logo elektroda
logo elektroda
X
logo elektroda
REKLAMA
REKLAMA
Adblock/uBlockOrigin/AdGuard mogą powodować znikanie niektórych postów z powodu nowej reguły.

Jak usunąć robaka zmieniającego tapetę i tworzącego pliki .tmp i .dat?

zonkil 28 Gru 2007 19:01 3255 11
REKLAMA
  • #1 4633084
    zonkil
    Poziom 31  
    Posty: 2623
    Pomógł: 77
    Ocena: 346
    Witam
    Wczoraj przez przypadek zainstalowałem sobie plik który zainfekował mi system. Przeskanowałem system 3 skanerami antiwirusowymi użyłem SmitfraudFix z 3 razy oraz Spybot - Search & Destroy z 5 razy prawie wszystkio usunęło poza robakiem który zmienia mi tapetę.
    Antivir wywala komunikaty np. taki:
    Cytat:
    Virus or unwanted program 'BAT/Fake.Privdanger [BAT/Fake.Privdanger]'
    detected in file 'C:\DOCUME~1\Kamil\USTAWI~1\Temp\install-privacy-danger.bat.
    Action performed: Delete file
    po którym zawsze zmienia się tapeta.
    Następnie:
    Cytat:
    Virus or unwanted program 'VBS/Click.A [VBS/Click.A]'
    detected in file 'C:\DOCUME~1\Kamil\USTAWI~1\Temp\tmp222.tmp.
    Action performed: Delete file
    i tak ciągle tylko z innymi nazwami plików.

    SmitfraudFix użyłem w trybie awaryjnym usunąłem wszystko z Temp ale ciągle pojawiają się tam pliki BIT656.tmp, BIT219.tmp itd oraz cteng_1_1_71198818691.dat, cteng_1_2_41198847261.dat itd. których nie da się usunąć pod Windowsem.
    Co mi radzicie?
  • REKLAMA
  • #2 4633202
    Kolobos
    Spec od komputerów
    Posty: 85179
    Pomógł: 17172
    Ocena: 10457
    Daj w zalaczniku log z combofix oraz hijackthis.
  • #3 4633218
    birband
    Poziom 24  
    Posty: 878
    Pomógł: 58
    Ocena: 44
    Jak znasz nazwy plików i nie udaje się ich usunąć pod normalnie działającym windowsem - przejdź w tryb awaryjny i tam pousuwaj te pliki.
  • #4 4633738
    zonkil
    Poziom 31  
    Posty: 2623
    Pomógł: 77
    Ocena: 346
    Tak też zrobiłem i dalej to samo wracaja jakby robak siedział w explorerze. Te pliki cteng_1_1_71198818691.dat, cteng_1_2_41198847261.dat należą do Incredimail więc odpadają.

    Combofix:
    Cytat:
    ComboFix 07-12-21.4 - Kamil 2007-12-28 21:02:00.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.127 [GMT 1:00]
    Running from: C:\Documents and Settings\Kamil\Pulpit\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\dat.txt
    C:\WINDOWS\rs.txt
    C:\WINDOWS\search_res.txt
    C:\WINDOWS\system32\NTSVC.ocx
    C:\WINDOWS\system32\temp1.exe
    C:\WINDOWS\system32\temp2.exe

    .
    ((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-28 )))))))))))))))))))))))))))))))
    .

    2007-12-28 20:54 . 2007-12-28 20:54 10,624 --a------ C:\WINDOWS\system32\drivers\pxark.sys
    2007-12-28 20:53 . 2007-12-28 20:53 <DIR> d-------- C:\Program Files\PrevxCSI
    2007-12-28 20:44 . 2007-12-28 20:54 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\PrevxCSI
    2007-12-28 20:44 . 2007-12-28 20:44 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Prevx
    2007-12-28 14:49 . 2007-12-28 14:49 0 --a------ C:\WINDOWS\mtstack16.INI
    2007-12-28 12:35 . 2007-12-28 12:39 <DIR> d-------- C:\Program Files\SkanerOnline
    2007-12-27 21:21 . 2007-12-27 21:21 7,168 --ahs---- C:\WINDOWS\Thumbs.db
    2007-12-27 18:36 . 2007-12-28 12:58 2,888 --a------ C:\WINDOWS\system32\tmp.reg
    2007-12-27 18:35 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
    2007-12-27 18:35 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
    2007-12-27 18:35 . 2007-12-20 23:11 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
    2007-12-27 18:35 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
    2007-12-27 18:35 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
    2007-12-27 18:35 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
    2007-12-27 10:49 . 2007-12-27 10:51 <DIR> d-------- C:\Program Files\GraphCalc
    2007-12-27 10:24 . 2007-12-27 21:21 <DIR> d-------- C:\Program Files\Advanced Grapher
    2007-12-27 10:08 . 2007-12-27 10:08 85 --a------ C:\WINDOWS\wininit.ini
    2007-12-27 09:19 . 2007-12-27 10:09 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
    2007-12-26 20:27 . 2007-12-26 20:27 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
    2007-12-26 20:10 . 2007-12-26 19:34 90,112 --a------ C:\WINDOWS\fvkwdrt.exe
    2007-12-22 19:20 . 2007-12-22 19:20 <DIR> d-------- C:\WINDOWS\system32\recover
    2007-12-20 14:48 . 2007-12-20 14:48 3,120 --------- C:\WINDOWS\.lfa
    2007-12-12 22:37 . 2007-12-27 21:21 <DIR> d-------- C:\Program Files\LimeWire
    2007-12-12 22:37 . 2007-12-12 22:37 <DIR> d-------- C:\Documents and Settings\Kamil\Incomplete
    2007-12-12 22:37 . 2007-12-26 08:22 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\LimeWire
    2007-12-12 22:37 . 2007-09-27 07:01 1,648,003 -r-h----- C:\WINDOWS\HTTPSBinTCP.exe
    2007-12-10 19:21 . 2007-12-10 19:21 <DIR> d-------- C:\Program Files\Intel
    2007-12-10 19:21 . 2007-12-10 19:21 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\InstallShield
    2007-12-10 19:11 . 2007-12-22 19:21 <DIR> d-------- C:\Program Files\nLite
    2007-12-10 18:58 . 2007-12-10 18:58 <DIR> d-------- C:\Program Files\MagicISO
    2007-12-10 18:50 . 2007-12-10 18:50 <DIR> d-------- C:\F6 Floppy Utility
    2007-12-06 15:48 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
    2007-12-06 15:48 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
    2007-12-06 15:48 . 2007-12-06 15:48 395 --a------ C:\WINDOWS\BRWMARK.INI
    2007-12-06 15:48 . 2007-12-06 15:48 34 --a------ C:\WINDOWS\system32\BD2030.DAT
    2007-12-06 15:37 . 2007-12-06 15:37 <DIR> d-------- C:\Program Files\Brownie
    2007-12-06 15:29 . 2007-12-06 15:36 <DIR> d-------- C:\Program Files\Brother
    2007-12-06 15:29 . 2004-11-18 01:25 188,416 --------- C:\WINDOWS\system32\Pdrvinst.dll
    2007-12-06 15:29 . 2003-12-12 09:37 86,016 --------- C:\WINDOWS\system32\BrWebIns.dll
    2007-12-06 15:29 . 2003-07-03 01:08 65,536 --------- C:\WINDOWS\system32\BRWEBUP.EXE
    2007-12-05 22:37 . 2007-12-05 22:37 <DIR> d-------- C:\Program Files\wxMaxima
    2007-12-05 22:29 . 2007-12-05 22:30 <DIR> d-------- C:\Program Files\Maxima-5.13.0
    2007-12-03 21:00 . 2007-12-03 21:01 <DIR> d-------- C:\Nowy folder
    2007-12-02 11:04 . 2007-12-02 11:04 <DIR> d--hs---- C:\WINDOWS\ftpcache
    2007-12-02 11:04 . 2007-12-02 11:04 <DIR> d-------- C:\Program Files\PHP Expert Editor 4.2
    2007-12-02 10:45 . 2007-12-02 10:54 47,400 --a------ C:\WINDOWS\php.ini

