Standardowa diagnostyka nic nie dała…zaraz zarzuce logiem z Combo…
W dniu 29.06.2008 , o godzinie 0:05 został dopisany post przez larry.bigl
ComboFix 08-06-20.4 - Larry 2008-06-28 23:58:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.247 [GMT 2:00]
Running from: C:\Documents and Settings\Larry\Pulpit\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-28 )))))))))))))))))))))))))))))))
.
2008-06-28 19:15 . 2008-06-28 19:15
2008-06-28 17:59 . 2008-06-28 17:59 3,375,681 --a------ C:\WINDOWS{00000000-00000000-0000000A-00001102-00000002-100A1102}.BAK
2008-06-26 15:16 . 2008-06-26 16:01
2008-06-25 23:38 . 2007-03-08 01:51 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-06-25 21:45 . 2007-01-05 17:57 633,344 -ra------ C:\WINDOWS\system32\drivers\cfosspeed.sys
2008-06-25 21:44 . 2008-06-29 00:00
2008-06-25 21:44 . 2007-01-05 18:03 270,336 --a------ C:\WINDOWS\system32\cfosspeed.dll
2008-06-24 23:54 . 2008-06-24 23:54
2008-06-24 14:57 . 2008-06-24 14:57 1,905 --a------ C:\WINDOWS\diagwrn.xml
2008-06-24 14:57 . 2008-06-24 14:57 1,905 --a------ C:\WINDOWS\diagerr.xml
2008-06-22 16:42 . 2005-02-27 21:57 331,776 --a------ C:\WINDOWS\system32\AviSplitter.ax
2008-06-22 16:42 . 2005-03-20 23:54 301,056 --a------ C:\WINDOWS\system32\VSFilter.dll
2008-06-21 10:57 . 2008-06-21 11:00
2008-06-07 18:39 . 2008-06-07 18:39
2008-06-07 13:32 . 2003-08-29 00:55 423,424 --a------ C:\WINDOWS\system32\WMAVDS32.ax
2008-06-07 13:32 . 2001-05-16 16:54 309,616 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-06-07 13:32 . 2001-03-26 03:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2008-06-05 22:05 . 2008-06-26 16:01
2008-06-04 22:21 . 2008-06-04 22:21
2008-05-31 13:13 . 2008-05-31 13:13
2008-05-28 14:27 . 2008-06-28 19:16 102,619 --a------ C:\WINDOWS\system32\oodbs.lor
2008-05-28 13:48 . 2008-05-28 13:48
2008-05-28 12:53 . 2008-05-28 12:53 0 --a------ C:\WINDOWS\oodcnt.INI
2008-05-28 12:45 . 2008-05-28 12:45
2008-05-28 12:44 . 2008-05-28 12:44
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-28 21:55 --------- d-----w C:\Documents and Settings\Larry\Dane aplikacji\foobar2000
2008-06-28 17:17 --------- d-----w C:\Documents and Settings\Larry\Dane aplikacji\The Bat!
2008-06-28 13:50 --------- d-----w C:\Program Files\jv16 PowerTools
2008-06-26 13:11 --------- d-----w C:\Documents and Settings\Larry\Dane aplikacji\uTorrent
2008-06-26 13:09 --------- d-----w C:\Program Files\Common Files\Pointstone
2008-06-26 12:50 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-06-26 12:41 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-06-26 12:41 --------- d-----w C:\Program Files\Creative
2008-06-18 11:37 33 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-06-12 07:04 --------- d-----w C:\Program Files\Picasa2
2008-06-10 17:59 --------- d-----w C:\Program Files\foobar2000
2008-06-04 20:22 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-05-27 15:11 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-05-27 11:52 --------- d-----w C:\Program Files\Gadu-Gadu
2008-05-25 10:20 --------- d-----w C:\Program Files\Common Files\Nero
2008-05-25 10:17 --------- d-----w C:\Program Files\Ahead
2008-05-25 10:16 --------- d-----w C:\Program Files\Common Files\Ahead
2008-05-24 21:46 --------- d-----w C:\Documents and Settings\Larry\Dane aplikacji\Media Player Classic
2008-05-24 16:57 --------- d-----w C:\Program Files\Java
2008-05-24 16:56 --------- d-----w C:\Program Files\Common Files\Java
2008-05-24 12:33 --------- d-----w C:\Documents and Settings\Larry\Dane aplikacji\Teleca
2008-05-24 12:31 --------- d-----w C:\Documents and Settings\Larry\Dane aplikacji\Sony Ericsson
2008-05-24 12:21 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-23 16:07 --------- d-----w C:\Program Files\Google
2008-05-23 08:21 --------- d—a-w C:\Program Files\Ad Muncher
2008-05-22 22:34 --------- d-----w C:\Program Files\Alwil Software
2008-05-22 21:48 --------- d-----w C:\Program Files\uTorrent
2008-05-22 21:40 --------- d-----w C:\Documents and Settings\Larry\Dane aplikacji\Gadu-Gadu
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“thebat_startup”=“C:\Program Files\The Bat!\thebat.exe” [2007-03-27 15:33 11475448]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2008-03-20 12:04 2127296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Ad Muncher”=“C:\Program Files\Ad Muncher\AdMunch.exe” [2007-11-03 12:48 779776]
“cFosSpeed”=“C:\Program Files\cFosSpeed\cFosSpeed.exe” [2007-01-05 18:00 815104]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2008-05-16 01:19 79224]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“vidc.ffds”= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusDisableNotify”=dword:00000001
“UpdatesDisableNotify”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\uTorrent\utorrent.exe”=
“C:\Program Files\Gadu-Gadu\gg.exe”=
“D:\GRY\Disciples II\Discipl2.exe”=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-09-19 11:03]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-09-15 11:07]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{85bff382-2c1e-11dd-9ade-4d6564696130}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe
*Newly Created Service* - ASWUPDSV
*Newly Created Service* - AVAST!_ANTIVIRUS
*Newly Created Service* - AVAST!_MAIL_SCANNER
*Newly Created Service* - AVAST!_WEB_SCANNER
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-29 00:00:25
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-29 0:02:31
ComboFix-quarantined-files.txt 2008-06-28 22:01:34
Pre-Run: 5,488,816,128 bajtów wolnych
Post-Run: 5,486,149,632 bajtów wolnych
116