teraz jest biale tlo.
oto log z combofixa:
ComboFix 08-05-01.3 - gkopcza 2008-05-05 9:47:45.3 - FAT32 x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.91 [GMT 1:00]
Running from: C:\Documents and Settings\gkopcza\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\gkopcza\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
FILE ::
C:\WINDOWS\tdomgafw.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Search Settings
C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
C:\Program Files\Search Settings\SearchSettings.exe
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\tdomgafw.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-05 to 2008-05-05 )))))))))))))))))))))))))))))))
.
2008-05-05 00:42 . 2008-05-05 00:42
2008-05-05 00:04 . 2008-05-05 00:04 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-05-04 10:18 . 2008-05-04 10:18
2008-05-04 09:54 . 2008-05-04 09:54
2008-05-04 09:54 . 2008-05-04 09:54
2008-05-04 09:52 . 2008-05-04 09:52
2008-05-04 09:14 . 2008-05-04 09:14
2008-05-04 08:55 . 2008-05-04 08:55
2008-05-04 03:36 . 2008-05-04 01:07 94,208 --a------ C:\WINDOWS\svorbmke.exe
2008-05-04 03:36 . 2008-05-04 01:08 81,920 --a------ C:\WINDOWS\knxsrgte.exe
2008-04-22 20:09 . 2008-04-22 20:09
2008-04-22 15:05 . 2004-05-25 17:06 417,792 --a------ C:\WINDOWS\system32\ac3filter.ax
2008-04-22 15:05 . 2005-02-27 21:48 356,352 --a------ C:\WINDOWS\system32\RealMediaSplitter.ax
2008-04-22 15:02 . 2008-04-22 15:02
2008-04-22 15:00 . 2008-04-22 15:00 38 --a------ C:\WINDOWS\avisplitter.INI
2008-04-22 14:48 . 2008-04-22 14:48
2008-04-22 14:39 . 2008-04-22 14:39
2008-04-18 17:14 . 2008-04-18 17:14
2008-04-18 17:14 . 2008-04-18 17:14
2008-04-12 10:47 . 2008-04-12 10:47
2008-04-10 18:20 . 2008-05-04 10:21 268 --ah----- C:\sqmdata19.sqm
2008-04-10 18:20 . 2008-05-04 10:21 244 --ah----- C:\sqmnoopt19.sqm
2008-04-10 15:29 . 2008-05-04 09:40 268 --ah----- C:\sqmdata18.sqm
2008-04-10 15:29 . 2008-05-04 09:40 244 --ah----- C:\sqmnoopt18.sqm
2008-04-10 13:44 . 2008-05-03 17:34 268 --ah----- C:\sqmdata17.sqm
2008-04-10 13:44 . 2008-05-03 17:34 244 --ah----- C:\sqmnoopt17.sqm
2008-04-10 12:19 . 2008-05-03 11:30 268 --ah----- C:\sqmdata16.sqm
2008-04-10 12:19 . 2008-05-03 11:30 244 --ah----- C:\sqmnoopt16.sqm
2008-04-10 10:01 . 2008-04-10 10:01 335 --a------ C:\WINDOWS\mozregistry.dat
2008-04-10 09:57 . 2008-05-03 00:08 268 --ah----- C:\sqmdata15.sqm
2008-04-10 09:57 . 2008-05-03 00:08 244 --ah----- C:\sqmnoopt15.sqm
2008-04-10 09:26 . 2008-05-02 15:59 268 --ah----- C:\sqmdata14.sqm
2008-04-10 09:26 . 2008-05-02 15:59 244 --ah----- C:\sqmnoopt14.sqm
2008-04-09 22:44 . 2008-05-02 09:53 268 --ah----- C:\sqmdata13.sqm
2008-04-09 22:44 . 2008-05-02 09:53 244 --ah----- C:\sqmnoopt13.sqm
2008-04-09 07:34 . 2008-04-09 07:34
2008-04-07 14:07 . 2008-04-07 14:08
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-31 22:25 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2008-03-28 18:41 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2008-03-21 21:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 21:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-20 10:10 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-03-20 09:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 09:09 1,845,504 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-15 16:33 --------- d-----w C:\Program Files\SopCast
2008-03-10 14:50 --------- d-----w C:\Program Files\F1 Challenge 2007
2008-03-01 14:02 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-01 14:02 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-01 14:02 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-01 14:02 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-01 14:02 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-01 14:02 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2008-02-22 11:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-20 07:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 07:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 06:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 06:38 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 06:38 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-18 10:23 4,608 ----a-w C:\WINDOWS\system32\w95inf32.dll
2008-02-18 10:23 2,272 ----a-w C:\WINDOWS\system32\w95inf16.dll
2008-02-16 14:46 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 13:00 15360]
“DAEMON Tools Lite”=“C:\Program Files\DAEMON Tools Lite\daemon.exe” [2008-02-14 00:09 486856]
