Domel17
(Malgoska1795 Oficial)
31 Lipiec 2007 12:18
#1
Zacznę od tego, że to log z kompa mojego kumpla
jessica
(jessica)
31 Lipiec 2007 16:08
#2
Kosmetycznie sfiksuj ten wpis w Hijacku:
>>Hijack>>scan(Do a system scan only)>>zaznacz go >> Fix checked .
Na AVG może pomoże jego reinstalacja?
Nic tu, w tym logu, nie widzę podejrzanego.
Możesz jeszcze dać, na wszelki wypadek, log z ComboFixa -->
http://forum.dobreprogramy.pl/viewtopic.php?t=36654
(na samym dole tej strony z linku) - log wklej na http://wklej.org/ , a w poście daj tylko link.
.
Domel17
(Malgoska1795 Oficial)
1 Sierpień 2007 18:07
#3
ZROBIONE
AVG sam się naprawił
Oto log z ComboFix:
ComboFix 07-07-30.2 - “Damian” 2007-08-01 19:55:37.1 [GMT 2:00] - NTFS Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.Prawda * Created a new restore point ((((((((((((((((((((((((( Files Created from 2007-07-01 to 2007-08-01 ))))))))))))))))))))))))))))))) 2007-08-01 19:55 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-31 14:04 2007-07-30 12:16 2007-07-11 16:02 2007-07-11 12:46 2007-07-11 12:46 2007-07-09 14:11 2007-07-08 20:18 2007-07-08 20:16 2007-07-02 19:58 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-08-01 19:57 --------- d-------- C:\Program Files\FlashGet 2007-08-01 19:48 --------- d-------- C:\Program Files\Wanadoo 2007-07-31 13:43 --------- d-------- C:\Program Files\Deutsch Translator 2 2007-07-31 13:34 --------- d-------- C:\DOCUME~1\Damian\DANEAP~1\Skype 2007-07-11 19:12 --------- d-------- C:\Program Files\eMule 2007-07-07 13:36 --------- d-------- C:\Program Files\Sports Interactive 2007-07-07 13:36 --------- d-------- C:\Program Files\Common Files\InstallShield 2007-06-23 21:26 2560 --a------ C:\WINDOWS\system32\BitCometRes.dll 2007-06-21 20:19 --------- d-------- C:\Program Files\Cartall 2007-06-21 20:19 --------- d-------- C:\Program Files\Borland 2007-06-18 23:37 22 --a------ C:\WINDOWS\system32\drivers\adidsl.cfg 2007-06-18 23:37 --------- d–h----- C:\Program Files\InstallShield Installation Information 2007-06-18 23:37 --------- d-------- C:\Program Files\SAGEM 2007-06-18 18:25 --------- d-------- C:\Program Files\VID_0E8FPID_0003 2007-06-04 20:23 --------- d-------- C:\DOCUME~1\Damian\DANEAP~1\Lavasoft 2007-06-04 20:22 --------- d-------- C:\Program Files\Lavasoft 2007-06-04 20:21 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard 2007-06-01 15:41 --------- d-------- C:\Program Files\BitComet 2007-05-16 17:18 683520 --a------ C:\WINDOWS\system32\inetcomm.dll 2007-05-11 17:49 2316 --a------ C:\Program Files\INSTALL.LOG 2007-03-19 20:13 6422611 --a------ C:\Program Files\frostwire-4.13.1.6.windows.exe 1998-04-30 15:56 129024 --a------ C:\Program Files\UNWISE.EXE 2006-05-03 10:06:54 163,328 --sh–r C:\WINDOWS\system32\flvDX.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “AVG7_CC”=“C:\PROGRA~1\Grisoft\AVG7\avgcc.exe” [2007-04-19 08:46] “SoundMan”=“SOUNDMAN.EXE” [2004-01-08 20:54 C:\WINDOWS\SOUNDMAN.EXE] “nwiz”=“nwiz.exe” [2006-10-22 12:22 C:\WINDOWS\system32\nwiz.exe] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43] “WOOWATCH”=“C:\PROGRA~1\Wanadoo\Watch.exe” [2002-12-09 18:24] “WOOTASKBARICON”=“C:\PROGRA~1\Wanadoo\TaskbarIcon.exe” [2002-12-09 18:24] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] “Kleptomania”="" [] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-04-17 23:41] “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-06-01 17:51] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-06-18 23:37:03] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^TeleSA.