log z combo fix'a
ComboFix 08-12-11.05 - Druss 2008-12-12 14:53:31.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.108 [GMT 1:00]
Running from: c:\documents and settings\Druss\Pulpit\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\hlvdd.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-12 to 2008-12-12 )))))))))))))))))))))))))))))))
.
2008-12-12 12:48 . 2008-12-12 12:48 <DIR> d-------- c:\program files\ALWIL Software
2008-12-12 12:48 . 2001-08-31 09:13 130,048 --------- c:\windows\system32\vic32.dll
2008-12-12 12:48 . 2002-10-02 11:36 42,560 --a------ c:\windows\system32\drivers\avmon.sys
2008-12-12 12:48 . 2002-10-02 11:38 40,192 --a------ c:\windows\system32\drivers\avmon2.sys
2008-12-12 12:48 . 2002-10-02 11:54 32,768 --a------ c:\windows\system32\avss30.scr
2008-12-12 12:48 . 2002-10-02 11:34 16,560 --a------ c:\windows\system32\drivers\aavmker.sys
2008-12-12 12:47 . 2008-12-12 12:47 2,491 --a------ c:\windows\Avast32.MIF
2008-12-12 12:46 . 2008-12-12 12:46 <DIR> d-------- C:\CHIP
2008-12-12 12:45 . 2008-12-12 12:49 208 --a------ c:\windows\VOGEL.INI
2008-12-01 21:01 . 2008-12-01 21:01 <DIR> d-------- c:\program files\Avanquest update
2008-12-01 20:58 . 2008-12-01 21:00 <DIR> d-------- c:\program files\Motorola Phone Tools
2008-11-26 14:22 . 2008-11-26 15:10 <DIR> d-------- c:\documents and settings\Druss\Dane aplikacji\U3
2008-11-12 18:05 . 2005-07-28 08:18 685,056 --a------ c:\windows\system32\drivers\hardlock.sys
2008-11-12 18:05 . 2008-12-12 12:51 0 --a------ c:\windows\TempFile
2008-11-12 17:27 . 2006-02-02 07:42 468,084 --a------ c:\windows\cluninst.exe
2008-11-12 17:26 . 2006-08-25 01:35 4,096 --a------ c:\windows\system\LEXHDL5.DLL
2008-11-12 17:25 . 2008-11-12 17:26 <DIR> d-------- C:\etka
2008-11-12 17:25 . 2008-11-12 17:40 98 --a------ c:\windows\etkinst.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-10 20:22 --------- d-----w c:\program files\eMule
2008-12-01 20:01 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-01 19:58 92,064 ----a-w c:\documents and settings\Druss\mqdmmdm.sys
2008-12-01 19:58 9,232 ----a-w c:\documents and settings\Druss\mqdmmdfl.sys
2008-12-01 19:58 79,328 ----a-w c:\documents and settings\Druss\mqdmserd.sys
2008-12-01 19:58 66,656 ----a-w c:\documents and settings\Druss\mqdmbus.sys
2008-12-01 19:58 6,208 ----a-w c:\documents and settings\Druss\mqdmcmnt.sys
2008-12-01 19:58 5,936 ----a-w c:\documents and settings\Druss\mqdmwhnt.sys
2008-12-01 19:58 4,048 ----a-w c:\documents and settings\Druss\mqdmcr.sys
2008-12-01 19:58 25,600 ----a-w c:\windows\system32\drivers\usbsermptxp.sys
2008-12-01 19:58 25,600 ----a-w c:\documents and settings\Druss\usbsermptxp.sys
2008-12-01 19:58 22,768 ----a-w c:\documents and settings\Druss\usbsermpt.sys
2008-11-11 11:38 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\FLEXnet
2008-11-11 11:18 --------- d-----w c:\program files\Common Files\Adobe
2008-11-11 11:14 --------- d-----w c:\program files\Bonjour
2008-11-11 10:45 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-11-11 00:37 --------- d-----w c:\program files\Nokia
2008-11-10 14:08 --------- d-----w c:\documents and settings\Druss\Dane aplikacji\Nokia Multimedia Player
2008-11-10 14:08 --------- d-----w c:\documents and settings\Druss\Dane aplikacji\Nokia
2008-11-10 13:44 --------- d-----w c:\program files\Common Files\PCSuite
2008-11-10 13:44 --------- d-----w c:\program files\Common Files\Nokia
2008-11-10 13:43 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Downloaded Installations
2008-11-10 13:39 --------- d-----w c:\program files\PC Connectivity Solution
2008-11-10 13:39 --------- d-----w c:\program files\DIFX
2008-11-10 13:32 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Installations
2007-11-21 21:20 32 ----a-w c:\documents and settings\All Users\Dane aplikacji\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2007-04-17 2113536]
"EVEREST AutoStart"="c:\everest\everest.exe" [2007-10-17 2043488]
"Creative MediaSource Go"="c:\program files\Creative\MediaSource5\Go\CTCMSGoU.exe" [2006-11-09 204800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-03-31 950664]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2005-12-14 176128]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-02-22 32768]
"PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2007-04-08 721656]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"USB Storage Toolbox"="c:\program files\USB Disk Win98 Driver\Res.EXE" [2005-09-14 65536]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AvMaiSrv"="c:\progra~1\ALWILS~1\AVAST32\AvMaiSrv.exe" [2002-10-02 172032]
"Avast32"="c:\progra~1\ALWILS~1\AVAST32\ASTART32.EXE" [2002-10-02 32768]
"ATIPTA"="atiptaxx.exe" [2006-02-22 c:\windows\system32\atiptaxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-02-22 32768]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
ATI CATALYST System Tray.lnk - c:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-02-22 32768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
