manciu Poziom 1

Joined: 28 May 2009 Posts: 1 Location: Poznań
|
#1
28 May 2009 16:16 Komputer wysyła spam - pomocy! |
|
|
|
Witam.
Od pewnego czasu komputer wysyła spam. Oto logi:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:55:02, on 2009-05-28
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Lenovo\PM Driver\PMSveH.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\vsnp2std.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Pomocnik rejestracji usługi Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Skrót do strony właściwości High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [PMHandler] C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
O4 - HKLM\..\Run: [AMSG] C:\PROGRA~1\THINKV~1\AMSG\amsg.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUman000
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Wyślij do urządzenia &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/welcome/3000notebook
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Usługa inteligentnego transferu w tle (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Harmonogram automatycznej usługi LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Usługa Auto-Protect programu Norton AntiVirus (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: Aktualizacje automatyczne (wuauserv) - Unknown owner - C:\WINDOWS\
O24 - Desktop Component 0: (no name) - http://www.krajobrazy.net.pl/foto/tapety120/w36.jpg
ComboFix 09-05-26.05 - Manciu 2009-05-28 16:31.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.48.1045.18.502.153 [GMT 2:00]
Uruchomiony z: c:\documents and settings\Manciu\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Manciu\Dane aplikacji\ShoppingReport
c:\documents and settings\Manciu\Dane aplikacji\ShoppingReport\cs\Config.xml
c:\documents and settings\Manciu\Dane aplikacji\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\Manciu\Dane aplikacji\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\Manciu\Dane aplikacji\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\Manciu\Dane aplikacji\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\Manciu\Dane aplikacji\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\Manciu\Dane aplikacji\ShoppingReport\cs\res1\WhiteList.dbs
c:\documents and settings\Manciu\Dane aplikacji\wiaserva.log
c:\program files\FunWebProducts
c:\program files\FunWebProducts\ScreenSaver\Images\01A0215B.urr
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\FunWebProducts\Shared\Cache\WebfettiBtn.html
c:\program files\Internet Explorer\msimg32.dll
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
c:\program files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
c:\program files\MyWebSearch\bar\1.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MSG.DLL
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSSVC.EXE
c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Cache\016BC7BF
c:\program files\MyWebSearch\bar\Cache\0181751F.bin
c:\program files\MyWebSearch\bar\Cache\01817BE6.bin
c:\program files\MyWebSearch\bar\Cache\018185B9
c:\program files\MyWebSearch\bar\Cache\061AA3A5.bin
c:\program files\MyWebSearch\bar\Cache\061AC6BD.bin
c:\program files\MyWebSearch\bar\Cache\061AEF34.bin
c:\program files\MyWebSearch\bar\Cache\061AFE28.bin
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
c:\program files\ShoppingReport
c:\program files\ShoppingReport\Uninst.exe
c:\program files\ThinkPad\ConnectUtilities\ACGina.dll
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\71d21861.sys
c:\windows\system32\drivers\str.sys
c:\windows\system32\f3PSSavr.scr
c:\windows\system32\wbem\grpconv.exe
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\grpconv.exe was missing
Plik odzyskano z -
c:\windows\system32\proquota.exe was missing
Plik odzyskano z -
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_RASAUTODCOMLAUNCH
-------\Service_71d21861
-------\Service_MyWebSearchService
-------\Service_RasAutoDcomLaunch
((((((((((((((((((((((((( Pliki utworzone od 2009-04-28 do 2009-05-28 )))))))))))))))))))))))))))))))
.
