Stado wirusów mnie zaatakowało/czy możecie sprawdzić loga?


(Lumenn 16) #1

dzisiaj od rana walczyłam z kompem:) i chyba wygrałam bitwe z wirusami:) choć zdziwiło mnie, że mks_vir nie znalazł mi nic, kasperky kilka a AVG juz 27 syfu:) mam nadzieje, ze juz bedzie Ok, chociaz wciąż:

  • przy ładowaniu pulpitu otwieraja mi sie 2x Moje dokumenty

  • nie moge sie dostac do menedżera zadań ( a wcześniej mogłam)

  • wciąż mam problem z dzwiekiem, tzn. działaja mi programy muzyczno - filmowe, na interii mogę oglądac za to Youtube i inne juz nie ma dzwieku:( probowalam juz wszystkie łatki do Toshiby: Hotkey i ta Audio ale wciaz nie działa:(

ale wracajac do głównego tematu, chciałabym poprosic o sprawdzenie mi loga:)

wklejam i tak: http://wklejto.pl/6662

z góry bardzo dziękuje:)


(Pan Ziombl) #2

O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)

O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)

O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)

O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)

O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)

O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)

O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)

O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)

O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)

O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)

O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)

O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)

O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)

O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)

O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)

O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)

O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)

O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)

O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)

O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)

O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)

O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)

O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)

O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)

O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)

O4 - HKCU..\Run: [EXPLORER.EXE] EXPLORER.EXE

O4 - HKCU..\Run: [wsctf.exe] wsctf.exe

O23 - Service: Plug and Play (RPC) (PlugPlayRPC) - Unknown owner - C:\WINDOWS\portsv.exe (file missing)


(Lumenn 16) #3

ooops, czyli ze za duzo usunelam?


(Kambor4) #4

Te w/w wpisy sfiksuj w Hijacku:

>>Hijack>>scan(Do a system scan only)>>zaznacz je >> Fix checked

Daj log z -----> ComboFix.

:slight_smile:


(Leon$) #5

wpisy

usuń HijackThisem >> Fix checked

Pobierz Combofix http://www.searchengines.pl/index.php?s ... ntry395642 ale nie włączaj.

Otwórz notatnik i wklej

zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe

http://img.wklej.org/images/88953CFScri ... iemoes.gif

Powinno rozpocząć się usuwanie

Potem log z usuwania Combofix

Pobierz System Repair Engineer

http://www.cybertrash.pl/images/tata/System%20Repair/System%20Repair%20Engineer.html

przeskanuj daj log

:slight_smile:


(adpawl) #6

lummen, zmień tytuł "witajcie:) prośba ma taka jak wielu..." na konkertny - albo temat -> KOSZ!


(Leon$) #7

Otwórz notatnik i wklej

zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe

http://img.wklej.org/images/88953CFScri ... iemoes.gif

Powinno rozpocząć się usuwanie

Potem log z usuwania Combofix

Pobierz System Repair Engineer

http://www.cybertrash.pl/images/tata/System%20Repair/System%20Repair%20Engineer.html

przeskanuj daj log

:slight_smile:


(Lumenn 16) #8

a co wklejenie tego w notatniku daje?

2008-07-25,23:26:14


System Repair Engineer 2.6.12.1018 Emergency Scan Mode

Smallfrogs (http://www.KZTechs.com)


Windows XP Home Edition Dodatek Service Pack 2 (Build 2600)


Follow item(s) have been selected:

    All Boot Items (Including Registry, Startup Folders, Services and so on)

    Browser Add-ons

    Running Processes (Including process model information)

    File Associations

    Winsock Provider

    Autorun.Inf

    HOSTS File

    Process Privileges Scan




Boot Items

Registry

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

  [(Verified)Microsoft Windows Publisher]

  [TOSHIBA]

  [(Verified)Google Inc]

<"C:\Program Files\Tlen.pl\tlen.exe" --confdir=home> [o2.pl Sp. z o.o.]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

  [(Verified)Microsoft Windows Hardware Compatibility Publisher]

<"C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang PL> [TOSHIBA Inc.]

  [TOSHIBA Corporation]

  [N/A]

  [TOSHIBA]

  []

<"C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon> [THOMSON Telecom Belgium]

  [N/A]

  [(Verified)"Sygate Technologies, Inc."]

<"C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]

  [(Verified)AVG Technologies]

<; "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"> [ATI Technologies, Inc.]

