usunalem za pomoca OTMoveIt, potem SDFix, a nastepnie uzylem Gmera, oto posty:
-
nie wykryl zadnych zmian w systemie
-
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-07-18 19:14:01
Windows 5.1.2600
---- Services - GMER 1.0.13 ----
Service .NET CLR Data
Service .NET CLR Networking
Service .NETFramework
Service C:\WINDOWS\services.exe [DISABLED] A-Load
Service [sYSTEM] Aavmker4
Service [DISABLED] Abiosdsk
Service [DISABLED] abp480n5
Service C:\WINDOWS\System32\DRIVERS\ACPI.sys [bOOT] ACPI
Service [DISABLED] ACPIEC
Service System32\Drivers\adildr.sys [AUTO] ADILOADER
Service System32\DRIVERS\adiusbaw.sys [MANUAL] adiusbaw
Service C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [MANUAL] Adobe LM Service
Service [DISABLED] adpu160m
Service C:\WINDOWS\system32\drivers\aec.sys [MANUAL] aec
Service C:\WINDOWS\System32\drivers\afd.sys [AUTO] AFD
Service [DISABLED] Aha154x
Service [DISABLED] aic78u2
Service [DISABLED] aic78xx
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Alerter
Service C:\WINDOWS\System32\alg.exe [MANUAL] ALG
Service [DISABLED] AliIde
Service [DISABLED] amsint
Service C:\WINDOWS\system32\svchost.exe [MANUAL] AppMgmt
Service [DISABLED] asc
Service [DISABLED] asc3350p
Service [DISABLED] asc3550
Service [AUTO] asc3550u
Service ASP.NET
Service ASP.NET_1.1.4322
Service C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [MANUAL] aspnet_state
Service [AUTO] aswMon2
Service [MANUAL] aswRdr
Service [sYSTEM] aswTdi
Service C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [AUTO] aswUpdSv
Service C:\WINDOWS\System32\DRIVERS\asyncmac.sys [MANUAL] AsyncMac
Service C:\WINDOWS\System32\DRIVERS\atapi.sys [bOOT] atapi
Service [DISABLED] Atdisk
Service C:\WINDOWS\System32\DRIVERS\atmarpc.sys [MANUAL] Atmarpc
Service C:\WINDOWS\System32\svchost.exe [AUTO] AudioSrv
Service C:\WINDOWS\System32\DRIVERS\audstub.sys [MANUAL] audstub
Service C:\Program Files\Alwil Software\Avast4\ashServ.exe [AUTO] avast! Antivirus
Service C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [MANUAL] avast! Web Scanner
Service C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys [sYSTEM] AVG Anti-Spyware Driver
Service C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe [AUTO] AVG Anti-Spyware Guard
Service C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys [sYSTEM] AvgAsCln
Service BattC
Service [sYSTEM] Beep
Service C:\WINDOWS\System32\svchost.exe [AUTO] BITS
Service C:\WINDOWS\System32\svchost.exe [AUTO] Browser
Service [DISABLED] cbidf2k
Service [DISABLED] cd20xrnt
Service [sYSTEM] Cdaudio
Service [DISABLED] Cdfs
Service C:\WINDOWS\System32\DRIVERS\cdrom.sys [sYSTEM] Cdrom
Service [sYSTEM] Changer
Service C:\WINDOWS\system32\cisvc.exe [MANUAL] cisvc
Service C:\WINDOWS\system32\clipsrv.exe [MANUAL] ClipSrv
Service [DISABLED] CmdIde
Service C:\WINDOWS\System32\dllhost.exe [MANUAL] COMSysApp
Service ContentFilter
Service ContentIndex
Service [DISABLED] Cpqarray
Service C:\WINDOWS\system32\svchost.exe [AUTO] CryptSvc
Service C:\WINDOWS\System32\drivers\ctac32k.sys [MANUAL] ctac32k
Service C:\WINDOWS\system32\drivers\ctaud2k.sys [MANUAL] ctaud2k
Service C:\WINDOWS\System32\DRIVERS\ctljystk.sys [MANUAL] ctljystk
Service ctlntsvc
Service C:\WINDOWS\System32\drivers\ctprxy2k.sys [MANUAL] ctprxy2k
Service C:\WINDOWS\System32\drivers\ctsfm2k.sys [MANUAL] ctsfm2k
Service [DISABLED] dac2w2k
Service [DISABLED] dac960nt
Service C:\WINDOWS\System32\svchost.exe [AUTO] Dhcp
Service C:\WINDOWS\System32\DRIVERS\disk.sys [bOOT] Disk
Service C:\WINDOWS\System32\dmadmin.exe [MANUAL] dmadmin
Service C:\WINDOWS\System32\drivers\dmboot.sys [DISABLED] dmboot
Service C:\WINDOWS\System32\drivers\dmio.sys [bOOT] dmio
Service C:\WINDOWS\System32\drivers\dmload.sys [bOOT] dmload
Service C:\WINDOWS\System32\svchost.exe [AUTO] dmserver
Service C:\WINDOWS\system32\drivers\DMusic.sys [MANUAL] DMusic
Service C:\WINDOWS\System32\svchost.exe [AUTO] Dnscache
Service [DISABLED] dpti2o
Service C:\WINDOWS\system32\drivers\drmkaud.sys [MANUAL] drmkaud
Service C:\WINDOWS\system32\drivers\emu10k1m.sys [MANUAL] emu10k
Service C:\WINDOWS\system32\drivers\ctlfacem.sys [MANUAL] emu10k1
Service C:\WINDOWS\System32\drivers\emupia2k.sys [MANUAL] emupia
Service C:\WINDOWS\System32\svchost.exe [AUTO] ERSvc
Service C:\WINDOWS\system32\services.exe [AUTO] Eventlog
Service C:\WINDOWS\System32\svchost.exe [MANUAL] EventSystem
Service [DISABLED] Fastfat
Service C:\WINDOWS\System32\svchost.exe [MANUAL] FastUserSwitchingCompatibility
Service C:\WINDOWS\System32\DRIVERS\fdc.sys [MANUAL] Fdc
Service [sYSTEM] Fips
Service C:\WINDOWS\System32\DRIVERS\flpydisk.sys [MANUAL] Flpydisk
Service [sYSTEM] Fs_Rec
Service C:\WINDOWS\System32\DRIVERS\ftdisk.sys [bOOT] Ftdisk
Service C:\WINDOWS\System32\DRIVERS\gameenum.sys [MANUAL] gameenum
Service C:\WINDOWS\System32\DRIVERS\gmer.sys [MANUAL] gmer
Service C:\WINDOWS\System32\DRIVERS\msgpc.sys [MANUAL] Gpc
Service System32\DRIVERS\GT680x.SYS [MANUAL] GT680x
Service C:\WINDOWS\system32\drivers\ha10kx2k.sys [MANUAL] ha10kx2k
Service C:\WINDOWS\System32\svchost.exe [AUTO] helpsvc
Service C:\WINDOWS\System32\svchost.exe [DISABLED] HidServ
Service C:\WINDOWS\System32\DRIVERS\hidusb.sys [MANUAL] hidusb
Service C:\WINDOWS\System32\drivers\HPFECP16.SYS [AUTO] HPFECP16
Service [DISABLED] hpn
Service [DISABLED] hpt3xx
Service [sYSTEM] i2omgmt
Service [DISABLED] i2omp
Service C:\WINDOWS\System32\DRIVERS\i8042prt.sys [sYSTEM] i8042prt
Service C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [MANUAL] IDriverT
Service [sYSTEM] Imapi
Service C:\WINDOWS\System32\imapi.exe [MANUAL] ImapiService
Service inetaccs
Service [DISABLED] ini910u
Service Inport
Service [DISABLED] IntelIde
Service C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys [MANUAL] IpFilterDriver
Service C:\WINDOWS\System32\DRIVERS\ipinip.sys [MANUAL] IpInIp
Service C:\WINDOWS\System32\DRIVERS\ipnat.sys [MANUAL] IpNat
Service C:\WINDOWS\System32\DRIVERS\ipsec.sys [sYSTEM] IPSec
Service C:\WINDOWS\System32\DRIVERS\irenum.sys [MANUAL] IRENUM
Service ISAPISearch
Service C:\WINDOWS\System32\DRIVERS\isapnp.sys [bOOT] isapnp
Service C:\WINDOWS\System32\DRIVERS\kbdclass.sys [sYSTEM] Kbdclass
Service C:\WINDOWS\system32\drivers\kmixer.sys [MANUAL] kmixer
Service [bOOT] KSecDD
Service C:\WINDOWS\System32\DRIVERS\L8042Kbd.sys [MANUAL] L8042Kbd
Service C:\WINDOWS\System32\DRIVERS\L8042mou.Sys [MANUAL] L8042mou
Service C:\WINDOWS\System32\svchost.exe [AUTO] lanmanserver
Service C:\WINDOWS\System32\svchost.exe [AUTO] lanmanworkstation
Service [sYSTEM] lbrtfdc
Service ldap
Service LHidKe
Service LicenseService
Service C:\WINDOWS\System32\svchost.exe [AUTO] LmHosts
Service C:\WINDOWS\System32\DRIVERS\LMouKE.Sys [MANUAL] LMouKE
Service C:\WINDOWS\System32\svchost.exe [DISABLED] Messenger
Service [sYSTEM] mnmdd
Service C:\WINDOWS\System32\mnmsrvc.exe [MANUAL] mnmsrvc
Service [MANUAL] Modem
Service C:\WINDOWS\System32\DRIVERS\mouclass.sys [sYSTEM] Mouclass
Service C:\WINDOWS\System32\DRIVERS\mouhid.sys [MANUAL] mouhid
Service [bOOT] MountMgr
Service [DISABLED] mraid35x
Service C:\WINDOWS\System32\DRIVERS\mrxdav.sys [MANUAL] MRxDAV
Service C:\WINDOWS\System32\DRIVERS\mrxsmb.sys [sYSTEM] MRxSmb
Service C:\WINDOWS\System32\msdtc.exe [MANUAL] MSDTC
Service [sYSTEM] Msfs
Service C:\WINDOWS\System32\msiexec.exe [MANUAL] MSIServer
Service C:\WINDOWS\system32\drivers\MSKSSRV.sys [MANUAL] MSKSSRV
Service C:\WINDOWS\system32\drivers\MSPCLOCK.sys [MANUAL] MSPCLOCK
Service C:\WINDOWS\system32\drivers\MSPQM.sys [MANUAL] MSPQM
Service C:\WINDOWS\System32\mswsag.sys [sYSTEM] mswsag
Service C:\WINDOWS\system32\drivers\msmpu401.sys [MANUAL] ms_mpu401
Service [bOOT] Mup
Service [bOOT] NDIS
Service C:\WINDOWS\System32\DRIVERS\NetMotCM.sys [MANUAL] ndiscm
Service C:\WINDOWS\System32\DRIVERS\ndistapi.sys [MANUAL] NdisTapi
Service C:\WINDOWS\System32\DRIVERS\ndisuio.sys [MANUAL] Ndisuio
Service C:\WINDOWS\System32\DRIVERS\ndiswan.sys [MANUAL] NdisWan
Service [MANUAL] NDProxy
Service C:\WINDOWS\System32\DRIVERS\netbios.sys [sYSTEM] NetBIOS
Service C:\WINDOWS\System32\DRIVERS\netbt.sys [DISABLED] NetBT
Service C:\WINDOWS\system32\netdde.exe [MANUAL] NetDDE
Service C:\WINDOWS\system32\netdde.exe [MANUAL] NetDDEdsdm
Service C:\WINDOWS\System32\lsass.exe [MANUAL] Netlogon
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Netman
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Nla
Service [sYSTEM] Npfs
Service [DISABLED] Ntfs
Service C:\WINDOWS\System32\lsass.exe [MANUAL] NtLmSsp
Service C:\WINDOWS\system32\svchost.exe [MANUAL] NtmsSvc
Service [sYSTEM] Null
Service NULLPROTO
Service C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [MANUAL] nv
Service nv4
Service C:\WINDOWS\System32\nvsvc32.exe [AUTO] NVSvc
Service C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys [MANUAL] NwlnkFlt
Service C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys [MANUAL] NwlnkFwd
Service C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [MANUAL] ose
Service C:\WINDOWS\system32\drivers\ctoss2k.sys [MANUAL] ossrv
Service Outlook
Service C:\WINDOWS\System32\DRIVERS\parport.sys [MANUAL] Parport
Service [bOOT] PartMgr
Service [AUTO] ParVdm
Service C:\WINDOWS\System32\DRIVERS\PavProc.sys [AUTO] PavProc
Service C:\WINDOWS\System32\DRIVERS\pci.sys [bOOT] PCI
Service [sYSTEM] PCIDump
Service [DISABLED] PCIIde
Service [DISABLED] Pcmcia
Service [MANUAL] PDCOMP
Service [MANUAL] PDFRAME
Service [MANUAL] PDRELI
Service [MANUAL] PDRFRAME
Service [DISABLED] perc2
Service [DISABLED] perc2hib
Service PerfDisk
Service PerfNet
Service PerfOS
Service PerfProc
Service C:\WINDOWS\system32\drivers\pfc.sys [MANUAL] pfc
Service C:\WINDOWS\system32\services.exe [AUTO] PlugPlay
Service C:\WINDOWS\System32\lsass.exe [AUTO] PolicyAgent
Service C:\WINDOWS\System32\DRIVERS\raspptp.sys [MANUAL] PptpMiniport
Service C:\WINDOWS\System32\DRIVERS\processr.sys [sYSTEM] Processor
Service C:\WINDOWS\system32\lsass.exe [AUTO] ProtectedStorage
Service C:\WINDOWS\System32\DRIVERS\psched.sys [MANUAL] PSched
Service C:\WINDOWS\System32\DRIVERS\ptilink.sys [MANUAL] Ptilink
Service C:\WINDOWS\System32\DRIVERS\PxHelp20.sys [bOOT] PxHelp20
Service [DISABLED] ql1080
Service [DISABLED] Ql10wnt
Service [DISABLED] ql12160
Service [DISABLED] ql1240
Service [DISABLED] ql1280
Service C:\WINDOWS\System32\DRIVERS\rasacd.sys [sYSTEM] RasAcd
Service C:\WINDOWS\System32\svchost.exe [MANUAL] RasAuto
Service C:\WINDOWS\System32\DRIVERS\rasl2tp.sys [MANUAL] Rasl2tp
Service C:\WINDOWS\System32\svchost.exe [MANUAL] RasMan
Service C:\WINDOWS\System32\DRIVERS\raspppoe.sys [MANUAL] RasPppoe
Service C:\WINDOWS\System32\DRIVERS\raspti.sys [MANUAL] Raspti
Service C:\WINDOWS\System32\DRIVERS\rdbss.sys [sYSTEM] Rdbss
Service C:\WINDOWS\System32\DRIVERS\RDPCDD.sys [sYSTEM] RDPCDD
Service RDPDD
Service C:\WINDOWS\System32\DRIVERS\rdpdr.sys [MANUAL] rdpdr
Service RDPNP
Service [MANUAL] RDPWD
Service C:\WINDOWS\system32\sessmgr.exe [MANUAL] RDSessMgr
Service C:\WINDOWS\System32\DRIVERS\redbook.sys [sYSTEM] redbook
Service C:\WINDOWS\System32\svchost.exe [DISABLED] RemoteAccess
Service C:\WINDOWS\system32\svchost.exe [AUTO] RemoteRegistry
Service C:\WINDOWS\System32\locator.exe [MANUAL] RpcLocator
Service C:\WINDOWS\system32\svchost.exe [AUTO] RpcSs
Service C:\WINDOWS\System32\rsvp.exe [MANUAL] RSVP
Service C:\WINDOWS\system32\lsass.exe [AUTO] SamSs
Service C:\Program [AUTO] SansaService
Service C:\WINDOWS\System32\SCardSvr.exe [MANUAL] SCardDrv
Service C:\WINDOWS\System32\SCardSvr.exe [MANUAL] SCardSvr
Service C:\WINDOWS\System32\svchost.exe [AUTO] Schedule
Service C:\WINDOWS\System32\DRIVERS\secdrv.sys [AUTO] Secdrv
Service C:\WINDOWS\System32\svchost.exe [AUTO] seclogon
Service C:\WINDOWS\system32\svchost.exe [AUTO] SENS
Service C:\WINDOWS\System32\DRIVERS\serenum.sys [MANUAL] serenum
Service C:\WINDOWS\System32\DRIVERS\serial.sys [sYSTEM] Serial
Service [sYSTEM] Sfloppy
Service C:\WINDOWS\system32\drivers\sfmanm.sys [MANUAL] sfman
Service C:\WINDOWS\System32\svchost.exe [AUTO] SharedAccess
Service C:\WINDOWS\System32\svchost.exe [AUTO] ShellHWDetection
Service [DISABLED] Simbad
Service [DISABLED] Sparrow
Service C:\WINDOWS\system32\drivers\splitter.sys [MANUAL] splitter
Service C:\WINDOWS\system32\spoolsv.exe [AUTO] Spooler
Service C:\WINDOWS\System32\DRIVERS\sr.sys [bOOT] sr
Service C:\WINDOWS\System32\svchost.exe [AUTO] srservice
Service C:\WINDOWS\System32\DRIVERS\srv.sys [MANUAL] Srv
Service C:\WINDOWS\System32\svchost.exe [MANUAL] SSDPSRV
Service C:\WINDOWS\System32\DRIVERS\st3tgbus.sys [MANUAL] st3tgbus
Service C:\WINDOWS\System32\DRIVERS\st3tiger.sys [MANUAL] st3tiger
Service C:\WINDOWS\System32\svchost.exe [AUTO] stisvc
Service [MANUAL] svcWRSSSDK
Service C:\WINDOWS\System32\DRIVERS\swenum.sys [MANUAL] swenum
Service C:\WINDOWS\system32\drivers\swmidi.sys [MANUAL] swmidi
Service C:\WINDOWS\System32\dllhost.exe [MANUAL] SwPrv
Service [DISABLED] symc810
Service [DISABLED] symc8xx
Service [DISABLED] sym_hi
Service [DISABLED] sym_u3
Service C:\WINDOWS\system32\drivers\sysaudio.sys [MANUAL] sysaudio
Service C:\WINDOWS\system32\smlogsvc.exe [MANUAL] SysmonLog
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TapiSrv
Service C:\WINDOWS\System32\DRIVERS\tcpip.sys [sYSTEM] Tcpip
Service [MANUAL] TDPIPE
Service [MANUAL] TDTCP
Service C:\WINDOWS\System32\DRIVERS\termdd.sys [sYSTEM] TermDD
Service C:\WINDOWS\System32\svchost.exe [MANUAL] TermService
Service C:\WINDOWS\System32\svchost.exe [AUTO] Themes
Service C:\WINDOWS\System32\tlntsvr.exe [MANUAL] TlntSvr
Service [DISABLED] TosIde
Service C:\WINDOWS\system32\svchost.exe [AUTO] TrkWks
Service TSDDD
Service [DISABLED] Udfs
Service [DISABLED] ultra
Service C:\WINDOWS\System32\DRIVERS\update.sys [MANUAL] Update
Service C:\WINDOWS\System32\svchost.exe [AUTO] uploadmgr
Service C:\WINDOWS\System32\svchost.exe [DISABLED] upnphost
Service C:\WINDOWS\System32\ups.exe [MANUAL] UPS
Service C:\WINDOWS\System32\DRIVERS\Sacm2A.sys [MANUAL] USBCM
Service C:\WINDOWS\System32\DRIVERS\usbhub.sys [MANUAL] usbhub
Service C:\WINDOWS\System32\DRIVERS\usbscan.sys [MANUAL] usbscan
Service C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [MANUAL] USBSTOR
Service C:\WINDOWS\System32\DRIVERS\usbuhci.sys [MANUAL] usbuhci
Service VFILT
Service C:\WINDOWS\System32\drivers\vga.sys [sYSTEM] VgaSave
Service C:\WINDOWS\System32\DRIVERS\viaagp.sys [bOOT] viaagp
Service C:\WINDOWS\System32\DRIVERS\viaagp1.sys [bOOT] viaagp1
Service C:\WINDOWS\System32\DRIVERS\viaidexp.sys [bOOT] ViaIde
Service [bOOT] VolSnap
Service C:\WINDOWS\System32\vsdatant.sys [sYSTEM] vsdatant
Service C:\WINDOWS\system32\ZoneLabs\vsmon.exe [AUTO] vsmon
Service C:\WINDOWS\System32\vssvc.exe [MANUAL] VSS
Service VXD
Service C:\WINDOWS\System32\svchost.exe [DISABLED] W32Time
Service W3SVC
Service C:\WINDOWS\System32\DRIVERS\wanarp.sys [MANUAL] Wanarp
Service [MANUAL] WDICA
Service C:\WINDOWS\system32\drivers\wdmaud.sys [MANUAL] wdmaud
Service C:\WINDOWS\System32\svchost.exe [AUTO] WebClient
Service C:\WINDOWS\system32\svchost.exe [AUTO] winmgmt
Service [MANUAL] Winsock
Service WinSock2
Service WinTrust
Service C:\WINDOWS\System32\svchost.exe [AUTO] WmdmPmSp
Service C:\WINDOWS\System32\svchost.exe [MANUAL] Wmi
Service WmiApRpl
Service C:\WINDOWS\System32\wbem\wmiapsrv.exe [MANUAL] WmiApSrv
Service C:\WINDOWS\System32\drivers\ws2ifsl.sys [DISABLED] WS2IFSL
Service C:\WINDOWS\System32\mswsaf.sys [AUTO] wsmsag
Service C:\WINDOWS\system32\svchost.exe [AUTO] wuauserv
Service C:\WINDOWS\System32\svchost.exe [AUTO] WZCSVC
Service {0BD767F7-DB39-4C4D-B31E-59EEE9773F97}
Service {56F2FE94-0C95-4358-B4F2-B0D3201C11A9}
---- EOF - GMER 1.0.13 ----
ponizej zamieszczam tez ostatni log z Combofixa:
((((((((((((((((((((((((( Files Created from 2007-06-18 to 2007-07-18 )))))))))))))))))))))))))))))))
2007-07-18 18:51 59,104 --a------ C:\WINDOWS\system32\drivers\asc3550u.sys
2007-07-13 16:53
2007-07-13 16:49 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-28 23:34 90,112 --a------ C:\WINDOWS\system32\RegDACL.exe
2007-06-28 23:34 9,006 --a------ C:\clean.bat
2007-06-28 23:34 86,528 --a------ C:\WINDOWS\system32\catchme.exe
2007-06-28 23:34 53,248 --a------ C:\WINDOWS\system32\process.exe
2007-06-28 23:34 4,096 --a------ C:\WINDOWS\system32\reboot.exe
2007-06-24 22:01 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-24 21:56
2007-06-24 21:52 53,248 --a------ C:\WINDOWS\system32\KemXML.dll
2007-06-24 21:52 51,712 --a------ C:\WINDOWS\system32\drivers\i8042prt.sys
2007-06-24 21:52 23,808 --a------ C:\WINDOWS\system32\drivers\kbdclass.sys
2007-06-24 21:52 22,272 --a------ C:\WINDOWS\system32\drivers\mouclass.sys
2007-06-24 21:52 155,648 --a------ C:\WINDOWS\system32\kemutb.dll
2007-06-24 21:52 126,976 --a------ C:\WINDOWS\system32\KemUtil.dll
2007-06-24 21:52 110,592 --a------ C:\WINDOWS\system32\KemWnd.dll
2007-06-24 21:51 94,208 --a------ C:\WINDOWS\KHALMNPR.Exe
2007-06-24 21:51 69,760 --a------ C:\WINDOWS\system32\drivers\LMouKE.Sys
2007-06-24 21:51 55,808 --a------ C:\WINDOWS\system32\drivers\L8042mou.Sys
2007-06-24 21:51 13,568 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.sys
2007-06-24 21:51
2007-06-24 21:51
2007-06-22 00:58
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-18 16:47:26 -------- d-----w C:\Program Files\PestPatrol
2007-07-15 20:38:16 67,298 ----a-w C:\WINDOWS\system32\perfc015.dat
2007-07-15 20:38:16 436,322 ----a-w C:\WINDOWS\system32\perfh015.dat
2007-06-25 15:57:52 -------- d-----w C:\Program Files\Hitman Pro
2007-06-24 19:51:29 -------- d–h--w C:\Program Files\InstallShield Installation Information
2007-06-20 15:45:30 59,104 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-06-10 20:32:55 -------- d-----w C:\Program Files\DC++
2007-05-18 20:30:56 -------- d-----w C:\Program Files\Winamp
2007-05-15 22:00:09 12 ----a-w C:\WINDOWS\system32\sl.bin
2007-05-08 16:19:36 164 ----a-w C:\install.dat
2007-05-07 21:42:15 0 ----a-w C:\WINDOWS\system32\kgctini.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [2003-11-04 01:17]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“PestPatrol Control Center”=“C:\PROGRA~1\PESTPA~1\PPControl.exe” [2004-11-15 11:49]
“CookiePatrol”=“C:\PROGRA~1\PESTPA~1\CookiePatrol.exe” [2005-01-10 09:35]
“TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2005-07-11 18:14]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-01-15 19:28]
[HKEY_USERS.default\software\microsoft\windows\currentversion\run]
“Norton SystemWorks”=“C:\Program Files\Norton SystemWorks\cfgwiz.exe” /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoBandCustomize”=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
“{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [2007-05-30 14:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
“System”=“csxue.exe”
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\mswsag.sys]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Arek^Menu Start^Programy^Autostart^Adobe Gamma.lnk]
path=C:\Documents and Settings\Arek\Menu Start\Programy\Autostart\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Arek^Menu Start^Programy^Autostart^OpenOffice.ux.pl 2.0.2.lnk]
path=C:\Documents and Settings\Arek\Menu Start\Programy\Autostart\OpenOffice.ux.pl 2.0.2.lnk
backup=C:\WINDOWS\pss\OpenOffice.ux.pl 2.0.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg!AVG Anti-Spyware]
“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDElbyCDFL]
“C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe” /L ElbyCDFL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
“C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
“C:\Program Files\D-Tools\daemon.exe” -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Device Detector]
“C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe” -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
KHALMNPR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
“C:\Program Files\Messenger\msmsgs.exe” /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 9.0]
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
“C:\Program Files\QuickTime\qttask.exe” -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
“C:\Program Files\Real\RealPlayer\realplay.exe” /RunUPGToolCommandReBoot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDFix]
C:\SDFix\RunThis.bat /second
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VaCtrls]
v7
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDVDPatch]
CTHELPER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
“C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe”
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-18 18:57:54
Windows 5.1.2600 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
C:\WINDOWS\system32\nmk4.dat
C:\WINDOWS\system32\mswsag.sys
C:\WINDOWS\system32\qo.dll
C:\WINDOWS\system32\qo.sys
C:\WINDOWS\system32\wsmsag.sys
scan completed successfully
hidden files: 5
**************************************************************************
Completion time: 2007-07-18 18:58:42
C:\ComboFix-quarantined-files.txt … 2007-07-12 12:57
C:\ComboFix2.txt … 2007-07-17 17:36
C:\ComboFix3.txt … 2007-07-12 12:57
— E O F —
Co ciekawe 5 hidden files :
C:\WINDOWS\system32\nmk4.dat
C:\WINDOWS\system32\mswsag.sys
C:\WINDOWS\system32\qo.dll
C:\WINDOWS\system32\qo.sys
C:\WINDOWS\system32\wsmsag.sys
nie mogl usunac OTMOveIt bo… ich nie znalazl.
Niestety w dalszym ciagu nie wyswietla mi zadnej strony z netu lub tez komp sie wylacza jak klikam na IE (tzn. znika obraz na monitorze i musze resetowac kompa, bo wlasciwie w ten sposob to sie zawsze odbywa )
Pliz help!