kwaite09
(Kwaite09)
31 Październik 2007 16:08
#1
Mam problem. Co chwile wyskakują mi alerty dotyczące szkodników i nie wiem jak je usunąć. Poniżej log z hijack.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:03:36, on 2007-10-31 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe D:\Programy\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\System32\FTRTSVC.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PSIService.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Video Add-on\icthis.exe C:\Program Files\Video Add-on\isfmntr.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Video Add-on\icmntr.exe C:\Program Files\Video Add-on\isfmm.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe D:\Programy\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\neostrada tp\neostradatp.exe C:\Program Files\neostrada tp\ComComp.exe C:\PROGRA~1\NEOSTR~1\Toaster.exe C:\PROGRA~1\NEOSTR~1\Inactivity.exe C:\PROGRA~1\NEOSTR~1\PollingModule.exe C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE C:\Program Files\neostrada tp\Watch.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.imesh.com/sidebar.html?src=ssb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.imesh.com/sidebar.html?src=ssb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.imesh.com/sidebar.html?src=ssb R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.imesh.com/sidebar.html?src=ssb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = neostrada tp R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL O2 - BHO: (no name) - {598F4775-6FB6-477B-9842-E0426824E077} - C:\DOCUME~1\KW!AT\USTAWI~1\Temp~DP14.dll (file missing) O2 - BHO: (no name) - {B499D34E-58EF-4927-AB9F-7AF52B2C4C82} - C:\Program Files\Video Add-on\isfmdl.dll O4 - HKLM…\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM…\Run: [Resume copy] copyfstq.exe /startup O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe” O4 - HKLM…\Run: [updReg] C:\WINDOWS\Updreg.exe O4 - HKLM…\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe O4 - HKLM…\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\QTTask.exe” -atboottime O4 - HKLM…\Run: [!AVG Anti-Spyware] “D:\Programy\AVG Anti-Spyware 7.5\avgas.exe” /minimized O4 - HKLM…\Run: [NI.UGA6P_0001_N122M2210] “C:\Documents and Settings\KW!AT\Pulpit\install_en.exe” O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKLM…\Policies\Explorer\Run: [some] C:\Program Files\Video Add-on\icthis.exe O4 - HKLM…\Policies\Explorer\Run: [start] C:\Program Files\Video Add-on\isfmntr.exe O4 - HKUS\S-1-5-19…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘USŁUGA LOKALNA’) O4 - HKUS\S-1-5-20…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘USŁUGA SIECIOWA’) O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘SYSTEM’) O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘Default user’) O4 - Startup: neostrada tp.lnk = C:\Program Files\neostrada tp\GestMAJ.exe O4 - Global Startup: Kalendarz XP.lnk = D:\Programy\Kalendarz XP\Kalendarz.exe O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra ‘Tools’ menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing) O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing) O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O17 - HKLM\System\CCS\Services\Tcpip…{3FD8665F-2D3F-437B-A31A-8E53CF3BEB78}: NameServer = 194.204.159.1 217.98.63.164 O17 - HKLM\System\CS1\Services\Tcpip…{3FD8665F-2D3F-437B-A31A-8E53CF3BEB78}: NameServer = 194.204.159.1 217.98.63.164 O22 - SharedTaskScheduler: boardwalk - {75a65a53-15c9-4a0c-bb40-a7ca8b24f544} - (no file) O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Programy\AVG Anti-Spyware 7.5\guard.exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe – End of file - 7044 bytes
bodek32
(bodek32)
31 Październik 2007 17:14
#2
Zastosuj w trybie awaryjnym i wyłączonym przywracaniem systemu Smitfraudfix opcja nr 2
Potem dajesz nowy log z hijacka + log z Combofix