<; C:\WINDOWS\System32\DLA\DLACTRLW.EXE> [Sonic Solutions]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

  [(Verified)Microsoft Windows Component Publisher]

  [(Verified)Microsoft Windows Publisher]

  [(Verified)Microsoft Windows Publisher]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]

  [(Verified)Microsoft Corporation]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]

<%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [File is missing]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]

<%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]

<%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]

<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]

  [(Verified)Microsoft Windows Publisher]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]

  [(Verified)Microsoft Windows Publisher]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]

  [(Verified)Microsoft Windows Component Publisher]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]

<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]

  [(Verified)Microsoft Corporation]


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

<; "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun> [(Verified)DAEMON Tools Code Signing Services]

<; "C:\Program Files\Messenger\msmsgs.exe" /background> [(Verified)Microsoft Windows XP Publisher]

<; "C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" /NoDialog> [Time Information Services Ltd.]

<; "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray> [Nokia]

<; "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized> [(Verified)Skype Technologies SA]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

<; C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe> [France Télécom R&D]




==================================

Startup Folders

[Microsoft Office]
 C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [Microsoft Corporation]>

[Szybkie uruchamianie programu Microsoft Office OneNote 2003]
 C:\PROGRA~1\MICROS~2\OFFICE11\ONENOTEM.EXE [Microsoft Corporation]>



==================================

Services

[ANIWZCSd Service / ANIWZCSdService][Stopped/Manual Start]

<(File is missing)>


[Urządzenie mobilne Apple / Apple Mobile Device][Running/Auto Start]


  <"C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe">


[Zarządzanie aplikacjami / AppMgmt][Stopped/Manual Start]

%SystemRoot%\System32\appmgmts.dll>


[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]




[AVG Free8 E-mail Scanner / avg8emc][Running/Auto Start]




[AVG Free8 WatchDog / avg8wd][Running/Auto Start]




[Bonjour Service / Bonjour Service][Running/Auto Start]


  <"C:\Program Files\Bonjour\mDNSResponder.exe">


[ConfigFree Service / CFSvcs][Running/Auto Start]




[Google Updater Service / gusvc][Stopped/Manual Start]


  <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe">


[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]


  <"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe">


[Machine Debug Manager / MDM][Running/Auto Start]


  <"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe">


[Pml Driver HPZ12 / Pml Driver HPZ12][Running/Auto Start]




[ServiceLayer / ServiceLayer][Stopped/Manual Start]


  <"C:\Program Files\PC Connectivity Solution\ServiceLayer.exe">


[Sygate Personal Firewall / SmcService][Running/Auto Start]






==================================

Drivers

[D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB) / A3AB][Stopped/Manual Start]




[SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) / alcan5wn][Stopped/Manual Start]




[SpeedTouch ADSL Modem ATM Transport / alcaudsl][Stopped/Manual Start]




[ANIO Service / ANIO][Running/Auto Start]


  <\??\C:\WINDOWS\system32\ANIO.SYS>


[Atheros Wireless Network Adapter Service / AR5211][Stopped/Manual Start]




[ati2mtag / ati2mtag][Running/Manual Start]




[AVG Free AVI Loader Driver x86 / AvgLdx86][Running/System Start]


  <\SystemRoot\System32\Drivers\avgldx86.sys>


[AVG Free On-access Scanner Minifilter Driver x86 / AvgMfx86][Running/System Start]


  <\SystemRoot\System32\Drivers\avgmfx86.sys>


[AVG Free8 Network Redirector / AvgTdiX][Running/Auto Start]


  <\SystemRoot\System32\Drivers\avgtdix.sys>


[Access 32bits INT15 routine / BoiHwsetup][Running/Manual Start]




[Conexant AMC 3D Environmental Audio / CAMCAUD][Running/Manual Start]




[CAMCHALA / CAMCHALA][Running/Manual Start]




[DLABOIOM / DLABOIOM][Running/Auto Start]




[DLACDBHM / DLACDBHM][Running/System Start]




[DLADResN / DLADResN][Running/Auto Start]




[DLAIFS_M / DLAIFS_M][Running/Auto Start]




[DLAOPIOM / DLAOPIOM][Running/Auto Start]




[DLAPoolM / DLAPoolM][Running/Auto Start]




[DLARTL_N / DLARTL_N][Running/System Start]




[DLAUDFAM / DLAUDFAM][Running/Auto Start]




