Skocz do zawartości


Zdjęcie

Logi - Proces explorer.exe zajmuje 100% cpu


  • Zamknięty Temat jest zamknięty
16 odpowiedzi w tym temacie

#1 Pawel_pl

Pawel_pl

    Początkujący

  • 15 postów

Napisano 31 08 2008 - 20:31

Witam
Tak jak w temacie od jakiegoś czasu explorer znacząco spowalnia mi komputer .
Oto mój log z hijacka:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:25, on 2008-08-31
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\sichost.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
D:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
D:\WINDOWS\system32\ctfmon.exe
C:\TortoiseSVN\bin\TSVNCache.exe
D:\Program Files\Dassault Systemes\B08\intel_a\code\bin\CATSysDemon.exe
D:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\WINDOWS\system32\SvCHOsT.eXE
D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wdfmgr.exe
D:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Windows Media Player\wmplayer.exe
C:\HijackThis\HijackThis.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.3929.cn?tn=102722
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
F2 - REG:system.ini: UserInit=D:\WINDOWS\system32\userinit.exe,D:\WINDOWS\system32\sichost.exe
O1 - Hosts: 127.0.,0
O1 - Hosts: 127.0.01222.volumeplay1.com
O1 - Hosts: 127.0.0.3adlaji.cn
O1 - Hosts: 127.0.0.lwww.xxie.net
O1 - Hosts: 127.0.01www.gfrgfrsa.cn
O1 - Hosts: 202.165.102.205 972.aksjd11.com
O1 - Hosts: 202.165.102.205 w3og.cn
O1 - Hosts: 203.208.35.100 qazc.fourtw.cn
O1 - Hosts: 203.208.35.100 www.aujoy.cn
O1 - Hosts: 203.208.35.101 www.hao601.cn
O1 - Hosts: 203.208.35.101 www.psp476.cn
O1 - Hosts: 72.14.235.99 222.1212l112.net
O1 - Hosts: 72.14.235.99 444.1212l112.netn
O1 - Hosts: 72.14.235.99 555.1212l112.net
O1 - Hosts: 72.14.235.99 111.1212l112.net
O1 - Hosts: 65.55.21.250 111.3243l24.com
O1 - Hosts: 65.55.21.250 222.3243l24.com
O1 - Hosts: 65.55.21.250 333.3243l24.com
O1 - Hosts: 125.64.8.112 kao2.gmwo03.com
O1 - Hosts: 125.64.8.112 kao.gmwo06.com
O1 - Hosts: 125.64.8.112 444.gmwo07.com
O1 - Hosts: 116.252.185.15 ru.update365.us
O1 - Hosts: 116.252.185.15 ad.update365.us
O1 - Hosts: 207.46.232.182 popmails.net
O1 - Hosts: 203.208.37.99 3.goodhh.com
O1 - Hosts: 220.181.37.55 down.rwixr.com
O1 - Hosts: 160.79.42.52 www.xdj2008.com
O1 - Hosts: 63.175.76.152 www.revtr.cn
O1 - Hosts: 219.133.40.91 qq.ljsll.com
O1 - Hosts: 203.208.35.102 www.aassccwe.cn
O1 - Hosts: 209.132.177.50 973.aksjd11.com
O1 - Hosts: 209.132.177.50 974.aksjd11.com
O1 - Hosts: 209.132.177.50 971.aksjd11.com
O1 - Hosts: 209.132.177.50 975.aksjd11.com
O1 - Hosts: 72.14.235.104 user1.12-39.net
O1 - Hosts: 72.14.235.147 www.infomt.net
O1 - Hosts: 192.150.18.101 ata1.sysions.net
O1 - Hosts: 192.150.18.101 ata2.sysions.net
O1 - Hosts: 192.150.18.101 ata3.sysions.net
O1 - Hosts: 192.150.18.101 ata4.sysions.net
O1 - Hosts: 193.120.42.226 8nnnnn99.cn
O1 - Hosts: 24.39.54.34 www.haoaoao.cn
O2 - BHO: AcroIEHlprObj Class - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - D:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - D:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [AudioDeck] D:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [NeroFilterCheck] D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "D:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "D:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [3PMmUpdate] rundll32 "D:\WINDOWS\Update.dll",Main
O4 - HKLM\..\Run: [HBService] explore.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Add to AMV Converter... - D:\Program Files\MP3 Player Utilities 4.09\AMVConverter\grab.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - D:\Program Files\MP3 Player Utilities 4.09\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - D:\Program Files\Messenger\msgmr.dll
O21 - SSODL: sysocmgr - {DA1DE019-A6A8-ED40-4B87-248B2A93DE99} - D:\WINDOWS\sysocmgr.dll
O21 - SSODL: inetresdxc.dll - {BB4E3499-0132-4d3f-849A-2BE1B26D84E1} - D:\WINDOWS\system32\inetresdxc.dll
O21 - SSODL: certmgrkd.dll - {9E8287B0-0F3A-48ae-99C5-A6E0AAC36BC5} - D:\WINDOWS\system32\certmgrkd.dll
O21 - SSODL: dispexcb.dll - {76D44356-B494-443a-BEDC-AA68DE4255E6} - D:\WINDOWS\system32\dispexcb.dll
O21 - SSODL: slbiopfs2.dll - {EB9660D8-E1CD-4ff0-B4A9-00CD907F928A} - D:\WINDOWS\system32\slbiopfs2.dll
O21 - SSODL: imgutilhx2.dll - {DA56B183-A731-402b-9235-2CB8803E212D} - D:\WINDOWS\system32\imgutilhx2.dll
O21 - SSODL: tscfgwmijxsj.dll - {2CB77746-8ECC-40ca-8217-10CA8BE5EFC8} - D:\WINDOWS\system32\tscfgwmijxsj.dll
O21 - SSODL: bitdldgo.dll - {21BE5FDF-D4CB-4850-AD99-21E68B50BF3F} - D:\WINDOWS\system32\bitdldgo.dll
O21 - SSODL: xolehlpjh.dll - {F0930A2F-D971-4828-8209-B7DFD266ED44} - D:\WINDOWS\system32\xolehlpjh.dll
O21 - SSODL: mstimewd.dll - {65056902-6E7B-4bd7-95BA-688DB5FA5BEB} - D:\WINDOWS\system32\mstimewd.dll
O21 - SSODL: adsntzt.dll - {E0F3526A-4165-4589-80CD-50B6FBAC3BDA} - D:\WINDOWS\system32\adsntzt.dll
O21 - SSODL: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - D:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
O23 - Service: ci (alga) - Unknown owner - D:\WINDOWS\system32\alga.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - D:\Program Files\Dassault Systemes\B08\intel_a\code\bin\CATSysDemon.exe
O23 - Service: {C8C5F96A-1521-4854-97D0-F391F129AF68} (fincfmmh) - Unknown owner - E:\ophcrack\pwdump\imokav.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: kernel32 - Unknown owner - c:\windows\system32\KERNEL32.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - D:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: mfc42 - Unknown owner - c:\windows\mfc42.exe (file missing)
O23 - Service: DurrentControlSetione (MsWin32Reggdit) - Unknown owner - C:\WINDOWS\system32\serev.exe (file missing)
O23 - Service: National Instruments Domain Service (NIDomainService) - Unknown owner - D:\WINDOWS\system32\scardsvc.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: QQ¸üĐ·ţÎń (QQUpdate) - Unknown owner - D:\WINDOWS\system32\QQUpdate.exe (file missing)
O23 - Service: service_display (service_svcname) - Unknown owner - D:\WINDOWS\system32\servciesa.exe (file missing)
O23 - Service: Desktop Drivers (TopdeskDriver) - Unknown owner - D:\WINDOWS\system32\explsore.exe (file missing)

--
End of file - 10841 bytes
Z góry dzięki za pomoc.

  • 0

#2 karolkuich

karolkuich

    Początkujący

  • 141 postów

Napisano 31 08 2008 - 23:05

No jest tego troszkę... :)

Nie ma co sie męczyć z Hijackiem... Daj od razu ComboFix : http://forum.idg.pl/index.php?showtopic=118804 , ale wcześniej pobierz i użyj wszystkich programów z tej strony : http://www.bezpieczenstwosystemow.pl/index.php?topic=266.0 , w szczególności HostsXpert w tej opcji : 4. Restore MS Hosts File przywraca plik HOSTS do prawidłowej postaci.


