Szalony Kojot
Użytkownik
- Dołączył
- Sierpień 31, 2006
- Posty
- 176
Oto logi z ComboFix nie wiem gdzie je umieścić więc daje tutaj:
ComboFix 07-11-08.1 - Azi 2007-11-17 13:11:46.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.409 [GMT 1:00]
Running from: E:ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.
2007-11-17 13:08 51,200 --a------ C:WINDOWSNirCmd.exe
2007-11-15 15:37 <DIR> d-------- Crogram FilesOpera
2007-11-15 15:12 <DIR> d-------- C:WINDOWSDED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2007-11-15 15:12 <DIR> d-------- Cocuments and SettingsAll UsersDane aplikacjiLavasoft
2007-11-15 15:02 <DIR> d--hs---- C:FOUND.002
2007-11-15 14:07 <DIR> dr-h----- Crogram Filesrnamfler
2007-11-15 10:12 <DIR> d--hs---- C:FOUND.001
2007-11-14 08:16 <DIR> d-------- Crogram FilesAshampoo
2007-11-03 19:44 <DIR> d-------- Cocuments and SettingsAll UsersDane aplikacjiDAEMON Tools Pro
2007-11-03 11:50 <DIR> d-------- Crogram FilesDAEMON Tools Pro
2007-11-01 19:35 <DIR> d-------- Crogram FilesDownload Express
2007-11-01 19:35 <DIR> d-------- Cocuments and SettingsDefault UserDane aplikacjiMetaProducts
2007-11-01 19:35 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiMetaProducts
2007-11-01 18:21 <DIR> d-------- Cocuments and SettingsAziDane aplikacjitheimagingfactory
2007-10-30 17:15 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiDAEMON Tools Pro
2007-10-30 17:14 90,112 --a------ Crogr_.dll
2007-10-29 16:43 98,304 --a------ C:WINDOWSsystem32CmdLineExt.dll
2007-10-28 21:20 <DIR> d--h----- C:host
2007-10-28 21:13 663,716 --ah----- C:WINDOWSsvhosted.exe
2007-10-28 18:52 53,248 --a------ C:WINDOWSsystem32suppdll.dll
2007-10-28 18:52 35,363 --a------ C:WINDOWSsystem32windrvNT.sys
2007-10-28 18:50 <DIR> d-------- Cocuments and SettingsAziWINDOWS
2007-10-28 17:48 <DIR> d-------- Cocuments and SettingsAll UsersDane aplikacjiLightScribe
2007-10-28 17:46 <DIR> d-------- Crogram Filesilliminable
2007-10-28 17:46 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiDroppix
2007-10-28 17:46 1,012,736 --a------ C:WINDOWSsystem32vorbis.dll
2007-10-28 17:46 12,800 --a------ C:WINDOWSsystem32ogg.dll
2007-10-28 17:45 <DIR> d-------- Crogram FilesCommon FilesLightScribe
2007-10-28 17:45 <DIR> d-------- Crogram FilesCommon FilesDroppix
2007-10-28 17:45 24,576 --a------ C:WINDOWSsystem32msxml3a.dll
2007-10-28 17:44 <DIR> d-------- Cocuments and SettingsAll UsersDane aplikacjiDroppix
2007-10-28 11:45 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiAutodesk
2007-10-28 11:41 2,297,552 --a------ C:WINDOWSsystem32d3dx9_26.dll
2007-10-28 11:36 169 --a------ C:WINDOWS.dat
2007-10-28 11:25 <DIR> d-------- Crogram FilesCommon FilesAutodesk Shared
2007-10-28 11:24 <DIR> d-------- Cocuments and SettingsAll UsersDane aplikacjiAutodesk
2007-10-18 19:42 <DIR> d-------- Crogram FilesMKVTOAVI
2007-10-18 19:34 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiApple Computer
2007-10-17 08:32 <DIR> d-------- Crogram FilesChameleon Clock
2007-10-17 07:09 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiWinamp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-25 16:44 8,488,960 ----a-w C:WINDOWSsystem32dllcacheshell32.dll
2007-10-16 19:31 --------- d-----w Cocuments and SettingsAziDane aplikacjiThinstall
2007-10-16 19:24 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiAzureus
2007-10-16 19:23 --------- d-----w Cocuments and SettingsAziDane aplikacjiAzureus
