something like this opened - but it was called "log". is it ok?
ComboFix 08-09-26.06 - sylwia 2008-09-27 21:13:50.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.314 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\sylwia\Pulpit\ComboFix.exe
Użyto następujących komend :: C:\Documents and Settings\sylwia\Pulpit\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((( Pliki utworzone od 2008-08-27 do 2008-09-27 )))))))))))))))))))))))))))))))
.
2008-09-27 17:48 . 2008-09-27 17:48 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-27 17:44 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-27 17:43 . 2008-09-27 17:44 <DIR> d-------- C:\Program Files\Java
2008-09-27 17:43 . 2008-09-27 17:43 <DIR> d-------- C:\Program Files\Common Files\Java
2008-09-27 17:25 . 2008-09-27 17:27 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-27 17:25 . 2008-09-27 17:25 <DIR> d-------- C:\Documents and Settings\sylwia\Dane aplikacji\Malwarebytes
2008-09-27 17:25 . 2008-09-27 17:25 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
2008-09-27 17:25 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-27 17:25 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-27 17:07 . 2008-09-27 17:07 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-27 17:07 . 2008-09-27 17:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-27 17:07 . 2008-09-27 17:07 <DIR> d-------- C:\Documents and Settings\sylwia\Dane aplikacji\SUPERAntiSpyware.com
2008-09-27 17:07 . 2008-09-27 17:07 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\SUPERAntiSpyware.com
2008-09-27 16:59 . 2008-09-27 16:59 <DIR> d-------- C:\Program Files\CCleaner
2008-09-26 23:25 . 2001-08-17 20:13 27,165 --a--c--- C:\WINDOWS\system32\dllcache\fetnd5.sys
2008-09-26 23:23 . 2001-08-17 21:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-09-26 23:18 . 2001-08-17 20:12 97,354 --a--c--- C:\WINDOWS\system32\dllcache\aspndis3.sys
2008-09-26 23:15 . 2001-08-17 21:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-09-26 23:14 . 2004-08-04 00:38 2,149,888 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-09-26 23:14 . 2001-10-26 17:29 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-09-26 22:14 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-09-25 22:24 . 2008-09-27 20:39 <DIR> d--h----- C:\Documents and Settings\Administrator\Ustawienia lokalne
2008-09-25 22:24 . 2008-09-22 20:21 <DIR> d-------- C:\Documents and Settings\Administrator\Ulubione
2008-09-25 22:24 . 2008-09-22 19:26 <DIR> d--h----- C:\Documents and Settings\Administrator\Szablony
2008-09-25 22:24 . 2008-09-22 20:21 <DIR> d-------- C:\Documents and Settings\Administrator\Pulpit
2008-09-25 22:24 . 2008-09-22 20:21 <DIR> d-------- C:\Documents and Settings\Administrator\Moje dokumenty
2008-09-25 22:24 . 2008-09-22 20:21 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Start
2008-09-25 22:24 . 2008-09-22 20:21 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dane aplikacji
2008-09-25 22:24 . 2008-09-25 22:25 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-25 20:02 . 2008-09-25 20:02 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-09-25 20:02 . 2008-09-25 20:02 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-09-25 19:37 . 2008-09-25 22:19 <DIR> d-------- C:\Program Files\Yahoo!
2008-09-24 23:57 . 2008-09-24 23:57 <DIR> d-------- C:\Documents and Settings\sylwia\Dane aplikacji\MSN6
2008-09-24 23:57 . 2008-09-24 23:57 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\MSN6
2008-09-24 23:23 . 2008-09-24 23:23 130 --a------ C:\WINDOWS\wininit.ini
2008-09-24 23:11 . 2008-09-25 19:33 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-09-24 22:59 . 2008-09-24 23:01 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-09-24 00:03 . 2008-04-11 20:51 683,520 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-23 21:14 . 2008-09-23 21:15 <DIR> d-------- C:\Program Files\NAPI-PROJEKT
2008-09-23 20:03 . 2008-09-23 20:03 3,532 --a------ C:\drmHeader.bin
2008-09-23 19:00 . 2008-09-23 19:00 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\IM
2008-09-23 18:59 . 2008-09-23 19:00 <DIR> d-------- C:\Program Files\IncrediMail
2008-09-23 18:59 . 2008-09-23 18:59 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\IncrediMail
2008-09-23 18:41 . 2008-09-25 22:58 <DIR> d-------- C:\Documents and Settings\sylwia\Dane aplikacji\The Bat!
2008-09-23 18:40 . 2008-09-23 18:51 <DIR> d-------- C:\Program Files\The Bat!
2008-09-22 23:26 . 2008-09-22 23:26 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-09-22 23:26 . 2008-09-22 23:26 <DIR> d-------- C:\WINDOWS\system32\custom matrices
2008-09-22 23:26 . 2008-09-22 23:26 <DIR> d-------- C:\WINDOWS\system32\C2MP
2008-09-22 23:16 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-09-22 23:15 . 2008-09-22 23:15 <DIR> d-------- C:\Program Files\Microsoft Works
2008-09-22 23:14 . 2008-09-22 23:14 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-09-22 23:13 . 2008-09-22 23:13 <DIR> dr-h----- C:\MSOCache
2008-09-22 23:13 . 2008-09-22 23:16 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-09-22 23:06 . 2008-09-22 23:06 <DIR> d-------- C:\Program Files\Avira
2008-09-22 23:06 . 2008-09-22 23:06 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-09-22 22:54 . 2008-09-25 00:03 <DIR> d-------- C:\Documents and Settings\sylwia\Dane aplikacji\uTorrent
2008-09-22 22:50 . 2008-09-22 22:50 <DIR> d-------- C:\Documents and Settings\sylwia\Dane aplikacji\Gadu-Gadu
2008-09-22 22:49 . 2008-09-22 22:49 <DIR> d-------- C:\Program Files\Gadu-Gadu
2008-09-22 22:49 . 2008-09-22 22:50 <DIR> d-------- C:\Documents and Settings\sylwia\Gadu-Gadu
2008-09-22 22:41 . 2008-09-22 22:43 <DIR> d-------- C:\Program Files\Winamp
2008-09-22 22:41 . 2008-09-22 22:45 <DIR> d-------- C:\Documents and Settings\sylwia\Dane aplikacji\Winamp
2008-09-22 22:36 . 2008-09-27 20:42 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2008-09-22 22:36 . 2008-09-22 22:36 <DIR> d-------- C:\Documents and Settings\sylwia\Dane aplikacji\Thunderbird
2008-09-22 22:36 . 2008-09-22 22:36 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-22 22:31 . 2008-09-22 22:31 <DIR> d-------- C:\Program Files\SubEdit-Player
2008-09-22 22:22 . 2008-09-22 22:22 <DIR> d-------- C:\Documents and Settings\LocalService\Menu Start
2008-09-22 22:17 . 2008-09-22 22:43 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-09-22 22:14 . 2008-09-22 22:14 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-22 22:14 . 2004-08-04 00:43 333,312 --a--c--- C:\WINDOWS\system32\dllcache\aqueue.dll
2008-09-22 22:14 . 2004-08-04 00:43 105,984 --a--c--- C:\WINDOWS\system32\dllcache\evntagnt.dll
2008-09-22 22:12 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\
002249_.tmp
2008-09-22 22:11 . 2008-09-22 22:11 <DIR> d-------- C:\WINDOWS\EHome
2008-09-22 20:31 . 2008-09-22 20:31 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-09-22 20:30 . 2008-09-22 20:30 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-09-22 20:22 . 2004-08-04 00:44 77,312 --a------ C:\WINDOWS\system32\usbui.dll
2008-09-22 20:22 . 2001-08-17 23:00 2,944 --a------ C:\WINDOWS\system32\drivers\msmpu401.sys
2008-09-22 20:21 . 2008-09-22 20:21 <DIR> dr-h----- C:\Documents and Settings\Default User\Ustawienia lokalne
2008-09-22 20:21 . 2008-09-22 20:21 <DIR> d-------- C:\Documents and Settings\Default User\Ulubione
2008-09-22 20:21 . 2008-09-22 19:26 <DIR> d--h----- C:\Documents and Settings\Default User\Szablony
2008-09-22 20:21 . 2008-09-22 20:21 <DIR> d-------- C:\Documents and Settings\Default User\Pulpit
2008-09-22 20:21 . 2008-09-22 20:21 <DIR> d-------- C:\Documents and Settings\Default User\Moje dokumenty
2008-09-22 20:21 . 2008-09-22 20:21 <DIR> dr------- C:\Documents and Settings\Default User\Menu Start
2008-09-22 20:21 . 2008-09-22 20:21 <DIR> dr-h----- C:\Documents and Settings\Default User\Dane aplikacji
2008-09-22 20:21 . 2008-09-22 20:21 <DIR> d-------- C:\Documents and Settings\All Users\Ulubione
2008-09-22 20:21 . 2008-09-22 20:21 <DIR> d--h----- C:\Documents and Settings\All Users\Szablony
2008-09-22 20:21 . 2008-09-27 17:25 <DIR> d-------- C:\Documents and Settings\All Users\Pulpit
2008-09-22 20:21 . 2008-09-22 22:16 <DIR> dr------- C:\Documents and Settings\All Users\Menu Start
2008-09-22 20:21 . 2008-09-22 19:27 <DIR> dr------- C:\Documents and Settings\All Users\Dokumenty
2008-09-22 20:21 . 2008-09-27 17:25 <DIR> dr-h----- C:\Documents and Settings\All Users\Dane aplikacji
2008-09-22 20:20 . 2008-09-22 19:29 <DIR> d--h----- C:\Documents and Settings\Default User
2008-09-22 20:20 . 2008-09-22 19:28 <DIR> d-------- C:\Documents and Settings\All Users
2008-09-22 20:20 . 2008-09-25 22:24 <DIR> d-------- C:\Documents and Settings
2008-09-22 20:15 . 2008-09-22 20:15 <DIR> d-------- C:\Program Files\Philips Semiconductors
2008-09-22 20:14 . 2003-09-16 20:11 327,168 --a------ C:\WINDOWS\IsUninst.exe
2008-09-22 20:11 . 2008-09-22 20:14 <DIR> d-------- C:\Program Files\Terminator
2008-09-22 20:05 . 2008-09-22 20:05 13,646 --a------ C:\WINDOWS\system32\wpa.bak
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-09-23 20:25 578,560 ----a-w C:\WINDOWS\system32\user32.DLL
2008-09-22 18:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-22 17:47 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-09-22 17:47 --------- d-----w C:\Program Files\AvRack
2008-09-22 17:42 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-22 17:36 --------- d-----w C:\Program Files\ATI Technologies
2008-09-22 17:29 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-22 17:28 --------- d-----w C:\Program Files\Usługi online
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:33 253,952 ----a-w C:\WINDOWS\system32\es.dll
.
file copied: C:\WINDOWS\system32\user32.dll -> C:\Qoobox\Quarantine\C\WINDOWS\system32\user32.dll .vir.vir ( 578560 bytes )
C:\WINDOWS\system32\user32.dll ... is infected !! (additional data below)
561,664 2003-04-16 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
578,560 2004-08-03 22:44:14 C:\WINDOWS\ServicePackFiles\i386\user32.dll
578,560 2008-09-23 20:25:56 C:\WINDOWS\system32\user32.DLL
------- Sigcheck -------
2003-04-16 14:00 561664 3a4892a57cfe05d61e4bbc3ec3e24a63 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2004-08-04 00:44 578560 0c81764f50f32d376e6e4b9e9f4b01a0 C:\WINDOWS\ServicePackFiles\i386\user32.dll
2008-09-23 22:25 578560 49d4bddebff2ad94b991a5eb1af6d8bc C:\WINDOWS\system32\user32.DLL
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-12 335872]
"Quick TV Agent"="C:\Program Files\Terminator\Quick TV\Scheduled.exe" [2004-10-11 740352]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 36352]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
TV Remote Control.lnk - C:\Program Files\Terminator\TV7131 Utilities\P3XRCtl.exe [2008-09-22 57344]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\ati1taxx.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\ati2xexx.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\ati5otxx.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\ati8rxxx.sys]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
--a------ 2008-07-24 14:22 243072 C:\Program Files\IncrediMail\bin\IncMail.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:44 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
R3 Cap713x;Philips Cap713x Video Capture;C:\WINDOWS\system32\DRIVERS\Cap713x.sys [2004-10-20 414592]
S0 bibfanpm;bibfanpm;C:\WINDOWS\system32\drivers\ahbw h.sys [ ]
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\sylwia\Dane aplikacji\Mozilla\Firefox\Profiles\9g9bv1zj.defaul t\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.jawnet.pl/
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - C:\WINDOWS\system32\C2MP\npdivx32.dll
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-27 21:15:11
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
************************************************** ************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
PROCES: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\ComboFix\pv.cfexe
.
************************************************** ************************
.
Czas ukończenia: 2008-09-27 21:16:32 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2008-09-27 19:16:29
ComboFix2.txt 2008-09-27 18:39:28
Przed: 14˙568˙873˙984 bajt˘w wolnych
Po: 14,546,182,144 bajt˘w wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
227 --- E O F --- 2008-09-25 20:57:19