--a------ 2005-02-22 21:21 32768 c:\program files\ATI Technologies\ATI.ACE\CLI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-03 23:44 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2005-11-08 23:00 128920 c:\program files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--------- 2006-03-23 17:06 1398272 c:\program files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2004-06-16 06:03 221184 c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2004-06-16 06:03 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 17:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
--------- 2005-02-10 16:00 1937408 c:\program files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--------- 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--------- 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2007-06-18 15:10 271360 c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
--a------ 2007-06-19 10:17 1241088 c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 00:00 90112 c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-04-01 19:49 36352 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
-ra------ 2005-05-03 12:38 64512 c:\windows\system32\P17.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Atari\\Test Drive Unlimited\\TestDriveUnlimited.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\NAPI-PROJEKT\\napisy.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\ALWIL Software\\AVAST32\\avserver.exe"=
"c:\\Program Files\\ALWIL Software\\AVAST32\\quick32.exe"=
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [2005-12-06 35328]
R1 Aavmker;Avast32 Asynchronous Virus Monitor;c:\windows\system32\drivers\Aavmker.sys [2008-12-12 16560]
R1 atitray;atitray;\??\c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [2008-02-11 17952]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2007-03-31 15424]
R2 AvMon2;Avast32 Standard Shield Support;c:\windows\system32\drivers\AvMon2.sys [2008-12-12 40192]
R2 PStrip;PStrip;c:\windows\system32\drivers\pstrip.sys [2006-09-30 27936]
R3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\DRIVERS\Amps2prt.sys [2005-12-08 12800]
R3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\DRIVERS\e4usbaw.sys [2006-12-23 116992]
R3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\everest\kerneld.wnt [2008-02-12 22640]
S1 SpyEmrg;Spy Emergency Driver;c:\windows\system32\Drivers\spyemrg.sys []
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\Drivers\e4ldr.sys [2006-12-23 64000]
S3 Avast32 Start as Service;Avast32 Start as Service;c:\program files\ALWIL Software\AVAST32\avserver.exe /ServiceStart [2008-12-12 245760]
S3 iteio;iteio;\??\c:\windows\system32\drivers\iteio.sys [2006-10-04 3680]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
*Newly Created Service* - AAVMKER
*Newly Created Service* - AVMON2
*Newly Created Service* - AVUPDSVC
*Newly Created Service* - EVERESTDRIVER
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DDDFC9C8-A0F8-E0CF-AF00-F0F423E36752}]
c:\windows\system32\svchast.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-StartCCC - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
MSConfigStartUp-avast! - c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
MSConfigStartUp-AVFX Engine - c:\program files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
MSConfigStartUp-BearShare - c:\program files\BearShare\BearShare.exe
MSConfigStartUp-SpyEmergency - c:\program files\Spy Emergency 2005\SpyEmergency.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_02\bin\jusched.exe
MSConfigStartUp-SoundMan - SOUNDMAN.EXE
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.pl/mStart Page = about:blank
IE: Download all links using BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Download all videos using BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: Download link using &BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
LSP: c:\windows\system32\imon.dll
TCP: {CE9B9E42-11FF-4744-B896-8EF7691691D8} = 194.204.159.1 217.98.63.164
O16 -: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\system32\SkanerOnlineUninstall.exe - c:\windows\system32\SkanerOnline.dll
O16 -: {68282C51-9459-467B-95BF-3C0E89627E55}
hxxp://www.mks.com.pl/skaner/SkanerOnline.cabc:\windows\Downloaded Program Files\SkanerOnline.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-12 14:59:04
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Creative Detector = "c:\program files\Creative\MediaSource\Detector\CTDetect.exe" /R???w0??w????*??w???w????O??w:???m????? ?????????????L???L??????????wO??w:???m????? ?????????????k!?sO??w:???m????? ?????L??????????sm????? ?????m???????$??????sm????? ?????????????rl?w?? ?N??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\everest\kerneld.wnt"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(692)
c:\windows\system32\imon.dll
.
Completion time: 2008-12-12 15:03:05
ComboFix-quarantined-files.txt 2008-12-12 14:02:01
Pre-Run: 8˙159˙150˙080 bajt˘w wolnych
Post-Run: 8,707,821,568 bajt˘w wolnych
209