wiem, że kiedyś już miałem, bo brat dziś podłączył telefon, i znów jest ;/
Próbowałem : Spyware Doctor'em , usunął się, a następnie znów powrócił, combofix też nie dał rady
Log z combofix'a
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.2047.1365 [GMT 1:00]
Uruchomiony z: e:\documents and settings\admin\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\windows\mstray.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2009-01-25 do 2009-02-25 )))))))))))))))))))))))))))))))
.
2009-02-25 15:36 . 2009-02-25 15:36 <DIR> d-------- e:\program files\SkanerOnline
2009-02-25 15:35 . 2009-02-25 15:36 <DIR> d-------- e:\documents and settings\admin\Dane aplikacji\HPAppData
2009-02-25 12:20 . 2009-02-25 12:24 <DIR> d-------- e:\program files\Spyware Doctor
2009-02-25 12:20 . 2009-02-25 12:20 <DIR> d-------- e:\documents and settings\admin\Dane aplikacji\PC Tools
2009-02-25 12:20 . 2008-08-25 12:36 81,288 --a------ e:\windows\system32\drivers\iksyssec.sys
2009-02-25 12:20 . 2008-08-25 12:36 66,952 --a------ e:\windows\system32\drivers\iksysflt.sys
2009-02-25 12:20 . 2008-08-25 12:36 40,840 --a------ e:\windows\system32\drivers\ikfilesec.sys
2009-02-25 12:20 . 2008-06-02 16:19 29,576 --a------ e:\windows\system32\drivers\kcom.sys
2009-02-25 12:05 . 2009-02-25 12:05 697 ---hs---- E:\comment.htt
2009-02-25 12:05 . 2009-02-25 12:05 72 ---hs---- E:\desktop.ini
2009-02-24 18:24 . 2008-04-14 00:15 26,112 --a------ e:\windows\system32\drivers\usbser.sys
2009-02-24 18:24 . 2008-04-14 00:15 26,112 --a--c--- e:\windows\system32\dllcache\usbser.sys
2009-02-24 18:24 . 2008-03-21 13:57 14,640 --------- e:\windows\system32\spmsgXP_2k3.dll
2009-02-24 18:24 . 2009-02-24 18:24 0 --ah----- e:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-02-24 18:24 . 2009-02-24 18:24 0 --ah----- e:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-02-24 18:23 . 2009-02-24 18:23 <DIR> d-------- e:\documents and settings\All Users\Dane aplikacji\PC Suite
2009-02-24 18:23 . 2009-02-24 18:25 <DIR> d-------- e:\documents and settings\admin\Dane aplikacji\PC Suite
2009-02-24 18:23 . 2009-02-24 18:23 <DIR> d-------- e:\documents and settings\admin\Dane aplikacji\Nokia
2009-02-24 18:22 . 2009-02-24 18:22 <DIR> d-------- e:\program files\PC Connectivity Solution
2009-02-24 18:22 . 2009-02-24 18:22 <DIR> d-------- e:\program files\Nokia
2009-02-24 18:22 . 2009-02-24 18:22 <DIR> d-------- e:\program files\DIFX
2009-02-24 18:22 . 2009-02-24 18:22 <DIR> d-------- e:\program files\Common Files\PCSuite
2009-02-24 18:22 . 2009-02-24 18:22 <DIR> d-------- e:\program files\Common Files\Nokia
2009-02-24 18:22 . 2008-09-15 07:29 1,112,288 --a------ e:\windows\system32\wdfcoinstaller01007.dll
2009-02-24 18:22 . 2008-09-15 07:56 659,968 --a------ e:\windows\system32\nmwcdcocls.dll
2009-02-24 18:22 . 2008-09-15 07:56 91,136 --a------ e:\windows\system32\nmwcdcls.dll
2009-02-24 18:22 . 2008-09-15 07:56 22,016 --a------ e:\windows\system32\drivers\ccdcmbo.sys
2009-02-24 18:22 . 2008-08-26 09:26 18,816 --a------ e:\windows\system32\drivers\pccsmcfd.sys
2009-02-24 18:22 . 2008-09-15 07:56 17,664 --a------ e:\windows\system32\drivers\ccdcmb.sys
2009-02-24 18:22 . 2008-09-15 07:56 8,064 --a------ e:\windows\system32\drivers\usbser_lowerfltj.sys
2009-02-24 18:22 . 2008-09-15 07:56 8,064 --a------ e:\windows\system32\drivers\usbser_lowerflt.sys
2009-02-24 18:21 . 2009-02-24 18:21 <DIR> d-------- e:\documents and settings\All Users\Dane aplikacji\Installations
2009-02-24 16:10 . 2009-02-24 16:10 118,784 --a------ e:\windows\SeaMonkeyUninstall.exe