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-12-28 20:02 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\uTorrent
    2007-12-28 18:58 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Tlen.pl
    2007-12-28 07:40 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Skype
    2007-12-27 20:21 --------- d-----w C:\Program Files\K-Lite Codec Pack
    2007-12-27 18:58 --------- d-----w C:\Program Files\FlashGet
    2007-12-22 18:23 --------- d-----w C:\Program Files\NAPI-PROJEKT
    2007-12-22 18:22 --------- d-----w C:\Program Files\Wolfram Research
    2007-12-20 20:31 --------- d-----w C:\Program Files\Tlen.pl
    2007-12-20 13:46 --------- d-----w C:\Program Files\IncrediMail
    2007-12-14 18:04 --------- d-----w C:\Program Files\FDRLab
    2007-12-13 14:48 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
    2007-12-12 21:28 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
    2007-12-10 18:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-12-10 17:28 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\BearShare
    2007-12-06 14:29 --------- d-----w C:\Program Files\Common Files\InstallShield
    2007-12-01 17:32 --------- d-----w C:\Program Files\SubEdit-Player
    2007-11-24 21:53 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Participatory Culture Foundation
    2007-11-20 20:33 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Media Player Classic
    2007-11-20 20:32 --------- d-----w C:\Program Files\Real Alternative
    2007-11-20 20:32 --------- d-----w C:\Program Files\Media Player Classic
    2007-11-20 20:20 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\OpenOfficeT72
    2007-11-19 20:27 20,747 ------w C:\WINDOWS\system32\drivers\AegisP.sys
    2007-11-19 20:27 --------- d-----w C:\Program Files\RALINK
    2007-11-13 10:25 20,480 ------w C:\WINDOWS\system32\drivers\secdrv.sys
    2007-11-11 22:15 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\MfcEmbed
    2007-11-11 22:13 --------- d-----w C:\Program Files\OpenOfficeT7 2.3
    2007-11-03 07:22 --------- d-----w C:\Program Files\Toribash-3.04
    2007-11-02 16:23 --------- d-----w C:\Program Files\YouTube Video Downloader
    2007-11-02 15:01 --------- d-----w C:\Program Files\IrfanView
    2007-11-02 13:32 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Logitech
    2007-11-02 09:54 --------- d-----w C:\Program Files\Logitech
    2007-11-02 09:53 --------- d-----w C:\Program Files\Common Files\Logitech
    2007-10-29 22:44 1,291,264 ------w C:\WINDOWS\system32\quartz.dll
    2007-10-29 19:59 --------- d-----w C:\Program Files\DC++
    2007-10-25 08:28 222,720 ------w C:\WINDOWS\system32\wmasf.dll
    2007-10-12 14:10 13,312 ----a-w C:\WINDOWS\buninst.exe
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87EF7048-8905-4E82-862E-65004D4DFA80}]
    C:\WINDOWS\domnftwwrn.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Uchwyt nakładania ikony podpisu cyfrowego]
    @={36A21736-36C2-4C11-8ACB-D4136F2B57BD}

    [HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
    2004-07-01 22:12 136312 --------- C:\WINDOWS\system32\AcSignIcon.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Bandwidth Monitor Pro"="C:\Program Files\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe" [2005-02-12 11:29]
    "IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-12-20 14:48]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:44]
    "LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-11-02 12:37]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMan"="SOUNDMAN.EXE" [2004-07-27 16:01 C:\WINDOWS\SOUNDMAN.EXE]
    "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-12 19:18]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50]
    "Acrobat Assistant 7.0"="D:\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 01:12]
    "GrooveMonitor"="D:\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47]
    "ULiRaid"="C:\Program Files\ULiRaid\ULiRaid.exe" [2006-05-12 12:57]
    "NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
    "nwiz"="nwiz.exe" [2006-10-22 11:22 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
    "DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-11-22 16:38]
    "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10]
    "PowerS"="C:\WINDOWS\PowerS.exe" [2001-08-03 16:56]
    "WinFast Schedule"="C:\Program Files\WinFast\WFTVFM\WFWIZ.exe" [2007-05-22 09:14]
    "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 14:46 C:\WINDOWS\KHALMNPR.Exe]
    "PrevxCSI"="C:\Program Files\PrevxCSI\prevxcsi.exe" [2007-12-28 20:44]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:44]
    "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 09:17]

    C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
    Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-09-09 11:53:31]
    Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-02 12:37:24]
    Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-02 10:53:08]
    Microsoft Office.lnk - D:\office\Office10\OSA.EXE [2001-02-13 09:01:04]
    Przyspieszenie uruchomienia programu AutoCAD.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2004-07-01 22:10:06]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSharedDocuments"= 1 (0x1)
    "ForceClassicControlPanel"= 1 (0x1)
    "NoSMConfigurePrograms"= 1 (0x1)
    "NoRecentDocsMenu"= 1 (0x1)
    "NoChangeKeyboardNavigationIndicators"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "alxvdvm"= {B4292098-43AC-4B9B-B311-143CEB5C2F6F} - C:\WINDOWS\alxvdvm.dll [ ]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Ralink Wireless Utility.lnk]
    path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Ralink Wireless Utility.lnk
    backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    C:\WINDOWS\system32\dumprep 0 -k