[DLAUDF_M / DLAUDF_M][Running/Auto Start]




[DRVMCDB / DRVMCDB][Running/Boot Start]


  <\SystemRoot\System32\Drivers\DRVMCDB.SYS>


[DRVNDDM / DRVNDDM][Running/Auto Start]




[dtscsi / dtscsi][Stopped/Manual Start]


  <\SystemRoot\System32\Drivers\dtscsi.sys>


[IEEE-1284.4 Driver HPZid412 / HPZid412][Stopped/Manual Start]




[Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12][Stopped/Manual Start]




[USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12][Stopped/Manual Start]




[HSFHWATI / HSFHWATI][Running/Manual Start]




[HSF_DPV / HSF_DPV][Running/Manual Start]




[IVI ASPI Shell / Iviaspi][Running/Manual Start]




[mdmxsdk / mdmxsdk][Running/Auto Start]




[TOSHIBA Network Device Usermode I/O Protocol / Netdevio][Running/Auto Start]




[Nokia USB Phone Parent / nmwcd][Stopped/Manual Start]




[Nokia USB Generic / nmwcdc][Stopped/Manual Start]




[PCANDIS5 NDIS Protocol Driver / PCANDIS5][Stopped/Manual Start]


  <\??\C:\WINDOWS\system32\PCANDIS5.SYS>


[PCCS Mode Change Filter Driver / pccsmcfd][Stopped/Manual Start]




[Creative PC-CAM 300 (Video) / PD016VID][Stopped/Manual Start]




[Padus ASPI Shell / Pfc][Running/Manual Start]




[Sterownik bezpośredniego połączenia kablowego / Ptilink][Running/Manual Start]




[PxHelp20 / PxHelp20][Running/Boot Start]


  <\SystemRoot\System32\Drivers\PxHelp20.sys>


[Quanta HotKey Keyboard Filter Driver / qkbfiltr][Running/Manual Start]




[Quanta HotKey Mouse Filter Driver / qmofiltr][Running/Manual Start]




[Realtek 10/100/1000 NIC Family all in one NDIS XP Driver / RTL8023xp][Running/Manual Start]




[Sterownik NT karty Realtek RTL8139(A/B/C)-based PCI Fast Ethernet / rtl8139][Stopped/Manual Start]




[Secdrv / Secdrv][Stopped/Manual Start]




[sptd / sptd][Running/Boot Start]


  <\SystemRoot\System32\Drivers\sptd.sys>


[Synaptics TouchPad Driver / SynTP][Running/Manual Start]




[Teefer for NT / Teefer][Running/Boot Start]


  <\SystemRoot\SYSTEM32\Drivers\Teefer.sys>


[upperdev / upperdev][Stopped/Manual Start]




[UsbserFilt / UsbserFilt][Stopped/Manual Start]




[SyGate for NT, wg3n / wg3n][Running/Auto Start]


  <\SystemRoot\SYSTEM32\Drivers\wg3n.sys>


[SyGate for NT, wg4n / wg4n][Running/Auto Start]


  <\SystemRoot\SYSTEM32\Drivers\wg4n.sys>


[SyGate for NT, wg5n / wg5n][Running/Auto Start]


  <\SystemRoot\SYSTEM32\Drivers\wg5n.sys>


[SyGate for NT, wg6n / wg6n][Running/Auto Start]


  <\SystemRoot\SYSTEM32\Drivers\wg6n.sys>


[winachsf / winachsf][Running/Manual Start]




[wpsdrvnt / wpsdrvnt][Running/System Start]


  <\??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys>




==================================

Browser Add-ons

[AcroIEHlprObj Class]


  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} 


[AVG Safe Search]


  {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} 


[DriveLetterAccess]


  {5CA3D70E-1895-11CF-8E15-001234567890} 


[SSVHelper Class]


  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} 


[AVG Security Toolbar]


  {A057A204-BACC-4D26-9990-79A187E2698E} 


[Google Toolbar Helper]


  {AA58ED58-01DD-4d91-8333-CF10577473F7} 


[Google Toolbar Notifier BHO]


  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} 


[Java Plug-in]


  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} 


[&Badanie]


  {92780B25-18CC-41C8-B9BE-3C9C571A8263} 


[&Google]


  {2318C2B1-4965-11d4-9B18-009027A5CD4F} 


[AVG Security Toolbar]


  {A057A204-BACC-4D26-9990-79A187E2698E} 


[MainControl Class]


  {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} 


[MksSkanerOnline Class]


  {68282C51-9459-467B-95BF-3C0E89627E55} 


[Java Plug-in]


  {8AD9C840-044E-11D1-B3E9-00805F499D93} 


[]


  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >


[Java Plug-in]


  {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} 


[Java Plug-in 1.5.0_06]


  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} 


[Shockwave Flash Object]


  {D27CDB6E-AE6D-11CF-96B8-444553540000} 


[Google Script Object]


  {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} 


[QuickTime Object]


  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} 


[AcroIEHlprObj Class]


  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} 


[]


  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <, >


[]


  {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} <, >


[]


  {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} <, >


[]


  {166B1BCA-3F9C-11CF-8075-444553540000} <, >


[Windows Media Player]


  {22D6F312-B0F6-11D0-94AB-0080C74C7E95} 


[&Google]


  {2318C2B1-4965-11D4-9B18-009027A5CD4F} 


[HTML Document]


  {25336920-03F9-11CF-8FD0-00AA00686F13} <%SystemRoot%\system32\mshtml.dll, (Signed) N/A>


[DHTML Edit Control Safe for Scripting for IE5]


  {2D360201-FFF5-11D1-8D03-00A0C959BC0A} 


[Tabular Data Control]


  {333C7BC4-460F-11D0-BC04-0080C7055A83} 


[AVG Safe Search]


  {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} 


[MainControl Class]


  {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} 


[XML Document]


  {48123BC4-99D9-11D1-A6B3-00C04FD91555} 


[Shell Name Space]


  {55136805-B2DE-11D1-B9F2-00A0C98BC547} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A>


[DriveLetterAccess]


  {5CA3D70E-1895-11CF-8E15-001234567890} 


[]


  {6117669B-8C2D-41FA-A6D9-9E484B999CF0} <, >


[WUWebControl Class]


  {6414512B-B978-451D-A0D8-FCFDF33E833C} 


[MksSkanerOnline Class]


  {68282C51-9459-467B-95BF-3C0E89627E55} 


[Windows Media Player]


  {6BF52A52-394A-11D3-B153-00C04F79FAA6} 


[Active Desktop Mover]


  {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, (Signed) N/A>


[SSVHelper Class]


  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} 


[Przeglądarka sieci Web firmy Microsoft]


  {8856F961-340A-11D0-A96B-00C04FD705A2} 


[]


  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >


[]


  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >


[]


  {9ECB9560-04F9-4BBC-943D-298DDF1699E1} <, >


[AVG Security Toolbar]


  {A057A204-BACC-4D26-9990-79A187E2698E} 


[]


  {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} <, >


[Google Toolbar Helper]


  {AA58ED58-01DD-4D91-8333-CF10577473F7} 


[Google Toolbar Notifier BHO]


  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} 


[SearchAssistantOC]


  {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\system32\shdocvw.dll, (Signed) N/A>


[RDS.DataSpace]


  {BD96C556-65A3-11D0-983A-00C04FC29E36} 


[]


  {C4069E3A-68F1-403E-B40E-20066696354B} <, >


[AUDIO__BASIC Moniker Class]


  {CD3AFA73-B84F-48F0-9393-7EDC34128127} 


[AUDIO__MP3 Moniker Class]


  {CD3AFA76-B84F-48F0-9393-7EDC34128127} 


[VIDEO__X_MS_ASF Moniker Class]


  {CD3AFA8F-B84F-48F0-9393-7EDC34128127} 


[Shockwave Flash Object]


  {D27CDB6E-AE6D-11CF-96B8-444553540000} 


[]


  {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >


[]


  {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} <, >


[E&ksport do programu Microsoft Excel]






==================================

Running Processes



[PID][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]


    [C] [ATI Technologies Inc., 6.14.10.4124]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][C] [ATI Technologies Inc., 6.14.10.4124]


    [C] [ATI Technologies, Inc., 6, 14, 10, 2499]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]


    [C] [Apple Inc., 1,0,4,12]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]


    [C] [Apple Inc., 1,0,4,12]




[PID][C] [Sygate Technologies, Inc., 5.6.00.2808]


    [C] [Sygate Technologies, Inc., 5, 5, 0, 0]


    [C] [Sygate Technologies, Inc., 1.62.1200.0]


    [C] [N/A,]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 0]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 0]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]


    [C] [N/A,]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 0]


    [C] [Sygate Technologies, Inc., 5, 5, 0, 0]


    [C] [Sygate Technologies, Inc., 2, 3, 3115, 0]


    [C] [Sygate Technologies, Inc., 1.01.1222]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 0]


    [C] [Sygate Technologies, Inc., 5, 5, 0, 0]


    [C] [N/A,]


    [C] [Apple Inc., 1,0,4,12]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][C] [ATI Technologies Inc., 6.14.10.4124]


    [C] [ATI Technologies, Inc., 6, 14, 10, 2499]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][C] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]


    [C] [Hewlett Packard, 6.01.00.009]


    [C] [Hewlett Packard, 2.01.00.005]


    [C] [Microsoft Corporation, 6.01.00.009]


    [C] [Hewlett Packard, 6.01.00.009]


    [C] [Hewlett-Packard Company, 60.054.45.00]


    [C] [Hewlett-Packard Corporation, 60.054.45.00]


    [C] [Apple Inc., 1,0,4,12]




[PID][C] [Apple, Inc., 1, 14, 0, 0]




[PID][C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]




[PID][C] [Apple Inc., 1,0,4,12]




[PID][C] [TOSHIBA CORPORATION, 6, 0, 0, 1]


    [C] [TOSHIBA CORPORATION, 6, 0, 0, 9]


    [C] [TOSHIBA CORPORATION, 6, 0, 0, 3]




[PID][C] [Microsoft Corporation, 7.00.9064.9150]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [HP, 10, 1, 1, 5]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][C] [Microsoft Corporation, 5.2.3790.1230 built by: DNSRV(bld4act)]




[PID][C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]


    [C] [Apple Inc., 1,0,4,12]




[PID][C] [Synaptics, Inc., 8.2.9 16Dec05]


    [C] [Synaptics, Inc., 8.2.9 16Dec05]


    [C] [Synaptics, Inc., 8.2.9 16Dec05]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [TOSHIBA Inc., 1, 7, 9, 2]


    [C] [Microsoft Corporation, 7.10.3077.0]


    [C] [Microsoft Corporation, 7.10.3052.4]


    [C] [Quanta Computer Inc., 3, 0, 5, 1]


    [C] [Microsoft Corporation, 7.10.3077.0]


    [C] [ATI Technologies, Inc., 6, 14, 10, 2495]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [TOSHIBA Corporation, 1, 0, 15, 0]


    [C] [TOSHIBA Corporation, 1, 0, 4, 0]


    [C] [TOSHIBA Corporation, 1, 0, 1, 0]


    [C] [TOSHIBA Corporation, 1, 0, 3, 0]


    [C] [TOSHIBA Corporation, 1, 0, 4, 0]


    [C] [, 1, 0, 0, 5]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [TOSHIBA CORPORATION, 6, 0, 1, 1]


    [C] [TOSHIBA CORPORATION, 1, 0, 0, 12]


    [C] [TOSHIBA CORPORATION, 6, 0, 0, 9]


    [C] [TOSHIBA CORPORATION, 6, 0, 0, 3]


    [C] [TOSHIBA CORPORATION, 4, 0, 2, 1006]


    [C] [TOSHIBA CORPORATION, 1, 0, 0, 5]


    [C] [TOSHIBA CORPORATION, 5, 0, 0, 1]


    [C] [TOSHIBA CORPORATION, 5, 0, 0, 1]


    [C] [TOSHIBA CORPORATION, 6, 0, 0, 17]


    [C] [Toshiba, 6, 0, 0, 6]


    [C] [TOSHIBA, 6, 0, 0, 4]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [TOSHIBA, 1, 2, 10, 0]


    [C] [, 1, 2, 2, 0]


    [C] [Synaptics, Inc., 8.2.9 16Dec05]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [THOMSON Telecom Belgium, 301.0.0.12]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [TOSHIBA, 1, 0, 6, 0]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [Google Inc., 2, 0, 301, 1654]


    [C] [Google Inc., 3, 0, 1225, 9868]


    [C] [Google Inc., 3, 0, 1225, 9868]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [o2.pl Sp. z o.o., 5.60.2.29]


    [C] [N/A,]


    [C] [N/A,]


    [C] [N/A,]


    [C] [N/A,]


    [C] [N/A,]


    [C] [N/A,]


    [C] [N/A,]


    [C] [N/A,]


    [C] [Apple Inc., 1,0,4,12]


    [C] [N/A,]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]


    [C] [Adobe Systems, Inc., 9,0,115,0]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][C] [Synaptics, Inc., 8.2.9 16Dec05]


    [C] [Synaptics, Inc., 8.2.9 16Dec05]


    [C] [Synaptics, Inc., 8.2.9 16Dec05]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [TOSHIBA Corporation, 1, 0, 2, 0]


    [C] [TOSHIBA Corporation, 1, 0, 8, 0]


    [C] [TOSHIBA Corporation, 1, 0, 4, 0]


    [C] [TOSHIBA Corporation, 1, 0, 3, 0]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]




[PID][C] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]




[PID][C] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]


    [C] [TOSHIBA Corporation, 1, 0, 8, 0]


    [C] [TOSHIBA Corporation, 1, 0, 4, 0]


    [C] [TOSHIBA Corporation, 1, 0, 3, 0]


    [C] [N/A,]


    [C] [Adobe Systems, Inc., 7.0.0.0]


    [C] [N/A,]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [Adobe Systems Incorporated, 7.0.5.2005092300]


    [C] [Microsoft Corporation, 7.10.3052.4]




[PID][C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]




[PID][C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]




[PID][C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]




[PID][C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]




[PID][C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]




[PID][C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]


    [C] [AVG Technologies CZ, s.r.o., 8.0.0.134]




[PID][C] [Smallfrogs Studio, 2.6.12.1018]




[PID][C] [Smallfrogs Studio, 2.6.12.1018]


    [C] [Sygate Technologies, Inc., 5. 5. 0. 5]


    [C] [N/A,]




==================================

File Associations

.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]

.EXE OK. ["%1" %*]

.COM OK. ["%1" %*]

.PIF OK. ["%1" %*]

.REG OK. [regedit.exe "%1"]

.BAT OK. ["%1" %*]

.SCR OK. ["%1" /S]

.CHM OK. ["C:\WINDOWS\hh.exe" %1]

.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]

.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]

.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]

.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]

.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]

.LNK OK. [{00021401-0000-0000-C000-000000000046}]



==================================

Winsock Provider

N/A


==================================

Autorun.Inf

N/A


==================================

HOSTS File

127.0.0.1 localhost



==================================

Process Privileges Scan

Special Privileges Enabled: SeLoadDriverPrivilege [PID = 572, C:\PROGRAM FILES\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE]

Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2560, C:\PROGRAM FILES\TOSHIBA\WINDOWS UTILITIES\HOTKEY.EXE]

Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2568, C:\WINDOWS\SYSTEM32\TPSMAIN.EXE]

Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2592, C:\PROGRAM FILES\TOSHIBA\CONFIGFREE\NDSTRAY.EXE]

Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2640, C:\PROGRAM FILES\TOSHIBA\TOUCH AND LAUNCH\PADEXE.EXE]

Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2664, C:\PROGRAM FILES\THOMSON\SPEEDTOUCH USB\DRAGDIAG.EXE]

Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2920, C:\PROGRAM FILES\TOSHIBA\TOSCDSPD\TOSCDSPD.EXE]

Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2936, C:\PROGRAM FILES\TLEN.PL\TLEN.EXE]

Special Privileges Enabled: SeLoadDriverPrivilege [PID = 1628, C:\WINDOWS\SYSTEM32\TPSBATTM.EXE]

Special Privileges Enabled: SeLoadDriverPrivilege [PID = 1444, C:\DOCUMENTS AND SETTINGS\EVE\PULPIT\SRENG2\SRENGLDR.EXE]



==================================

API HOOK

N/A


==================================

Hidden Process

N/A

(Asterisk) #9

Proszę zastosować się do tego Tematu i edytować własnego posta

w celu zmiany jego tytułu na konkretny.

W przeciwnym razie topic wyląduje w Śmietniku.


(huber2t) #10

Combofix usuwa te pliki

Daj log z usuwania z combofix


(Lumenn 16) #11

log z Combofixa

ComboFix 08-07-24.6 - Eve 2008-07-25 22:37:11.2 - NTFSx86

Running from: C:\Documents and Settings\Eve\Pulpit\ComboFix.exe

Command switches used :: C:\Documents and Settings\Eve\Pulpit\CFScript.txt

* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED!!

FILE ::

C:\WINDOWS\system32\bbcbedbb.dll

C:\WINDOWS\system32\daaeb7_s.dll

C:\WINDOWS\system32\EXPLORER.EXE

C:\WINDOWS\system32\wsctf.exe

E:\EXPLORER.EXE

E:\pa39xth.cmd

F:\xn1i9x.com

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\WINDOWS\system32\bbcbedbb.dll

C:\WINDOWS\system32\daaeb7_s.dll

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_PLUGPLAYRPC

-------\Service_PlugPlayRPC

((((((((((((((((((((((((( Files Created from 2008-06-25 to 2008-07-25 )))))))))))))))))))))))))))))))

.

2008-07-25 22:10 . 2008-07-25 22:10

2008-07-25 22:10 .

2008-07-25 22:10 .

2008-07-25 13:04 . 2008-07-25 16:54

2008-07-25 13:00 . 2008-07-25 13:00 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys

2008-07-25 13:00 . 2008-07-25 13:00 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll

2008-07-25 12:59 . 2008-07-25 13:04

2008-07-25 12:59 . 2008-07-25 12:59

2008-07-25 12:59 . 2008-07-25 13:03

2008-07-25 12:59 . 2008-07-25 12:59

2008-07-25 12:59 . 2008-07-25 12:59 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys

2008-07-25 12:09 . 2008-07-25 12:09

2008-07-25 11:51 . 2008-07-25 11:51

2008-07-25 00:06 . 2008-07-25 10:48

2008-07-25 00:06 . 2008-07-25 00:06

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-25 19:43 --------- d-----w C:\Program Files\SkanerOnline

2008-07-25 19:38 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-07-25 11:58 --------- d-----w C:\Program Files\PC Tools AntiVirus

2008-07-25 08:48 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP

2008-07-24 15:50 --------- d-----w C:\Documents and Settings\Eve\Dane aplikacji\uTorrent

2008-07-24 07:53 --------- d-----w C:\Documents and Settings\Eve\Dane aplikacji\Tlen.pl

2008-07-23 17:31 --------- d-----w C:\Program Files\eMule

2008-07-04 06:51 --------- d-----w C:\Program Files\EA GAMES

2008-06-21 12:00 --------- d-----w C:\Program Files\uTorrent

2008-06-21 11:38 --------- d-----w C:\Program Files\Electronic Arts

2008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-19 20:52 --------- d-----w C:\Documents and Settings\Eve\Dane aplikacji\Skype

2008-06-14 18:01 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-11 17:03 --------- d-----w C:\Program Files\DAEMON Tools Lite

2008-06-11 12:17 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys

2008-06-11 12:16 --------- d-----w C:\Documents and Settings\Eve\Dane aplikacji\DAEMON Tools

2008-06-11 12:08 --------- d-----w C:\Program Files\Alcohol Soft

2008-05-31 18:46 --------- d-----w C:\Documents and Settings\Eve\Dane aplikacji\Nokia Multimedia Player

2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll

2008-04-03 12:48 24,624 -c--a-w C:\Documents and Settings\Eve\Dane aplikacji\GDIPFONTCACHEV1.DAT

2007-08-09 15:02 560 -c--a-w C:\Program Files\Global.sw

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]

"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-12 13:04 65536]

"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-05 20:22 68856]

"Komunikator"="C:\Program Files\Tlen.pl\tlen.exe" [2006-05-12 14:13 959488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-17 01:32 761945]

"Toshiba Hotkey Utility"="C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" [2006-01-28 06:13 1589248]

"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-12-22 16:34 1077329]

"WooCnxMon"="C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [2003-10-16 19:07 24576]

"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 12:38 866816]

"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]

"QuickTime Task"="C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" [2006-09-01 15:57 282624]

"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-25 12:59 1232152]

"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-12-11 22:05 344064]

"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 06:20 122940]

"TPSMain"="TPSMain.exe" [2005-08-04 15:16 266240 C:\WINDOWS\system32\TPSMain.exe]

"NDSTray.exe"="NDSTray.exe" [bU]

"CFSServ.exe"="CFSServ.exe" [bU]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]

C:\Documents and Settings\Eve\Menu Start\Programy\Autostart\

Szybkie uruchamianie programu Microsoft Office OneNote 2003.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2005-03-17 15:06:14 59080]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\

Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"msacm.avis"= ff_acm.acm

"VIDC.VQJC"= PD016dec.dll

"vidc.3iv2"= 3ivxVfWCodec.dll

"VIDC.VP31"= vp31vfw.dll

"msacm.divxa32"= DivXa32.acm

"msacm.l3codec"= L3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]