  • 0

#3 Pawel_pl

Pawel_pl

    Początkujący

  • 15 postów

Napisano 01 09 2008 - 12:33

Zrobiłem tak jak kazałeś z tym ,że używając HostsXpert nie miałem tej opcji do wyboru,zamiast tego delete'nołem wszystkie linie prócz localhost.
Log z Combofix:
ComboFix 08-08-29.02 - Administrator 2008-09-01 12:10:55.9 - NTFSx86 NETWORK
Running from: D:\Documents and Settings\Administrator\Pulpit\ComboFix.exe

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED [img]http://www.forum.tweaks.pl/public/style_emoticons/default/excl.gif[/img][/b][/color]
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Program Files\Messenger\msgmr.dll
D:\WINDOWS\AppPatch\AcSpecf.sdb
D:\WINDOWS\AppPatch\AcXtrnel.sdb
D:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
D:\WINDOWS\Fonts\Framdee.ttf
D:\WINDOWS\linkinfo.dll
D:\WINDOWS\sysocmgr.dll
D:\WINDOWS\system32\adsntzt.dll
D:\WINDOWS\system32\adsntzt.nls
D:\WINDOWS\system32\avicapwm.dll
D:\WINDOWS\system32\avicapwm.nls
D:\WINDOWS\system32\bootvidgj.dll
D:\WINDOWS\system32\bootvidgj.nls
D:\WINDOWS\system32\certmgrkd.dll
D:\WINDOWS\system32\certmgrkd.nls
D:\WINDOWS\system32\cliconfgzx.dll
D:\WINDOWS\system32\cliconfgzx.nls
D:\WINDOWS\system32\discard.ini
D:\WINDOWS\system32\dispexcb.dll
D:\WINDOWS\system32\dispexcb.nls
D:\WINDOWS\system32\dpvvoxmh.dll
D:\WINDOWS\system32\dpvvoxmh.nls
D:\WINDOWS\system32\drivers\HBKernel.sys
D:\WINDOWS\system32\drivers\nvmini.sys
D:\WINDOWS\system32\eskisl.dll
D:\WINDOWS\system32\explore.exe
D:\WINDOWS\system32\havser.ini
D:\WINDOWS\system32\HBmhly.dll
D:\WINDOWS\system32\imgutilhx2.dll
D:\WINDOWS\system32\imgutilhx2.nls
D:\WINDOWS\system32\kandaof.dll
D:\WINDOWS\system32\lensch.dll
D:\WINDOWS\system32\mshta.dll
D:\WINDOWS\system32\mstimewd.dll
D:\WINDOWS\system32\mstimewd.nls
D:\WINDOWS\system32\Nessery.sys
D:\WINDOWS\system32\ntvdm32.exe
D:\WINDOWS\system32\qxfel.dll
D:\WINDOWS\system32\qxfelk.exe
D:\WINDOWS\system32\rasdlgcq.dll
D:\WINDOWS\system32\rasdlgcq.nls
D:\WINDOWS\system32\scrruncqsj.dll
D:\WINDOWS\system32\scrruncqsj.nls
D:\WINDOWS\system32\sichost.exe
D:\WINDOWS\system32\slbiopfs2.dll
D:\WINDOWS\system32\slbiopfs2.nls
D:\WINDOWS\system32\sovlost.exe
D:\WINDOWS\system32\sufost.ini
D:\WINDOWS\system32\thermaltinc.dll
D:\WINDOWS\system32\tscfgwmijxsj.dll
D:\WINDOWS\system32\tscfgwmijxsj.nls
D:\WINDOWS\system32\Update.dat
D:\WINDOWS\system32\url1.exe
D:\WINDOWS\system32\wllame.dll
D:\WINDOWS\system32\zgtwfx.dll
D:\WINDOWS\temp\wmsetup.dll
D:\WINDOWS\Update.dll

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_HBKERNEL
-------\Legacy_KERNEL32
-------\Legacy_MFC42
-------\Legacy_NESSERY
-------\Legacy_NVMINI
-------\Service_HBKernel
-------\Service_kernel32
-------\Service_mfc42
-------\Service_Nessery
-------\Service_nvmini
-------\Service_RESSDT


(((((((((((((((((((((((((   Files Created from 2008-08-01 to 2008-09-01  )))))))))))))))))))))))))))))))
.

