log z Combo
ComboFix 08-01-13.1 - ppp 2008-01-13 10:38:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.52 [GMT 1:00]Running from: C:\Documents and Settings\ppp\Pulpit\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\4_exception.nls
C:\WINDOWS\system32\drivers\Dvkp75.sys
C:\WINDOWS\system32\drivers\SBVN49.sys
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\system32\kb9253279.exe
C:\WINDOWS\system32\kb9253309.exe
C:\WINDOWS\system32\kb9253311.exe
C:\WINDOWS\system32\koos.exe
C:\WINDOWS\system32\kprof
C:\WINDOWS\system32\poof
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_KPROF
-------\LEGACY_NDISWON
-------\LEGACY_POOF
-------\LEGACY_RUNTIME
-------\LEGACY_SBVN49
-------\LEGACY_SMTPDRV
-------\smtpdrv
((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.
2008-01-13 10:37 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 10:12 . 2008-01-13 10:12
2008-01-11 18:41 . 2008-01-11 18:41 29 --a------ C:\WINDOWS\system32\qpwaarsq.tmp
2008-01-11 18:33 . 2008-01-11 18:33
2008-01-11 18:28 . 2006-08-12 13:13
2008-01-11 18:28 . 2006-08-12 13:13
2008-01-11 18:28 . 2006-08-12 11:23
2008-01-11 18:28 . 2008-01-11 18:35
2008-01-11 18:28 . 2006-08-12 13:13
2008-01-11 18:28 . 2006-08-12 13:13
2008-01-11 18:28 . 2006-08-12 13:13
2008-01-09 21:49 . 2008-01-09 21:49 81,920 --a------ C:\WINDOWS\system32\pj116568.dll
2008-01-09 21:49 . 2008-01-09 21:49 44,686 --ah----- C:\WINDOWS\system32\pj116568.dl_
2008-01-09 16:24 . 24,832 C:\WINDOWS\system32\drivers\Txc83.sys
2008-01-07 17:40 . 2008-01-11 18:21 22 --a------ C:\autoexec.ba_
2008-01-06 21:13 . 21,760 C:\WINDOWS\Dhl58.sys
2008-01-06 13:08 . 2008-01-06 13:08
2008-01-06 13:08 . 2008-01-06 13:08 72,192 --a------ C:\bot.exe
2008-01-06 13:08 . 21,760 C:\WINDOWS\system32\drivers\Dhl58.sys
2008-01-06 12:19 . 2008-01-06 12:19 260 --a------ C:\WINDOWS\AUDOZ3_0.INI
2007-12-19 23:10 . 2008-01-03 23:03
2007-12-13 22:59 . 2007-12-13 22:59
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 21:52 --------- d-----w C:\Program Files\Google
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
2007-12-02 15:12 394672 --a------ C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshIEHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44 15360]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-08-03 23:55 1667584]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2006-09-14 16:49 1672904]
“RSSNewser”=“C:\Documents and Settings\ppp\Dane aplikacji\RSSNewser\RSSNewser.exe” [2006-10-06 17:38 7400801]
“Paseczek”=“C:\Program Files\Paseczek\Paseczek.exe” [2006-09-18 23:15 1454592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 10:50 155648]
“WinampAgent”=“C:\Program Files\Winamp\Winampa.exe” [2003-04-02 03:20 12288]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2004-11-15 14:17 4624384]
“nwiz”=“nwiz.exe” [2004-11-15 14:17 921600 C:\WINDOWS\system32\nwiz.exe]
“NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2004-11-15 14:17 86016]
“ShStatEXE”=“C:\Program Files\Network Associates\VirusScan\SHSTAT.exe” [2003-10-15 06:10 81990]
“McAfeeUpdaterUI”=“C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe” [2003-09-10 02:11 135251]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe” [2006-10-12 03:10 49263]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-05-20 09:54 98304]
“Sony Ericsson PC Suite”=“C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” [2005-10-26 16:17 159744]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\partnershipreg]
C:\Documents and Settings\All Users\Dokumenty\Settings\partnership.dll 2008-01-06 13:08 13201 C:\Documents and Settings\All Users\Dokumenty\Settings\partnership.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Dhl58.sys]
@=“Driver”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Txc83.sys]
@=“Driver”
R0 AFPAnsi;G-DATA Ukrywacz Ansi;C:\WINDOWS\system32\Drivers\AFPAnsi.sys [2002-10-09 14:53]
R0 Dhl58;Dhl58;C:\WINDOWS\system32\Drivers\Dhl58.sys []
R0 FO_PAnt;FotoOffice VirtualDisc Driver;C:\WINDOWS\system32\Drivers\FO_PAnt.sys [2003-07-17 13:56]
R0 Txc83;Txc83;C:\WINDOWS\system32\Drivers\Txc83.sys []
R3 SiS7012;Service for AC’97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2003-04-08 08:56]
R3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys [2006-02-17 20:34]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-13 10:46:34
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
- C:\Documents and Settings\All Users\Dokumenty\Settings\partnership.dll
.
Completion time: 2008-01-13 10:51:47 - machine was rebooted [ppp]
ComboFix-quarantined-files.txt 2008-01-13 09:51:33
i co dalej ? bo chyba coś nie do końca jest tak z komputwerem Mcafee pokazuje przy uruchomieniu komunikat ComboFix 08-01-13.1 - ppp 2008-01-13 10:38:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.52 [GMT 1:00]Running from: C:\Documents and Settings\ppp\Pulpit\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\4_exception.nls
C:\WINDOWS\system32\drivers\Dvkp75.sys
C:\WINDOWS\system32\drivers\SBVN49.sys
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\system32\kb9253279.exe
C:\WINDOWS\system32\kb9253309.exe
C:\WINDOWS\system32\kb9253311.exe
C:\WINDOWS\system32\koos.exe
C:\WINDOWS\system32\kprof
C:\WINDOWS\system32\poof
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_KPROF
-------\LEGACY_NDISWON
-------\LEGACY_POOF
-------\LEGACY_RUNTIME
-------\LEGACY_SBVN49
-------\LEGACY_SMTPDRV
-------\smtpdrv
((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.
2008-01-13 10:37 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 10:12 . 2008-01-13 10:12
2008-01-11 18:41 . 2008-01-11 18:41 29 --a------ C:\WINDOWS\system32\qpwaarsq.tmp
2008-01-11 18:33 . 2008-01-11 18:33
2008-01-11 18:28 . 2006-08-12 13:13
2008-01-11 18:28 . 2006-08-12 13:13
2008-01-11 18:28 . 2006-08-12 11:23
2008-01-11 18:28 . 2008-01-11 18:35
2008-01-11 18:28 . 2006-08-12 13:13
2008-01-11 18:28 . 2006-08-12 13:13
2008-01-11 18:28 . 2006-08-12 13:13
2008-01-09 21:49 . 2008-01-09 21:49 81,920 --a------ C:\WINDOWS\system32\pj116568.dll
2008-01-09 21:49 . 2008-01-09 21:49 44,686 --ah----- C:\WINDOWS\system32\pj116568.dl_
2008-01-09 16:24 . 24,832 C:\WINDOWS\system32\drivers\Txc83.sys
2008-01-07 17:40 . 2008-01-11 18:21 22 --a------ C:\autoexec.ba_
2008-01-06 21:13 . 21,760 C:\WINDOWS\Dhl58.sys
2008-01-06 13:08 . 2008-01-06 13:08
2008-01-06 13:08 . 2008-01-06 13:08 72,192 --a------ C:\bot.exe
2008-01-06 13:08 . 21,760 C:\WINDOWS\system32\drivers\Dhl58.sys
2008-01-06 12:19 . 2008-01-06 12:19 260 --a------ C:\WINDOWS\AUDOZ3_0.INI
2007-12-19 23:10 . 2008-01-03 23:03
2007-12-13 22:59 . 2007-12-13 22:59
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 21:52 --------- d-----w C:\Program Files\Google
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
2007-12-02 15:12 394672 --a------ C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshIEHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44 15360]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-08-03 23:55 1667584]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2006-09-14 16:49 1672904]
“RSSNewser”=“C:\Documents and Settings\ppp\Dane aplikacji\RSSNewser\RSSNewser.exe” [2006-10-06 17:38 7400801]
“Paseczek”=“C:\Program Files\Paseczek\Paseczek.exe” [2006-09-18 23:15 1454592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 10:50 155648]
“WinampAgent”=“C:\Program Files\Winamp\Winampa.exe” [2003-04-02 03:20 12288]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2004-11-15 14:17 4624384]
“nwiz”=“nwiz.exe” [2004-11-15 14:17 921600 C:\WINDOWS\system32\nwiz.exe]
“NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2004-11-15 14:17 86016]
“ShStatEXE”=“C:\Program Files\Network Associates\VirusScan\SHSTAT.exe” [2003-10-15 06:10 81990]
“McAfeeUpdaterUI”=“C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe” [2003-09-10 02:11 135251]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe” [2006-10-12 03:10 49263]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-05-20 09:54 98304]
“Sony Ericsson PC Suite”=“C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” [2005-10-26 16:17 159744]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\partnershipreg]
C:\Documents and Settings\All Users\Dokumenty\Settings\partnership.dll 2008-01-06 13:08 13201 C:\Documents and Settings\All Users\Dokumenty\Settings\partnership.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Dhl58.sys]
@=“Driver”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Txc83.sys]
@=“Driver”
R0 AFPAnsi;G-DATA Ukrywacz Ansi;C:\WINDOWS\system32\Drivers\AFPAnsi.sys [2002-10-09 14:53]
R0 Dhl58;Dhl58;C:\WINDOWS\system32\Drivers\Dhl58.sys []
R0 FO_PAnt;FotoOffice VirtualDisc Driver;C:\WINDOWS\system32\Drivers\FO_PAnt.sys [2003-07-17 13:56]
R0 Txc83;Txc83;C:\WINDOWS\system32\Drivers\Txc83.sys []
R3 SiS7012;Service for AC’97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2003-04-08 08:56]
R3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys [2006-02-17 20:34]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-13 10:46:34
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
- C:\Documents and Settings\All Users\Dokumenty\Settings\partnership.dll
.
Completion time: 2008-01-13 10:51:47 - machine was rebooted [ppp]
ComboFix-quarantined-files.txt 2008-01-13 09:51:33
i co dalej bo chyba nie do końca jest ok Mcafee pokazuje komunikat o smtdrv.sys jako usunięto z windows/system32 a strona startowa zmienia się na wyszukiwarkę Imech, nie wiem jak teraz napisać skrypt bo trzeba go chyba skopiować do Combo i jeszcze raz uruchomić dzięki za pomoc.