Z tym combofix to ciekawa sprawa bo zeskanował mi kompa i usunął coś lub całość do logowania za pomocą odciska palca.teraz już mi to nie działa(nie ma oprogramowania) ale mniejsza z tym o to log z combofix:
ComboFix 08-04-22.5 - diablo-82 2008-04-24 18:08:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1483 [GMT 2:00]
Running from: C:\Documents and Settings\diablo-82\Pulpit\download\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\diablo-82\Dane aplikacji\inst.exe
C:\Program Files\Bioscrypt\VeriSoft\Bin\ASWLNPkg.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASBroker
-------\Service_ASBroker
((((((((((((((((((((((((( Files Created from 2008-03-24 to 2008-04-24 )))))))))))))))))))))))))))))))
.
2008-04-24 17:41 . 2008-04-24 17:41
2008-04-20 15:13 . 2008-04-21 20:10
2008-04-20 14:54 . 2008-04-24 14:25
2008-04-20 14:54 . 2008-04-20 15:32
2008-04-20 14:54 . 2008-04-20 14:54 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-04-20 14:54 . 2008-04-20 14:54 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-04-20 14:54 . 2008-04-20 14:54 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-04-20 14:54 . 2008-04-20 14:54 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-04-20 14:53 . 2008-04-20 14:53
2008-04-20 14:53 . 2008-04-20 14:53
2008-04-20 11:07 . 2008-04-20 11:09
2008-04-20 11:07 . 2008-04-20 11:07
2008-04-20 11:07 . 2008-04-20 11:07
2008-04-20 11:07 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-04-20 11:07 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-04-20 11:07 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-04-20 11:07 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-04-20 11:07 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-04-19 21:02 . 2008-04-19 21:02
2008-04-19 21:02 . 2008-04-19 21:02
2008-04-14 22:49 . 2008-04-14 22:49
2008-04-14 22:49 . 2008-04-15 18:43 246 --ah----- C:\WINDOWS\sysreg.dat
2008-04-13 15:32 . 2008-04-13 15:39
2008-04-13 15:31 . 2008-04-13 15:53
2008-04-09 22:49 . 2008-04-09 23:04
2008-04-09 22:49 . 2008-04-09 22:49 94,208 --a------ C:\WINDOWS\system32\drivers\ezplay.sys
2008-04-09 22:49 . 2008-04-09 23:04 94,208 --a------ C:\Documents and Settings\diablo-82\Dane aplikacji\ezplay.sys
2008-04-09 22:49 . 2008-04-09 22:49 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-04-09 22:49 . 2008-04-09 23:04 47,360 --a------ C:\Documents and Settings\diablo-82\Dane aplikacji\pcouffin.sys
2008-04-09 21:37 . 2008-04-09 21:37
2008-04-09 21:34 . 2008-04-24 18:10
2008-04-09 21:34 . 2008-04-09 21:36
2008-04-09 21:34 . 2008-02-07 20:18
2008-04-09 21:34 . 2008-02-07 21:08
2008-04-09 21:34 . 2008-04-09 21:37
2008-04-09 21:34 . 2008-02-07 21:08
2008-04-09 21:34 . 2008-04-09 21:35
2008-04-09 21:34 . 2008-04-20 14:54
2008-04-09 21:34 . 2008-04-24 18:08 1,024 --ah----- C:\Documents and Settings\Administrator\NtUser.dat.LOG
2008-04-09 21:18 . 2008-04-09 21:18
2008-04-09 20:17 . 2008-04-09 20:17
2008-04-09 20:17 . 2008-04-09 20:17
2008-04-09 20:10 . 2008-04-09 20:10
2008-04-08 23:06 . 2008-04-08 23:06
2008-04-06 17:25 . 2008-04-06 17:25
2008-04-06 17:03 . 2008-04-06 17:03
2008-04-06 14:25 . 2008-04-06 14:26
2008-04-06 11:08 . 2008-04-06 11:08
2008-04-06 11:06 . 2008-04-06 11:06
2008-04-06 11:06 . 2008-04-06 11:06
2008-04-06 11:06 . 2008-04-06 11:06
2008-04-06 11:06 . 2006-07-11 21:55 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-04-06 11:06 . 2008-04-24 18:14 2,410 --a------ C:\hpqp.ini
2008-04-06 11:06 . 2008-04-24 18:13 39 --a------ C:\XP_TV.ini
2008-04-05 20:49 . 2008-04-20 15:16
2008-04-05 20:12 . 2008-04-05 20:12
2008-04-05 20:12 . 2008-04-05 20:12
2008-04-05 16:39 . 2007-08-16 00:33 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-04-05 16:39 . 2007-08-16 00:33 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2008-04-03 22:54 . 2008-04-03 22:54
2008-04-02 21:29 . 2008-04-02 21:29
2008-04-02 16:07 . 2004-08-04 00:44 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-02 16:07 . 1998-08-27 06:51 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2008-04-02 16:07 . 1998-08-20 13:02 140,800 --a------ C:\WINDOWS\system32\tm20dec.ax
2008-04-02 16:07 . 1998-09-02 10:28 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe
2008-04-02 16:07 . 1998-09-02 10:28 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2008-04-02 16:06 . 1998-09-02 10:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2008-04-02 16:06 . 1998-08-17 11:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2008-04-02 16:06 . 1998-08-17 11:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2008-04-02 16:06 . 1998-08-17 11:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2008-04-02 16:06 . 2008-04-02 16:06 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2008-04-02 16:06 . 2008-04-02 16:06 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2008-04-02 16:02 . 2008-04-02 16:18
2008-04-01 21:35 . 2002-03-11 18:10 90,112 --a------ C:\WINDOWS\cgmopenbho.2
2008-04-01 21:34 . 2008-04-01 21:34
2008-04-01 21:34 . 2008-04-01 21:34
2008-04-01 21:34 . 2001-04-06 08:11 118,784 --a------ C:\WINDOWS\system32\spnsrvnt.exe
2008-04-01 21:34 . 2001-04-06 08:11 73,216 --a------ C:\WINDOWS\system32\drivers\SENTINEL.SYS
2008-04-01 21:34 . 2001-04-06 08:11 49,152 --a------ C:\WINDOWS\system32\SNTI386.DLL
2008-04-01 21:34 . 2001-04-06 08:11 9,949 --------- C:\WINDOWS\system32\SENTINEL.HLP
2008-04-01 21:33 . 2008-04-01 21:36
2008-04-01 20:59 . 2002-03-11 18:10 90,112 --a------ C:\WINDOWS\cgmopenbho.1
2008-04-01 18:47 . 2008-04-01 18:52
2008-04-01 18:08 . 1998-05-07 10:57 143,872 --a------ C:\WINDOWS\system32\iacenc.dll
2008-04-01 17:38 . 2008-04-01 17:38
2008-04-01 17:38 . 2008-04-01 17:38
2008-03-31 23:25 . 2008-03-31 23:25 831,488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 23:25 . 2008-03-31 23:25 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 23:25 . 2008-03-31 23:25 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 23:25 . 2008-03-31 23:25 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 23:25 . 2008-03-31 23:25 682,496 --a------ C:\WINDOWS\system32\DivX.dll
2008-03-31 23:25 . 2008-03-31 23:25 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-30 22:01 . 2008-03-30 22:01 0 --a------ C:\WINDOWS\frontend.INI
2008-03-30 21:48 . 2008-04-01 21:40 914 --a------ C:\WINDOWS\ODBC.INI
2008-03-30 21:44 . 2008-04-24 18:12
2008-03-30 21:43 . 1997-04-08 20:08 299,520 --a------ C:\WINDOWS\uninst.exe
2008-03-30 21:43 . 2002-08-28 14:42 10,752 --a------ C:\WINDOWS\system32\testfile.doc
2008-03-30 21:33 . 2002-03-21 08:26 115,200 --a------ C:\WINDOWS\system32\HMPCab.dll
2008-03-29 22:20 . 2008-03-29 22:47
2008-03-29 22:07 . 2008-03-29 22:07
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-24 16:14 --------- d-----w C:\Documents and Settings\diablo-82\Dane aplikacji\Skype
2008-04-24 16:07 --------- d—a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-04-24 15:44 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-04-24 15:37 --------- d-----w C:\Documents and Settings\diablo-82\Dane aplikacji\uTorrent
2008-04-24 12:30 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-23 17:23 --------- d-----w C:\Documents and Settings\diablo-82\Dane aplikacji\skypePM
2008-04-19 19:30 --------- d-----w C:\Program Files\English Translator 3
2008-04-19 19:02 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-04-09 19:12 --------- d-----w C:\Program Files\Restorator 2007
2008-04-09 19:12 --------- d-----w C:\Program Files\Pitagoras 2000
2008-04-09 18:41 --------- d-----w C:\Program Files\DivX
2008-04-08 20:05 --------- d-----w C:\Documents and Settings\diablo-82\Dane aplikacji\Tlen.pl
2008-04-06 09:05 --------- d-----w C:\Program Files\Hp
2008-04-06 07:52 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-04-05 19:53 --------- d-----w C:\Program Files\Winamp
2008-04-05 19:52 --------- d-----w C:\Documents and Settings\diablo-82\Dane aplikacji\Winamp
2008-04-05 15:33 --------- d-----w C:\Program Files\Codec Pack - All In 1
2008-03-31 20:20 --------- d-----w C:\Program Files\Call of Duty
2008-03-22 15:26 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-18 16:06 --------- d-----w C:\Documents and Settings\diablo-82\Dane aplikacji\AD ON Multimedia
2008-03-18 16:03 --------- d-----w C:\Program Files\CDex_150
2008-03-17 09:13 --------- d-----w C:\Program Files\Java
2008-03-17 09:11 --------- d-----w C:\Program Files\Common Files\Java
2008-03-16 18:27 --------- d-----w C:\Program Files\uTorrent
2008-03-13 18:28 57,344 ------w C:\WINDOWS\system32\sol.exe
2008-03-13 13:51 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-03-13 13:51 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-03-13 13:49 --------- d-----w C:\Program Files\Futuremark
2008-03-13 10:16 --------- d-----w C:\Program Files\CPUMon
2008-03-06 14:29 --------- d-----w C:\Program Files\Lexmark X5100 Series
2008-03-02 15:13 --------- d-----w C:\Program Files\Common Files\BinarySense
2008-03-02 14:43 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Bluetooth
2008-03-02 12:44 --------- d-----w C:\Program Files\IVT Corporation
2008-03-02 09:20 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Hagel Technologies
2008-02-28 20:22 --------- d-----w C:\Program Files\NAPI-PROJEKT
2008-02-24 18:40 --------- d-----w C:\Documents and Settings\diablo-82\Dane aplikacji\BinarySense
2008-02-24 14:59 --------- d-----w C:\Documents and Settings\diablo-82\Dane aplikacji\Corel
2008-02-13 18:29 164 ----a-w C:\install.dat
2008-02-09 20:26 2,516 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-02-07 20:11 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2008-02-07 19:40 737,280 ----a-w C:\WINDOWS\iun6002.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-04-20 14:54 2051328 --a------ C:\PROGRA~1\AVG\AVG8\avgtoolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
“{A057A204-BACC-4D26-9990-79A187E2698E}”= “C:\PROGRA~1\AVG\AVG8\avgtoolbar.dll” [2008-04-20 14:54 2051328]
[HKEY_CLASSES_ROOT\clsid{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
“{A057A204-BACC-4D26-9990-79A187E2698E}”= C:\PROGRA~1\AVG\AVG8\avgtoolbar.dll [2008-04-20 14:54 2051328]
[HKEY_CLASSES_ROOT\clsid{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\CFi]
@={2DBD5D71-CBB7-41D1-B170-511646B170BD}
[HKEY_CLASSES_ROOT\CLSID{2DBD5D71-CBB7-41D1-B170-511646B170BD}]
2008-02-25 15:22 55296 --a------ C:\PROGRA~1\CFi\SHELLT~1\CFiShlJP.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-11-12 16:51 21877544]
“Komunikator”=“C:\Program Files\Tlen.pl\tlen.exe” [2007-12-07 12:16 6254592]
“CFi ShellToys Utility Manager”=“C:\Program Files\CFi\ShellToys\CFiShlMan.exe” [2008-02-25 15:22 44032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“QlbCtrl”=“C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe” [2007-02-13 12:38 159744]
“CognizanceTS”=“rundll32.exe” [2004-08-04 00:44 33280 C:\WINDOWS\system32\rundll32.exe]
“TweakMASTER”=“C:\PROGRA~1\TWEAKM~1\TMTray.exe” [2006-11-27 16:26 284712]
“QPService”=“C:\Program Files\HP\QuickPlay\QPService.exe” [2006-07-11 21:55 102400]
“AVG8_TRAY”=“C:\PROGRA~1\AVG\AVG8\avgtray.exe” [2008-04-20 14:54 1177368]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2007-08-07 19:21 8462336]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{067B597C-C099-4A08-A180-E5FEC5DCF2DF}”= C:\PROGRA~1\CFi\SHELLT~1\CFiShlEx.dll [2008-02-25 15:22 43008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=APSHook.dll,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“vidc.iv31”= C:\WINDOWS\system32\ir32_32.dll
“vidc.iv32”= C:\WINDOWS\system32\ir32_32.dll
“msacm.l3acm”= l3codecp.acm
“vidc.DIV3”= DivXc32.dll
“vidc.DIV4”= DivXc32f.dll
“vidc.XVID”= xvid.dll
“VIDC.HFYU”= huffyuv.dll
“msacm.divxa32”= DivXa32.acm
“msacm.lameacm”= LameACM.dll
“vidc.3ivx”= 3ivxVfWCodec.dll
“SENTINEL”= snti386.dll
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^diablo-82^Menu Start^Programy^Autostart^HDDlife.lnk]
path=C:\Documents and Settings\diablo-82\Menu Start\Programy\Autostart\HDDlife.lnk
backup=C:\WINDOWS\pss\HDDlife.lnkStartup
[HKLM~\startupfolder\C:^Documents and Settings^diablo-82^Menu Start^Programy^Autostart^Rejestrowanie produktów Corela.lnk]
path=C:\Documents and Settings\diablo-82\Menu Start\Programy\Autostart\Rejestrowanie produktów Corela.lnk
backup=C:\WINDOWS\pss\Rejestrowanie produktów Corela.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a------ 2007-10-23 15:18 202024 C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a------ 2004-08-04 00:44 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DU Meter]
C:\Program Files\DU Meter\DUMeter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
–a------ 2006-10-27 01:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
–a------ 2006-07-27 15:44 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a------ 2005-02-17 00:11 49152 c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
–a------ 2007-10-03 16:15 480560 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a------ 2005-08-11 17:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a------ 2005-08-11 17:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]
–a------ 2006-07-13 07:33 57344 C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X5100 Series]
–a------ 2003-03-04 15:03 86099 C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
–a------ 2007-08-23 18:36 455968 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LinkScanner Monitor]
–a------ 2007-11-25 18:31 1967384 C:\Program Files\ExPLabs.com\LinkScanner\LinkScannerMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
–a------ 2007-09-20 09:51 1836328 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a------ 2004-08-04 00:44 33280 C:\WINDOWS\system32\rundll32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a------ 2007-08-07 19:21 81920 C:\WINDOWS\system32\NVMCTRAY.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a------ 2007-08-07 19:22 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
–a------ 2008-01-04 21:56 5367664 C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
–a------ 2007-09-14 20:29 102400 C:\Program Files\Synaptics\SynTP\SynTPStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
–a------ 2008-04-07 19:51 873040 C:\Program Files\Trojan Remover\Trjscan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Twoje TVN24]
C:\Program Files\Pasek TVN24\tvn-ustawienia.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a------ 2008-03-27 08:35 36352 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusDisableNotify”=dword:00000001
“UpdatesDisableNotify”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Tlen.pl\tlen.exe”=
“C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE”=
“C:\Program Files\Microsoft Office\Office12\GROOVE.EXE”=
“C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE”=
“C:\Program Files\uTorrent\uTorrent.exe”=
“C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files\Kaspersky Internet Security 7.0.1.321\Polish\setup.exe”=
“C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe”=
“C:\Program Files\Mozilla Firefox\firefox.exe”=
“C:\Program Files\AVG\AVG8\avgupd.exe”=
“C:\Program Files\AVG\AVG8\avgemc.exe”=
“C:\Program Files\AVG\AVG8\avgnsx.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“3389:TCP”= 3389:TCP:@xpsp2res.dll,-22009
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-04-20 14:54]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-20 14:54]
R2 ASChannel;Local Communication Channel;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:44]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-20 14:54]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-20 14:53]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-04-20 14:54]
R2 COSIDS_TB;COSIDS_TB;C:\PROGRA~1\COSIDS\BIN\TbMux32.exe [2001-11-20 15:37]
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-11-14 12:04]
S3 mirrorv3;mirrorv3;C:\WINDOWS\system32\DRIVERS\rminiv3.sys [2006-11-01 06:01]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
“C:\Program Files\Common Files\LightScribe\LSRunOnce.exe”
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-24 18:13:19
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
folder error: C:\DOCUME~1\DIABLO~1\USTAWI~1\Temp\
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
- C:\Program Files\Tlen.pl\hook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\PROGRA~1\cosids\APACHE~1\Apache\ApchT2kW.exe
C:\PROGRA~1\cosids\APACHE~1\Apache\ApchT2kW.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\Java\JRE16~1.0_0\bin\java.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-04-24 18:17:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-24 16:17:03
Pre-Run: 64,691,802,112 bajtów wolnych
Post-Run: 64,676,061,184 bajt˘w wolnych
363
W dniu 24.04.2008 , o godzinie 19:43 został dopisany post przez diablo-82
No i czy ktoś coś widzi nie pożądanego w tych dwóch log-ach? Proszę o możliwie szybką odpowiedź. Czy może problem nie tkwi w zainfekowaniu?