2008-09-01 09:40 . 2008-09-01 09:40	1,004,320	--a------	D:\WINDOWS\system32\dwikuquh.dll
2008-09-01 09:40 . 2008-09-01 09:40	288	--a------	D:\WINDOWS\system32\dwikuquh.nls
2008-09-01 08:23 . 2008-09-01 08:23	73,728	-rahs----	D:\WINDOWS\LOIK0SCH.exe
2008-09-01 08:23 . 2008-09-01 08:23	73,728	-r-hs----	D:\WINDOWS\GR1K5LHVCI.exe
2008-09-01 08:23 . 2008-09-01 08:23	28,672	--a------	D:\WINDOWS\DQDRTB.exe
2008-09-01 08:14 . 2008-09-01 08:14	61,440	-r-hs----	D:\WINDOWS\U58CLZC97.exe
2008-09-01 08:14 . 2008-09-01 08:14	61,440	-rahs----	D:\WINDOWS\778VT.exe
2008-09-01 08:14 . 2008-09-01 08:14	28,672	--a------	D:\WINDOWS\QFR75FN7.exe
2008-09-01 07:00 . 2008-09-01 07:00	61,440	--a------	D:\WINDOWS\27PA8F5HP8SL.exe
2008-09-01 06:59 . 2008-09-01 06:59	61,440	--a------	D:\WINDOWS\O5GZD.exe
2008-09-01 06:58 . 2008-09-01 06:58	61,440	-rahs----	D:\WINDOWS\LENOJ.exe
2008-09-01 06:58 . 2008-09-01 06:58	61,440	-r-hs----	D:\WINDOWS\156FYY2OO.exe
2008-09-01 06:58 . 2008-09-01 06:58	28,672	--a------	D:\WINDOWS\7L710W67U.exe
2008-08-31 18:08 . 2008-08-31 18:07	73,728	-rahs----	D:\WINDOWS\NS7MT.exe
2008-08-31 18:08 . 2008-08-31 18:08	73,728	--a------	D:\WINDOWS\L48YQRKYT.exe
2008-08-31 18:08 . 2008-08-31 18:08	28,672	--a------	D:\WINDOWS\3SSMRIPWV24.exe
2008-08-31 18:07 . 2008-08-31 18:07	73,728	-r-hs----	D:\WINDOWS\3A105M16OW.exe
2008-08-31 17:26 . 2008-08-31 17:25	73,728	-rahs----	D:\WINDOWS\K8QWY1FBH.exe
2008-08-31 17:26 . 2008-08-31 17:26	28,672	--a------	D:\WINDOWS\MJ9ZB.exe
2008-08-31 17:25 . 2008-08-31 17:25	73,728	-r-hs----	D:\WINDOWS\SSVQHMV3Q.exe
2008-08-31 15:26 . 2008-08-31 15:25	73,728	-rahs----	D:\WINDOWS\YMGIOK.exe
2008-08-31 15:26 . 2008-08-31 15:26	28,672	--a------	D:\WINDOWS\E3Y8BLT.exe
2008-08-31 15:25 . 2008-08-31 15:25	73,728	-r-hs----	D:\WINDOWS\7QSR2K0YXD.exe
2008-08-31 15:09 . 2008-08-31 15:08	73,728	-rahs----	D:\WINDOWS\4UOMDGR88H.exe
2008-08-31 15:09 . 2008-08-31 15:09	28,672	--a------	D:\WINDOWS\EVTCPQ2AIQQ2.exe
2008-08-31 15:08 . 2008-08-31 15:08	73,728	-r-hs----	D:\WINDOWS\A1EWHE1YQ1L5.exe
2008-08-31 14:58 . 2008-09-01 09:41	793,376	--a------	D:\WINDOWS\system32\xolehlpjh.dll
2008-08-31 14:58 . 2008-08-31 14:58	28,672	--a------	D:\WINDOWS\system32\cxpop.dll
2008-08-31 14:58 . 2008-08-31 14:58	288	--a------	D:\WINDOWS\system32\xolehlpjh.nls
2008-08-31 14:58 . 2008-08-31 14:58	288	--a------	D:\WINDOWS\system32\bitdldgo.nls
2008-08-31 14:57 . 2008-09-01 08:10	714,528	--a------	D:\WINDOWS\system32\inetresdxc.dll
2008-08-31 14:57 . 2008-08-31 14:57	288	--a------	D:\WINDOWS\system32\inetresdxc.nls
2008-08-31 14:56 . 2008-08-31 14:56	10,752	--a------	D:\WINDOWS\~Temp5359.tmp
2008-08-31 14:51 . 2008-08-31 14:51	61,440	-rahs----	D:\WINDOWS\DL1CRX.exe
2008-08-31 14:51 . 2008-08-31 14:51	28,672	--a------	D:\WINDOWS\8P8LQ3NB.exe
2008-08-31 14:31 . 2008-08-31 14:31	73,728	-r-hs----	D:\WINDOWS\UNCCA8.exe
2008-08-31 14:31 . 2008-08-31 14:31	73,728	-rahs----	D:\WINDOWS\5NUS2BO.exe
2008-08-31 14:31 . 2008-08-31 14:31	28,672	--a------	D:\WINDOWS\8XYDU.exe
2008-08-31 13:57 . 2008-08-31 13:57	<DIR>	d--------	D:\Program Files\Spybot - Search & Destroy
2008-08-31 13:57 . 2008-08-31 14:26	<DIR>	d--------	D:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Spybot - Search & Destroy
2008-08-31 13:15 . 2008-08-31 13:15	61,440	-r-hs----	D:\WINDOWS\QOI5OX.exe
2008-08-31 13:15 . 2008-08-31 13:15	61,440	-rahs----	D:\WINDOWS\AQY29LQX8.exe
2008-08-31 13:15 . 2008-08-31 13:15	28,672	--a------	D:\WINDOWS\BKD5U3R6BL.exe
2008-08-31 12:33 . 2008-08-31 12:33	73,728	-rahs----	D:\WINDOWS\S8NGB9LI3VUU.exe
2008-08-31 12:33 . 2008-08-31 12:33	28,672	--a------	D:\WINDOWS\3BABBV7PB.exe
2008-08-31 10:49 . 2008-08-31 11:39	37,129	--a------	D:\WINDOWS\system32\wincecomm.exe
2008-08-30 12:57 . 2008-08-31 15:00	<DIR>	d--------	D:\!KillBox
2008-08-28 14:35 . 2008-08-28 14:34	14,943	--a------	D:\WINDOWS\system32\vistaXA.exe
2008-08-28 14:35 . 2008-08-28 14:34	14,943	--a------	D:\WINDOWS\system32\config\systemprofile\vistaXA.exe
2008-08-28 09:28 . 2008-08-28 09:28	23,552	---hs----	D:\WINDOWS\system32\alga.exe
2008-08-26 22:43 . 	<DIR>		D:\Documents and Settings\LocalService.ZARZąDZANIE NT\Ulubione
2008-08-26 22:43 . 	<DIR>		D:\Documents and Settings\LocalService.ZARZąDZANIE NT\Ulubione
2008-08-26 22:43 . 	<DIR>		D:\Documents and Settings\LocalService.ZARZąDZANIE NT\Dane aplikacji\Google
2008-08-23 18:07 . 2008-09-01 10:55	70,993	--a------	D:\WINDOWS\system32\zlzogu.rds
2008-08-23 13:45 . 2008-08-23 13:45	<DIR>	d--------	D:\Program Files\3DO
2008-08-19 17:35 . 2008-08-19 17:35	13,054	--a------	D:\WINDOWS\tianlong.exe
2008-08-19 17:33 . 2008-08-19 17:33	923,424	--a------	D:\WINDOWS\system32\abqzzdos.dll
2008-08-19 17:33 . 2004-08-04 14:00	395,776	--a------	D:\WINDOWS\system32\tmpzydf0.exe
2008-08-19 17:33 . 2004-08-04 14:00	395,776	--a------	D:\WINDOWS\system32\tmplljydf1.exe
2008-08-19 17:33 . 2008-08-19 17:33	13,824	--a------	D:\WINDOWS\moyu.exe
2008-08-19 17:33 . 2008-08-19 17:33	288	--a------	D:\WINDOWS\system32\abqzzdos.nls
2008-08-19 17:13 . 2008-08-19 17:13	288	--a------	D:\WINDOWS\system32\rponvneb.nls
2008-08-19 17:12 . 2004-08-04 14:00	395,776	--a------	D:\WINDOWS\system32\tmpzydf1.exe
2008-08-19 15:15 . 2008-08-19 15:15	0	--a------	D:\Documents and Settings\MUZYKA.MUZYKA-CA405851\dhtnodes.dat
2008-08-19 14:56 . 2004-08-04 14:00	395,776	--a------	D:\WINDOWS\system32\tmplljydf3.exe
2008-08-19 14:56 . 2008-08-19 14:56	14,072	--a------	D:\WINDOWS\system32\mstmpxmlfun.xml
2008-08-19 14:56 . 2008-08-19 14:56	288	--a------	D:\WINDOWS\system32\ebeeyipj.nls
2008-08-19 10:28 . 2008-08-19 10:28	288	--a------	D:\WINDOWS\system32\dbtqyucx.nls
2008-08-19 10:27 . 2004-08-04 14:00	395,776	--a------	D:\WINDOWS\system32\tmpzydf2.exe
2008-08-19 08:36 . 2008-08-19 08:36	288	--a------	D:\WINDOWS\system32\apvofwfj.nls
2008-08-18 22:04 . 2008-08-18 22:04	288	--a------	D:\WINDOWS\system32\heavtjkn.nls
2008-08-18 19:06 . 2008-08-18 19:06	11,776	--a------	D:\WINDOWS\system32\follwelk.exe
2008-08-18 19:04 . 2008-08-18 19:04	288	--a------	D:\WINDOWS\system32\tbfdimbq.nls
2008-08-18 17:13 . 2008-08-18 17:13	288	--a------	D:\WINDOWS\system32\klozsfcy.nls
2008-08-18 09:22 . 2008-08-19 17:19	34,816	--a------	D:\WINDOWS\setup_102722.exe
2008-08-18 09:09 . 2008-08-18 09:09	288	--a------	D:\WINDOWS\system32\lghmavuu.nls
2008-08-18 09:07 . 2004-08-04 14:00	395,776	--a------	D:\WINDOWS\system32\tmpzydf3.exe
