Witam , kilka dni temu pozyczlem pendrive nagralem na niego dane i podpielem pod innego kompa , po czym na pena wbil sie vir i od tego czasu na zadnym komputerze nie pokazuje pendrive. Prosze pomozcie Mi. przesyłam logi z combofixa
ComboFix 08-12-01.03 - ty 2008-12-02 19:34:00.4 - FAT32 x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.675 [GMT 1:00]
Uruchomiony z: c:\documents and settings\ty\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-02 do 2008-12-02 )))))))))))))))))))))))))))))))
.
2008-12-02 19:04 . 2008-12-02 19:04
2008-12-02 18:04 . 2008-12-02 18:04
2008-12-02 17:27 . 2008-12-02 17:27
2008-12-01 21:20 . 2008-12-01 21:20
2008-12-01 19:50 . 2008-12-01 19:50
2008-12-01 19:41 . 2003-12-08 11:53 36,256 --a------ c:\windows\system32\drivers\alcan5ln.sys
2008-11-27 20:55 . 2008-11-27 20:55
2008-11-25 22:59 . 2008-12-02 19:23 3,375,681 --a------ c:\windows{00000002-00000000-00000002-00001102-00000002-100A1102}.BAK
2008-11-25 18:22 . 2008-11-25 18:22
2008-11-24 23:04 . 2008-11-24 23:04
2008-11-24 23:04 . 2008-11-24 23:04
2008-11-24 19:10 . 2008-11-24 19:10
2008-11-24 19:08 . 2008-11-24 19:08
2008-11-24 19:01 . 2008-11-24 19:01
2008-11-24 18:59 . 2008-11-24 18:59
2008-11-24 18:59 . 2005-03-08 05:43 51,120 -ra------ c:\windows\system32\drivers\HPZid412.sys
2008-11-24 18:59 . 2005-03-08 05:43 16,496 -ra------ c:\windows\system32\drivers\HPZipr12.sys
2008-11-24 18:58 . 2005-03-08 05:43 21,744 -ra------ c:\windows\system32\drivers\HPZius12.sys
2008-11-24 18:58 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-11-24 18:58 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\dllcache\usbscan.sys
2008-11-24 18:55 . 2008-11-24 18:33 113,479 --------- c:\windows\hpoins07.dat.temp
2008-11-24 18:55 . 2005-05-24 09:22 21,124 --------- c:\windows\hpomdl07.dat.temp
2008-11-24 18:28 . 2008-11-24 18:28
2008-11-24 18:28 . 2004-08-03 23:08 26,496 --a------ c:\windows\system32\dllcache\usbstor.sys
2008-11-24 18:24 . 2008-11-24 19:09 113,547 --a------ c:\windows\hpoins07.dat
2008-11-24 18:24 . 2005-05-24 09:22 21,124 --------- c:\windows\hpomdl07.dat
2008-11-24 18:18 . 2008-11-24 18:18
2008-11-19 21:18 . 2008-11-19 21:18
2008-11-19 21:16 . 2005-11-10 13:03 49,265 --a------ c:\windows\system32\jpicpl32.cpl
2008-11-19 21:15 . 2008-11-19 21:15
2008-11-19 21:15 . 2008-11-19 21:15
2008-11-18 18:22 . 2008-11-18 18:22
2008-11-18 18:22 . 2008-11-18 18:22
2008-11-16 20:05 . 2008-12-02 16:51 138,512 --a------ c:\windows\system32\drivers\PnkBstrK.sys
2008-11-16 20:04 . 2008-11-16 20:04
2008-11-16 20:04 . 2008-12-02 16:51 201,440 --a------ c:\windows\system32\PnkBstrB.exe
2008-11-16 20:04 . 2008-11-16 20:04 66,872 --a------ c:\windows\system32\PnkBstrA.exe
2008-11-16 20:02 . 2008-11-16 20:03
2008-11-16 20:02 . 2008-11-16 20:02
2008-11-16 19:51 . 2008-11-16 19:51
2008-11-16 19:51 . 2008-11-16 19:51
2008-11-16 18:50 . 2008-11-16 18:50 118,784 -r------- c:\windows\bwUnin-7.2.0.137-8876480SL.exe
2008-11-16 17:15 . 2008-11-16 17:15
2008-11-16 17:15 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2008-11-16 17:13 . 2008-11-16 17:13
2008-11-16 17:13 . 2008-11-16 17:13
2008-11-16 17:13 . 2008-11-16 17:13
