dawidek11
(Dawidex11)
19 Sierpień 2007 12:33
#1
Wiec mam problem z svchost.exe poniewaz znajduje on sie w "C:\Program Files\Internet Explorer\Setup"i proboje sie caly czas laczyc z internetem poniewaz zonealarm mnie informuje wiec blokuje polaczenie z netem . skanowalem svchost.exe na srtonie virustotal ale tylko jeden antywirus “podejrzewal wirusa” wiec wyslalem go kaspersky zeby przeanalizowali ten plik i jest on wirusem Backdoor.Win32.Agent.arb .
kaspersky skasowal ale musial sie zrestartowac komp zeby sie kasowalo tylko nie jestem pewien czy niemam jeszcze jakiejs infekcji wiec podam ogi z hijack… i silent…
Zgory dzieki.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:22:36 PM, on 8/19/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PSIService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Mixer.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\VistaStart\ViStart.exe C:\Program Files\RocketDock\RocketDock.exe C:\Program Files\Webshots\webshots.scr C:\Program Files\TGTSoft\StyleXP\StyleXP.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.pl/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM…\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM…\Run: [nwiz] “nwiz.exe” /install O4 - HKLM…\Run: [ZoneAlarm Client] “C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe” O4 - HKLM…\Run: [!AVG Anti-Spyware] “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized O4 - HKLM…\Run: [NvCplDaemon] “RUNDLL32.EXE” C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM…\Run: [AVP] “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe” O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU…\Run: [ViStart] C:\Program Files\VistaStart\ViStart O4 - HKCU…\Run: [swg] “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” O4 - HKCU…\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU…\Run: [RocketDock] “C:\Program Files\RocketDock\RocketDock.exe” O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll O15 - Trusted Zone: http://arcaonline.arcabit.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing) O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe – End of file - 4855 bytes
“Silent Runners.vbs”, revision R50, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “ctfmon.exe” = “C:\WINDOWS\system32\ctfmon.exe” [MS] “ViStart” = “C:\Program Files\VistaStart\ViStart” [“Lee Matthew Chantrey & Windows X”] “swg” = ““C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”” [“Google Inc.”] “STYLEXP” = “C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide” [empty string] “RocketDock” = ““C:\Program Files\RocketDock\RocketDock.exe”” [null data] HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “C-Media Mixer” = “Mixer.exe /startup” [“C-Media Electronic Inc. (http://www.cmedia.com.tw )”] “nwiz” = ““nwiz.exe” /install” [“NVIDIA Corporation”] “ZoneAlarm Client” = ““C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe”” [“Zone Labs, LLC”] “!AVG Anti-Spyware” = ““C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized” [“GRISOFT s.r.o.”] “NvCplDaemon” = ““RUNDLL32.EXE” C:\WINDOWS\system32\NvCpl.dll,NvStartup” [MS] “AVP” = ““C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe”” [“Kaspersky Lab”] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM…CLSID} = “AcroIEHlprObj Class” \InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] {AA58ED58-01DD-4d91-8333-CF10577473F7}(Default) = (no title provided) -> {HKLM…CLSID} = “Google Toolbar Helper” \InProcServer32(Default) = “c:\program files\google\googletoolbar2.dll” [“Google Inc.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Display Panning CPL Extension” -> {HKLM…CLSID} = “Display Panning CPL Extension” \InProcServer32(Default) = “deskpan.dll” [file not found] “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “HyperTerminal Icon Ext” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”] “{A70C977A-BF00-412C-90B7-034C51DA2439}” = “NvCpl DesktopContext Class” -> {HKLM…CLSID} = “DesktopContext Class” \InProcServer32(Default) = “C:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”] “{1CDB2949-8F65-4355-8456-263E7C208A5D}” = “Desktop Explorer” -> {HKLM…CLSID} = “Desktop Explorer” \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A47}” = “Desktop Explorer Menu” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A48}” = “nView Desktop Context Menu” -> {HKLM…CLSID} = “nView Desktop Context Menu” \InProcServer32(Default) = “C:\WINDOWS\system32\nvshell.dll” [“NVIDIA Corporation”] “{E0D79304-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79305-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79306-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79307-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “D:\WinZip\rarext.dll” [null data] “{32020A01-506E-484D-A2A8-BE3CF17601C3}” = “AlcoholShellEx” -> {HKLM…CLSID} = “AlcoholShellEx” \InProcServer32(Default) = “D:\alkohol\ALCOHO~1\AXShlEx.dll” [“Alcohol Soft Development Team”] “{85E0B171-04FA-11D1-B7DA-00A0C90348D6}” = “Web Anti-Virus statistics” -> {HKLM…CLSID} = “Web Anti-Virus statistics” \InProcServer32(Default) = “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll” [“Kaspersky Lab”] “{FFB699E0-306A-11d3-8BD1-00104B6F7516}” = “Play on my TV helper” -> {HKLM…CLSID} = “NVIDIA CPL Extension” \InProcServer32(Default) = “C:\WINDOWS\system32\nvcpl.dll” [“NVIDIA Corporation”] “{611AD258-4138-4348-A534-9856FA6BA398}” = “IconPackager Icon Handler” -> {HKLM…CLSID} = “IPIconHandlerExt Class” \InProcServer32(Default) = “C:\Program Files\Stardock\Object Desktop\IconPackager\shellext.dll” [“Stardock.net , Inc”] “{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}” = “Nokia Phone Browser” -> {HKLM…CLSID} = “Nokia Phone Browser” \InProcServer32(Default) = “C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll” [“Nokia”] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\ <> “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}” = “AVG Anti-Spyware 7.5” -> {HKLM…CLSID} = “CShellExecuteHookImpl Object” \InProcServer32(Default) = “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [“GRISOFT s.r.o.”] HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ “WPDShServiceObj” = “{AAA288BA-9A4C-45B0-95D7-94D524869DB5}” -> {HKLM…CLSID} = “WPDShServiceObj Class” \InProcServer32(Default) = “C:\WINDOWS\system32\WPDShServiceObj.dll” [MS] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ <> klogon\DLLName = “C:\WINDOWS\system32\klogon.dll” [“Kaspersky Lab”] <> WRNotifier\DLLName = “WRLogonNTF.dll” [“Webroot Software, Inc.”] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = “PDF Column Info” -> {HKLM…CLSID} = “PDF Shell Extension” \InProcServer32(Default) = “C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ AVG Anti-Spyware(Default) = “{8934FCEF-F5B8-468f-951F-78A921CD3920}” -> {HKLM…CLSID} = “CContextScan Object” \InProcServer32(Default) = “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll” [“GRISOFT s.r.o.”] Kaspersky Anti-Virus(Default) = “{dd230880-495a-11d1-b064-008048ec2fc5}” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\ShellEx.dll” [“Kaspersky Lab”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “D:\WinZip\rarext.dll” [null data] WinZip(Default) = “{E0D79304-84BE-11CE-9641-444553540000}” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ AVG Anti-Spyware(Default) = “{8934FCEF-F5B8-468f-951F-78A921CD3920}” -> {HKLM…CLSID} = “CContextScan Object” \InProcServer32(Default) = “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll” [“GRISOFT s.r.o.”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “D:\WinZip\rarext.dll” [null data] WinZip(Default) = “{E0D79304-84BE-11CE-9641-444553540000}” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ Kaspersky Anti-Virus(Default) = “{dd230880-495a-11d1-b064-008048ec2fc5}” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\ShellEx.dll” [“Kaspersky Lab”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “D:\WinZip\rarext.dll” [null data] WinZip(Default) = “{E0D79304-84BE-11CE-9641-444553540000}” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “DisableRegistryTools” = (REG_DWORD) hex:0x00000000 {User Configuration|Administrative Templates|System| Prevent access to registry editing tools} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} “undockwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ “Wallpaper” = “C:\WINDOWS\web\wallpaper\Bliss.bmp” Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ “Wallpaper” = “C:\WINDOWS\web\wallpaper\Bliss.bmp” Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ “SCRNSAVE.EXE” = “C:\WINDOWS\System32\logon.scr” [MS] Startup items in “Albert” & “All Users” startup folders: -------------------------------------------------------- C:\Documents and Settings\Albert\Start Menu\Programs\Startup “Webshots” -> shortcut to: “C:\Program Files\Webshots\Launcher.exe /t” [null data] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ “{2318C2B1-4965-11D4-9B18-009027A5CD4F}” -> {HKLM…CLSID} = “&Google” \InProcServer32(Default) = “c:\program files\google\googletoolbar2.dll” [“Google Inc.”] HKLM\Software\Microsoft\Internet Explorer\Toolbar\ “{2318C2B1-4965-11D4-9B18-009027A5CD4F}” = (no title provided) -> {HKLM…CLSID} = “&Google” \InProcServer32(Default) = “c:\program files\google\googletoolbar2.dll” [“Google Inc.”] Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ HKLM\Software\Classes\CLSID{85E0B171-04FA-11D1-B7DA-00A0C90348D6}(Default) = “Web Anti-Virus statistics” Implemented Categories{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32(Default) = “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll” [“Kaspersky Lab”] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}\ “ButtonText” = “Web Anti-Virus statistics” Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Ad-Aware 2007 Service, aawservice, ““C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe”” [“Lavasoft AB”] AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe” [“GRISOFT s.r.o.”] Kaspersky Anti-Virus 7.0, AVP, ““C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe” -r” [“Kaspersky Lab”] Machine Debug Manager, MDM, ““C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE”” [MS] NVIDIA Display Driver Service, NVSvc, “C:\WINDOWS\system32\nvsvc32.exe” [“NVIDIA Corporation”] ProtexisLicensing, ProtexisLicensing, “C:\WINDOWS\system32\PSIService.exe” [null data] TrueVector Internet Monitor, vsmon, “C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service” [“Zone Labs, LLC”] Windows Driver Foundation - User-mode Driver Framework, WudfSvc, “C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup” {“C:\WINDOWS\System32\WUDFSvc.dll” [MS]} ---------- <>: Suspicious data at a malware launch point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + The search for DESKTOP.INI DLL launch points on all local fixed drives took 40 seconds. ---------- (total run time: 103 seconds)
Gutek
(Gutek)
19 Sierpień 2007 12:39
#2
Daj log z ComboFix
usuń w trybie awaryjnym folder
dawidek11
(Dawidex11)
19 Sierpień 2007 12:54
#3
Oki teraz bede usowal ten folder w trybie awaryjnym .
Oto log