2008-08-18 09:00 . 2008-08-18 09:00	288	--a------	D:\WINDOWS\system32\jmgkxhqh.nls
2008-08-17 20:12 . 2008-08-17 20:12	288	--a------	D:\WINDOWS\system32\qfrnguvx.nls
2008-08-17 17:19 . 2008-08-17 17:18	36,352	--a------	D:\WINDOWS\system32\sovnost.exe
2008-08-17 17:19 . 2008-08-17 17:19	2,432	--a------	D:\WINDOWS\system32\Fessery.sys
2008-08-17 17:18 . 2008-08-17 17:18	20,480	--a------	D:\WINDOWS\system32\soulost.exe
2008-08-17 17:12 . 2008-08-17 17:12	288	--a------	D:\WINDOWS\system32\pnalmwps.nls
2008-08-17 14:19 . 2008-08-19 17:19	696,980	--a------	D:\WINDOWS\system32\twainyy.dll
2008-08-17 14:19 . 2008-08-19 17:18	28,672	--a------	D:\WINDOWS\system32\ringtte.dll
2008-08-17 14:13 . 2008-08-17 14:13	288	--a------	D:\WINDOWS\system32\ervurvsl.nls
2008-08-17 13:54 . 2008-08-17 13:54	148	--a------	D:\WINDOWS\system32\twainyy.nls
2008-08-17 13:38 . 2008-08-17 13:38	288	--a------	D:\WINDOWS\system32\znedvadj.nls
2008-08-16 19:59 . 2008-08-16 19:59	288	--a------	D:\WINDOWS\system32\hzyjyvbx.nls
2008-08-16 15:08 . 2008-08-16 15:08	<DIR>	d--------	D:\Program Files\Funshion Online
2008-08-16 15:08 . 2008-08-16 15:09	<DIR>	d--------	D:\Documents and Settings\MUZYKA.MUZYKA-CA405851\funshion
2008-08-16 15:08 . 2004-08-04 14:00	359,040	--a------	D:\WINDOWS\system32\drivers\tcpip.sys.do
2008-08-16 15:08 . 2008-08-19 17:50	28	--a------	D:\WINDOWS\funshionplugin2.INI
2008-08-16 14:57 . 2008-08-16 14:57	288	--a------	D:\WINDOWS\system32\utozuonl.nls
2008-08-16 11:34 . 2008-08-16 11:34	288	--a------	D:\WINDOWS\system32\hlkbtqiw.nls
2008-08-16 08:39 . 2008-08-16 20:05	740,500	--a------	D:\WINDOWS\system32\kbdgrms(2).dll
2008-08-16 08:39 . 2008-08-16 20:05	577,452	--a------	D:\WINDOWS\system32\bootvidgj(2).dll
2008-08-16 08:38 . 2008-08-16 20:04	696,236	--a------	D:\WINDOWS\system32\slbiopfs2(2).dll
2008-08-16 08:37 . 2008-08-16 20:04	921,516	--a------	D:\WINDOWS\system32\comuidsg(2).dll
2008-08-16 08:37 . 2008-08-16 20:02	651,180	--a------	D:\WINDOWS\system32\tscfgwmijxsj(2).dll
2008-08-16 08:36 . 2008-08-16 20:01	955,820	--a------	D:\WINDOWS\system32\catsrvwl(2).dll
2008-08-16 08:36 . 2008-08-16 20:02	737,708	--a------	D:\WINDOWS\system32\dispexcb(2).dll
2008-08-16 08:36 . 2008-08-19 17:15	28,672	--a------	D:\WINDOWS\system32\follwel.dll
2008-08-16 08:35 . 2008-08-16 20:00	1,055,380	--a------	D:\WINDOWS\system32\dpvvoxmh(2).dll
2008-08-16 08:35 . 2008-08-16 20:01	841,504	--a------	D:\WINDOWS\system32\adsntzt(2).dll
2008-08-16 08:35 . 2008-08-16 20:01	664,492	--a------	D:\WINDOWS\system32\lweurqhx(2).dll
2008-08-16 08:35 . 2008-08-16 20:01	570,284	--a------	D:\WINDOWS\system32\msobjstl(2).dll
2008-08-16 08:34 . 2008-08-19 17:34	22,520	--a------	D:\WINDOWS\system32\xsbvgzd.exe
2008-08-16 08:34 . 2008-08-16 08:34	288	--a------	D:\WINDOWS\system32\xwccdqrm.nls
2008-08-16 08:34 . 2008-08-19 17:42	280	---hs----	D:\WINDOWS\system32\xsbvgzd.cfg
2008-08-15 22:01 . 2008-08-19 17:42	44,544	--a------	D:\WINDOWS\system\dljj32a.dll
2008-08-15 21:14 . 2008-08-16 09:41	114	--a------	D:\WINDOWS\7THLEVEL.INI
2008-08-11 11:43 . 2008-08-11 11:44	<DIR>	d--------	D:\Do Ostatniego Pocisku
2008-08-10 13:06 . 2008-08-10 13:08	<DIR>	d--------	D:\First Game in Ogre
2008-08-08 16:26 . 2008-08-08 16:26	39,032	--a------	D:\WINDOWS\system32\ilu.dll
2008-08-08 16:26 . 2008-08-08 16:26	26,792	--a------	D:\WINDOWS\system32\ilut.dll
2008-08-07 19:54 . 2008-08-07 19:54	107,888	--a------	D:\WINDOWS\system32\CmdLineExt.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-01 10:18	233,472	----a-w	D:\Documents and Settings\NetworkService.ZARZąDZANIE NT\NTUSER.DAT
2008-09-01 10:18	233,472	----a-w	D:\Documents and Settings\NetworkService.ZARZąDZANIE NT\NTUSER.DAT
2008-09-01 10:18	233,472	----a-w	D:\Documents and Settings\LocalService.ZARZąDZANIE NT\NTUSER.DAT
2008-09-01 10:18	233,472	----a-w	D:\Documents and Settings\LocalService.ZARZąDZANIE NT\NTUSER.DAT
2008-08-31 12:30	4,224	----a-w	D:\WINDOWS\system32\drivers\beep.sys
2008-08-16 15:04	---------	d--h--w	D:\Program Files\InstallShield Installation Information
2008-08-08 15:47	---------	d-----w	D:\Program Files\Sony
2008-08-08 15:46	---------	d-----w	D:\Program Files\Sunny Ball
2008-08-08 15:45	---------	d-----w	D:\Program Files\AGEIA Technologies
2008-08-08 08:50	---------	d-----w	D:\Program Files\GameHouse
2008-07-28 14:00	---------	d-----w	D:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Microsoft Help
2008-07-28 13:51	---------	d-----w	D:\Program Files\Microsoft Visual Studio .NET 2003
2008-07-28 08:58	---------	d-----w	D:\Program Files\Common Files\Merge Modules
2008-07-28 08:56	---------	d-----w	D:\Program Files\Microsoft.NET
2008-07-26 14:58	---------	d-----w	D:\Program Files\3D Exploration
2008-07-26 12:51	---------	d-----w	D:\Program Files\directx
2008-07-25 22:05	---------	d-----w	D:\Program Files\Edgard Multimedia
2008-07-25 20:59	---------	d-----w	D:\Program Files\Edgard
2008-07-20 21:06	---------	d-----w	D:\Program Files\Auralog
2008-07-17 11:37	---------	d-----w	D:\Program Files\Audible
2008-07-09 18:49	---------	d-----w	D:\Program Files\Canon
2008-07-09 18:47	---------	d-----w	D:\Program Files\Common Files\ScanSoft Shared
2008-07-09 18:47	---------	d-----w	D:\Program Files\Common Files\InstallShield
2008-07-09 18:47	---------	d-----w	D:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ScanSoft
2008-07-09 18:47	---------	d-----w	D:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\InstallShield
2008-07-09 18:46	---------	d-----w	D:\Program Files\ScanSoft
2008-07-09 18:42	---------	d-----w	D:\Program Files\CanonBJ
2008-07-09 18:37	3,072	--sha-w	D:\Program Files\Thumbs.db
2008-07-09 18:37	---------	d-----w	D:\Program Files\Winamp Remote
2008-07-09 18:28	---------	d--h--w	D:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\CanonBJ
2008-07-02 15:39	---------	d-----w	D:\Program Files\MP3 Player Utilities 4.09
2008-03-31 17:06	357	----a-w	D:\Documents and Settings\MUZYKA.MUZYKA-CA405851\.cb_layout.bin
2008-03-18 17:06	3,289	----a-w	D:\Documents and Settings\MUZYKA\ie_updates3r.exe
2008-03-18 16:54	357	----a-w	D:\Documents and Settings\MUZYKA\.cb_layout.bin
2004-08-04 12:00	6,144	--sha-w	D:\WINDOWS\system32\ghjsw.dll
2004-08-17 18:00	75,264	--sh--w	D:\WINDOWS\system32\NetNtEx.dll
2004-08-04 12:00	41,240	--sha-w	D:\WINDOWS\system32\xsbvgzd(2).dll
2004-08-04 12:00	41,240	--sh--w	D:\WINDOWS\system32\xsbvgzd.dll
2004-08-04 12:00	6,144	--sha-w	D:\WINDOWS\system32\zxdtye.dll
.

