witam
mam problem ctfmon.exe po skasowaniu plików z dysków C i D : autorun.ini , folderu Recycled , Recycler oraz ctfmon.exe z autostartu trojan ciągle powraca i tworzy wymienione wyżej pliki na nowo na obu partycjach .
Deckard’s System Scanner v20070826.66
Run by Smigol on 2007-08-31 02:04:09
Computer is in Normal Mode.
– System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable…success.
– Last 1 Restore Point(s) –
1: 2007-08-31 00:04:13 UTC - RP1 - Punkt kontrolny systemu
Backed up registry hives.
Performed disk cleanup.
– HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-08-31 02:06:03
Platform: Windows XP Dodatek Service Pack. 1 (5.01.2600)
MSIE: Internet Explorer (6.00.2800.1106)
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sygate\SPF\Smc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\WButton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\GWHotKey.exe
C:\Documents and Settings\Smigol\Menu Start\Programy\Autostart\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Documents and Settings\Smigol\Pulpit\dss.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.microsoft.com/isapi/redir.dl … cid=0x0415
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKEY_LOCAL_MACHINE…\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [soundMan] SOUNDMAN.EXE
O4 - HKEY_LOCAL_MACHINE…\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [LMgrPanelICON] C:\Program Files\Launch Manager\PanelICON.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [Wbutton] “C:\Program Files\Launch Manager\Wbutton.exe”
O4 - HKEY_LOCAL_MACHINE…\Run: [AVManager] “C:\Program Files\Wistron\AVManager\AVManager.exe”
O4 - HKEY_LOCAL_MACHINE…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKEY_LOCAL_MACHINE…\Run: [smcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKEY_LOCAL_MACHINE…\Run: [Multi-function Keyboard] GWHotKey.exe
O4 - Startup: ctfmon.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra ‘Tools’ menuitem: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Pokrewne - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm
O9 - Extra ‘Tools’ menuitem: Po&każ łącza pokrewne - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm
O16 - DPF: {00000162-9980-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/ … ma9dmo.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/ … mv9VCM.CAB
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://download.microsoft.com/download/ … mv9dmo.cab
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc … wflash.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Zango/i … e55ab221c8
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
– File Associations -----------------------------------------------------------
.scr - AutoCADScriptFile - shell\open\command - “C:\WINDOWS\notepad.exe” “%1”
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 Teefer (Teefer for NT) - c:\windows\system32\drivers\teefer.sys
R1 Amfilter (A4Tech Mouse Filter Driver) - c:\windows\system32\drivers\amfilter.sys
R1 Hotkey - c:\windows\system32\drivers\hotkey.sys
R1 wpsdrvnt - c:\windows\system32\drivers\wpsdrvnt.sys
R2 ElbyCDIO (ElbyCDIO Driver) - c:\windows\system32\drivers\elbycdio.sys
R2 Sentinel - c:\windows\system32\drivers\sentinel.sys
R2 wg3n (SyGate for NT, wg3n) - c:\windows\system32\drivers\wg3n.sys
R3 AnyDVD - c:\windows\system32\drivers\anydvd.sys
R3 ElbyDelay - c:\windows\system32\drivers\elbydelay.sys
S3 Amps2prt (A4Tech PS/2 Port Mouse Driver) - c:\windows\system32\drivers\amps2prt.sys
S3 Amusbprt (A4Tech HID-compliant Mouse Driver) - c:\windows\system32\drivers\amusbprt.sys
S3 usbsermptxp (Motorola USB Modem Driver for MPT XP) - c:\windows\system32\drivers\usbsermptxp.sys
– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Diskeeper - c:\program files\executive software\diskeeperlite\dkservice.exe
– Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Kontroler sieci
Device ID: PCI\VEN_8086&DEV_4220&SUBSYS_27018086&REV_05\4&16793A72&0&08F0
Manufacturer:
Name: Kontroler sieci
PNP Device ID: PCI\VEN_8086&DEV_4220&SUBSYS_27018086&REV_05\4&16793A72&0&08F0
Service:
– Files created between 2007-07-31 and 2007-08-31 -----------------------------
