
jestem tu nowy i prosze o wybaczenie ewentualnuch bledow:P ostatnio ktos przyslal mi przez komunikator plik o rozszerzeniu exe nie pamietam jaki ale chwile pozniej wyswietlila mi sie ikonka obok zegarka "RelevantKnowledge". Od razu troche poszperalem w necie i usunalem troche syfu, ale nie znam sie aż tak wiec chcialbym by ktos przegladnal log z combofix-a
- Kod: Zaznacz wszystko
ComboFix 08-11-20.02 - mat 2008-11-21 19:33:08.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.498 [GMT 1:00]
Uruchomiony z: c:\documents and settings\mat\Pulpit\ComboFix.exe
[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.
((((((((((((((((((((((((( Pliki utworzone od 2008-10-21 do 2008-11-21 )))))))))))))))))))))))))))))))
.
2008-11-21 18:45 . 2008-11-21 18:45 <DIR> d-------- c:\program files\Enigma Software Group
2008-11-21 18:28 . 2008-11-21 18:28 <DIR> d-------- c:\windows\LastGood
2008-11-20 17:26 . 2008-11-20 17:26 38 --a------ c:\windows\AviSplitter.INI
2008-11-18 23:40 . 2008-11-18 23:40 <DIR> d-------- c:\documents and settings\mat\Dane aplikacji\OpenOffice.org
2008-11-18 23:39 . 2008-11-18 23:39 <DIR> d-------- c:\program files\OpenOffice.org 3
2008-11-12 23:45 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 23:03 . 2008-09-04 18:17 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-10 13:19 . 2008-11-10 18:54 <DIR> d-------- c:\program files\NAPI-PROJEKT
2008-11-09 13:56 . 2005-06-13 10:05 96,224 --a------ c:\windows\system32\drivers\w800mdm.sys
2008-11-09 13:56 . 2005-06-13 10:06 87,792 --a------ c:\windows\system32\drivers\w800mgmt.sys
2008-11-09 13:56 . 2005-06-13 10:08 85,664 --a------ c:\windows\system32\drivers\w800obex.sys
2008-11-09 13:56 . 2005-06-13 10:03 60,768 --a------ c:\windows\system32\drivers\w800bus.sys
2008-11-09 13:56 . 2005-06-13 10:05 9,264 --a------ c:\windows\system32\drivers\w800mdfl.sys
2008-11-09 13:56 . 2005-06-13 10:08 6,144 --a------ c:\windows\system32\drivers\w800cmnt.sys
2008-11-09 13:56 . 2005-06-13 10:08 6,144 --a------ c:\windows\system32\drivers\w800cm.sys
2008-11-09 13:56 . 2005-06-13 10:03 5,744 --a------ c:\windows\system32\drivers\w800whnt.sys
2008-11-09 13:56 . 2005-06-13 10:03 5,744 --a------ c:\windows\system32\drivers\w800wh.sys
2008-11-09 13:53 . 2008-11-09 13:53 <DIR> d-------- c:\program files\Sony Ericsson
2008-11-03 13:35 . 2008-11-11 23:38 <DIR> d-------- c:\documents and settings\mat\Dane aplikacji\GanymedeNet
2008-10-28 14:31 . 2008-11-21 14:26 <DIR> d-------- c:\documents and settings\mat\Dane aplikacji\skypePM
2008-10-28 14:31 . 2008-10-28 14:31 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-10-28 14:30 . 2008-11-21 18:14 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Skype
2008-10-27 21:38 . 2008-11-21 00:15 <DIR> d-------- c:\program files\SkanerOnline
2008-10-27 16:59 . 2008-10-27 16:59 23,575 --a------ c:\windows\Microsoft Outlook.FAV
2008-10-27 16:58 . 2008-10-27 17:00 212,992 --a------ c:\windows\outlook.pst
2008-10-27 16:58 . 2008-10-27 16:58 8,790 --a------ c:\windows\extend.dat
2008-10-26 14:35 . 2008-10-26 14:40 <DIR> d-------- c:\program files\Genesys PC Camera Device
2008-10-26 14:35 . 2006-05-18 17:58 309,760 --a------ c:\windows\system32\DIFxAPI.dll
2008-10-26 14:34 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-23 17:06 . 2008-11-10 20:42 <DIR> d-------- c:\documents and settings\mat\Dane aplikacji\Winamp
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-21 18:23 --------- d-----w c:\documents and settings\mat\Dane aplikacji\MegauploadToolbar
2008-10-27 20:48 --------- d-----w c:\documents and settings\mat\Dane aplikacji\Cyberlink
2008-10-26 13:35 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-21 21:31 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Megaupload
2008-10-19 21:51 --------- d-----w c:\documents and settings\mat\Dane aplikacji\MyPhoneExplorer
2008-10-19 15:58 --------- d-----w c:\program files\Common Files\Ahead
2008-10-16 14:42 --------- d-----w c:\documents and settings\mat\Dane aplikacji\Media Player Classic
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-06 18:47 --------- d-----w c:\program files\Realtek
2008-10-06 15:22 --------- d-----w c:\program files\MegauploadToolbar
2008-10-06 15:22 --------- d-----w c:\documents and settings\mat\Dane aplikacji\EmailNotifier
2008-10-06 15:22 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\EmailNotifier
2008-10-06 14:31 --------- d-----w c:\program files\AC3Filter
2008-10-02 15:48 --------- d-----w c:\program files\Java
2008-10-02 15:43 --------- d-----w c:\program files\Common Files\Java
2008-10-02 11:52 --------- d-----w c:\documents and settings\mat\Dane aplikacji\Gadu-Gadu
2008-10-02 11:11 --------- d-----w c:\program files\PLAY ONLINE
2008-09-15 15:27 1,846,656 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-09 17:33 315,392 ----a-w c:\windows\HideWin.exe
