csb021
(Kamil Mielewczyk)
13 Grudzień 2008 11:26
#1
Mój komputer ostatnio zaraził się wirusem Brontok, ponieważ na chwile wyłączyłem antywirusa i akurat wtedy podłączyłem pendrive od kolegi. Teraz wirus zablokował mi edycję rejestru i niewiem co zrobić. Tutaj log:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:22:17, on 2008-12-13 Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\D-Tools\daemon.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe C:\WINDOWS\Mixer.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\TomTom HOME 2\HOMERunner.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Common Files\Teleca Shared\Generic.exe C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\WinRAR\WinRAR.exe C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe C:\DOCUME~1\Admin\USTAWI~1\Temp\Rar$EX22.594\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://192.168.1.1/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza F2 - REG:system.ini: UserInit=userinit.exe,EXPLORER.EXE O1 - Hosts: Yahoo! O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: Yahoo! - Help O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: Sorry, the page you requested was not found. O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: Search Yahoo! O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: advanced search most popular O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: Yahoo! Web Hosting O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: Yahoo! Web Hosting has three affordable plans to meet your needs - starting at just $11.95. O1 - Hosts: O1 - Hosts: O1 - Hosts: Learn more… O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: src=“http://adserver.yahoo.com/a?f=76001284p=geocitiesl=MONc=shbg=ffffff ” O1 - Hosts: width=470 height=580 marginwidth=0 marginheight=0 hspace=0 O1 - Hosts: vspace=0 frameborder=0 scrolling=no O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: O1 - Hosts: href='http://rd.yahoo.com/footer/?http://address.yahoo.com/'Address Book · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://alerts.yahoo.com/'Alerts · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://auctions.yahoo.com/'Auctions · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://billpay.yahoo.com/'Bill Pay · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://bookmarks.yahoo.com/'Bookmarks · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://briefcase.yahoo.com/'Briefcase · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://broadcast.yahoo.com/'Broadcast · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://calendar.yahoo.com/'Calendar · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://chat.yahoo.com/'Chat · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://classifieds.yahoo.com/'Classifieds · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://clubs.yahoo.com/'Clubs · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://companion.yahoo.com/'Companion · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://experts.yahoo.com/'Experts · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://games.yahoo.com/'Games · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://greetings.yahoo.com/'Greetings · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://geocities.yahoo.com/'Home Pages · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://invites.yahoo.com/'Invites · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://mail.yahoo.com/'Mail · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://maps.yahoo.com/'Maps · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://members.yahoo.com/'Member Directory · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://messenger.yahoo.com/'Messenger · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://my.yahoo.com/'My Yahoo! · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://news.yahoo.com/'News · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://paydirect.yahoo.com/'PayDirect · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://people.yahoo.com/'People Search · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://personals.yahoo.com/'Personals · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://photos.yahoo.com/'Photos · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://shopping.yahoo.com/'Shopping · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://sports.yahoo.com/'Sports · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://finance.yahoo.com/'Stock Quotes · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://tv.yahoo.com/'TV · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://travel.yahoo.com/'Travel · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://weather.yahoo.com/'Weather · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://www.yahooligans.com/'Yahooligans · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://yp.yahoo.com/'Yellow Pages · O1 - Hosts: href='http://rd.yahoo.com/footer/?http://docs.yahoo.com/docs/family/more.html’more … O1 - Hosts: O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O3 - Toolbar: Tłumaczenie - {0D704FAD-66E9-4F0A-BFED-4F665770DDB3} - C:\Program Files\Techland\Common\InternetTranslator\InternetTranslator.dll O4 - HKLM…\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe O4 - HKLM…\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” O4 - HKLM…\Run: [DAEMON Tools-1033] “C:\Program Files\D-Tools\daemon.exe” -lang 1033 O4 - HKLM…\Run: [AVP] “C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe” O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM…\Run: [GrooveMonitor] “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” O4 - HKLM…\Run: [WinampAgent] “C:\Program Files\Winamp\winampa.exe” O4 - HKLM…\Run: [sony Ericsson PC Suite] “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions O4 - HKLM…\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM…\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe” O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM…\Run: [nwiz] nwiz.exe /install O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU…\Run: [TomTomHOME.exe] “C:\Program Files\TomTom HOME 2\HOMERunner.exe” O4 - HKCU…\Run: [wsctf.exe] wsctf.exe O4 - HKCU…\Run: [EXPLORER.EXE] EXPLORER.EXE O4 - HKUS\S-1-5-19…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘USŁUGA LOKALNA’) O4 - HKUS\S-1-5-20…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘USŁUGA SIECIOWA’) O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’) O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’) O4 - Startup: Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O8 - Extra context menu item: Eksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Statystyki dla ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra ‘Tools’ menuitem: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {B46B0919-62BA-4D99-A5C4-916B57A6805C} - C:\Program Files\Techland\Common\InternetTranslator\InternetTranslator.dll O9 - Extra ‘Tools’ menuitem: @C :\Program Files\Techland\Common\InternetTranslator\InternetTranslator.dll,-103 - {B46B0919-62BA-4D99-A5C4-916B57A6805C} - C:\Program Files\Techland\Common\InternetTranslator\InternetTranslator.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll ,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe O23 - Service: ##Id_String1 .6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe – End of file - 14959 bytes Coś poradzicie? Dzięki z góry!
Leon1
(Leon$)
13 Grudzień 2008 11:35
#2
włącz HijackThis >> Do a system scan only >> w oknie programu pokaże się log >> zaznacz kratki przy podanych wpisach >> klikasz Fix checked
csb021
(Kamil Mielewczyk)
13 Grudzień 2008 11:47
#3
Dzięki wielkie! Combofix zrobił swoje i wszystko naprawił Jeszcze robię skan Kasperskim i zobaczę czy wszystko jest OK, ale wszystko wygląda na to, że jest
Leon1
(Leon$)
13 Grudzień 2008 11:52
#4
jak skończy skanować to pokaż logi o które prosiłem