Dziękuje za sprawdzenie loga hijack,a to log combofix
"sir Daniello" - 2007-07-23 16:13:59 - ComboFix 07-07-23.6 - Dodatek Service Pack 2 NTFS
((((((((((((((((((((((((( Files Created from 2007-06-23 to 2007-07-23 )))))))))))))))))))))))))))))))
2007-07-23 15:40 51,200 --a------ D:\WINDOWS\nircmd.exe
2007-07-23 13:56 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\DANEAP~1\NVIDIA
2007-07-23 13:51 208,896 --a------ D:\WINDOWS\system32\NVUNINST.EXE
2007-07-23 11:55 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\DANEAP~1\nView_Profiles
2007-07-23 10:05 208,896 --a------ D:\WINDOWS\system32\nvudisp.exe
2007-07-23 10:05 <DIR> d-------- D:\WINDOWS\nview
2007-07-18 09:14 4,027 --a------ D:\WINDOWS\BricoPackFoldersDelete.cmd
2007-07-17 20:03 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\DANEAP~1\Spybot - Search & Destroy
2007-07-17 17:34 4,212 ---h----- D:\WINDOWS\system32\zllictbl.dat
2007-07-17 17:34 11,264 --a------ D:\WINDOWS\system32\SpOrder.dll
2007-07-17 17:33 <DIR> d-------- D:\WINDOWS\Internet Logs
2007-07-17 13:18 299,520 --a------ D:\WINDOWS\uninst.exe
2007-07-17 13:18 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\WINDOWS
2007-07-17 09:33 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\Pulpit
2007-07-16 19:51 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\DANEAP~1\SopCast
2007-07-16 19:45 <DIR> d-------- D:\Program Files\Common Files\Real
2007-07-16 19:44 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\DANEAP~1\Real
2007-07-15 17:17 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\DANEAP~1\Desktop Sidebar
2007-07-13 20:03 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\DANEAP~1\Media Player Classic
2007-07-13 18:12 <DIR> d-------- D:\WINDOWS\system32\ZeroSpyware Limited Edition
2007-07-13 17:55 <DIR> d-------- D:\WINDOWS\system32\zslfiles
2007-07-13 17:44 <DIR> d-------- D:\Program Files\FBM Software
2007-07-12 17:21 159,744 --a------ D:\WINDOWS\system32\hasher.dll
2007-07-12 14:28 75,264 --a------ D:\WINDOWS\system32\unacev2.dll
2007-07-12 14:28 156,160 --a------ D:\WINDOWS\system32\unrar3.dll
2007-07-11 19:49 98,304 --a------ D:\WINDOWS\system32\msir3jp.dll
2007-07-11 19:49 9,216 --a------ D:\WINDOWS\system32\kbdnecAT.dll
2007-07-11 19:49 838,144 --a------ D:\WINDOWS\system32\chtbrkr.dll
2007-07-11 19:49 76,288 --a------ D:\WINDOWS\system32\uniime.dll
2007-07-11 19:49 70,656 --a------ D:\WINDOWS\system32\korwbrkr.dll
2007-07-11 19:49 7,680 --a------ D:\WINDOWS\system32\kbdnecNT.dll
2007-07-11 19:49 7,168 --a------ D:\WINDOWS\system32\kbdnec95.dll
2007-07-11 19:49 7,168 --a------ D:\WINDOWS\system32\kbdibm02.dll
2007-07-11 19:49 7,168 --a------ D:\WINDOWS\system32\f3ahvoas.dll
2007-07-11 19:49 6,656 --a------ D:\WINDOWS\system32\kbdlk41a.dll
2007-07-11 19:49 6,656 --a------ D:\WINDOWS\system32\c_is2022.dll
2007-07-11 19:49 6,144 --a------ D:\WINDOWS\system32\kbdlk41j.dll
2007-07-11 19:49 6,144 --a------ D:\WINDOWS\system32\kbdax2.dll
2007-07-11 19:49 6,144 --a------ D:\WINDOWS\system32\kbd106n.dll
2007-07-11 19:49 6,144 --a------ D:\WINDOWS\system32\kbd101a.dll
2007-07-11 19:49 6,144 --a------ D:\WINDOWS\system32\kbd101.dll
2007-07-11 19:49 218,112 --a------ D:\WINDOWS\system32\c_g18030.dll