2007-10-16 07:14 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiSpybot - Search & Destroy
2007-10-15 16:27 --------- d-----w Crogram FilesWindows Media Connect 2
2007-10-14 19:19 685,816 ----a-w C:WINDOWSsystem32driverssptd.sys
2007-10-14 14:43 --------- d-----w Crogram FilesHP
2007-10-08 20:22 --------- d-----w Crogram FilesURUSoft
2007-10-08 19:07 2,321,408 ----a-w C:WINDOWSsystem32TUKernel.exe
2007-10-06 15:37 --------- d-----w Cocuments and SettingsAziDane aplikacjiMyPhoneExplorer
2007-10-06 15:36 --------- d-----w Crogram FilesMyPhoneExplorer
2007-10-06 14:42 --------- d-----w Crogram FilesFar
2007-09-30 16:59 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiApple Computer
2007-09-30 16:58 --------- d-----w Crogram FilesApple Software Update
2007-09-30 16:58 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiApple
2007-09-29 21:48 --------- d-----w Cocuments and SettingsAziDane aplikacjiTuneUp Software
2007-09-29 21:47 --------- d-----w Crogram FilesCommon FilesWise Installation Wizard
2007-09-29 21:47 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiTuneUp Software
2007-09-29 19:15 512,096 ----a-w C:WINDOWSsystem32driversamon.sys
2007-09-29 19:15 298,104 ----a-w C:WINDOWSsystem32imon.dll
2007-09-29 19:15 15,424 ----a-w C:WINDOWSsystem32driversnod32drv.sys
2007-09-29 12:00 --------- d-----w Cocuments and SettingsAziDane aplikacjiCorel
2007-09-29 11:55 --------- d-----w Crogram FilesCommon FilesCorel
2007-09-29 11:12 --------- d-----w Cocuments and SettingsAziDane aplikacjiReallusion
2007-09-29 10:36 940 ---ha-w C:hpothb07.dat
2007-09-27 16:40 68,208 ----a-w C:WINDOWSsystem32driversps7agqwb.sys
2007-09-27 16:40 64,616 ----a-w C:WINDOWSsystem32driverspe3agqwb.sys
2007-09-27 15:28 --------- d-----w Cocuments and SettingsAziDane aplikacjiNero
2007-09-27 15:21 --------- d-----w Crogram FilesNero
2007-09-27 15:21 --------- d-----w Crogram FilesCommon FilesNero
2007-09-27 15:21 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiNero
2007-09-24 11:29 --------- d-----w Crogram FilesEltima Software
2007-09-24 09:31 --------- d-----w Crogram FilesRex-team
2007-09-23 22:08 --------- d-----w Crogram FilesMacromedia
2007-09-23 22:08 --------- d-----w Crogram FilesCommon FilesMacromedia
2007-08-21 07:18 683,520 ----a-w C:WINDOWSsystem32inetcomm.dll
2007-08-21 07:18 683,520 ----a-w C:WINDOWSsystem32dllcacheinetcomm.dll
2007-08-20 11:01 824,832 ----a-w C:WINDOWSsystem32dllcachewininet.dll
2007-08-20 11:01 671,232 ----a-w C:WINDOWSsystem32dllcachemstime.dll
2007-08-20 11:01 63,488 ------w C:WINDOWSsystem32dllcacheicardie.dll
2007-08-20 11:01 6,058,496 ------w C:WINDOWSsystem32dllcacheieframe.dll
2007-08-20 11:01 52,224 ------w C:WINDOWSsystem32dllcachemsfeedsbs.dll
2007-08-20 11:01 477,696 ----a-w C:WINDOWSsystem32dllcachemshtmled.dll
2007-08-20 11:01 459,264 ------w C:WINDOWSsystem32dllcachemsfeeds.dll
2007-08-20 11:01 44,544 ----a-w C:WINDOWSsystem32dllcacheiernonce.dll
2007-08-20 11:01 384,512 ----a-w C:WINDOWSsystem32dllcacheiedkcs32.dll
2007-08-20 11:01 383,488 ------w C:WINDOWSsystem32dllcacheieapfltr.dll
2007-08-20 11:01 3,584,512 ----a-w C:WINDOWSsystem32dllcachemshtml.dll
2007-08-20 11:01 27,648 ----a-w C:WINDOWSsystem32dllcachejsproxy.dll
2007-08-20 11:01 267,776 ------w C:WINDOWSsystem32dllcacheiertutil.dll
2007-08-20 11:01 232,960 ----a-w C:WINDOWSsystem32dllcachewebcheck.dll
2007-08-20 11:01 230,400 ----a-w C:WINDOWSsystem32dllcacheieaksie.dll
2007-08-20 11:01 214,528 ----a-w C:WINDOWSsystem32dllcachedxtrans.dll
