log ComboFix
Код:

ComboFix 09-01-21.04 - Sasha 2009-01-25 15:55:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1251.1.1049.18.767.390 [GMT 0:00]
Running from: c:\documents and settings\Sasha\Рабочий стол\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090124-0] *On-access scanning disabled* (Updated)
FW: AGAVA Firewall *disabled*
FW: Outpost Firewall Pro *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Cache
.
((((((((((((((((((((((((( Files Created from 2008-12-25 to 2009-01-25 )))))))))))))))))))))))))))))))
.
2009-01-25 15:21 . 2009-01-25 15:21 578,560 --a--c--- c:\windows\system32\dllcache\user32.dll
2009-01-25 15:18 . 2009-01-25 15:18 <DIR> d-------- c:\windows\ERUNT
2009-01-25 15:12 . 2009-01-25 15:37 <DIR> d-------- C:\SDFix
2009-01-25 12:30 . 2009-01-25 12:55 250 --a------ c:\windows\gmer.ini
2009-01-25 11:53 . 2009-01-25 11:53 <DIR> d--h----- c:\windows\$hf_mig$
2009-01-25 11:17 . 2009-01-25 11:17 0 --a------ c:\windows\nsreg.dat
2009-01-24 17:15 . 2009-01-24 17:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\PreEmptive Solutions
2009-01-24 17:08 . 2009-01-24 17:08 <DIR> d-------- c:\windows\symbols
2009-01-24 17:05 . 2009-01-24 17:09 <DIR> d-------- c:\program files\HTML Help Workshop
2009-01-24 17:05 . 2009-01-24 17:15 <DIR> d-------- c:\program files\Common Files\Merge Modules
2009-01-24 17:05 . 2009-01-24 17:05 <DIR> d-------- c:\program files\CE Remote Tools
2009-01-21 12:59 . 2009-01-21 12:59 <DIR> d-------- c:\program files\ICQToolbar
2009-01-21 12:55 . 2009-01-21 13:03 <DIR> d-------- c:\program files\ICQ6
2009-01-21 12:55 . 2009-01-21 12:55 <DIR> d-------- c:\documents and settings\Sasha\Application Data\InstallShield
2009-01-16 16:11 . 2009-01-18 18:09 <DIR> d-------- c:\documents and settings\Sasha\Application Data\SWF.max
2009-01-15 21:41 . 2009-01-15 21:41 <DIR> d-------- c:\documents and settings\Sasha\Application Data\vlc
2009-01-15 21:21 . 2009-01-15 21:21 <DIR> d-------- c:\program files\VideoLAN
2009-01-12 17:52 . 2009-01-12 17:59 <DIR> d-------- c:\program files\EWB512
2009-01-12 17:52 . 2009-01-12 17:52 216,064 --a------ c:\windows\iun3405.exe
2009-01-06 08:47 . 2009-01-06 08:47 <DIR> d-------- c:\program files\Microl
2009-01-04 17:43 . 2009-01-04 17:43 <DIR> d-------- c:\documents and settings\Sasha\Application Data\VyPRESS
2009-01-03 19:24 . 2009-01-03 19:24 <DIR> d-------- c:\documents and settings\Sasha\Application Data\Media Player Classic
2009-01-03 15:22 . 2008-12-29 16:13 61,440 --a------ c:\windows\system32\DWRCSh32.DLL
2009-01-03 15:17 . 2009-01-03 15:21 <DIR> d-------- c:\documents and settings\Sasha\Application Data\DameWare Development
2009-01-03 15:16 . 2009-01-03 15:16 <DIR> d-------- c:\documents and settings\Sasha\Application Data\DWMRCMSI
2009-01-03 15:15 . 2009-01-03 15:26 <DIR> d-------- c:\program files\DameWare Development
2009-01-03 14:23 . 2009-01-03 14:23 <DIR> d-------- c:\program files\ICQ6Toolbar
2009-01-03 14:23 . 2009-01-03 14:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\ICQ
2009-01-03 14:22 . 2009-01-03 14:24 <DIR> d-------- c:\documents and settings\Sasha\Application Data\ICQ
2009-01-02 23:19 . 2009-01-03 22:45 <DIR> d-------- c:\documents and settings\Sasha\Application Data\Download Master
2009-01-02 22:36 . 2008-10-30 07:31 <DIR> d--h----- c:\documents and settings\Mama\Шаблоны
2009-01-02 22:36 . 2009-01-16 08:05 <DIR> d-------- c:\documents and settings\Mama\Рабочий стол
2009-01-02 22:36 . 2009-01-24 09:48 <DIR> dr------- c:\documents and settings\Mama\Мои документы
2009-01-02 22:36 . 2008-10-30 10:23 <DIR> dr------- c:\documents and settings\Mama\Главное меню
2009-01-02 22:36 . 2009-01-02 22:37 <DIR> dr------- c:\documents and settings\Mama\Избранное
2009-01-02 22:36 . 2009-01-02 22:36 <DIR> d-------- c:\documents and settings\Mama
2009-01-02 18:45 . 2009-01-02 18:45 <DIR> d-------- c:\documents and settings\Sasha\Application Data\DivX
2009-01-02 14:24 . 2009-01-02 14:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-01-02 13:40 . 2009-01-02 23:29 <DIR> d-------- c:\documents and settings\Sasha\Application Data\Winamp
2009-01-02 13:32 . 2008-10-30 07:31 <DIR> d--h----- c:\documents and settings\Sasha\Шаблоны
2009-01-02 13:32 . 2009-01-25 15:13 <DIR> d-------- c:\documents and settings\Sasha\Рабочий стол
2009-01-02 13:32 . 2009-01-24 16:33 <DIR> dr------- c:\documents and settings\Sasha\Мои документы
2009-01-02 13:32 . 2008-10-30 10:23 <DIR> dr------- c:\documents and settings\Sasha\Главное меню
2009-01-02 13:32 . 2009-01-02 13:32 <DIR> dr------- c:\documents and settings\Sasha\Избранное
2009-01-02 13:32 . 2009-01-25 15:32 <DIR> d-------- c:\documents and settings\Sasha
2008-12-30 12:00 . 2008-12-30 14:00 21,840 --a----t- c:\windows\system32\SIntfNT.dll
2008-12-30 12:00 . 2008-12-30 14:00 17,212 --a----t- c:\windows\system32\SIntf32.dll
2008-12-30 12:00 . 2008-12-30 14:00 12,067 --a----t- c:\windows\system32\SIntf16.dll
2008-12-29 09:56 . 2008-12-29 09:56 <DIR> d-------- c:\program files\Winamp Toolbar
2008-12-29 09:56 . 2008-12-29 09:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Winamp Toolbar
2008-12-27 23:27 . 2008-12-24 17:24 703,904 --a------ c:\windows\system32\drivers\SandBox.sys
2008-12-27 23:27 . 2008-12-17 11:07 257,176 --a------ c:\windows\system32\drivers\afwcore.sys
2008-12-27 23:26 . 2008-12-27 23:27 <DIR> d-------- c:\windows\system32\Filt
2008-12-27 23:26 . 2008-12-27 23:26 <DIR> d-------- c:\program files\Agnitum
2008-12-27 23:26 . 2008-12-27 23:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\Agnitum
2008-12-27 23:26 . 2008-06-20 09:45 30,864 --a------ c:\windows\system32\drivers\afw.sys
2008-12-27 23:26 . 2008-12-04 12:13 49 --a------ c:\windows\transp.gif
2008-12-27 23:16 . 2004-08-18 16:00 2,134,528 --a--c--- c:\windows\system32\dllcache\smtpsnap.dll
2008-12-27 09:03 . 2008-12-27 09:03 <DIR> d-------- c:\program files\Aura
2008-12-26 23:00 . 2008-12-26 23:00 <DIR> d-------- c:\program files\DMoNsoft
2008-12-26 21:19 . 2008-12-26 21:24 <DIR> d-------- c:\program files\Seoadministrator
2008-12-26 21:19 . 2000-01-24 04:01 2,023,424 --a------ c:\windows\system32\VCL50.BPL
2008-12-26 21:19 . 2000-01-31 04:00 1,496,064 --a------ c:\windows\system32\cc3250mt.dll
2008-12-26 21:19 . 2003-10-16 16:25 1,315,840 --a------ c:\windows\system32\indy50.bpl
2008-12-26 21:19 . 2000-01-24 04:01 558,080 --a------ c:\windows\system32\VCLDB50.BPL
2008-12-26 21:19 . 2000-01-24 04:01 534,016 --a------ c:\windows\system32\tee50.BPL
2008-12-26 21:19 . 2000-01-24 04:01 248,832 --a------ c:\windows\system32\VCLX50.BPL
2008-12-26 21:19 . 2000-01-31 04:00 219,648 --a------ c:\windows\system32\cg32.dll
2008-12-26 21:19 . 2000-01-24 04:01 197,120 --a------ c:\windows\system32\NMFAST50.BPL