ComboFix 07-08-14.4 - “Albert” 2007-08-19 13:43:22.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.964 [GMT 1:00] * Created a new restore point ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\Cfx32.lic C:\WINDOWS\system32\cfx32.ocx ((((((((((((((((((((((((( Files Created from 2007-07-19 to 2007-08-19 ))))))))))))))))))))))))))))))) 2007-08-18 23:25 2007-08-18 23:17 2007-08-18 21:42 2007-08-17 17:29 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys 2007-08-16 19:22 2007-08-16 19:22 2007-08-16 11:02 2007-08-13 21:21 2007-08-12 16:47 36 --a------ C:\DOCUME~1\Albert\zestaw.bat 2007-08-08 10:25 2,560 --a------ C:\WINDOWS_MSRSTRT.EXE 2007-08-08 09:01 36,864 --------- C:\WINDOWS\system32\wbsys.dll 2007-08-08 09:01 20,480 --a------ C:\WINDOWS\system32\wbload.dll 2007-08-07 09:42 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys 2007-08-07 08:58 2007-08-06 10:30 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll 2007-08-06 10:30 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll 2007-08-06 10:30 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll 2007-08-06 10:30 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll 2007-08-06 10:30 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll 2007-08-06 10:30 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll 2007-08-06 10:30 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll 2007-08-06 10:30 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll 2007-08-06 10:30 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll 2007-08-06 10:30 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll 2007-08-06 10:30 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll 2007-08-06 10:30 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll 2007-08-06 10:30 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll 2007-08-06 10:30 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll 2007-08-06 10:30 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-08-06 10:30 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll 2007-08-06 10:30 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll 2007-08-06 10:30 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll 2007-08-06 10:30 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll 2007-08-04 19:16 2007-08-04 19:16 2007-08-04 18:39 2007-08-04 18:37 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys 2007-08-04 18:37 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll 2007-08-04 18:37 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys 2007-08-04 18:37 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys 2007-08-04 18:37 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys 2007-08-04 18:27 383,238 --a------ C:\WINDOWS\system32\libmp3lame-0.dll 2007-08-04 18:27 3,086,336 --a------ C:\WINDOWS\system32\NCMedia.dll 2007-08-04 18:27 3,086,336 --a------ C:\WINDOWS\system32\flvvideo.dll 2007-08-04 18:27 2007-08-04 18:11 135,168 --a------ C:\WINDOWS\system32\DSKernel2.dll 2007-08-04 18:11 1,936,528 --a------ C:\WINDOWS\system32\ltmm15.dll 2007-08-04 18:10 2007-08-04 18:07 2007-08-04 17:36 2007-08-03 17:21 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-08-19 13:48 30123552 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2007-08-19 13:46 1300512 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2007-08-19 13:14 --------- d-------- C:\Program Files\VistaStart 2007-08-19 13:08 410324 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx 2007-08-19 13:08 124796 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx 2007-08-18 21:42 --------- d-------- C:\Program Files\RogueRemover 2007-08-16 00:03 --------- d-------- C:\DOCUME~1\Albert\APPLIC~1\ViStart 2007-08-15 23:29 --------- d-------- C:\Program Files\Thoosje Sidebar V2.0 2007-08-15 21:31 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys 2007-08-15 21:31 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys 2007-08-04 18:42 --------- d-------- C:\Program