“msnmsgr”=“C:\Program Files\MSN Messenger\msnmsgr.exe” [2007-01-19 12:54 5674352]
“Odkurzacz-MCD”=“C:\Program Files\Odkurzacz\odk_mcd.exe” [2008-02-04 18:13 266240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“HControl”=“C:\WINDOWS\ATK0100\HControl.exe” [2006-04-17 02:24 110592]
“Zshutdown”=“c:\sysprep\patch\sysprep.cmd” []
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe” [2008-02-22 04:25 144784]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 22:16 39792]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2008-01-31 23:13 385024]
“iTunesHelper”=“C:\Program Files\iTunes\iTunesHelper.exe” [2008-02-04 14:18 267048]
“RemoteControl”=“C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe” [2005-01-12 03:01 32768]
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2006-01-12 16:40 155648]
“Wireless Console 2”=“C:\Program Files\Wireless Console 2\wcourier.exe” [2005-10-17 17:09 987136]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-04-26 19:48 7561216]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 13:00 15360]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
“tdomgafw”= {D9351C96-12FB-4B9A-9232-FCEEC79A70D1} - C:\WINDOWS\tdomgafw.dll []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“VIDC.ACDV”= ACDV.dll
“vidc.asv2”= asusasv2.dll
“VIDC.YV12”= yv12vfw.dll
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DSLMON.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk
backup=C:\WINDOWS\pss\DSLMON.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\05663211184888321335963662509937]
C:\Program Files\XP Antivirus\xpa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
–a------ 2005-05-03 03:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Antivirus]
C:\Program Files\Antivirus 2008\Antvrs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Live Update]
–a------ 2006-02-21 15:20 180224 C:\Program Files\ASUS\ASUS Live Update\ALU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\e©ůýůüűďţóÎŃřřÁřôÄĘýÜńűĘŢó]
C:\Program Files\XP Antivirus\xpa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a------ 2006-04-26 19:48 7561216 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a------ 2006-04-26 19:48 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a------ 2006-04-26 19:48 1519616 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a------ 2005-12-18 23:52 15797248 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
–a------ 2006-01-19 21:34 544768 C:\WINDOWS\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
–a------ 2005-10-20 23:26 761945 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a------ 2006-11-21 18:38 35328 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console 2]
–a------ 2005-10-17 17:09 987136 C:\Program Files\Wireless Console 2\wcourier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusOverride”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Bonjour\mDNSResponder.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“C:\Program Files\Gadu-Gadu\gg.exe”=
“C:\Program Files\uTorrent\utorrent.exe”=
“C:\Program Files\MSN Messenger\msnmsgr.exe”=
“C:\Program Files\MSN Messenger\livecall.exe”=
“C:\Program Files\SopCast\SopCast.exe”=
“C:\Program Files\SopCast\adv\SopAdver.exe”=
“C:\Program Files\iTunes\iTunes.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 18:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 18:35]
R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\WINDOWS\system32\ASNDIS5.SYS [2002-09-09 19:54]
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 14:49]
R3 SynMini;USB2.0 1.3M Web Cam;C:\WINDOWS\system32\Drivers\SynMini.sys [2005-10-03 10:26]
R3 SynScan;USB2.0 1.3M Web Cam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys [2005-10-03 10:26]
S2 ELOADER;General Purpose USB Driver (adildr.sys);C:\WINDOWS\system32\Drivers\adildr.sys [2007-02-07 16:50]
.
Contents of the ‘Scheduled Tasks’ folder
“2008-04-22 14:43:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job”
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-05 09:50:50
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\LAVASOFT\AD-AWARE 2007\AAWSERVICE.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\PROGRAM FILES\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-05-05 9:52:48 - machine was rebooted
ComboFix2.txt 2008-05-05 00:04:20
ComboFix-quarantined-files.txt 2008-05-05 08:52:38
Pre-Run: 2,278,768,640 bajtów wolnych
Post-Run: 2,269,888,512 bajt˘w wolnych
217 — E O F — 2008-05-05 08:43:53