2007-08-20 11:01 193,024 ----a-w C:WINDOWSsystem32dllcachemsrating.dll
2007-08-20 11:01 153,088 ----a-w C:WINDOWSsystem32dllcacheieakeng.dll
2007-08-20 11:01 132,608 ----a-w C:WINDOWSsystem32dllcacheextmgr.dll
2007-08-20 11:01 124,928 ----a-w C:WINDOWSsystem32dllcacheadvpack.dll
2007-08-20 11:01 105,984 ----a-w C:WINDOWSsystem32dllcacheurl.dll
2007-08-20 11:01 102,400 ----a-w C:WINDOWSsystem32dllcacheoccache.dll
2007-08-20 11:01 1,152,000 ----a-w C:WINDOWSsystem32dllcacheurlmon.dll
2007-08-17 11:24 63,488 ----a-w C:WINDOWSsystem32dllcacheie4uinit.exe
2007-08-17 11:24 625,152 ----a-w C:WINDOWSsystem32dllcacheiexplore.exe
2007-08-17 11:24 13,824 ------w C:WINDOWSsystem32dllcacheieudinit.exe
2007-08-17 08:34 161,792 ----a-w C:WINDOWSsystem32dllcacheieakui.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Sony Ericsson PC Suite"="Crogram FilesSony EricssonMobile2Application LauncherApplication Launcher.exe" [2005-10-26 16:17]
"nod32kui"="Crogram FilesEsetnod32kui.exe" [2007-09-29 20:15]
"QuickTime Task"="Erogram FilesQuickTimeqttask.exe" [2007-06-29 05:24]
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"TuneUp MemOptimizer"="Erogram FilesTuneUp Utilities 2007MemOptimizer.exe" [2007-04-26 20:50]
"ctfmon.exe"="C:WINDOWSsystem32ctfmon.exe" [2004-08-04 12:00]
Cocuments and SettingsAziMenu StartProgramyAutostart
Adobe Gamma.lnk - Crogram FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe [2005-03-16 19:16:50]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"NoResolveSearch"=1 (0x1)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogon]
"UIHost"="C:WINDOWSsystem32logonui.exe"
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionrun-]
"CTFMON.EXE"=C:WINDOWSsystem32ctfmon.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionrun-]
"SunJavaUpdateSched"="Crogram FilesJavajre1.6.0_02binjusched.exe"
R0 pe3agqwb;Loki Environment Driver (pe3agqwb);C:WINDOWSsystem32driverspe3agqwb.sys
R0 pe3agqwc;Loki Environment Driver (pe3agqwc);C:WINDOWSsystem32driverspe3agqwc.sys
R0 ps6agqwc;Loki Synchronization Driver (ps6agqwc);C:WINDOWSsystem32driversps6agqwc.sys
R0 ps7agqwb;Loki Synchronization Driver (ps7agqwb);C:WINDOWSsystem32driversps7agqwb.sys
R1 fwdrv;Firewall Driver;C:WINDOWSsystem32driversfwdrv.sys
R1 khips;Kerio HIPS Driver;C:WINDOWSsystem32driverskhips.sys
R2 AASW2_Service;Ashampoo AntiSpyWare 2 Service;erogram FilesAshampooAshampoo AntiSpyWare 2AntiSpyWareService.exe
R2 mi-raysat_3dsMax2008_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit;"Drogram FilesAutodesk3ds Max 2008mentalraysatelliteraysat_3dsMax2008_32server.exe"
R2 UxTuneUp;TuneUp Theme Extension;C:WINDOWSSystem32svchost.exe -k netsvcs
R2 windrvNT;windrvNT;??C:WINDOWSsystem32windrvNT.sys
S2 pr2agqwb;Loki Drivers Auto Removal (pr2agqwb);C:WINDOWSsystem32pr2agqwb.exe svc
S2 pr2agqwc;Loki Drivers Auto Removal (pr2agqwc);C:WINDOWSsystem32pr2agqwc.exe svc
S3 musbehco;musbehco;??COCUME~1AziUSTAWI~1Tempmusbehco.sys
S4 Droppix Service;Droppix Service;"Crogram FilesCommon FilesDroppixDxService.exe"
S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;Crogram FilesNeroNero8Nero BackItUpNBService.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"Crogram FilesCommon FilesLightScribeLSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2007-11-10 19:17:14 C:WINDOWSTasks1-Click Maintenance.job"
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 13:16:03
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-17 13:18:01
.