------- Sigcheck -------

2004-08-04 14:00  108544  fb1d7f253003a07c0bf5fd79c9959bd1	D:\WINDOWS\system32\SERVICES.EXE
2004-08-04 14:00  108544  3da8d964d2cc12ef8e8c342471a37917	D:\WINDOWS\system32\dllcache\services.exe
.
(((((((((((((((((((((((((((((   snapshot@2008-08-30_13.16.17.79   )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 12:00:00	15,576	----a-w	D:\WINDOWS\system32\aolkua.dll
- 2008-08-28 12:35:47	16,384	----a-w	D:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 1982-08-31 08:09:08	16,384	----a-w	D:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-08-28 12:35:47	32,768	----a-w	D:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
+ 1982-08-31 08:09:08	32,768	----a-w	D:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
- 2008-08-28 12:35:53	32,768	----a-w	D:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
+ 1982-08-31 08:09:08	32,768	----a-w	D:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
- 2008-08-30 10:44:28	4,224	-c--a-w	D:\WINDOWS\system32\dllcache\beep.sys
+ 2008-08-31 12:30:29	4,224	-c--a-w	D:\WINDOWS\system32\dllcache\beep.sys
- 2008-08-29 07:14:32	16,896	----a-w	D:\WINDOWS\system32\msisipv6.dll
+ 2008-08-31 09:58:35	16,896	----a-w	D:\WINDOWS\system32\msisipv6.dll
+ 2004-08-04 12:00:00	108,544	----a-w	D:\WINDOWS\system32\wins\mbgpgxnz.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35	536576	--a------	C:\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35	536576	--a------	C:\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35	536576	--a------	C:\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35	536576	--a------	C:\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35	536576	--a------	C:\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35	536576	--a------	C:\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35	536576	--a------	C:\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
"Gadu-Gadu"="C:\Gadu-Gadu\gg.exe" [2008-09-01 08:48 745472]
"SpybotSD TeaTimer"="D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"NeroHomeFirstStart"="D:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe" [2006-12-23 17:43 10752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 13:35 90112]
"AudioDeck"="D:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2006-09-05 19:28 540672]
"NeroFilterCheck"="D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"SSBkgdUpdate"="D:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"OpwareSE4"="D:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 12:02 79400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"4czlpzi5fz"="%systemroot%\system32\4czlpzi5fz.dll" [BU]
"A[beeep]"="%systemroot%\system32\Di83x1.dll" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-03-23 01:16 171448]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}"= "D:\WINDOWS\system32\inetresdxc.dll" [2008-09-01 08:10 714528]
"{F0930A2F-D971-4828-8209-B7DFD266ED44}"= "D:\WINDOWS\system32\xolehlpjh.dll" [2008-09-01 09:41 793376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"inetresdxc.dll"= {BB4E3499-0132-4d3f-849A-2BE1B26D84E1} - D:\WINDOWS\system32\inetresdxc.dll [2008-09-01 08:10 714528]
"xolehlpjh.dll"= {F0930A2F-D971-4828-8209-B7DFD266ED44} - D:\WINDOWS\system32\xolehlpjh.dll [2008-09-01 09:41 793376]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIVF"= DivX412.dll
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Gadu-Gadu\\gg.exe"=
"E:\\Program Files\\Gadu-Gadu\\gg.exe"=
"D:\\Program Files\\Hamachi\\hamachi.exe"=
"C:\\Tzar\\Tzar.exe"=
"C:\\HydraIRC\\HydraIRC.exe"=

R0 lzdx0zp;lzdx0z;D:\WINDOWS\system32\DRIVERS\lzdx0zp.sys [2004-08-04 14:00]
R0 mejph;mejph;D:\WINDOWS\system32\drivers\mejph.sys [2004-08-04 14:00]
S2 alga;ci;D:\WINDOWS\system32\alga.exe [2008-08-28 09:28]
S2 BBDemon;Backbone Service;D:\Program Files\Dassault Systemes\B08\intel_a\code\bin\CATSysDemon.exe [2001-12-11 22:29]
S2 MsWin32Reggdit;DurrentControlSetione;C:\WINDOWS\system32\serev.exe []
S2 njlocn;njlocn;D:\WINDOWS\system32\SvCHOsT.eXE [2004-08-04 14:00]
S2 QQUpdate;QQ¸üĐ·ţÎń<img src='http://www.forum.tweaks.pl/public/style_emoticons/<#EMO_DIR#>/smile.png' class='bbc_emoticon' alt=':)' />:\WINDOWS\system32\QQUpdate.exe []
S2 service_svcname;service_display;D:\WINDOWS\system32\servciesa.exe []
S2 TopdeskDriver;Desktop Drivers;D:\WINDOWS\system32\explsore.exe []
S3 6E2S9MO7DHG4;MHYF73P6;D:\WINDOWS\7AEWSYF.txt [2008-08-31 14:53]
S3 fincfmmh;{C8C5F96A-1521-4854-97D0-F391F129AF68};E:\ophcrack\pwdump\imokav.exe []
S3 PZKW5D;BOV2LO;D:\WINDOWS\CF6T9CX7I0.txt [2008-08-31 13:15]
S3 TLG1VNGPV4;HCTEXI9II;D:\WINDOWS\VGJ3MGOFN.txt [2008-09-01 07:15]
S3 UK4KOW63Z;N16OEB72JLJ;D:\WINDOWS\79UO0JE47.txt [2008-08-31 18:20]
S4 360°˛Č«ÎŔĘżÉýĽ¶łĚĐň;360°˛Č«ÎŔĘżÉýĽ¶łĚĐň<img src='http://www.forum.tweaks.pl/public/style_emoticons/<#EMO_DIR#>/smile.png' class='bbc_emoticon' alt=':)' />:\WINDOWS\360.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
njlocn	REG_MULTI_SZ   	njlocn
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC} - D:\WINDOWS\system32\rasdlgcq.dll
SSODL-rasdlgcq.dll-{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC} - D:\WINDOWS\system32\rasdlgcq.dll


.
------- Supplementary Scan -------
.
FireFox -: Profile - D:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\rvfq2k5n.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-01 12:19:39
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: D:\WINDOWS\explorer.exe
-> C:\TortoiseSVN\iconv\_tbl_simple.so
-> C:\TortoiseSVN\iconv\windows-1250.so
-> C:\TortoiseSVN\iconv\utf-8.so
.
------------------------ Other Running Processes ------------------------
.
C:\TortoiseSVN\bin\TSVNCache.exe
.
**************************************************************************
.
Completion time: 2008-09-01 12:27:14 - machine was rebooted
ComboFix-quarantined-files.txt  2008-09-01 10:27:08
ComboFix2.txt  2008-08-30 11:16:53
ComboFix3.txt  2008-04-16 16:55:32

Pre-Run: 5,471,432,704 bajtów wolnych
Post-Run: 5,498,941,440 bajt˘w wolnych

387

  • 0

#4 ordynat

ordynat

    Zaawansowany użytkownik

  • 804 postów

Napisano 01 09 2008 - 13:57

Raczej się nie wygrzebierz z tej infekcji - jest już zbyt rozwinięta, rozległa.

