ComboFix 08-05-15.3 - User 2008-05-17 8:30:54.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.571 [GMT 2:00]
Running from: C:\Documents and Settings\User\Moje dokumenty\bogusawa.polednik@neostrada.pl\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\User\Moje dokumenty\bogusawa.polednik@neostrada.pl\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
FILE ::
C:\temp\abmaster.dll
C:\temp\avfix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\abmaster.dll
C:\temp\avfix.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-17 to 2008-05-17 )))))))))))))))))))))))))))))))
.
2008-05-16 23:08 . 2008-05-16 23:08
2008-05-16 21:32 . 2008-05-16 21:32
2008-05-16 15:52 . 2008-05-16 15:52
2008-05-16 15:49 . 2008-05-17 08:23
2008-05-16 15:49 . 2008-05-16 15:52
2008-05-16 15:49 . 2007-12-06 15:51 28,568 --a------ C:\WINDOWS\system32\drivers\AVHook.sys
2008-05-16 15:49 . 2007-12-06 15:51 21,912 --a------ C:\WINDOWS\system32\drivers\AVRec.sys
2008-05-16 15:49 . 2008-02-12 10:44 21,904 --a------ C:\WINDOWS\system32\drivers\AVFilter.sys
2008-05-14 20:17 . 2008-05-14 20:17
2008-05-14 12:42 . 2008-05-14 12:42
2008-05-14 00:07 . 2008-05-14 00:07
2008-05-14 00:00 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-05-14 00:00 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-05-14 00:00 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-05-14 00:00 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-05-14 00:00 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-05-13 23:36 . 2008-05-17 08:24
2008-05-13 23:35 . 2008-05-13 23:35
2008-05-13 13:06 . 2008-05-13 15:19
2008-05-12 16:39 . 2008-05-17 08:32
2008-05-12 15:43 . 2008-05-12 15:44
2008-05-12 15:43 . 2008-05-12 16:37
2008-05-12 13:43 . 2008-05-12 13:43
2008-05-12 13:43 . 2008-05-12 13:43
2008-05-11 23:23 . 2008-05-11 23:25
2008-05-11 10:44 . 2008-05-11 10:44
2008-05-11 10:44 . 2008-05-11 10:44
2008-05-11 10:44 . 2008-05-11 10:44
2008-05-11 10:09 . 2008-04-14 19:20 712,704 --------- C:\WINDOWS\system32\windowscodecs.dll
2008-05-11 10:09 . 2008-04-14 19:20 346,112 --------- C:\WINDOWS\system32\windowscodecsext.dll
2008-05-11 10:09 . 2008-04-14 19:20 276,992 --------- C:\WINDOWS\system32\wmphoto.dll
2008-05-11 10:09 . 2008-04-14 19:20 69,120 --------- C:\WINDOWS\system32\wlanapi.dll
2008-05-11 10:09 . 2008-04-14 19:20 53,248 --------- C:\WINDOWS\system32\tsgqec.dll
2008-05-11 10:09 . 2008-04-14 19:20 50,688 --------- C:\WINDOWS\system32\tspkg.dll
2008-05-11 10:09 . 2008-04-14 19:21 32,768 --------- C:\WINDOWS\system32\setupn.exe
2008-05-11 10:09 . 2008-04-13 20:40 10,240 --------- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-05-11 10:07 . 2008-04-14 19:20 651,264 --------- C:\WINDOWS\system32\dot3ui.dll
2008-04-23 10:11 . 2008-04-23 10:12 98,927 --a------ C:\WINDOWS\hpqins16.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-17 06:29 --------- d-----w C:\Program Files\Neostrada TP
2008-05-16 22:17 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-15 21:12 28,672 ----a-w C:\WINDOWS\Gtwatch.exe
2008-05-12 17:56 --------- d-----w C:\Program Files\SkanerOnline
2008-05-12 14:44 --------- d-----w C:\Program Files\ArcaBit
2008-05-10 23:01 --------- d-----w C:\Program Files\Zestawy maturalne
2008-05-10 20:08 --------- d-----w C:\Documents and Settings\User\Dane aplikacji\AdobeUM
2008-04-27 17:44 --------- d-----w C:\Program Files\English Translator 3
2008-04-14 20:51 11,264 ------w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 20:50 997,888 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 20:50 424,960 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 17:46 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 17:26 332,288 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 17:22 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 17:22 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 17:22 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 17:22 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 17:22 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 17:22 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 17:22 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 17:22 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 17:20 999,936 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-04-14 17:19 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 17:18 5,632 ----a-w C:\WINDOWS\system32\wmi.dll
2008-04-14 17:18 1,449,472 ----a-w C:\WINDOWS\system32\winntbbu.dll
2008-04-14 17:17 57,375 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 17:13 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 17:12 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-14 17:06 3,584 ----a-w C:\WINDOWS\system32\icmp.dll
2008-04-14 17:05 9,344 ----a-w C:\WINDOWS\system32\framebuf.dll
2008-04-14 17:03 3,072 ----a-w C:\WINDOWS\system32\dpnlobby.dll
2008-04-14 17:03 3,072 ----a-w C:\WINDOWS\system32\dpnaddr.dll
2008-04-14 17:01 16,896 ----a-w C:\WINDOWS\system32\cfgmgr32.dll
2008-04-14 17:00 285,696 ----a-w C:\WINDOWS\system32\atmfd.dll
2008-04-14 16:34 73,472 ----a-w C:\WINDOWS\system32\drivers\sr.sys
2008-04-14 16:33 80,256 ----a-w C:\WINDOWS\system32\drivers\parport.sys
2008-04-14 16:33 68,608 ----a-w C:\WINDOWS\system32\drivers\pci.sys
2008-04-14 16:33 120,320 ----a-w C:\WINDOWS\system32\drivers\pcmcia.sys
2008-04-14 16:32 46,848 ----a-w C:\WINDOWS\system32\drivers\p3.sys
2008-04-14 16:30 2,190,336 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-14 16:29 2,067,200 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-14 16:25 4,096 ------w C:\WINDOWS\system32\dsprpres.dll
2008-04-14 16:22 89,600 ------w C:\WINDOWS\system32\msxml6r.dll
2008-04-14 16:22 800,000 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-14 16:22 153,856 ----a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-14 16:20 80,896 ------w C:\WINDOWS\system32\msshavmsg.dll
2008-04-14 16:20 24,960 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys
2008-04-14 16:18 37,632 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys
2008-04-14 16:17 40,832 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys
2008-04-14 16:16 40,448 ------w C:\WINDOWS\system32\drivers\intelppm.sys
2008-04-14 16:15 49,664 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-14 16:13 563,200 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-14 16:11 65,280 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-14 16:11 53,248 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-14 16:09 25,728 ------w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-14 16:07 10,240 ----a-w C:\WINDOWS\system32\gpkrsrc.dll
2008-04-14 16:05 67,584 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-14 16:05 58,880 ----a-w C:\WINDOWS\system32\drivers\redbook.sys
2008-04-14 16:05 273,920 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-14 16:05 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-14 16:03 44,672 ----a-w C:\WINDOWS\system32\drivers\fips.sys
2008-04-14 16:01 52,864 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-14 16:00 39,936 ----a-w C:\WINDOWS\system32\drivers\processr.sys
2008-04-14 15:59 103,936 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-14 15:58 41,856 ------w C:\WINDOWS\system32\drivers\amdk7.sys
2008-04-14 15:58 41,472 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys
2008-04-14 15:55 23,296 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys
2008-04-14 15:54 30,208 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-14 15:54 188,544 ----a-w C:\WINDOWS\system32\drivers\acpi.sys
2008-04-13 19:28 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:21 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 19:15 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 19:15 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 19:14 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 19:14 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 19:00 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 19:00 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 18:57 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 18:57 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 18:57 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 18:57 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 18:57 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 18:57 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 18:57 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 18:56 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 18:56 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
.
((((((((((((((((((((((((((((( snapshot@2008-05-16_23.32.45,69 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-16 20:43:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-17 06:22:49 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2008-04-14 19:21 15360]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2006-10-10 17:51 1636040]
“updateMgr”=“C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe” [2006-03-30 17:45 313472]
“SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search Destroy\TeaTimer.exe” [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2004-03-03 10:29 2904064]
“nwiz”=“nwiz.exe” [2004-03-03 10:29 782336 C:\WINDOWS\system32\nwiz.exe]
“NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2004-03-03 10:29 46080]
“HPHUPD08”=“C:\Program Files\HP\Digital Imaging{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe” [2005-06-01 19:35 49152]
“HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2005-05-11 23:12 49152]
“WooCnxMon”=“C:\PROGRA~1\NEOSTR~1\CnxMon.exe” [2003-10-16 18:07 24576]
“WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2003-10-16 18:07 20480]
“WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” [2003-10-16 18:07 53248]
“Adobe Photo Downloader”=“C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe” [2005-06-07 00:46 57344]
“Gtwatch”=“C:\WINDOWS\gtwatch.exe” [2008-05-15 23:12 28672]
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 12:50 155648]
“OrderReminder”=“C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe” [2006-01-30 18:00 98304]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-02-10 23:44 282624]
“Windows Defender”=“C:\Program Files\Windows Defender\MSASCui.exe” [2006-11-03 20:20 866584]
“avgnt”=“C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe” [2008-02-12 10:06 262401]
“PCTAVApp”=“C:\Program Files\PC Tools AntiVirus\PCTAV.exe” [2008-03-05 09:37 1238928]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” [2008-04-14 19:21 15360]
“DWQueuedReporting”=“C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe” [2007-03-13 17:38 39264]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-10-27 17:13:59 962661]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
HP Image Zone - szybkie uruchamianie.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-12 00:49:24 73728]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 11:01:04 83360]
Ulead Photo Express Calendar Checker For My Custom Edition.lnk - C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 My Custom Edition\CalCheck.exe [2006-12-28 21:46:56 57344]
[HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer]
“StartMenuLogOff”= 1 (0x1)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Gadu-Gadu\gg.exe”=
“C:\Program Files\Internet Explorer\iexplore.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“C:\WINDOWS\system32\mmc.exe”=
S2 ArcaVirMonitor;ArcaVir Antivirus Monitor Service;C:\Program Files\ArcaBit\ArcaVir\AvMon.exe []
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys []
S3 arcaen;ArcaVir Monitor Kernel Engine Driver;C:\Program Files\ArcaBit\ArcaVir\arcaen.sys []
S3 arcaev;ArcaVir Monitor Kernel Events Driver;C:\Program Files\ArcaBit\ArcaVir\arcaev.sys []
S3 arcafd;ArcaVir Monitor Kernel Filter Driver;C:\Program Files\ArcaBit\ArcaVir\arcafd.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{a0d867d0-bd11-11db-8a13-85b56a53d4f4}]
\Shell\AutoRun\command - 6l6w8.com
\Shell\explore\Command - 6l6w8.com
\Shell\open\Command - 6l6w8.com
.
Contents of the ‘Scheduled Tasks’ folder
“2008-05-16 22:00:01 C:\WINDOWS\Tasks\HPpromotions journeysoftware.job”
- C:\Program Files\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe
“2008-05-17 06:27:03 C:\WINDOWS\Tasks\MP Scheduled Scan.job”
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-17 08:38:10
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ASFWHide]
“ImagePath”="??\C:\DOCUME~1\User\USTAWI~1\Temp\ASFWHide"
.
Completion time: 2008-05-17 8:40:30
ComboFix-quarantined-files.txt 2008-05-17 06:40:08
ComboFix2.txt 2008-05-16 21:33:47
Pre-Run: 7,744,622,592 bajtów wolnych
Post-Run: 7,748,304,896 bajtów wolnych
243 — E O F — 2008-05-16 08:09:10
W dniu 17.05.2008 , o godzinie 8:57 został dopisany post przez robertp
po przeskanowaniu kasperskim pendrive wyszło, że jest na nim trojan “Trojan-PSW.Win32.OnLine.Games.yuj” osadzony w pliku "autorun.inf.
ale podczas skanowania systemu nie wykazuje tego wirusa na dyskach.