Komputer Się Tnie, Wirusy
#61
Napisano 22 kwietnia 2009 - 10:15
#63
Napisano 22 kwietnia 2009 - 10:48
#64
Napisano 22 kwietnia 2009 - 02:45
#65
Napisano 30 czerwca 2009 - 01:21
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 02:15:58, on 2009-06-30 Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ESET\ESET Smart Security\ekrn.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\vmnat.exe C:\Program Files\VMware\VMware Workstation\vmware-authd.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\ESET\ESET Smart Security\egui.exe C:\Program Files\Razer\DeathAdder\razerhid.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Analog Devices\SoundMAX\Smax4.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\AutoConnect\AutoConnect.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Razer\DeathAdder\razertra.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Razer\DeathAdder\razerofa.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe D:\Steam\Steam.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\TC UP\totalcmd.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [AutoConnect] C:\Program Files\AutoConnect\AutoConnect.exe O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{2197A085-315D-4ED8-A6F2-DBEE4F848CED}: NameServer = 217.116.100.65 79.163.127.70 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe -- End of file - 5411 bytesWiem, że wiruskiem jest napewno to O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe
no i upx.bat, który wwala mi sie z autorun.inf na każdy dysk. Od razu mówię, że robi mi nie pokazuj ukrytych plików i folderów. Próbowałem wywalić je przez TC, ale skutecznie sie kopiują na kolejne dyski. Teraz nodem robie skan. Jak coś to może owi będzie miał czas i zrobi mi to przez VNC, albo sam się bedę męczył.
#66
Napisano 30 czerwca 2009 - 06:50
..."Umiesz liczyć - licz na siebie"...
Head Admin @ Tawerna-cs.org
#68
Napisano 30 czerwca 2009 - 09:10
asdasdas
#69
Napisano 30 czerwca 2009 - 11:11
ComboFix 09-06-29.04 - Administrator 2009-06-30 12:03.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.3007.2601 [GMT 2:00] Uruchomiony z: c:\documents and settings\Administrator\Pulpit\ComboFix.exe AV: ESET Smart Security 4.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} FW: Zapora osobista *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0} . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Autorun.inf C:\upx.bat c:\windows\AhnRpta.exe c:\windows\system32\e8main0.dll c:\windows\system32\msssc.dll c:\windows\system32\nmdfgds0.dll c:\windows\system32\nmdfgds1.dll c:\windows\system32\olhrwef.exe c:\windows\system32\setup.ini D:\Autorun.inf D:\upx.bat E:\Autorun.inf E:\upx.bat . ((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_AVPsys ((((((((((((((((((((((((( Pliki utworzone od 2009-05-28 do 2009-06-30 ))))))))))))))))))))))))))))))) . 2009-06-30 09:50 . 2009-06-30 09:49 108386 --sh--r- C:\2nuk.com 2009-06-30 00:15 . 2009-06-30 00:15 -------- d-----w- c:\program files\Trend Micro 2009-06-29 02:09 . 2008-04-14 20:51 221184 ----a-w- c:\windows\system32\wmpns.dll 2009-06-26 08:34 . 2009-06-26 08:34 -------- d-----w- c:\documents and settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Apple 2009-06-25 18:17 . 2008-04-14 20:50 26624 ----a-w- c:\documents and settings\LocalService\Dane aplikacji\Microsoft\UPnP Device Host\upnphost\udhisapi.dll 2009-06-25 16:09 . 2009-06-25 16:09 -------- d-----w- c:\program files\Common Files\INCA Shared 2009-06-25 12:57 . 2006-02-04 01:50 4682 ----a-w- c:\windows\system32\npptNT2.sys 2009-06-24 16:26 . 2009-06-24 16:26 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Help 2009-06-23 20:01 . 2009-06-23 20:01 -------- d--h--w- c:\windows\system32\GroupPolicy 2009-06-22 14:33 . 2009-06-22 14:33 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Apple Computer 2009-06-22 14:24 . 2009-06-22 14:24 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Apple 2009-06-22 14:24 . 2009-06-22 14:24 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Apple Computer 2009-06-21 15:56 . 2009-06-28 10:30 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\teamspeak2 2009-06-19 12:45 . 2007-07-19 22:57 267112 ----a-w- c:\windows\system32\xactengine2_9.dll 2009-06-19 12:45 . 2007-07-19 16:14 444776 ----a-w- c:\windows\system32\d3dx10_35.dll 2009-06-19 12:45 . 2007-07-19 16:14 1358192 ----a-w- c:\windows\system32\D3DCompiler_35.dll 2009-06-19 12:45 . 