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
    C:\WINDOWS\svchost.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProxyWay]
    C:\Program Files\ProxyWay\proxyway.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2007-09-25 00:11 132496 --a------ C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

    R0 avgntmgr;avgntmgr;C:\WINDOWS\system32\DRIVERS\avgntmgr.sys [2007-09-06 14:34]
    R0 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys [2005-07-04 13:21]
    R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys [2005-05-03 16:31]
    R1 avgntdd;avgntdd;C:\WINDOWS\system32\DRIVERS\avgntdd.sys [2007-09-06 14:34]
    R2 ALIEHCD;ALi PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ALIEHCI.sys [2003-12-18 19:56]
    R2 HOSTNT;Hostnt;C:\WINDOWS\system32\drivers\hostnt.sys [2007-09-23 09:43]
    R2 MHDRV;Mhdrv;C:\WINDOWS\system32\drivers\mhdrv.sys [2007-09-23 09:43]
    R2 RCMHDOG;RCMHDOG;C:\WINDOWS\system32\drivers\rcmhdog.sys [2007-09-23 09:43]
    R3 aliroothub;USB 2.0 Root Hub;C:\WINDOWS\system32\DRIVERS\AliRtHub.sys [2003-12-18 09:45]
    R3 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2007-12-28 20:54]
    R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS [2005-03-22 19:36]
    R3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS [2005-01-06 15:55]
    S2 BT848;WinFast TV2000 XP WDM Video Capture;C:\WINDOWS\system32\drivers\wf2kvcap.sys [2004-10-04 11:34]
    S2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;C:\WINDOWS\system32\drivers\wf2ktunr.sys [2004-10-04 11:34]
    S2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;C:\WINDOWS\system32\drivers\wf2kxbar.sys [2004-10-04 11:34]
    S3 DSDrv4;DSDrv4;C:\PROGRA~1\DScaler\DSDrv4.sys [2005-10-19 18:43]
    S3 PortTalk;PortTalk;C:\WINDOWS\system32\Drivers\PortTalk.sys [2002-01-12 15:30]
    S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]

    *Newly Created Service* - PXARK
    .
    Contents of the 'Scheduled Tasks' folder
    "2007-12-28 16:29:03 C:\WINDOWS\Tasks\1-Click Maintenance.job"
    - C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
    .
    **************************************************************************

    catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-28 21:03:48
    Windows 5.1.2600 Dodatek Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .


    Hijackthis:
    Cytat:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:06, on 2007-12-28
    Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    D:\Acrobat 7.0\Distillr\Acrotray.exe
    D:\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\ULiRaid\ULiRaid.exe
    C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
    C:\WINDOWS\PowerS.exe
    C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\PROGRA~1\INCRED~1\bin\IMApp.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\Tlen.pl\tlen.exe
    C:\Program Files\TC PowerPack\totalcmd.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 146.164.34.14:80
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\MICROS~1\Office12\GRA8E1~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: BDEX System - {87EF7048-8905-4E82-862E-65004D4DFA80} - C:\WINDOWS\domnftwwrn.dll (file missing)
    O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\Acrobat 7.0\Distillr\Acrotray.exe"
    O4 - HKLM\..\Run: [GrooveMonitor] "D:\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [ULiRaid] C:\Program Files\ULiRaid\ULiRaid.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [PowerS] C:\WINDOWS\PowerS.exe
    O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [PrevxCSI] "C:\Program Files\PrevxCSI\prevxcsi.exe" -boot
    O4 - HKCU\..\Run: [Bandwidth Monitor Pro] "C:\Program Files\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe" /minimized
    O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA LOKALNA')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O4 - Global Startup: Microsoft Office.lnk = D:\office\Office10\OSA.EXE
    O4 - Global Startup: Przyspieszenie uruchomienia programu AutoCAD.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
    O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.07\AMVConverter\grab.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert to existing PDF - res://D:\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://D:\MICROS~1\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\Office12\REFIEBAR.DLL
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
    O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\MICROS~1\Office12\GR99D3~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O21 - SSODL: alxvdvm - {B4292098-43AC-4B9B-B311-143CEB5C2F6F} - C:\WINDOWS\alxvdvm.dll (file missing)
    O21 - SSODL: bvtqfvx - {A47F4957-E229-4D9A-B309-D96029005B8B} - (no file)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    --
    End of file - 11613 bytes
  • REKLAMA
  • REKLAMA
  • #6 4634011
    Kolobos
    Spec od komputerów
    Posty: 85179
    Pomógł: 17172
    Ocena: 10457
    :arrow: daniel.mil
    To zwykly trojan.

    :arrow: metalli
    Jak masz zamiar w kazdym watku podawac ten link to lepiej juz nic nie pisz.

    :arrow: zonkil
    Odinstaluj Logitech Desktop Messenger.

    W hijackthis usun:
    O2 - BHO: BDEX System - {87EF7048-8905-4E82-862E-65004D4DFA80} - C:\WINDOWS\domnftwwrn.dll (file missing)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
    O21 - SSODL: alxvdvm - {B4292098-43AC-4B9B-B311-143CEB5C2F6F} - C:\WINDOWS\alxvdvm.dll (file missing)
    O21 - SSODL: bvtqfvx - {A47F4957-E229-4D9A-B309-D96029005B8B} - (no file)

    Wklej do notatnika to:

    File::
    C:\WINDOWS\fvkwdrt.exe
    C:\WINDOWS\HTTPSBINTCP.EXE

    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87EF7048-8905-4E82-862E-65004D4DFA80}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "alxvdvm"=-

    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]


    Plik zapisz w katalogu z combofix pod nazwa CFScript.txt, nastepnie przeciagnij plik CFScript.txt na ikone combofix.exe (tak jak to masz pokazane tutaj http://i12.tinypic.com/4l761r5.gif ). Po wszystkim daj log w zalaczniku. Zrob tez skan przy pomocy SuperAntiSpyware.
  • #7 4634078
    zonkil
    Poziom 31  
    Posty: 2623
    Pomógł: 77
    Ocena: 346
    Cytat:
    ComboFix 07-12-21.4 - Kamil 2007-12-28 22:15:51.3 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.116 [GMT 1:00]
    Running from: C:\Documents and Settings\Kamil\Pulpit\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\system32\NTSVC.ocx
    .
    ---- Previous Run -------
    .
    C:\WINDOWS\dat.txt
    C:\WINDOWS\rs.txt
    C:\WINDOWS\search_res.txt
    C:\WINDOWS\system32\NTSVC.ocx
    C:\WINDOWS\system32\temp1.exe
    C:\WINDOWS\system32\temp2.exe

    .
    ((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-28 )))))))))))))))))))))))))))))))
    .

    2007-12-28 21:50 . 2007-12-28 21:52 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2007-12-28 21:50 . 2007-12-28 21:50 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\SUPERAntiSpyware.com
    2007-12-28 21:50 . 2007-12-28 21:50 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\SUPERAntiSpyware.com
    2007-12-28 21:14 . 2007-12-28 21:14 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Grisoft
    2007-12-28 21:10 . 2007-12-28 21:11 <DIR> d-------- C:\Program Files\RogueRemover FREE
    2007-12-28 21:06 . 2007-12-28 21:06 <DIR> d-------- C:\Program Files\Trend Micro
    2007-12-28 20:54 . 2007-12-28 20:54 10,624 --a------ C:\WINDOWS\system32\drivers\pxark.sys
    2007-12-28 20:53 . 2007-12-28 21:21 <DIR> d-------- C:\Program Files\PrevxCSI
    2007-12-28 20:44 . 2007-12-28 20:54 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\PrevxCSI
    2007-12-28 20:44 . 2007-12-28 20:44 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Prevx
    2007-12-28 14:49 . 2007-12-28 14:49 0 --a------ C:\WINDOWS\mtstack16.INI
    2007-12-28 12:35 . 2007-12-28 12:39 <DIR> d-------- C:\Program Files\SkanerOnline
    2007-12-27 21:21 . 2007-12-27 21:21 7,168 --ahs---- C:\WINDOWS\Thumbs.db
    2007-12-27 18:36 . 2007-12-28 12:58 2,888 --a------ C:\WINDOWS\system32\tmp.reg
    2007-12-27 18:35 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
    2007-12-27 18:35 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
    2007-12-27 18:35 . 2007-12-20 23:11 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
    2007-12-27 18:35 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
    2007-12-27 18:35 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
    2007-12-27 18:35 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
    2007-12-27 10:49 . 2007-12-27 10:51 <DIR> d-------- C:\Program Files\GraphCalc
    2007-12-27 10:24 . 2007-12-28 21:11 <DIR> d-------- C:\Program Files\Advanced Grapher
    2007-12-27 10:08 . 2007-12-27 10:08 85 --a------ C:\WINDOWS\wininit.ini
    2007-12-27 09:19 . 2007-12-28 21:20 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
    2007-12-26 20:27 . 2007-12-26 20:27 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
    2007-12-26 20:10 . 2007-12-26 19:34 90,112 --a------ C:\WINDOWS\fvkwdrt.exe
    2007-12-22 19:20 . 2007-12-22 19:20 <DIR> d-------- C:\WINDOWS\system32\recover
    2007-12-20 14:48 . 2007-12-20 14:48 3,120 --------- C:\WINDOWS\.lfa
    2007-12-12 22:37 . 2007-12-27 21:21 <DIR> d-------- C:\Program Files\LimeWire
    2007-12-12 22:37 . 2007-12-12 22:37 <DIR> d-------- C:\Documents and Settings\Kamil\Incomplete
    2007-12-12 22:37 . 2007-12-26 08:22 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\LimeWire
    2007-12-12 22:37 . 2007-09-27 07:01 1,648,003 -r-h----- C:\WINDOWS\HTTPSBinTCP.exe
    2007-12-10 19:21 . 2007-12-10 19:21 <DIR> d-------- C:\Program Files\Intel
    2007-12-10 19:21 . 2007-12-10 19:21 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\InstallShield
    2007-12-10 19:11 . 2007-12-22 19:21 <DIR> d-------- C:\Program Files\nLite
    2007-12-10 18:58 . 2007-12-10 18:58 <DIR> d-------- C:\Program Files\MagicISO
    2007-12-10 18:50 . 2007-12-10 18:50 <DIR> d-------- C:\F6 Floppy Utility
    2007-12-06 15:48 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
    2007-12-06 15:48 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
    2007-12-06 15:48 . 2007-12-06 15:48 395 --a------ C:\WINDOWS\BRWMARK.INI
    2007-12-06 15:48 . 2007-12-06 15:48 34 --a------ C:\WINDOWS\system32\BD2030.DAT
    2007-12-06 15:37 . 2007-12-06 15:37 <DIR> d-------- C:\Program Files\Brownie
    2007-12-06 15:29 . 2007-12-06 15:36 <DIR> d-------- C:\Program Files\Brother
    2007-12-06 15:29 . 2004-11-18 01:25 188,416 --------- C:\WINDOWS\system32\Pdrvinst.dll
    2007-12-06 15:29 . 2003-12-12 09:37 86,016 --------- C:\WINDOWS\system32\BrWebIns.dll
    2007-12-06 15:29 . 2003-07-03 01:08 65,536 --------- C:\WINDOWS\system32\BRWEBUP.EXE
    2007-12-05 22:37 . 2007-12-05 22:37 <DIR> d-------- C:\Program Files\wxMaxima
    2007-12-05 22:29 . 2007-12-05 22:30 <DIR> d-------- C:\Program Files\Maxima-5.13.0
    2007-12-03 21:00 . 2007-12-03 21:01 <DIR> d-------- C:\Nowy folder
    2007-12-02 11:04 . 2007-12-02 11:04 <DIR> d--hs---- C:\WINDOWS\ftpcache
    2007-12-02 11:04 . 2007-12-02 11:04 <DIR> d-------- C:\Program Files\PHP Expert Editor 4.2
    2007-12-02 10:45 . 2007-12-02 10:54 47,400 --a------ C:\WINDOWS\php.ini

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-12-28 20:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2007-12-28 20:48 --------- d-----w C:\Program Files\Bandwidth Monitor Pro
    2007-12-28 20:04 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\uTorrent
    2007-12-28 18:58 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Tlen.pl
    2007-12-28 07:40 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Skype
    2007-12-27 20:21 --------- d-----w C:\Program Files\K-Lite Codec Pack
    2007-12-27 18:58 --------- d-----w C:\Program Files\FlashGet
    2007-12-22 18:23 --------- d-----w C:\Program Files\NAPI-PROJEKT
    2007-12-22 18:22 --------- d-----w C:\Program Files\Wolfram Research
    2007-12-20 20:31 --------- d-----w C:\Program Files\Tlen.pl
    2007-12-20 13:46 --------- d-----w C:\Program Files\IncrediMail
    2007-12-14 18:04 --------- d-----w C:\Program Files\FDRLab
    2007-12-13 14:48 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
    2007-12-12 21:28 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
    2007-12-10 18:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-12-10 17:28 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\BearShare
    2007-12-06 14:29 --------- d-----w C:\Program Files\Common Files\InstallShield
    2007-12-01 17:32 --------- d-----w C:\Program Files\SubEdit-Player
    2007-11-24 21:53 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Participatory Culture Foundation
    2007-11-20 20:33 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Media Player Classic
    2007-11-20 20:32 --------- d-----w C:\Program Files\Real Alternative
    2007-11-20 20:32 --------- d-----w C:\Program Files\Media Player Classic
    2007-11-20 20:20 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\OpenOfficeT72
    2007-11-19 20:27 20,747 ------w C:\WINDOWS\system32\drivers\AegisP.sys
    2007-11-19 20:27 --------- d-----w C:\Program Files\RALINK
    2007-11-13 10:25 20,480 ------w C:\WINDOWS\system32\drivers\secdrv.sys
    2007-11-11 22:15 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\MfcEmbed
    2007-11-11 22:13 --------- d-----w C:\Program Files\OpenOfficeT7 2.3
    2007-11-03 07:22 --------- d-----w C:\Program Files\Toribash-3.04
    2007-11-02 16:23 --------- d-----w C:\Program Files\YouTube Video Downloader
    2007-11-02 15:01 --------- d-----w C:\Program Files\IrfanView
    2007-11-02 13:32 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Logitech
    2007-11-02 09:54 --------- d-----w C:\Program Files\Logitech
    2007-11-02 09:53 --------- d-----w C:\Program Files\Common Files\Logitech
    2007-10-29 22:44 1,291,264 ------w C:\WINDOWS\system32\quartz.dll
    2007-10-29 19:59 --------- d-----w C:\Program Files\DC++
    2007-10-25 08:28 222,720 ------w C:\WINDOWS\system32\wmasf.dll
    2007-10-12 14:10 13,312 ----a-w C:\WINDOWS\buninst.exe
    .

    ((((((((((((((((((((((((((((( snapshot(_at_)2007-12-28_21.03.50,93 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2007-12-28 20:50:47 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
    + 2007-12-28 20:50:47 18,944 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
    + 2007-12-28 20:50:47 65,024 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
    + 2007-12-28 20:40:58 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_218.dat
    - 1999-12-17 08:13:04 86,016 ----a-w C:\WINDOWS\unvise32.exe
    + 1999-12-17 09:13:04 86,016 ----a-w C:\WINDOWS\unvise32.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Uchwyt nakładania ikony podpisu cyfrowego]
    @={36A21736-36C2-4C11-8ACB-D4136F2B57BD}

    [HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
    2004-07-01 22:12 136312 --------- C:\WINDOWS\system32\AcSignIcon.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Bandwidth Monitor Pro"="C:\PROGRA~1\BANDWI~1\Bandwidth Monitor Pro.exe" [2005-02-09 19:32]
    "IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-12-20 14:48]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:44]
    "LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-11-02 12:37]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMan"="SOUNDMAN.EXE" [2004-07-27 16:01 C:\WINDOWS\SOUNDMAN.EXE]
    "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-12 19:18]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50]
    "Acrobat Assistant 7.0"="D:\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 01:12]
    "GrooveMonitor"="D:\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47]
    "ULiRaid"="C:\Program Files\ULiRaid\ULiRaid.exe" [2006-05-12 12:57]
    "NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
    "nwiz"="nwiz.exe" [2006-10-22 11:22 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
    "DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-11-22 16:38]
    "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10]
    "PowerS"="C:\WINDOWS\PowerS.exe" [2001-08-03 16:56]
    "WinFast Schedule"="C:\Program Files\WinFast\WFTVFM\WFWIZ.exe" [2007-05-22 09:14]
    "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 14:46 C:\WINDOWS\KHALMNPR.Exe]
    "PrevxCSI"="C:\Program Files\PrevxCSI\prevxcsi.exe" []

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:44]
    "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 09:17]

    C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
    Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-09-09 11:53:31]
    Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-02 12:37:24]
    Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-02 10:53:08]
    Microsoft Office.lnk - D:\office\Office10\OSA.EXE [2001-02-13 09:01:04]
    Przyspieszenie uruchomienia programu AutoCAD.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2004-07-01 22:10:06]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSharedDocuments"= 1 (0x1)
    "ForceClassicControlPanel"= 1 (0x1)
    "NoSMConfigurePrograms"= 1 (0x1)
    "NoRecentDocsMenu"= 1 (0x1)
    "NoChangeKeyboardNavigationIndicators"= 0 (0x0)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Ralink Wireless Utility.lnk]
    path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Ralink Wireless Utility.lnk
    backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    C:\WINDOWS\system32\dumprep 0 -k

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
    C:\WINDOWS\svchost.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProxyWay]
    C:\Program Files\ProxyWay\proxyway.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2007-09-25 00:11 132496 --a------ C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

    R0 avgntmgr;avgntmgr;C:\WINDOWS\system32\DRIVERS\avgntmgr.sys [2007-09-06 14:34]
    R0 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys [2005-07-04 13:21]
    R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys [2005-05-03 16:31]
    R1 avgntdd;avgntdd;C:\WINDOWS\system32\DRIVERS\avgntdd.sys [2007-09-06 14:34]
    R2 ALIEHCD;ALi PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ALIEHCI.sys [2003-12-18 19:56]
    R2 HOSTNT;Hostnt;C:\WINDOWS\system32\drivers\hostnt.sys [2007-09-23 09:43]
    R2 MHDRV;Mhdrv;C:\WINDOWS\system32\drivers\mhdrv.sys [2007-09-23 09:43]
    R2 RCMHDOG;RCMHDOG;C:\WINDOWS\system32\drivers\rcmhdog.sys [2007-09-23 09:43]
    R3 aliroothub;USB 2.0 Root Hub;C:\WINDOWS\system32\DRIVERS\AliRtHub.sys [2003-12-18 09:45]
    R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS [2005-03-22 19:36]
    R3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS [2005-01-06 15:55]
    S2 BT848;WinFast TV2000 XP WDM Video Capture;C:\WINDOWS\system32\drivers\wf2kvcap.sys [2004-10-04 11:34]
    S2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;C:\WINDOWS\system32\drivers\wf2ktunr.sys [2004-10-04 11:34]
    S2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;C:\WINDOWS\system32\drivers\wf2kxbar.sys [2004-10-04 11:34]
    S3 DSDrv4;DSDrv4;C:\PROGRA~1\DScaler\DSDrv4.sys [2005-10-19 18:43]
    S3 PortTalk;PortTalk;C:\WINDOWS\system32\Drivers\PortTalk.sys [2002-01-12 15:30]
    S3 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2007-12-28 20:54]
    S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]

    *Newly Created Service* - SASDIFSV
    *Newly Created Service* - SASENUM
    *Newly Created Service* - SASKUTIL
    .
    Contents of the 'Scheduled Tasks' folder
    "2007-12-28 16:29:03 C:\WINDOWS\Tasks\1-Click Maintenance.job"
    - C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
    .
    **************************************************************************

    catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-28 22:18:22
    Windows 5.1.2600 Dodatek Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-12-28 22:18:56
    .
    2007-12-22 02:01:15 --- E O F ---


    Cytat:
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 12/28/2007 at 10:12 PM

    Application Version : 3.9.1008

    Core Rules Database Version : 3369
    Trace Rules Database Version: 1365

    Scan type : Quick Scan
    Total Scan Time : 00:20:01

    Memory items scanned : 647
    Memory threats detected : 0
    Registry items scanned : 787
    Registry threats detected : 0
    File items scanned : 17118
    File threats detected : 16

    Adware.Tracking Cookie
    C:\Documents and Settings\Kamil\Cookies\kamil@adbrite[1].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@serving-sys[2].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@sale.trustedantivirus[1].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@454-OS[3].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@www.multimediabox[2].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@ad.adocean[2].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@protect.trustedantivirus[2].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@trustedantivirus[2].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@bs.serving-sys[1].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@gomyhit[2].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@454-OS[2].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@ads.adbrite[1].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@hit.stat[2].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@flixbanner.bearshare[1].txt
    C:\Documents and Settings\Kamil\Cookies\kamil@adserver.o2[1].txt

    Trojan.Downloader-DNSDoor
    C:\WINDOWS\HTTPSBINTCP.EXE
  • #8 4634274
    Kolobos
    Spec od komputerów
    Posty: 85179
    Pomógł: 17172
    Ocena: 10457
    Nie zrobiles tego co Ci napisalem. Miales utworzyc plik CFscript.txt z zawartoscia, ktora podalem i przeciagnac na combofix.exe
  • #9 4634353
    zonkil
    Poziom 31  
    Posty: 2623
    Pomógł: 77
    Ocena: 346
    Cytat:
    ComboFix 07-12-21.4 - Kamil 2007-12-28 23:06:56.5 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.91 [GMT 1:00]
    Running from: C:\Documents and Settings\Kamil\Pulpit\ComboFix.exe
    Command switches used :: C:\Documents and Settings\Kamil\Pulpit\CFScript.txt
    * Created a new restore point

    FILE
    C:\WINDOWS\fvkwdrt.exe
    C:\WINDOWS\HTTPSBINTCP.EXE
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\fvkwdrt.exe
    C:\WINDOWS\HTTPSBINTCP.EXE

    .
    ((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-28 )))))))))))))))))))))))))))))))
    .

    2007-12-28 22:24 . 2007-12-28 22:24 250 --a------ C:\WINDOWS\gmer.ini
    2007-12-28 21:50 . 2007-12-28 22:19 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2007-12-28 21:50 . 2007-12-28 21:50 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\SUPERAntiSpyware.com
    2007-12-28 21:50 . 2007-12-28 21:50 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\SUPERAntiSpyware.com
    2007-12-28 21:14 . 2007-12-28 21:14 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Grisoft
    2007-12-28 21:10 . 2007-12-28 21:11 <DIR> d-------- C:\Program Files\RogueRemover FREE
    2007-12-28 21:06 . 2007-12-28 21:06 <DIR> d-------- C:\Program Files\Trend Micro
    2007-12-28 20:54 . 2007-12-28 20:54 10,624 --a------ C:\WINDOWS\system32\drivers\pxark.sys
    2007-12-28 20:53 . 2007-12-28 21:21 <DIR> d-------- C:\Program Files\PrevxCSI
    2007-12-28 20:44 . 2007-12-28 20:54 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\PrevxCSI
    2007-12-28 20:44 . 2007-12-28 20:44 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Prevx
    2007-12-28 14:49 . 2007-12-28 14:49 0 --a------ C:\WINDOWS\mtstack16.INI
    2007-12-28 12:35 . 2007-12-28 12:39 <DIR> d-------- C:\Program Files\SkanerOnline
    2007-12-27 21:21 . 2007-12-27 21:21 7,168 --ahs---- C:\WINDOWS\Thumbs.db
    2007-12-27 18:36 . 2007-12-28 12:58 2,888 --a------ C:\WINDOWS\system32\tmp.reg
    2007-12-27 18:35 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
    2007-12-27 18:35 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
    2007-12-27 18:35 . 2007-12-20 23:11 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
    2007-12-27 18:35 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
    2007-12-27 18:35 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
    2007-12-27 18:35 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
    2007-12-27 10:49 . 2007-12-27 10:51 <DIR> d-------- C:\Program Files\GraphCalc
    2007-12-27 10:24 . 2007-12-28 21:11 <DIR> d-------- C:\Program Files\Advanced Grapher
    2007-12-27 10:08 . 2007-12-27 10:08 85 --a------ C:\WINDOWS\wininit.ini
    2007-12-27 09:19 . 2007-12-28 21:20 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
    2007-12-26 20:27 . 2007-12-26 20:27 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
    2007-12-22 19:20 . 2007-12-22 19:20 <DIR> d-------- C:\WINDOWS\system32\recover
    2007-12-20 14:48 . 2007-12-20 14:48 3,120 --------- C:\WINDOWS\.lfa
    2007-12-12 22:37 . 2007-12-27 21:21 <DIR> d-------- C:\Program Files\LimeWire
    2007-12-12 22:37 . 2007-12-12 22:37 <DIR> d-------- C:\Documents and Settings\Kamil\Incomplete
    2007-12-12 22:37 . 2007-12-26 08:22 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\LimeWire
    2007-12-10 19:21 . 2007-12-10 19:21 <DIR> d-------- C:\Program Files\Intel
    2007-12-10 19:21 . 2007-12-10 19:21 <DIR> d-------- C:\Documents and Settings\Kamil\Dane aplikacji\InstallShield
    2007-12-10 19:11 . 2007-12-22 19:21 <DIR> d-------- C:\Program Files\nLite
    2007-12-10 18:58 . 2007-12-10 18:58 <DIR> d-------- C:\Program Files\MagicISO
    2007-12-10 18:50 . 2007-12-10 18:50 <DIR> d-------- C:\F6 Floppy Utility
    2007-12-06 15:48 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
    2007-12-06 15:48 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
    2007-12-06 15:48 . 2007-12-06 15:48 395 --a------ C:\WINDOWS\BRWMARK.INI
    2007-12-06 15:48 . 2007-12-06 15:48 34 --a------ C:\WINDOWS\system32\BD2030.DAT
    2007-12-06 15:37 . 2007-12-06 15:37 <DIR> d-------- C:\Program Files\Brownie
    2007-12-06 15:29 . 2007-12-06 15:36 <DIR> d-------- C:\Program Files\Brother
    2007-12-06 15:29 . 2004-11-18 01:25 188,416 --------- C:\WINDOWS\system32\Pdrvinst.dll
    2007-12-06 15:29 . 2003-12-12 09:37 86,016 --------- C:\WINDOWS\system32\BrWebIns.dll
    2007-12-06 15:29 . 2003-07-03 01:08 65,536 --------- C:\WINDOWS\system32\BRWEBUP.EXE
    2007-12-05 22:37 . 2007-12-05 22:37 <DIR> d-------- C:\Program Files\wxMaxima
    2007-12-05 22:29 . 2007-12-05 22:30 <DIR> d-------- C:\Program Files\Maxima-5.13.0
    2007-12-03 21:00 . 2007-12-03 21:01 <DIR> d-------- C:\Nowy folder
    2007-12-02 11:04 . 2007-12-02 11:04 <DIR> d--hs---- C:\WINDOWS\ftpcache
    2007-12-02 11:04 . 2007-12-02 11:04 <DIR> d-------- C:\Program Files\PHP Expert Editor 4.2
    2007-12-02 10:45 . 2007-12-02 10:54 47,400 --a------ C:\WINDOWS\php.ini