i raport ze smitfraudfix
bodek32
(bodek32)
31 Październik 2007 20:47
#4
Otwórz notatnik i wklej w nim to
Plik>zapisz jako…>zmień rozszerzenie na: wszystkie pliki i zapisz pod nazwą FIX.REG odpalasz plik FIX.REG i resetujesz komputer
Przeskanuj plik na http://www.virustotal.com lub http://www.virusscan.jotti.org
Skasuj ten wpis hijackthis
Przeczyść katalog temp za pomocą ATF Cleaner
Potem dajesz log z Combofix
Update
do posta niżej
tak to również do kasacji musiałem przeoczyć
A tak swoją drogą. Ciekawe dlaczego nie pokazał się w logu z Combofix
kwaite09
(Kwaite09)
1 Listopad 2007 17:53
#6
zafixowałem oba pliki:
wyczyściłem też temp za pomocą AFT Cleaner
log z COMBOFIX
ComboFix 07-10-29.1** - KW!AT 2007-11-01 18:39:27.2 - NTFSx86 Running from: C:\Documents and Settings\KW!AT\Moje dokumenty\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-10-01 to 2007-11-01 ))))))))))))))))))))))))))))))) . 2007-10-31 19:45 51,200 --a–c— C:\WINDOWS\NirCmd.exe 2007-10-31 19:36 2,614 --a–c— C:\WINDOWS\system32\tmp.reg 2007-10-31 19:35 289,144 --a–c— C:\WINDOWS\system32\VCCLSID.exe 2007-10-31 19:35 288,417 --a–c— C:\WINDOWS\system32\SrchSTS.exe 2007-10-31 19:35 53,248 --a–c— C:\WINDOWS\system32\Process.exe 2007-10-31 19:35 51,200 --a–c— C:\WINDOWS\system32\dumphive.exe 2007-10-31 19:35 25,600 --a–c— C:\WINDOWS\system32\WS2Fix.exe 2007-10-31 17:02 2007-10-30 21:59 24,064 --a–c— C:\WINDOWS\system32\msxml3a.dll 2007-10-30 15:13 2007-10-22 13:13 2007-10-14 14:20 584,192 -----c— C:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-07 15:15 2007-10-01 18:16 2007-10-01 18:16 2007-10-01 18:01 2007-10-01 18:00 40,960 --a–c— C:\WINDOWS\system32\FTRTSVC.exe 2007-10-01 18:00 36,864 --a–c— C:\WINDOWS\system32\IfHelper.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-01 17:17 --------- dc----w C:\Program Files\neostrada tp 2007-10-30 21:57 --------- dc----w C:\Documents and Settings\KW!AT\Dane aplikacji\Corel 2007-10-29 21:55 --------- dc–a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP 2007-10-24 20:17 --------- dc----w C:\Documents and Settings\KW!AT\Dane aplikacji\Azureus 2007-09-21 18:09 --------- dc-h–w C:\Program Files\InstallShield Installation Information 2007-09-17 20:10 --------- dc----w C:\Documents and Settings\KW!AT\Dane aplikacji\foobar2000 2007-09-14 10:57 --------- dc----w C:\Program Files\foobar2000 2007-09-07 12:33 --------- dc----w C:\Program Files\Common Files\Corel 2007-09-07 12:33 --------- dc----w C:\Documents and Settings\All Users\Dane aplikacji\Corel 2007-09-06 10:05 94,416 -c–a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-09-06 10:05 92,848 -c–a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-09-06 10:03 23,152 -c–a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-09-06 10:02 42,912 -c–a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-09-06 10:00 26,624 -c–a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-09-04 09:12 --------- dc----w C:\Documents and Settings\LocalService\Dane aplikacji\Ahead . ((((((((((((((((((((((((((((( snapshot@2007-10-31_20.00.55,31 ))))))))))))))))))))))))))))))))))))))))) . + 2007-11-01 17:16:35 16,384 -c–atw C:\WINDOWS\Temp\Perflib_Perfdata_4a8.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 11:06] “Resume copy”=“copyfstq.exe” [2002-03-24 12:54 C:\WINDOWS\COPYFSTQ.EXE] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe” [2007-07-12 03:00] “UpdReg”=“C:\WINDOWS\Updreg.exe” [2000-05-11 01:00] “AHQInit”=“C:\Program Files\Creative\SBLive\Program\AHQInit.exe” [2001-05-10 17:49] “AudioHQ”=“C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE” [2001-08-17 17:01] “NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-10-22 11:22] “NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2006-10-22 11:22] “QuickTime Task”=“C:\Program Files\QuickTime\QTTask.exe” [2007-06-29 05:24] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] C:\Documents and Settings\KW!AT\Menu Start\Programy\Autostart\ neostrada tp.lnk - C:\Program Files\neostrada tp\GestMAJ.exe [2007-10-01 18:01:15] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Kalendarz XP.lnk - D:\Programy\Kalendarz XP\Kalendarz.exe [2007-02-27 19:43:47] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{93994DE8-8239-4655-B1D1-5F4E91300429}”= C:\Program Files\DVDIdle Pro\DVDShell.dll [2004-10-09 15:18 49152] R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys R1 hwinterface;hwinterface;C:\WINDOWS\system32\Drivers\hwinterface.sys R1 ISODrive;ISO CD-ROM Device Driver;??