dawidek11
(Dawidex11)
24 Listopad 2007 23:42
#1
Witam mam problem z port’ami usb od noki n95, noki n73 i noki n70 .Dzis chcialem przeslac sobie muze na telefon a tu nic niemozna podlaczyc telefony z kompem , po podlaczeniu nic sie nie pokazuje ani w telefonie ani na kompie. Dodam ze jak wlaczam menadzera uzadzen to mam wszystkie 3 porty zablokowane jak je odblokowuje to pokazane ze sa odblokowane i nic to samo, a jak zrestartuje kompa to w menadzerze uzadzen znow te same pory sa zablokowane nie wiem od czego to sie stalo przeciez niedawno se muze przesylalem podam logi moze to jakas infekcja :?..
Hijack
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:41:17 PM, on 11/24/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Vista Drive Icon\DrvIcon.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe D:\Comodo\Firewall\CPF.exe C:\Program Files\RocketDock\RocketDock.exe C:\Program Files\AveDesk 1.3\AVEDESK.EXE C:\Program Files\LClock\lclock.exe C:\Program Files\Webshots\Webshots.scr C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe D:\Comodo\Firewall\cmdagent.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe D:\eMule\emule.exe C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O4 - HKLM…\Run: [NvCplDaemon] “RUNDLL32.EXE” C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM…\Run: [NvMediaCenter] “RunDLL32.exe” NvMCTray.dll,NvTaskbarInit O4 - HKLM…\Run: [DrvIcon] C:\Program Files\Vista Drive Icon\DrvIcon.exe O4 - HKLM…\Run: [!AVG Anti-Spyware] “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized O4 - HKLM…\Run: [avgnt] “C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe” /min O4 - HKLM…\Run: [COMODO Firewall Pro] “D:\Comodo\Firewall\CPF.exe” /background O4 - HKCU…\Run: [RocketDock] “C:\Program Files\RocketDock\RocketDock.exe” O4 - HKCU…\Run: [AVEDESK] “C:\Program Files\AveDesk 1.3\AVEDESK.EXE” O4 - HKCU…\Run: [LClock] C:\Program Files\LClock\lclock.exe O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O15 - Trusted Zone: http://arcaonline.arcabit.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab O20 - AppInit_DLLs: wbsys.dll O23 - Service: AntiVir PersonalEdition Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe O23 - Service: AntiVir PersonalEdition Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe O23 - Service: AntiVir PersonalEdition Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe O23 - Service: AntiVir PersonalEdition Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe O23 - Service: ##Id_String1 .6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - D:\Comodo\Firewall\cmdagent.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing) – End of file - 5331 bytes
Silent Runners
“Silent Runners.vbs”, revision 52, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “RocketDock” = ““C:\Program Files\RocketDock\RocketDock.exe”” [null data] “AVEDESK” = ““C:\Program Files\AveDesk 1.3\AVEDESK.EXE”” [" Andreas Verhoeven"] “LClock” = “C:\Program Files\LClock\lclock.exe” [null data] HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “NvCplDaemon” = ““RUNDLL32.EXE” C:\WINDOWS\system32\NvCpl.dll,NvStartup” [MS] “NvMediaCenter” = ““RunDLL32.exe” NvMCTray.dll,NvTaskbarInit” [MS] “DrvIcon” = “C:\Program Files\Vista Drive Icon\DrvIcon.exe” [“artArmin”] “!AVG Anti-Spyware” = ““C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized” [“GRISOFT s.r.o.”] “avgnt” = ““C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe” /min” [“Avira GmbH”] “COMODO Firewall Pro” = ““D:\Comodo\Firewall\CPF.exe” /background” [“COMODO”] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM…CLSID} = “Adobe PDF Reader Link Helper” \InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Display Panning CPL Extension” -> {HKLM…CLSID} = “Display Panning CPL Extension” \InProcServer32(Default) = “deskpan.dll” [file not found] “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “HyperTerminal Icon Ext” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”] “{A70C977A-BF00-412C-90B7-034C51DA2439}” = “NvCpl DesktopContext Class” -> {HKLM…CLSID} = “DesktopContext Class” \InProcServer32(Default) = “C:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”] “{1CDB2949-8F65-4355-8456-263E7C208A5D}” = “Desktop Explorer” -> {HKLM…CLSID} = “Desktop