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-12-28 22:05 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\uTorrent
    2007-12-28 21:40 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Tlen.pl
    2007-12-28 21:28 --------- d-----w C:\Program Files\Bandwidth Monitor Pro
    2007-12-28 20:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2007-12-28 07:40 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Skype
    2007-12-27 20:21 --------- d-----w C:\Program Files\K-Lite Codec Pack
    2007-12-27 18:58 --------- d-----w C:\Program Files\FlashGet
    2007-12-22 18:23 --------- d-----w C:\Program Files\NAPI-PROJEKT
    2007-12-22 18:22 --------- d-----w C:\Program Files\Wolfram Research
    2007-12-20 20:31 --------- d-----w C:\Program Files\Tlen.pl
    2007-12-20 13:46 --------- d-----w C:\Program Files\IncrediMail
    2007-12-14 18:04 --------- d-----w C:\Program Files\FDRLab
    2007-12-13 14:48 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
    2007-12-12 21:28 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
    2007-12-10 18:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-12-10 17:28 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\BearShare
    2007-12-06 14:29 --------- d-----w C:\Program Files\Common Files\InstallShield
    2007-12-01 17:32 --------- d-----w C:\Program Files\SubEdit-Player
    2007-11-24 21:53 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Participatory Culture Foundation
    2007-11-20 20:33 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Media Player Classic
    2007-11-20 20:32 --------- d-----w C:\Program Files\Real Alternative
    2007-11-20 20:32 --------- d-----w C:\Program Files\Media Player Classic
    2007-11-20 20:20 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\OpenOfficeT72
    2007-11-19 20:27 20,747 ------w C:\WINDOWS\system32\drivers\AegisP.sys
    2007-11-19 20:27 --------- d-----w C:\Program Files\RALINK
    2007-11-13 10:25 20,480 ------w C:\WINDOWS\system32\drivers\secdrv.sys
    2007-11-11 22:15 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\MfcEmbed
    2007-11-11 22:13 --------- d-----w C:\Program Files\OpenOfficeT7 2.3
    2007-11-03 07:22 --------- d-----w C:\Program Files\Toribash-3.04
    2007-11-02 16:23 --------- d-----w C:\Program Files\YouTube Video Downloader
    2007-11-02 15:01 --------- d-----w C:\Program Files\IrfanView
    2007-11-02 13:32 --------- d-----w C:\Documents and Settings\Kamil\Dane aplikacji\Logitech
    2007-11-02 09:54 --------- d-----w C:\Program Files\Logitech
    2007-11-02 09:53 --------- d-----w C:\Program Files\Common Files\Logitech
    2007-10-29 22:44 1,291,264 ------w C:\WINDOWS\system32\quartz.dll
    2007-10-29 19:59 --------- d-----w C:\Program Files\DC++
    2007-10-25 08:28 222,720 ------w C:\WINDOWS\system32\wmasf.dll
    2007-10-12 14:10 13,312 ----a-w C:\WINDOWS\buninst.exe
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Uchwyt nakładania ikony podpisu cyfrowego]
    @={36A21736-36C2-4C11-8ACB-D4136F2B57BD}

    [HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
    2004-07-01 22:12 136312 --------- C:\WINDOWS\system32\AcSignIcon.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Bandwidth Monitor Pro"="C:\PROGRA~1\BANDWI~1\Bandwidth Monitor Pro.exe" [2005-02-09 19:32]
    "IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-12-20 14:48]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:44]
    "LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-11-02 12:37]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMan"="SOUNDMAN.EXE" [2004-07-27 16:01 C:\WINDOWS\SOUNDMAN.EXE]
    "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-12 19:18]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50]
    "Acrobat Assistant 7.0"="D:\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 01:12]
    "GrooveMonitor"="D:\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47]
    "ULiRaid"="C:\Program Files\ULiRaid\ULiRaid.exe" [2006-05-12 12:57]
    "NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
    "nwiz"="nwiz.exe" [2006-10-22 11:22 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
    "DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-11-22 16:38]
    "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10]
    "PowerS"="C:\WINDOWS\PowerS.exe" [2001-08-03 16:56]
    "WinFast Schedule"="C:\Program Files\WinFast\WFTVFM\WFWIZ.exe" [2007-05-22 09:14]
    "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 14:46 C:\WINDOWS\KHALMNPR.Exe]
    "PrevxCSI"="C:\Program Files\PrevxCSI\prevxcsi.exe" []

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:44]
    "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 09:17]

    C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
    Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-09-09 11:53:31]
    Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-02 12:37:24]
    Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-02 10:53:08]
    Microsoft Office.lnk - D:\office\Office10\OSA.EXE [2001-02-13 09:01:04]
    Przyspieszenie uruchomienia programu AutoCAD.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2004-07-01 22:10:06]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSharedDocuments"= 1 (0x1)
    "ForceClassicControlPanel"= 1 (0x1)
    "NoSMConfigurePrograms"= 1 (0x1)
    "NoRecentDocsMenu"= 1 (0x1)
    "NoChangeKeyboardNavigationIndicators"= 0 (0x0)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Ralink Wireless Utility.lnk]
    path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Ralink Wireless Utility.lnk
    backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    C:\WINDOWS\system32\dumprep 0 -k

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProxyWay]
    C:\Program Files\ProxyWay\proxyway.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2007-09-25 00:11 132496 --a------ C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

    R0 avgntmgr;avgntmgr;C:\WINDOWS\system32\DRIVERS\avgntmgr.sys [2007-09-06 14:34]
    R0 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys [2005-07-04 13:21]
    R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys [2005-05-03 16:31]
    R1 avgntdd;avgntdd;C:\WINDOWS\system32\DRIVERS\avgntdd.sys [2007-09-06 14:34]
    R2 ALIEHCD;ALi PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ALIEHCI.sys [2003-12-18 19:56]
    R2 HOSTNT;Hostnt;C:\WINDOWS\system32\drivers\hostnt.sys [2007-09-23 09:43]
    R2 MHDRV;Mhdrv;C:\WINDOWS\system32\drivers\mhdrv.sys [2007-09-23 09:43]
    R2 RCMHDOG;RCMHDOG;C:\WINDOWS\system32\drivers\rcmhdog.sys [2007-09-23 09:43]
    R3 aliroothub;USB 2.0 Root Hub;C:\WINDOWS\system32\DRIVERS\AliRtHub.sys [2003-12-18 09:45]
    R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS [2005-03-22 19:36]
    R3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS [2005-01-06 15:55]
    S2 BT848;WinFast TV2000 XP WDM Video Capture;C:\WINDOWS\system32\drivers\wf2kvcap.sys [2004-10-04 11:34]
    S2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;C:\WINDOWS\system32\drivers\wf2ktunr.sys [2004-10-04 11:34]
    S2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;C:\WINDOWS\system32\drivers\wf2kxbar.sys [2004-10-04 11:34]
    S3 DSDrv4;DSDrv4;C:\PROGRA~1\DScaler\DSDrv4.sys [2005-10-19 18:43]
    S3 PortTalk;PortTalk;C:\WINDOWS\system32\Drivers\PortTalk.sys [2002-01-12 15:30]
    S3 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2007-12-28 20:54]
    S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]

    .
    Contents of the 'Scheduled Tasks' folder
    "2007-12-28 16:29:03 C:\WINDOWS\Tasks\1-Click Maintenance.job"
    - C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
    .
    **************************************************************************

    catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-28 23:08:26
    Windows 5.1.2600 Dodatek Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-12-28 23:08:58
    C:\ComboFix2.txt ... 2007-12-28 23:05
    C:\ComboFix3.txt ... 2007-12-28 22:18
    .
    2007-12-22 02:01:15 --- E O F ---
  • Pomocny post
    #10 4634592
    Kolobos
    Spec od komputerów
    Posty: 85179
    Pomógł: 17172
    Ocena: 10457
    Juz wyglada ok.
  • REKLAMA
  • #11 4742127
    ppp.j
    Poziom 12  
    Posty: 4
    Ocena: 1
    Spyware Doctor permanentnie wykrywa Tracking Cookies i podaje taki komunikat.
    Application.TrackingCookies (8infekcji)
    Plik cookie przeglądarki
    -hit.gemius.pl/hit.gemius.pl
    -m.webtrends.com/m.webtrends.com
    -tradedubler.com/tradedubler.com
    -Gtestss.hit.gemius.pl
    -Gtestb.hit.gemius.pl
    -TD_PIC.tradedubler.com
    -TD_UNIQUE_IMP.tradedubler.com
    -S4UNIQUE.stat.4u.pl
    Po usunięciu i restarcie problem powraca. Używam głównie Opery i Firefox.
    Proszę o pomoc na poziomie początkującym.

    OK. Sorry. Już zmieniam.
    Dss


    oraz Silent Runners
    Załączniki:
    • extra.txt (19.15 KB) Musisz być zalogowany, aby pobrać ten załącznik.
    • main.txt (18.62 KB) Musisz być zalogowany, aby pobrać ten załącznik.
    • Startup Programs (PAWEŁ-DOM) 2008-01-27 21.38.46.txt (23.48 KB) Musisz być zalogowany, aby pobrać ten załącznik.

Podsumowanie tematu

LABEL_AI_GENERATED
Problem dotyczy infekcji robakiem zmieniającym tapetę oraz tworzącym pliki tymczasowe (.tmp) i dane (.dat), które nie dają się usunąć w normalnym trybie Windows. Próby usunięcia za pomocą SmitfraudFix, Spybot - Search & Destroy oraz trzech skanerów antywirusowych nie przyniosły pełnego efektu. Pliki cteng_1_1_71198818691.dat i podobne zostały zidentyfikowane jako należące do programu Incredimail i nie są związane z infekcją. Zalecane jest wykonanie skanów i czyszczenia w trybie awaryjnym, użycie narzędzi ComboFix i HijackThis do identyfikacji i usunięcia złośliwych plików oraz wpisów w rejestrze, w tym usunięcie podejrzanych BHO i SSODL. Wskazano na konieczność utworzenia skryptu CFScript.txt do automatycznego usuwania plików takich jak fvkwdrt.exe i HTTPSBINTCP.EXE oraz wpisów rejestru. Po zastosowaniu tych działań i instalacji programu SUPERAntiSpyware problem został rozwiązany. Dodatkowo zasugerowano odinstalowanie Logitech Desktop Messenger, który mógł być powiązany z infekcją. W dyskusji pojawiły się także informacje o problemach z wykrywaniem Tracking Cookies przez Spyware Doctor, które po usunięciu powracały, co nie było bezpośrednio powiązane z głównym problemem robaka.
Podsumowanie AI na podstawie dyskusji. Może zawierać błędy.
REKLAMA