--- E O F ---
I HJ:
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
Crogram FilesTGTSoftStyleXPStyleXPService.exe
Drogram FilesLavasoftAd-Aware 2007aawservice.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32ctfmon.exe
Crogram FilesEsetnod32kui.exe
Erogram FilesTuneUp Utilities 2007MemOptimizer.exe
C:WINDOWSsystem32devldr32.exe
erogram FilesAshampooAshampoo AntiSpyWare 2AntiSpyWareService.exe
Crogram FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe
Crogram FilesBonjourmDNSResponder.exe
Crogram FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe
Crogram FilesCommon FilesLightScribeLSSrvc.exe
Drogram FilesAutodesk3ds Max 2008mentalraysatelliteraysat_3dsMax2008_32server.exe
Crogram FilesEsetnod32krn.exe
C:WINDOWSsystem32oodag.exe
C:WINDOWSsystem32svchost.exe
Crogram FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe
Crogram FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe
Crogram FilesMozilla Firefoxfirefox.exe
Cocuments and SettingsAziPulpitIkonkihijackthisHijackThis.exe
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - Crogram FilesJavajre1.6.0_02binssv.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - Crogram FilesTGTSoftStyleXPTGT_BHO.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - CROGRA~1STARDO~1SDIEInt.dll
O4 - HKLM..Run: [Sony Ericsson PC Suite] "Crogram FilesSony EricssonMobile2Application LauncherApplication Launcher.exe" /startoptions
O4 - HKLM..Run: [nod32kui] "Crogram FilesEsetnod32kui.exe" /WAITSERVICE
O4 - HKLM..Run: [QuickTime Task] "Erogram FilesQuickTimeqttask.exe" -atboottime
O4 - HKCU..Run: [TuneUp MemOptimizer] "Erogram FilesTuneUp Utilities 2007MemOptimizer.exe" autostart
O4 - HKCU..Run: [STYLEXP] Crogram FilesTGTSoftStyleXPStyleXP.exe -Hide
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = Crogram FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O8 - Extra context menu item: Download with Star Downloader - Crogram FilesStar Downloadersdie.htm
O10 - Unknown file in Winsock LSP: crogram filesbonjourmdnsnsp.dll
O23 - Service: Ashampoo AntiSpyWare 2 Service (AASW2_Service) - Unknown owner - erogram FilesAshampooAshampoo AntiSpyWare 2AntiSpyWareService.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - Drogram FilesLavasoftAd-Aware 2007aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - Crogram FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - Crogram FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - Crogram FilesBonjourmDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - Crogram FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - Crogram FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - Crogram FilesCommon FilesLightScribeLSSrvc.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit (mi-raysat_3dsMax2008_32) - Unknown owner - Drogram FilesAutodesk3ds Max 2008mentalraysatelliteraysat_3dsMax2008_32server.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - Crogram FilesEsetnod32krn.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:WINDOWSsystem32oodag.exe
O23 - Service: Loki Drivers Auto Removal (pr2agqwb) (pr2agqwb) - Unknown owner - C:WINDOWSsystem32pr2agqwb.exe (file missing)
O23 - Service: Loki Drivers Auto Removal (pr2agqwc) (pr2agqwc) - Unknown owner - C:WINDOWSsystem32pr2agqwc.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - Crogram FilesTGTSoftStyleXPStyleXPService.exe
To co jest to nie mogę usunąć więc usunąłem pliki ...