2007-07-19 16:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll 2009-06-19 12:45 . 2007-07-19 22:54 18280 ----a-w- c:\windows\system32\x3daudio1_2.dll 2009-06-19 12:45 . 2007-06-20 18:46 266088 ----a-w- c:\windows\system32\xactengine2_8.dll 2009-06-19 12:45 . 2007-05-16 14:45 443752 ----a-w- c:\windows\system32\d3dx10_34.dll 2009-06-19 12:45 . 2007-05-16 14:45 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll 2009-06-19 12:45 . 2007-05-16 14:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll 2009-06-19 12:45 . 2007-04-04 16:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll 2009-06-19 12:45 . 2007-04-04 16:55 261480 ----a-w- c:\windows\system32\xactengine2_7.dll 2009-06-18 18:50 . 2008-04-13 22:15 26112 -c--a-w- c:\windows\system32\dllcache\usbser.sys 2009-06-18 18:50 . 2008-04-13 22:15 26112 ----a-w- c:\windows\system32\drivers\usbser.sys 2009-06-18 18:49 . 2008-03-21 11:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll 2009-06-18 18:49 . 2008-03-21 11:57 23856 ----a-w- c:\windows\system32\spupdsvc.exe 2009-06-18 18:26 . 2009-06-18 18:50 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\PC Suite 2009-06-18 18:26 . 2009-06-18 18:50 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Nokia 2009-06-18 18:26 . 2009-06-18 18:26 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\PC Suite 2009-06-18 18:13 . 2009-06-18 18:13 -------- d-----w- c:\program files\Common Files\PCSuite 2009-06-18 18:13 . 2009-06-18 18:13 -------- d-----w- c:\program files\Common Files\Nokia 2009-06-18 18:13 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys 2009-06-18 18:12 . 2009-06-18 18:12 -------- d-----w- c:\program files\PC Connectivity Solution 2009-06-18 18:12 . 2009-02-09 05:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys 2009-06-18 18:12 . 2009-02-09 05:37 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys 2009-06-18 18:12 . 2009-02-09 05:37 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll 2009-06-18 18:12 . 2009-02-09 05:37 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys 2009-06-18 18:12 . 2009-02-09 05:32 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll 2009-06-18 18:12 . 2009-02-09 05:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll 2009-06-18 18:12 . 2009-06-18 18:13 -------- d-----w- c:\program files\Nokia 2009-06-18 18:12 . 2009-06-18 18:05 34396584 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_eng_web.exe 2009-06-18 18:12 . 2009-06-18 18:12 8192 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe 2009-06-18 18:12 . 2009-06-18 18:12 61440 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe 2009-06-18 18:12 . 2009-06-18 18:12 10240 ----a-w- c:\documents and settings\All Users\Dane aplikacji\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe 2009-06-18 18:11 . 2009-06-18 18:11 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Installations 2009-06-17 18:43 . 2009-06-19 23:21 334912 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\id Software\quakelive\home\baseq3\cgamex86.dll 2009-06-17 18:43 . 2009-06-19 22:51 449600 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\id Software\quakelive\home\baseq3\qagamex86.dll 2009-06-17 18:43 . 2009-06-19 12:47 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\PunkBuster 2009-06-17 18:43 . 2009-06-17 18:43 874660 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\id Software\quakelive\home\pb\pbcls.dll 2009-06-17 18:43 . 2009-06-17 18:43 57344 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\id Software\quakelive\home\pb\pbags.dll 2009-06-17 18:43 . 2009-06-19 23:21 171072 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\id Software\quakelive\home\baseq3\uix86.dll 2009-06-17 18:43 . 2009-06-19 23:09 57344 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\id Software\quakelive\home\pb\pbag.dll 2009-06-17 18:43 . 2009-06-19 23:09 479232 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\id Software\quakelive\home\pb\pbsv.dll 2009-06-17 18:43 . 2009-06-19 23:09 874660 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\id Software\quakelive\home\pb\pbcl.dll 2009-06-17 18:43 . 2009-06-19 23:09 2669632 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\id Software\quakelive\home\baseq3\quakelive.dll 2009-06-17 16:35 . 2009-06-17 16:35 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\id Software 2009-06-17 16:32 . 