Skocz do zawartości


Zdjęcie

Brak dostępu do C: D: E:


  • Zaloguj się, aby dodać odpowiedź
2 odpowiedzi w tym temacie

#1 Lilli

Lilli

    Nowy

  • 2 postów

Napisano 03 02 2008 - 19:09

Witam! Gdy chcę wejść do jednej z 3 partycji wyskakuje mi komunikat "Brak dostępu". Wejść można jedynie przez "eksploruj".
Program Spyware wykrywał mi wielkokrotnie wirusy, trojany- ctfmon. Zawsze gdy Spyware działał nie mogłam się dostać do żadnej partycji.. Ale gdy wyłaczyłam Spywara wszystko działało ok. NIestety dzisiaj komunikat wyskakuje pomimo wyłaczonego Spywara ( z włączonym po skanowaniu to samo).
Zainstalowałam NOD32, który także wygrył tego ctfmon... wykrył usunął.. i nadal to samo:( Pomóżcie...
pozdrawiam:*

  • 0

#2 wncvirus

wncvirus

    Leń !

  • 851 postów

Napisano 04 02 2008 - 00:41

Pokaż logi z combofixa

  • 0

#3 Lilli

Lilli

    Nowy

  • 2 postów

Napisano 05 02 2008 - 18:03

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED Dołączona grafika
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Autorun.inf
D:\Autorun.inf
E:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-01-05 to 2008-02-05 )))))))))))))))))))))))))))))))
.

2008-02-05 16:58 . 2008-02-05 16:58 <DIR> d----c--- C:\Documents and Settings\All Users\Szablony
2008-02-05 16:51 . 2004-08-04 13:00 395,776 --a------ C:\kmd.exe
2008-02-03 14:35 . 2008-02-03 14:35 <DIR> d----c--- C:\Documents and Settings\All Users\Dane aplikacji\ESET
2008-02-02 21:57 . 2008-02-02 21:57 <DIR> d-------- C:\Program Files\Hamachi
2008-02-02 21:57 . 2008-02-05 17:03 <DIR> d-------- C:\Documents and Settings\Kasia &reg;\Dane aplikacji\Hamachi
2008-01-28 11:59 . 2008-02-02 14:36 <DIR> dr-hsc--- C:\Recycled
2008-01-13 14:06 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-01-13 14:06 . 2008-01-13 19:38 385 --a------ C:\WINDOWS\ODBC.INI
2008-01-05 17:00 . 2008-01-05 17:00 <DIR> d-------- C:\Documents and Settings\Kasia &reg;\Dane aplikacji\TamoSoft
2008-01-05 16:59 . 2008-01-05 17:03 <DIR> d-------- C:\Program Files\SmartWhois
2008-01-05 16:59 . 2008-01-05 16:59 <DIR> d----c--- C:\Documents and Settings\All Users\Dane aplikacji\TamoSoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-03 13:27 --------- d-----w C:\Program Files\Spyware Terminator
2008-02-02 20:57 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-02-02 15:01 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-02-01 18:36 --------- d-----w C:\Documents and Settings\Kasia &reg;\Dane aplikacji\BearShare
2008-01-25 16:40 --------- d-----w C:\Program Files\Ganymede
2008-01-19 19:43 --------- d-----w C:\Program Files\Real Alternative
2008-01-05 15:00 --------- d-----w C:\Program Files\BitComet
2008-01-05 14:58 --------- d-----w C:\Program Files\Picasa2
2007-12-28 20:34 --------- d-----w C:\Program Files\BearShare
2007-11-25 10:04 11,690 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-11-07 09:29 723,968 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-07-13 15:37 476,752 -c--a-w C:\Documents and Settings\All Users\Dane aplikacji\pswi_preloaded.exe
2007-07-13 16:46 168 --sh--r C:\WINDOWS\system32\04AE879064.sys
2007-07-13 17:14 56 --sh--r C:\WINDOWS\system32\6D27ACA3FF.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-07-09 08:39 2119104]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [2005-03-05 17:18 2236416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-12-15 21:01 5513216]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-04-20 00:17 421888]

C:\Documents and Settings\Kasia R\Menu Start\Programy\Autostart\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2008-02-02 21:57:34 624416]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^hamachi.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\hamachi.lnk
backup=C:\WINDOWS\pss\hamachi.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Kalendarz XP.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Kalendarz XP.lnk
backup=C:\WINDOWS\pss\Kalendarz XP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
--a------ 2007-12-02 17:09 7820728 C:\Program Files\BearShare\BearShare.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet Accelerator]
C:\Program Files\BitComet Accelerator\BitComet Accelerator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 13:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
--a------ 2007-07-09 08:39 2119104 C:\Program Files\Gadu-Gadu\gg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-06-10 10:44 249856 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-06-10 10:44 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator]
C:\Program Files\Tlen.pl\tlen.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2004-12-15 21:01 5513216 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2004-12-15 21:01 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2004-12-15 21:01 1490944 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
C:\Program Files\Winamp Remote\bin\OrbTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp]
C:\Program Files\PC Tools AntiVirus\PCTAV.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skrót do strony właściwości High Definition Audio]
--------- 2004-03-17 14:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tguard]
C:\Program Files\WebLock\tguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
C:\Program Files\Save\Save.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\wianmpa.exe

R3 cmudax;C-Media High Definition Audio Interface;C:\WINDOWS\system32\drivers\cmudax.sys [2004-10-21 11:56]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys [2006-11-21 20:42]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k510mdfl.sys [2006-11-21 20:42]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\k510mdm.sys [2006-11-21 20:42]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2006-11-21 20:42]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys [2006-11-21 20:42]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c77bcd2-a009-11dc-9b24-000feaf72662}]
\Shell\AutoRun\command - I:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c77bcd4-a009-11dc-9b24-000feaf72662}]
\Shell\AutoRun\command - I:\AutoRun.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-05 17:06:19
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-05 17:06:37
ComboFix-quarantined-files.txt 2008-02-05 16:06:35
.
2008-01-14 15:37:45 --- E O F ---

;)
Działa!.. ;) Dzięki wncvirus ;)
Niech żyje ComboFix ;) !
pozdrawiam:*

  • 0




Użytkownicy przeglądający ten temat: 0

0 użytkowników, 0 gości, 0 anonimowych