2007-08-31 01:53:09 0 dr-hs---- C:\Recycled
2007-08-28 02:57:11 0 d-------- C:\Program Files\Media Player Classic
2007-08-28 02:57:10 0 d-------- C:\Program Files\Real Alternative
2007-08-27 19:13:25 349696 --a------ C:\WINDOWS\System32\hypertrm.dll
2007-08-26 04:01:51 0 d-------- C:\Program Files\ArcaMicroScan
2007-08-25 23:56:47 0 d-------- C:\Program Files\MyGlobalSearch
2007-08-12 03:46:26 0 d-------- C:\WINDOWS\Sun
2007-08-12 03:45:44 0 d-------- C:\Program Files\Java
2007-08-12 03:44:45 0 d-------- C:\Program Files\Common Files\Java
2007-08-11 18:41:51 0 d-------- C:\Program Files\Common Files\Real
2007-08-11 18:41:48 0 d-------- C:\Program Files\Real
2007-08-07 17:23:53 2829 --a------ C:\WINDOWS\War3Unin.pif
2007-08-07 17:23:53 139264 --a------ C:\WINDOWS\War3Unin.exe
2007-08-07 17:23:53 66045 --a------ C:\WINDOWS\War3Unin.dat
2007-08-07 14:08:13 86016 --a------ C:\WINDOWS\unvise32.exe
– Find3M Report ---------------------------------------------------------------
2007-08-31 00:20:32 0 d-------- C:\Program Files\Mozilla Thunderbird
2007-08-29 18:18:26 0 d-------- C:\Program Files\DC++
2007-08-28 12:19:33 0 d-------- C:\Documents and Settings\Smigol\Dane aplikacji\Uniblue
2007-08-28 02:57:10 0 d-------- C:\Documents and Settings\Smigol\Dane aplikacji\Real
2007-08-28 02:54:04 0 d-------- C:\Program Files\Common Files
2007-08-27 19:13:53 436560 --a------ C:\WINDOWS\System32\perfh015.dat
2007-08-27 19:13:53 67496 --a------ C:\WINDOWS\System32\perfc015.dat
2007-08-27 19:13:32 0 d-------- C:\Program Files\Windows NT
2007-08-12 03:46:26 0 d-------- C:\Documents and Settings\Smigol\Dane aplikacji\Sun
2007-08-12 03:46:21 9758 --a------ C:\WINDOWS\mozver.dat
2007-08-07 14:05:48 0 d–h----- C:\Program Files\InstallShield Installation Information
2007-07-20 10:34:38 847872 --a------ C:\WINDOWS\System32\ArcaOnline.dll
2007-07-12 02:38:30 0 d-------- C:\Program Files\BitComet
– Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ATIModeChange”=“Ati2mdxx.exe” [2001-09-04 23:24 C:\WINDOWS\system32\Ati2mdxx.exe]
“ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2003-06-25 16:30]
“SynTPLpr”=“C:\Program Files\Synaptics\SynTP\SynTPLpr.exe” [2003-04-25 05:51]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2003-04-25 05:44]
“AGRSMMSG”=“AGRSMMSG.exe” [2003-06-27 15:53 C:\WINDOWS\AGRSMMSG.exe]
“SoundMan”=“SOUNDMAN.EXE” [2003-08-15 22:34 C:\WINDOWS\SOUNDMAN.EXE]
“LaunchAp”=“C:\Program Files\Launch Manager\LaunchAp.exe” [2003-05-12 15:28]
“HotkeyApp”=“C:\Program Files\Launch Manager\HotkeyApp.exe” [2003-09-24 14:53]
“CtrlVol”=“C:\Program Files\Launch Manager\CtrlVol.exe” [2003-09-16 15:28]
“LMgrPanelICON”=“C:\Program Files\Launch Manager\PanelICON.exe” [2003-09-24 17:37]
“Wbutton”=“C:\Program Files\Launch Manager\Wbutton.exe” [2003-09-12 16:24]
“AVManager”=“C:\Program Files\Wistron\AVManager\AVManager.exe” [2003-09-24 17:49]
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 12:50]
“AnyDVD”=“C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe” [2006-03-16 21:37]
“SmcService”=“C:\PROGRA~1\Sygate\SPF\smc.exe” [2003-12-24 15:44]
“Multi-function Keyboard”=“GWHotKey.exe” [2001-08-28 12:13 C:\WINDOWS\GWHotKey.exe]
C:\Documents and Settings\Smigol\Menu Start\Programy\Autostart\
ctfmon.exe [2007-02-16 14:34:26]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@=“Service”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@=“Volume shadow copy”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
“C:\Program Files\BearShare\BearShare.exe” /pause
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
“C:\Program Files\DAEMON Tools\daemon.exe” -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
“C:\Program Files\Messenger\msmsgs.exe” /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
“C:\Program Files\QuickTime\qttask.exe” -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
“C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{2ff3bc11-b520-11da-9c7c-806d6172696f}]
AutoRun\command- RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\Recycled\ctfmon.exe
Open(&O)\command- C:\Recycled\Recycled\ctfmon.exe
– End of Deckard’s System Scanner: finished at 2007-08-31 02:06:28 ------------