Witam jeszcze raz. Wielkie dzieki za przydatne info. juz spiesze umiescic loga z combofix
ComboFix 08-06-05.3 - user 2008-06-06 22:11:57.1 - NTFSx86
Running from: C:\Documents and Settings\user\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
FILE ::
C:\WINDOWS\nmwegbsf.dll
C:\WINDOWS\system32\qjcqckqo.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\user\Pulpit\Privacy Protector.url
C:\WINDOWS\nmwegbsf.dll
C:\WINDOWS\system32\1.htm
C:\WINDOWS\system32\905757\905757.dll
C:\WINDOWS\system32\dqdztmoc.dll
C:\WINDOWS\system32\gqrru.exe
C:\WINDOWS\system32\iifeeCRH.dll
C:\WINDOWS\system32\jkkKcDTl.dll
C:\WINDOWS\system32\lTDcKkkj.ini
C:\WINDOWS\system32\lTDcKkkj.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\oqkcqcjq.ini
C:\WINDOWS\system32\prsgrc.dll
C:\WINDOWS\system32\w3naeld.dll
C:\WINDOWS\system32\xGfMlUtv.ini
C:\WINDOWS\system32\xGfMlUtv.ini2
C:\WINDOWS\system32\ycogxxti.ini
----- BITS: Possible infected sites -----
hxxp://139.18.143.201
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSUPDATE
((((((((((((((((((((((((( Files Created from 2008-05-06 to 2008-06-06 )))))))))))))))))))))))))))))))
.
2008-06-06 20:15 . 2008-06-06 20:15 117,640 --a------ C:\test.htm
2008-06-06 15:20 . 2008-06-06 15:20 92,032 --a------ C:\WINDOWS\system32\itxxgocy.dll
2008-06-06 09:35 . 2008-06-06 19:52
2008-06-06 09:35 . 2008-06-06 19:54
2008-06-05 13:12 . 2008-06-05 13:12
2008-06-05 12:37 . 2008-06-05 12:37
2008-06-05 11:58 . 2008-06-05 11:54 294 --ahs---- C:\WINDOWS\system32\ugkvppjv.ini
2008-06-05 11:45 . 2008-06-05 11:45 1,273,594 —hs---- C:\WINDOWS\system32\ugkvppjv.tmp
2008-06-05 11:24 . 2008-06-05 11:48 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-06-05 11:24 . 2008-06-05 11:48 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-06-05 11:21 . 2008-06-06 19:55
2008-06-05 11:21 . 2008-06-06 23:22 1,698,848 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-05 11:21 . 2008-06-06 23:20 23,780 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-05 11:21 . 2008-06-06 23:22 22,304 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-05 11:21 . 2008-06-06 23:20 3,092 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-05 10:42 . 2008-06-05 10:42
2008-06-05 10:34 . 2008-06-05 10:34
2008-06-05 10:34 . 2008-06-05 10:34
2008-06-05 10:33 . 2008-06-05 10:33
2008-06-05 10:32 . 2008-06-05 10:32 324,352 --------- C:\WINDOWS\system32\vtUlMfGx.dll_old
2008-06-05 10:17 . 2008-06-05 10:17
2008-06-05 10:00 . 2008-06-05 10:00
2008-06-05 09:52 . 2008-06-05 09:52 16 --a------ C:\WINDOWS\system32\coh.cache
2008-06-05 09:51 . 2008-06-05 09:51
2008-06-05 09:49 . 2008-06-05 09:49
2008-06-05 09:49 . 2008-06-05 09:49
2008-06-05 09:49 . 2008-06-05 09:49
2008-06-05 09:43 . 2008-06-05 09:43
2008-06-05 09:43 . 2008-06-05 09:43
2008-06-05 09:37 . 2008-06-05 09:37
2008-06-05 09:32 . 2008-06-05 09:32
2008-06-05 09:31 . 2008-06-05 11:31
2008-06-05 09:27 . 2008-06-06 23:06
2008-06-05 09:27 . 2008-06-05 09:27
2008-06-05 09:27 . 2008-06-05 09:27
2008-06-05 09:27 . 2008-06-05 09:27
2008-06-05 09:27 . 2008-06-05 09:27
2008-06-05 09:27 . 2008-06-05 09:27
2008-06-05 09:27 . 2008-06-05 09:27
2008-06-05 09:27 . 2008-06-05 09:27
2008-06-05 09:27 . 2008-06-05 09:27
2008-06-05 01:46 . 2008-06-05 00:17 245,760 --a------ C:\WINDOWS\nogxfvblawt.dll
2008-06-05 01:46 . 2008-06-05 00:17 229,376 --------- C:\WINDOWS\erpobmsw.dll_old
2008-06-05 01:46 . 2008-06-05 09:27 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-06-05 01:46 . 2008-06-05 00:17 94,208 --a------ C:\WINDOWS\exmk.exe
