babo1
(Babo1)
31 Marzec 2007 15:59
#1
po ok 2 minutach od restartu systemu pojawia sie bład aplikacji services.exe lub smc.exe oba odwołują sie do procesu csrss.exe, podejrzewam ze to jakis syf wkradł sie do systemu. poniżej logi z hijack i silenta:
Logfile of HijackThis v1.99.1
Scan saved at 17:57:15, on 2007-03-31
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\MKS\Bin\NetMonSV.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MKS\Bin\mksmonsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MKS\Bin\mks_scan.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\MKS\Bin\mks_menu.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\vsnpstd3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Netia\Net\netianet.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cleanmgr.exe
C:\Documents and Settings\pc\Pulpit\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.o2.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
F2 - REG:system.ini: Shell=explorer.exe
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [ABREGMON] C:\Program Files\MKS\Bin\ABregmon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NETIANET] C:\Program Files\Netia\Net\netianet.exe
O4 - Startup: onet.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{662E2098-A1AA-4F1E-AB61-891F1BB71F19}: NameServer = 213.241.79.37 83.238.255.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{86267C0F-A2E3-41BB-AFE1-D72FE3BEE585}: NameServer = 197.204.159.1,193.110.120.5
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. - C:\Program Files\MKS\Bin\NetMonSV.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Gene6 FTP Server (G6FTPServer) - Unknown owner - C:\Program Files\Gene6 FTP Server\G6FTPSERVER.EXE (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:\Program Files\MKS\bin\MkSUpdateInt.exe
O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe
O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS\Bin\mks_scan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
“Silent Runners.vbs”, revision R50, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “ctfmon.exe” = “C:\WINDOWS\system32\ctfmon.exe” [MS] “NETIANET” = “C:\Program Files\Netia\Net\netianet.exe” [“OF.PL sp.z .o.o.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “NvCplDaemon” = “RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup” [MS] “nwiz” = “nwiz.exe /install” [“NVIDIA Corporation”] “NvMediaCenter” = “RunDLL32.exe NvMCTray.dll,NvTaskbarInit” [MS] “NeroFilterCheck” = “C:\WINDOWS\system32\NeroCheck.exe” [“Ahead Software Gmbh”] “SunJavaUpdateSched” = “C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe” [“Sun Microsystems, Inc.”] “MKS_MENU” = “C:\Program Files\MKS\Bin\mks_menu.exe” [“MKS Sp. z o.o.”] “SmcService” = “C:\PROGRA~1\Sygate\SPF\smc.exe -startgui” [“Sygate Technologies, Inc.”] “LVCOMSX” = “C:\WINDOWS\system32\LVCOMSX.EXE” [“Labtec Inc.”] “LogitechVideoRepair” = "C:\Program Files\Logitech\Video\ISStart.exe " [“Labtec Inc.”] “TkBellExe” = “C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot” [“RealNetworks, Inc.”] “ABREGMON” = “C:\Program Files\MKS\Bin\ABregmon.exe” [“ArcaBit”] “HP Software Update” = “C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [“Hewlett-Packard Co.”] “snpstd3” = “C:\WINDOWS\vsnpstd3.exe” [empty string] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {A5366673-E8CA-11D3-9CD9-0090271D075B}(Default) = (no title provided) -> {HKLM…CLSID} = “IeCatch2 Class” \InProcServer32(Default) = “C:\PROGRA~1\FlashGet\jccatch.dll” [“Amaze Soft”] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Rozszerzenie CPL kadrowania wyświetlania” -> {HKLM…CLSID} = “Rozszerzenie CPL kadrowania wyświetlania” \InProcServer32(Default) = “deskpan.dll” [file not found] “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”] “{A70C977A-BF00-412C-90B7-034C51DA2439}” = “NvCpl DesktopContext Class” -> {HKLM…CLSID} = “DesktopContext Class” \InProcServer32(Default) = “C:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”] “{FFB699E0-306A-11d3-8BD1-00104B6F7516}” = “Play on my TV helper” -> {HKLM…CLSID} = “NVIDIA CPL Extension” \InProcServer32(Default) = “C:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”] “{1CDB2949-8F65-4355-8456-263E7C208A5D}” = “Desktop Explorer” -> {HKLM…CLSID} = “Desktop Explorer” \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A47}” = “Desktop Explorer Menu” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A48}” = “nView Desktop Context Menu” -> {HKLM…CLSID} = “nView Desktop Context Menu” \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{00020D75-0000-0000-C000-000000000046}” = “Microsoft Office Outlook Desktop Icon Handler” -> {HKLM…CLSID} = “Microsoft Office Outlook” \InProcServer32(Default) = “C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL” [MS] “{0006F045-0000-0000-C000-000000000046}” = “Microsoft Office Outlook Custom Icon Handler” -> {HKLM…CLSID} = “Rozszerzenie ikon plików programu Outlook” \InProcServer32(Default) = “C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL” [MS] “{42042206-2D85-11D3-8CFF-005004838597}” = “Microsoft Office HTML Icon Handler” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Microsoft Office\OFFICE11\msohev.dll” [MS] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] “{32020A01-506E-484D-A2A8-BE3CF17601C3}” = “AlcoholShellEx” -> {HKLM…CLSID} = “AlcoholShellEx” \InProcServer32(Default) = “C:\PROGRA~1\Alcohol Soft\Alcohol 120\AXShlEx.dll” [“Alcohol Soft Development Team”] “{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}” = “Shell Extensions for RealOne Player” -> {HKLM…CLSID} = “RealOne Player Context Menu Class” \InProcServer32(Default) = “C:\Program Files\Real\RealOne Player\rpplugins\ierpplug.dll” [“RealNetworks”] “{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}” = “My Labtec Pictures” -> {HKLM…CLSID} = “My Labtec Pictures” \InProcServer32(Default) = “C:\Program Files\Logitech\Video\Namespc2.dll” [“Labtec Inc.”] “{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}” = “TuneUp Shredder Shell Context Menu Extension” -> {HKLM…CLSID} = “TuneUp Shredder Shell Context Menu Extension” \InProcServer32(Default) = ““C:\Program Files\TuneUp Utilities 2006\sdshelex.dll”” [“TuneUp Software GmbH”] HKLM\Software\Classes\PROTOCOLS\Filter\ <> text/xml\CLSID = “{807553E5-5146-11D5-A672-00B0D022E945}” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL” [MS] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ CopyPath(Default) = “{303FEFF0-6ABA-11D3-90E4-0090272D53E3}” -> {HKLM…CLSID} = “CopyPathExt Class” \InProcServer32(Default) = “C:\WINDOWS\system32\skySpaceExt_1.0.1.dll” [empty