Nie wiem jak sie posługiwac tym programem ;p niewiem jak sie daje te logi a jezeli chodzi o p2p to niemam na kompie i niemiałem zadnych takich programów.
a w msconfig pisze : winlogin.exe C:\windows\system32\winlogin.exe Common Startup.
Moze mi ktos wytłumaczyc jak zrobic log i jak go wrzucic na forum.
Złączono Posta : 22.05.2007 (Wto) 18:14
ok juz mam log z combofix :
“dom” - 2007-05-22 18:10:26 Dodatek Service Pack 2
ComboFix 07-05.21.6.V - Running from: “C:\Documents and Settings\dom\Pulpit”
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\winlogin.exe
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-22 ))))))))))))))))))))))))))))))))))
2007-05-19 17:36
2007-05-14 07:46
2007-05-13 15:28
2007-05-13 15:26 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-05-13 15:24
2007-05-13 15:24
2007-05-13 15:23 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-05-13 15:23 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-05-13 15:23 38,912 --------- C:\WINDOWS\system32\picn20.dll
2007-05-13 15:23 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2007-05-13 15:23 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-05-13 15:23 2,973,696 --------- C:\WINDOWS\UNNeroVision.exe
2007-05-13 15:23 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2007-05-13 15:23 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-05-13 15:23
2007-05-13 15:23
2007-05-13 15:23
2007-05-13 12:30
2007-05-10 15:26
2007-05-10 15:25
2007-05-01 16:35
2007-05-01 12:09
2007-05-01 12:09
2007-04-30 20:56
2007-04-30 17:19
2007-04-30 17:03 233,472 --a------ C:\WINDOWS\system32\Ilda32.dll
2007-04-30 17:03 18,944 --a------ C:\WINDOWS\system32\BORLNDMM.DLL
2007-04-30 14:35 737,280 --a------ C:\WINDOWS\iun6002.exe
2007-04-22 20:35
2007-04-22 20:34 654,848 --a------ C:\WINDOWS\system32\x264vfw.dll
2007-04-22 20:34 630,784 --a------ C:\WINDOWS\system32\vp7vfw.dll
2007-04-22 20:34 438,272 --a------ C:\WINDOWS\system32\vp6vfw.dll
2007-04-22 20:34 144,384 --a------ C:\WINDOWS\system32\Iacenc.dll
2007-04-22 20:33 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-04-22 20:33 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-04-22 20:33 639,066 --a------ C:\WINDOWS\system32\divx.dll
2007-04-22 20:33 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-04-22 20:33 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-04-22 20:33 196,608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-04-22 20:33 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-04-22 20:33 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-04-22 20:33 1,565,480 --a------ C:\WINDOWS\system32\wmv9vcm.dll
2007-04-22 20:33 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-04-22 20:33
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-21 19:40:11 -------- d-----w C:\DOCUME~1\dom\DANEAP~1\Skype
2007-05-19 15:41:10 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-05-19 15:40:55 -------- d–h--w C:\Program Files\InstallShield Installation Information
2007-05-14 14:19:05 -------- d-----w C:\DOCUME~1\dom\DANEAP~1\OpenOffice.ux.pl2
2007-04-21 17:51:19 1,289 ----a-w C:\WINDOWS\mozver.dat
2007-04-21 14:32:38 -------- d-----w C:\Program Files\CCleaner
2007-04-21 13:44:34 -------- d-----w C:\DOCUME~1\dom\DANEAP~1\FinalBurner DATA
2007-04-20 18:19:48 -------- d-----w C:\DOCUME~1\dom\DANEAP~1\Morpheus Software
2007-04-17 13:39:01 -------- d-----w C:\DOCUME~1\dom\DANEAP~1\Gadu-Gadu
2007-04-16 16:27:39 64,342 ----a-w C:\WINDOWS\system32\perfc015.dat
2007-04-16 16:27:39 429,946 ----a-w C:\WINDOWS\system32\perfh015.dat
2007-04-14 19:35:57 -------- d-----w C:\Program Files\Kalendarz XP
2007-04-13 12:44:29 -------- d-----w C:\Program Files\Real Alternative
2007-04-13 12:44:22 -------- d-----w C:\DOCUME~1\dom\DANEAP~1\Real
2007-04-10 09:24:12 -------- d-----w C:\Program Files\EA GAMES
2007-04-10 06:27:22 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-04-10 06:27:22 249,856 ------w C:\WINDOWS\Setup1.exe
2007-04-05 09:39:26 -------- d-----w C:\Program Files\Wielka Powtorka Lektury 1
2007-04-05 09:38:44 -------- d-----w C:\Program Files\Edgard Multimedia
2007-04-03 14:53:13 2,038 ----a-w C:\WINDOWS\unins000.dat
2007-03-28 16:43:16 181,760 ----a-w C:\WINDOWS\system32\iwpsetup.exe
2007-03-26 14:48:30 -------- d-----w C:\Program Files\Codemasters
2007-03-25 07:54:46 -------- d-----w C:\DOCUME~1\dom\DANEAP~1\AdobeUM
2007-03-24 20:10:19 -------- d-----w C:\Program Files\Common Files\DirectX
2007-03-24 12:54:05 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-02-12 13:23:23 16 ----a-w C:\WINDOWS\system32\DataRnvx.dat
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 06:12]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“BigDog303”=“C:\WINDOWS\VM303_STI.exe” [2005-06-23 05:13]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-01-15 19:28]
“ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2005-02-01 22:05]
“ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” [2005-02-01 23:23]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43]
“LXSUPMON”=“C:\WINDOWS\system32\LXSUPMON.exe” [2002-01-28 14:48]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe” [2006-12-01 12:46]
[HKEY_USERS.default\software\microsoft\windows\currentversion\run]
“”=
“ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” runtime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^ATI CATALYST System Tray.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ATI CATALYST System Tray.lnk
backup=C:\WINDOWS\pss\ATI CATALYST System Tray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Kalendarz XP.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Kalendarz XP.lnk
backup=C:\WINDOWS\pss\Kalendarz XP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Ulead Photo Express 3.0 SE Calendar Checker.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Ulead Photo Express 3.0 SE Calendar Checker.lnk
backup=C:\WINDOWS\pss\Ulead Photo Express 3.0 SE Calendar Checker.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^dom^Menu Start^Programy^Autostart^OpenOffice.ux.pl 2.0.4.lnk]
path=C:\Documents and Settings\dom\Menu Start\Programy\Autostart\OpenOffice.ux.pl 2.0.4.lnk
backup=C:\WINDOWS\pss\OpenOffice.ux.pl 2.0.4.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EdHTML]
C:\Program Files\Binboy\EdHTMLv5.0\EdHTML.exe /none
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXSUPMON]
C:\WINDOWS\system32\LXSUPMON.EXE RUN
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
“C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized
*Newly Created Service* -PROCEXP90
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-22 18:12:30
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303 = C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)???0???@???
scanning hidden files …
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2007-05-22 18:12:56
C:\ComboFix-quarantined-files.txt … 2007-05-22 18:12
— E O F —