Wstawiam LOGa z COMBOFIXa
ComboFix 09-01-21.04 - MNK 2009-01-30 0:04:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1535.979 [GMT 1:00]
Uruchomiony z: d:\documents and settings\MNK\Pulpit\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated)
FW: Zapora osobista *enabled*
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\windows\system32\Cache
.
((((((((((((((((((((((((( Pliki utworzone od 2008-12-28 do 2009-01-29 )))))))))))))))))))))))))))))))
.
2009-01-23 11:40 . 2009-01-23 11:40
2009-01-22 09:58 . 2009-01-22 11:57
2009-01-22 09:18 . 2009-01-22 09:18
2009-01-22 09:18 . 2009-01-22 09:18
2009-01-22 09:18 . 2009-01-22 09:18 361,728 --a------ d:\windows\system32\TuneUpDefragService.exe
2009-01-22 09:18 . 2008-07-18 15:05 28,416 --a------ d:\windows\system32\uxtuneup.dll
2009-01-22 09:16 . 2009-01-22 09:16
2009-01-21 08:50 . 2001-08-18 06:36 8,704 --a------ d:\windows\system32\kbdjpn.dll
2009-01-21 08:50 . 2001-08-18 06:36 8,704 --a–c— d:\windows\system32\dllcache\kbdjpn.dll
2009-01-21 08:50 . 2001-08-18 06:36 8,192 --a------ d:\windows\system32\kbdkor.dll
2009-01-21 08:50 . 2001-08-18 06:36 8,192 --a–c— d:\windows\system32\dllcache\kbdkor.dll
2009-01-21 08:50 . 2001-08-17 22:55 6,144 --a------ d:\windows\system32\kbd106.dll
2009-01-21 08:50 . 2001-08-17 22:55 6,144 --a------ d:\windows\system32\kbd101c.dll
2009-01-21 08:50 . 2001-08-17 22:55 6,144 --a------ d:\windows\system32\kbd101b.dll
2009-01-21 08:50 . 2001-08-17 22:55 6,144 --a–c— d:\windows\system32\dllcache\kbd106.dll
2009-01-21 08:50 . 2001-08-17 22:55 6,144 --a–c— d:\windows\system32\dllcache\kbd101c.dll
2009-01-21 08:50 . 2001-08-17 22:55 6,144 --a–c— d:\windows\system32\dllcache\kbd101b.dll
2009-01-21 08:50 . 2001-08-17 22:55 5,632 --a------ d:\windows\system32\kbd103.dll
2009-01-21 08:50 . 2001-08-17 22:55 5,632 --a–c— d:\windows\system32\dllcache\kbd103.dll
2009-01-21 08:02 . 2008-03-03 18:21 568 --ah----- d:\windows\nod32fixtemdono.reg
2009-01-21 08:01 . 2009-01-21 08:01
2009-01-14 07:57 . 2009-01-14 07:57
2009-01-14 07:57 . 2009-01-14 07:57
2009-01-14 07:55 . 2009-01-14 07:55 0 --ah----- d:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-01-14 07:55 . 2009-01-14 07:55 0 --ah----- d:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-01-14 07:54 . 2009-01-14 07:54
2009-01-14 07:54 . 2009-01-14 07:54
2009-01-14 07:54 . 2007-11-15 10:06 301,656 --a------ d:\windows\system32\BtCoreIf.dll
2009-01-14 07:54 . 2007-11-15 10:07 170,512 --a------ d:\windows\system32\kemutb.dll
2009-01-14 07:54 . 2007-11-15 10:07 141,840 --a------ d:\windows\system32\KemUtil.dll
2009-01-14 07:54 . 2007-11-15 10:07 117,264 --a------ d:\windows\system32\KemWnd.dll
2009-01-14 07:54 . 2007-11-15 10:07 76,304 --a------ d:\windows\system32\KemXML.dll
2009-01-12 15:32 . 2009-01-12 15:32
2009-01-12 15:31 . 2009-01-20 22:59
2009-01-12 01:27 . 2009-01-12 01:30
2008-12-31 10:34 . 2009-01-02 15:19 770 --a------ d:\windows\Sof2.INI
2008-12-30 01:39 . 2008-12-30 01:40 5,460 --a------ d:\windows\BricoPackFoldersDelete.cmd
2008-12-29 15:34 . 2008-12-29 15:34
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-29 23:01 --------- d-----w d:\documents and settings\MNK\Dane aplikacji\uTorrent
2009-01-29 19:42 --------- d-----w d:\documents and settings\MNK\Dane aplikacji\Tlen.pl
2009-01-14 06:54 --------- d–h--w d:\program files\InstallShield Installation Information
2009-01-14 06:54 --------- d-----w d:\program files\Common Files\Logishrd
2008-12-30 00:40 70,537 ----a-w d:\windows\BricoPackUninst.cmd
2008-12-28 00:42 --------- d-----w d:\program files\Image-Line
2008-12-28 00:03 --------- d—a-w d:\documents and settings\All Users\Dane aplikacji\TEMP
2008-12-27 11:56 --------- d-----w d:\program files\VstPlugins
2008-12-27 11:55 --------- d-----w d:\program files\Outsim
2008-12-26 18:38 --------- d-----w d:\documents and settings\MNK\Dane aplikacji\Hamachi
2008-12-26 18:34 25,280 ----a-w d:\windows\system32\drivers\hamachi.sys
2008-12-26 17:56 --------- d-----w d:\documents and settings\All Users\Dane aplikacji\FlashFXP
2008-12-23 18:24 410,984 ----a-w d:\windows\system32\deploytk.dll
2008-12-23 18:24 --------- d-----w d:\program files\Java
2008-12-22 09:04 --------- d-----w d:\documents and settings\MNK\Dane aplikacji\PC Suite
2008-12-22 09:04 --------- d-----w d:\documents and settings\MNK\Dane aplikacji\Nokia
2008-12-22 09:03 0 —ha-w d:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-22 09:03 0 —ha-w d:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-12-22 09:03 --------- d-----w d:\documents and settings\All Users\Dane aplikacji\PC Suite
2008-12-22 09:01 --------- d-----w d:\program files\Common Files\PCSuite
2008-12-22 09:01 --------- d-----w d:\program files\Common Files\Nokia
2008-12-22 09:01 --------- d-----w d:\documents and settings\All Users\Dane aplikacji\Installations
2008-12-22 09:00 --------- d-----w d:\program files\PC Connectivity Solution
2008-12-22 09:00 --------- d-----w d:\program files\DIFX
2008-12-21 21:46 351,744 ----a-w d:\windows\system32\avisynth.dll
2008-12-21 09:31 --------- d-----w d:\documents and settings\MNK\Dane aplikacji\ipla
2008-12-21 09:31 --------- d-----w d:\documents and settings\All Users\Dane aplikacji\ipla
2008-12-21 09:29 348,160 ----a-w d:\windows\system32\Msvcr71.dll
2008-12-21 09:29 1,700,352 ----a-w d:\windows\system32\gdiplus.dll
2008-12-21 09:29 1,060,864 ----a-w d:\windows\system32\mfc71.dll
2008-12-19 17:57 --------- d-----w d:\documents and settings\MNK\Dane aplikacji\Godlike
2008-12-18 22:33 --------- d-----w d:\documents and settings\MNK\Dane aplikacji\Ahead
2008-12-18 22:32 --------- d-----w d:\program files\Common Files\Ahead
2008-12-17 22:30 815,104 ----a-w d:\windows\system32\xvidcore.dll
2008-12-17 22:30 180,224 ----a-w d:\windows\system32\xvidvfw.dll
2008-12-17 13:30 219,648 ----a-w d:\windows\system32\uxtheme.dll
2008-12-17 12:38 --------- d-----w d:\documents and settings\MNK\Dane aplikacji\Gadu-Gadu
2008-12-17 12:35 --------- d-----w d:\documents and settings\All Users\Dane aplikacji\tlen.pl
2008-12-17 12:26 --------- d-----w d:\program files\Windows Media Connect 2
2008-12-17 12:19 --------- d-----w d:\documents and settings\All Users\Dane aplikacji\ESET
2008-12-17 12:10 --------- d-----w d:\program files\Winamp
2008-12-17 11:16 --------- d-----w d:\program files\Realtek Sound Manager
2008-12-17 11:16 --------- d-----w d:\program files\Realtek AC97
2008-12-17 11:16 --------- d-----w d:\program files\AvRack
2008-12-17 11:15 --------- d-----w d:\program files\Common Files\InstallShield
2008-12-17 10:42 --------- d-----w d:\program files\microsoft frontpage
2008-12-17 10:41 --------- d-----w d:\program files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“d:\windows\system32\ctfmon.exe” [2004-08-03 15360]
“WMPNSCFG”=“d:\program files\Windows Media Player\WMPNSCFG.exe” [2006-12-01 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NvCplDaemon”=“d:\windows\system32\NvCpl.dll” [2008-05-03 13529088]
“NvMediaCenter”=“d:\windows\system32\NvMcTray.dll” [2008-05-03 86016]
“NeroFilterCheck”=“d:\windows\system32\NeroCheck.exe” [2001-07-09 155648]
“Adobe Reader Speed Launcher”=“d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2008-06-12 34672]
“egui”=“e:\program files\ESET\ESET Smart Security\egui.exe” [2008-07-01 1447168]
“SoundMan”=“SOUNDMAN.EXE” [2006-08-03 d:\windows\soundman.exe]
“nwiz”=“nwiz.exe” [2008-05-03 d:\windows\system32\nwiz.exe]
“Kernel and Hardware Abstraction Layer”=“KHALMNPR.EXE” [2007-09-21 d:\windows\KHALMNPR.Exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“d:\windows\system32\CTFMON.EXE” [2004-08-03 15360]
d:\documents and settings\All Users\Menu Start\Programy\Autostart\
Logitech SetPoint.lnk - e:\program files\Logitech\SetPoint\SetPoint.exe [2009-01-14 784912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2007-11-15 10:10 72208 d:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“vidc.ffds”= e:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a------ 2008-12-23 19:24 136600 d:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“UpdatesDisableNotify”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“e:\Program files\Tlen.pl\tlen.exe”=
“e:\Program files\Gadu-Gadu\gg.exe”=
“e:\Program files\uTorrent\uTorrent.exe”=
“e:\Program files\GokaDCek\GokaDCek.exe”=
“e:\Program files\Soldier of Fortune II - Double Helix\SoF2MP.exe”=
“e:\Program files\PS3 Media Server\PMS.exe”=
R4 ekrn;Eset Service;e:\program files\ESET\ESET Smart Security\ekrn.exe [2008-07-01 468224]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;d:\windows\system32\drivers\libusb0.sys [2008-12-19 33792]
S3 PS3 Media Server;PS3 Media Server;e:\program files\PS3 Media Server\win32\service\wrapper.exe [2008-08-17 217088]
S4 NOD32FiXTemDono;Eset Nod32 Boot;d:\windows\system32\regedt32.exe [2001-10-26 3584]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://onet.pl/
uInternet Connection Wizard,ShellNext = hxxp://ggao.hit.gemius.pl/hitredir/id=b … nka.kfc.pl
TCP: {A6065E9F-1EE4-4B5E-93FA-AD8CFC1CF490} = 208.67.222.222,208.67.220.220
DPF: {68282C51-9459-467B-95BF-3C0E89627E55} - hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
FF - ProfilePath - d:\documents and settings\MNK\Dane aplikacji\Mozilla\Firefox\Profiles\oqcxpmft.default\
FF - prefs.js: browser.startup.homepage - http://www.onet.pl
FF - component: d:\documents and settings\MNK\Dane aplikacji\Mozilla\Firefox\Profiles\oqcxpmft.default\extensions\bkmrksync@nokia.com\components\BkMrkExt.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- FIREFOX - SPOSÓB POSTĘPOWANIA ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 00:06:08
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
skanowanie ukrytych procesów …
skanowanie ukrytych wpisów autostartu …
skanowanie ukrytych plików …
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
d:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
d:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Czas ukończenia: 2009-01-30 0:07:28
ComboFix-quarantined-files.txt 2009-01-29 23:07:22
Przed: 5 524 250 624 bajtów wolnych
Po: 5,514,899,456 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=“Microsoft Windows XP Professional” /noexecute=optin /fastdetect /numproc=1
195
– Dodane 30.01.2009 (Pt) 8:42 –
I jak pomoże mi ktoś ten problem rozwiązać ? I Co z tym logiem z COMBOFIXa ? :x
– Dodane 30.01.2009 (Pt) 8:47 –
I jak pomoże mi ktoś ten problem rozwiązać ? I Co z tym logiem z COMBOFIXa ? :x