\C:\Program Files\UltraISO\drivers\ISODrive.sys R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys S3 Cap7134;Philips Proteus (7134) WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys S3 Fadpu16E;Fadpu16E;??\C:\DOCUME~1\KW!AT\USTAWI~1\Temp\Fadpu16E.sys S3 NtApm;Sterownik interfejsu NT Apm/Legacy;C:\WINDOWS\system32\DRIVERS\NtApm.sys S3 PhTVTune;Philips WDM TVTuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys S3 StMp3Rec;%SvcDesc%;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{8bb819e0-ae34-11db-8f44-000e2e9d5707}] AutoRun\command - I:\m.exe . ************************************************************************** catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-01 18:43:58 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … C:\WINDOWS\system32\kb16.com 14913 bytes C:\WINDOWS\system32\powercfg.exe 49152 bytes executable C:\WINDOWS\system32\skdll.dll 5632 bytes executable C:\WINDOWS\system32\iasacct.dll 23552 bytes executable C:\WINDOWS\system32\iasads.dll 41472 bytes executable C:\WINDOWS\system32\iashlpr.dll 32256 bytes executable C:\WINDOWS\system32\iasnap.dll 62464 bytes executable C:\WINDOWS\system32\iaspolcy.dll 17920 bytes executable C:\WINDOWS\system32\iasrad.dll 119808 bytes executable C:\WINDOWS\system32\iasrecst.dll 141312 bytes executable C:\WINDOWS\system32\iassam.dll 86528 bytes executable C:\WINDOWS\system32\iassdo.dll 252416 bytes executable C:\WINDOWS\system32\iassvcs.dll 60928 bytes executable C:\WINDOWS\system32\icaapi.dll 11264 bytes executable C:\WINDOWS\system32\iccvid.dll 125952 bytes executable C:\WINDOWS\system32\icfgnt5.dll 16384 bytes executable C:\WINDOWS\system32\icm32.dll 254976 bytes executable C:\WINDOWS\system32\icmp.dll 3584 bytes executable C:\WINDOWS\system32\icmui.dll 55296 bytes executable C:\WINDOWS\system32\icsxml C:\WINDOWS\system32\icwdial.dll 73728 bytes executable C:\WINDOWS\system32\icwphbk.dll 65536 bytes executable C:\WINDOWS\system32\ideograf.uce 60458 bytes C:\WINDOWS\system32\idq.dll 121344 bytes executable C:\WINDOWS\system32\ie4uinit.exe 34304 bytes executable C:\WINDOWS\system32\ieakeng.dll 139264 bytes executable C:\WINDOWS\system32\ieaksie.dll 219648 bytes executable C:\WINDOWS\system32\ieakui.dll 237568 bytes executable C:\WINDOWS\system32\iedkcs32.dll 323584 bytes executable C:\WINDOWS\system32\ieencode.dll 81920 bytes executable C:\WINDOWS\system32\iepeers.dll 251392 bytes executable C:\WINDOWS\system32\iernonce.dll 48640 bytes executable C:\WINDOWS\system32\iesetup.dll 63488 bytes executable C:\WINDOWS\system32\ieuinit.inf 46306 bytes C:\WINDOWS\system32\iexpress.exe 114688 bytes executable C:\WINDOWS\system32\IfHelper.dll 36864 bytes executable C:\WINDOWS\system32\ifmon.dll 139264 bytes executable C:\WINDOWS\system32\openfiles.exe 70144 bytes executable C:\WINDOWS\system32\opengl32.dll 713728 bytes executable C:\WINDOWS\system32\osk.exe 216064 bytes executable C:\WINDOWS\system32\osuninst.dll 67584 bytes executable C:\WINDOWS\system32\osuninst.exe 41472 bytes executable C:\WINDOWS\system32\OUTLPERF.H 551 bytes C:\WINDOWS\system32\OUTLPERF.INI 5679 bytes C:\WINDOWS\system32\p2p.dll 116224 bytes executable C:\WINDOWS\system32\p2pgasvc.dll 86016 bytes executable C:\WINDOWS\system32\p2pgraph.dll 312320 bytes executable C:\WINDOWS\system32\p2pnetsh.dll 88064 bytes executable