Wklej do Notatnika:
File::
D:\WINDOWS\system32\dwikuquh.dll
D:\WINDOWS\system32\dwikuquh.nls
D:\WINDOWS\LOIK0SCH.exe
D:\WINDOWS\GR1K5LHVCI.exe
D:\WINDOWS\DQDRTB.exe
D:\WINDOWS\U58CLZC97.exe
D:\WINDOWS\778VT.exe
D:\WINDOWS\QFR75FN7.exe
D:\WINDOWS\27PA8F5HP8SL.exe
D:\WINDOWS\O5GZD.exe
D:\WINDOWS\LENOJ.exe
D:\WINDOWS\156FYY2OO.exe
D:\WINDOWS\7L710W67U.exe
D:\WINDOWS\NS7MT.exe
D:\WINDOWS\L48YQRKYT.exe
D:\WINDOWS\3SSMRIPWV24.exe
D:\WINDOWS\3A105M16OW.exe
D:\WINDOWS\K8QWY1FBH.exe
D:\WINDOWS\MJ9ZB.exe
D:\WINDOWS\SSVQHMV3Q.exe
D:\WINDOWS\YMGIOK.exe
D:\WINDOWS\E3Y8BLT.exe
D:\WINDOWS\7QSR2K0YXD.exe
D:\WINDOWS\4UOMDGR88H.exe
D:\WINDOWS\EVTCPQ2AIQQ2.exe
D:\WINDOWS\A1EWHE1YQ1L5.exe
D:\WINDOWS\system32\xolehlpjh.dll
D:\WINDOWS\system32\cxpop.dll
D:\WINDOWS\system32\xolehlpjh.nls
D:\WINDOWS\system32\bitdldgo.nls
D:\WINDOWS\system32\inetresdxc.dll
D:\WINDOWS\system32\inetresdxc.nls
D:\WINDOWS\~Temp5359.tmp
D:\WINDOWS\DL1CRX.exe
D:\WINDOWS\8P8LQ3NB.exe
D:\WINDOWS\UNCCA8.exe
D:\WINDOWS\5NUS2BO.exe
D:\WINDOWS\8XYDU.exe
D:\WINDOWS\QOI5OX.exe
D:\WINDOWS\AQY29LQX8.exe
D:\WINDOWS\BKD5U3R6BL.exe
D:\WINDOWS\S8NGB9LI3VUU.exe
D:\WINDOWS\3BABBV7PB.exe
D:\WINDOWS\system32\wincecomm.exe
D:\WINDOWS\system32\vistaXA.exe
D:\WINDOWS\system32\config\systemprofile\vistaXA.exe
D:\WINDOWS\system32\alga.exe
D:\WINDOWS\system32\zlzogu.rds
D:\WINDOWS\tianlong.exe
D:\WINDOWS\system32\abqzzdos.dll
D:\WINDOWS\system32\tmpzydf0.exe
D:\WINDOWS\system32\tmplljydf1.exe
D:\WINDOWS\moyu.exe
D:\WINDOWS\system32\abqzzdos.nls
D:\WINDOWS\system32\rponvneb.nls
D:\WINDOWS\system32\tmpzydf1.exe
D:\WINDOWS\system32\tmplljydf3.exe
D:\WINDOWS\system32\ebeeyipj.nls
D:\WINDOWS\system32\dbtqyucx.nls
D:\WINDOWS\system32\tmpzydf2.exe
D:\WINDOWS\system32\apvofwfj.nls
D:\WINDOWS\system32\heavtjkn.nls
D:\WINDOWS\system32\follwelk.exe
D:\WINDOWS\system32\tbfdimbq.nls
D:\WINDOWS\system32\klozsfcy.nls
D:\WINDOWS\setup_102722.exe
D:\WINDOWS\system32\lghmavuu.nls
D:\WINDOWS\system32\tmpzydf3.exe
D:\WINDOWS\system32\jmgkxhqh.nls
D:\WINDOWS\system32\qfrnguvx.nls
D:\WINDOWS\system32\sovnost.exe
D:\WINDOWS\system32\Fessery.sys
D:\WINDOWS\system32\soulost.exe
D:\WINDOWS\system32\pnalmwps.nls
D:\WINDOWS\system32\twainyy.dll
D:\WINDOWS\system32\ringtte.dll
D:\WINDOWS\system32\ervurvsl.nls
D:\WINDOWS\system32\twainyy.nls
D:\WINDOWS\system32\znedvadj.nls
D:\WINDOWS\system32\hzyjyvbx.nls
D:\WINDOWS\funshionplugin2.INI
D:\WINDOWS\system32\utozuonl.nls
D:\WINDOWS\system32\hlkbtqiw.nls
D:\WINDOWS\system32\kbdgrms(2).dll
D:\WINDOWS\system32\bootvidgj(2).dll
D:\WINDOWS\system32\slbiopfs2(2).dll
D:\WINDOWS\system32\comuidsg(2).dll
D:\WINDOWS\system32\tscfgwmijxsj(2).dll
D:\WINDOWS\system32\catsrvwl(2).dll
D:\WINDOWS\system32\dispexcb(2).dll
D:\WINDOWS\system32\follwel.dll
D:\WINDOWS\system32\dpvvoxmh(2).dll
D:\WINDOWS\system32\adsntzt(2).dll
D:\WINDOWS\system32\lweurqhx(2).dll
D:\WINDOWS\system32\msobjstl(2).dll
D:\WINDOWS\system32\xsbvgzd.exe
D:\WINDOWS\system32\xwccdqrm.nls
D:\WINDOWS\system32\xsbvgzd.cfg
D:\WINDOWS\system\dljj32a.dll
D:\WINDOWS\system32\ghjsw.dll
D:\WINDOWS\system32\NetNtEx.dll
D:\WINDOWS\system32\xsbvgzd(2).dll
D:\WINDOWS\system32\xsbvgzd.dll
D:\WINDOWS\system32\zxdtye.dll
D:\WINDOWS\system32\aolkua.dll
D:\WINDOWS\system32\dllcache\beep.sys
D:\WINDOWS\system32\msisipv6.dll
D:\WINDOWS\system32\msisipv6.dll
D:\WINDOWS\system32\wins\mbgpgxnz.dll
D:\WINDOWS\system32\DRIVERS\lzdx0zp.sys
D:\WINDOWS\system32\drivers\mejph.sys

Driver::
lzdx0zp
mejph
alga
MsWin32Reggdit
njlocn
QQUpdate
service_svcname
TopdeskDriver
6E2S9MO7DHG4
fincfmmh
PZKW5D
TLG1VNGPV4
UK4KOW63Z
360°˛Č?ÎŔĘżÉýĽ?łĚĐň

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"4czlpzi5fz"=-
"A[beeep]"=-
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}"=-
"{F0930A2F-D971-4828-8209-B7DFD266ED44}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"inetresdxc.dll"=-
"xolehlpjh.dll"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
"njlocn"=-

Folder::
D:\!KillBox
>>Plik>>Zapisz jako... >>> CFScript
Przeciągnij i upuść plik CFScript.txt na plik ComboFix.exe
--> Dołączona grafika
Ma się rozpocząć usuwanie. (i powstanie log).
Daj ten log, który powstanie w trakcie usuwania.

ordynat
  • 0

#5 Pawel_pl

Pawel_pl

    Początkujący

  • 15 postów

Napisano 01 09 2008 - 19:58

Przed przeczytaniem twojego posta zrobilem formata ,bo już wogóle programy mi nie chciały działać ,komp troche pochodził i znowu się pojawił problem z explorerem .Użyłem combofix'a tak jak mówiłeś ,a o to log:
ComboFix 08-08-31.01 - MUZYKA 2008-09-01 19:44:39.1 - NTFSx86
Running from: D:\Documents and Settings\MUZYKA\Pulpit\ComboFix.exe
Command switches used :: D:\Documents and Settings\MUZYKA\Pulpit\CFScript.txt.txt

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED [img]http://www.forum.tweaks.pl/public/style_emoticons/default/excl.gif[/img][/b][/color]