2009-05-28 14:38 . 2004-08-04 20:00 50688 ----a-w c:\windows\system32\proquota.exe
2009-05-28 14:38 . 2004-08-04 20:00 50688 ----a-w c:\windows\system32\dllcache\proquota.exe
2009-05-28 14:37 . 2004-08-04 20:00 39424 ----a-w c:\windows\system32\grpconv.exe
2009-05-28 14:37 . 2004-08-04 20:00 39424 ----a-w c:\windows\system32\dllcache\grpconv.exe
2009-05-28 12:48 . 2009-02-05 20:06 23152 ----a-w c:\windows\system32\drivers\aswRdr.sys
2009-05-28 12:48 . 2009-02-05 20:06 51376 ----a-w c:\windows\system32\drivers\aswTdi.sys
2009-05-28 12:48 . 2009-02-05 20:05 26944 ----a-w c:\windows\system32\drivers\aavmker4.sys
2009-05-28 12:48 . 2009-02-05 20:04 97480 ----a-w c:\windows\system32\AvastSS.scr
2009-05-28 12:48 . 2009-02-05 20:08 93296 ----a-w c:\windows\system32\drivers\aswmon.sys
2009-05-28 12:48 . 2009-02-05 20:08 94032 ----a-w c:\windows\system32\drivers\aswmon2.sys
2009-05-28 12:48 . 2009-02-05 20:07 114768 ----a-w c:\windows\system32\drivers\aswSP.sys
2009-05-28 12:48 . 2009-02-05 20:07 20560 ----a-w c:\windows\system32\drivers\aswFsBlk.sys
2009-05-28 12:48 . 2009-02-05 20:11 1256296 ----a-w c:\windows\system32\aswBoot.exe
2009-05-28 12:47 . 2009-05-28 12:47 -------- d-----w c:\program files\Alwil Software
2009-05-27 17:39 . 2009-05-27 17:39 -------- d-----w c:\program files\Trend Micro
2009-05-27 17:28 . 2009-05-27 17:28 -------- d-----w c:\program files\ClustalX2
2009-05-27 17:25 . 2009-05-28 14:15 -------- d-----w c:\program files\Symantec
2009-05-27 16:57 . 2009-05-27 16:57 96976 ----a-w c:\windows\system32\drivers\klin.dat
2009-05-27 16:57 . 2009-05-27 16:57 87855 ----a-w c:\windows\system32\drivers\klick.dat
2009-05-27 16:55 . 2009-05-27 17:04 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-27 16:55 . 2009-05-27 17:04 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-27 16:55 . 2009-05-27 16:55 -------- d-----w c:\program files\Kaspersky Lab
2009-05-27 16:55 . 2009-05-27 16:55 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab
2009-05-26 12:56 . 2009-05-26 12:56 -------- d-----w c:\documents and settings\Manciu\Dotter
2009-05-25 23:50 . 2009-05-26 00:18 108080641 ----a-w c:\documents and settings\Manciu\Dane aplikacji\Opera\Opera\profile\cache4\temporary_download\OOo_3.1.0_Win32Intel_install_pl.exe
2009-05-25 06:01 . 2009-05-28 14:44 115008 ----a-w c:\windows\system32\drivers\91ed905f.sys
2009-05-21 17:42 . 2009-05-21 17:42 -------- d-----w c:\program files\LGE GSM PC Sync
2009-05-21 17:42 . 2009-05-21 17:42 -------- d-----w c:\program files\eMule
2009-05-20 09:33 . 2009-05-21 17:45 -------- d-----w c:\documents and settings\Administrator.LENOVO-49028DC7\Dane aplikacji
2009-05-20 09:33 . 2006-03-24 15:15 135 ----a-w c:\documents and settings\Administrator.LENOVO-49028DC7\Ustawienia lokalne\Dane aplikacji\fusioncache.dat
2009-05-20 09:33 . 2009-05-21 17:45 -------- d-----w c:\documents and settings\Administrator.LENOVO-49028DC7\Ustawienia lokalne\Dane aplikacji\Microsoft
2009-05-20 09:33 . 2009-05-21 17:45 -------- d-----w c:\documents and settings\Administrator.LENOVO-49028DC7\Ustawienia lokalne
2009-05-20 09:33 . 2009-05-21 17:45 -------- d-----w c:\documents and settings\Administrator.LENOVO-49028DC7\Ulubione
2009-05-20 09:33 . 2009-05-21 17:45 -------- d-----w c:\documents and settings\Administrator.LENOVO-49028DC7\Moje dokumenty
2009-05-20 09:33 . 2009-05-21 17:45 -------- d-----w c:\documents and settings\Administrator.LENOVO-49028DC7\Szablony
2009-05-20 09:33 . 2009-05-21 17:45 -------- d-s---w c:\documents and settings\Administrator.LENOVO-49028DC7
2009-05-20 08:43 . 2009-05-21 17:47 -------- d-----w c:\documents and settings\All Users\Dane aplikacji\G DATA
2009-05-20 08:42 . 2009-05-20 08:42 -------- d-----w c:\windows\l2schemas
2009-05-20 08:39 . 2009-05-21 17:48 -------- d-----w c:\program files\Common Files\G DATA
2009-05-20 08:39 . 2009-05-20 08:39 -------- d-----w c:\program files\G DATA
2009-05-11 18:56 . 2009-05-11 18:56 -------- d-----w c:\documents and settings\Manciu\.gstreamer-0.10
2009-05-11 18:04 . 2009-05-11 18:04 -------- d-----w c:\documents and settings\Manciu\Dane aplikacji\OpenFM
2009-05-10 10:05 . 2009-05-10 17:11 -------- d-----w c:\documents and settings\Manciu\Dane aplikacji\Nowe Gadu-Gadu
2009-05-10 10:04 . 2009-05-26 16:09 -------- d-----w c:\program files\Nowe Gadu-Gadu
2009-05-05 12:30 . 2009-05-25 06:01 195 --s-a-w c:\windows\system32\2090242729.dat