C:\WINDOWS\system32\p2psvc.dll 526848 bytes executable C:\WINDOWS\system32\packager.exe 59392 bytes executable C:\WINDOWS\system32\pagefileconfig.vbs 168167 bytes C:\WINDOWS\system32\panmap.dll 10240 bytes executable C:\WINDOWS\system32\paqsp.dll 157696 bytes executable C:\WINDOWS\system32\pathping.exe 22528 bytes executable C:\WINDOWS\system32\svchost.exe 14336 bytes executable C:\WINDOWS\system32\svcpack.dll 6144 bytes executable C:\WINDOWS\system32\swprv.dll 139264 bytes executable C:\WINDOWS\system32\swreg.exe 139776 bytes executable C:\WINDOWS\system32\swsc.exe 40960 bytes executable C:\WINDOWS\system32\swxcacls.exe 79360 bytes executable C:\WINDOWS\system32\sxs.dll 714240 bytes executable C:\WINDOWS\system32\syncapp.exe 51200 bytes executable C:\WINDOWS\system32\synceng.dll 57856 bytes executable C:\WINDOWS\system32\syncui.dll 192512 bytes executable C:\WINDOWS\system32\sysdm.cpl 301056 bytes executable C:\WINDOWS\system32\sysedit.exe 19168 bytes C:\WINDOWS\system32\sysinv.dll 15872 bytes executable C:\WINDOWS\system32\syskey.exe 37376 bytes executable C:\WINDOWS\system32\sysmon.ocx 219648 bytes executable C:\WINDOWS\system32\sysocmgr.exe 107008 bytes executable C:\WINDOWS\system32\sysprint.sep 3214 bytes C:\WINDOWS\system32\sysprtj.sep 3577 bytes C:\WINDOWS\system32\syssetup.dll 991744 bytes executable C:\WINDOWS\system32\system.drv 3360 bytes C:\WINDOWS\system32\systeminfo.exe 70144 bytes executable C:\WINDOWS\system32\systray.exe 3072 bytes executable C:\WINDOWS\system32\t2embed.dll 118272 bytes executable C:\WINDOWS\system32\TABCTL32.OCX 224016 bytes executable C:\WINDOWS\system32\tapi.dll 19200 bytes C:\WINDOWS\system32\tapi3.dll 860160 bytes executable C:\WINDOWS\system32\tapi32.dll 182272 bytes executable C:\WINDOWS\system32\msprivs.dll 48128 bytes executable C:\WINDOWS\system32\MSPRPPL.DLL 7680 bytes executable C:\WINDOWS\system32\msr2c.dll 69632 bytes executable C:\WINDOWS\system32\msr2cenu.dll 7168 bytes executable C:\WINDOWS\system32\msratelc.dll 63488 bytes executable C:\WINDOWS\system32\msrating.dll 146432 bytes executable C:\WINDOWS\system32\msrclr40.dll 73802 bytes executable C:\WINDOWS\system32\Msrd2x35.dll 252176 bytes executable C:\WINDOWS\system32\msrd2x40.dll 421919 bytes executable C:\WINDOWS\system32\msrd3x40.dll 315423 bytes executable C:\WINDOWS\system32\MSRDO20.DLL 397312 bytes executable C:\WINDOWS\system32\msrecr40.dll 28746 bytes executable C:\WINDOWS\system32\Msrepl35.dll 407312 bytes executable C:\WINDOWS\system32\msrepl40.dll 552989 bytes executable C:\WINDOWS\system32\msrle32.dll 11264 bytes executable C:\WINDOWS\system32\mssap.dll 134656 bytes executable C:\WINDOWS\system32\msscds32.ax 69632 bytes executable C:\WINDOWS\system32\msscp.dll 414720 bytes executable C:\WINDOWS\system32\msscript.ocx 102400 bytes executable C:\WINDOWS\system32\mssign32.dll 36352 bytes executable C:\WINDOWS\system32\mssip32.dll 4608 bytes executable C:\WINDOWS\system32\msstdfmt.dll 118784 bytes executable C:\WINDOWS\system32\msstkprp.dll 94208 bytes executable C:\WINDOWS\system32\msswch.dll 13312 bytes executable C:\WINDOWS\system32\msswchx.exe 6656 bytes executable C:\WINDOWS\system32\mstask.dll 278528 bytes executable C:\WINDOWS\system32\Mstext35.dll 165648 bytes executable C:\WINDOWS\system32\mstext40.dll 258077 bytes executable C:\WINDOWS\system32\mstime.dll 532480 bytes executable C:\WINDOWS\system32\mstinit.exe 12288 bytes executable C:\WINDOWS\system32\mstlsapi.dll 115712 bytes executable C:\WINDOWS\system32\mstsc.exe 408576 bytes executable C:\WINDOWS\system32\mstscax.dll 655360 bytes executable C:\WINDOWS\system32\msuni11.dll 241725 bytes executable C:\WINDOWS\system32\msutb.dll 195072 bytes executable C:\WINDOWS\system32\msv1_0.dll 129536 bytes executable C:\WINDOWS\system32\ff_libdts.dll 167936 bytes executable C:\WINDOWS\system32\finger.exe 9728 bytes executable C:\WINDOWS\system32\fsusd.dll 81920 bytes executable C:\WINDOWS\system32\graphics.com 19806 bytes C:\WINDOWS\system32\ias C:\WINDOWS\system32\ifsutil.dll 70656 bytes executable C:\WINDOWS\system32\infosoft.dll 450560 bytes executable C:\WINDOWS\system32\ipsecsnp.dll 354816 bytes executable C:\WINDOWS\system32\javacpl.cpl 69632 bytes executable C:\WINDOWS\system32\fastopen.exe 882 bytes C:\WINDOWS\system32\faultrep.dll 80896 bytes executable C:\WINDOWS\system32\faxpatch.exe 20992 bytes executable C:\WINDOWS\system32\fc.exe 14848 bytes executable C:\WINDOWS\system32\fde.dll 118784 bytes executable C:\WINDOWS\system32\fdeploy.dll 75264 bytes executable C:\WINDOWS\system32\feclient.dll 21504 bytes executable C:\WINDOWS\system32\ffdshow.ax 2211840 bytes executable C:\WINDOWS\system32\ffdshow.ax.manifest 547 bytes C:\WINDOWS\system32\ff_liba52.dll 44032 bytes executable C:\WINDOWS\system32\fsutil.exe 62976 bytes executable C:\WINDOWS\system32\ftp.exe 44544 bytes executable C:\WINDOWS\system32\FTRTSVC.exe 40960 bytes executable C:\WINDOWS\system32\ftsrch.dll 176640 bytes executable C:\WINDOWS\system32\fwcfg.dll 60416 bytes executable C:\WINDOWS\system32\g711codc.ax 41472 bytes executable C:\WINDOWS\system32\gb2312.uce 24006 bytes C:\WINDOWS\system32\gcdef.dll 77312 bytes executable C:\WINDOWS\system32\gdi.exe 24576 bytes C:\WINDOWS\system32\gdi32.dll 282112 bytes executable C:\WINDOWS\system32\geo.nls 24772 bytes C:\WINDOWS\system32\getmac.exe 56832 bytes executable C:\WINDOWS\system32\getuname.dll 605696 bytes executable C:\WINDOWS\system32\glmf32.dll 285184 bytes executable C:\WINDOWS\system32\glu32.dll 123904 bytes executable C:\WINDOWS\system32\gpedit.dll 569856 bytes executable C:\WINDOWS\system32\gpedit.msc 34346 bytes C:\WINDOWS\system32\gpkcsp.dll 101888 bytes executable C:\WINDOWS\system32\gpkrsrc.dll 10240 bytes executable C:\WINDOWS\system32\gpresult.exe 122880 bytes executable C:\WINDOWS\system32\gptext.dll 199680 bytes executable C:\WINDOWS\system32\gpupdate.exe 58368 bytes executable C:\WINDOWS\system32\graftabl.com 26112 bytes executable C:\WINDOWS\system32\kerberos.dll 295936 bytes executable C:\WINDOWS\system32\kernel32.dll 1013248 bytes executable C:\WINDOWS\system32\key01.sys 42809 bytes C:\WINDOWS\system32\keyboard.drv 2000 bytes C:\WINDOWS\system32\keyboard.sys 42537 bytes C:\WINDOWS\system32\keymgr.dll 152064 bytes executable C:\WINDOWS\system32\keystone.exe 425984 bytes executable C:\WINDOWS\system32\KGyGaAvL.sys 2516 bytes C:\WINDOWS\system32\kmddsp.tsp 33280 bytes executable C:\WINDOWS\system32\korean.uce 12876 bytes C:\WINDOWS\system32\krnl386.exe 92320 bytes C:\WINDOWS\system32\ksproxy.ax 130048 bytes executable C:\WINDOWS\system32\kstvtune.ax 61952 bytes executable C:\WINDOWS\system32\ksuser.dll 4096 bytes executable C:\WINDOWS\system32\kswdmcap.ax 91136 bytes executable C:\WINDOWS\system32\ksxbar.ax 43008 bytes executable C:\WINDOWS\system32\l3codeca.acm 290816 bytes executable C:\WINDOWS\system32\l3codecp.acm 232448 bytes executable C:\WINDOWS\system32\l3codecx.ax 98304 bytes executable C:\WINDOWS\system32\label.exe 9728 bytes executable C:\WINDOWS\system32\lameEnc.dll 92160 bytes executable C:\WINDOWS\system32\lame_enc.dll 237568 bytes executable C:\WINDOWS\system32\langwrbk.dll 89600 bytes executable C:\WINDOWS\system32\lanman.drv 223680 bytes C:\WINDOWS\system32\LAPRXY.dll 11264 bytes executable C:\WINDOWS\system32\libavcodec.dll 2012672 bytes executable C:\WINDOWS\system32\libdivx.dll 1044480 bytes executable C:\WINDOWS\system32\libmpeg2_ff.dll 112128 bytes executable C:\WINDOWS\system32\libmplayer.dll 395264 bytes executable C:\WINDOWS\system32\licdll.dll 424960 bytes executable C:\WINDOWS\system32\licmgr10.dll 22016 bytes executable C:\WINDOWS\system32\licwmi.dll 58880 bytes executable C:\WINDOWS\system32\igmpagnt.dll 8192 bytes executable C:\WINDOWS\system32\iissuba.dll 9216 bytes executable C:\WINDOWS\system32\ils.dll 81920 bytes executable