ComboFix 07-12-21.4 - ja 2007-12-27 6:25:28.2 - FAT32 x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.580 [GMT 1:00]
Running from: C:\Documents and Settings\ja\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\ja\Pulpit\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\adssite-remove.exe
C:\WINDOWS\system32\adssite_sidebar.dll
C:\WINDOWS\system32\adssite_sidebar_uninstall.exe
C:\WINDOWS\system32\ninjaext-uninstall.exe
C:\WINDOWS\system32\ninjaext.dll
C:\WINDOWS\system32\rightonadz-uninst.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
C:\VundoFix Backups\winexz32.dll.bad
C:\WINDOWS\system32\adssite-remove.exe
C:\WINDOWS\system32\adssite_sidebar.dll
C:\WINDOWS\system32\adssite_sidebar_uninstall.exe
C:\WINDOWS\system32\ninjaext-uninstall.exe
C:\WINDOWS\system32\ninjaext.dll
C:\WINDOWS\system32\rightonadz-uninst.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-27 to 2007-12-27 )))))))))))))))))))))))))))))))
.
2007-12-25 20:23 . 2007-12-25 20:23
2007-12-24 20:26 . 2007-12-24 20:26
2007-12-24 14:39 . 2007-12-24 14:39
2007-12-24 14:39 . 2007-12-24 14:39
2007-12-24 14:37 . 2007-12-24 14:37 715,248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-12-20 15:25 . 2007-12-20 15:25
2007-12-17 10:00 . 2007-12-17 10:00
2007-12-17 10:00 . 2007-12-17 10:00
2007-12-17 10:00 . 2007-12-17 10:00
2007-12-17 09:30 . 2007-12-17 09:30
2007-12-17 09:30 . 2007-12-17 09:30 32 --a------ C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2007-12-17 09:28 . 2007-12-17 09:28
2007-12-11 06:35 . 2007-12-11 06:35
2007-12-09 13:04 . 2007-12-09 13:04
2007-12-08 19:49 . 2007-12-08 19:49
2007-12-05 06:22 . 2007-12-05 06:22
2007-12-05 06:18 . 2007-12-05 06:18
2007-12-05 06:18 . 2007-12-05 06:19 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2007-12-05 06:18 . 2007-12-05 06:19 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2007-12-05 06:18 . 2007-12-05 06:19 1,406 --a------ C:\WINDOWS\system32\Help.ico
2007-12-03 07:27 . 2007-12-03 07:27
2007-11-28 09:30 . 2007-11-28 09:30
2007-11-27 20:56 . 2007-11-27 20:56
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-11-27 19:56 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-11-02 23:31 --------- d-----w C:\Program Files\Java
2007-11-02 23:25 --------- d-----w C:\Program Files\Common Files\Java
2007-04-19 14:53 25,024 ----a-w C:\Documents and Settings\ja\Dane aplikacji\GDIPFONTCACHEV1.DAT
2004-10-01 14:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( snapshot@2007-12-26_14.37.34,48 )))))))))))))))))))))))))))))))))))))))))
.
-
2007-03-13 09:57:12 163,328 ----a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
-
2007-12-27 05:21:48 8,036 ----a-w C:\WINDOWS\system32\crypgext.dat
- 2007-12-26 13:35:30 2,263,450 ----a-w C:\WINDOWS\system32\psbace.dat
- 2007-12-27 05:21:42 2,268,428 ----a-w C:\WINDOWS\system32\psbace.dat
- 2007-12-26 13:37:20 287,480 ----a-w C:\WINDOWS\system32\rdpwssuy.dat
-
2007-12-27 05:21:48 288,605 ----a-w C:\WINDOWS\system32\rdpwssuy.dat
-
2007-12-27 05:15:12 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_570.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\sceclbm]
@={93C8EE68-E5DC-35BF-41FF-5704F5F420A2}
[HKEY_CLASSES_ROOT\CLSID{93C8EE68-E5DC-35BF-41FF-5704F5F420A2}]
2004-08-03 22:44 71168 --a------ C:\WINDOWS\system32\sceclbm.dIl
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-03 22:44]
“PowerBar”="" []
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-05-04 20:21]
“NBJ”=“C:\Program Files\Ahead\Nero BackItUp\NBJ.exe” [2005-10-11 18:25]
“Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-12-07 15:08]
“DAEMON Tools Lite”=“C:\Program Files\DAEMON Tools Lite\daemon.exe” [2007-12-19 21:13]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“RTHDCPL”=“RTHDCPL.EXE” [2006-05-18 07:27 C:\WINDOWS\RTHDCPL.exe]