Files\Common Files\PCSuite 2007-08-04 18:42 --------- d-------- C:\Program Files\Common Files\Nokia 2007-08-04 18:36 --------- d-------- C:\Program Files\Nokia 2007-08-04 18:10 737280 --a------ C:\WINDOWS\iun6002.exe 2007-07-19 07:59 3583488 --a–c— C:\WINDOWS\system32\dllcache\mshtml.dll 2007-07-13 00:31 765952 --a–c— C:\WINDOWS\system32\dllcache\vgx.dll 2007-07-11 15:17 --------- d–h----- C:\Program Files\InstallShield Installation Information 2007-07-11 15:17 --------- d-------- C:\Program Files\JPA 2007-07-11 14:10 --------- d-------- C:\Program Files\YzShadow 2007-07-11 13:54 --------- d-------- C:\Program Files\Glass2k 2007-07-11 12:53 --------- d-------- C:\Program Files\RocketDock 2007-07-09 15:31 --------- d-------- C:\Program Files\r2 studios 2007-07-07 18:58 --------- d-------- C:\Program Files\Common Files\Stardock 2007-07-07 10:52 --------- d-------- C:\Program Files\Stardock 2007-07-07 09:26 --------- d-------- C:\DOCUME~1\Albert\APPLIC~1\Gadu-Gadu 2007-07-07 09:20 --------- d-------- C:\Program Files\Gadu-Gadu 2007-07-07 00:34 --------- d-------- C:\Program Files\JLC’s Software 2007-07-04 20:24 --------- d-------- C:\DOCUME~1\Albert\APPLIC~1\PC Suite 2007-07-04 20:22 --------- d-------- C:\DOCUME~1\Albert\APPLIC~1\Nokia 2007-07-04 19:32 --------- d-------- C:\Program Files\ArcaMicroScan 2007-07-02 20:33 82258 --a------ C:\WINDOWS\system32\drivers\klin.dat 2007-07-02 20:33 82258 --a------ C:\WINDOWS\system32\drivers\klick.dat 2007-07-02 20:31 --------- d-------- C:\Program Files\Kaspersky Lab 2007-06-29 21:06 146432 --a–c— C:\WINDOWS\system32\dllcache\regedit.exe 2007-06-29 21:06 146432 --a------ C:\WINDOWS\regedit.exe 2007-06-29 19:00 --------- d-------- C:\Program Files\SkanerOnline 2007-06-28 12:51 206088 --a------ C:\WINDOWS\system32\klogon.dll 2007-06-28 12:50 22457 --a------ C:\WINDOWS\system32\drivers\klop.dat 2007-06-27 15:34 823808 --a–c— C:\WINDOWS\system32\dllcache\wininet.dll 2007-06-27 15:34 671232 --a–c— C:\WINDOWS\system32\dllcache\mstime.dll 2007-06-27 15:34 6058496 -----c— C:\WINDOWS\system32\dllcache\ieframe.dll 2007-06-27 15:34 52224 -----c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2007-06-27 15:34 477696 --a–c— C:\WINDOWS\system32\dllcache\mshtmled.dll 2007-06-27 15:34 459264 -----c— C:\WINDOWS\system32\dllcache\msfeeds.dll 2007-06-27 15:34 44544 --a–c— C:\WINDOWS\system32\dllcache\iernonce.dll 2007-06-27 15:34 384512 --a–c— C:\WINDOWS\system32\dllcache\iedkcs32.dll 2007-06-27 15:34 383488 -----c— C:\WINDOWS\system32\dllcache\ieapfltr.dll 2007-06-27 15:34 27648 --a–c— C:\WINDOWS\system32\dllcache\jsproxy.dll 2007-06-27 15:34 267776 -----c— C:\WINDOWS\system32\dllcache\iertutil.dll 2007-06-27 15:34 232960 --a–c— C:\WINDOWS\system32\dllcache\webcheck.dll 2007-06-27 15:34 230400 --a–c— C:\WINDOWS\system32\dllcache\ieaksie.dll 2007-06-27 15:34 193024 --a–c— C:\WINDOWS\system32\dllcache\msrating.dll 2007-06-27 15:34 153088 --a–c— C:\WINDOWS\system32\dllcache\ieakeng.dll 2007-06-27 15:34 132608 --a–c— C:\WINDOWS\system32\dllcache\extmgr.dll 2007-06-27 15:34 124928 --a–c— C:\WINDOWS\system32\dllcache\advpack.dll 2007-06-27 15:34 1152000 --a–c— C:\WINDOWS\system32\dllcache\urlmon.dll 2007-06-27 15:34 105984 --a–c— C:\WINDOWS\system32\dllcache\url.dll 2007-06-27 15:34 102400 --a–c— C:\WINDOWS\system32\dllcache\occache.dll 2007-06-27 09:27 63488 --a–c— C:\WINDOWS\system32\dllcache\ie4uinit.exe 2007-06-27 09:27 625152 --a–c— C:\WINDOWS\system32\dllcache\iexplore.exe 2007-06-27 09:27 13824 -----c— C:\WINDOWS\system32\dllcache\ieudinit.exe 2007-06-27 08:00 161792 --a–c— C:\WINDOWS\system32\dllcache\ieakui.dll 2007-06-26 20:55 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll 2007-06-26 07:08 1104896 --a–c— C:\WINDOWS\system32\dllcache\msxml3.dll 