

takze Combofix:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 18:42:09, on 2008-07-05Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.20583)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\system32\kxmixer.exeC:\WINDOWS\PixArt\PAC207\Monitor.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\DAEMON Tools\daemon.exeC:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeO2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dllO2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dllO4 - HKLM\..\Run: [AtiPTA] atiptaxx.exeO4 - HKLM\..\Run: [kX Mixer] C:\WINDOWS\system32\kxmixer.exe --startupO4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exeO4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA LOKALNA')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA SIECIOWA')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exeO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO9 - Extra button: Kolekcja wycinków HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dllO9 - Extra button: Zaznaczanie HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dllO17 - HKLM\System\CCS\Services\Tcpip\..\{C287274D-25AB-4BD9-8E6D-B554BCA147AE}: NameServer = 213.241.79.37 83.238.255.76O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)--End of file - 3545 bytes
prosze o szybka pomocComboFix 08-07-04.5 - Administrator 2008-07-05 18:46:03.2 - NTFSx86Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.293 [GMT 2:00]Running from: C:\Documents and Settings\Administrator\Pulpit\ComboFix.exeWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.((((((((((((((((((((((((( Files Created from 2008-06-05 to 2008-07-05 ))))))))))))))))))))))))))))))).2008-07-05 18:29 . 2008-07-05 18:29 <DIR> d-------- C:\WINDOWS\ERUNT2008-07-05 18:27 . 2008-07-05 18:36 <DIR> d-------- C:\SDFix2008-07-05 18:13 . 2008-07-05 18:13 <DIR> d-------- C:\WINDOWS\system32\xircom2008-07-05 18:13 . 2008-07-05 18:13 <DIR> d-------- C:\WINDOWS\system32\oobe2008-07-05 18:13 . 2008-07-05 18:13 <DIR> d-------- C:\WINDOWS\srchasst2008-07-05 18:13 . 2008-07-05 18:13 <DIR> d-------- C:\WINDOWS\msagent2008-07-05 18:13 . 2008-07-05 18:13 <DIR> d-------- C:\Program Files\microsoft frontpage2008-07-05 18:05 . 2008-07-05 18:05 <DIR> d-------- C:\Program Files\Trend Micro2008-07-05 08:34 . 2008-07-05 08:34 169 --a------ C:\WINDOWS\adidsl.ini2008-07-05 08:34 . 2008-07-05 08:34 21 --a------ C:\WINDOWS\Fast800.ini2008-07-05 08:33 . 2008-07-05 08:33 <DIR> d-------- C:\Program Files\SAGEM2008-07-05 08:32 . 2008-07-05 08:32 <DIR> d-------- C:\Documents and Settings\Administrator\Dane aplikacji\InstallShield2008-06-30 18:21 . 2008-07-05 08:44 <DIR> d-------- C:\Program Files\AutoConnect2008-06-30 18:03 . 2008-06-30 21:42 30 --a------ C:\WINDOWS\TextSpy.ini2008-06-30 17:49 . 2008-06-30 17:49 8,192 --a------ C:\WINDOWS\REGLOCS.OLD2008-06-30 17:48 . 2008-07-05 08:34 990 --a------ C:\WINDOWS\adiras.ini2008-06-15 19:22 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll2008-06-15 19:18 . 2008-06-15 19:18 <DIR> d--h----- C:\WINDOWS\PIF2008-06-15 16:58 . 2008-06-29 14:36 304,160 --a------ C:\PA207.DAT2008-06-15 14:45 . 2008-06-15 14:45 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\AVS4YOU2008-06-15 13:24 . 2008-06-15 13:24 <DIR> d-------- C:\Documents and Settings\Administrator\Dane aplikacji\DivX.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2008-07-05 06:34 33 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg2008-07-05 06:33 --------- d--h--w C:\Program Files\InstallShield Installation Information2008-06-22 17:24 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\HP2008-06-14 19:35 --------- d-----w C:\Program Files\DAEMON Tools2008-06-14 19:34 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys2008-06-14 19:23 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Winamp2008-06-14 19:10 --------- d-----w C:\Program Files\Common Files\Adobe2008-06-14 19:07 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\HP2008-06-14 19:06 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\WEBREG2008-06-14 19:03 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Hewlett-Packard2008-06-14 18:59 --------- d-----w C:\Program Files\HP2008-06-14 18:59 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\HPSSUPPLY2008-06-14 18:59 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\HPAppData2008-06-14 18:58 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\HP Product Assistant2008-06-14 18:57 --------- d-----w C:\Program Files\Hewlett-Packard2008-06-14 18:57 --------- d-----w C:\Program Files\Common Files\HP2008-06-14 18:57 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard2008-06-14 18:52 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\ArcSoft2008-06-14 18:44 --------- d-----w C:\Program Files\Common Files\ArcSoft2008-06-14 18:43 --------- d-----w C:\Program Files\ArcSoft2008-06-14 18:42 --------- d-----w C:\Program Files\PC Camera2008-06-14 18:42 --------- d-----w C:\Program Files\Common Files\PAC2072008-06-14 18:42 --------- d-----w C:\Program Files\Common Files\InstallShield2008-06-14 18:35 --------- d-----w C:\Program Files\kX Project2008-06-14 18:34 --------- d-----w C:\Program Files\Winamp2008-06-14 18:32 --------- d-----w C:\Program Files\Common Files\AVSMedia2008-06-14 18:32 --------- d-----w C:\Program Files\AVS4YOU2008-06-14 18:30 --------- d-----w C:\Program Files\Codec2008-06-14 18:29 --------- d-----w C:\Program Files\Real2008-06-14 18:29 --------- d-----w C:\Program Files\Common Files\xing shared2008-06-14 18:29 --------- d-----w C:\Program Files\Common Files\Real2008-06-14 18:25 --------- d-----w C:\Program Files\MultiRes2008-06-14 18:24 451,072 ----a-w C:\WINDOWS\Radeon Omega Drivers v2.6.87 Uninstall.exe2008-06-14 18:17 --------- d-----w C:\Program Files\Radeon Omega Drivers2008-06-14 18:14 --------- d-----w C:\Program Files\Intel2008-06-14 18:06 --------- d-----w C:\Program Files\Real Alternative2008-06-14 18:06 --------- d-----w C:\Program Files\QuickTime Alternative2008-06-14 18:06 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer2008-06-14 18:05 --------- d-----w C:\Program Files\Java2008-06-14 18:05 --------- d-----w C:\Program Files\Common Files\Java2008-06-14 18:00 --------- d-----w C:\Program Files\Windows Media Connect 2.------- Sigcheck -------2007-07-10 15:06 642560 ce594e18fe0d0af804f1f3694921ce62 C:\WINDOWS\system32\user32.dll2007-07-14 00:56 814592 ce7193c5f7c01b19768e066087c1c919 C:\WINDOWS\system32\wininet.dll2007-07-28 03:15 360576 0fb6743e937c7bb248b2530a5a77abc6 C:\WINDOWS\system32\drivers\tcpip.sys2007-07-26 19:30 2067584 5362d54a6925afdcbbba53b43ee65774 C:\WINDOWS\system32\ntkrnlpa.exe2007-07-26 19:31 2190464 9899bb89856e3bd4ef13e11ccee49b71 C:\WINDOWS\system32\ntoskrnl.exe2007-07-14 00:42 974848 32f67215c57df2c401bf93b7ee65987f C:\WINDOWS\explorer.exe.((((((((((((((((((((((((((((( snapshot@2008-07-05_18.08.27,37 ))))))))))))))))))))))))))))))))))))))))).- 2008-07-05 16:04:45 2,048 --s-a-w C:\WINDOWS\bootstat.dat+ 2008-07-05 16:35:17 2,048 --s-a-w C:\WINDOWS\bootstat.dat+ 2008-07-05 00:04:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE+ 2008-07-05 16:29:49 2,121,728 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT+ 2008-07-05 16:29:49 143,360 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat+ 2008-07-05 00:04:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE+ 2008-07-05 16:29:43 2,121,728 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT+ 2008-07-05 16:29:43 143,360 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:44 15360]"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-22 14:06 167368][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"kX Mixer"="C:\WINDOWS\system32\kxmixer.exe" [2005-07-14 15:17 472576]"Monitor"="C:\WINDOWS\PixArt\PAC207\Monitor.exe" [2006-11-03 11:01 319488]"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]"AtiPTA"="atiptaxx.exe" [2005-11-23 02:05 344064 C:\WINDOWS\system32\atiptaxx.exe][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:44 15360][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"nltide_2"="shell32" [X]C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-07-05 08:33:52 1205840]HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520][HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"DisableStatusMessages"= 1 (0x1)[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]"NoSMMyPictures"= 1 (0x1)"NoSMConfigurePrograms"= 1 (0x1)"NoSMHelp"= 1 (0x1)"NoResolveTrack"= 1 (0x1)"NoResolveSearch"= 1 (0x1)[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]"NoSMMyPictures"= 1 (0x1)"NoSMConfigurePrograms"= 1 (0x1)"NoSMHelp"= 1 (0x1)"NoResolveTrack"= 1 (0x1)"NoResolveSearch"= 1 (0x1)[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]"msacm.ac3filter"= ac3filter.acm[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\system32\\sessmgr.exe"=R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2007-01-04 13:48]R3 kxwdmdrv;kX WDM Driver Service;C:\WINDOWS\system32\drivers\kx.sys [2005-07-14 15:17]R3 PAC207;PC Camera;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-29 13:30]S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2007-01-04 13:47]S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc.**************************************************************************catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-07-05 18:47:19Windows 5.1.2600 Dodatek Service Pack 2 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.Completion time: 2008-07-05 18:48:10ComboFix-quarantined-files.txt 2008-07-05 16:48:04ComboFix2.txt 2008-07-05 16:08:43Pre-Run: 1,504,022,528 bajtów wolnychPost-Run: 1,497,403,392 bajtów wolnych157