2009-05-02 17:05 . 1996-12-03 11:07 403216 ------w c:\windows\system32\msrepl35.dll
2009-05-02 17:05 . 1997-09-30 23:00 377344 ------w c:\windows\system\Mm.dll
2009-05-02 17:05 . 1997-09-30 23:00 247808 ------w c:\windows\system\DATABASE.DLL
2009-05-02 17:05 . 2009-05-02 17:05 -------- d-----w c:\program files\Bio-Rad Laboratories
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-28 14:15 . 2006-12-21 03:59 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-05-28 13:28 . 2008-12-31 10:00 -------- d-----w c:\program files\Perfect Defender 2009
2009-05-28 12:44 . 2006-12-21 03:59 -------- d---a-w c:\documents and settings\All Users\Dane aplikacji\Symantec
2009-05-27 17:13 . 2009-05-27 17:13 3676 ----a-w c:\windows\system32\PerfStringBackup.TMP
2009-05-27 17:13 . 2006-12-21 11:25 515016 ----a-w c:\windows\system32\perfh015.dat
2009-05-27 17:13 . 2006-12-21 11:25 100430 ----a-w c:\windows\system32\perfc015.dat
2009-05-27 17:04 . 2009-05-27 16:55 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-27 17:04 . 2009-05-27 16:55 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-27 15:59 . 2007-03-04 00:43 -------- d---a-w c:\documents and settings\Manciu\Dane aplikacji\Symantec
2009-05-27 15:56 . 2006-12-21 03:58 -------- d-----w c:\program files\PCDR5
2009-05-24 14:10 . 2006-12-21 04:10 5427 ----a-w c:\windows\system32\EGATHDRV.SYS
2009-05-21 13:46 . 2008-02-12 00:03 -------- d-----w c:\documents and settings\Manciu\Dane aplikacji\skypePM
2009-05-10 10:03 . 2007-03-09 16:45 -------- d-----w c:\program files\Gadu-Gadu
2009-05-09 19:44 . 2008-02-29 18:53 -------- d-----w c:\documents and settings\Manciu\Dane aplikacji\Skype
2009-04-29 13:23 . 2007-11-29 09:22 -------- d-----w c:\program files\English Translator 3
2009-04-26 09:22 . 2007-10-22 19:44 -------- d-----w c:\program files\Leksykonia
2009-04-01 19:00 . 2009-04-01 18:59 -------- d-----w c:\documents and settings\Manciu\Dane aplikacji\pdfforge
2009-04-01 18:59 . 2009-04-01 18:59 -------- d-----w c:\documents and settings\Manciu\Dane aplikacji\Search Settings
2009-03-31 20:55 . 2009-03-31 20:54 -------- d-----w c:\program files\pdfforge Toolbar
2009-03-06 14:01 . 2006-12-21 11:26 285696 ----a-w c:\windows\system32\pdh.dll
2004-07-22 08:51 . 2004-07-22 08:51 3432656 -c--a-w c:\program files\ManagedDX.CAB
2004-07-19 20:58 . 2004-07-19 20:58 1156363 -c--a-w c:\program files\BDANT.cab
2004-07-19 20:53 . 2004-07-19 20:53 976020 -c--a-w c:\program files\BDAXP.cab
2004-07-09 12:17 . 2004-07-09 12:17 13265040 -c--a-w c:\program files\dxnt.cab
2004-07-09 07:13 . 2004-07-09 07:13 15493481 -c--a-w c:\program files\DirectX.cab
2004-07-09 07:13 . 2004-07-09 07:13 703080 -c--a-w c:\program files\BDA.cab
2004-07-09 02:08 . 2004-07-09 02:08 472576 -c--a-w c:\program files\dxsetup.exe
2004-07-09 02:08 . 2004-07-09 02:08 2242560 -c--a-w c:\program files\dsetup32.dll
2004-07-09 01:03 . 2004-07-09 01:03 62976 -c--a-w c:\program files\DSETUP.dll
2008-01-03 17:19 . 2008-01-13 01:01 581632 ----a-w c:\program files\opera\program\plugins\Control.dll
2008-01-03 17:01 . 2008-01-13 01:01 1490944 ----a-w c:\program files\opera\program\plugins\dirapi.dll
2008-01-03 17:20 . 2008-01-13 01:01 24576 ----a-w c:\program files\opera\program\plugins\DynaPlayer.dll
2008-01-03 17:39 . 2008-01-13 00:59 1113600 ----a-w c:\program files\opera\program\plugins\gi.dll
2008-01-03 16:46 . 2008-01-13 00:59 52288 ----a-w c:\program files\opera\program\plugins\gtapi.dll
2008-01-03 16:59 . 2008-01-13 01:01 606208 ----a-w c:\program files\opera\program\plugins\iml32.dll
2008-01-03 17:18 . 2008-01-13 01:09 339968 ----a-w c:\program files\opera\program\plugins\Plugin.dll
2008-01-03 17:19 . 2008-01-13 01:01 475136 ----a-w c:\program files\opera\program\plugins\PluginPing.dll
2008-01-03 17:11 . 2008-01-13 01:01 180224 ----a-w c:\program files\opera\program\plugins\Proj.dll
2008-01-03 17:18 . 2008-01-13 01:01 86016 ----a-w c:\program files\opera\program\plugins\SwMenu.dll
2008-01-03 17:22 . 2008-01-13 01:01 98304 ----a-w c:\program files\opera\program\plugins\SwOnce.dll
2008-01-03 16:46 . 2008-01-13 00:59 50808 ----a-w c:\program files\opera\program\plugins\SYMCCHECKER.DLL
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
2009-01-30 13:12 650752 ----a-w c:\program files\pdfforge Toolbar\WidgiToolbarIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 774233]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPHKMGR.exe" [2006-05-08 94208]