2009-06-19 23:09 138944 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2009-06-17 16:32 . 2009-06-17 16:32 22328 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\PnkBstrK.sys 2009-06-17 16:32 . 2009-06-19 23:09 189784 ----a-w- c:\windows\system32\PnkBstrB.exe 2009-06-17 16:31 . 2009-06-17 20:04 75064 ----a-w- c:\windows\system32\PnkBstrA.exe 2009-06-17 16:31 . 2009-06-17 16:31 2246144 ----a-w- c:\windows\system32\pbsvc.exe 2009-06-17 16:31 . 2009-06-17 16:31 -------- d-----w- c:\windows\system32\LogFiles 2009-06-17 16:31 . 2009-06-17 16:31 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\id Software 2009-06-13 13:52 . 2009-06-13 13:53 8 ----a-w- c:\windows\system32\nvModes.dat 2009-06-13 13:41 . 2009-06-13 13:41 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\nView_Profiles 2009-06-11 07:43 . 2009-06-11 07:43 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\GHISLER 2009-06-10 19:55 . 2009-06-10 19:55 -------- d-----w- c:\program files\FlashFXP 2009-06-10 19:55 . 2009-06-10 19:55 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\FlashFXP 2009-06-06 14:55 . 2009-06-06 15:28 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Any Video Converter 2009-06-06 14:55 . 2009-06-06 14:56 -------- d-----w- c:\program files\Any Video Converter 2009-06-04 19:32 . 2009-06-04 19:32 -------- d-----w- c:\documents and settings\LocalService\Ustawienia lokalne\Dane aplikacji\ESET 2009-06-04 16:55 . 2009-06-04 16:55 -------- d-----w- c:\program files\WinSCP 2009-06-03 21:32 . 2009-06-03 21:32 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Cream Software 2009-06-03 21:32 . 2009-06-03 21:32 -------- d-----w- c:\program files\Cream Software 2009-06-03 10:17 . 2009-06-03 10:18 -------- d-----w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\Adobe 2009-06-03 10:16 . 2009-06-03 10:17 -------- d-----w- c:\program files\Common Files\Adobe 2009-06-02 21:01 . 2009-06-02 21:05 -------- d-----w- c:\program files\AMX Mod X 2009-06-02 07:11 . 2009-06-02 07:11 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-06-02 07:11 . 2009-06-02 07:11 -------- d-----w- c:\program files\Java 2009-06-02 07:11 . 2009-06-02 07:11 152576 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\Sun\Java\jre1.6.0_13\lzma.dll 2009-05-31 13:31 . 2009-06-30 09:56 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\skypePM 2009-05-31 13:31 . 2009-05-31 13:31 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-05-31 13:29 . 2009-06-30 10:01 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Skype 2009-05-31 13:29 . 2009-05-31 13:29 -------- d-----w- c:\program files\Common Files\Skype 2009-05-31 13:29 . 2009-05-31 13:29 -------- d-----r- c:\program files\Skype 2009-05-31 13:29 . 2009-05-31 13:29 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Skype 2009-05-31 12:01 . 2009-06-29 23:23 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\HLSW 2009-05-31 12:01 . 2009-06-01 13:55 -------- d-s---w- c:\program files\HLSW 2009-05-31 11:52 . 2008-04-13 22:15 10624 -c--a-w- c:\windows\system32\dllcache\gameenum.sys 2009-05-31 11:52 . 2008-04-13 22:15 10624 ----a-w- c:\windows\system32\drivers\gameenum.sys 2009-05-31 11:52 . 2001-08-17 18:19 40704 -c--a-w- c:\windows\system32\dllcache\es1371mp.sys 2009-05-31 11:52 . 2001-08-17 18:19 40704 ----a-w- c:\windows\system32\drivers\es1371mp.sys 2009-05-31 11:01 . 2009-06-03 19:54 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Ventrilo 2009-05-31 11:01 . 2009-05-31 11:02 -------- d-----w- c:\program files\Ventrilo 2009-05-31 11:00 . 2009-05-31 11:00 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-30 10:07 . 2009-05-30 13:09 -------- d-----w- c:\documents and settings\LocalService\Dane aplikacji\VMware 2009-06-30 10:07 . 2009-05-30 13:05 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\VMware 2009-06-30 10:07 . 2009-05-30 15:06 -------- d-----w- c:\program files\AutoConnect 2009-06-30 09:19 . 2009-05-30 13:40 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\AIMP 2009-06-29 18:49 . 2009-05-30 12:54 -------- d-----w- c:\program files\Mozilla Thunderbird 2009-06-26 05:46 . 2009-05-30 18:51 42592 ----a-w- c:\documents and settings\Administrator\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT 2009-06-25 12:45 . 2009-05-30 12:21 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-25 06:54 . 2009-05-30 16:23 -------- d-----w- c:\program files\mIRC 2009-06-24 16:26 . 