Brak dźwięków


(Robert1993) #1

Witam. Zauważyłem, że system nie odtwarza żadnych dźwięków. Z głośnikami jest wszystko w porządku, podłączałem nawet drugie, aby się upewnić. Jestem ciekawy, czy może to sprawka jakiegoś wirusa, tak więc daję log z HijackThis i proszę o sprawdzenie.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:06:58, on 2008-02-21

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Boot mode: Normal


Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\Ati2evxx.exe

C:\Program Files\Sygate\SPF\smc.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\system32\stisvc.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\system32\mspmspsv.exe

C:\WINNT\system32\svchost.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\WINNT\system32\Ati2evxx.exe

C:\WINNT\Explorer.EXE

C:\WINNT\SOUNDMAN.EXE

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe

C:\Program Files\A4tech\Mouse\Awmmain.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe

C:\WINNT\system32\wuauclt.exe

C:\PROGRA~1\NEOSTR~1\NeostradaTP.exe

C:\PROGRA~1\NEOSTR~1\ComComp.exe

C:\PROGRA~1\NEOSTR~1\Watch.exe

C:\Program Files\Winamp\winamp.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe

O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe /waitservice

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui

O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe

O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe

O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\A4tech\Mouse\Awmmain.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [svchost] C:\WINNT\svchost\svchost.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')

O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll

O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\PROGRA~1\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)

O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\PROGRA~1\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (GINBOARDS Class) - http://67.15.101.3/g_bin/pl/boards_2_0_0_17.cab

O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://217.96.55.11//activex/AMC.cab

O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} (SignActivX Control) - https://www.bph.pl/sezam/components/SignActivX.cab

O16 - DPF: {AC120B1D-9411-4111-AF52-118052D85D45} (GameDesire Darts Games) - http://67.15.101.3/g_bin/pl/darts_2_0_0_29.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/pl/billard8_2_0_0_21.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{4A19EFE0-0047-4A76-980B-30CF2B57FD8B}: NameServer = 194.204.159.1 217.98.63.164

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Usługa administracyjna Menedżera dysków logicznych (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Outpost Firewall Service (OutpostFirewall) - Unknown owner - C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe (file missing)

O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe


--

End of file - 6199 bytes

(zagorskid) #2

Jak tam kodeki? Spróbuj zainstalować jakąś paczkę, np. CCCP.


(Leon$) #3

start >> uruchom >> cmd

sc stop OutpostFirewall

sc delete OutpostFirewall

wpisy

O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe /waitservice

O4 - HKLM\..\Run: [svchost] C:\WINNT\svchost\svchost.exe

O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\PROGRA~1\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)

O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\PROGRA~1\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)

O16 - DPF: {AC120B1D-9411-4111-AF52-118052D85D45} (GameDesire Darts Games) - http://67.15.101.3/g_bin/pl/darts_2_0_0_29.cab

O23 - Service: Outpost Firewall Service (OutpostFirewall) - Unknown owner - C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe (file missing)

usuń HijackThisem >> Fix checked Pobierz Combofix http://www.bezpieczenstwosystemow.pl/index.php?topic=18.0 ale nie włączaj otwórz notatnik i wklej

File:: 

C:\WINNT\svchost\svchost.exe

zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe

http://img.wklej.org/images/88953CFScri … iemoes.gif

Powinno rozpocząć się usuwanie

Potem log z usuwania

Po restarcie jeśli wszystko będzie OK usuń ręcznie folder C: \Qoobox

:slight_smile:


(Robert1993) #4

Heh, nie mogę zrobić tego sc~, bo mam:


(Leon$) #5

Przepraszam ty masz Win 2000 opuść to puźniej zrobisz to inaczej

resztę zrób jak pisałem

:slight_smile:


(Robert1993) #6

Ok, zrobiłem wszystko, co kazałeś. Jak na razie się nic nie zmieniło.

Oto log z ComboFix:

ComboFix 08-02-21 - Robert 2008-02-21 21:19:55.1 - NTFSx86

Microsoft Windows 2000 Professional 5.0.2195.4.1250.1.1045.18.257 [GMT 1:00]

Running from: C:\Documents and Settings\Administrator\Pulpit\ComboFix.exe

Command switches used :: C:\Documents and Settings\Administrator\Pulpit\CFScript.txt


[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED [/b][/color]


FILE ::

C:\WINNT\svchost\svchost.exe

.


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.


C:\WINNT\svchost\svchost.exe

C:\WINNT\Web\default.htt


.

((((((((((((((((((((((((( Files Created from 2008-01-21 to 2008-02-21 )))))))))))))))))))))))))))))))

.