2009-02-24 16:09 . 2009-02-24 16:09 <DIR> d-------- e:\program files\mozilla.org
2009-02-24 16:09 . 2009-02-24 16:09 <DIR> d-------- e:\program files\Common Files\mozilla.org
2009-02-24 16:09 . 2009-02-24 16:09 118,784 --a------ e:\windows\GREUninstall.exe
2009-02-24 16:09 . 2009-02-24 16:10 7,738 --a------ e:\windows\mozver.dat
2009-02-24 10:54 . 2009-02-24 16:04 <DIR> d-------- e:\documents and settings\admin\Dane aplikacji\skypePM
2009-02-24 10:54 . 2009-02-24 10:54 56 --ah----- e:\windows\system32\ezsidmv.dat
2009-02-24 10:53 . 2009-02-24 10:53 <DIR> dr------- e:\program files\Skype
2009-02-24 10:53 . 2009-02-24 10:53 <DIR> d-------- e:\program files\Common Files\Skype
2009-02-24 10:53 . 2009-02-24 10:53 <DIR> d-------- e:\documents and settings\All Users\Dane aplikacji\Skype
2009-02-24 10:53 . 2009-02-25 14:39 <DIR> d-------- e:\documents and settings\admin\Dane aplikacji\Skype
2009-02-24 09:36 . 2009-02-24 09:36 <DIR> d-------- e:\documents and settings\All Users\Dane aplikacji\WEBREG
2009-02-24 09:36 . 2009-02-24 09:36 <DIR> d-------- e:\documents and settings\admin\Dane aplikacji\HP
2009-02-23 16:39 . 2007-10-30 10:11 729,088 -ra------ e:\windows\system32\hpowiax7.dll
2009-02-23 16:39 . 2007-10-30 10:11 581,632 -ra------ e:\windows\system32\hpotscl6.dll
2009-02-23 16:39 . 2007-10-30 10:11 303,104 -ra------ e:\windows\system32\hpovst15.dll
2009-02-23 16:39 . 2008-04-14 00:15 15,104 --a------ e:\windows\system32\drivers\usbscan.sys
2009-02-23 16:39 . 2008-04-14 00:15 15,104 --a--c--- e:\windows\system32\dllcache\usbscan.sys
2009-02-23 16:37 . 2009-02-23 16:37 <DIR> d-------- e:\documents and settings\All Users\Dane aplikacji\HP Product Assistant
2009-02-23 16:37 . 2009-02-23 16:37 <DIR> d-------- e:\documents and settings\All Users\Dane aplikacji\HP
2009-02-23 16:37 . 2009-02-23 16:37 0 --a------ e:\windows\system32\YOYO
2009-02-23 16:36 . 2009-02-23 16:36 <DIR> d-------- e:\program files\Hewlett-Packard
2009-02-23 16:36 . 2009-02-23 16:36 <DIR> d-------- e:\program files\Common Files\HP
2009-02-23 16:36 . 2009-02-23 16:36 <DIR> d-------- e:\program files\Common Files\Hewlett-Packard
2009-02-23 16:35 . 2009-02-23 16:37 <DIR> d-------- e:\program files\HP
2009-02-23 16:34 . 2009-02-23 16:34 <DIR> d-------- e:\documents and settings\All Users\Dane aplikacji\Hewlett-Packard
2009-02-23 16:34 . 2007-11-08 15:52 271,704 -ra------ e:\windows\system32\hpzids01.dll
2009-02-23 16:34 . 2009-02-24 09:36 169,233 --a------ e:\windows\hpoins27.dat
2009-02-23 16:34 . 2007-10-20 18:25 117,760 --a------ e:\windows\system32\hpzll5mu.dll
2009-02-23 16:34 . 2007-10-30 10:25 49,920 -ra------ e:\windows\system32\drivers\HPZid412.sys
2009-02-23 16:34 . 2007-10-30 10:25 16,496 -ra------ e:\windows\system32\drivers\HPZipr12.sys
2009-02-23 16:34 . 2008-01-18 16:56 932 --------- e:\windows\hpomdl27.dat
2009-02-23 16:33 . 2009-02-24 18:23 <DIR> d----c--- e:\windows\system32\DRVSTORE
2009-02-23 16:33 . 2007-10-30 10:25 372,736 -ra------ e:\windows\system32\hppldcoi.dll
2009-02-23 16:33 . 2007-10-30 10:25 309,760 -ra------ e:\windows\system32\difxapi.dll
2009-02-23 16:33 . 2008-04-14 00:17 25,856 --a------ e:\windows\system32\drivers\usbprint.sys
2009-02-23 16:33 . 2008-04-14 00:17 25,856 --a--c--- e:\windows\system32\dllcache\usbprint.sys
2009-02-23 16:33 . 2007-10-30 10:25 21,568 -ra------ e:\windows\system32\drivers\HPZius12.sys
2009-02-23 10:20 . 2009-02-23 10:20 <DIR> d-------- e:\program files\Common Files\NSV
2009-02-23 10:16 . 2009-02-23 10:18 <DIR> d-------- e:\program files\Winamp
2009-02-23 10:16 . 2009-02-23 10:20 <DIR> d-------- e:\documents and settings\admin\Dane aplikacji\Winamp
2009-02-22 18:10 . 2009-02-22 18:10 <DIR> d-------- e:\windows\Sun
2009-02-22 16:42 . 2009-02-22 16:43 <DIR> d-------- e:\program files\fsfs
2009-02-21 21:15 . 2009-02-21 21:15 <DIR> d-------- e:\program files\TeamViewer
2009-02-21 21:15 . 2009-02-21 21:21 <DIR> d-------- e:\documents and settings\admin\Dane aplikacji\TeamViewer
2009-02-21 21:14 . 2009-02-21 21:14 <DIR> d-------- e:\documents and settings\admin\temp
2009-02-21 15:29 . 2008-04-14 22:51 221,184 --a------ e:\windows\system32\wmpns.dll
2009-02-21 14:50 . 2009-02-25 13:07 <DIR> d-a------ e:\documents and settings\All Users\Dane aplikacji\TEMP
2009-02-21 14:14 . 2008-04-14 00:15 32,128 --a------ e:\windows\system32\drivers\usbccgp.sys
2009-02-21 14:14 . 2008-04-14 00:15 32,128 --a--c--- e:\windows\system32\dllcache\usbccgp.sys
2009-02-21 14:14 . 2008-04-14 00:15 26,368 --a--c--- e:\windows\system32\dllcache\usbstor.sys
2009-02-21 10:42 . 2009-02-21 10:41 410,984 --a------ e:\windows\system32\deploytk.dll
2009-02-21 10:42 . 2009-02-21 10:41 73,728 --a------ e:\windows\system32\javacpl.cpl
2009-02-21 10:41 . 2009-02-21 10:41 <DIR> d-------- e:\program files\Java
2009-02-21 10:26 . 2009-02-21 10:26 <DIR> d-------- e:\documents and settings\admin\Dane aplikacji\Gadu-Gadu
2009-02-21 10:23 . 2009-02-21 10:23 <DIR> d-------- e:\program files\Gadu-Gadu
2009-02-20 19:55 . 2009-02-20 19:55 <DIR> d-------- e:\program files\7-Zip
2009-02-20 19:46 . 2009-02-20 19:46 <DIR> d-------- e:\program files\MSBuild
2009-02-20 19:44 . 2009-02-20 19:44 <DIR> d-------- e:\windows\system32\XPSViewer
2009-02-20 19:44 . 2009-02-20 19:44 <DIR> d-------- e:\program files\Reference Assemblies
2009-02-20 19:43 . 2006-06-29 13:07 14,048 --------- e:\windows\system32\spmsg2.dll
2009-02-20 19:33 . 2009-02-20 19:33 <DIR> d-------- e:\windows\system32\xlive
2009-02-20 19:33 . 2009-02-20 19:33 <DIR> d-------- e:\program files\Microsoft Games for Windows - LIVE
2009-02-20 19:33 . 2008-03-05 15:56 3,786,760 --a------ e:\windows\system32\D3DX9_37.dll
2009-02-20 19:33 . 2008-03-05 15:56 1,420,824 --a------ e:\windows\system32\D3DCompiler_37.dll
2009-02-20 19:33 . 2008-02-05 23:07 462,864 --a------ e:\windows\system32\d3dx10_37.dll
2009-02-20 19:33 . 2007-04-04 18:53 81,768 --a------ e:\windows\system32\xinput1_3.dll
2009-02-20 19:16 . 2009-02-20 19:16 <DIR> d-------- e:\windows\ServicePackFiles
2009-02-20 19:15 . 2008-04-14 22:51 294,912 -----c--- e:\windows\system32\dllcache\dlimport.exe
2009-02-20 19:12 . 2006-12-29 00:31 19,569 --a------ e:\windows\002691_.tmp
2009-02-20 18:31 . 2009-02-21 18:59 <DIR> d-------- e:\program files\Common Files\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-20 16:02 315,392 ----a-w e:\windows\HideWin.exe
2009-02-20 16:02 --------- d--h--w e:\program files\InstallShield Installation Information
2009-02-20 16:02 --------- d-----w e:\program files\Realtek
2009-02-20 16:01 --------- d-----w e:\program files\Common Files\InstallShield
2009-02-20 15:59 --------- d-----w e:\program files\AutoConnect
2009-02-20 15:49 --------- d-----w e:\program files\Konnekt
2009-02-20 15:46 --------- d-----w e:\program files\Thomson
2009-02-20 15:40 --------- d-----w e:\program files\AGEIA Technologies
2009-02-20 15:39 --------- d-----w e:\program files\Common Files\Wise Installation Wizard
2009-02-20 15:31 --------- d-----w e:\program files\microsoft frontpage
2009-02-20 15:30 --------- d-----w e:\program files\Usługi online
2009-01-21 16:11 473,600 ----a-w e:\windows\system32\SkanerOnline.dll
2009-01-07 10:28 453,152 ----a-w e:\windows\system32\NVUNINST.EXE
2008-12-10 08:45 70,936 ----a-w e:\windows\system32\PhysXLoader.dll
2008-12-04 08:28 24,344 ----a-w e:\windows\system32\PhysXDevice.dll
2008-11-26 07:55 288,024 ----a-w e:\windows\system32\PhysXCplUI.exe
2008-11-25 07:38 288,024 ----a-w e:\windows\system32\PhysXCompatCplUI.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Konnekt"="e:\program files\Konnekt\konnekt.exe" [2005-05-24 503808]
"RGSC"="d:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2009-01-02 306088]
"Gadu-Gadu"="e:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"MSMSGS"="e:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="e:\program files\Skype\Phone\Skype.exe" [2009-02-04 23975720]
"PC Suite Tray"="e:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"EXPLORER.EXE"="EXPLORER.EXE" [2008-04-14 e:\windows\explorer.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"SpeedTouch USB Diagnostics"="e:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="e:\program files\Java\jre6\bin\jusched.exe" [2009-02-21 148888]
"WinampAgent"="e:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"HP Software Update"="e:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="e:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"nwiz"="nwiz.exe" [2009-01-15 e:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 e:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
e:\documents and settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - e:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"d:\\Program Files\\Steam\\steamapps\\stec_kamil\\counter-strike\\hl.exe"=
"e:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"e:\\WINDOWS\\system32\\java.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"e:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"d:\\Program Files\\Steam\\Steam.exe"=
"e:\\Program Files\\Skype\\Phone\\Skype.exe"=
S3 sdAuxService;PC Tools Auxiliary Service;e:\program files\Spyware Doctor\pctsAuxs.exe [2009-02-25 356920]
--- Inne Usługi/Sterowniki w Pamięci ---
*NewlyCreated* - IKFILESEC
*NewlyCreated* - IKSYSFLT
*NewlyCreated* - IKSYSSEC
*NewlyCreated* - MCHINJDRV
*NewlyCreated* - SDAUXSERVICE
*NewlyCreated* - SDCORESERVICE
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38491f85-0322-11de-8cb0-000e50f3c6d9}]
\Shell\AutoRun\command - G:\EXPLORER.EXE
\Shell\explore\Command - G:\EXPLORER.EXE
\Shell\open\Command - G:\EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38491f86-0322-11de-8cb0-000e50f3c6d9}]
\Shell\AutoRun\command - H:\EXPLORER.EXE
\Shell\explore\Command - H:\EXPLORER.EXE
\Shell\open\Command - H:\EXPLORER.EXE
.
Zawartość folderu 'Zaplanowane zadania'
2009-02-25 e:\windows\Tasks\WebReg HP Deskjet F2200 series.job
- e:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2007-10-14 20:40]
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-AutoConnect - e:\program files\AutoConnect\AutoConnect.exe
HKCU-Run-wsctf.exe - wsctf.exe
.
------- Skan uzupełniający -------
.
TCP: {E8136976-CCD6-49AC-8A98-27468187C0FC} = 194.204.159.1 217.98.63.164
DPF: {68282C51-9459-467B-95BF-3C0E89627E55} - hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
FF - ProfilePath - e:\documents and settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\ri2wntka.default\
FF - component: e:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: e:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-25 15:39:36
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2009-02-25 15:40:15
ComboFix-quarantined-files.txt 2009-02-25 14:40:13
Przed: 7 121 174 528 bajtów wolnych
Po: 7,137,517,568 bajtów wolnych
232