Explorer” \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A47}” = “Desktop Explorer Menu” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A48}” = “nView Desktop Context Menu” -> {HKLM…CLSID} = “nView Desktop Context Menu” \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{45AC2688-0253-4ED8-97DE-B5370FA7D48A}” = “Shell Extension for Malware scanning” -> {HKLM…CLSID} = “Shell Extension for Malware scanning” \InProcServer32(Default) = “C:\Program Files\Avira\AntiVir PersonalEdition Premium\shlext.dll” [“Avira GmbH”] “{E0D79304-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79305-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79306-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79307-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{32020A01-506E-484D-A2A8-BE3CF17601C3}” = “AlcoholShellEx” -> {HKLM…CLSID} = “AlcoholShellEx” \InProcServer32(Default) = “D:\alkohol\ALCOHO~1\AXShlEx.dll” [“Alcohol Soft Development Team”] “{FFB699E0-306A-11d3-8BD1-00104B6F7516}” = “Play on my TV helper” -> {HKLM…CLSID} = “NVIDIA CPL Extension” \InProcServer32(Default) = “C:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”] “{611AD258-4138-4348-A534-9856FA6BA398}” = “IconPackager Icon Handler” -> {HKLM…CLSID} = “IPIconHandlerExt Class” \InProcServer32(Default) = “C:\Program Files\Stardock\Object Desktop\IconPackager\shellext.dll” [“Stardock.net , Inc”] “{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}” = “Nokia Phone Browser” -> {HKLM…CLSID} = “Nokia Phone Browser” \InProcServer32(Default) = “C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll” [“Nokia”] “{2F5AC606-70CF-461C-BFE1-734234536262}” = “WindowBlinds CPL Extension” -> {HKLM…CLSID} = “DisplayCplExt Class” \InProcServer32(Default) = “C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbui.dll” [“Stardock.Net , Inc”] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRar\rarext.dll” [null data] “{85E0B171-04FA-11D1-B7DA-00A0C90348D6}” = “Statystyki dla ochrony WWW” -> {HKLM…CLSID} = “Statystyki dla ochrony WWW” \InProcServer32(Default) = “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll” [“Kaspersky Lab”] “{0006F045-0000-0000-C000-000000000046}” = “Microsoft Outlook Custom Icon Handler” -> {HKLM…CLSID} = “Outlook File Icon Extension” \InProcServer32(Default) = “C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL” [MS] “{42042206-2D85-11D3-8CFF-005004838597}” = “Microsoft Office HTML Icon Handler” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Microsoft Office\Office10\msohev.dll” [MS] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ <> “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}” = “AVG Anti-Spyware 7.5” -> {HKLM…CLSID} = “CShellExecuteHookImpl Object” \InProcServer32(Default) = “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [“GRISOFT s.r.o.”] HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ “WPDShServiceObj” = “{AAA288BA-9A4C-45B0-95D7-94D524869DB5}” -> {HKLM…CLSID} = “WPDShServiceObj Class” \InProcServer32(Default) = “C:\WINDOWS\system32\WPDShServiceObj.dll” [MS] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\ <> “AppInit_DLLs” = "wbsys.dll " [“Stardock.Net , Inc”] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ <> klogon\DLLName = “C:\WINDOWS\system32\klogon.dll” [“Kaspersky Lab”] <> WBSrv\DLLName = “C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll” [“Stardock”] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = “PDF Column Info” -> {HKLM…CLSID} = “PDF Shell Extension” \InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ AVG Anti-Spyware(Default) = “{8934FCEF-F5B8-468f-951F-78A921CD3920}” -> {HKLM…CLSID} = “CContextScan Object” \InProcServer32(Default) = “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll” [“GRISOFT s.r.o.”] Kaspersky Anti-Virus(Default) = “{dd230880-495a-11d1-b064-008048ec2fc5}” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\ShellEx.dll” [“Kaspersky Lab”] Shell Extension for Malware scanning(Default) = “{45AC2688-0253-4ED8-97DE-B5370FA7D48A}” -> {HKLM…CLSID} = “Shell Extension for Malware scanning” \InProcServer32(Default) = “C:\Program Files\Avira\AntiVir PersonalEdition Premium\shlext.dll” [“Avira GmbH”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRar\rarext.dll” [null data] WinZip(Default) = “{E0D79304-84BE-11CE-9641-444553540000}” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ AVG Anti-Spyware(Default) = “{8934FCEF-F5B8-468f-951F-78A921CD3920}” -> {HKLM…CLSID} = “CContextScan Object” \InProcServer32(Default) = “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll” [“GRISOFT s.r.o.”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRar\rarext.dll” [null data] WinZip(Default) = “{E0D79304-84BE-11CE-9641-444553540000}” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ Kaspersky Anti-Virus(Default) = “{dd230880-495a-11d1-b064-008048ec2fc5}” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\ShellEx.dll” [“Kaspersky Lab”] Shell Extension for Malware scanning(Default) = “{45AC2688-0253-4ED8-97DE-B5370FA7D48A}” -> {HKLM…CLSID} = “Shell Extension for Malware scanning” \InProcServer32(Default) = “C:\Program Files\Avira\AntiVir PersonalEdition Premium\shlext.dll” [“Avira GmbH”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRar\rarext.dll” [null data] WinZip(Default) = “{E0D79304-84BE-11CE-9641-444553540000}” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “DisableRegistryTools” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|System| Prevent access to registry editing tools} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} “undockwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ “Wallpaper” = “C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp” Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ “Wallpaper” = “C:\Documents and Settings\Albert\Application Data\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp” Startup items in “Albert” & “All Users” startup folders: -------------------------------------------------------- C:\Documents and Settings\Albert\Start Menu\Programs\Startup “Webshots” -> shortcut to: “C:\Program Files\Webshots\Launcher.exe /t” [null data] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000004\LibraryPath = “C:\Program Files\Bonjour\mdnsNSP.dll” [“Apple Computer, Inc.”] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: avsda.dll [“Avira GmbH”], 01 - 02, 22 %SystemRoot%\system32\mswsock.dll [MS], 03 - 05, 08 - 21 %SystemRoot%\system32\rsvpsp.dll [MS], 06 - 07 Toolbars, Explorer Bars, Extensions: ------------------------------------ Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ HKLM\Software\Classes\CLSID{85E0B171-04FA-11D1-B7DA-00A0C90348D6}(Default) = “Statystyki dla ochrony WWW” Implemented Categories{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32(Default) = “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll” [“Kaspersky Lab”] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ AntiVir PersonalEdition Premium Guard, AntiVirService, ““C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe”” [“Avira GmbH”] AntiVir PersonalEdition Premium MailGuard, AntiVirMailService, ““C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe”” [“Avira GmbH”] AntiVir PersonalEdition Premium MailGuard helper service, AVEService, ““C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe”” [“Avira GmbH”] AntiVir PersonalEdition Premium Scheduler, AntiVirScheduler, ““C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe”” [“Avira GmbH”] AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe” [“GRISOFT s.r.o.”] Comodo Application Agent, CmdAgent, “D:\Comodo\Firewall\cmdagent.exe” [“COMODO”] Machine Debug Manager, MDM, ““C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE”” [MS] NVIDIA Display Driver Service, NVSvc, “C:\WINDOWS\system32\nvsvc32.exe” [“NVIDIA Corporation”] ServiceLayer, ServiceLayer, ““C:\Program Files\PC Connectivity Solution\ServiceLayer.exe”” [“Nokia.”] Windows Driver Foundation - User-mode Driver Framework, WudfSvc, “C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup” {“C:\WINDOWS\System32\WUDFSvc.dll” [MS]} Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ HP Standard TCP/IP Port\Driver = “HpTcpMon.dll” [“Hewlett Packard”] PCL hpz3l054\Driver = “hpz3l054.dll” [“Hewlett-Packard Company”] ---------- (launch time: 2007-11-24 23:33:39) <>: Suspicious data at a malware launch point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + The search for DESKTOP.INI DLL launch points on all local fixed drives took 256 seconds. ---------- (total run time: 346 seconds)
Pozdrawiam
Dam jeszcze log z ComoFixa…niemoglem cos wejsc na strone wklej.org wiec wkleje tutaj (chyba sie nie obrazicie )
ComboFix
ComboFix 07-11-19.3 - Albert 2007-11-24 23:48:43.22 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.875 [GMT 0:00] Running from: C:\Documents and Settings\Albert\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2007-10-24 to 2007-11-24 ))))))))))))))))))))))))))))))) . 2007-11-24 10:56 2007-11-23 17:05 2007-11-23 16:56 2007-11-23 16:32 2007-11-22 20:57 2007-11-22 19:14 2007-11-22 19:14 2007-11-22 16:46 86,016 --a------ C:\WINDOWS\unvise32.exe 2007-11-22 16:33 2007-11-22 16:19 2007-11-22 16:19 2007-11-20 20:27 2007-11-20 18:23 139,008 --a------ C:\WINDOWS\system32\guard32.dll 2007-11-18 19:02 2007-11-18 19:01 2007-11-18 19:01 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm 2007-11-17 16:33 2007-11-17 09:55 2007-11-17 09:18 2007-11-17 09:15 2007-11-14 18:31 2007-11-14 18:18 2007-11-14 00:46 10,158,080 --a–c— C:\WINDOWS\system32\dllcache\shell32.dll 2007-11-13 16:24 2007-11-08 15:28 2007-11-07 16:37 2007-11-05 18:18 2007-11-05 18:18 504,913 --a------ C:\WINDOWS\XP Ultimate Uninstaller.exe 2007-11-05 17:12 2007-11-05 17:11 2007-11-05 15:26 2007-11-05 13:19 2007-11-05 13:12 2007-11-05 12:24 2007-11-05 12:07 2007-11-05 09:49 433,664 --a------ C:\WINDOWS\system32\wiaacmgr.backup 2007-11-05 09:49 126,976 --a------ C:\WINDOWS\system32\mshearts.backup 2007-11-05 09:49 35,328 --a------ C:\WINDOWS\system32\winchat.backup 2007-11-05 09:48 589,312 --a------ C:\WINDOWS\system32\wiashext.backup 2007-11-05 09:48 549,888 --a------ C:\WINDOWS\system32\appwiz.backup 2007-11-05 09:48 438,272 --a------ C:\WINDOWS\system32\shimgvw.backup 2007-11-05 09:48 232,960 --a------ C:\WINDOWS\system32\webcheck.backup 2007-11-05 09:48 155,136 --a------ C:\WINDOWS\system32\hdwwiz.backup 2007-11-05 09:48 28,672 --a------ C:\WINDOWS\system32\batmeter.backup 2007-11-05 09:24 8,453,632 --a------ C:\WINDOWS\system32\shell32.backup 2007-11-05 09:24 98,304 --a------ C:\WINDOWS\system32\ahui.backup 2007-11-05 09:24 78,848 --a------ C:\WINDOWS\system32\msiexec.backup 2007-11-05 09:24 55,296 --a------ C:\WINDOWS\system32\freecell.backup 2007-11-05 09:24 49,152 --a------ C:\WINDOWS\rebuild.exe 2007-11-05 09:23 183,808 --a------ C:\WINDOWS\system32\accwiz.backup 2007-11-05 09:20 2007-11-05 09:13 2007-11-04 16:41 2007-11-01 15:39 2007-10-31 23:35 2007-10-31 21:40 2007-10-29 10:55 299,520 --a------ C:\WINDOWS\uninst.exe 2007-10-29 10:42 286,720 --------- C:\WINDOWS\Setup1.exe 2007-10-29 10:42 73,216 --a------ C:\WINDOWS\ST6UNST.EXE 2007-10-27 09:49 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-24 23:58 25,523,488 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat 2007-11-24 23:57 661,792 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat 2007-11-24 23:54 64,112 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx 2007-11-24 23:54 348,008 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2007-11-24 19:53 --------- d-----w C:\Documents and Settings\Albert\Application Data\foobar2000 2007-11-24 13:36 --------- d-----w C:\Program Files\ArcaMicroScan 2007-11-23 19:53 --------- d-----w C:\Program Files\Common Files\Adobe 2007-11-23 19:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2007-11-22 19:01 --------- d-----w C:\Program Files\AnMing 2007-11-22 16:28 --------- d-----w C:\Program Files\AveDesk 1.3 2007-11-21 22:57 --------- d-----w C:\Program Files\RocketDock 2007-11-20 21:47 --------- d-----w C:\Documents and Settings\Albert\Application Data\Comodo 2007-11-20 21:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Comodo 2007-11-17 10:13 --------- d-----w C:\Program Files\PeerGuardian2 2007-11-04 17:46 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-11-03 11:24 --------- d-----w C:\Program Files\Audacity 2007-10-31 23:50 82,061 ----a-w C:\WINDOWS\system32\drivers\klick.dat 2007-10-31 23:50 81,549 ----a-w C:\WINDOWS\system32\drivers\klin.dat 2007-10-20 23:55 --------- d-----w C:\Documents and Settings\Albert\Application Data\AdobeAUM 2007-10-20 20:59 237,568 ----a-w C:\WINDOWS\system32\OggDS.dll 2007-10-20 20:58 921,600 ----a-w C:\WINDOWS\system32\vorbisenc.dll 2007-10-20 20:58 9,216 ----a-w C:\WINDOWS\system32\cpuinf32.dll 2007-10-20 20:58 755,200 ----a-w C:\WINDOWS\system32\ir50_32.dll 2007-10-20 20:58 45,056 ----a-w C:\WINDOWS\system32\ogg.dll 2007-10-20 20:58 188,416 ----a-w C:\WINDOWS\system32\vorbis.dll 2007-10-18 18:16 --------- d-----w C:\Documents and Settings\Albert\Application Data\AdobeUM 2007-10-14 18:54 --------- d-----w C:\Program Files\Webshots 2007-10-14 18:54 --------- d-----w C:\Program Files\Gadu-Gadu 2007-10-14 11:34 --------- d-----w C:\Program Files\SkanerOnline 2007-10-08 19:28 --------- d-----w C:\Program Files\Inno Setup 5 2007-10-07 16:04 --------- d-----w C:\Program Files\EsetOnlineScanner 2007-10-06 20:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype 2007-10-06 20:18 --------- d-----w C:\Program Files\Common Files\snpstd3 2007-10-06 20:17 --------- d-----w C:\Documents and Settings\Albert\Application Data\InstallShield 2007-10-01 13:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2007-09-30 19:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2007-09-30 14:02 --------- d-----w C:\Program Files\RegCleaner 2007-09-29 20:31 --------- d-----w C:\Program Files\Lavasoft 2007-09-28 18:07 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2007-09-28 18:05 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2007-09-28 18:05 739,840 ----a-w C:\WINDOWS\system32\divx.dll 2007-09-28 14:35 --------- d—a-w C:\Documents and Settings\All Users\Application Data\TEMP 2007-09-04 18:56 164,352 ----a-w C:\WINDOWS\system32\unrar.dll 2007-04-11 08:10 476,752 ----a-w C:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe 2007-02-18 18:23 84,418 ----a-w C:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat 2004-09-28 02:00 26,240 ----a-w C:\WINDOWS\inf\RAMDSK.SYS 2007-04-18 17:39 88 --sh–r C:\WINDOWS\system32\300190A549.sys 2007-04-18 17:40 3,140 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “RocketDock”=“C:\Program Files\RocketDock\RocketDock.exe” [2007-03-18 23:05] “AVEDESK”=“C:\Program Files\AveDesk 1.3\AVEDESK.EXE” [2005-10-25 22:44] “LClock”=“C:\Program Files\LClock\lclock.exe” [2004-09-19 18:27] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NvCplDaemon”=“RUNDLL32.exe” [2004-08-04 01:07 C:\WINDOWS\system32\rundll32.exe] “NvMediaCenter”=“RunDLL32.exe” [2004-08-04 01:07 C:\WINDOWS\system32\rundll32.exe] “DrvIcon”=“C:\Program Files\Vista Drive Icon\DrvIcon.exe” [2007-07-04 19:59] “!AVG Anti-Spyware”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-11 09:25] “avgnt”=“C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe” [2007-11-14 18:28] “COMODO Firewall Pro”=“D:\Comodo\Firewall\CPF.exe” [2007-11-20 21:51] C:\Documents and Settings\Albert\Start Menu\Programs\Startup\ Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2007-03-18 14:04:47] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] “DisableRegistryTools”= 0 (0x0) C:\WINDOWS\system32\klogon.dll 2007-06-28 12:51 206088 C:\WINDOWS\system32\klogon.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv] C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2005-12-06 20:16 176128 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll R2 AntiVirMailService;AntiVir PersonalEdition Premium MailGuard;“C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe” R2 AVEService;AntiVir PersonalEdition Premium MailGuard helper service;“C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe” R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys S1 krnl_akl;krnl_akl;??\C:\WINDOWS\system32\drivers\krnl_akl.sys S3 BOCDRIVE;BOClean Kernel Monitor.;??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys S3 MEMSWEEP2;MEMSWEEP2;??\C:\WINDOWS\system32\69.tmp S3 PRODIGY;PRODIGY;C:\WINDOWS\system32\Drivers\PRODIGY.SYS S3 SER120;OTI Serial port driver;C:\WINDOWS\system32\DRIVERS\SER120.sys . ************************************************************************** catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-24 23:59:17 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-25 0:01:25 - machine was rebooted . — E O F —
Dodam ze po uzyciu ComoFix’a komputer sie zrestartowal na zyczenie comofixa
Po uzyciu comofixa w menadzeze urzadzen obok portow noki pokazaly sie zolte wykrzykniki moze jutro przeinstaluje jakos te sterowniki od 3 telefonow moze cos pomoze .
A jak wezme PPM i properties to w informacjach o sterowniku pisze