C:\WINDOWS\system32\imaadp32.acm 16384 bytes executable C:\WINDOWS\system32\imagehlp.dll 144384 bytes executable C:\WINDOWS\system32\imagX7.dll 1568768 bytes executable C:\WINDOWS\system32\imagXpr7.dll 476320 bytes executable C:\WINDOWS\system32\imagXR7.dll 262144 bytes executable C:\WINDOWS\system32\imagXRA7.dll 471040 bytes executable C:\WINDOWS\system32\imapi.exe 150016 bytes executable C:\WINDOWS\system32\IME C:\WINDOWS\system32\imekr61.ime 94720 bytes executable C:\WINDOWS\system32\imeshare.dll 36921 bytes executable C:\WINDOWS\system32\imgutil.dll 35840 bytes executable C:\WINDOWS\system32\imjp81.ime 340023 bytes executable C:\WINDOWS\system32\imjp81k.dll 811064 bytes executable C:\WINDOWS\system32\imm32.dll 110080 bytes executable C:\WINDOWS\system32\inetcfg.dll 278528 bytes executable C:\WINDOWS\system32\inetcomm.dll 683520 bytes executable C:\WINDOWS\system32\inetcpl.cpl 359424 bytes executable C:\WINDOWS\system32\inetcplc.dll 117760 bytes executable C:\WINDOWS\system32\inetmib1.dll 33280 bytes executable C:\WINDOWS\system32\inetpp.dll 75264 bytes executable C:\WINDOWS\system32\inetppui.dll 15872 bytes executable C:\WINDOWS\system32\inetres.dll 49664 bytes executable C:\WINDOWS\system32\inetsrv C:\WINDOWS\system32\Inetwh32.dll 54784 bytes executable C:\WINDOWS\system32\ipsecsvc.dll 183296 bytes executable C:\WINDOWS\system32\ipsink.ax 16384 bytes executable C:\WINDOWS\system32\ipsmsnap.dll 386048 bytes executable C:\WINDOWS\system32\ipv6.exe 53760 bytes executable C:\WINDOWS\system32\ipv6mon.dll 60416 bytes executable C:\WINDOWS\system32\ipxmontr.dll 88064 bytes executable C:\WINDOWS\system32\ipxpromn.dll 71168 bytes executable C:\WINDOWS\system32\ipxrip.dll 21504 bytes executable C:\WINDOWS\system32\ipxroute.exe 24064 bytes executable C:\WINDOWS\system32\ipxrtmgr.dll 39936 bytes executable C:\WINDOWS\system32\ipxsap.dll 66560 bytes executable C:\WINDOWS\system32\ipxwan.dll 20992 bytes executable C:\WINDOWS\system32\ir32_32.dll 199168 bytes executable C:\WINDOWS\system32\ir41_32.ax 848384 bytes executable C:\WINDOWS\system32\ir41_qc.dll 120320 bytes executable C:\WINDOWS\system32\ir41_qcx.dll 338432 bytes executable C:\WINDOWS\system32\ir50_32.dll 464 bytes C:\WINDOWS\system32\ir50_qc.dll 198144 bytes executable C:\WINDOWS\system32\ir50_qcx.dll 181760 bytes executable C:\WINDOWS\system32\irclass.dll 13312 bytes executable C:\WINDOWS\system32\irprops.cpl 380928 bytes executable C:\WINDOWS\system32\isign32.dll 86016 bytes executable C:\WINDOWS\system32\isrdbg32.dll 32768 bytes executable C:\WINDOWS\system32\itircl.dll 155136 bytes executable C:\WINDOWS\system32\itss.dll 137216 bytes executable C:\WINDOWS\system32\iuengine.dll 198424 bytes executable C:\WINDOWS\system32\ivfsrc.ax 145408 bytes executable C:\WINDOWS\system32\IVI_Diagnostic.txt 1931 bytes C:\WINDOWS\system32\ixsso.dll 54784 bytes executable C:\WINDOWS\system32\iyuv_32.dll 47616 bytes executable C:\WINDOWS\system32\java.exe 135168 bytes executable C:\WINDOWS\system32\KBDAL.DLL 6656 bytes executable C:\WINDOWS\system32\kbdaze.dll 5632 bytes executable C:\WINDOWS\system32\kbdazel.dll 5632 bytes executable C:\WINDOWS\system32\kbdbe.dll 6144 bytes executable C:\WINDOWS\system32\kbdbene.dll 6144 bytes executable C:\WINDOWS\system32\kbdblr.dll 5632 bytes executable C:\WINDOWS\system32\kbdbr.dll 6144 bytes executable C:\WINDOWS\system32\kbdbu.dll 5632 bytes executable C:\WINDOWS\system32\kbdca.dll 6144 bytes executable C:\WINDOWS\system32\kbdcan.dll 7680 bytes executable C:\WINDOWS\system32\kbdcr.dll 6656 bytes executable C:\WINDOWS\system32\kbdcz.dll 7168 bytes executable C:\WINDOWS\system32\kbdcz1.dll 6656 bytes executable C:\WINDOWS\system32\kbdcz2.dll 6656 bytes executable C:\WINDOWS\system32\kbdda.dll 6144 bytes executable C:\WINDOWS\system32\kbddv.dll 5120 bytes executable C:\WINDOWS\system32\kbdes.dll 6144 bytes executable C:\WINDOWS\system32\kbdest.dll 6144 bytes