
Daj nowy log z ComboFixa.
==========================
K.
ComboFix 08-09-05.02 - beata1983 2008-09-07 14:02:32.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.133 [GMT 2:00]
Running from: C:\Documents and Settings\beata1983\Pulpit\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((( Files Created from 2008-08-07 to 2008-09-07 )))))))))))))))))))))))))))))))
.
2008-09-07 13:22 . 2008-09-07 13:22 <DIR> d-------- C:\Program Files\Avira
2008-09-07 13:22 . 2008-09-07 13:22 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-09-06 08:01 . 2008-09-06 08:01 <DIR> d-------- C:\Program Files\Mp3 Knife
2008-09-06 08:01 . 2004-04-12 17:27 1,081,616 --a------ C:\WINDOWS\system32\mscomctl.ocx
2008-09-06 08:01 . 2004-04-12 17:27 609,584 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-09-06 08:01 . 2004-04-12 17:27 152,848 --a------ C:\WINDOWS\system32\comdlg32.ocx
2008-09-06 07:48 . 2008-09-06 07:48 <DIR> d-------- C:\Program Files\NCH Software
2008-09-06 07:48 . 2008-09-06 07:48 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\NCH Swift Sound
2008-09-06 07:47 . 2008-09-06 07:48 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-09-06 07:47 . 2008-09-06 07:47 <DIR> d-------- C:\Documents and Settings\beata1983\Dane aplikacji\NCH Swift Sound
2008-09-06 07:41 . 2007-08-11 20:05 158,208 --a------ C:\WINDOWS\system32\CDRipUpd.exe
2008-09-06 07:14 . 2008-09-06 07:25 <DIR> d-------- C:\Documents and Settings\beata1983\Dane aplikacji\AccurateRip
2008-09-06 07:13 . 2008-09-06 07:14 <DIR> d-------- C:\Program Files\Exact Audio Copy
2008-09-06 06:59 . 2008-09-06 06:59 <DIR> d-------- C:\Documents and Settings\beata1983\Dane aplikacji\PCToolsFirewallPlus
2008-09-06 06:57 . 2008-09-06 07:05 <DIR> d-------- C:\Program Files\PC Tools Firewall Plus
2008-09-06 06:57 . 2008-09-07 13:10 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-09-06 06:57 . 2008-07-28 11:29 160,792 --a------ C:\WINDOWS\system32\drivers\pctfw2.sys
2008-09-06 06:57 . 2008-07-17 16:53 93,952 --a------ C:\WINDOWS\system32\drivers\pctfw.sys
2008-09-06 06:57 . 2008-08-05 15:58 58,136 --a------ C:\WINDOWS\system32\drivers\FWAuthdriver.sys
2008-09-05 21:28 . 2008-09-07 13:12 <DIR> d-a------ C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-09-05 17:26 . 2008-09-05 17:26 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-09-05 17:26 . 2008-09-05 17:26 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-08-24 15:13 . 2008-08-24 15:13 580,096 --a--c--- C:\WINDOWS\system32\dllcache\user32.dll
2008-08-24 15:10 . 2008-08-24 15:11 <DIR> d-------- C:\WINDOWS\ERUNT
2008-08-24 15:05 . 2008-08-24 15:21 <DIR> d-------- C:\SDFix
2008-08-24 13:48 . 2008-08-24 13:48 100 --a------ C:\index.ini
2008-08-24 09:57 . 2008-08-24 09:57 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-08-24 09:39 . 2008-08-24 09:39 <DIR> d-------- C:\Program Files\PrevxCSI
2008-08-24 09:39 . 2008-08-24 09:39 17,408 --a------ C:\WINDOWS\system32\drivers\pxark.sys
2008-08-24 09:38 . 2008-09-07 10:38 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\PrevxCSI
2008-08-23 14:10 . 2008-08-23 14:10 <DIR> d-------- C:\Program Files\Alwil Software
2008-08-23 14:03 . 2008-08-23 14:03 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Avg8
2008-08-23 09:14 . 2008-08-23 09:14 <DIR> d-------- C:\WINDOWS\system32\pl-pl
2008-08-23 09:14 . 2008-08-23 09:14 <DIR> d-------- C:\WINDOWS\system32\pl
2008-08-23 09:14 . 2008-08-23 09:14 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-23 09:14 . 2008-08-23 09:14 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-23 09:08 . 2008-08-23 09:15 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-23 08:50 . 2008-08-23 08:50 <DIR> d-------- C:\WINDOWS\EHome
2008-08-22 23:58 . 2008-08-23 10:30 <DIR> d-------- C:\Program Files\PokerStars
2008-08-22 18:57 . 2004-08-03 22:41 1,309,184 --------- C:\WINDOWS\system32\drivers\mtlstrm.sys
2008-08-22 18:57 . 2004-08-03 22:29 452,736 --------- C:\WINDOWS\system32\drivers\mtxparhm.sys
2008-08-22 18:57 . 2004-08-03 22:41 126,686 --------- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2008-08-22 18:57 . 2004-07-17 11:35 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2008-08-22 18:57 . 2004-08-04 14:00 36,644 -----c--- C:\WINDOWS\system32\dllcache\mplayer2.inf
2008-08-22 18:57 . 2004-08-04 14:00 22,060 -----c--- C:\WINDOWS\system32\dllcache\npds.zip
2008-08-22 18:57 . 2004-08-04 14:00 2,778 -----c--- C:\WINDOWS\system32\dllcache\mplogoh.gif