“SkyTel”=“SkyTel.EXE” [2006-05-16 11:04 C:\WINDOWS\SkyTel.exe]
“NvCplDaemon”=“RUNDLL32.exe” [2004-08-03 22:44 C:\WINDOWS\system32\rundll32.exe]
“NvMediaCenter”=“RunDLL32.exe” [2004-08-03 22:44 C:\WINDOWS\system32\rundll32.exe]
“RemoteControl”=“C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe” [2004-11-02 20:24]
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 10:50]
“AVG7_CC”=“C:\PROGRA~1\Grisoft\AVG7\avgcc.exe” [2007-12-21 09:45]
“HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2006-02-19 02:41]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 14:00]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2006-10-25 18:58]
“Adobe Photo Downloader”=“C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe” [2005-06-06 23:46]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11]
“postSetupCheck”=“C:\WINDOWS\System32\Rundll32.exe” [2004-08-03 22:44]
“WinampAgent”=“C:\Program Files\Winamp\wianmpa.exe” []
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-03 22:44]
“AVG7_Run”=“C:\PROGRA~1\Grisoft\AVG7\avgw.exe” [2007-10-24 09:46]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 07:05:26]
Anti-Spyware Blocker.lnk - C:\Program Files\Anti-Spyware Blocker\Anti-Virus.exe [2005-03-28 22:59:20]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04]
Eksplorator.lnk - E:\Edbud3.12\Eksplorator.exe [2007-03-23 17:18:10]
S3 sony_ssm.sys;sony_ssm.sys;C:\DOCUME~1\ja\USTAWI~1\Temp\sony_ssm.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{adb128b8-b225-11dc-ad77-0016e633a4d2}]
\Shell\AutoRun\command - G:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{adb128b9-b225-11dc-ad77-0016e633a4d2}]
\Shell\AutoRun\command - H:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{adb128ba-b225-11dc-ad77-0016e633a4d2}]
\Shell\AutoRun\command - I:\autorun.exe
\Shell\directx\command - I:\DirectX9\dxsetup.exe
\Shell\setup\command - I:\setup.exe
.
Contents of the ‘Scheduled Tasks’ folder
“2007-12-22 11:41:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job”
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-27 06:26:29
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PowerBar = ???l?@?l?@?D???w???wl?@?l?@??? ???w???w???w?m?wx???m?w??? ???|x???0??? nt???w??? ???M???l?@?l?@???w???t?@???l?@?8?@?l?@?3??s???8?@?_??s8?@?8?@
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-27 6:26:48
C:\ComboFix2.txt … 2007-12-26 14:37
_________________________________________________________________________________________
Jest… zrobiłem del Avasta i Anty… a nastepnie podłączyłem scan AVG. AVG przeszedł bez przeszkód. Skasowałem wpis w HiJackThis. Zrobiłem restart i… problemu NIEma

A teraz pyt.:
-
Co się stało z “chrymi” plikami z kwarantanny z Avast.
-
To są pliki z kwarantanny AVG
C:\WINDOWS\system32\ipv6monr.dll
C:\System Volume Information_restore{1D46A4W2-7188-4872-A8E0-F3F3FF39FE4E}\RP150\A0130295.dll
C:\WINDOWS\Installer.exe
C:\System Volume Information_restore{1D46A4W2-7188-4872-A8E0-F3F3FF39FE4E}\RP151\A0131418.dll
C:\System Volume Information_restore{1D46A4W2-7188-4872-A8E0-F3F3FF39FE4E}\RP151\A0131431.exe
C:\System Volume Information_restore{1D46A4W2-7188-4872-A8E0-F3F3FF39FE4E}\RP152\A0131486.dll
C:\WINDOWS\System32\AClient.dll
C:\System Volume Information_restore{1D46A4W2-7188-4872-A8E0-F3F3FF39FE4E}\RP152\A0133778.dll
!C:\WINDOWS\System32\gzmrt.dll
C:\System Volume Information_restore{1D46A4W2-7188-4872-A8E0-F3F3FF39FE4E}\RP267\A0200677.DLL
!C:\WINDOWS\System32\advvpi32.dll
!- W “object type” zaznaczone są czerwonym wykrzyknikiem co oznacza “Moved object”
Co z nimi???
W avascie tych system Volume… było ok 15
- Co to za pliki i jak z nimi postępować.
A tak w ogóle to dziękuje Ci za pomoc - dla mnie to czarna magia, a dla Ciebie poświęcenie Twojego czasu na bezinteresowna pomoc - Dzięki.