FILE ::
D:\WINDOWS\~Temp5359.tmp
D:\WINDOWS\156FYY2OO.exe
D:\WINDOWS\27PA8F5HP8SL.exe
D:\WINDOWS\3A105M16OW.exe
D:\WINDOWS\3BABBV7PB.exe
D:\WINDOWS\3SSMRIPWV24.exe
D:\WINDOWS\4UOMDGR88H.exe
D:\WINDOWS\5NUS2BO.exe
D:\WINDOWS\778VT.exe
D:\WINDOWS\7L710W67U.exe
D:\WINDOWS\7QSR2K0YXD.exe
D:\WINDOWS\8P8LQ3NB.exe
D:\WINDOWS\8XYDU.exe
D:\WINDOWS\A1EWHE1YQ1L5.exe
D:\WINDOWS\AQY29LQX8.exe
D:\WINDOWS\BKD5U3R6BL.exe
D:\WINDOWS\DL1CRX.exe
D:\WINDOWS\DQDRTB.exe
D:\WINDOWS\E3Y8BLT.exe
D:\WINDOWS\EVTCPQ2AIQQ2.exe
D:\WINDOWS\funshionplugin2.INI
D:\WINDOWS\GR1K5LHVCI.exe
D:\WINDOWS\K8QWY1FBH.exe
D:\WINDOWS\L48YQRKYT.exe
D:\WINDOWS\LENOJ.exe
D:\WINDOWS\LOIK0SCH.exe
D:\WINDOWS\MJ9ZB.exe
D:\WINDOWS\moyu.exe
D:\WINDOWS\NS7MT.exe
D:\WINDOWS\O5GZD.exe
D:\WINDOWS\QFR75FN7.exe
D:\WINDOWS\QOI5OX.exe
D:\WINDOWS\S8NGB9LI3VUU.exe
D:\WINDOWS\setup_102722.exe
D:\WINDOWS\SSVQHMV3Q.exe
D:\WINDOWS\system\dljj32a.dll
D:\WINDOWS\system32\abqzzdos.dll
D:\WINDOWS\system32\abqzzdos.nls
D:\WINDOWS\system32\adsntzt(2).dll
D:\WINDOWS\system32\alga.exe
D:\WINDOWS\system32\aolkua.dll
D:\WINDOWS\system32\apvofwfj.nls
D:\WINDOWS\system32\bitdldgo.nls
D:\WINDOWS\system32\bootvidgj(2).dll
D:\WINDOWS\system32\catsrvwl(2).dll
D:\WINDOWS\system32\comuidsg(2).dll
D:\WINDOWS\system32\config\systemprofile\vistaXA.exe
D:\WINDOWS\system32\cxpop.dll
D:\WINDOWS\system32\dbtqyucx.nls
D:\WINDOWS\system32\dispexcb(2).dll
D:\WINDOWS\system32\dllcache\beep.sys
D:\WINDOWS\system32\dpvvoxmh(2).dll
D:\WINDOWS\system32\DRIVERS\lzdx0zp.sys
D:\WINDOWS\system32\drivers\mejph.sys
D:\WINDOWS\system32\dwikuquh.dll
D:\WINDOWS\system32\dwikuquh.nls
D:\WINDOWS\system32\ebeeyipj.nls
D:\WINDOWS\system32\ervurvsl.nls
D:\WINDOWS\system32\Fessery.sys
D:\WINDOWS\system32\follwel.dll
D:\WINDOWS\system32\follwelk.exe
D:\WINDOWS\system32\ghjsw.dll
D:\WINDOWS\system32\heavtjkn.nls
D:\WINDOWS\system32\hlkbtqiw.nls
D:\WINDOWS\system32\hzyjyvbx.nls
D:\WINDOWS\system32\inetresdxc.dll
D:\WINDOWS\system32\inetresdxc.nls
D:\WINDOWS\system32\jmgkxhqh.nls
D:\WINDOWS\system32\kbdgrms(2).dll
D:\WINDOWS\system32\klozsfcy.nls
D:\WINDOWS\system32\lghmavuu.nls
D:\WINDOWS\system32\lweurqhx(2).dll
D:\WINDOWS\system32\msisipv6.dll
D:\WINDOWS\system32\msobjstl(2).dll
D:\WINDOWS\system32\NetNtEx.dll
D:\WINDOWS\system32\pnalmwps.nls
D:\WINDOWS\system32\qfrnguvx.nls
D:\WINDOWS\system32\ringtte.dll
D:\WINDOWS\system32\rponvneb.nls
D:\WINDOWS\system32\slbiopfs2(2).dll
D:\WINDOWS\system32\soulost.exe
D:\WINDOWS\system32\sovnost.exe
D:\WINDOWS\system32\tbfdimbq.nls
D:\WINDOWS\system32\tmplljydf1.exe
D:\WINDOWS\system32\tmplljydf3.exe
D:\WINDOWS\system32\tmpzydf0.exe
D:\WINDOWS\system32\tmpzydf1.exe
D:\WINDOWS\system32\tmpzydf2.exe
D:\WINDOWS\system32\tmpzydf3.exe
D:\WINDOWS\system32\tscfgwmijxsj(2).dll
D:\WINDOWS\system32\twainyy.dll
D:\WINDOWS\system32\twainyy.nls
D:\WINDOWS\system32\utozuonl.nls
D:\WINDOWS\system32\vistaXA.exe
D:\WINDOWS\system32\wincecomm.exe
D:\WINDOWS\system32\wins\mbgpgxnz.dll
D:\WINDOWS\system32\xolehlpjh.dll
D:\WINDOWS\system32\xolehlpjh.nls
D:\WINDOWS\system32\xsbvgzd(2).dll
D:\WINDOWS\system32\xsbvgzd.cfg
D:\WINDOWS\system32\xsbvgzd.dll
D:\WINDOWS\system32\xsbvgzd.exe
D:\WINDOWS\system32\xwccdqrm.nls
D:\WINDOWS\system32\zlzogu.rds
D:\WINDOWS\system32\znedvadj.nls
D:\WINDOWS\system32\zxdtye.dll
D:\WINDOWS\tianlong.exe
D:\WINDOWS\U58CLZC97.exe
D:\WINDOWS\UNCCA8.exe
D:\WINDOWS\YMGIOK.exe
.

  • 0

#6 ordynat

ordynat

    Zaawansowany użytkownik

  • 804 postów

Napisano 01 09 2008 - 20:17

Po pierwsze - to nie jest cały log
Po drugie - użycie Scriptu po formacie jest bezcelowe - przecież format usunął infekcje.

ordynat
  • 0

#7 Pawel_pl

Pawel_pl

    Początkujący

  • 15 postów

Napisano 01 09 2008 - 20:23

Sformatowałem dysk z windą i zainstalowałem ją jeszcze raz ,reszty dysków nieruszałem :) .
Więc jakaś infekcja chyba pozostała bo błąd jest odnowa .
Zamieszczam nowy log z combofix'a:
ComboFix 08-08-31.01 - MUZYKA 2008-09-01 21:05:30.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1250.1.1045.18.98 [GMT 2:00]
Running from: D:\Documents and Settings\MUZYKA\Pulpit\ComboFix.exe

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED [img]http://www.forum.tweaks.pl/public/style_emoticons/default/excl.gif[/img][/b][/color]
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Program Files\Messenger\msgmr.dll
D:\WINDOWS\AppPatch\AcSpecf.sdb
D:\WINDOWS\AppPatch\AcXtrnel.sdb
D:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
D:\WINDOWS\Fonts\Framdee.ttf
D:\WINDOWS\sysocmgr.dll
D:\WINDOWS\system32\avicapwm.dll
D:\WINDOWS\system32\avicapwm.nls
D:\WINDOWS\system32\bootvidgj.dll
D:\WINDOWS\system32\bootvidgj.nls
D:\WINDOWS\system32\certmgrkd.dll
D:\WINDOWS\system32\certmgrkd.nls
D:\WINDOWS\system32\cliconfgzx.dll
D:\WINDOWS\system32\cliconfgzx.nls
D:\WINDOWS\system32\dispexcb.dll
D:\WINDOWS\system32\dispexcb.nls
D:\WINDOWS\system32\dpvvoxmh.dll
D:\WINDOWS\system32\dpvvoxmh.nls
D:\WINDOWS\system32\drivers\IsDrv118.sys
D:\WINDOWS\system32\imgutilhx2.dll
D:\WINDOWS\system32\imgutilhx2.nls
D:\WINDOWS\system32\mshta.dll
D:\WINDOWS\system32\mstimewd.dll
D:\WINDOWS\system32\mstimewd.nls
D:\WINDOWS\system32\qxfel.dll
D:\WINDOWS\system32\qxfelk.exe
D:\WINDOWS\system32\rasdlgcq.dll
D:\WINDOWS\system32\rasdlgcq.nls
D:\WINDOWS\system32\scrruncqsj.dll
D:\WINDOWS\system32\scrruncqsj.nls
D:\WINDOWS\system32\slbiopfs2.dll
D:\WINDOWS\system32\slbiopfs2.nls
D:\WINDOWS\system32\tscfgwmijxsj.dll
D:\WINDOWS\system32\tscfgwmijxsj.nls
D:\WINDOWS\temp\wmsetup.dll
D:\WINDOWS\Update.dll
.
---- Previous Run -------
.
D:\Program Files\Messenger\msgmr.dll
D:\WINDOWS\AppPatch\AcSpecf.sdb
D:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
D:\WINDOWS\Fonts\Framdee.ttf
D:\WINDOWS\sysocmgr.dll
D:\WINDOWS\system32\avicapwm.dll
D:\WINDOWS\system32\avicapwm.nls
D:\WINDOWS\system32\bootvidgj.dll
D:\WINDOWS\system32\bootvidgj.nls
D:\WINDOWS\system32\certmgrkd.dll
D:\WINDOWS\system32\certmgrkd.nls
D:\WINDOWS\system32\cliconfgzx.dll
D:\WINDOWS\system32\cliconfgzx.nls
D:\WINDOWS\system32\dispexcb.dll
D:\WINDOWS\system32\dispexcb.nls
D:\WINDOWS\system32\dllcache\beep.sys
D:\WINDOWS\system32\dpvvoxmh.dll
D:\WINDOWS\system32\dpvvoxmh.nls
D:\WINDOWS\system32\imgutilhx2.dll
D:\WINDOWS\system32\imgutilhx2.nls
D:\WINDOWS\system32\inetresdxc.dll
D:\WINDOWS\system32\inetresdxc.nls
D:\WINDOWS\system32\mshta.dll
D:\WINDOWS\system32\mstimewd.dll
D:\WINDOWS\system32\mstimewd.nls
D:\WINDOWS\system32\qxfel.dll
D:\WINDOWS\system32\qxfelk.exe
D:\WINDOWS\system32\rasdlgcq.dll
D:\WINDOWS\system32\rasdlgcq.nls
D:\WINDOWS\system32\scrruncqsj.dll
D:\WINDOWS\system32\scrruncqsj.nls
D:\WINDOWS\system32\slbiopfs2.dll
D:\WINDOWS\system32\slbiopfs2.nls
D:\WINDOWS\system32\tscfgwmijxsj.dll
D:\WINDOWS\system32\tscfgwmijxsj.nls
D:\WINDOWS\system32\xolehlpjh.dll
D:\WINDOWS\system32\xolehlpjh.nls
D:\WINDOWS\Update.dll

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_IsDrv118


(((((((((((((((((((((((((   Files Created from 2008-08-01 to 2008-09-01  )))))))))))))))))))))))))))))))
.