2007-07-11 19:49 1,677,824 --a------ D:\WINDOWS\system32\chsbrkr.dll
2007-07-11 19:48 811,064 --a------ D:\WINDOWS\system32\imjp81k.dll
2007-07-11 19:48 8,704 --a------ D:\WINDOWS\system32\kbdjpn.dll
2007-07-11 19:48 8,192 --a------ D:\WINDOWS\system32\kbdkor.dll
2007-07-11 19:48 6,144 --a------ D:\WINDOWS\system32\kbd106.dll
2007-07-11 19:48 6,144 --a------ D:\WINDOWS\system32\kbd101c.dll
2007-07-11 19:48 6,144 --a------ D:\WINDOWS\system32\kbd101b.dll
2007-07-11 19:48 5,632 --a------ D:\WINDOWS\system32\kbd103.dll
2007-07-11 19:44 6,144 -ra------ D:\WINDOWS\system32\kbdth3.dll
2007-07-11 19:44 6,144 -ra------ D:\WINDOWS\system32\kbdth2.dll
2007-07-11 19:44 6,144 -ra------ D:\WINDOWS\system32\kbdinpun.dll
2007-07-11 19:44 6,144 --a------ D:\WINDOWS\system32\ftlx041e.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdvntc.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdurdu.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdth1.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdth0.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdsyr2.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdsyr1.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdintel.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdintam.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdinmar.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdinkan.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdinhin.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdinguj.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdindev.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdheb.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbdfa.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbddiv2.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbddiv1.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbda3.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbda2.dll
2007-07-11 19:44 5,632 -ra------ D:\WINDOWS\system32\kbda1.dll
2007-07-11 19:44 5,632 --a------ D:\WINDOWS\system32\kbdusa.dll
2007-07-11 19:44 5,120 -ra------ D:\WINDOWS\system32\kbdgeo.dll
2007-07-11 19:44 5,120 -ra------ D:\WINDOWS\system32\kbdarmw.dll
2007-07-11 19:44 5,120 -ra------ D:\WINDOWS\system32\kbdarme.dll
2007-07-11 19:44 185,344 --a------ D:\WINDOWS\system32\Thawbrkr.dll
2007-07-11 19:44 10,752 --a------ D:\WINDOWS\system32\c_iscii.dll
2007-07-11 19:35 <DIR> d-------- D:\WINDOWS\system32\NtmsData
2007-07-11 13:48 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\DANEAP~1\SUPERAntiSpyware.com
2007-07-11 13:43 <DIR> d-------- D:\Program Files\Common Files\Scanner
2007-07-11 13:43 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\DANEAP~1\CA
2007-07-11 13:37 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\DANEAP~1\SUPERAntiSpyware.com
2007-07-11 13:20 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\DANEAP~1\Lavasoft
2007-07-11 13:10 512,688 --a------ D:\WINDOWS\system32\XceedCry.dll
2007-07-11 13:10 423,784 --a------ D:\WINDOWS\system32\XceedBkp.dll
2007-07-11 13:10 101,888 --a------ D:\WINDOWS\system32\VB6STKIT.DLL
2007-07-10 20:11 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\DANEAP~1\Onet
2007-07-10 20:11 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\DANEAP~1\MozillaControl