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\TeleSA.lnk backup=C:\WINDOWS\pss\TeleSA.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^VIA RAID TOOL.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\VIA RAID TOOL.lnk backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADS] C:\Windows\ADS.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu] “C:\Program Files\Gadu-Gadu\gg.exe” /tray [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kleptomania] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator] C:\Program Files\Tlen.pl\tlen.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] C:\Valve\Steam\Steam.exe -silent [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VGAUtil] C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe R0 uagp35;Filtr AGPv3.5 firmy Microsoft;C:\WINDOWS\system32\DRIVERS\uagp35.sys R0 viadsk;viadsk;C:\WINDOWS\system32\DRIVERS\viadsk.sys R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys R1 PQNTDrv;PQNTDrv;C:\WINDOWS\system32\drivers\PQNTDrv.sys R2 BT848;AVerMedia, AVerTV WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;C:\WINDOWS\system32\drivers\BTTUNER.sys R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys R2 GenPort;GenPort;C:\WINDOWS\system32\drivers\GenPort.sys R2 MapMem;MapMem;C:\WINDOWS\system32\drivers\MapMem.sys R2 NTRemap;NTRemap;C:\WINDOWS\system32\drivers\NTRemap.sys R3 adiusbaw;USB ADSL WAN Adapter;C:\WINDOWS\system32\DRIVERS\adiusbaw.sys R3 ALCXSENS;Service for WDM 3D Audio Driver;C:\WINDOWS\system32\drivers\ALCXSENS.SYS R3 axsaki;axsaki;C:\WINDOWS\system32\DRIVERS\axsaki.sys R3 axskbus;axskbus;C:\WINDOWS\system32\DRIVERS\axskbus.sys R3 irsir;Sterownik portu szeregowego podczerwieni Microsoft;C:\WINDOWS\system32\DRIVERS\irsir.sys R3 usbstor;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS R3 vulfnths;VIA USB Host Controller Lower Filter;C:\WINDOWS\system32\Drivers\vulfnth.sys R3 vulfntrs;VIA USB Roothub Lower Filter;C:\WINDOWS\system32\Drivers\vulfntr.sys S2 ADILOADER;General Purpose USB Driver (adildr.sys);C:\WINDOWS\system32\Drivers\adildr.sys S3 ddxgb;ddxgb;??\C:\DOCUME~1\Damian\USTAWI~1\Temp\ddxgb.sys S3 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys S3 k750bus;Sony Ericsson 750 driver (WDM);C:\WINDOWS\system32\DRIVERS\k750bus.sys S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k750mdfl.sys S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k750mdm.sys S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k750mgmt.sys S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k750obex.sys S3 MSIRCOMM;Microsoft IR Communications Driver;C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys S3 SNPP106;PC Camera (6029 CIF);C:\WINDOWS\system32\DRIVERS\snpp106.sys S3 USB_RNDIS;ADI Remote NDIS Network Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys S3 ZDCndis5;ZDCndis5 Protocol Driver;??\C:\WINDOWS\system32\ZDCndis5.SYS S3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver;??\C:\WINDOWS\system32\ZDPNDIS5.SYS S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\ZDPSp50.sys ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-08-01 19:57:21 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden registry entries … [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c] “Order”=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,… scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-08-01 19:58:01 — E O F —
EDIT: Sorry ale z przyzwyczajenia wkleiłem log z Combo do posta :?
qrczak13
(qrczak13)
1 Sierpień 2007 20:52
#4
Domel17
(Malgoska1795 Oficial)
3 Sierpień 2007 21:03
#5