2009-05-30 15:29 -------- d-----w- c:\program files\TC UP 2009-06-19 13:40 . 2009-05-30 15:55 -------- d-----w- c:\program files\Gadu-Gadu 2009-06-18 18:49 . 2009-06-18 18:49 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf 2009-06-18 18:49 . 2009-06-18 18:49 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf 2009-06-10 00:29 . 2009-05-30 19:32 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Xfire 2009-06-05 17:17 . 2009-05-30 13:13 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\VMware 2009-06-05 11:11 . 2009-05-30 19:32 -------- d-----w- c:\program files\Xfire 2009-05-31 12:47 . 2009-05-30 12:09 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-05-30 23:04 . 2009-05-30 23:04 -------- d-----w- c:\program files\RegCleaner 2009-05-30 22:49 . 2009-05-30 22:49 -------- d-----w- c:\program files\Analog Devices 2009-05-30 22:21 . 2009-05-30 12:21 -------- d-----w- c:\program files\Common Files\InstallShield 2009-05-30 20:59 . 2009-05-30 20:59 -------- d-----w- c:\program files\SMPlayer 2009-05-30 19:59 . 2009-05-30 19:59 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Gadu-Gadu 2009-05-30 19:47 . 2009-05-30 19:45 -------- d-----w- c:\program files\UltraVNC 2009-05-30 17:47 . 2009-05-30 17:47 15872 ----a-r- c:\documents and settings\Administrator\Dane aplikacji\Microsoft\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C9.exe 2009-05-30 16:50 . 2009-05-30 16:38 98304 ----a-w- c:\documents and settings\Administrator\Dane aplikacji\Soldat\Battleye\BEClient.dll 2009-05-30 16:38 . 2009-05-30 16:38 0 ----a-r- C:\logwmemory.bin 2009-05-30 16:36 . 2009-05-30 16:36 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Soldat 2009-05-30 16:23 . 2009-05-30 16:23 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\mIRC 2009-05-30 15:47 . 2009-05-30 15:47 -------- d-----w- c:\program files\Microsoft.NET 2009-05-30 15:30 . 2009-05-30 15:30 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\HEXelon 2009-05-30 13:38 . 2009-05-30 13:38 -------- d-----w- c:\program files\AIMP2 2009-05-30 13:36 . 2009-05-30 13:36 -------- d-----w- c:\program files\DIFX 2009-05-30 13:36 . 2009-05-30 13:36 -------- d-----w- c:\program files\Razer 2009-05-30 13:34 . 2009-05-30 13:34 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\InstallShield 2009-05-30 13:06 . 2001-10-26 18:15 50922 ----a-w- c:\windows\system32\perfc015.dat 2009-05-30 13:06 . 2001-10-26 18:15 358514 ----a-w- c:\windows\system32\perfh015.dat 2009-05-30 13:05 . 2009-05-30 13:05 -------- d-----w- c:\program files\VMware 2009-05-30 13:04 . 2009-05-30 13:04 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\Thunderbird 2009-05-30 13:00 . 2009-05-30 13:00 -------- d-----w- c:\documents and settings\Administrator\Dane aplikacji\ESET 2009-05-30 12:59 . 2009-05-30 12:59 -------- d-----w- c:\program files\ESET 2009-05-30 12:59 . 2009-05-30 12:59 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\ESET 2009-05-30 12:55 . 2009-05-30 12:55 -------- d-----w- c:\program files\7-Zip 2009-05-30 12:49 . 2009-05-30 12:49 0 ----a-w- c:\windows\nsreg.dat 2009-05-30 12:29 . 2009-05-30 12:28 -------- d-----w- c:\program files\Orange 2009-05-30 12:29 . 2009-05-30 12:29 -------- d-----w- c:\program files\ZTE ZXDSL 852 2009-05-30 12:21 . 2009-05-30 12:21 -------- d-----w- c:\program files\Realtek 2009-05-30 12:19 . 2009-05-30 12:19 -------- d-----w- c:\program files\Intel 2009-05-30 12:10 . 2009-05-30 12:10 -------- d-----w- c:\program files\microsoft frontpage 2009-05-30 12:09 . 2009-05-30 12:09 -------- d-----w- c:\program files\Usługi online 2009-05-30 12:06 . 2009-05-30 12:06 21856 ----a-w- c:\windows\system32\emptyregdb.dat 2009-05-21 22:50 . 2009-05-21 22:50 41808 ----a-w- c:\windows\system32\xfcodec.dll 2009-05-05 08:51 . 2009-05-05 08:51 625728 ----a-w- c:\documents and settings\All Users\Dane aplikacji\id Software\QuakeLive\npquakezero.dll 2009-04-09 13:21 . 2009-04-09 13:21 55768 ----a-w- c:\windows\system32\drivers\epfwtdi.sys 2009-04-09 13:21 . 2009-04-09 13:21 33096 ----a-w- c:\windows\system32\drivers\epfwndis.sys 2009-04-09 13:21 . 2009-04-09 13:21 133000 ----a-w- c:\windows\system32\drivers\epfw.sys 2009-04-09 13:18 . 2009-04-09 13:18 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys 2009-04-09 13:10 . 2009-04-09 13:10 113960 ----a-w- c:\windows\system32\drivers\eamon.sys . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AutoConnect"="c:\program files\AutoConnect\AutoConnect.exe" [2006-12-02 310784] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016] "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-09 2029640] "DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-02 148888] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776] "AdslTaskBar"="stmctrl.dll" - c:\windows\system32\stmctrl.dll [2008-04-23 151552] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\VMware\\VMware Workstation\\vmware-authd.exe"= "c:\\Program Files\\UltraVNC\\vncviewer.exe"= "c:\\Program Files\\FlashFXP\\FlashFXP.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5900:TCP"= 5900:TCP:vnc5900 "5800:TCP"= 5800:TCP:vnc5800 R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-04-09 107256] R1 VD_FileDisk;VD_FileDisk;c:\windows\system32\drivers\vd_filedisk.sys [2006-01-13 15872] R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-04-09 731840] R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2008-09-18 54960] R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2009-05-30 22784] R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [2009-05-30 60255] R3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\drivers\torususb.sys [2009-05-30 683791] . . ------- Skan uzupełniający ------- . IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 LSP: c:\program files\VMware\VMware Workstation\vsocklib.dll TCP: {2197A085-315D-4ED8-A6F2-DBEE4F848CED} = 217.116.100.65 79.163.127.70 FF - ProfilePath - c:\documents and settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\9ny54wjq.default\ FF - prefs.js: browser.startup.homepage - google.pl FF - plugin: c:\documents and settings\All Users\Dane aplikacji\id Software\QuakeLive\npquakezero.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-30 12:07 Windows 5.1.2600 Dodatek Service Pack 3 NTFS skanowanie ukrytych procesów ... skanowanie ukrytych wpisów autostartu ... skanowanie ukrytych plików ... skanowanie pomyślnie ukończone ukryte pliki: 0 ************************************************************************** . ------------------------ Pozostałe uruchomione procesy ------------------------ . c:\windows\system32\rundll32.exe c:\windows\system32\rundll32.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\PnkBstrB.exe c:\windows\system32\vmnat.exe c:\windows\system32\vmnetdhcp.exe c:\program files\VMware\VMware Workstation\vmware-authd.exe c:\program files\Razer\DeathAdder\razertra.exe c:\windows\system32\wscntfy.exe c:\program files\Razer\DeathAdder\razerofa.exe c:\windows\system32\wbem\wmiapsrv.exe . ************************************************************************** . Czas ukończenia: 2009-06-30 12:09 - komputer został uruchomiony ponownie ComboFix-quarantined-files.txt 2009-06-30 10:09 Przed: 2 678 984 704 bajtów wolnych Po: 2 692 108 288 bajtów wolnych WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 275
I log z Hijackthis
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:20:15, on 2009-06-30 Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\ESET\ESET Smart Security\egui.exe C:\Program Files\Razer\DeathAdder\razerhid.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\AutoConnect\AutoConnect.exe C:\Program Files\ESET\ESET Smart Security\ekrn.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\vmnat.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\Program Files\VMware\VMware Workstation\vmware-authd.exe C:\Program Files\Razer\DeathAdder\razertra.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Razer\DeathAdder\razerofa.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKCU\..\Run: [AutoConnect] C:\Program Files\AutoConnect\AutoConnect.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{2197A085-315D-4ED8-A6F2-DBEE4F848CED}: NameServer = 217.116.100.65 79.163.127.70 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe -- End of file - 5540 bytes
Użytkownik ShataN edytował ten post 30 czerwca 2009 - 11:21
#70
Napisano 30 czerwca 2009 - 11:23
..."Umiesz liczyć - licz na siebie"...
Head Admin @ Tawerna-cs.org
#71
Napisano 17 grudnia 2009 - 05:05
Inne tematy zakładane o podobnych problemach będą karane ostrzeżeniem
Wyżej stare problemy, przeczytajcie zanim napiszecie !
BUMP
Użytkownik Juri edytował ten post 17 grudnia 2009 - 05:42
asdasdas
#72
Napisano 23 października 2012 - 06:14
Czy umie ktoś zaradzić?
#73
Napisano 24 października 2012 - 03:59