2007-07-10 20:11 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\DANEAP~1\Listonosz
2007-07-10 20:11 <DIR> d-------- D:\DOCUME~1\SIRDAN~1\DANEAP~1\AutoUpdate
2007-07-10 08:12 63,488 --a------ D:\WINDOWS\system32\unam4ie.exe
2007-07-10 08:12 4,608 --a------ D:\WINDOWS\system32\w95inf32.dll
2007-07-10 08:12 38,160 --a------ D:\WINDOWS\system32\LMRTREND.dll
2007-07-10 08:12 221,184 --a------ D:\WINDOWS\system32\wmpns.dll
2007-07-10 08:12 2,272 --a------ D:\WINDOWS\system32\w95inf16.dll
2007-07-10 08:12 194,320 --a------ D:\WINDOWS\system32\qcut.dll
2007-07-10 08:12 182,032 --a------ D:\WINDOWS\system32\dxtmsft3.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-23 13:54:20 1,277 ----a-w D:\WINDOWS\mozver.dat
2007-07-22 18:44:42 219,648 ----a-w D:\WINDOWS\system32\uxtheme.dll
2007-07-18 07:16:51 -------- d-----w D:\Program Files\Movie Maker
2007-07-16 15:48:35 -------- d--h--w D:\Program Files\InstallShield Installation Information
2007-07-16 02:09:58 194 --sha-w D:\Program Files\desktop.ini
2007-07-12 11:14:02 6,632,448 ----a-w D:\WINDOWS\system32\logonuiX.exe
2007-07-11 03:00:55 87,188 ----a-w D:\WINDOWS\system32\perfc015.dat
2007-07-11 03:00:55 494,652 ----a-w D:\WINDOWS\system32\perfh015.dat
2007-07-02 10:16:14 -------- d-----w D:\Program Files\Windows NT
2007-06-23 19:28:58 163,644 ----a-w D:\WINDOWS\system32\drivers\secdrv.sys
2007-06-22 16:29:14 -------- d-----w D:\DOCUME~1\SIRDAN~1\DANEAP~1\Talkback
2007-06-20 07:13:32 -------- d-----w D:\DOCUME~1\SIRDAN~1\DANEAP~1\Gadu-Gadu
2007-06-20 04:46:23 -------- d-----w D:\Program Files\VID_0E8F&PID_0012
2007-06-20 04:41:38 -------- d-----w D:\Program Files\Common Files\Nero
2007-06-20 04:39:15 -------- d-----w D:\Program Files\Common Files\Ahead
2007-06-20 04:32:13 0 ----a-w D:\WINDOWS\nsreg.dat
2007-06-20 04:15:40 -------- d-----w D:\DOCUME~1\SIRDAN~1\DANEAP~1\ATI
2007-06-20 04:12:43 -------- d-----w D:\Program Files\Common Files\InstallShield
2007-06-20 04:01:50 -------- d-----w D:\Program Files\MSXML 6.0
2007-06-20 03:46:53 -------- d-----w D:\Program Files\MSBuild
2007-06-20 03:42:42 -------- d-----w D:\Program Files\Reference Assemblies
2007-06-20 03:41:16 -------- d-----w D:\Program Files\Windows Media Connect 2
2007-06-20 02:45:41 -------- d-----w D:\Program Files\Messenger
2007-06-19 22:28:54 -------- d-----w D:\Program Files\Common Files\ODBC
2007-06-19 22:28:51 -------- d-----w D:\Program Files\Common Files\SpeechEngines
2007-06-19 21:05:59 -------- d-----w D:\Program Files\Alwil Software
2007-06-19 20:53:44 -------- d-----w D:\Program Files\Realtek
2007-06-19 20:48:01 -------- d-----w D:\Program Files\DIFX
2007-06-19 20:40:18 -------- d-----w D:\Program Files\microsoft frontpage
2007-06-19 20:38:50 -------- d--h--w D:\Program Files\WindowsUpdate
2007-06-19 20:38:47 -------- d-----w D:\Program Files\Usługi online
2007-06-19 20:37:59 -------- d-----w D:\Program Files\Common Files\MSSoap
2007-06-19 20:37:22 21,856 ----a-w D:\WINDOWS\system32\emptyregdb.dat
2007-06-19 20:36:32 -------- d-----w D:\Program Files\MSN Gaming Zone
2007-05-18 01:57:53 268,288 ----a-w D:\WINDOWS\system32\ati2dvag.dll
2007-05-18 01:41:03 2,922,144 ----a-w D:\WINDOWS\system32\ati3duag.dll
2007-05-18 01:30:58 1,512,960 ----a-w D:\WINDOWS\system32\ativvaxx.dll