2008-02-21 21:20 . 08-02-21 21:20 16,384	--a----t-	C:\WINNT\system32\Perflib_Perfdata_3cc.dat

2008-02-21 20:53 . 08-02-21 20:53 16,384	--a----t-	C:\WINNT\system32\Perflib_Perfdata_274.dat

2008-02-21 19:05 . 08-02-21 19:05

----a-w 2,676,736 2002-08-09 08:36:56 C:\Program Files\rpgmaker\RPG MAKER PL 2.0 .exe

[/code] ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “MsnMsgr”=“C:\Program Files\MSN Messenger\MsnMsgr.exe” [07-09-04 23:40 6856704] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“SOUNDMAN.EXE” [02-10-16 11:24 47104 C:\WINNT\SOUNDMAN.EXE] “ATIPTA”=“atiptaxx.exe” [06-02-22 01:05 344064 C:\WINNT\system32\atiptaxx.exe] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [07-12-04 14:00 79224] “SmcService”=“C:\PROGRA~1\Sygate\SPF\smc.exe” [04-10-15 19:40 2577632] “WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [03-10-16 19:07 20480] “WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” [03-10-16 19:07 53248] “WheelMouse”=“C:\Program Files\A4tech\Mouse\Awmmain.exe” [01-03-20 07:32 229376] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [07-07-09 18:24 282624] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “Picasa Media Detector”=“C:\Program Files\Picasa2\PicasaMediaDetector.exe” [07-09-28 02:17 443968] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] “^SetupICWDesktop”=“C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe” [03-06-19 11:05 188688] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-02-03 22:17:09 962661] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56 65588] [HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^InterVideo WinCinema Manager.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\InterVideo WinCinema Manager.lnk backup=C:\WINNT\pss\InterVideo WinCinema Manager.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager] --a------ 03-12-22 08:38 241664 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 04-02-18 18:55 49152 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility] --a------ 04-03-04 15:46 172032 C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb10.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 01-07-09 10:50 155648 C:\WINNT\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Omnipage] --a------ 02-06-03 10:38 49152 C:\Program Files\ScanSoft\OmniPageSE\opware32.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 07-07-09 18:24 282624 C:\Program Files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 04-12-06 20:31 36975 C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon] --a------ 03-10-16 19:07 24576 C:\PROGRA~1\NEOSTR~1\CnxMon.exe R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINNT\system32\drivers\sfsync03.sys [05-10-13 14:46] R2 aswMon;avast! Standard Shield Support;C:\WINNT\system32\drivers\aswMon.sys [07-12-04 15:56] S1 VFILT;Outpost Firewall Kernel Driver;C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\2000\FILTNT.SYS [] S3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\ADBLOCK.DLL [] S3 Amps2prt;Newmentech PS/2 Port Mouse Driver;C:\WINNT\system32\DRIVERS\Amps2prt.sys [] S3 Aps2wmou;A4Tech PS/2 Port Mouse Filter Driver;C:\WINNT\system32\DRIVERS\Aps2wmou.sys [01-03-20 07:32] S3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\CONTENT.DLL [] S3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\DNSCACHE.DLL [] S3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\FTPFILT.DLL [] S3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\HTMLFILT.DLL [] S3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\HTTPFILT.DLL [] S3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\IMAPFILT.DLL [] S3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\MAILFILT.DLL [] S3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\NNTPFILT.DLL [] S3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\POP3FILT.DLL [] S3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\PROTECT.DLL [] S3 uscsc108;uscsc108;C:\WINNT\system32\DRIVERS\uscsc108.sys [] S3 V0260VID;Live! Cam Vista IM;C:\WINNT\system32\DRIVERS\V0260Vid.sys [06-04-01 16:16] . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-02-21 21:25:52 Windows 5.0.2195 Service Pack 4 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-02-21 21:28:27 ComboFix-quarantined-files.txt 2008-02-21 20:28:05 . 2007-08-16 20:13:05 — E O F — [/code]


(Leon$) #7

Otwórz notatnik i wklej

Folder:: 

C:\WINNT\svchost


Driver:: 

VFILT

ADBLOCK.DLL

Amps2prt

CONTENT.DLL

DNSCACHE.DLL

FTPFILT.DLL

HTMLFILT.DLL

HTTPFILT.DLL

IMAPFILT.DLL

MAILFILT.DLL

NNTPFILT.DLL

POP3FILT.DLL

PROTECT.DLL

uscsc108

zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe

http://img.wklej.org/images/88953CFScri … iemoes.gif

Powinno rozpocząć się usuwanie

Potem log z usuwania

Po restarcie jeśli wszystko będzie OK usuń ręcznie folder C: \Qoobox

Co do braku dźwięku tu jest plik.reg ale do XP czy zadziała na 2000 nie wiem http://www.bercik64.republika.pl/FIX%20by%20mgr.inz.Player.reg

:slight_smile:


(Robert1993) #8

Proszę, o to log:

ComboFix 08-02-21 - Robert 2008-02-22 17:53:18.2 - NTFSx86

Microsoft Windows 2000 Professional 5.0.2195.4.1250.1.1045.18.313 [GMT 1:00]

Running from: C:\Documents and Settings\Administrator\Pulpit\ComboFix.exe

Command switches used :: C:\Documents and Settings\Administrator\Pulpit\CFScript.txt


[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED [/b][/color]

.