ComboFix 07-11-08.1 - Azi 2007-11-17 13:11:46.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.409 [GMT 1:00]
Running from: E:ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.
2007-11-17 13:08 51,200 --a------ C:WINDOWSNirCmd.exe
2007-11-15 15:37 <DIR> d-------- Crogram FilesOpera
2007-11-15 15:12 <DIR> d-------- C:WINDOWSDED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2007-11-15 15:12 <DIR> d-------- Cocuments and SettingsAll UsersDane aplikacjiLavasoft
2007-11-15 15:02 <DIR> d--hs---- C:FOUND.002
2007-11-15 14:07 <DIR> dr-h----- Crogram Filesrnamfler
2007-11-15 10:12 <DIR> d--hs---- C:FOUND.001
2007-11-14 08:16 <DIR> d-------- Crogram FilesAshampoo
2007-11-03 19:44 <DIR> d-------- Cocuments and SettingsAll UsersDane aplikacjiDAEMON Tools Pro
2007-11-03 11:50 <DIR> d-------- Crogram FilesDAEMON Tools Pro
2007-11-01 19:35 <DIR> d-------- Crogram FilesDownload Express
2007-11-01 19:35 <DIR> d-------- Cocuments and SettingsDefault UserDane aplikacjiMetaProducts
2007-11-01 19:35 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiMetaProducts
2007-11-01 18:21 <DIR> d-------- Cocuments and SettingsAziDane aplikacjitheimagingfactory
2007-10-30 17:15 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiDAEMON Tools Pro
2007-10-30 17:14 90,112 --a------ Crogr_.dll
2007-10-29 16:43 98,304 --a------ C:WINDOWSsystem32CmdLineExt.dll
2007-10-28 21:20 <DIR> d--h----- C:host
2007-10-28 21:13 663,716 --ah----- C:WINDOWSsvhosted.exe
2007-10-28 18:52 53,248 --a------ C:WINDOWSsystem32suppdll.dll
2007-10-28 18:52 35,363 --a------ C:WINDOWSsystem32windrvNT.sys
2007-10-28 18:50 <DIR> d-------- Cocuments and SettingsAziWINDOWS
2007-10-28 17:48 <DIR> d-------- Cocuments and SettingsAll UsersDane aplikacjiLightScribe
2007-10-28 17:46 <DIR> d-------- Crogram Filesilliminable
2007-10-28 17:46 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiDroppix
2007-10-28 17:46 1,012,736 --a------ C:WINDOWSsystem32vorbis.dll
2007-10-28 17:46 12,800 --a------ C:WINDOWSsystem32ogg.dll
2007-10-28 17:45 <DIR> d-------- Crogram FilesCommon FilesLightScribe
2007-10-28 17:45 <DIR> d-------- Crogram FilesCommon FilesDroppix
2007-10-28 17:45 24,576 --a------ C:WINDOWSsystem32msxml3a.dll
2007-10-28 17:44 <DIR> d-------- Cocuments and SettingsAll UsersDane aplikacjiDroppix
2007-10-28 11:45 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiAutodesk
2007-10-28 11:41 2,297,552 --a------ C:WINDOWSsystem32d3dx9_26.dll
2007-10-28 11:36 169 --a------ C:WINDOWS.dat
2007-10-28 11:25 <DIR> d-------- Crogram FilesCommon FilesAutodesk Shared
2007-10-28 11:24 <DIR> d-------- Cocuments and SettingsAll UsersDane aplikacjiAutodesk
2007-10-18 19:42 <DIR> d-------- Crogram FilesMKVTOAVI
2007-10-18 19:34 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiApple Computer
2007-10-17 08:32 <DIR> d-------- Crogram FilesChameleon Clock
2007-10-17 07:09 <DIR> d-------- Cocuments and SettingsAziDane aplikacjiWinamp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-25 16:44 8,488,960 ----a-w C:WINDOWSsystem32dllcacheshell32.dll
2007-10-16 19:31 --------- d-----w Cocuments and SettingsAziDane aplikacjiThinstall
2007-10-16 19:24 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiAzureus
2007-10-16 19:23 --------- d-----w Cocuments and SettingsAziDane aplikacjiAzureus
2007-10-16 07:14 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiSpybot - Search & Destroy
2007-10-15 16:27 --------- d-----w Crogram FilesWindows Media Connect 2
2007-10-14 19:19 685,816 ----a-w C:WINDOWSsystem32driverssptd.sys
2007-10-14 14:43 --------- d-----w Crogram FilesHP
2007-10-08 20:22 --------- d-----w Crogram FilesURUSoft
2007-10-08 19:07 2,321,408 ----a-w C:WINDOWSsystem32TUKernel.exe
2007-10-06 15:37 --------- d-----w Cocuments and SettingsAziDane aplikacjiMyPhoneExplorer
2007-10-06 15:36 --------- d-----w Crogram FilesMyPhoneExplorer
2007-10-06 14:42 --------- d-----w Crogram FilesFar
2007-09-30 16:59 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiApple Computer
2007-09-30 16:58 --------- d-----w Crogram FilesApple Software Update
2007-09-30 16:58 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiApple
2007-09-29 21:48 --------- d-----w Cocuments and SettingsAziDane aplikacjiTuneUp Software
2007-09-29 21:47 --------- d-----w Crogram FilesCommon FilesWise Installation Wizard
2007-09-29 21:47 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiTuneUp Software
2007-09-29 19:15 512,096 ----a-w C:WINDOWSsystem32driversamon.sys
2007-09-29 19:15 298,104 ----a-w C:WINDOWSsystem32imon.dll
2007-09-29 19:15 15,424 ----a-w C:WINDOWSsystem32driversnod32drv.sys
2007-09-29 12:00 --------- d-----w Cocuments and SettingsAziDane aplikacjiCorel
2007-09-29 11:55 --------- d-----w Crogram FilesCommon FilesCorel
2007-09-29 11:12 --------- d-----w Cocuments and SettingsAziDane aplikacjiReallusion
2007-09-29 10:36 940 ---ha-w C:hpothb07.dat
2007-09-27 16:40 68,208 ----a-w C:WINDOWSsystem32driversps7agqwb.sys
2007-09-27 16:40 64,616 ----a-w C:WINDOWSsystem32driverspe3agqwb.sys
2007-09-27 15:28 --------- d-----w Cocuments and SettingsAziDane aplikacjiNero
2007-09-27 15:21 --------- d-----w Crogram FilesNero
2007-09-27 15:21 --------- d-----w Crogram FilesCommon FilesNero
2007-09-27 15:21 --------- d-----w Cocuments and SettingsAll UsersDane aplikacjiNero
2007-09-24 11:29 --------- d-----w Crogram FilesEltima Software
2007-09-24 09:31 --------- d-----w Crogram FilesRex-team
2007-09-23 22:08 --------- d-----w Crogram FilesMacromedia
2007-09-23 22:08 --------- d-----w Crogram FilesCommon FilesMacromedia
2007-08-21 07:18 683,520 ----a-w C:WINDOWSsystem32inetcomm.dll
2007-08-21 07:18 683,520 ----a-w C:WINDOWSsystem32dllcacheinetcomm.dll
2007-08-20 11:01 824,832 ----a-w C:WINDOWSsystem32dllcachewininet.dll
2007-08-20 11:01 671,232 ----a-w C:WINDOWSsystem32dllcachemstime.dll
2007-08-20 11:01 63,488 ------w C:WINDOWSsystem32dllcacheicardie.dll
2007-08-20 11:01 6,058,496 ------w C:WINDOWSsystem32dllcacheieframe.dll
2007-08-20 11:01 52,224 ------w C:WINDOWSsystem32dllcachemsfeedsbs.dll
2007-08-20 11:01 477,696 ----a-w C:WINDOWSsystem32dllcachemshtmled.dll
2007-08-20 11:01 459,264 ------w C:WINDOWSsystem32dllcachemsfeeds.dll
2007-08-20 11:01 44,544 ----a-w C:WINDOWSsystem32dllcacheiernonce.dll
2007-08-20 11:01 384,512 ----a-w C:WINDOWSsystem32dllcacheiedkcs32.dll
2007-08-20 11:01 383,488 ------w C:WINDOWSsystem32dllcacheieapfltr.dll
2007-08-20 11:01 3,584,512 ----a-w C:WINDOWSsystem32dllcachemshtml.dll
2007-08-20 11:01 27,648 ----a-w C:WINDOWSsystem32dllcachejsproxy.dll
2007-08-20 11:01 267,776 ------w C:WINDOWSsystem32dllcacheiertutil.dll
2007-08-20 11:01 232,960 ----a-w C:WINDOWSsystem32dllcachewebcheck.dll
2007-08-20 11:01 230,400 ----a-w C:WINDOWSsystem32dllcacheieaksie.dll
2007-08-20 11:01 214,528 ----a-w C:WINDOWSsystem32dllcachedxtrans.dll
2007-08-20 11:01 193,024 ----a-w C:WINDOWSsystem32dllcachemsrating.dll
