Log z Combofix.exe
ComboFix 08-07-12.3 - domownicy 2008-07-13 16:57:55.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.355 [GMT 2:00]
Running from: C:\Documents and Settings\domownicy\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\domownicy\Pulpit\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\domownicy\Dane aplikacji\Install.dat
.
---- Previous Run -------
.
C:\Program Files\WebRebates4
C:\Program Files\WebRebates4\README.txt
C:\Program Files\WebRebates4\w11150.exe
C:\Program Files\WebRebates4\webarebates\topr11150.dat
C:\Program Files\WebRebates4\webarebates\toprp11170.dat
C:\Program Files\WebRebates4\webdrebates\Alcia\m46f828a77358.dat
C:\Program Files\WebRebates4\webdrebates\Alcia\w472b3f2f5150.dat
C:\Program Files\WebRebates4\webdrebates\Damian\m46f828a77358.dat
C:\Program Files\WebRebates4\webdrebates\Damian\w472b3f2f5150.dat
C:\Program Files\WebRebates4\webdrebates\domownicy\m46f828a77358.dat
C:\Program Files\WebRebates4\webdrebates\domownicy\w472b3f2f5150.dat
C:\Program Files\WebRebates4\webdrebates\l472b3f322fa8.dat
C:\Program Files\WebRebates4\webdrebates\m46f8289afbe.dat
C:\Program Files\WebRebates4\webdrebates\Mirek\w472b3f2f5150.dat
C:\Program Files\WebRebates4\webdrebates\r472b3f2264b9.dat
C:\Program Files\WebRebates4\webdrebates\v46f828aa632a.dat
C:\Program Files\WebRebates4\webdrebates\webzrebates.dat
C:\Program Files\WebRebates4\webrebates.dll
C:\Program Files\WebRebates4\webrebates.exe
C:\Program Files\WebRebates4\webrebates2.dll
C:\Program Files\WebRebates4\websrebates\Html\ftoprRPMP0.htm
C:\Program Files\WebRebates4\websrebates\Html\ftoprRPMS0.htm
C:\Program Files\WebRebates4\websrebates\Html\ftoprUPMP0.htm
C:\Program Files\WebRebates4\websrebates\Html\ftoprUPMS0.htm
C:\Program Files\WebRebates4\websrebates\Html\toprC0.htm
C:\Program Files\WebRebates4\websrebates\Html\toprP0.htm
C:\Program Files\WebRebates4\websrebates\Html\toprR1.htm
C:\Program Files\WebRebates4\websrebates\Html\toprRPMF0.htm
C:\Program Files\WebRebates4\websrebates\Html\toprUPMF0.htm
C:\Program Files\WebRebates4\websrebates\Html\toprXPMP0.htm
C:\Program Files\WebRebates4\websrebates\Html\toprXPMS0.htm
C:\Program Files\WebRebates4\websrebates\Images\topr_blnk.gif
C:\Program Files\WebRebates4\websrebates\Images\topr_c_envelope.gif
C:\Program Files\WebRebates4\websrebates\Images\topr_c_footer.gif
C:\Program Files\WebRebates4\websrebates\Images\topr_c_hdr_autotrack_remove.gif
C:\Program Files\WebRebates4\websrebates\Images\topr_c_hdr_settings.gif
C:\Program Files\WebRebates4\websrebates\Images\topr_c_hdr_settings_toprebates.gif
C:\Program Files\WebRebates4\websrebates\Images\topr_c_pop_circles.gif
C:\Program Files\WebRebates4\websrebates\Images\topr_c_pop_circles_bg2.gif
C:\Program Files\WebRebates4\websrebates\Images\topr_c_warning.gif
C:\Program Files\WebRebates4\websrebates\websrebates\weblrebates.dat
C:\Program Files\WebRebates4\websrebates\websrebates\webprebates.dat
C:\Program Files\WebRebates4\websrebates\websrebates\websrebates.dat
C:\Program Files\WebRebates4\websrebates\webtrebates\log.txt
C:\WINDOWS\hosts
C:\WINDOWS\system32\h@tkeysh@@k.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-13 to 2008-07-13 )))))))))))))))))))))))))))))))
.
2008-07-13 16:33 . 2008-07-13 16:33
2008-07-07 15:16 . 2008-07-07 15:16
2008-07-06 19:04 . 2008-07-06 19:04
2008-07-05 10:34 . 2008-07-05 10:34
2008-07-05 10:34 . 2008-07-05 10:34
2008-07-05 10:06 . 2008-07-05 10:06
2008-07-05 10:05 . 2008-07-13 17:02
2008-07-05 10:05 . 2008-07-13 17:02
2008-07-05 10:05 . 2008-07-07 14:36
2008-07-05 10:05 . 2008-07-07 14:36
2008-07-05 10:05 . 2005-04-13 19:05
2008-07-05 10:05 . 2005-04-13 19:05
2008-07-05 10:05 . 2008-07-13 16:18
2008-07-05 10:05 . 2008-07-13 16:18
2008-07-05 10:05 . 2008-07-13 15:54
2008-07-05 10:05 . 2008-07-13 15:54
2008-07-05 10:05 . 2005-04-13 20:59
2008-07-05 10:05 . 2005-04-13 20:59
2008-07-05 10:05 . 2008-07-06 13:02
2008-07-05 10:05 . 2008-07-06 13:02
2008-07-05 10:05 . 2008-07-13 16:21
2008-07-04 16:47 . 2008-07-04 16:47 160 --a------ C:\WINDOWS\y.reg
2008-07-04 16:47 . 2008-07-04 16:47 156 --a------ C:\WINDOWS\z.reg
2008-07-04 16:47 . 2008-07-04 16:47 155 --a------ C:\WINDOWS\x.reg
2008-07-04 16:47 . 2008-07-04 16:47 64 --a------ C:\WINDOWS\system_32.bat
2008-07-02 14:44 . 2008-07-02 14:44 280 --a------ C:\WINDOWS\game.ini
2008-06-27 22:18 .
2008-06-27 22:18 .
2008-06-22 18:07 . 2008-06-22 18:32
2008-06-16 20:46 . 2008-06-16 20:46
2008-06-16 18:39 . 2008-06-16 18:39
2008-06-16 18:36 . 2008-06-16 18:39
2008-06-16 18:36 . 2008-06-16 18:36
2008-06-16 18:36 . 2008-06-16 18:36
2008-06-16 18:31 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-06-16 18:26 . 2008-06-16 18:26
2008-06-16 16:37 . 2008-06-16 15:43
2008-06-16 15:51 . 2008-06-16 15:51
2008-06-16 15:51 . 2008-06-16 15:51
2008-06-16 15:44 . 2008-06-16 15:43
2008-06-16 15:36 . 2007-04-05 12:16 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-06-13 16:08 . 2008-06-13 16:08
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-13 12:26 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Avg7
2008-07-04 20:53 --------- d-----w C:\Program Files\FlashGet
2008-07-04 20:21 --------- d-----w C:\Documents and Settings\domownicy\Dane aplikacji\Skype
2008-07-04 14:51 --------- d-----w C:\Program Files\Activision
2008-07-02 12:44 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-06-27 19:59 --------- d-----w C:\Program Files\Football Generation
2008-06-27 19:53 --------- d-----w C:\Documents and Settings\domownicy\Dane aplikacji\OpenOffice.org2
2008-06-16 15:07 --------- d-----w C:\Documents and Settings\Damian\Dane aplikacji\OpenOffice.org2
2008-06-14 18:01 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 01:03 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-06-06 18:44 --------- d-----w C:\Program Files\McDonaldsFairies
2008-06-05 17:19 --------- d-----w C:\Program Files\Sims
2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:03 662,016 ----a-w C:\WINDOWS\system32\wininet.dll
2006-12-13 20:33 34 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\amlistx.dat
2006-12-13 20:33 0 ----a-w C:\Documents and Settings\domownicy\Dane aplikacji\amopn.dat
2006-11-12 13:15 368,678 ----a-w C:\Program Files\Nowe miasto.sc3
2006-04-05 12:38 8,011,748 ----a-w C:\Program Files\Śmieci.zip
2005-12-02 21:28 2,678,784 ----a-w C:\Program Files\Foxit Reader.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-03-12 16:05 25590312]
“ares”=“C:\Program Files\Ares\Ares.exe” [2007-05-04 02:32 961024]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\Gadu-Gadu\gg.exe” [2008-03-20 12:04 2127296]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2005-05-12 00:12 49152]