executable C:\WINDOWS\system32\kbdfc.dll 6144 bytes executable C:\WINDOWS\system32\kbdfi.dll 6144 bytes executable C:\WINDOWS\system32\kbdfi1.dll 7168 bytes executable C:\WINDOWS\system32\lpr.exe 8192 bytes executable C:\WINDOWS\system32\lprhelp.dll 10240 bytes executable C:\WINDOWS\system32\lprmonui.dll 9216 bytes executable C:\WINDOWS\system32\lsasrv.dll 723968 bytes executable C:\WINDOWS\system32\lsass.exe 13312 bytes executable C:\WINDOWS\system32\lusrmgr.msc 41851 bytes C:\WINDOWS\system32\lz32.dll 2560 bytes executable C:\WINDOWS\system32\lzexpand.dll 9936 bytes C:\WINDOWS\system32\l_except.nls 168 bytes C:\WINDOWS\system32\l_intl.nls 7046 bytes C:\WINDOWS\system32\maag.dll 196608 bytes executable C:\WINDOWS\system32\Macromed C:\WINDOWS\system32\MafiaSetup.exe 233472 bytes executable C:\WINDOWS\system32\magnify.exe 73216 bytes executable C:\WINDOWS\system32\mag_hook.dll 8192 bytes executable C:\WINDOWS\system32\main.cpl 188928 bytes executable C:\WINDOWS\system32\makecab.exe 85504 bytes executable C:\WINDOWS\system32\mapi32.dll 112128 bytes executable C:\WINDOWS\system32\mapistub.dll 112128 bytes executable C:\WINDOWS\system32\MatroskaSplitter.ax 344064 bytes executable C:\WINDOWS\system32\mcastmib.dll 14848 bytes executable C:\WINDOWS\system32\mcd32.dll 10240 bytes executable C:\WINDOWS\system32\mcdsrv32.dll 10496 bytes executable C:\WINDOWS\system32\mchgrcoi.dll 4608 bytes executable C:\WINDOWS\system32\mciavi32.dll 84992 bytes executable C:\WINDOWS\system32\mcicda.dll 17408 bytes executable C:\WINDOWS\system32\mciole16.dll 8192 bytes C:\WINDOWS\system32\mciole32.dll 7680 bytes executable C:\WINDOWS\system32\mciqtz32.dll 35328 bytes executable C:\WINDOWS\system32\mciseq.dll 23040 bytes executable C:\WINDOWS\system32\mciseq.drv 25296 bytes C:\WINDOWS\system32\mciwave.dll 23552 bytes executable C:\WINDOWS\system32\mciwave.drv 28160 bytes C:\WINDOWS\system32\mdhcp.dll 50176 bytes executable C:\WINDOWS\system32\mdimon.dll 17920 bytes executable C:\WINDOWS\system32\mdminst.dll 118784 bytes executable C:\WINDOWS\system32\mdmxsdk.dll 86016 bytes executable C:\WINDOWS\system32\mdwmdmsp.dll 147968 bytes executable C:\WINDOWS\system32\mem.exe 39434 bytes C:\WINDOWS\system32\mf3216.dll 40960 bytes executable C:\WINDOWS\system32\mfc40.dll 924432 bytes executable C:\WINDOWS\system32\mfc40loc.dll 53248 bytes executable C:\WINDOWS\system32\mfc40u.dll 927504 bytes executable C:\WINDOWS\system32\mfc42.dll 1028096 bytes executable C:\WINDOWS\system32\mfc42loc.dll 53248 bytes executable C:\WINDOWS\system32\MFC42PLK.DLL 53248 bytes executable C:\WINDOWS\system32\mfc42u.dll 981760 bytes executable C:\WINDOWS\system32\mfc70.dll 974848 bytes executable C:\WINDOWS\system32\mfcans32.dll 149504 bytes executable C:\WINDOWS\system32\mfcsubs.dll 22528 bytes executable C:\WINDOWS\system32\mfcuia32.dll 108032 bytes executable C:\WINDOWS\system32\MFPLAT.dll 212992 bytes executable C:\WINDOWS\system32\mgmtapi.dll 14848 bytes executable C:\WINDOWS\system32\mib.bin 46258 bytes C:\WINDOWS\system32\Microsoft C:\WINDOWS\system32\midimap.dll 18944 bytes executable C:\WINDOWS\system32\miglibnt.dll 60928 bytes executable C:\WINDOWS\system32\migpwd.exe 52224 bytes executable C:\WINDOWS\system32\mimefilt.dll 18944 bytes executable C:\WINDOWS\system32\mindex.dll 163840 bytes executable C:\WINDOWS\system32\miniime.tpl 11776 bytes executable C:\WINDOWS\system32\mlang.dat 673088 bytes C:\WINDOWS\system32\mlang.dll 586240 bytes executable C:\WINDOWS\system32\mlfcache.dat 31544 bytes C:\WINDOWS\system32\mll_hp.dll 3584 bytes executable C:\WINDOWS\system32\mll_mtf.dll 7680 bytes executable C:\WINDOWS\system32\mll_qic.dll 5632 bytes executable C:\WINDOWS\system32\mmc.exe 815616 bytes executable C:\WINDOWS\system32\mmcbase.dll 75264 bytes executable C:\WINDOWS\system32\mmcndmgr.dll 1196032 bytes executable C:\WINDOWS\system32\mmcshext.dll 50688 bytes executable C:\WINDOWS\system32\mmdriver.inf 1492 bytes C:\WINDOWS\system32\mmdrv.dll 12288 bytes executable C:\WINDOWS\system32\mmfutil.dll 17920 bytes executable C:\WINDOWS\system32\mmsys.cpl 623104 bytes executable C:\WINDOWS\system32\mmsystem.dll 69552 bytes C:\WINDOWS\system32\mmtask.tsk 1152 bytes C:\WINDOWS\system32\mnmdd.dll 34560 bytes executable C:\WINDOWS\system32\mnmsrvc.exe 32768 bytes executable C:\WINDOWS\system32\MobOlExt.dll 69632 bytes executable C:\WINDOWS\system32\mobsync.dll 208384 bytes executable C:\WINDOWS\system32\mobsync.exe 143872 bytes executable C:\WINDOWS\system32\mode.com 19456 bytes executable C:\WINDOWS\system32\modemui.dll 155136 bytes executable C:\WINDOWS\system32\modex.dll 10112 bytes executable C:\WINDOWS\system32\more.com 15872 bytes executable C:\WINDOWS\system32\moricons.dll 216064 bytes executable C:\WINDOWS\system32\mountvol.exe 8192 bytes executable C:\WINDOWS\system32\mouse.drv 2032 bytes C:\WINDOWS\system32\MP43DECD.dll 259072 bytes executable C:\WINDOWS\system32\MP43DMOD.dll 4096 bytes executable C:\WINDOWS\system32\MP4SDECD.dll 317440 bytes executable C:\WINDOWS\system32\MP4SDMOD.dll 4096 bytes executable C:\WINDOWS\system32\mp4splitter.ax 516096 bytes executable C:\WINDOWS\system32\mpeg2data.ax 118272 bytes executable C:\WINDOWS\system32\mpg2splt.ax 148992 bytes executable C:\WINDOWS\system32\MPG4DECD.dll 259072 bytes executable C:\WINDOWS\system32\MPG4DMOD.dll 4096 bytes executable C:\WINDOWS\system32\mpg4ds32.ax 262144 bytes executable C:\WINDOWS\system32\mplay32.exe 124928 bytes executable C:\WINDOWS\system32\mplvpx.dll 464 bytes C:\WINDOWS\system32\mpnotify.exe 22016 bytes executable C:\WINDOWS\system32\mpr.dll 59904 bytes executable C:\WINDOWS\system32\mprapi.dll 87040 bytes executable C:\WINDOWS\system32\mprddm.dll 69120 bytes executable C:\WINDOWS\system32\mprdim.dll 49152 bytes executable C:\WINDOWS\system32\mprmsg.dll 106496 bytes executable C:\WINDOWS\system32\mprui.dll 47616 bytes executable C:\WINDOWS\system32\mqad.dll 138240 bytes executable C:\WINDOWS\system32\mqbkup.exe 19968 bytes executable C:\WINDOWS\system32\mqcertui.dll 10752 bytes executable C:\WINDOWS\system32\mqdscli.dll 47104 bytes executable C:\WINDOWS\system32\mqise.dll 16896 bytes executable C:\WINDOWS\system32\mqlogmgr.dll 89088 bytes executable C:\WINDOWS\system32\mqoa.dll 225280 bytes executable C:\WINDOWS\system32\mqoa.tlb 81408 bytes executable C:\WINDOWS\system32\mqoa10.tlb 36864 bytes executable C:\WINDOWS\system32\mqoa20.tlb 55296 bytes executable C:\WINDOWS\system32\mqperf.dll 8192 bytes executable C:\WINDOWS\system32\mqperf.ini 20629 bytes C:\WINDOWS\system32\mqprfsym.h 2755 bytes C:\WINDOWS\system32\mqqm.dll 660992 bytes executable C:\WINDOWS\system32\mqrt.dll 177152 bytes executable C:\WINDOWS\system32\mqrtdep.dll 123392 bytes executable C:\WINDOWS\system32\mqsec.dll 95744 bytes executable C:\WINDOWS\system32\mqsnap.dll 517632 bytes executable C:\WINDOWS\system32\mqsvc.exe 4608 bytes executable C:\WINDOWS\system32\mqtgsvc.exe 117248 bytes executable C:\WINDOWS\system32\mqtrig.dll 186880 bytes executable C:\WINDOWS\system32\mqupgrd.dll 48640 bytes executable C:\WINDOWS\system32\mqutil.dll 512000 bytes executable C:\WINDOWS\system32\mrinfo.exe 13824 bytes executable C:\WINDOWS\system32\MRT.exe 18089592 bytes executable C:\WINDOWS\system32\msaatext.dll 102912 bytes executable ************************************************************************** . Completion time: 2007-11-01 18:46:05 C:\ComboFix2.txt … 2007-10-31 20:03 . — E O F —
i jak to wygląda??
Gutek
(Gutek)
1 Listopad 2007 22:01
#7
Otwórz Notatnik i wklej w nim to:
Plik >>> Zapisz jako >>> Zmień rozszerzenie z TXT na Wszystkie pliki >>> Zapisz pod nazwą FIX.REG >>> kliknij dwa razy na utworzony plik FIX.REG i potwierdź dodanie do rejestru >>> restart.
kwaite09
(Kwaite09)
1 Listopad 2007 22:32
#8
Zrobione
Nie wiem dlaczego mi to umknęło wcześniej DZIĘKI WIELKIE!