2008-06-05 01:46 . 2008-06-05 00:17 81,920 --a------ C:\WINDOWS\xbqmfsed.exe
2008-06-05 00:48 . 2008-06-05 00:48
2008-06-05 00:12 . 2008-06-05 11:17
2008-06-05 00:00 . 2008-06-05 00:00
2008-06-04 23:53 . 2008-06-04 23:53 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-04 23:41 . 2008-06-04 23:41
2008-06-04 23:41 . 2005-11-28 14:12 683,488 --a------ C:\WINDOWS\studsavinfo.exe
2008-06-04 10:36 . 2008-06-04 10:36
2008-06-03 23:59 . 2008-06-03 23:59 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-06-02 09:02 . 2004-08-04 00:43 716,288 --a------ C:\WINDOWS\system32\ntlib.dll
2008-06-02 09:01 . 2008-06-02 09:01 0 --a------ C:\WINDOWS\system32\zakaz1.clk
2008-06-01 23:13 . 2008-06-01 23:44 724,992 --a------ C:\WINDOWS\iun6002.exe
2008-06-01 23:11 . 2008-06-04 00:25
2008-06-01 22:08 . 2004-08-04 00:43 716,288 --a------ C:\WINDOWS\system32\hlxb.dll
2008-05-29 16:53 . 2008-05-17 13:23 4,090,320 --a------ C:\WINDOWS\system32\ssartworkz_pc.dll
2008-05-29 16:53 . 2007-09-28 17:11 338,384 --a------ C:\WINDOWS\system32\JS32CE_pc.dll
2008-05-29 16:53 . 2008-05-16 15:57 258,352 --a------ C:\WINDOWS\system32\unicows.dll
2008-05-29 16:53 . 2007-09-28 17:11 186,832 --a------ C:\WINDOWS\system32\Archimedes_pc.dll
2008-05-29 16:53 . 2008-05-17 13:23 88,528 --a------ C:\WINDOWS\system32\sszlib_pc.dll
2008-05-14 22:28 . 2008-05-14 22:28 29,165 --a------ C:\WINDOWS\system32\nfjjrgmshsi
2008-05-14 22:28 . 2008-06-05 13:00 8,242 --a------ C:\Documents and Settings\user\mpr2.dat
2008-05-14 22:28 . 2008-06-05 13:00 8,242 --a------ C:\Documents and Settings\user\mpr.dat
2008-05-06 21:39 . 2008-05-22 21:29 0 --a------ C:\IAX_OUT.DAT
2008-05-06 21:39 . 2008-05-22 21:29 0 --a------ C:\IAX_IN.DAT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2060-08-18 17:02 1,496,064 ------w C:\WINDOWS\system32\CC3250MT.DLL
2060-08-18 16:40 909,824 ------w C:\WINDOWS\system32\CP3245MT.DLL
2060-08-18 16:40 24,064 ------w C:\WINDOWS\system32\BORLNDMM.DLL
2008-06-06 21:17 --------- d-----w C:\Documents and Settings\user\Dane aplikacji\Skype
2008-06-05 09:52 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-06-05 09:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-05 09:21 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-05 09:16 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Symantec
2008-06-05 08:53 --------- d-----w C:\Program Files\BitComet
2008-06-03 22:41 --------- d-----w C:\Program Files\MarBit
2008-06-03 22:25 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-06-03 21:25 --------- d-----w C:\Program Files\onlineTV 2
2008-06-03 21:22 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-06-03 21:20 --------- d-----w C:\Program Files\Winamp
2008-06-01 21:45 --------- d-----w C:\Program Files\GK3neu
2008-05-06 06:06 --------- d-----w C:\Program Files\AskPBar
2008-04-29 19:59 --------- d-----w C:\Program Files\TerraSipPhonerLite
2008-04-26 22:09 --------- d-----w C:\Program Files\Elaborate Bytes
2008-04-21 21:15 --------- d-----w C:\Documents and Settings\user\Dane aplikacji\IrfanView
2008-04-15 22:47 --------- d-----w C:\Program Files\NiemPol
2008-04-14 18:35 --------- d-----w C:\Program Files\PDFCreator PL
2008-04-14 18:35 --------- d-----w C:\Documents and Settings\user\Dane aplikacji\PDFCreator
2006-07-26 16:48 6,770,772 ----a-w C:\Program Files\realalt149.exe
2006-07-26 16:46 735,883 ----a-w C:\Program Files\ac3filter_1_02a_test8.exe