string] MkS_Vir(Default) = “{CC4245C0-D511-11D0-8918-444553540000}” -> {HKLM…CLSID} = “MkS_Vir Shell Extension” \InProcServer32(Default) = “C:\Program Files\MKS\Bin\MkSShell.dll” [null data] TuneUp Shredder(Default) = “{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}” -> {HKLM…CLSID} = “TuneUp Shredder Shell Context Menu Extension” \InProcServer32(Default) = ““C:\Program Files\TuneUp Utilities 2006\sdshelex.dll”” [“TuneUp Software GmbH”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ TuneUp Shredder(Default) = “{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}” -> {HKLM…CLSID} = “TuneUp Shredder Shell Context Menu Extension” \InProcServer32(Default) = ““C:\Program Files\TuneUp Utilities 2006\sdshelex.dll”” [“TuneUp Software GmbH”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ CopyPath(Default) = “{303FEFF0-6ABA-11D3-90E4-0090272D53E3}” -> {HKLM…CLSID} = “CopyPathExt Class” \InProcServer32(Default) = “C:\WINDOWS\system32\skySpaceExt_1.0.1.dll” [empty string] MkS_Vir(Default) = “{CC4245C0-D511-11D0-8918-444553540000}” -> {HKLM…CLSID} = “MkS_Vir Shell Extension” \InProcServer32(Default) = “C:\Program Files\MKS\Bin\MkSShell.dll” [null data] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ “NoUserNameInStartMenu” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoRecentDocsNetHood” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoLowDiskSpaceChecks” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoRecentDocsMenu” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “ForceClassicControlPanel” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoCDBurning” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoSaveSettings” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|Desktop| Don’t save settings at exit} “NoInstrumentation” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “MemCheckBoxInRunDlg” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoResolveSearch” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoResolveTrack” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “DisallowRun” = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ “NoWelcomeScreen” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoSMHelp” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoRemoteRecursiveEvents” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “NoCDBurning” = (REG_DWORD) hex:0x00000001 {unrecognized setting} “MemCheckBoxInRunDlg” = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\ “No_LaunchMediaBar” = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} “undockwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be enabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ “Wallpaper” = “C:\Moje dokumenty\Moje obrazy\100DSCIM\PICT1534.JPG” Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ “Wallpaper” = “C:\Documents and Settings\pc\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp” Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ “SCRNSAVE.EXE” = “C:\WINDOWS\system32\logon.scr” [MS] Startup items in “pc” & “All Users” startup folders: ---------------------------------------------------- C:\Documents and Settings\pc\Menu Start\Programy\Autostart “onet” -> shortcut to: “” [file not found] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart “Adobe Gamma Loader” -> shortcut to: “C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe” [“Adobe Systems, Inc.”] “HP Digital Imaging Monitor” -> shortcut to: “C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe” [“Hewlett-Packard Co.”] Enabled Scheduled Tasks: ------------------------ “1-Click Maintenance” -> launches: “C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe /schedulestart” [“TuneUp Software GmbH”] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 19 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKLM\Software\Microsoft\Internet Explorer\Toolbar\ “{E0E899AB-F487-11D5-8D29-0050BA6940E3}” = “FlashGet Bar” -> {HKLM…CLSID} = “FlashGet Bar” \InProcServer32(Default) = “C:\PROGRA~1\FlashGet\fgiebar.dll” [“Amaze Soft”] Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ HKLM\Software\Classes\CLSID{FF059E31-CC5A-4E2E-BF3B-96E929D65503}(Default) = “&Badanie” Implemented Categories{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32(Default) = “C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL” [MS] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ “MenuText” = “Sun Java Console” “CLSIDExtension” = “{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}” -> {HKLM…CLSID} = “Java Plug-in 1.5.0_01” \InProcServer32(Default) = “C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll” [“Sun Microsystems, Inc.”] {92780B25-18CC-41C8-B9BE-3C9C571A8263}\ “ButtonText” = “Badanie” {D6E814A0-E0C5-11D4-8D29-0050BA6940E3}\ “ButtonText” = “FlashGet” “MenuText” = “&FlashGet” “Exec” = “C:\PROGRA~1\FlashGet\flashget.exe” [“Amaze Soft”] Miscellaneous IE Hijack Points ------------------------------ HKLM\Software\Microsoft\Internet Explorer\AboutURLs\ <> “TuneUp” = “file://C|/Documents and Settings/All Users/Dane aplikacji/TuneUp Software/Common/base.css” [file not found] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ ArcaBit NetMonitor, ABNetMon, “C:\Program Files\MKS\Bin\NetMonSV.exe” [“ArcaBit sp. z o.o.”] C-DillaCdaC11BA, C-DillaCdaC11BA, “C:\WINDOWS\system32\drivers\CDAC11BA.EXE” [“Macrovision”] Crypkey License, Crypkey License, “crypserv.exe” [“CrypKey (Canada) Ltd.”] Machine Debug Manager, MDM, ““C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE”” [MS] MkS_Scan, MkS_Scan, “C:\Program Files\MKS\Bin\mks_scan.exe” [empty string] MkS_Vir Monitor, MksVirMonSvc, “C:\Program Files\MKS\Bin\mksmonsv.exe” [empty string] NVIDIA Display Driver Service, NVSvc, “C:\WINDOWS\system32\nvsvc32.exe” [“NVIDIA Corporation”] Office Source Engine, ose, ““C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE”” [MS] Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ EPSON V5 2KMonitor\Driver = “EBPMON2.DLL” [“SEIKO EPSON CORPORATION”] HP Standard TCP/IP Port\Driver = “HpTcpMon.dll” [“Hewlett Packard”] hpzlnt12\Driver = “hpzlnt12.dll” [“HP”] Microsoft Document Imaging Writer Monitor\Driver = “mdimon.dll” [MS] ---------- <>: Suspicious data at a malware launch point. <>: Suspicious data at a browser hijack point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points, use the -supp parameter or answer “No” at the first message box and “Yes” at the second message box. ---------- (total run time: 155 seconds, including 7 seconds for message boxes)
adam9870
(adam9870)
31 Marzec 2007 16:07
#2
Usuń wpisy HJT, pokaż log z ComboScan .
