coś tu sie stało … wystąpił problem z aplikacją sedcfexei zostanie zamknięta . nim dowiem się jak usunąć alctmr.exe to prosże podpowiedzieć od czego ten proces… o jest juz log
en ComboFix 07-10-07.2 - Tesmen 2007-10-08 0:09:58.1 - FAT32x86 BĄd wejcia: Brak aparatu skrypt˘w dla plik˘w o rozszerzeniu “.vbs”. Running from: D:\P_R_O_G_R_A_M_Y\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-09-07 to 2007-10-07 ))))))))))))))))))))))))))))))) . 2007-10-08 00:09 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-10-07 23:16 2007-10-07 23:11 2007-10-07 23:03 2007-10-06 22:36 2007-10-06 22:36 2007-10-05 01:38 28,672 --a------ C:\WINDOWS\system32\drivers\CO_Mon.sys 2007-10-05 01:37 2007-10-04 04:46 2007-10-01 18:04 2007-10-01 17:47 2007-09-26 00:13 2007-09-21 20:42 2007-09-19 23:24 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr 2007-09-19 23:24 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-09-19 23:24 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-09-19 23:24 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-09-19 23:24 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-09-19 23:24 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-09-19 23:23 801,144 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-09-18 23:40 2007-09-18 23:34 2007-09-18 23:08 2,662 --a------ C:\WINDOWS\unins000.dat 2007-09-18 21:41 2007-09-18 21:39 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-09-03 23:33 73216 --a------ C:\WINDOWS\ST6UNST.EXE 2007-09-03 23:33 249856 --------- C:\WINDOWS\Setup1.exe 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\dllcache\wuapi.dll 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe 2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\dllcache\wucltui.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\dllcache\wuweb.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll 2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll 2007-07-10 18:55 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll 2005-09-09 19:55 35 --a------ C:\Program Files\SCSSDist.ini 2002-01-05 03:40 487424 --a------ C:\Program Files\Common Files\msvcp70.dll 1999-06-25 10:55 149504 --a------ C:\Program Files\UNWISE.EXE 2007-07-01 09:34:08 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys 2007-06-30 15:28:18 8 --sh–r C:\WINDOWS\system32\920CB8ED52.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “HControl”=“C:\WINDOWS\ATK0100\HControl.exe” [2006-02-22 21:40] “RTHDCPL”=“RTHDCPL.EXE” [2006-05-04 00:59 C:\WINDOWS\RTHDCPL.exe] “Power_Gear”=“C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe” [2006-03-14 17:46] “avast!”=“d:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 12:06] “ADBSMSDEAutostart”=“c:\Program Files\Microsoft SQL Server\80\Tools\Binn\scm.exe” [2002-12-17 17:23] “ISUSPM Startup”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe” [2005-02-17 07:15] “ISUSScheduler”=“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” [2005-02-17 07:15] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 13:00] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2006-11-10 21:30] “Shareaza”=“d:\Program Files\Shareaza\Shareaza.exe” [2007-07-04 03:12] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu] “C:\Program Files\Gadu-Gadu\gg.exe” /tray [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] “C:\Program Files\Windows Defender\MSASCui.exe” -hide R3 ASNDIS5;ASNDIS5 Protocol Driver;??\C:\WINDOWS\ATK0100\ASNDIS5.SYS R3 SynMini;USB2.0 1.3M Web Cam;C:\WINDOWS\system32\Drivers\SynMini.sys R3 SynScan;USB2.0 1.3M Web Cam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys S3 GTEDGWModem;Option NV GTEDGWModem;C:\WINDOWS\system32\DRIVERS\GTEDG.sys S3 GTEDGWWNIC;Option NV GTEDGWWNIC;C:\WINDOWS\system32\DRIVERS\GTEDGNet.sys S3 ipswuio;ipswuio;C:\WINDOWS\system32\DRIVERS\ipswuio.sys S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys S3 NPF;Netgroup Packet Filter;C:\WINDOWS\system32\drivers\npf.sys S3 odysseyIM4;Odyssey Network Agent Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM4.sys S3 OptionWWSC;GT EDGE SIM Card Reader;C:\WINDOWS\system32\DRIVERS\GTEDGSC.sys *Newly Created Service* - CATCHME . Contents of the ‘Scheduled Tasks’ folder “2007-10-07 13:13:24 C:\WINDOWS\Tasks\MP Scheduled Scan.job” - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-08 00:12:37 Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-10-08 0:13:32 . — E O F —
proszę o łopatologiczne wytłumaczenie co ,jak, i czym usunąć, gdyż w tej kwestii jestem lajkonikiem w zamian za pomoc jestem skłonny do udzielenia 3% rabaciku na zakupy w naszym sklepiku…
acha fat 32 czy ntfs ?