jak przeskanowałem to teraz jest wszystko OK dzięki nie wiem co ten program zrobił ale dzięki
Złączono Posta : 06.11.2007 (Wto) 19:56
JEDNAK NIE musiałem sie cofnąć w czasie bo mi pozmieniało kilka rzeczy nad którymi dużo siedziałem a oto log:
ComboFix 07-11-06.4 - komputer 2007-11-06 18:41:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1630 [GMT 1:00]
Running from: E:\download\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2007-10-06 to 2007-11-06 )))))))))))))))))))))))))))))))
.
2007-11-06 18:41 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 17:51
2007-11-06 17:45 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2007-11-06 17:45 59,264 --a–c— C:\WINDOWS\system32\dllcache\usbaudio.sys
2007-11-06 17:44 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-11-06 17:44 31,616 --a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-11-06 14:16
2007-11-06 13:27
2007-11-06 13:27
2007-11-06 13:24 0 --a------ C:\WINDOWS\nsreg.dat
2007-11-06 13:18 21,035 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2007-11-06 13:16 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-11-06 13:16 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-11-06 13:16 740,442 --a------ C:\WINDOWS\system32\divx.dll
2007-11-06 13:16 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-11-06 13:16 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-11-06 13:16 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2007-11-06 13:16 163,840 --a------ C:\WINDOWS\system32\unrar.dll
2007-11-06 13:16 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-11-06 13:16 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-11-06 13:14
2007-11-06 13:04
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-06 12:20 --------- d–h--w C:\Program Files\InstallShield Installation Information
2007-11-06 11:59 682,232 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-11-06 10:48 --------- d-----w C:\Program Files\Realtek
2007-11-06 10:47 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-06 10:44 --------- d-----w C:\Documents and Settings\komputer\Dane aplikacji\InstallShield
2007-11-06 10:29 --------- d-----w C:\Program Files\microsoft frontpage
2007-11-06 10:27 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“RTHDCPL”=“RTHDCPL.EXE” [2006-11-14 10:21 C:\WINDOWS\RTHDCPL.exe]
“SkyTel”=“SkyTel.EXE” [2006-05-16 11:04 C:\WINDOWS\SkyTel.exe]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2007-04-19 13:26]
“nwiz”=“nwiz.exe” [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe]
“NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2007-04-19 13:26]
“LVCOMSX”=“C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe” [2006-06-26 10:33]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“DAEMON Tools”=“C:\progamy moje\DAEMON Tools\daemon.exe” [2007-04-03 23:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
“NoSMHelp”=1 (0x1)
“NoWelcomeScreen”=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoRecentDocsMenu”=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^NETGEAR WG111v2 Smart Wizard.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\NETGEAR WG111v2 Smart Wizard.lnk
backup=C:\WINDOWS\pss\NETGEAR WG111v2 Smart Wizard.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WheelMouse]
c:\progamy moje\mysz\Amoumain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\progamy moje\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
“wuauserv”=2 (0x2)
“wscsvc”=2 (0x2)
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys
*Newly Created Service* - CATCHME
*Newly Created Service* - LVPR2MON
*Newly Created Service* - LVPRCSRV
*Newly Created Service* - LVSRVLAUNCHER
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-06 18:42:40
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-06 18:43:05
.
— E O F —