babo1
(Babo1)
31 Marzec 2007 16:55
#3
ComboScan v20070306.20 run by pc on 2007-03-31 at 18:55:42
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 5 Restore Point(s) --
45: 2005-04-09 18:15:38 UTC - RP45 - Punkt kontrolny systemu
44: 2005-04-08 17:15:35 UTC - RP44 - Punkt kontrolny systemu
43: 2005-04-07 16:15:35 UTC - RP43 - Punkt kontrolny systemu
42: 2005-04-06 16:15:11 UTC - RP42 - Punkt kontrolny systemu
41: 2005-04-05 15:09:45 UTC - RP41 - Punkt kontrolny systemu
-- First Restore Point --
1: 2005-03-05 09:36:56 UTC - RP1 - Punkt kontrolny systemu
Performed disk cleanup.
-- HijackThis (run as pc.exe) --------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 18:57:02, on 2007-03-31
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\MKS\Bin\NetMonSV.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MKS\Bin\mksmonsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MKS\Bin\mks_scan.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\MKS\Bin\mks_menu.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\vsnpstd3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Netia\Net\netianet.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\MKS\Bin\mks_upd.exe
C:\Program Files\MKS\bin\MkSUpdateInt.exe
C:\comboscan.exe
C:\DOCUME~1\pc\Pulpit\hijackthis\pc.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.o2.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [ABREGMON] C:\Program Files\MKS\Bin\ABregmon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NETIANET] C:\Program Files\Netia\Net\netianet.exe
O4 - Startup: onet.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{662E2098-A1AA-4F1E-AB61-891F1BB71F19}: NameServer = 213.241.79.37 83.238.255.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{86267C0F-A2E3-41BB-AFE1-D72FE3BEE585}: NameServer = 197.204.159.1,193.110.120.5
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. - C:\Program Files\MKS\Bin\NetMonSV.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Gene6 FTP Server (G6FTPServer) - Unknown owner - C:\Program Files\Gene6 FTP Server\G6FTPSERVER.EXE (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:\Program Files\MKS\bin\MkSUpdateInt.exe
O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe
O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS\Bin\mks_scan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
-- HijackThis Fixed Entries (C:\DOCUME~1\pc\Pulpit\hijackthis\backups\) --------
backup-20070331-184221-545 F2 - REG:system.ini: Shell=explorer.exe
backup-20070331-184221-994 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
-- File Associations -----------------------------------------------------------
.bat - batfile - "%1" %*
.chm - chm.file - "C:\WINDOWS\hh.exe" %1
.cmd - cmdfile - "%1" %*
.com - comfile - "%1" %*
.exe - exefile - "%1" %*
.hlp - hlpfile - %SystemRoot%\System32\winhlp32.exe %1
.inf - inffile - %SystemRoot%\System32\NOTEPAD.EXE %1
.ini - inifile - %SystemRoot%\System32\NOTEPAD.EXE %1
.js - JSFile - %SystemRoot%\System32\WScript.exe "%1" %*
.lnk - lnkfile - {00021401-0000-0000-C000-000000000046}
.pif - piffile - "%1" %*
.reg - regfile - regedit.exe "%1"
.scr - scrfile - "%1" /S
.txt - txtfile - %SystemRoot%\system32\NOTEPAD.EXE %1
.vbs - VBSFile - %SystemRoot%\System32\WScript.exe "%1" %*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
0R a347bus - C:\WINDOWS\system32\drivers\a347bus.sys
0R a347scsi - C:\WINDOWS\system32\drivers\a347scsi.sys
1R ABTDI - C:\Program Files\MKS\Bin\abtdi.sys
2S ADILOADER (General Purpose USB Driver (adildr.sys)) - C:\WINDOWS\system32\drivers\adildr.sys
3R adiusbaw (USB ADSL WAN Adapter) - C:\WINDOWS\system32\drivers\adiusbaw.sys
3R ALCXWDM (Service for Realtek AC97 Audio (WDM)) - C:\WINDOWS\system32\drivers\ALCXWDM.SYS
1R AmdK7 (Sterownik procesora AMD K7) - C:\WINDOWS\system32\drivers\amdk7.sys
3R basic2 - C:\WINDOWS\system32\drivers\HSF_BSC2.sys
3S CCDECODE (Dekoder napisów) - C:\WINDOWS\system32\drivers\CCDECODE.sys
2R CdaC15BA - C:\WINDOWS\system32\drivers\CdaC15BA.SYS
2R Fallback - C:\WINDOWS\system32\drivers\HSF_FALL.sys
2R Fsks - C:\WINDOWS\system32\drivers\HSF_FSKS.sys
3S hamachi (Hamachi Network Interface) - C:\WINDOWS\system32\drivers\hamachi.sys
3S HidUsb (Sterownik Microsoft klasy HID) - C:\WINDOWS\system32\drivers\hidusb.sys
3S HPZid412 (IEEE-1284.4 Driver HPZid412) - C:\WINDOWS\system32\drivers\HPZid412.sys
3S HPZipr12 (Print Class Driver for IEEE-1284.4 HPZipr12) - C:\WINDOWS\system32\drivers\HPZipr12.sys
3S HPZius12 (USB to IEEE-1284.4 Translation Driver HPZius12) - C:\WINDOWS\system32\drivers\HPZius12.sys
3R hsf_msft - C:\WINDOWS\system32\drivers\HSF_MSFT.sys
2R K56 - C:\WINDOWS\system32\drivers\HSF_K56K.sys
4S Kbdpm39 - C:\WINDOWS\system32\drivers\HSF_BSC2.sys
3R LVUSBSta (Logitech USB Monitor Filter) - C:\WINDOWS\system32\drivers\LVUSBSta.sys
3S MksMonEn (MkS_Mon Kernel Engine) - C:\Program Files\MKS\Bin\mksmonen.sys
3S MksMonEv (MkS_Mon Kernel Events) - C:\Program Files\MKS\Bin\mksmonev.sys
3R MksMonFd (MkS_Mon Kernel Filter Driver) - C:\Program Files\MKS\Bin\mksmonfd.sys
3R MODEMCSA (Urządzenie filtru strumieniowego usługi Unimodem) - C:\WINDOWS\system32\drivers\MODEMCSA.sys
3S mouhid (Sterownik myszy HID) - C:\WINDOWS\system32\drivers\mouhid.sys
3S MSTEE (Konwerter strumieni Tee/Sink-to-Sink Microsoft Streaming) - C:\WINDOWS\system32\drivers\MSTEE.sys
2S MZU_RK - C:\WINDOWS\system32\MZU_DRV.sys
3S NABTSFEC (Koder-dekoder NABTS/FEC VBI) - C:\WINDOWS\system32\drivers\NABTSFEC.sys
3S NdisIP (Połączenie TV/wideo firmy Microsoft) - C:\WINDOWS\system32\drivers\NdisIP.sys
1R NetworkX - C:\WINDOWS\system32\Ckldrv.sys
3S ntportio - C:\DOCUME~1\pc\USTAWI~1\Temp\u\1140249648\ntportio.sys (not found)
3R nv - C:\WINDOWS\system32\drivers\nv4_mini.sys
3R pfc (Padus ASPI Shell) - C:\WINDOWS\system32\drivers\pfc.sys
3R PID_0928 (Labtec WebCam(PID_0928)) - C:\WINDOWS\system32\drivers\LV561AV.SYS
0R PxHelp20 - C:\WINDOWS\system32\drivers\pxhelp20.sys
3R Rksample - C:\WINDOWS\system32\drivers\HSF_SAMP.sys
3R rtl8139 (Realtek RTL8139/810X Family PCI Fast Ethernet NIC NT Driver) - C:\WINDOWS\system32\drivers\RTL8139.sys
3S Ser2pl (Prolific2 Serial port driver) - C:\WINDOWS\system32\drivers\ser2pl.sys
3S SLIP (BDA Slip De-Framer) - C:\WINDOWS\system32\drivers\SLIP.sys
3S SNPSTD3 (USB PC Camera (SNPSTD3)) - C:\WINDOWS\system32\drivers\snpstd3.sys
2R SoftFax - C:\WINDOWS\system32\drivers\HSF_FAXX.sys
3S SONYPVU1 (Sterownik filtru USB Sony (SONYPVU1)) - C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2R SpeakerPhone - C:\WINDOWS\system32\drivers\HSF_SPKP.sys
3S streamip (BDA IPSink) - C:\WINDOWS\system32\drivers\StreamIP.sys
0R Teefer (Teefer for NT) - C:\WINDOWS\system32\drivers\Teefer.sys
0R tffsport (M-Systems DiskOnChip 2000) - C:\WINDOWS\system32\drivers\tffsport.sys
2R Tones - C:\WINDOWS\system32\drivers\HSF_TONE.sys
0R uagp35 (Filtr AGPv3.5 firmy Microsoft) - C:\WINDOWS\system32\drivers\UAGP35.SYS
3S usbccgp (Rodzajowy sterownik nadrzędny USB Microsoft) - C:\WINDOWS\system32\drivers\usbccgp.sys
3R usbehci (Sterownik Miniport rozszerzonego kontrolera hosta USB 2.0 Microsoft) - C:\WINDOWS\system32\drivers\usbehci.sys
3S usbprint (Klasa PRINTER USB Microsoft) - C:\WINDOWS\system32\drivers\usbprint.sys
3S usbscan (Sterownik skanera USB) - C:\WINDOWS\system32\drivers\usbscan.sys
3S usbsermpt (Motorola USB Modem Driver for MPT) - C:\WINDOWS\system32\drivers\usbsermpt.sys
3S USBSTOR (Sterownik magazynu masowego USB) - C:\WINDOWS\system32\drivers\USBSTOR.SYS
2R V124 - C:\WINDOWS\system32\drivers\HSF_V124.sys
0R viaagp1 (VIA AGP Filter) - C:\WINDOWS\system32\drivers\VIAAGP1.SYS
3S VIAudio (VIA AC'97 Audio Controller (WDM)) - C:\WINDOWS\system32\drivers\viaudio.sys
2R wg3n (SyGate for NT, wg3n) - C:\WINDOWS\system32\drivers\wg3n.sys
1R wpsdrvnt - C:\WINDOWS\system32\drivers\wpsdrvnt.sys
3S WSTCODEC (Kodery-dekodery teletekstu w standardzie światowym) - C:\WINDOWS\system32\drivers\WSTCODEC.SYS
1R XPROTECTOR - C:\WINDOWS\system32\drivers\Oreans.sys
[COLOR=red][B]pe386 driver present[/B][/COLOR]
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
2R ABNetMon (ArcaBit NetMonitor) - C:\Program Files\MKS\Bin\NetMonSV.exe
3S aspnet_state (ASP.NET State Service) - C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
2R C-DillaCdaC11BA - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
2R Crypkey License - crypserv.exe
2S G6FTPServer (Gene6 FTP Server) - "C:\Program Files\Gene6 FTP Server\G6FTPSERVER.EXE"
3S IDriverT (InstallDriver Table Manager) - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
3R MkSUpdateInt - C:\Program Files\MKS\bin\MkSUpdateInt.exe
2R MksVirMonSvc (MkS_Vir Monitor) - C:\Program Files\MKS\Bin\mksmonsv.exe
3R MkS_Scan - C:\Program Files\MKS\Bin\mks_scan.exe
2R NVSvc (NVIDIA Display Driver Service) - C:\WINDOWS\system32\nvsvc32.exe
3S ose (Office Source Engine) - "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
2S Pml Driver HPZ12 - C:\WINDOWS\system32\HPZipm12.exe
2S SmcService (Sygate Personal Firewall Pro) - C:\Program Files\Sygate\SPF\smc.exe
3S TUWinStylerThemeSvc (TuneUp WinStyler Theme Service) - "C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe"
-- Scheduled Tasks -------------------------------------------------------------
2007-03-30 17:15:00 384 --a------ C:\WINDOWS\Tasks\1-Click Maintenance.job
-- Files created between 2007-02-28 and 2007-03-31 -----------------------------
2007-03-31 18:55:38 456344 --a------ C:\comboscan.exe
2007-03-22 23:51:02 0 d-------- C:\Program Files\Niezbędnik Internauty
2007-03-17 15:01:57 0 d-------- C:\Program Files\Netia
2007-03-12 23:31:23 38160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2007-03-12 23:31:18 182032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2007-03-12 23:31:05 63488 --a------ C:\WINDOWS\system32\unam4ie.exe
2007-03-12 23:30:57 10240 --a------ C:\WINDOWS\system32\vidx16.dll
2007-03-12 23:30:55 194320 --a------ C:\WINDOWS\system32\qcut.dll
2007-03-12 23:30:50 4608 --a------ C:\WINDOWS\system32\w95inf32.dll
2007-03-12 23:30:49 2272 --a------ C:\WINDOWS\system32\w95inf16.dll
2007-03-12 23:30:08 89088 --a------ C:\WINDOWS\system32\Zlib.dll
2007-03-12 23:30:07 909824 --a------ C:\WINDOWS\system32\cp3245mt.dll
2007-03-12 23:30:07 24064 --a------ C:\WINDOWS\system32\borlndmm.dll
2007-03-12 23:30:04 0 d-------- C:\Program Files\Reflex
2007-03-12 23:29:48 0 d-------- C:\WINDOWS\speech
2007-03-12 23:29:32 46592 --a------ C:\WINDOWS\system32\shellses.dll
2007-03-12 23:29:32 400896 --a------ C:\WINDOWS\system32\setresuk.dll
2007-03-12 23:29:31 22528 --a------ C:\WINDOWS\system32\rhmmplay.dll
2007-03-12 23:29:31 16896 --a------ C:\WINDOWS\system32\ibmwave.exe
2007-03-12 23:28:49 0 d-------- C:\ViaVoice
2007-03-12 23:27:54 245520 --a------ C:\WINDOWS\system32\MSRD2X32.DLL
2007-03-12 23:27:53 965904 --a------ C:\WINDOWS\system32\msjt3032.dll
-- Find3M Report ---------------------------------------------------------------
2007-03-31 17:16:04 0 d-------- C:\Program Files\Mozilla Firefox
2007-03-26 18:31:14 439194 --a------ C:\WINDOWS\system32\perfh015.dat
2007-03-26 18:31:14 68334 --a------ C:\WINDOWS\system32\perfc015.dat
2007-03-26 18:25:27 0 d-------- C:\Documents and Settings\pc\Dane aplikacji\Azureus
2007-03-26 18:17:46 0 d-------- C:\Documents and Settings\pc\Dane aplikacji\Skype
2007-03-12 23:30:16 0 d-------- C:\Program Files\Common Files\YDP
2007-02-26 00:12:36 0 d-------- C:\Program Files\Elfin
2007-02-26 00:06:34 86651 --a------ C:\Uninstal.exe
2007-02-26 00:01:18 0 d-------- C:\Documents and Settings\pc\Dane aplikacji\Adobe
2007-02-19 00:05:43 0 d-------- C:\Documents and Settings\pc\Dane aplikacji\Identities
2007-02-12 23:15:50 0 d-------- C:\Program Files\DITel
2007-02-03 00:17:00 0 d-------- C:\Program Files\FlashGet
2007-01-15 19:25:27 113548 --a------ C:\WINDOWS\hpoins07.dat
-- Registry Dump ---------------------------------------------------------------
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"NETIANET"="C:\\Program Files\\Netia\\Net\\netianet.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RunDLL32.exe NvMCTray.dll,NvTaskbarInit"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe"
"MKS_MENU"="C:\\Program Files\\MKS\\Bin\\mks_menu.exe"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"TkBellExe"="C:\\Program Files\\Common Files\\Real\\Update_OB\\evntsvc.exe -osboot"
"ABREGMON"="C:\\Program Files\\MKS\\Bin\\ABregmon.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"snpstd3"="C:\\WINDOWS\\vsnpstd3.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Skype"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"inimapping"="0"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"NETIANET"="C:\\Program Files\\Netia\\Net\\netianet.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"NETIANET"="C:\\Program Files\\Netia\\Net\\netianet.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"=dword:00000001
"NoSMHelp"=dword:00000001
"NoRemoteRecursiveEvents"=dword:00000001
"NoCDBurning"=dword:00000001
"MemCheckBoxInRunDlg"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"=dword:00000005
"NoUserNameInStartMenu"=dword:00000001
"NoRecentDocsNetHood"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001
"NoRecentDocsMenu"=dword:00000001
"ForceClassicControlPanel"=dword:00000001
"NoCDBurning"=dword:00000001
"NoSaveSettings"=dword:00000000
"NoInstrumentation"=dword:00000001
"MemCheckBoxInRunDlg"=dword:00000001
"NoResolveSearch"=dword:00000001
"NoResolveTrack"=dword:00000001
"DisallowRun"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\DisallowRun]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I]
Shell\AutoRun\command I:\autorun.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J]
Shell\AutoRun\command J:\Setup.exe
-- End of ComboScan: finished at 2007-03-31 at 18:58:11 ------------------------
adam9870
(adam9870)
31 Marzec 2007 19:18
#4
Są rootkity:
Otwórz Notatnik i wklej w nim to:
Plik >>> Zapisz jako >>> Zmień rozszerzenie z TXT na Wszystkie pliki >>> Zapisz pod nazwą FIX.BAT
Pobierz Gmer’a .
Teraz czynności będziesz wykonywał w Gmerze więc uruchom go, poczekaj chwilkę, kliknij na zakładkę >>> w celu otworzenia pozostałych.
W zakładce Procesy wybierz Gmer awaryjny >>> komputer się zrestartuje i zostanie samo okienko Gmer’a >>> w zakładce Procesy wskaż przez … (trzy kropki) plik FIX.BAT >>> przez chwilkę mignie ekran i reset.
Użyj narzędzia Rustock.b-fix .
Po wykonaniu wklej log z ComboFix plus dwa logi z Gmer’a wykonane przy takich ustawieniach:
Zakładka Rootkit >>> zaznaczone wszystko oprócz Pokazuj wszystko >>> kliknij Szukaj >>> czekaj cierpliwie aż skończy >>> Kopiuj >>> wklej do posta
Zakładka Rootkit >>> zaznaczone tylko Usługi i Pokazuj wszystko >>> kliknij Szukaj >>> czekaj cierpliwie aż skończy >>> Kopiuj >>> wklej do posta
Jeśli wszystkie logi nie zmieszczą się bezpośrednio do posta, to umieść je w jakimś serwisie hostingowym jako pliki *.txt, a tu tylko zlinkuj.
babo1
(Babo1)
1 Kwiecień 2007 13:38
#5
Bład wyskakuje nadal głwonie bład aplikacji smc.exe podczas wykonywania w trybie awaryjnym gmer zgłosił błedne parametry. oto logi które mialem wkleić.
ComboScan v20070306.20 run by pc on 2007-04-01 at 15:26:19
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as pc.exe) --------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 15:27:03, on 2007-04-01
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\MKS\Bin\NetMonSV.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MKS\Bin\mksmonsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MKS\Bin\mks_scan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\MKS\Bin\mks_menu.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\vsnpstd3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netia\Net\netianet.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\gmer\gmer.exe
C:\comboscan.exe
C:\DOCUME~1\pc\Pulpit\hijackthis\pc.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.o2.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [ABREGMON] C:\Program Files\MKS\Bin\ABregmon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NETIANET] C:\Program Files\Netia\Net\netianet.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{86267C0F-A2E3-41BB-AFE1-D72FE3BEE585}: NameServer = 197.204.159.1,193.110.120.5
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. - C:\Program Files\MKS\Bin\NetMonSV.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Gene6 FTP Server (G6FTPServer) - Unknown owner - C:\Program Files\Gene6 FTP Server\G6FTPSERVER.EXE (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:\Program Files\MKS\bin\MkSUpdateInt.exe
O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe
O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS\Bin\mks_scan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
-- Files created between 2007-03-01 and 2007-04-01 -----------------------------
2007-04-01 11:19:53 0 d-------- C:\Rustbfix
2007-04-01 10:59:13 0 d-------- C:\gmer
2007-04-01 10:53:35 80 --a------ C:\WINDOWS\gmer_uninstall.cmd
2007-04-01 10:37:21 342 --a------ C:\fix.bat
2007-03-31 18:55:38 456344 --a------ C:\comboscan.exe
2007-03-22 23:51:02 0 d-------- C:\Program Files\Niezbędnik Internauty
2007-03-17 15:01:57 0 d-------- C:\Program Files\Netia
2007-03-12 23:31:23 38160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2007-03-12 23:31:18 182032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2007-03-12 23:31:05 63488 --a------ C:\WINDOWS\system32\unam4ie.exe
2007-03-12 23:30:57 10240 --a------ C:\WINDOWS\system32\vidx16.dll
2007-03-12 23:30:55 194320 --a------ C:\WINDOWS\system32\qcut.dll
2007-03-12 23:30:50 4608 --a------ C:\WINDOWS\system32\w95inf32.dll
2007-03-12 23:30:49 2272 --a------ C:\WINDOWS\system32\w95inf16.dll
2007-03-12 23:30:08 89088 --a------ C:\WINDOWS\system32\Zlib.dll
2007-03-12 23:30:07 909824 --a------ C:\WINDOWS\system32\cp3245mt.dll
2007-03-12 23:30:07 24064 --a------ C:\WINDOWS\system32\borlndmm.dll
2007-03-12 23:30:04 0 d-------- C:\Program Files\Reflex
2007-03-12 23:29:48 0 d-------- C:\WINDOWS\speech
2007-03-12 23:29:32 46592 --a------ C:\WINDOWS\system32\shellses.dll
2007-03-12 23:29:32 400896 --a------ C:\WINDOWS\system32\setresuk.dll
2007-03-12 23:29:31 22528 --a------ C:\WINDOWS\system32\rhmmplay.dll
2007-03-12 23:29:31 16896 --a------ C:\WINDOWS\system32\ibmwave.exe
2007-03-12 23:28:49 0 d-------- C:\ViaVoice
2007-03-12 23:27:54 245520 --a------ C:\WINDOWS\system32\MSRD2X32.DLL
2007-03-12 23:27:53 965904 --a------ C:\WINDOWS\system32\msjt3032.dll
-- Find3M Report ---------------------------------------------------------------
2007-04-01 12:41:44 0 d-------- C:\Program Files\Mozilla Firefox
2007-03-26 18:31:14 439194 --a------ C:\WINDOWS\system32\perfh015.dat
2007-03-26 18:31:14 68334 --a------ C:\WINDOWS\system32\perfc015.dat
2007-03-26 18:25:27 0 d-------- C:\Documents and Settings\pc\Dane aplikacji\Azureus
2007-03-26 18:17:46 0 d-------- C:\Documents and Settings\pc\Dane aplikacji\Skype
2007-03-12 23:30:16 0 d-------- C:\Program Files\Common Files\YDP
2007-02-26 00:12:36 0 d-------- C:\Program Files\Elfin
2007-02-26 00:06:34 86651 --a------ C:\Uninstal.exe
2007-02-26 00:01:18 0 d-------- C:\Documents and Settings\pc\Dane aplikacji\Adobe
2007-02-19 00:05:43 0 d-------- C:\Documents and Settings\pc\Dane aplikacji\Identities
2007-02-12 23:15:50 0 d-------- C:\Program Files\DITel
2007-02-03 00:17:00 0 d-------- C:\Program Files\FlashGet
2007-01-15 19:25:27 113548 --a------ C:\WINDOWS\hpoins07.dat
-- Registry Dump ---------------------------------------------------------------
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"NETIANET"="C:\\Program Files\\Netia\\Net\\netianet.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RunDLL32.exe NvMCTray.dll,NvTaskbarInit"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe"
"MKS_MENU"="C:\\Program Files\\MKS\\Bin\\mks_menu.exe"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"TkBellExe"="C:\\Program Files\\Common Files\\Real\\Update_OB\\evntsvc.exe -osboot"
"ABREGMON"="C:\\Program Files\\MKS\\Bin\\ABregmon.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"snpstd3"="C:\\WINDOWS\\vsnpstd3.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Skype"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"inimapping"="0"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"NETIANET"="C:\\Program Files\\Netia\\Net\\netianet.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"NETIANET"="C:\\Program Files\\Netia\\Net\\netianet.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"=dword:00000001
"NoSMHelp"=dword:00000001
"NoRemoteRecursiveEvents"=dword:00000001
"NoCDBurning"=dword:00000001
"MemCheckBoxInRunDlg"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"=dword:00000005
"NoUserNameInStartMenu"=dword:00000001
"NoRecentDocsNetHood"=dword:00000001
"NoLowDiskSpaceChecks"=dword:00000001
"NoRecentDocsMenu"=dword:00000001
"ForceClassicControlPanel"=dword:00000001
"NoCDBurning"=dword:00000001
"NoSaveSettings"=dword:00000000
"NoInstrumentation"=dword:00000001
"MemCheckBoxInRunDlg"=dword:00000001
"NoResolveSearch"=dword:00000001
"NoResolveTrack"=dword:00000001
"DisallowRun"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\DisallowRun]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I]
Shell\AutoRun\command I:\autorun.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J]
Shell\AutoRun\command J:\Setup.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7e5f2a83-8d5d-11d9-bdcf-806d6172696f}]
Shell\AutoRun\command E:\SETUP.EXE
Shell\configure\command E:\SETUP.EXE
Shell\install\command E:\SETUP.EXE
-- End of ComboScan: finished at 2007-04-01 at 15:27:41 ------------------------
Złączono Posta : 01.04.2007 (Nie) 15:39
GMER 1.0.12.12086 - http://www.gmer.net Rootkit scan 2007-04-01 15:20:17 Windows 5.1.2600 Dodatek Service Pack 2 ---- System - GMER 1.0.12 ---- SSDT a347bus.sys ZwClose SSDT a347bus.sys ZwCreateKey SSDT a347bus.sys ZwCreatePagingFile SSDT ??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwCreateThread SSDT a347bus.sys ZwEnumerateKey SSDT a347bus.sys ZwEnumerateValueKey SSDT ??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwMapViewOfSection SSDT a347bus.sys ZwOpenKey SSDT a347bus.sys ZwQueryKey SSDT a347bus.sys ZwQueryValueKey SSDT a347bus.sys ZwSetSystemPowerState SSDT ??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwShutdownSystem SSDT ??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwTerminateProcess ---- Kernel code sections - GMER 1.0.12 ---- .text tcpip.sys!IPTransmit + 10BC F77F7CFA 6 Bytes CALL F97F83C0 Teefer.sys .text tcpip.sys!IPTransmit + 2810 F77F944E 3 Bytes CALL F97F83C0 Teefer.sys .text tcpip.sys!IPTransmit + 2814 F77F9452 2 Bytes [01, 90] .text tcpip.sys!ARPRcv + 506D F77FE4E0 3 Bytes CALL F97F83C0 Teefer.sys .text tcpip.sys!ARPRcv + 5071 F77FE4E4 2 Bytes [01, 90] .text wanarp.sys F8AC93FD 7 Bytes CALL F97F8510 Teefer.sys ---- Devices - GMER 1.0.12 ---- Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 81B714F0 Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 811FBCF0 Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F9DEA360] wpsdrvnt.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F9DEA580] wpsdrvnt.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F9DEA6A0] wpsdrvnt.sys Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F9DEA6D0] wpsdrvnt.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F9DEA360] wpsdrvnt.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F9DEA580] wpsdrvnt.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F9DEA6A0] wpsdrvnt.sys Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F9DEA6D0] wpsdrvnt.sys Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 818611E8 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 818611E8 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 8184EC18 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 818611E8 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 818611E8 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE_NAMED_PIPE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CLOSE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_READ 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_WRITE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_EA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_EA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_FLUSH_BUFFERS 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_VOLUME_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_VOLUME_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DIRECTORY_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_FILE_SYSTEM_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DEVICE_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_INTERNAL_DEVICE_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SHUTDOWN 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_LOCK_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CLEANUP 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_CREATE_MAILSLOT 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_SECURITY 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_SECURITY 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_POWER 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SYSTEM_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_DEVICE_CHANGE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_QUERY_QUOTA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_SET_QUOTA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 IRP_MJ_PNP 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 81943580 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 81943580 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_CREATE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_CREATE_NAMED_PIPE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_CLOSE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_READ 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_WRITE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_QUERY_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SET_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_QUERY_EA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SET_EA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_FLUSH_BUFFERS 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_QUERY_VOLUME_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SET_VOLUME_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_DIRECTORY_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_FILE_SYSTEM_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_DEVICE_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SHUTDOWN 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_LOCK_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_CLEANUP 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_CREATE_MAILSLOT 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_QUERY_SECURITY 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SET_SECURITY 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_POWER 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SYSTEM_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_DEVICE_CHANGE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_QUERY_QUOTA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_SET_QUOTA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 IRP_MJ_PNP 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE_NAMED_PIPE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CLOSE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_READ 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_WRITE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_EA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_EA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_FLUSH_BUFFERS 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_VOLUME_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_VOLUME_INFORMATION 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DIRECTORY_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_FILE_SYSTEM_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DEVICE_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_INTERNAL_DEVICE_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SHUTDOWN 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_LOCK_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CLEANUP 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_CREATE_MAILSLOT 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_SECURITY 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_SECURITY 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_POWER 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SYSTEM_CONTROL 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_DEVICE_CHANGE 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_QUERY_QUOTA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_SET_QUOTA 81943580 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f IRP_MJ_PNP 81943580 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 818611E8 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 818611E8 Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 817525F0 Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F9DEA360] wpsdrvnt.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F9DEA580] wpsdrvnt.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F9DEA6A0] wpsdrvnt.sys Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F9DEA6D0] wpsdrvnt.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F9DEA360] wpsdrvnt.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F9DEA580] wpsdrvnt.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F9DEA6A0] wpsdrvnt.sys Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F9DEA6D0] wpsdrvnt.sys Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 8184F5A8 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F9DEA360] wpsdrvnt.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [F9DEA580] wpsdrvnt.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F9DEA6A0] wpsdrvnt.sys Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F9DEA6D0] wpsdrvnt.sys Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 8184F5A8 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 81874B70 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 818382D0 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_CREATE 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_CLOSE 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_READ 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_WRITE 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_SET_INFORMATION 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_QUERY_EA 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_SET_EA 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_SHUTDOWN 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_CLEANUP 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_SET_SECURITY 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_POWER 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_SET_QUOTA 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port2Path0Target0Lun0 IRP_MJ_PNP 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CREATE 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CREATE_NAMED_PIPE 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CLOSE 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_READ 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_WRITE 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_INFORMATION 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_INFORMATION 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_EA 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_EA 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_FLUSH_BUFFERS 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_VOLUME_INFORMATION 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_VOLUME_INFORMATION 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_DIRECTORY_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_FILE_SYSTEM_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_DEVICE_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SHUTDOWN 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_LOCK_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CLEANUP 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CREATE_MAILSLOT 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_SECURITY 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_SECURITY 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_POWER 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SYSTEM_CONTROL 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_DEVICE_CHANGE 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_QUOTA 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_QUOTA 81778A90 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_PNP 81778A90 Device \FileSystem\Fastfat \Fat IRP_MJ_READ 811FBCF0 Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 81845210 Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_READ 81845210 Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 81845210 Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_READ 81845210 Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_READ 81845210 Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 81923540 ---- Modules - GMER 1.0.12 ---- Module _________ F994C000 ---- EOF - GMER 1.0.12 ----
Złączono Posta _: 01.04.2007 (Nie) 15:42_trzeci log sie nie zmiesił wiec wklejam linka do niego
http://download.yousendit.com/6AE29C61334E1337
babo1
(Babo1)
4 Kwiecień 2007 14:31
#7
nie jest ok błedy cały czas wyskakują a ja walcze, moze ktoś jeszcze spojrzałby na te moje logi. i powiedzial albo co zmienic albo ze są czyste pls
adam9870
(adam9870)
4 Kwiecień 2007 14:33
#8
Wklej nowy log z ComboFix’a plus dwa nowe logi z Gmer’a.