2008-09-04 17:17 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-26 19:11 987,136 ----a-w c:\windows\system32\VSFilter.dll
2008-08-26 08:27 826,368 ----a-w c:\windows\system32\wininet.dll
2006-06-23 06:48 32,768 ----a-r c:\windows\inf\UpdateUSB.exe
2004-03-11 11:27 40,960 ----a-w c:\program files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}]
2008-08-04 21:44 1947080 --a------ c:\progra~1\MEGAUP~1\MEGAUP~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-C39E-35F1D2A32EC8}"= "c:\progra~1\MEGAUP~1\MEGAUP~1.DLL" [2008-08-04 1947080]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A057A204-BACC-4D26-C39E-35F1D2A32EC8}"= "c:\progra~1\MEGAUP~1\MEGAUP~1.DLL" [2008-08-04 1947080]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-c39e-35f1d2a32ec8}]
[HKEY_CLASSES_ROOT\megauploadtoolbar.MEGAUPLOADTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"NVIDIA nTune"="e:\programy\nTune\nTune\nTuneCmd.exe" [2007-09-04 81920]
"Gadu-Gadu"="e:\programy\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-10-14 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-29 638976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-25 786521]
"Power_Gear"="e:\programy\Power4G\BatteryLife.exe" [2006-03-14 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 171520]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-09-10 864256]
"nwiz"="nwiz.exe" [2007-04-28 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-05-22 2756608]
Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-10-05 111376]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
Uruchamianie pakietu Office.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-10-05 51984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= e:\programy\CYBERL~1\Power2Go\CLMP3Enc.ACM
"msacm.ac3filter"= ac3filter.acm
"vidc.ffds"= ffdshow.ax
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
--a------ 2006-08-01 16:04 3313664 e:\programy\Bearshare\BearShare.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 16:05 81920 e:\programy\Daemon\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashGet]
--a------ 2008-08-19 08:47 1795656 e:\programy\FlashGet universal\flashget.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerBar]
--------- 2003-12-22 21:15 86016 e:\programy\Cyberlink\Multimedia Launcher\PowerBar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2003-10-31 18:42 32768 e:\programy\Cyberlink\PowerDVD\PDVDServ.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\gry\\Assasin\\AssassinsCreed_Dx9.exe"=
"f:\\gry\\Assasin\\AssassinsCreed_Dx10.exe"=
"f:\\gry\\Assasin\\AssassinsCreed_Launcher.exe"=
"e:\\programy\\Gadu-Gadu\\gg.exe"=
"e:\\programy\\Bearshare\\BearShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\gry\\FEAR\\FEAR.exe"=
"e:\\programy\\FlashGet universal\\FlashGet.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 nxsIO32;NextSensor Kernel I/O Driver;\??\c:\windows\System32\DRIVERS\nxsIO32.sys [2008-09-10 2208]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;c:\windows\System32\StkCSrv.exe [2008-09-09 24576]
R3 StkCMini;Syntek AVStream USB2.0 2M WebCam;c:\windows\system32\Drivers\StkCMini.sys [2008-09-09 1245056]
S1 ntiomin;ntiomin; []
S3 BIOSCHK;BIOSCHK;\??\c:\docume~1\mat\USTAWI~1\Temp\TII4.tmp\disk1\BIOSCHK.SYS []
S3 SoftFSB;SoftFSB;\??\c:\documents and settings\mat\Pulpit\SoftFSB.SYS []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e26bf4c-9072-11dd-99cd-001e8c432b8b}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d70b014a-92e7-11dd-99dc-001e8c432b8b}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d70b014b-92e7-11dd-99dc-001e8c432b8b}]
\Shell\AutoRun\command - H:\AutoRun.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - MCHINJDRV
*Newly Created Service* - PROCEXP90
.
.
------- Skan uzupełniający -------
.
uStart Page = google.pl/
IE: &Download All by FlashGet - e:\programy\FlashGet universal\ComDlls\Bhoall.htm
IE: &Download by FlashGet - e:\programy\FlashGet universal\ComDlls\Bholink.htm
LSP: c:\windows\system32\ua_lsp.dll
c:\windows\system32\SkanerOnlineUninstall.exe - c:\windows\system32\SkanerOnline.dll
O16 -: {68282C51-9459-467B-95BF-3C0E89627E55}
hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
c:\windows\Downloaded Program Files\SkanerOnline.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-21 19:35:06
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
PROCES: c:\windows\system32\winlogon.exe
-> c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
PROCES: c:\windows\system32\lsass.exe
-> c:\windows\system32\ua_lsp.dll
-> c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
PROCES: c:\windows\explorer.exe
-> c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
.
Czas ukończenia: 2008-11-21 19:36:09
ComboFix-quarantined-files.txt 2008-11-21 18:36:05
ComboFix2.txt 2008-11-21 17:19:05
Przed: 7 169 925 120 bajtów wolnych
Po: 7,163,301,888 bajtów wolnych
192 --- E O F --- 2008-11-12 22:53:21