--a------ 2008-04-01 11:39 486856 C:\Program Files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

--------- 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]

--a------ 2008-03-26 18:41 1232896 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]

--a------ 2008-03-28 11:20 1079296 C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

-ra------ 2007-07-02 18:10 23237416 C:\Program Files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]

--------- 2003-10-16 19:07 53248 C:\PROGRA~1\NEOSTR~1\TaskBarIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]

--------- 2003-10-16 19:07 20480 C:\PROGRA~1\NEOSTR~1\Watch.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\system32\sessmgr.exe"=

"C:\Program Files\Messenger\msmsgs.exe"=

"C:\Program Files\eMule\emule.exe"=

"C:\WINDOWS\system32\dpvsetup.exe"=

"C:\Program Files\Tlen.pl\tlen.exe"=

"C:\totalcmd\TOTALCMD.EXE"=

"C:\Program Files\Bonjour\mDNSResponder.exe"=

"C:\Program Files\Skype\Phone\Skype.exe"=

"C:\Program Files\uTorrent\uTorrent.exe"=

"C:\Program Files\AVG\AVG8\avgemc.exe"=

"C:\Program Files\AVG\AVG8\avgupd.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-25 13:00]

R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-25 12:59]

R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-25 12:59]

R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-25 12:59]

R3 BoiHwsetup;Access 32bits INT15 routine;C:\WINDOWS\system32\drivers\BoiHwSetup.sys [2005-06-11 06:42]

R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-11-29 23:50]

R3 qkbfiltr;Quanta HotKey Keyboard Filter Driver;C:\WINDOWS\system32\drivers\qkbfiltr.sys [2006-01-12 17:21]

R3 qmofiltr;Quanta HotKey Mouse Filter Driver;C:\WINDOWS\system32\drivers\qmofiltr.sys [2005-05-05 15:27]

S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2005-03-22 03:17]

S3 PD016VID;Creative PC-CAM 300 (Video);C:\WINDOWS\system32\DRIVERS\PD016Vid.sys [2002-06-21 02:10]

.

  • ORPHANS REMOVED - - - -

HKLM-Run-ANIWZCS2Service - (no file)

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-25 22:56:06

Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]

"ImagePath"=""

.

------------------------ Other Running Processes ------------------------

.

C:\WINDOWS\system32\ati2evxx.exe

C:\Program Files\Sygate\SPF\Smc.exe

C:\WINDOWS\system32\ati2evxx.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\system32\wdfmgr.exe

C:\Program Files\Toshiba\ConfigFree\NDSTray.exe

C:\Program Files\Synaptics\SynTP\Toshiba.exe

C:\WINDOWS\system32\TPSBattM.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

.

**************************************************************************

.

Completion time: 2008-07-25 23:03:34 - machine was rebooted

ComboFix-quarantined-files.txt 2008-07-25 21:03:14

ComboFix2.txt 2008-07-25 20:10:48

Pre-Run: 2,106,138,624 bajtów wolnych

Post-Run: 2,101,985,280 bajt˘w wolnych

185 --- E O F --- 2008-07-11 06:50:14


(Kambor4) #12

Czysto!

Usuń ręcznie folder C:**** \Qoobox ,

Usuń instalkę Combofix z dysku.

Wykonaj optymalizację autostartu

Przeczyść komputer Ccleanerem

Wyłącz i włącz przywracanie systemu na wszystkich dyskach. Instrukcja

Przeskanuj obszar mojego komputera http://www.kaspersky.pl/virusscanner.html (uruchom przez IE) Daj raport z niego na forum

lub

Dr.WEB CureIt!


(huber2t) #13

Pobierz ComboFix, ale nie uruchamiaj

Otwórz notatnik i wklej do niego:

Folder::

C:\WINDOWS\system32\1195


Registry::

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NDSTray.exe"=-

"CFSServ.exe"=-

Plik -> zapisz jako -> CFScript.txt.

Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe tak jak tu ->

02f8f1e3c410a4cc.gif

Rozpocznie się usuwanie i powstanie log, który dasz na forum.

Logi dajesz na http://wklejto.pl lub na http://wklej.org a w poście dajesz tylko link


(Leon$) #14

Uruchom System Repair Engineer zakładka System repair >> Browser Add-ons >> odszukaj i usuń

:slight_smile: