
Patrykose napisał(a):W każdym przypadku próbowałem już odłączać jeden napęd ale to nic nie dawało.
ComboFix 08-07-08.5 - Mirek 2008-07-09 10:20:05.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.207 [GMT 2:00]
Running from: C:\Documents and Settings\Mirek.KOMPUTER\Pulpit\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\hgu.bat
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
D:\Autorun.inf
D:\hgu.bat
E:\Autorun.inf
E:\hgu.bat
F:\Autorun.inf
F:\hgu.bat
C:\Autorun.inf . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-06-09 to 2008-07-09 )))))))))))))))))))))))))))))))
.
2008-07-09 10:27 . 2008-07-09 08:26 117,225 -r-hs---- C:\hgu.bat
2008-07-09 08:26 . 2008-07-09 08:26 77,312 -r-hs---- C:\WINDOWS\system32\ckvo1.dll
2008-07-09 08:25 . 2008-07-09 08:26 117,225 -r-hs---- C:\WINDOWS\system32\ckvo.exe
2008-07-09 08:25 . 2008-07-09 10:27 77,312 -r-hs---- C:\WINDOWS\system32\ckvo0.dll
2008-07-09 07:56 . 118,734 C:\00hoeav.com
2008-07-09 07:53 . 607 C:\autorun.inf
2008-07-08 20:02 . 2008-07-09 03:09 <DIR> d-------- C:\Program Files\PowerStrip
2008-07-08 11:37 . 2008-07-08 11:37 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-07-08 11:37 . 2008-07-08 11:37 <DIR> d-------- C:\Documents and Settings\Mirek.KOMPUTER\SystemRequirementsLab
2008-07-06 11:00 . 2008-07-06 11:00 528 --a------ C:\WINDOWS\eReg.dat
2008-07-04 09:42 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2008-07-04 09:42 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2008-07-04 09:42 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2008-07-04 09:42 . 2007-05-31 19:30 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2008-07-04 09:42 . 2007-04-04 18:55 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2008-07-04 09:42 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2008-07-04 09:42 . 2007-05-31 19:29 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2008-07-04 09:40 . 2008-07-04 09:40 22,328 --a------ C:\Documents and Settings\Mirek.KOMPUTER\Dane aplikacji\PnkBstrK.sys
2008-07-04 09:40 . 2008-07-04 09:40 319 --a------ C:\WINDOWS\game.ini
2008-07-04 09:17 . 2008-07-04 09:17 <DIR> d-------- C:\Program Files\Activision
2008-07-01 16:14 . 2008-07-01 16:14 <DIR> d-------- C:\Program Files\Sylvain Seccia
2008-06-29 16:36 . 2008-06-29 16:36 <DIR> d-------- C:\Program Files\Pivot Stickfigure Animator
2008-06-27 20:29 . 2008-06-27 20:29 <DIR> d-------- C:\Program Files\uTorrent
2008-06-27 20:29 . 2008-06-28 17:54 <DIR> d-------- C:\Documents and Settings\Mirek.KOMPUTER\Dane aplikacji\uTorrent
2008-06-26 14:41 . 2008-06-26 14:41 <DIR> d-------- C:\GAMES
2008-06-26 10:49 . 2008-07-05 12:51 <DIR> d-------- C:\GTA.San.Andreas
2008-06-24 09:37 . 2008-06-24 09:37 <DIR> d-------- C:\Program Files\GTA3Mods - GXT Editor
2008-06-19 11:18 . 2008-06-19 11:18 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Kaspersky Lab Setup Files
2008-06-19 11:10 . 2008-06-19 11:10 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-06-19 11:10 . 2008-06-19 11:26 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-06-19 11:09 . 2008-06-19 11:11 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-19 11:09 . 2008-06-19 11:11 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-06-19 11:09 . 2008-06-19 11:11 10,563 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-19 11:09 . 2008-06-19 11:11 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-19 11:08 . 2008-06-19 11:11 <DIR> d-------- C:\Program Files\Symantec
2008-06-19 11:08 . 2008-06-19 11:12 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Symantec
2008-06-19 11:03 . 2008-06-28 19:02 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-06-18 13:44 . 2008-06-16 01:13 112,672 -r-hs---- C:\6x8be16.cmd
2008-06-16 16:53 . 2008-06-16 16:53 <DIR> d-------- C:\Program Files\Alwil Software
2008-06-16 16:53 . 2003-03-18 22:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-06-16 11:12 . 2008-06-16 11:15 <DIR> d-------- C:\Program Files\Odkurzacz
2008-06-13 15:05 . 2008-06-13 15:05 <DIR> d-------- C:\Program Files\GameTop.com
2008-06-12 03:03 . 2008-06-12 03:03 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 13:31 . 2008-06-14 20:01 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 13:31 . 2008-06-14 20:01 273,024 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-09 08:24 262,144 ---ha-w C:\Documents and Settings\NetworkService.ZARZąDZANIE NT.000\NTUSER.DAT
2008-07-09 08:24 262,144 ---ha-w C:\Documents and Settings\NetworkService.ZARZąDZANIE NT.000\NTUSER.DAT
2008-07-09 08:24 262,144 ---ha-w C:\Documents and Settings\LocalService.ZARZąDZANIE NT.000\NTUSER.DAT
2008-07-09 08:24 262,144 ---ha-w C:\Documents and Settings\LocalService.ZARZąDZANIE NT.000\NTUSER.DAT
2008-07-08 09:26 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP
2008-07-06 06:52 --------- d-----w C:\Program Files\GameSpy Arcade
2008-07-04 07:40 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-07-04 07:40 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-04 07:40 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-07-04 07:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-01 05:58 --------- d-----w C:\Program Files\AIMP2
2008-06-25 15:23 --------- d-----w C:\Program Files\BitComet
2008-06-22 17:14 --------- d-----w C:\Program Files\Sanny Builder 3
2008-06-22 11:25 --------- d-----w C:\Program Files\WarRock