2006-07-17 22:26 4,272,232 ----a-w C:\Program Files\subedit+codecpack_pl.exe
2006-07-17 22:18 8,282,187 ----a-w C:\Program Files\vlc-0.8.5-win32.exe
2001-02-23 17:22 299,008 ----a-w C:\Program Files\bestplayer1.0.exe
1999-05-17 10:58 99,840 ----a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-08 23:53 70,144 ----a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-08 23:53 48,640 ----a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-08 23:53 31,744 ----a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-08 23:53 186,368 ----a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-08 23:53 17,920 ----a-w C:\Program Files\Common Files\IRASRIAL.DLL
2007-08-28 19:29 80 --sh–r C:\WINDOWS\system32\7148505F44.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{945328DB-7667-4043-9D75-CE942CC333C0}]
C:\WINDOWS\system32\vtUlMfGx.dll
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{E06E98B2-A901-4064-A05E-0F56D55DD86D}]
2008-06-05 00:17 245760 --a------ C:\WINDOWS\nogxfvblawt.dll
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{E1BACF55-35E1-4E47-9247-2D48660E5545}]
C:\Program Files\Zango\bin\10.1.181.0\HostIE.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
“{E1BACF55-35E1-4E47-9247-2D48660E5545}”= C:\Program Files\Zango\bin\10.1.181.0\HostIE.dll []
[HKEY_CLASSES_ROOT\clsid{e1bacf55-35e1-4e47-9247-2d48660e5545}]
[HKEY_CLASSES_ROOT\HostIE.Bho.1]
[HKEY_CLASSES_ROOT\TypeLib{087C4054-0A2B-4F35-B0DB-BED3E21650F4}]
[HKEY_CLASSES_ROOT\HostIE.Bho]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44 15360]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2005-09-15 15:43 1712128]
“SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search Destroy\TeaTimer.exe” [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“AVP”=“C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe” [2007-12-18 00:43 227856]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“msacm.l3acm”= l3codecp.acm
“vidc.3iv2”= 3ivxVfWCodec.dll
“msacm.divxa32”= divxa32.acm
“VIDC.HFYU”= huffyuv.dll
“VIDC.VP31”= vp31vfw.dll
“msacm.l3codecp”= l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winch62.sys]
@=“Driver”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winnr60.sys]
@=“Driver”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wintx47.sys]
@=“Driver”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winuy37.sys]
@=“Driver”
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Symantec Fax Starter Edition Port.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Symantec Fax Starter Edition Port.lnk
backup=C:\WINDOWS\pss\Symantec Fax Starter Edition Port.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^user^Menu Start^Programy^Autostart^UltimateZip Quick Start.lnk]
path=C:\Documents and Settings\user\Menu Start\Programy\Autostart\UltimateZip Quick Start.lnk
backup=C:\WINDOWS\pss\UltimateZip Quick Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
–a------ 2003-04-18 11:20 88363 C:\WINDOWS\agrsmmsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
–a------ 2003-10-30 16:46 192512 C:\Program Files\Apoint2K\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\callfromweb]
C:\Program Files\CallFromWeb\CallFromWeb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a------ 2007-04-04 00:29 165784 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrWebScheduler]
C:\Program Files\DrWeb\DRWEBSCD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eFON]
C:\Program Files\eFON\efon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eyeBeam SIP Client]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
–a------ 2005-09-15 15:43 1712128 C:\Program Files\Gadu-Gadu\gg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
–a------ 2004-01-26 19:03 118784 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
–a------ 2004-01-26 19:03 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator]
C:\Program Files\Tlen.pl\tlen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
–a------ 2003-01-02 16:16 172032 C:\Program Files\ltmoh\Ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneMoreKey]
C:\Program Files\XP Antivirus\xpa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PoivY]
C:\Program Files\PoivY.com\PoivY\PoivY.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
–a------ 2007-04-09 14:23 200704 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a------ 2004-11-02 20:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmaTel StacMon]
–a------ 2003-08-03 16:01 86073 C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
–a------ 2006-11-24 18:16 20058152 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SparVoip]
C:\Program Files\SparVoip\SparVoip.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\studNET-Autologin]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a------ 2007-07-14 21:38 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a------ 2005-10-12 00:38 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain]
–a------ 2004-03-03 12:57 278528 C:\WINDOWS\system32\TPSMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipBuster]
C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipCheapCom]
C:\Program Files\VoipCheapCom\VoipCheapCom.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipDiscount]
C:\Program Files\VoipDiscount.com\VoipDiscount\VoipDiscount.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipStunt]
C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeatherDPA]
C:\Program Files\Zango\bin\10.1.181.0\Weather.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a------ 2007-05-15 00:22 35328 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
“gusvc”=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Gadu-Gadu\gg.exe”=
“C:\Program Files\Gadu-Gadu\ggphone\ggphone.exe”=
“C:\Program Files\PeerCast\PeerCast.exe”=
“C:\Program Files\Winamp\winamp.exe”=
“C:\Program Files\BitComet\BitComet.exe”=
“C:\Program Files\SJLabs\SJphone\SJphone.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“14483:TCP”= 14483:TCP:BitComet 14483 TCP
“14483:UDP”= 14483:UDP:BitComet 14483 UDP
R1 SSHDRV82;SSHDRV82;C:\WINDOWS\system32\drivers\SSHDRV82.sys [2005-11-08 22:23]
R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;“C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe” [2006-09-13 15:54]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
S0 Winch62;Winch62;C:\WINDOWS\system32\Drivers\Winch62.sys []
S0 Winuy37;Winuy37;C:\WINDOWS\system32\Drivers\Winuy37.sys []
S3 wlags48d;Agere Wireless PCCard Service;C:\WINDOWS\system32\DRIVERS\wlags48d.sys [2003-07-24 09:13]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{ae49b400-980d-11db-ae7a-000e7b87cb13}]
\Shell\AutoRun\command - G:\LaunchU3.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-06 23:22:43
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-06-06 23:33:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-06 21:33:24
Pre-Run: 6,789,693,440 bajtów wolnych
Post-Run: 7,088,533,504 bajt˘w wolnych
313 — E O F — 2008-02-26 18:40:34