2008-08-22 18:57 . 2004-08-04 14:00 2,545 -----c--- C:\WINDOWS\system32\dllcache\mplogo.gif
2008-08-22 18:57 . 2004-08-04 14:00 403 -----c--- C:\WINDOWS\system32\dllcache\npdrmv2.zip
2008-08-22 18:56 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-08-22 18:56 . 2004-08-03 22:41 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2008-08-22 18:56 . 2004-08-03 22:41 220,032 --------- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2008-08-22 18:56 . 2004-08-04 14:00 5,971 -----c--- C:\WINDOWS\system32\dllcache\events.js
2008-08-22 18:55 . 2004-08-04 14:00 184,137 -----c--- C:\WINDOWS\system32\dllcache\compact.wmz
2008-08-22 18:55 . 2004-07-17 22:55 129,045 --------- C:\WINDOWS\system32\drivers\cxthsfs2.cty
2008-08-22 18:55 . 2004-08-04 14:00 9,585 -----c--- C:\WINDOWS\system32\dllcache\controls.css
2008-08-22 18:55 . 2004-08-04 14:00 999 -----c--- C:\WINDOWS\system32\dllcache\bktrh.gif
2008-08-22 18:55 . 2004-08-04 14:00 773 -----c--- C:\WINDOWS\system32\dllcache\cnth.gif
2008-08-22 18:55 . 2004-08-04 14:00 773 -----c--- C:\WINDOWS\system32\dllcache\cnt.gif
2008-08-22 18:55 . 2004-08-04 14:00 772 -----c--- C:\WINDOWS\system32\dllcache\cntd.gif
2008-08-22 18:55 . 2004-08-04 14:00 760 -----c--- C:\WINDOWS\system32\dllcache\cloapph.gif
2008-08-22 18:55 . 2004-08-04 14:00 717 -----c--- C:\WINDOWS\system32\dllcache\cloapp.gif
2008-08-15 19:16 . 2008-08-23 08:00 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-08-15 19:10 . 2008-08-15 21:37 <DIR> d-------- C:\Program Files\Common Files\Softwin
2008-08-15 18:56 . 2008-08-15 18:56 <DIR> d-------- C:\Documents and Settings\beata1983\DoctorWeb
2008-08-15 14:47 . 2008-08-15 15:16 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-08-15 13:53 . 2008-08-15 13:53 <DIR> d-------- C:\fsaua.data
2008-08-15 13:24 . 2008-04-11 21:06 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-06 16:41 --------- d-----w C:\Documents and Settings\beata1983\Dane aplikacji\foobar2000
2008-09-05 23:24 --------- d-----w C:\Program Files\DC++
2008-09-05 18:50 --------- d-----w C:\Documents and Settings\beata1983\Dane aplikacji\Skype
2008-09-05 18:01 --------- d-----w C:\Documents and Settings\beata1983\Dane aplikacji\skypePM
2008-09-05 17:06 --------- d-----w C:\Documents and Settings\beata1983\Dane aplikacji\gtk-2.0
2008-08-23 13:36 --------- d-----w C:\Program Files\SkanerOnline
2008-08-22 15:40 --------- d-----w C:\Program Files\Opera
2008-08-16 16:55 --------- d-----w C:\Program Files\SubEdit-Player
2008-08-09 04:37 --------- d-----w C:\Program Files\Java
2008-08-02 22:12 --------- d-----w C:\Program Files\foobar2000
2008-08-02 20:06 --------- d-----w C:\Program Files\Picasa2
2008-08-02 13:19 --------- d-----w C:\Program Files\Google
2008-08-02 13:00 --------- d-----w C:\Program Files\GIMP-2.0
2008-08-02 12:57 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-08-02 12:46 --------- d-----w C:\Documents and Settings\beata1983\Dane aplikacji\Ashampoo
2008-08-02 12:46 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ashampoo
2008-08-02 12:37 --------- d-----w C:\Program Files\WebHat Software
2008-08-02 05:24 --------- d-----w C:\Program Files\Winamp Remote
2008-08-01 19:49 --------- d-----w C:\Program Files\PartyGaming.Net
2008-08-01 16:29 --------- d-----w C:\Program Files\Skype
2008-08-01 16:29 --------- d-----w C:\Program Files\Common Files\Skype
2008-08-01 16:29 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-07-29 11:49 --------- d-----w C:\Documents and Settings\beata1983\Dane aplikacji\Ahead
2008-07-07 20:29 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-05 21:49 532,558 ----a-w C:\WINDOWS\system32\odGinaLibrary.dll
2008-07-05 21:49 139,330 ----a-w C:\WINDOWS\system32\odyGina.dll
2008-07-05 21:49 106,496 ----a-w C:\WINDOWS\system32\odyEvent.dll
2008-06-24 16:46 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:13 668,672 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:48 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-18 17:52 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-06-11 00:07 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-06-11 00:07 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-06-11 00:07 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-06-11 00:07 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-06-11 00:07 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-06-11 00:04 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-06-11 00:04 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
.
((((((((((((((((((((((((((((( snapshot@2008-09-06_12.25.22.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-09 11:15:51 45,376 ----a-w C:\WINDOWS\system32\drivers\avgntdd.sys
+ 2008-01-21 16:11:28 22,336 ----a-w C:\WINDOWS\system32\drivers\avgntmgr.sys
+ 2008-06-27 13:03:55 75,072 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-03-01 08:34:22 28,352 ----a-w C:\WINDOWS\system32\drivers\ssmdrv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"CDRipUpd.exe"="C:\WINDOWS\system32\CDRipUpd.exe" [2007-08-11 158208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 339968]
"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2005-03-30 32768]
"HotkeyApp"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2005-05-02 57344]
"LMgrVolOSD"="C:\Program Files\Launch Manager\OSD.exe" [2005-03-16 204800]
"LMgrOSD"="C:\Program Files\Launch Manager\OSDCtrl.exe" [2004-10-11 245760]
"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2005-04-18 81920]
"CtrlVol"="C:\Program Files\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
"00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2008-08-05 2611096]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SoundMan"="SOUNDMAN.EXE" [2005-03-24 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Java\\jre1.5.0\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2008-08-24 17408]
R1 Hotkey;Hotkey;C:\WINDOWS\system32\drivers\Hotkey.sys [2003-04-28 9867]
R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-07-28 160792]
R2 CSIScanner;CSIScanner;C:\Program Files\PrevxCSI\prevxcsi.exe [2008-08-24 618040]
R3 FWAuth;FWAuth Driver;C:\WINDOWS\system32\drivers\FWAuthDriver.sys [2008-08-05 58136]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2004-12-15 200192]
S1 Wbutton;Wbutton;C:\WINDOWS\system32\drivers\Wbutton.sys [ ]
S3 odysseyIM4;Odyssey Network Agent Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM4.sys [2005-05-18 173056]
*Newly Created Service* - ANTIVIRSCHEDULER
*Newly Created Service* - ANTIVIRSERVICE
*Newly Created Service* - AVGIO
*Newly Created Service* - AVGNTFLT
*Newly Created Service* - AVIPBB
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.onet.pl/
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O9 -: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 -: {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O16 -: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} - hxxp://arcaonline.arcabit.com/ArcaOnline.cab
C:\WINDOWS\Downloaded Program Files\ArcaOnline.inf
C:\WINDOWS\system32\ArcaMicroScanUpdater.exe
C:\WINDOWS\system32\ArcaOnlineUninstall.exe
C:\WINDOWS\system32\ArcaOnline.dll
O16 -: {68282C51-9459-467B-95BF-3C0E89627E55} - hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
C:\WINDOWS\Downloaded Program Files\SkanerOnline.inf
C:\WINDOWS\system32\SkanerOnlineUninstall.exe
C:\WINDOWS\system32\SkanerOnline.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-07 14:07:01
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CtrlVol = C:\Program Files\Launch Manager\CtrlVol.exe?????T??????|x??|????q??|?j?wQj?w????????0??? ???|???????????\??????|????????h?????@??J?????????????s???????s???sx??s@??????????????|h??sl??????????s?????????????????C?sc"?sx??s??????7~??@?N'?s?E9?-6@??E9????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-07 14:08:27
ComboFix-quarantined-files.txt 2008-09-07 12:07:54
Pre-Run: 4,401,012,736 bajtów wolnych
Post-Run: 4,390,584,320 bajtów wolnych
206 --- E O F --- 2008-08-23 16:36:02
********************************************************************************
* *
* FixIEDef Log *
* Version 1.5.6.6088 *
* *
********************************************************************************
Created at 14:17:21 on Sunday, September 07, 2008
Time Zone :
Logged On User : beata1983
Operating System : Microsoft Windows XP Home Edition Dodatek Service Pack 3
OS Version : 5.1.2600
System Langauge : Polish
Keyboard Layout : Polish
Processor : X86 AMD Turion(tm) 64 Mobile Technology ML-32
System Drive : C:\
Windows Directory : C:\WINDOWS
System Directory : C:\WINDOWS\system32
Total Physical Memory : 391328 KB
Free Physical Memory : 153828 KB
Total Virtual Memory : 2097024 KB
Free Virtual Memory : 2020772 KB
Boot State : Normal boot
--------------------------------------------------------------------------------
!!! Files that have been deleted !!!
C:\autorun.inf
--------------------------------------------------------------------------------
!!! Directories that have been removed !!!
No malicious directories to be removed
--------------------------------------------------------------------------------
!!! Registry entries that have been removed !!!
No malicious Registry entries found
================================================================================
All Done :)
ShadowPuterDude
Safe Surfing!!!
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 10 gości