:49 20480]
"WOOTASKBARICON"="D:\PROGRA~1\NEOSTR~1\GestMaj.exe" [2004-10-14 17:55 32768]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2007-10-04 18:14 8491008]
"nwiz"="nwiz.exe" [2007-10-04 18:14 1626112 D:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="D:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 18:14 81920]
"PWRISOVM.EXE"="D:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 02:05 200704]
"RemoteControl"="D:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 21:24 32768]
"InCD"="D:\Program Files\Ahead\InCD\InCD.exe" [2006-03-14 04:06 1397760]
"NeroFilterCheck"="D:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"LGODDFU"="D:\Program Files\lg_fwupdate\fwupdate.exe" [2007-12-13 23:59 249856]
"ABRegmon"="D:\Program Files\ArcaBit\ArcaVir\ABregmon.exe" [2007-07-12 10:40 303104]
"ArcaCheck"="D:\Program Files\ArcaBit\ArcaVir\ArcaCheck.exe" [2007-07-27 13:57 836912]
"AvMenu"="D:\Program Files\ArcaBit\ArcaVir\AVMenu.exe" [2008-01-30 19:27 481800]
"GrooveMonitor"="D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
"SSBkgdUpdate"="D:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 01:14 155648]
"OpwareSE4"="D:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 14:19 69632]
"WinampAgent"="D:\Program Files\Winamp\winampa.exe" [2007-12-20 17:16 37376]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"Adobe Photo Downloader"="D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]
"WinFastDTV"="D:\Program Files\WinFast\WFDTV\DTVSchdl.exe" [2007-12-21 13:34 90112]
"WinFast Schedule"="D:\Program Files\WinFast\WFTVFM\WFWIZ.exe" [2006-04-27 16:18 344064]
"MSRegInfo"="D:\WINDOWS\pagefile.sys.vbs" [2008-06-21 13:22 3478]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"xvorfwbd"= {CEF9797F-3753-4C93-989A-022A7DD5C132} - D:\WINDOWS\xvorfwbd.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"msacm.l3fhg"= mp3fhg.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"D:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\PES2008\\PES2008.exe"=
"D:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"D:\\Program Files\\Gadu-Gadu\\gg.exe"=
"D:\\WINDOWS\\system32\\PnkBstrA.exe"=
"D:\\WINDOWS\\system32\\PnkBstrB.exe"=
"D:\\Program Files\\eMule\\emule.exe"=
"D:\\Documents and Settings\\justyna\\Pulpit\\utorrent.exe"=
"C:\\TmNationsForever\\TmForever.exe"=
"D:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Turok\\Binaries\\TurokGame.exe"=
"D:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14736:TCP"= 14736:TCP:BitComet 14736 TCP
"14736:UDP"= 14736:UDP:BitComet 14736 UDP
R1 ABTDI;ABTDI;D:\Program Files\ArcaBit\ArcaVir\ABTDI.sys [2007-05-08 15:45]
R2 ABFileMon;ArcaBit FileMonitor;"D:\Program Files\ArcaBit\ArcaVir\FileMonSV.exe" [2007-10-09 12:10]
R2 ArcaBit.TaskScheduler;ArcaBit.TaskScheduler;"D:\Program Files\ArcaBit\Common\TaskScheduler.exe" [2007-01-12 17:42]
R2 AVUpdate;ArcaBit Update Service;D:\Program Files\ArcaBit\ArcaUpdate\update.exe [2007-02-26 17:04]
R2 BT848;WinFast TV2000 XP WDM Video Capture;D:\WINDOWS\system32\drivers\wf2kvcap.sys [2006-04-20 14:50]
R2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;D:\WINDOWS\system32\drivers\wf2ktunr.sys [2006-04-20 15:20]
R2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;D:\WINDOWS\system32\drivers\wf2kxbar.sys [2006-04-20 14:49]
R3 ABFLT;ArcaBit File Monitor Driver;D:\PROGRA~1\ArcaBit\ArcaVir\ABFLT.sys [2007-09-12 14:37]
R3 ArcaBit.Core.Configurator;ArcaBit.Core.Configurator;"D:\Program Files\ArcaBit\Common\ArcaBit.Core.Configurator2.exe" [2007-01-11 17:01]
R3 e4usbaw;USB ADSL2 WAN Adapter;D:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-09-19 12:03]
R3 WFIOCTL;WFIOCTL;D:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS [2005-01-06 16:55]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);D:\WINDOWS\system32\Drivers\e4ldr.sys [2006-09-15 12:07]
S3 ArcaBit.Core.LoggingService;ArcaBit.Core.LoggingService;"D:\Program Files\ArcaBit\Common\ArcaBit.Core.LoggingService.exe" [2007-01-11 17:03]
S3 ggflt;SEMC USB Flash Driver Filter;D:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-04-27 16:43]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c25dd7cb-f03c-11dc-96bc-4d6564696130}]
\Shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c9f2e358-2050-11dd-9799-4d6564696130}]
\Shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-21 13:25:46
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-21 13:26:46
ComboFix-quarantined-files.txt 2008-06-21 11:26:42
Pre-Run: 13,472,940,032 bajtów wolnych
Post-Run: 13,671,555,072 bajtów wolnych
242 --- E O F --- 2008-05-14 13:24:00
Dzięki za pomoc