2007-06-26 07:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll 2007-06-24 15:04 --------- d-------- C:\Program Files\Winamp 2007-06-24 15:04 --------- d-------- C:\Program Files\Webshots 2007-06-24 15:03 --------- d-------- C:\Program Files\Google 2007-06-24 10:14 --------- d-------- C:\Program Files\Common Files\Borland Shared 2007-06-24 10:13 --------- d-------- C:\Program Files\Borland 2007-06-22 22:09 --------- d-------- C:\Program Files\NKProds 2007-06-22 09:47 --------- d-------- C:\Program Files\Eusing Free Registry Cleaner 2007-06-19 14:31 282112 --a–c— C:\WINDOWS\system32\dllcache\gdi32.dll 2007-06-19 14:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll 2007-06-17 00:11 51200 --a------ C:\WINDOWS\nircmd.exe 2007-06-13 11:23 1033216 --a–c— C:\WINDOWS\system32\dllcache\explorer.exe 2007-06-13 11:23 1033216 --a------ C:\WINDOWS\explorer.exe 2007-06-11 23:51 10834944 --a–c— C:\WINDOWS\system32\dllcache\wmp.dll 2007-06-08 08:11 831048 --a------ C:\WINDOWS\system32\WudfUpdate_01005.dll 2004-09-28 03:00 26240 --a------ C:\WINDOWS\inf\RAMDSK.SYS 2007-04-18 17:39:31 88 --sh–r C:\WINDOWS\system32\300190A549.sys 2007-04-18 17:40:14 3,140 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “C-Media Mixer”=“Mixer.exe” [2002-10-15 19:00 C:\WINDOWS\mixer.exe] “nwiz”=“nwiz.exe” [2005-10-10 14:49 C:\WINDOWS\system32\nwiz.exe] “ZoneAlarm Client”=“C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe” [2007-03-09 01:02] “!AVG Anti-Spyware”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-14 15:06] “NvCplDaemon”=“RUNDLL32.exe” [2004-08-04 02:07 C:\WINDOWS\system32\rundll32.exe] “AVP”=“C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe” [2007-06-28 12:51] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 02:07] “ViStart”=“C:\Program Files\VistaStart\ViStart” [] “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-08-06 09:39] “STYLEXP”=“C:\Program Files\TGTSoft\StyleXP\StyleXP.exe” [2006-05-24 19:31] “RocketDock”=“C:\Program Files\RocketDock\RocketDock.exe” [2007-03-19 00:05] C:\Documents and Settings\Albert\Start Menu\Programs\Startup\ Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2007-03-18 15:04:47] R0 a347bus;a347bus;C:\WINDOWS\system32\DRIVERS\a347bus.sys R0 a347scsi;a347scsi;C:\WINDOWS\system32\Drivers\a347scsi.sys R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys S0 szkg;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys S3 MEMSWEEP2;MEMSWEEP2;??\C:\WINDOWS\system32\69.tmp S3 PRODIGY;PRODIGY;C:\WINDOWS\system32\Drivers\PRODIGY.SYS S3 SER120;OTI Serial port driver;C:\WINDOWS\system32\DRIVERS\SER120.sys S3 UsbDiag;LGE Mobile USB Serial Port;C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-08-19 13:47:25 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-08-19 13:50:11 C:\ComboFix-quarantined-files.txt … 2007-08-19 13:50 — E O F —
Gutek
(Gutek)
19 Sierpień 2007 13:00
#4
Czy usunięty został folder?
dawidek11
(Dawidex11)
19 Sierpień 2007 13:10
#5
Tak.
Dziekuje Bardzo :jupi:
Czy to juz wszystko?
Aha mam jeszcze pytanie: Mialem spyware doctor ale odinstalowalem bo mi sie cial kompbo mialem 512ramu wiec zainstalowalem spy sweeper ale kupilem sobie ramu 1gb i czy zainstalowac spyware doctor??Ktory lepszy?
dawidek11
(Dawidex11)
20 Sierpień 2007 00:17
#7
Mam jeszcze jedno pytanie dlaczego jak czsami otwieram wwdc to port 135 mam otwarty i jak go zamykam to i tak po 1 dniu znow jest otwarty ,uzywam rowniez Seconfig XP moze jakis backdoor otwiera mi ten port.
Zgory dzieki. ;]
Gutek
(Gutek)
20 Sierpień 2007 12:36
#8
Na pewno dobrze zamykasz? Windows Worms Doors Cleanera zmień znaczki z disable na enable. Po użyciu tego narzędzia wymagany jest reset sysa.
Dokończyć skanerami online - Skanery do wyboru i wrzuć wyniki skanu