“AVG7_CC”=“C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe” [2008-06-27 18:57 580096]
“PRONoMgr.exe”=“C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe” [2003-03-11 16:24 86016]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-07-13 21:20 98304]
“ImagePath”=“C:\windows\system_32.bat” [2008-07-04 16:47 64]
“SoundMan”=“SOUNDMAN.EXE” [2004-05-14 09:47 67072 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 00:44 15360]
“AVG7_Run”=“C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe” [2007-10-24 18:59 219136]
C:\Documents and Settings\Damian\Menu Start\Programy\Autostart\
OpenOffice.org 2.0.2.lnk - C:\Program Files\OpenOffice.org 2.0.2\program\quickstart.exe [2006-03-12 01:12:44 393216]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 00:23:26 282624]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
“{88485281-8b4b-4f8d-9ede-82e29a064277}”= “C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL” [2004-11-23 17:51 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
??? [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
??? [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a------ 2004-08-04 00:44 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a------ 2005-06-06 21:04 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusOverride”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Ares\Ares.exe”=
“C:\WINDOWS\system32\usmt\migwiz.exe”=
“C:\Program Files\Shareaza\Shareaza.exe”=
“C:\Program Files\EA GAMES\MOHAA\MOHAA.exe”=
“C:\WINDOWS\system32\muzapp.exe”=
“C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe”=
“C:\Program Files\Gadu-Gadu\Gadu-Gadu\gg.exe”=
“C:\Program Files\Gadu-Gadu\gg.exe”=
“C:\Program Files\Wolfenstein - Enemy Territory\ET.exe”=
“C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE”=
“C:\Program Files\Activision\Call of Duty 2\Kopia CoD2MP_s.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
*Newly Created Service* - CATCHME
.
HKCU-Run-Komunikator - C:\Program Files\Tlen.pl\tlen.exe
HKCU-Run-WinButler - C:\Documents and Settings\domownicy\Dane aplikacji\WinButler\WinButler.exe
HKLM-Run-SMSTray - C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-13 17:03:19
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\AudioSrv]
“ImagePath”="net user %username% 9314 "
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
- C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-07-13 17:05:29
ComboFix-quarantined-files.txt 2008-07-13 15:04:50
Pre-Run: 14,963,113,984 bajtów wolnych
Post-Run: 15,912,587,264 bajtów wolnych
203 — E O F — 2008-06-21 01:02:28
Problem nie zniknął 
W dniu 13.07.2008 , o godzinie 17:33 został dopisany post przez damianm14
Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: could not open file “C:Program FilesActivity Logger\alsys.exe”
Deletion of file “C:Program FilesActivity Logger\alsys.exe” failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
– bad path / the parent directory does not exist
Error: file “Folders to delete::” not found!
Deletion of file “Folders to delete::” failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
– the object does not exist
Error: file “C:\Program Files\WebRebates4” not found!
Deletion of file “C:\Program Files\WebRebates4” failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
– the object does not exist
Completed script processing.
*******************
Finished! Terminate.
O to log z avenger’a.