2008-11-16 16:01 . 2008-11-16 16:01
2008-11-16 16:00 . 2008-11-16 16:00
2008-11-15 22:43 . 2004-12-10 12:48 68,992 --a------ c:\windows\system32\drivers\LMouKE.Sys
2008-11-15 22:43 . 2004-12-10 12:48 52,992 --a------ c:\windows\system32\drivers\L8042MOU.SYS
2008-11-15 22:37 . 2004-12-10 12:48 36,480 --a------ c:\windows\system32\drivers\LHidUsbK.sys
2008-11-15 22:36 . 2008-11-15 22:36
2008-11-15 22:36 . 2003-03-18 21:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2008-11-15 22:36 . 2003-03-18 21:12 1,047,552 --a------ c:\windows\system32\MFC71u.dll
2008-11-15 22:36 . 2003-03-18 20:14 499,712 --a------ c:\windows\system32\msvcp71.dll
2008-11-15 22:36 . 2003-03-18 19:05 89,088 --a------ c:\windows\system32\atl71.dll
2008-11-15 22:35 . 2004-12-10 12:45 49,152 --a------ c:\windows\KHALMNPR.Exe
2008-11-15 22:35 . 2004-12-10 12:48 24,704 --a------ c:\windows\system32\drivers\LHidKE.Sys
2008-11-15 22:35 . 2004-12-10 12:47 13,056 --a------ c:\windows\system32\drivers\L8042Kbd.sys
2008-11-15 14:33 . 2008-11-15 14:33
2008-11-15 14:33 . 2008-11-15 14:33
2008-11-15 14:33 . 2007-04-23 02:15 3,596,288 --a------ c:\windows\system32\qt-dx331.dll
2008-11-15 14:33 . 2007-06-28 18:52 765,952 --a------ c:\windows\system32\xvidcore.dll
2008-11-15 14:33 . 2007-05-31 08:44 740,442 --a------ c:\windows\system32\divx.dll
2008-11-15 14:33 . 2007-06-07 21:11 380,928 --a------ c:\windows\system32\ac3filter.acm
2008-11-15 14:33 . 2004-01-25 18:18 217,088 --a------ c:\windows\system32\yv12vfw.dll
2008-11-15 14:33 . 2007-06-28 18:54 180,224 --a------ c:\windows\system32\xvidvfw.dll
2008-11-15 14:33 . 2007-05-22 11:02 163,840 --a------ c:\windows\system32\unrar.dll
2008-11-15 14:33 . 2007-04-23 02:02 73,728 --a------ c:\windows\system32\dpl100.dll
2008-11-15 14:33 . 2007-07-10 18:55 7,680 --a------ c:\windows\system32\ff_vfw.dll
2008-11-15 14:33 . 2007-07-10 18:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2008-11-15 14:32 . 2008-11-15 14:32
2008-11-13 22:05 . 2004-08-03 23:01 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-11-13 22:05 . 2004-08-03 23:01 25,856 --a------ c:\windows\system32\dllcache\usbprint.sys
2008-11-12 20:22 . 2008-11-12 20:22 754 --a------ c:\windows\WORDPAD.INI
2008-11-12 19:13 . 2008-11-12 19:13
2008-11-12 19:13 . 2008-11-12 19:13
2008-11-12 17:42 . 2008-11-12 17:42
2008-11-12 17:40 . 2008-11-12 17:40
2008-11-12 17:40 . 2008-02-06 03:20 628,760 -ra------ c:\windows\system32\drivers\lvrs.sys
2008-11-12 17:40 . 2008-02-06 03:18 195,096 --------- c:\windows\system32\lvci11701196.dll
2008-11-12 17:40 . 2008-02-06 02:37 66,482 -ra------ c:\windows\system32\lvcoinst.ini
2008-11-12 17:40 . 2008-02-06 03:21 41,752 -ra------ c:\windows\system32\drivers\LVUSBSta.sys
2008-11-12 17:40 . 2008-02-06 02:40 25,056 -ra------ c:\windows\system32\Repository.reg
2008-11-12 17:40 . 2008-02-06 03:17 13,848 -ra------ c:\windows\system32\drivers\lv302af.sys
2008-11-12 17:39 . 2008-11-12 17:39
2008-11-12 17:39 . 2008-11-12 17:39
2008-11-12 17:39 . 2008-11-12 17:39
2008-11-12 17:39 . 2008-11-12 17:40
2008-11-10 21:30 . 2008-11-10 21:30
2008-11-10 21:30 . 2008-11-10 21:30 32 --a------ c:\documents and settings\All Users\Dane aplikacji\ezsid.dat
2008-11-10 21:28 . 2008-11-10 21:28
2008-11-10 21:28 . 2008-11-10 21:28
2008-11-10 21:28 . 2008-11-10 21:28
2008-11-10 21:28 . 2008-11-10 21:28
2008-11-10 21:24 . 2008-11-10 21:25 0 --a------ c:\windows\nsreg.dat
2008-11-10 21:06 . 2008-11-10 21:06
2008-11-10 21:04 . 2003-12-08 11:53 70,688 --a------ c:\windows\system32\drivers\alcaudsl.sys
2008-11-10 21:04 . 2003-12-08 11:53 53,600 --a------ c:\windows\system32\drivers\alcan5wn.sys
2008-11-10 21:04 . 2008-12-02 18:05 16,376 --a------ c:\windows\system32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000002-100A1102}.rfx
2008-11-10 21:04 . 2008-12-02 18:05 16,376 --a------ c:\windows\system32\BMXState-{00000002-00000000-00000002-00001102-00000002-100A1102}.rfx
2008-11-10 21:04 . 2003-12-08 11:53 5,606 --a------ c:\windows\system32\stci.dll
2008-11-10 21:04 . 2003-12-08 11:53 5,280 --a------ c:\windows\system32\drivers\alcawh.sys
2008-11-10 21:04 . 2003-12-08 11:53 3,968 --a------ c:\windows\system32\drivers\alcacr.sys
2008-11-10 21:04 . 2008-12-02 18:05 1,080 --a------ c:\windows\system32\settingsbkup.sfm
2008-11-10 21:04 . 2008-12-02 18:05 1,080 --a------ c:\windows\system32\settings.sfm
2008-11-10 21:04 . 2008-12-02 18:05 288 --a------ c:\windows\system32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000002-100A1102}.dat
2008-11-10 21:04 . 2008-12-02 18:05 288 --a------ c:\windows\system32\DVCState-{00000002-00000000-00000002-00001102-00000002-100A1102}.dat
2008-11-10 21:03 . 2008-11-10 21:03
2008-11-10 21:03 . 2008-12-02 19:23 3,375,681 --a------ c:\windows{00000002-00000000-00000002-00001102-00000002-100A1102}.CDF
2008-11-10 21:02 . 2008-12-02 18:05 24,144 --a------ c:\windows\system32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000002-100A1102}.rfx
2008-11-10 21:02 . 2008-12-02 18:05 24,144 --a------ c:\windows\system32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000002-100A1102}.rfx
2008-11-10 21:01 . 2008-11-10 21:01
2008-11-10 21:00 . 2008-11-10 21:00
2008-11-10 21:00 . 2008-11-10 21:00
2008-11-10 21:00 . 2008-11-10 21:00
2008-11-10 21:00 . 2008-11-10 21:00
2008-11-10 21:00 . 1998-10-29 14:45 306,688 --a------ c:\windows\IsUninst.exe
2008-11-10 20:29 . 2001-07-22 02:15 643,717 --a------ c:\windows\system32\dllcache\ltts1033.lxa
2008-11-10 20:21 . 2008-11-10 20:21
2008-11-10 20:21 . 1998-01-08 02:00 1,048,576 --------- c:\windows\system32\SFMAN.DAT
2008-11-10 20:21 . 1995-01-13 07:10 149,504 --------- c:\windows\system32\MFCANS32.DLL
2008-11-10 20:21 . 1995-01-13 07:10 108,032 --------- c:\windows\system32\MFCUIA32.DLL
2008-11-10 20:21 . 2000-05-11 01:00 90,112 --------- c:\windows\Updreg.EXE
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 18:58 --------- d–h--w c:\program files\InstallShield Installation Information
2008-11-10 18:58 --------- d-----w c:\program files\ATI Technologies
2008-11-10 18:57 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-10 18:42 --------- d-----w c:\program files\microsoft frontpage
2008-11-10 18:40 --------- d-----w c:\program files\Usługi online
.
((((((((((((((((((((((((((((( snapshot@2008-12-02_17.23.24,73 )))))))))))))))))))))))))))))))))))))))))
.
-
2008-07-19 15:43:08 1,163,960 ----a-w c:\windows\system32\aswBoot.exe
-
2008-07-19 15:30:54 94,392 ----a-w c:\windows\system32\AvastSS.scr
-
2008-07-19 15:32:16 26,944 ----a-w c:\windows\system32\drivers\aavmker4.sys
-
2008-07-19 15:37:42 20,560 ----a-w c:\windows\system32\drivers\aswFsBlk.sys
-
2008-01-17 17:34:02 93,264 ----a-w c:\windows\system32\drivers\aswmon.sys
-
2008-07-19 15:37:22 94,416 ----a-w c:\windows\system32\drivers\aswmon2.sys
-
2008-07-19 15:33:42 23,152 ----a-w c:\windows\system32\drivers\aswRdr.sys
-
2008-07-19 15:35:18 78,416 ----a-w c:\windows\system32\drivers\aswSP.sys
-
2008-07-19 15:32:36 42,912 ----a-w c:\windows\system32\drivers\aswTdi.sys
- 2008-12-02 14:37:06 40,128 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-02 18:25:00 40,128 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-02 14:37:06 49,712 ----a-w c:\windows\system32\perfc015.dat
- 2008-12-02 18:25:00 49,712 ----a-w c:\windows\system32\perfc015.dat
- 2008-12-02 14:37:06 311,740 ----a-w c:\windows\system32\perfh009.dat
- 2008-12-02 18:25:00 311,740 ----a-w c:\windows\system32\perfh009.dat
- 2008-12-02 14:37:06 355,830 ----a-w c:\windows\system32\perfh015.dat
-
2008-12-02 18:25:00 355,830 ----a-w c:\windows\system32\perfh015.dat
-
2008-12-02 18:20:44 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_584.dat
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\ctfmon.exe” [2004-08-03 15360]
“Skype”=“c:\program files\Skype\Phone\Skype.exe” [2008-02-01 21898024]
“Gadu-Gadu”=“c:\program files\Gadu-Gadu\gg.exe” [2005-03-31 790528]
“LDM”=“c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe” [2008-11-16 32768]
“EXPLORER.EXE”=“EXPLORER.EXE” [2004-08-03 c:\windows\explorer.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-03-04 13500416]
“WinSys2”=“c:\windows\system32\winsys2.exe” [2008-03-04 208896]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-03-04 86016]
“UpdReg”=“c:\windows\UpdReg.EXE” [2000-05-11 90112]
“Jet Detection”=“c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe” [2001-11-29 28672]
“LogitechCommunicationsManager”=“c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe” [2008-02-13 564496]
“LogitechQuickCamRibbon”=“c:\program files\Logitech\QuickCam\Quickcam.exe” [2008-02-13 2196240]
“SunJavaUpdateSched”=“c:\program files\Java\jre1.5.0_06\bin\jusched.exe” [2005-11-10 36975]
“HP Software Update”=“c:\program files\HP\HP Software Update\HPWuSchd2.exe” [2005-05-11 49152]
“SpeedTouch USB Diagnostics”=“c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe” [2004-01-26 866816]
“NETIANET”=“c:\program files\Netia\Net\netianet.exe” [2007-05-18 493568]
“avast!”=“c:\progra~1\ALWILS~1\Avast4\ashDisp.exe” [2008-07-19 78008]
“nwiz”=“nwiz.exe” [2008-03-04 c:\windows\system32\nwiz.exe]
“CTHelper”=“CTHELPER.EXE” [2003-08-28 c:\windows\system32\CTHELPER.EXE]
“Logitech Hardware Abstraction Layer”=“KHALMNPR.EXE” [2004-12-10 c:\windows\KHALMNPR.Exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2004-08-03 15360]
c:\documents and settings\ty\Menu Start\Programy\Autostart\
Skr˘t (3) do etmin.lnk - d:\programy\etmin.exe [2007-06-07 24064]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-15 434176]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-11-16 450560]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“msacm.ctmp3”= c:\windows\system32\ctmp3.acm
“msacm.ac3filter”= ac3filter.acm
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“c:\Program Files\Gadu-Gadu\gg.exe”=
“c:\Program Files\Microsoft Office\Office12\ONENOTE.EXE”=
“c:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe”=
“d:\mircaaa\mIRC\mirc.exe”=
“d:\The All-Seeing Eye\eye.exe”=
“d:\Wolfenstein - Enemy Territory\ET.exe”=
“d:\BitComet\BitComet.exe”=
“c:\Program Files\Skype\Phone\Skype.exe”=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-02 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-02 20560]
R3 LVRS;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs.sys [2008-11-12 628760]
S3 alcan5ln;SpeedTouch USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\DRIVERS\alcan5ln.sys [2008-12-01 36256]
S3 SetupNTGLM7X;SetupNTGLM7X;??\F:\NTGLM7X.sys []
*Newly Created Service* - CATCHME
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - c:\documents and settings\ty\Dane aplikacji\Mozilla\Firefox\Profiles\x0ml0k7v.default\
FF -: plugin - c:\program files\Adobe\Acrobat 5.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 19:34:58
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
skanowanie ukrytych procesów …
skanowanie ukrytych wpisów autostartu …
skanowanie ukrytych plików …
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-12-02 19:35:26
ComboFix-quarantined-files.txt 2008-12-02 18:35:26
ComboFix2.txt 2008-12-02 18:25:38
Przed: 4 016 209 920 bajtów wolnych
Po: 4,005,789,696 bajtów wolnych
245