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.


C:\WINNT\svchost


.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


.

-------\LEGACY_ADBLOCK.DLL

-------\LEGACY_CONTENT.DLL

-------\LEGACY_DNSCACHE.DLL

-------\LEGACY_FTPFILT.DLL

-------\LEGACY_HTMLFILT.DLL

-------\LEGACY_HTTPFILT.DLL

-------\LEGACY_IMAPFILT.DLL

-------\LEGACY_VFILT

-------\ADBLOCK.DLL

-------\Amps2prt

-------\CONTENT.DLL

-------\DNSCACHE.DLL

-------\FTPFILT.DLL

-------\HTMLFILT.DLL

-------\HTTPFILT.DLL

-------\IMAPFILT.DLL

-------\VFILT



((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))

.


2008-02-21 19:05 . 08-02-21 19:05

----a-w 2,676,736 2002-08-09 08:36:56 C:\Program Files\rpgmaker\RPG MAKER PL 2.0 .exe

[/code] ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “MsnMsgr”=“C:\Program Files\MSN Messenger\MsnMsgr.exe” [07-09-04 23:40 6856704] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“SOUNDMAN.EXE” [02-10-16 11:24 47104 C:\WINNT\SOUNDMAN.EXE] “ATIPTA”=“atiptaxx.exe” [06-02-22 01:05 344064 C:\WINNT\system32\atiptaxx.exe] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [07-12-04 14:00 79224] “SmcService”=“C:\PROGRA~1\Sygate\SPF\smc.exe” [04-10-15 19:40 2577632] “WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [03-10-16 19:07 20480] “WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” [03-10-16 19:07 53248] “WheelMouse”=“C:\Program Files\A4tech\Mouse\Awmmain.exe” [01-03-20 07:32 229376] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [07-07-09 18:24 282624] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “Picasa Media Detector”=“C:\Program Files\Picasa2\PicasaMediaDetector.exe” [07-09-28 02:17 443968] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] “^SetupICWDesktop”=“C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe” [03-06-19 11:05 188688] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-02-03 22:17:09 962661] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56 65588] [HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^InterVideo WinCinema Manager.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\InterVideo WinCinema Manager.lnk backup=C:\WINNT\pss\InterVideo WinCinema Manager.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager] --a------ 03-12-22 08:38 241664 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 04-02-18 18:55 49152 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility] --a------ 04-03-04 15:46 172032 C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb10.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 01-07-09 10:50 155648 C:\WINNT\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Omnipage] --a------ 02-06-03 10:38 49152 C:\Program Files\ScanSoft\OmniPageSE\opware32.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 07-07-09 18:24 282624 C:\Program Files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 04-12-06 20:31 36975 C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon] --a------ 03-10-16 19:07 24576 C:\PROGRA~1\NEOSTR~1\CnxMon.exe R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINNT\system32\drivers\sfsync03.sys [05-10-13 14:46] R2 aswMon;avast! Standard Shield Support;C:\WINNT\system32\drivers\aswMon.sys [07-12-04 15:56] S3 Aps2wmou;A4Tech PS/2 Port Mouse Filter Driver;C:\WINNT\system32\DRIVERS\Aps2wmou.sys [01-03-20 07:32] S3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\MAILFILT.DLL [] S3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\NNTPFILT.DLL [] S3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\POP3FILT.DLL [] S3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\PROTECT.DLL [] S3 uscsc108;uscsc108;C:\WINNT\system32\DRIVERS\uscsc108.sys [] S3 V0260VID;Live! Cam Vista IM;C:\WINNT\system32\DRIVERS\V0260Vid.sys [06-04-01 16:16] . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-02-22 18:04:06 Windows 5.0.2195 Service Pack 4 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINNT\system32\Ati2evxx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\mspmspsv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\WINNT\system32\Ati2evxx.exe . ************************************************************************** . Completion time: 2008-02-22 18:10:58 - machine was rebooted ComboFix-quarantined-files.txt 2008-02-22 17:10:54 ComboFix2.txt 2008-02-21 20:28:28 . 2007-08-16 20:13:05 — E O F — [/code]

Co do tego wpisu do rejestru, to niestety nic nie zmienił.


(zagorskid) #9

A z kodekami próbowałeś? :]


(Robert1993) #10

Tak :slight_smile: