ComboFix 08-06-20.4 - Staszek 2008-06-27 7:32:05.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.644 [GMT 2:00] Running from: C:\Documents and Settings\Staszek\Pulpit\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED . /wow section - STAGE 38 pv: No matching processes found Składnia polecenia jest niepoprawna. ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\kmd.exe . ((((((((((((((((((((((((( Files Created from 2008-05-27 to 2008-06-27 ))))))))))))))))))))))))))))))) . 2008-06-26 20:58 . 2008-06-26 20:58 2008-06-26 20:54 . 2008-06-26 20:57 2008-06-26 20:45 . 2008-06-26 20:45 449,462 --a------ C:\HaxFix.exe 2008-06-26 20:40 . 2001-08-17 22:07 55,168 --a–c— C:\WINDOWS\system32\dllcache\aic78u2.sys 2008-06-26 20:40 . 2001-08-17 21:52 12,800 --a–c— C:\WINDOWS\system32\dllcache\aha154x.sys 2008-06-26 20:39 . 2001-10-26 17:30 24,576 --a–c— C:\WINDOWS\system32\dllcache\agcgauge.ax 2008-06-26 20:37 . 2008-04-14 18:29 2,146,816 --a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe 2008-06-26 20:37 . 2001-10-26 17:29 66,048 --a–c— C:\WINDOWS\system32\dllcache\s3legacy.dll 2008-06-23 20:28 . 2008-06-23 20:28 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-06-23 20:28 . 2008-06-23 20:28 1,409 --a------ C:\WINDOWS\QTFont.for 2008-06-23 14:07 . 2008-06-23 14:07 2008-06-16 10:54 . 2008-06-16 10:54 2008-06-12 16:29 . 2008-06-12 16:30 18,289 --a------ C:\WINDOWS\settings 2008-06-11 15:44 . 2008-05-08 16:02 203,136 -----c— C:\WINDOWS\system32\dllcache\rmcast.sys 2008-06-11 15:43 . 2008-06-14 19:36 273,024 -----c— C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-08 18:17 . 2008-06-08 18:23 2008-06-06 10:51 . 2008-06-18 11:25 2008-06-06 10:46 . 2008-06-06 10:49 2008-06-04 12:49 . 2004-08-03 22:31 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys 2008-06-04 12:49 . 2004-08-03 22:31 20,992 --a–c— C:\WINDOWS\system32\dllcache\rtl8139.sys 2008-06-03 12:08 . 2008-06-03 12:08 2008-06-03 00:57 . 2002-12-27 04:41 26,880 --a------ C:\WINDOWS\system32\drivers\VIAAGP1.SYS 2008-06-02 23:47 . 2008-06-02 23:47 2008-06-02 23:47 . 2008-06-02 23:47 2008-06-02 23:47 . 2008-06-02 23:47 2008-06-02 23:43 . 2008-06-02 23:48 2008-06-02 23:36 . 2008-06-02 23:36 2008-06-02 23:23 . 2004-08-04 00:35 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-27 05:17 --------- d-----w C:\Program Files\Trojan Remover 2008-06-25 16:42 --------- d-----w C:\Program Files\English Translator 3 2008-06-21 14:08 --------- d-----w C:\Program Files\NAPI-PROJEKT 2008-06-14 17:36 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-11 14:18 --------- d-----w C:\Program Files\HyCam2 2008-05-26 19:43 --------- d-----w C:\Program Files\SetEditOctagon 2008-05-26 15:53 --------- d-----w C:\Program Files\MarBit 2008-05-26 15:27 --------- d-----w C:\Program Files\ivo 2008-05-26 15:27 --------- d-----w C:\Documents and Settings\Staszek\Dane aplikacji\Expressivo 2008-05-24 07:54 --------- d—a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP 2008-05-20 23:10 --------- d-----w C:\Documents and Settings\Staszek\Dane aplikacji\ATI 2008-05-20 23:07 --------- d-----w C:\Program Files\ATI Technologies 2008-05-20 22:51 --------- d–h--w C:\Program Files\InstallShield Installation Information 2008-05-20 22:42 --------- d-----w C:\Documents and Settings\Staszek\Dane aplikacji\Wildfire 2008-05-19 18:52 --------- d-----w C:\Documents and Settings\Staszek\Dane aplikacji\atitray 2008-05-19 18:40 --------- d-----w C:\Program Files\MultiRes 2008-05-19 18:34 472,576 ----a-w C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe 2008-05-19 18:34 --------- d-----w C:\Program Files\Radeon Omega Drivers 2008-05-16 18:40 --------- d-----w C:\Documents and Settings\Staszek\Dane aplikacji\Skype 2008-05-15 10:38 --------- d-----w C:\Program Files\ESET 2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys 2008-05-08 12:11 --------- d-----w C:\Program Files\HHD Software 2008-05-08 12:01 --------- d-----w C:\Program Files\HP 2008-05-07 05:12 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-06 11:14 --------- d-----w C:\Program Files\MSXML 4.0 2008-05-06 11:14 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2 2008-05-05 15:42 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\HP 2008-05-05 15:38 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard 2008-04-23 07:20 826,368 ----a-w C:\WINDOWS\system32\wininet.dll 2008-04-14 20:51 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe 2008-04-14 20:50 997,888 ----a-w C:\WINDOWS\system32\setupapi.dll 2008-04-14 20:50 424,960 ----a-w C:\WINDOWS\system32\licdll.dll 2008-04-14 17:46 1,804 ----a-w C:\WINDOWS\system32\dcache.bin 2008-04-14 17:26 332,288 ----a-w C:\WINDOWS\system32\netsetup.exe 2008-04-14 17:22 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll 2008-04-14 17:22 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll 2008-04-14 17:22 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll 2008-04-14 17:20 999,936 ----a-w C:\WINDOWS\system32\syssetup.dll 2008-04-14 17:19 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll 2008-04-14 17:18 5,632 ----a-w C:\WINDOWS\system32\wmi.dll 2008-04-14 17:18 1,449,472 ----a-w C:\WINDOWS\system32\winntbbu.dll 2008-04-14 17:17 57,375 ----a-w C:\WINDOWS\system32\odbcji32.dll 2008-04-14 17:13 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll 2008-04-14 17:12 3,584 ----a-w C:\WINDOWS\system32\msafd.dll 2008-04-14 17:06 3,584 ----a-w C:\WINDOWS\system32\icmp.dll 2008-04-14 17:05 9,344 ----a-w C:\WINDOWS\system32\framebuf.dll 2008-04-14 17:03 3,072 ----a-w C:\WINDOWS\system32\dpnlobby.dll 2008-04-14 17:03 3,072 ----a-w C:\WINDOWS\system32\dpnaddr.dll 2008-04-14 17:01 16,896 ----a-w C:\WINDOWS\system32\cfgmgr32.dll 2008-04-14 17:00 285,696 ----a-w C:\WINDOWS\system32\atmfd.dll 2008-04-14 16:30 2,190,336 ----a-w C:\WINDOWS\system32\ntoskrnl.exe 2008-04-14 16:29 2,067,200 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe 2008-04-14 16:25 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll 2008-04-14 16:22 89,600 ------w C:\WINDOWS\system32\msxml6r.dll 2008-04-14 16:20 80,896 ------w C:\WINDOWS\system32\msshavmsg.dll 2008-04-14 16:15 49,664 ----a-w C:\WINDOWS\system32\inetres.dll 2008-04-14 16:13 563,200 ----a-w C:\WINDOWS\system32\shdoclc.dll 2008-04-14 16:07 10,240 ----a-w C:\WINDOWS\system32\gpkrsrc.dll 2008-04-14 16:05 67,584 ----a-w C:\WINDOWS\system32\browselc.dll 2008-04-14 16:05 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys 2008-04-14 15:59 103,936 ----a-w C:\WINDOWS\system32\dpcdll.dll 2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys 2008-04-13 18:40 427,008 ----a-w C:\WINDOWS\system32\xpob2res.dll 2008-04-13 18:37 2,953,216 ----a-w C:\WINDOWS\system32\xpsp2res.dll 2008-04-13 18:35 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll 2008-04-13 18:35 194,560 ----a-w C:\WINDOWS\system32\xpsp1res.dll 2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll 2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll 2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll 2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll 2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll 2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll 2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll 2008-04-13 16:48 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll 2008-04-13 16:45 216,064 ----a-w C:\WINDOWS\system32\moricons.dll 2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll 2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll 2008-04-09 22:58 4,608 ----a-w C:\WINDOWS\system32\w95inf32.dll 2008-04-09 22:58 2,272 ----a-w C:\WINDOWS\system32\w95inf16.dll 2008-04-03 20:01 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe 2008-03-29 15:23 691,545 ----a-w C:\WINDOWS\unins001.exe 2008-02-20 19:01 22,328 ----a-w C:\Documents and Settings\Staszek\Dane aplikacji\PnkBstrK.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2008-04-14 19:21 15360] “SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search Destroy\TeaTimer.exe” [2008-01-28 12:43 2097488] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-11-14 12:54 2131392] “Expressivo”=“C:\Program Files\ivo\Expressivo\expressivo.exe” [2007-12-07 16:26 2031616] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“SOUNDMAN.EXE” [2003-01-07 12:09 46592 C:\WINDOWS\SOUNDMAN.EXE] “NeroFilterCheck”=“C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe” [2006-01-12 17:40 155648] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe” [2005-03-04 04:36 36975] “CloneCDTray”=“C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” [2005-05-19 15:47 57344] “AnyDVD”=“C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe” [2007-12-01 18:51 469504] “DAEMON Tools”=“C:\Program Files\DAEMON Tools\daemon.exe” [2006-09-14 22:09 157592] “TrojanScanner”=“C:\Program Files\Trojan Remover\Trjscan.exe” [2007-11-02 16:18 524368] “egui”=“C:\Program Files\ESET\ESET Smart Security\egui.exe” [2008-02-20 12:06 1443072] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2008-03-27 08:35 36352] “Ad Muncher”=“C:\Program Files\Ad Muncher\AdMunch.exe” [2007-11-03 12:48 779776] “ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” [2006-01-02 17:41 45056] “NodLogin”=“C:\Program Files\ESET\ESET Smart Security\nodlogin.exe” [2008-06-03 21:12 343982] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2008-04-14 19:21 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] “vidc.iv31”= C:\WINDOWS\system32\ir32_32.dll “vidc.iv32”= C:\WINDOWS\system32\ir32_32.dll “VIDC.X264”= x264vfw.dll “VIDC.3iv2”= 3ivxVfWCodec.dll [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile] “EnableFirewall”= 0 (0x0) [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] “%windir%\system32\sessmgr.exe”= “%windir%\Network Diagnostic\xpnetdiag.exe”= “C:\Program Files\Gadu-Gadu\gg.exe”= “C:\Documents and Settings\All Users\Dokumenty\SBCL PREMIERE tomek.wysoka\SBCL vPlug1.6.7\SBCL v1.1b.exe”= “C:\totalcmd\TOTALCMD.EXE”= “E:\Program Files\EA GAMES\Need For Speed Underground\Speed.exe”= “C:\WINDOWS\system32\PnkBstrA.exe”= “C:\WINDOWS\system32\PnkBstrB.exe”= “C:\Program Files\Skype\Phone\Skype.exe”= [HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] “26448:TCP”= 26448:TCP:BitComet 26448 TCP “26448:UDP”= 26448:UDP:BitComet 26448 UDP R1 atitray;atitray;C:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [2007-11-05 09:55] R2 amdfix;amdfix;C:\WINDOWS\system32\drivers\amdfix.sys [2007-05-22 18:17] R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2008-04-14 19:21] R2 xinstall;xinstall;C:\WINDOWS\system32\drivers\xinstall.sys [2007-05-22 18:17] S3 UsbSagCom;Mobile Device Full USB Driver;C:\WINDOWS\system32\DRIVERS\UsbSagCom.sys [2007-06-29 15:20] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the ‘Scheduled Tasks’ folder “2008-06-20 16:15:46 C:\WINDOWS\Tasks\1-Click Maintenance.job” - C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-27 07:33:35 Windows 5.1.2600 Dodatek Service Pack 3 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-06-27 7:34:58 ComboFix-quarantined-files.txt 2008-06-27 05:34:47 Pre-Run: 7,624,339,456 bajtów wolnych Post-Run: 7,646,072,832 bajtów wolnych 201 — E O F — 2008-06-20 12:43:40 Jeśli źle wkleiłem to wybaczcie Pozdrawiam.