2007-08-20 11:01 153,088 ----a-w C:WINDOWSsystem32dllcacheieakeng.dll
2007-08-20 11:01 132,608 ----a-w C:WINDOWSsystem32dllcacheextmgr.dll
2007-08-20 11:01 124,928 ----a-w C:WINDOWSsystem32dllcacheadvpack.dll
2007-08-20 11:01 105,984 ----a-w C:WINDOWSsystem32dllcacheurl.dll
2007-08-20 11:01 102,400 ----a-w C:WINDOWSsystem32dllcacheoccache.dll
2007-08-20 11:01 1,152,000 ----a-w C:WINDOWSsystem32dllcacheurlmon.dll
2007-08-17 11:24 63,488 ----a-w C:WINDOWSsystem32dllcacheie4uinit.exe
2007-08-17 11:24 625,152 ----a-w C:WINDOWSsystem32dllcacheiexplore.exe
2007-08-17 11:24 13,824 ------w C:WINDOWSsystem32dllcacheieudinit.exe
2007-08-17 08:34 161,792 ----a-w C:WINDOWSsystem32dllcacheieakui.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Sony Ericsson PC Suite"="Crogram FilesSony EricssonMobile2Application LauncherApplication Launcher.exe" [2005-10-26 16:17]
"nod32kui"="Crogram FilesEsetnod32kui.exe" [2007-09-29 20:15]
"QuickTime Task"="Erogram FilesQuickTimeqttask.exe" [2007-06-29 05:24]
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"TuneUp MemOptimizer"="Erogram FilesTuneUp Utilities 2007MemOptimizer.exe" [2007-04-26 20:50]
"ctfmon.exe"="C:WINDOWSsystem32ctfmon.exe" [2004-08-04 12:00]
Cocuments and SettingsAziMenu StartProgramyAutostart
Adobe Gamma.lnk - Crogram FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe [2005-03-16 19:16:50]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"NoResolveSearch"=1 (0x1)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogon]
"UIHost"="C:WINDOWSsystem32logonui.exe"
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionrun-]
"CTFMON.EXE"=C:WINDOWSsystem32ctfmon.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionrun-]
"SunJavaUpdateSched"="Crogram FilesJavajre1.6.0_02binjusched.exe"
R0 pe3agqwb;Loki Environment Driver (pe3agqwb);C:WINDOWSsystem32driverspe3agqwb.sys
R0 pe3agqwc;Loki Environment Driver (pe3agqwc);C:WINDOWSsystem32driverspe3agqwc.sys
R0 ps6agqwc;Loki Synchronization Driver (ps6agqwc);C:WINDOWSsystem32driversps6agqwc.sys
R0 ps7agqwb;Loki Synchronization Driver (ps7agqwb);C:WINDOWSsystem32driversps7agqwb.sys
R1 fwdrv;Firewall Driver;C:WINDOWSsystem32driversfwdrv.sys
R1 khips;Kerio HIPS Driver;C:WINDOWSsystem32driverskhips.sys
R2 AASW2_Service;Ashampoo AntiSpyWare 2 Service;erogram FilesAshampooAshampoo AntiSpyWare 2AntiSpyWareService.exe
R2 mi-raysat_3dsMax2008_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit;"Drogram FilesAutodesk3ds Max 2008mentalraysatelliteraysat_3dsMax2008_32server.exe"
R2 UxTuneUp;TuneUp Theme Extension;C:WINDOWSSystem32svchost.exe -k netsvcs
R2 windrvNT;windrvNT;??C:WINDOWSsystem32windrvNT.sys
S2 pr2agqwb;Loki Drivers Auto Removal (pr2agqwb);C:WINDOWSsystem32pr2agqwb.exe svc
S2 pr2agqwc;Loki Drivers Auto Removal (pr2agqwc);C:WINDOWSsystem32pr2agqwc.exe svc
S3 musbehco;musbehco;??COCUME~1AziUSTAWI~1Tempmusbehco.sys
S4 Droppix Service;Droppix Service;"Crogram FilesCommon FilesDroppixDxService.exe"
S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;Crogram FilesNeroNero8Nero BackItUpNBService.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"Crogram FilesCommon FilesLightScribeLSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2007-11-10 19:17:14 C:WINDOWSTasks1-Click Maintenance.job"
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 13:16:03
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-17 13:18:01
.
--- E O F ---
I HJ:
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
Crogram FilesTGTSoftStyleXPStyleXPService.exe
Drogram FilesLavasoftAd-Aware 2007aawservice.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32ctfmon.exe
Crogram FilesEsetnod32kui.exe
Erogram FilesTuneUp Utilities 2007MemOptimizer.exe
C:WINDOWSsystem32devldr32.exe
erogram FilesAshampooAshampoo AntiSpyWare 2AntiSpyWareService.exe
Crogram FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe
Crogram FilesBonjourmDNSResponder.exe
Crogram FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe
Crogram FilesCommon FilesLightScribeLSSrvc.exe
Drogram FilesAutodesk3ds Max 2008mentalraysatelliteraysat_3dsMax2008_32server.exe
Crogram FilesEsetnod32krn.exe
C:WINDOWSsystem32oodag.exe
C:WINDOWSsystem32svchost.exe
Crogram FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe
Crogram FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe
Crogram FilesMozilla Firefoxfirefox.exe
Cocuments and SettingsAziPulpitIkonkihijackthisHijackThis.exe
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - Crogram FilesJavajre1.6.0_02binssv.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - Crogram FilesTGTSoftStyleXPTGT_BHO.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - CROGRA~1STARDO~1SDIEInt.dll
O4 - HKLM..Run: [Sony Ericsson PC Suite] "Crogram FilesSony EricssonMobile2Application LauncherApplication Launcher.exe" /startoptions
O4 - HKLM..Run: [nod32kui] "Crogram FilesEsetnod32kui.exe" /WAITSERVICE
O4 - HKLM..Run: [QuickTime Task] "Erogram FilesQuickTimeqttask.exe" -atboottime
O4 - HKCU..Run: [TuneUp MemOptimizer] "Erogram FilesTuneUp Utilities 2007MemOptimizer.exe" autostart
O4 - HKCU..Run: [STYLEXP] Crogram FilesTGTSoftStyleXPStyleXP.exe -Hide
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = Crogram FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O8 - Extra context menu item: Download with Star Downloader - Crogram FilesStar Downloadersdie.htm
O10 - Unknown file in Winsock LSP: crogram filesbonjourmdnsnsp.dll
O23 - Service: Ashampoo AntiSpyWare 2 Service (AASW2_Service) - Unknown owner - erogram FilesAshampooAshampoo AntiSpyWare 2AntiSpyWareService.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - Drogram FilesLavasoftAd-Aware 2007aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - Crogram FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - Crogram FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - Crogram FilesBonjourmDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - Crogram FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - Crogram FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - Crogram FilesCommon FilesLightScribeLSSrvc.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit (mi-raysat_3dsMax2008_32) - Unknown owner - Drogram FilesAutodesk3ds Max 2008mentalraysatelliteraysat_3dsMax2008_32server.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - Crogram FilesEsetnod32krn.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:WINDOWSsystem32oodag.exe
O23 - Service: Loki Drivers Auto Removal (pr2agqwb) (pr2agqwb) - Unknown owner - C:WINDOWSsystem32pr2agqwb.exe (file missing)
O23 - Service: Loki Drivers Auto Removal (pr2agqwc) (pr2agqwc) - Unknown owner - C:WINDOWSsystem32pr2agqwc.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - Crogram FilesTGTSoftStyleXPStyleXPService.exe
To co jest to nie mogę usunąć więc usunąłem pliki ...