"TPWAUDAP"="c:\program files\Lenovo\HOTKEY\TpWAudAp.exe" [2006-04-19 24576]
"PMHandler"="c:\progra~1\Lenovo\PMDRIV~1\PMHandler.exe" [2006-08-21 33128]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-06-25 1273856]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"snp2std"="c:\windows\vsnp2std.exe" [2006-07-10 675840]
"OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [2006-10-16 2502656]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-07-14 503808]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"LPManager"="c:\progra~1\Lenovo\LENOVO~2\LPMGR.exe" [2006-07-03 110592]
"AMSG"="c:\progra~1\THINKV~1\AMSG\amsg.exe" [2005-11-22 507904]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 196696]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-14 2341632]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2009-01-30 992256]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Skrót do strony właściwości High Definition Audio"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2006-08-30 89542]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
BTTray.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2006-1-17 618557]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2006-10-16 13:30 49152 ------w c:\program files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2006-10-05 18:53 32768 ------w c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2006-01-11 06:05 13824 ------w c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Program Files\\CambridgeSoft\\ChemOffice2008\\ChemDraw\\ChemDraw.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Nowe Gadu-Gadu\\gg.exe"=
R1 aswsp;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-05-28 114768]
R1 PMHler;PMHler;c:\windows\system32\drivers\PMHler.sys [2006-05-24 10240]
R2 aswfsblk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-05-28 20560]
R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2007-03-09 100032]
R2 MSSQL$CSSQL05;SQL Server (CSSQL05);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
R2 smi2;smi2;c:\program files\SMI2\smi2.sys [2006-07-14 3968]
S3 st3bus28;st3bus28;c:\windows\system32\DRIVERS\st3bus28.sys --> c:\windows\system32\DRIVERS\st3bus28.sys [?]
--- Inne Usługi/Sterowniki w Pamięci ---
*NewlyCreated* - aswrdr
*NewlyCreated* - avast!_mail_scanner
*NewlyCreated* - avast!_web_scanner
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKLM-Run-Onet.pl AutoUpdate - c:\program files\Common Files\Onet.pl\NewAutoUpdate.exe
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
HKLM-Run-winssvc - c:\documents and settings\Manciu\Dane aplikacji\Google\pzpsp23511834.exe
Notify-WgaLogon - (no file)
SafeBoot-procexp90.sys
.
------- Skan uzupełniający -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUman000
IE: &WordWeb... - c:\windows\wweb32.dll/lookup.html
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Wyślij do urządzenia &Bluetooth... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-28 16:44
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
**************************************************************************
Binary file raw_enum.dat matches
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(1736)
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\cscdll.dll
c:\program files\Softex\OmniPass\opxpgina.dll
c:\windows\system32\tphklock.dll
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(2100)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Lenovo\Bluetooth Software\bin\btwdins.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Softex\OmniPass\OmniServ.exe
c:\program files\Lenovo\PM Driver\PMSveH.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Lenovo\System Update\SUService.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files\Common Files\Lenovo\Logger\logmon.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\program files\Java\jre1.6.0_07\bin\jucheck.exe
.
**************************************************************************
.
Czas ukończenia: 2009-05-28 16:54 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-05-28 14:52
Przed: 8 421 535 744 bajtów wolnych
Po: 8 407 629 824 bajtów wolnych
WindowsXP-KB310994-SP2-Home-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
Czy mógłby to ktoś sprawdzić i napisać co dalej robić. Dziękuję
Proszę poprawnie umieścić logi. Przeniosłem z Sieć Internet - Dostęp.
Gusioo.
|
|