2008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-18 09:31 --------- d-----w C:\Program Files\Gadu-Gadu
2008-06-16 14:30 --------- d-----w C:\Documents and Settings\Mirek.KOMPUTER\Dane aplikacji\skypePM
2008-06-16 14:26 --------- d-----w C:\Program Files\XP Smoker
2008-06-16 14:26 --------- d-----w C:\Program Files\FlashGet
2008-06-16 14:26 --------- d-----w C:\Program Files\Eset
2008-06-16 13:40 --------- d-----w C:\Documents and Settings\Mirek\Dane aplikacji\BitTorrent
2008-06-08 13:40 --------- d-----w C:\Documents and Settings\Mirek.KOMPUTER\Dane aplikacji\Skype
2008-06-06 12:26 --------- d-----w C:\Program Files\PhotoFiltre Studio
2008-06-03 09:10 --------- d-----w C:\Program Files\Tales of Pirates Online
2008-05-29 18:06 --------- d-----w C:\Program Files\FDRLab
2008-05-23 08:39 --------- d-----w C:\Program Files\VirtuallTek
2008-05-21 07:15 --------- d-----w C:\Program Files\PowerISO
2008-05-18 17:57 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\nView_Profiles
2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:03 662,016 ----a-w C:\WINDOWS\system32\wininet.dll
2008-01-03 15:29 262,144 ---ha-w C:\Documents and Settings\NetworkService.ZARZąDZANIE NT\NTUSER.DAT
2008-01-03 15:29 262,144 ---ha-w C:\Documents and Settings\LocalService.ZARZąDZANIE NT\NTUSER.DAT
2007-12-22 19:20 32 ----a-w C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ezsid.dat
2007-05-23 23:47 17,144 ----a-w C:\Documents and Settings\Mirek\Dane aplikacji\GDIPFONTCACHEV1.DAT
2001-11-23 10:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
<pre>
----a-w 2,676,736 2002-08-09 08:36:56 C:\Program Files\ASCII\RPG Maker PL\RPG MAKER PL 2.0 .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [2007-12-07 17:03 1913656]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-07-16 23:54 961536]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 14:49 153136]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-11-14 12:54 2131392]
"EPSON Stylus DX4400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 08:01 180736]
"Odkurzacz-MCD"="C:\Program Files\Odkurzacz\odk_mcd.exe" [2008-03-03 14:44 266240]
"kamsoft"="C:\WINDOWS\system32\ckvo.exe" [2008-07-09 10:28 117225]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-10 04:06 7311360]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-12-10 04:06 86016]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 19:53 153136]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2006-10-23 01:48 40048]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-03-15 01:50 233472]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 19:47 51048]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-02-07 00:49 718704]
"isCfgWiz"="C:\Program Files\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SYMCUW.exe" [2008-01-30 20:14 611712]
"PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2008-05-02 02:37 726776]
"Cmaudio"="cmicnfg.cpl" [N/A]
"nwiz"="nwiz.exe" [2005-12-10 04:06 1519616 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360]
C:\Documents and Settings\Mirek\Menu Start\Programy\Autostart\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-03-14 18:35:42 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ZDSV"= scrvid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"E:\\TH\\Game\\THAW.exe"=
"C:\\Program Files\\Metin2_PL\\metin2.bin"=
"C:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\GameTop.com\\RIP3\\RIP3.exe"=
"C:\\Documents and Settings\\All Users.WINDOWS\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\english\\setup.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Sylvain Seccia\\Deadly Weaponz\\Deadly Weaponz.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22835:TCP"= 22835:TCP:BitComet 22835 TCP
"22835:UDP"= 22835:UDP:BitComet 22835 UDP
"27543:TCP"= 27543:TCP:BitComet 27543 TCP
"27543:UDP"= 27543:UDP:BitComet 27543 UDP
"24109:TCP"= 24109:TCP:BitComet 24109 TCP
"24109:UDP"= 24109:UDP:BitComet 24109 UDP
R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-01-25 19:47]
R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\pstrip.sys [2007-07-15 03:37]
R3 scrcap;scrcap;C:\WINDOWS\system32\DRIVERS\scrcap.sys [2006-12-27 16:47]
S2 Windows_IE7.0;Windows_IE7.0;C:\Program Files\IE7.0.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61b6cd08-3acb-11dd-b3f3-00138f07e3e5}]
\Shell\AutoRun\command - K:\a3g3.bat
\Shell\explore\Command - K:\a3g3.bat
\Shell\open\Command - K:\a3g3.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{979ca746-267e-11dd-b3df-00138f07e3e5}]
\Shell\Auto\command - J:\IE7.0.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL IE7.0.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a89a2a94-ae67-11dc-bc88-00138f07e3e5}]
\Shell\AutoRun\command - D:\stw1ojde.bat
\Shell\explore\Command - D:\stw1ojde.bat
\Shell\open\Command - D:\stw1ojde.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2a9e5b6-0315-11dd-b3a9-00138f07e3e5}]
\Shell\AutoRun\command - L:\6x8be16.cmd
\Shell\explore\Command - L:\6x8be16.cmd
\Shell\open\Command - L:\6x8be16.cmd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-09 10:27:20
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Completion time: 2008-07-09 10:32:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-09 08:31:55
Pre-Run: 38,323,821,568 bajtów wolnych
Post-Run: 38,447,776,768 bajt˘w wolnych
229 --- E O F --- 2008-07-09 01:01:02
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 15 gości