2008-12-26 21:19 . 2000-01-31 04:00 147,456 --a------ c:\windows\system32\BCBSMP50.BPL
2008-12-26 21:19 . 2000-01-31 04:00 84,480 --a------ c:\windows\system32\BCBIE50.BPL
2008-12-26 21:19 . 2000-01-24 04:01 65,024 --a------ c:\windows\system32\inet50.bpl
2008-12-25 19:32 . 2008-10-30 07:31 <DIR> d--h----- c:\documents and settings\MICROSOF-54597A\ASPNET\Шаблоны
2008-12-25 19:32 . 2008-10-30 10:23 <DIR> d-------- c:\documents and settings\MICROSOF-54597A\ASPNET\Рабочий стол
2008-12-25 19:32 . 2008-10-30 10:23 <DIR> d-------- c:\documents and settings\MICROSOF-54597A\ASPNET\Мои документы
2008-12-25 19:32 . 2008-10-30 10:23 <DIR> dr------- c:\documents and settings\MICROSOF-54597A\ASPNET\Главное меню
2008-12-25 19:32 . 2008-10-30 10:23 <DIR> d-------- c:\documents and settings\MICROSOF-54597A\ASPNET\Избранное
2008-12-25 19:32 . 2008-12-25 19:32 <DIR> d-------- c:\documents and settings\MICROSOF-54597A\ASPNET
2008-12-25 19:32 . 2008-12-25 19:32 <DIR> d-------- c:\documents and settings\MICROSOF-54597A
2008-12-25 18:17 . 2004-08-18 16:00 125,952 --a--c--- c:\windows\system32\dllcache\ftpsv251.dll
2008-12-25 18:17 . 2004-08-18 16:00 7,680 --a--c--- c:\windows\system32\dllcache\ftpctrs2.dll
2008-12-25 18:17 . 2004-08-18 16:00 6,144 --a--c--- c:\windows\system32\dllcache\ftpmib.dll
2008-12-25 16:45 . 2008-12-27 23:18 <DIR> d-------- C:\Inetpub
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-24 17:23 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-24 17:09 --------- d-----w c:\program files\MSBuild
2009-01-24 00:33 --------- d-----w c:\program files\Java
2009-01-21 12:11 --------- d-----w c:\program files\QIP Infium
2009-01-16 16:16 --------- d-----w c:\program files\SWF.max
2009-01-03 14:24 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-02 22:45 --------- d-----w c:\program files\DU Meter
2008-12-29 10:37 --------- d-----w c:\program files\Winamp
2008-12-26 08:59 --------- d-----w c:\program files\Multi Password Recovery
2008-12-23 11:36 --------- d-----w c:\program files\Neat Corporation
2008-12-18 20:52 --------- d-----w c:\program files\Download Master
2008-12-18 19:10 --------- d-----w c:\program files\Microsoft
2008-12-18 17:10 --------- d-----w c:\program files\QIP
2008-12-18 12:29 --------- d-----w c:\program files\Radmin
2008-12-16 18:32 --------- d-----w c:\program files\Ahead
2008-12-16 18:31 --------- d-----w c:\program files\SlySoft
2008-12-11 17:25 --------- d-----w c:\program files\Vypress Chat
2008-12-10 10:49 --------- d-----w c:\documents and settings\All Users\Application Data\Hagel Technologies
2008-12-05 08:49 --------- d-----w c:\documents and settings\All Users\Application Data\ABBYY
2008-12-05 08:08 --------- d-----w c:\program files\Mustek 1200 UB PLUS
2008-12-01 11:51 --------- d-----w c:\program files\Business Objects
2008-12-01 11:48 --------- d-----w c:\program files\Windows Mobile 5.0 SDK R2
2008-12-01 11:48 --------- d-----w c:\program files\Microsoft Device Emulator
2008-12-01 11:40 --------- d-----w c:\program files\Microsoft.NET
2008-12-01 11:07 --------- d-----w c:\program files\Microsoft Web Designer Tools
2008-11-29 18:04 --------- d-----w c:\program files\Sun
2008-11-29 16:28 --------- d-----w c:\program files\Alcohol Soft
2008-11-27 20:00 --------- d-----w c:\program files\EBMKiev-DEMO
2008-10-30 08:14 60,416 ----a-w c:\windows\ALCFDRTM.EXE
2007-10-15 21:27 168,509 --sha-r c:\windows\system32\xouxh.dll
.
------- Sigcheck -------
2007-10-15 21:39 578560 5231f1983829611637e9493105e84751 c:\windows\system32\user32.dll
2009-01-25 15:21 578560 5231f1983829611637e9493105e84751 c:\windows\system32\dllcache\user32.dll
2007-10-16 05:50 360576 bb4d3a8e6f7eb1d370bc4ad27ab23368 c:\windows\system32\drivers\tcpip.sys
2007-10-16 06:57 2066176 794c6ea35a1598ae49bff6faff9ebcab c:\windows\system32\ntkrnlpa.exe
2007-10-16 06:56 2188928 0dceef0666c2a8f078fead29699f8b6d c:\windows\system32\ntoskrnl.exe
2007-10-15 21:38 1608704 7a4ec6b6d1bc9a866438371b1662385c c:\windows\explorer.exe
2007-10-15 21:38 30208 dfac8122228107f7bca18a71056b5abe c:\windows\system32\ctfmon.exe
2007-10-15 21:39 80216 94dac979b510d047ab4ed7ff22a68f4d c:\windows\system32\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Punto Switcher"="c:\program files\Punto Switcher\ps.exe" [2007-01-25 201728]
"VistaIcon"="c:\program files\VistaDriveIcon\VistaDrv.exe" [2007-07-02 132608]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2008-06-08 2645528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-13 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-13 81920]
"VolumeControl"="c:\program files\VolumeControl\volume.exe" [2003-09-15 36864]
"Diamondback"="c:\program files\Razer\Diamondback 3G\razerhid.exe" [2007-08-01 147456]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-24 132496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2008-12-25 1227080]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall Pro\feedback.exe" [2008-12-25 432968]
"nwiz"="nwiz.exe" [2007-07-13 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Punto Switcher"="c:\program files\Punto Switcher\ps.exe" [2007-01-25 201728]
"VistaIcon"="c:\program files\VistaDriveIcon\VistaDrv.exe" [2007-07-02 132608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IE7_011"="shell32" [X]
"ZZZZ2_FirstLogonSetting"="advpack.dll" [2007-10-16 c:\windows\system32\advpack.dll]
"IE7_012"="advpack.dll" [2007-10-16 c:\windows\system32\advpack.dll]
"IE7_013"="rebuild.exe" [2007-09-15 c:\windows\system32\rebuild.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoThumbnailCache"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoThumbnailCache"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Vypress Chat\\VyChat.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5223:TCP"= 5223:TCP:tlbjz
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-04 111184]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [2008-12-27 703904]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [2008-12-27 30864]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2008-12-27 257176]
R3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\drivers\DB3G.sys [2008-10-30 13225]
R4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 Licensing Service;d:\program files\ABBYY FineReader 9.0\NetworkLicenseServer.exe [2007-09-24 566560]
R4 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [2008-12-27 1267016]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-11-04 20560]
R4 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [2008-12-10 1386008]
R4 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2009-01-03 222456]
S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [2008-12-27 34080]
S3 mirrorv3;mirrorv3;c:\windows\system32\drivers\rminiv3.sys [2006-11-01 3328]
S3 mpr_freader;MPR FileReader Driver;c:\program files\Multi Password Recovery\mpr_freader.sys [2007-08-13 2816]
S3 VSPerfDrv90;Performance Tools Driver 9.0;d:\programming\Microsoft Visual Studio 9.0\Team Tools\Performance Tools\VSPerfDrv90.sys [2007-09-04 55664]
S4 hpzsgznxq;Network Helper;c:\windows\system32\svchost.exe -k netsvcs [2004-08-18 14336]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2008-07-10 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-07-09 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
hpzsgznxq
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Gtwatch - c:\windows\gtwatch.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.kornet.ru/
IE: &Экспорт в Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: {{8DAE90AD-4583-4977-9DD4-4360F7A45C74} - c:\program files\Download Master\dmaster.exe
FF - ProfilePath - c:\documents and settings\Sasha\Application Data\Mozilla\Firefox\Profiles\egnxc2bs.default\
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-25 16:02:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(828)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(892)
c:\windows\system32\SETUPAPI.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Razer\Diamondback 3G\razertra.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Razer\Diamondback 3G\razerofa.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-25 16:04:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-25 16:04:48
Pre-Run: 1*110*016*000 байт свободно
Post-Run: 1,108,385,792 байт свободно
261
Собственно с касперским и CureIt возникли небольшие проблемы - нет доступа к сайтам ) попытаюсь выложить максимум логов
