oto log :
ComboFix 08-07-02.3 - Administrator 2008-07-03 8:55:26.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.130 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Pulpit\Combo-Fix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((( Files Created from 2008-06-03 to 2008-07-03 )))))))))))))))))))))))))))))))
.
2008-07-03 08:30 . 2008-07-03 08:30
2008-07-02 17:15 . 2008-07-02 17:15
2008-07-02 17:15 . 2008-07-02 17:15
2008-07-02 12:14 . 2008-07-02 12:14 0 --a------ C:\12
2008-06-29 21:14 . 2008-06-29 21:14
2008-06-29 21:01 . 2008-06-29 21:11
2008-06-24 19:30 . 2008-06-24 19:30
2008-06-22 09:31 . 2008-07-02 18:15
2008-06-22 09:30 . 2008-07-02 12:14
2008-06-21 21:01 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-21 20:54 . 2008-06-21 21:01
2008-06-21 20:51 . 2008-06-21 20:51
2008-06-21 13:50 . 2008-06-22 22:43
2008-06-18 13:57 . 2008-06-18 18:03
2008-06-18 13:43 . 2008-06-18 13:43
2008-06-16 18:15 . 2008-06-25 19:02
2008-06-16 16:44 . 2008-06-16 16:55
2008-06-15 18:45 . 2008-06-15 18:45
2008-06-15 08:39 . 2008-06-15 08:39
2008-06-15 08:38 . 2008-06-18 18:03
2008-06-14 12:56 . 2008-06-14 12:56
2008-06-14 12:56 . 2008-06-14 12:56
2008-06-12 17:07 . 2007-03-08 01:51 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-06-11 14:26 . 2008-05-08 14:14 203,008 -----c— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-11 14:25 . 2008-06-14 20:01 273,024 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 14:25 . 2008-06-14 20:01 273,024 -----c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-07 20:30 . 2008-06-07 20:30
2008-06-06 20:29 . 2008-06-07 08:16
2008-06-06 20:28 . 2008-07-03 08:18
2008-06-06 20:25 . 2008-06-06 20:27
2008-06-06 20:25 . 2008-06-06 20:24 6,144 --a------ C:\WINDOWS\system32\drivers\k750cm.sys
2008-06-06 20:24 . 2008-06-06 20:25
2008-06-06 20:24 . 2005-07-07 16:25 5,744 -ra------ C:\WINDOWS\system32\drivers\k750wh.sys
2008-06-05 11:26 . 2008-07-02 14:47 93 --a------ C:\WINDOWS\LEXSTAT.INI
2008-06-05 00:13 . 2008-06-05 00:13
2008-06-05 00:12 . 2008-06-30 20:55
2008-06-05 00:06 . 2008-06-05 00:06
2008-06-05 00:05 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-06-05 00:05 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-06-05 00:05 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-06-05 00:00 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-06-04 23:58 . 2008-06-04 23:58
2008-06-04 23:57 . 2008-06-04 23:57
2008-06-04 23:55 . 2008-06-04 23:55
2008-06-04 23:55 . 2008-06-22 22:43
2008-06-04 23:55 . 2006-10-05 04:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-06-04 23:55 . 2006-10-05 04:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-06-04 23:51 . 2008-06-04 23:56
2008-06-04 23:51 . 2008-06-10 13:51
2008-06-04 23:50 . 2008-06-04 23:50
2008-06-04 23:09 . 2008-06-04 23:11
2008-06-04 23:09 . 2006-10-22 15:06 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-06-04 23:09 . 2006-10-22 12:22 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-06-04 23:09 . 2008-07-03 07:09 88,566 --a------ C:\WINDOWS\system32\nvapps.xml
2008-06-04 23:09 . 2006-10-22 12:22 17,056 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-06-04 23:08 . 2008-06-06 20:24
2008-06-04 23:08 . 2008-06-04 23:08
2008-06-04 22:56 . 2006-10-04 16:06 1,197,294 -----c— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-06-04 22:56 . 2006-10-04 16:06 764,868 -----c— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-06-04 22:56 . 2006-10-04 16:06 217,118 -----c— C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-06-04 22:55 . 2008-06-04 22:55
2008-06-04 22:53 . 2008-06-04 22:53
2008-06-04 22:53 . 2008-06-04 22:54
2008-06-04 22:47 . 2008-06-04 22:49
2008-06-04 22:43 . 2007-10-25 18:44 8,488,960 -----c— C:\WINDOWS\system32\dllcache\shell32.dll
2008-06-04 22:42 . 2007-07-09 15:20 582,656 -----c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-06-04 22:37 . 2008-04-23 09:20 6,066,176 -----c— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-06-04 22:37 . 2007-04-17 11:32 2,455,488 -----c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-06-04 22:37 . 2007-03-08 07:11 1,036,288 -----c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-06-04 22:37 . 2008-04-23 09:20 459,264 -----c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-06-04 22:37 . 2008-04-23 09:20 383,488 -----c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-06-04 22:37 . 2008-04-23 09:20 267,776 -----c— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-06-04 22:37 . 2008-04-23 09:20 63,488 -----c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-06-04 22:37 . 2008-04-23 09:20 52,224 -----c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-06-04 22:37 . 2008-04-22 09:39 13,824 -----c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-04 22:35 . 2006-11-07 21:03 33,792 --a–c— C:\WINDOWS\system32\dllcache\custsat.dll
2008-06-04 22:16 . 2008-06-04 22:16 133 --a------ C:\WINDOWS\ODBC.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-04 12:27 --------- d-----w C:\Program Files\Alwil Software
2008-06-04 10:28 --------- d-----w C:\Program Files\Usługi online
2008-05-08 12:14 203,008 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:03 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 07:20 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 01:44 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2008-05-16 01:19 79224]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-10-22 12:22 7700480]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 01:44 15360]
[HKLM~\startupfolder\C:^Documents and Settings^Administrator^Menu Start^Programy^Autostart^spoolsv.exe]
path=C:\Documents and Settings\Administrator\Menu Start\Programy\Autostart\spoolsv.exe
backup=C:\WINDOWS\pss\spoolsv.exeStartup
=
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
–a------ 2004-08-04 01:44 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
–a------ 2006-10-27 00:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a------ 2006-10-22 12:22 7700480 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a------ 2006-10-22 12:22 86016 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a------ 2008-03-25 04:28 144784 C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a------ 2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE”=
“C:\Program Files\Microsoft Office\Office12\GROOVE.EXE”=
“C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE”=
“C:\Program Files\Gadu-Gadu\gg.exe”=
“C:\Program Files\EA SPORTS\FIFA 07\fifa07.exe”=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
S2 AKEProtect;AKEProtect;C:\Program Files\Anti Keylogger Elite\AKEProtect.sys []
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
*Newly Created Service* - CATCHME
.
MSConfigStartUp-AQQ - C:\PROGRA~1\WapSter\AQQ\AQQ.exe
MSConfigStartUp-hosted - C:\Windows\system32\system.exe
MSConfigStartUp-ISS_SIP - C:\Program Files\Anti Keylogger Elite\AKE.exe
MSConfigStartUp-Patched - C:\WINDOWS\patched.exe
MSConfigStartUp-Sony Ericsson PC Suite - C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
MSConfigStartUp-swg - C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
MSConfigStartUp-WinampAgent - C:\Program Files\Winamp\winampa.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-03 08:56:35
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-03 8:57:37
ComboFix-quarantined-files.txt 2008-07-03 06:57:25
Pre-Run: 6,530,887,680 bajtów wolnych
Post-Run: 6,524,006,400 bajtów wolnych
160 — E O F — 2008-06-20 17:15:18
W dniu 03.07.2008 , o godzinie 14:49 został dopisany post przez Ciachoo4you
I jak te logi?