2007-05-18 01:10:21 368,640 ----a-w D:\WINDOWS\system32\ati2cqag.dll
2007-05-16 15:18:58 683,520 ----a-w D:\WINDOWS\system32\inetcomm.dll
2007-04-30 15:46:10 745,600 ----a-w D:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:35:28 95,872 ----a-w D:\WINDOWS\system32\AvastSS.scr
2007-04-25 14:23:30 144,896 ----a-w D:\WINDOWS\system32\schannel.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-01 20:10 D:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 19:04 D:\WINDOWS\SkyTel.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 19:43 D:\WINDOWS\Alcmtr.exe]
"avast!"="D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
"DAEMON Tools-1033"="C:\programy\daemon\daemon.exe" [2004-08-22 17:05]
"LogonStudio"="C:\programy\LogonStudio\logonstudio.exe" [2002-09-03 18:38]
"QuickTime Task"="C:\programy\Quiktim\qttask.exe" [2007-04-27 09:41]
"WinampAgent"="C:\programy\winamp\winampa.exe" [2007-05-15 00:22]
"BootSkin Startup Jobs"="C:\programy\BootSkin\BootSkin.exe" [2004-04-26 16:21]
"nwiz"="nwiz.exe" [2007-04-19 13:26 D:\WINDOWS\system32\nwiz.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\programy\crystal XP\Crystal Clear\RocketDock\RocketDock.exe" [2006-05-14 22:47]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00]
"SkinClock"="C:\programy\clock\Clock Tray Skins\ClockTraySkins.exe" [2006-10-14 14:35]
"UberIcon"="C:\programy\crystal XP\Crystal Clear\UberIcon\UberIcon Manager.exe" [2006-02-05 14:20]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"MRUBlaster"=C:\programy\MRUblaster\MRU-Blaster\indexcleaner.exe -CC
D:\Documents and Settings\sir Daniello\Menu Start\Programy\Autostart\
PopTray.lnk - C:\programy\POP3 tray\PopTray.exe [2006-09-16 15:01:16]
RocketDock.lnk - C:\programy\crystal XP\Crystal Clear\RocketDock\RocketDock.exe [2006-05-14 22:47:48]
Stardock ObjectDock.lnk - C:\programy\ObjectDock\ObjectDock.exe [2007-07-04 18:15:32]
UberIcon.lnk - C:\programy\crystal XP\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-02-05 14:20:14]
Y'z Shadow.lnk - C:\programy\crystal XP\Crystal Clear\YzShadow\YzShadow.exe [2002-09-30 21:09:06]
Y'z Toolbar.lnk - C:\programy\crystal XP\Crystal Clear\YzToolbar\YzToolBar.exe [2002-09-29 14:41:10]
D:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
WinZip Quick Pick.lnk - C:\programy\winzip\WZQKPICK.EXE [2007-07-15 14:39:23]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x);D:\WINDOWS\system32\drivers\sfsync02.sys
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x);D:\WINDOWS\system32\drivers\sfvfs02.sys
R1 AmdK8;Sterownik procesora AMD;D:\WINDOWS\system32\DRIVERS\AmdK8.sys
R2 FileDeleter;ZeroSpyware FileDeleter;C:\programy\zero spyware\FileDeleter.exe
R3 netrcacm;RCA USB Digital Cable Modem Driver;D:\WINDOWS\system32\DRIVERS\netrcacm.sys
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0;D:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
S3 idsvc;Windows CardSpace;"D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;"D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-23 16:14:43
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c]
"Order"=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,..
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-23 16:15:32
--- E O F ---