2008-09-01 19:59 . 2008-09-01 19:59	856,864	--a------	D:\WINDOWS\system32\xolehlpjh.dll
2008-09-01 19:59 . 2008-09-01 19:59	693,024	--a------	D:\WINDOWS\system32\inetresdxc.dll
2008-09-01 19:59 . 2008-09-01 19:59	557,856	--a------	D:\WINDOWS\system32\nsvcessp.dll
2008-09-01 19:59 . 2008-09-01 19:59	288	--a------	D:\WINDOWS\system32\xolehlpjh.nls
2008-09-01 19:59 . 2008-09-01 19:59	288	--a------	D:\WINDOWS\system32\nsvcessp.nls
2008-09-01 19:59 . 2008-09-01 19:59	288	--a------	D:\WINDOWS\system32\inetresdxc.nls
2008-09-01 17:37 . 2008-09-01 17:37	<DIR>	d--------	D:\Program Files\Microsoft.NET
2008-09-01 17:37 . 2008-09-01 17:39	<DIR>	d--------	D:\Program Files\Common Files\Merge Modules
2008-09-01 17:37 . 2008-09-01 17:39	<DIR>	d--------	D:\Microsoft Visual Studio 8
2008-09-01 17:37 . 2008-09-01 18:12	<DIR>	d--------	D:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-09-01 17:15 . 2008-09-01 17:15	<DIR>	d--------	D:\Program Files\DAEMON Tools Lite
2008-09-01 17:13 . 2008-09-01 17:13	<DIR>	d--------	D:\Documents and Settings\MUZYKA\Dane aplikacji\DAEMON Tools
2008-09-01 17:13 . 2008-09-01 17:13	716,272	--a------	D:\WINDOWS\system32\drivers\sptd.sys
2008-09-01 17:07 . 2008-09-01 17:07	13,646	--a------	D:\WINDOWS\system32\wpa.bak
2008-09-01 17:04 . 2008-09-01 17:04	0	--a------	D:\WINDOWS\nsreg.dat

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-01 16:02	---------	d-----w	D:\Program Files\Microsoft Visual Studio .NET 2003
2008-09-01 16:00	1,032,992	----a-w	D:\WINDOWS\system32\ytsfdojf.dll
2008-09-01 14:54	---------	d-----w	D:\Program Files\InstallShield Installation Information
2008-09-01 14:53	---------	d-----w	D:\Program Files\VIAudioi
2008-09-01 14:52	---------	d-----w	D:\Program Files\VIA
2008-09-01 14:52	---------	d-----w	D:\Program Files\Common Files\InstallShield
2008-09-01 14:32	---------	d-----w	D:\Program Files\microsoft frontpage
2008-09-01 14:28	---------	d-----w	D:\Program Files\Usługi online
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-02-14 01:09 486856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDeck"="D:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2006-09-05 18:28 540672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}"= "D:\WINDOWS\system32\inetresdxc.dll" [2008-09-01 19:59 693024]
"{F0930A2F-D971-4828-8209-B7DFD266ED44}"= "D:\WINDOWS\system32\xolehlpjh.dll" [2008-09-01 19:59 856864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"inetresdxc.dll"= {BB4E3499-0132-4d3f-849A-2BE1B26D84E1} - D:\WINDOWS\system32\inetresdxc.dll [2008-09-01 19:59 693024]
"xolehlpjh.dll"= {F0930A2F-D971-4828-8209-B7DFD266ED44} - D:\WINDOWS\system32\xolehlpjh.dll [2008-09-01 19:59 856864]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC} - D:\WINDOWS\system32\rasdlgcq.dll
SSODL-rasdlgcq.dll-{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC} - D:\WINDOWS\system32\rasdlgcq.dll


.
------- Supplementary Scan -------
.
FireFox -: Profile - D:\Documents and Settings\MUZYKA\Dane aplikacji\Mozilla\Firefox\Profiles\anu6bdx7.default\
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-01 21:08:42
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 


D:\DOCUME~1\MUZYKA\USTAWI~1\Temp\RGI1.tmp
D:\WINDOWS\linkinfo.dll 46592 bytes executable
D:\WINDOWS\system32\drivers\nvmini.sys 17152 bytes executable
D:\WINDOWS\system32\linkinfo.dll 18944 bytes executable

scan completed successfully
hidden files: 4

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nvmini]
"ImagePath"="system32\DRIVERS\nvmini.sys"
.
------------------------ Other Running Processes ------------------------
.
D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
D:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-09-01 21:10:51 - machine was rebooted [MUZYKA]
ComboFix-quarantined-files.txt  2008-09-01 19:10:47

Pre-Run: 16,782,704,640 bajtów wolnych
Post-Run: 16,775,667,712 bajt˘w wolnych

174

  • 0

#8 wncvirus

wncvirus

    Leń !

  • 851 postów

Napisano 02 09 2008 - 16:30

wklej do notatnika

Files::

D:\WINDOWS\system32\xolehlpjh.dll
D:\WINDOWS\system32\xolehlpjh.nls
D:\WINDOWS\system32\inetresdxc.dll
D:\WINDOWS\system32\nsvcessp.dll
D:\WINDOWS\system32\ytsfdojf.dll
   D:\WINDOWS\system32\nsvcessp.nls
   D:\WINDOWS\system32\inetresdxc.nls

>>Plik>>Zapisz jako... >>> CFScript (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe)
Przeciągnij i upuść plik CFScript.txt na plik ComboFix.exe (czyli ikonkę CFScript.txt na ikonkę ComboFix.exe)
– podobnie jak na tym obrazku -->Dołączona grafika
(jeśli pojawi się pytanie "1 or 2" - to wpisz [*b]1[/b] i naciśnij ENTER) Ma się rozpocząć usuwanie. (i powstanie log)
Po restarcie usuń ręcznie folder C: \Qoobox.

Po wykonaniu tego daj nowego loga.
  • 0

#9 Pawel_pl

Pawel_pl

    Początkujący

  • 15 postów

Napisano 02 09 2008 - 16:51

Zrobione ,nowy log:
ComboFix 08-08-31.01 - MUZYKA 2008-09-02 16:42:47.4 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1250.1.1045.18.97 [GMT 2:00]
Running from: D:\Documents and Settings\MUZYKA\Pulpit\ComboFix.exe
Command switches used :: D:\Documents and Settings\MUZYKA\Pulpit\CFScript.txt
 * Created a new restore point

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED [img]http://www.forum.tweaks.pl/public/style_emoticons/default/excl.gif[/img][/b][/color]
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Program Files\Messenger\msgmr.dll
D:\WINDOWS\AppPatch\AcSpecf.sdb
D:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
D:\WINDOWS\Fonts\Framdee.ttf
D:\WINDOWS\sysocmgr.dll
D:\WINDOWS\system32\adsntzt.dll
D:\WINDOWS\system32\adsntzt.nls
D:\WINDOWS\system32\avicapwm.dll
D:\WINDOWS\system32\avicapwm.nls
D:\WINDOWS\system32\bootvidgj.dll
D:\WINDOWS\system32\bootvidgj.nls
D:\WINDOWS\system32\cliconfgzx.dll
D:\WINDOWS\system32\cliconfgzx.nls
D:\WINDOWS\system32\cupops.dll
D:\WINDOWS\system32\cupopsk.exe
D:\WINDOWS\system32\dispexcb.dll
D:\WINDOWS\system32\dispexcb.nls
D:\WINDOWS\system32\dpvvoxmh.dll
D:\WINDOWS\system32\dpvvoxmh.nls
D:\WINDOWS\system32\imgutilhx2.dll
D:\WINDOWS\system32\imgutilhx2.nls
D:\WINDOWS\system32\lweurqhx.dll
D:\WINDOWS\system32\lweurqhx.nls
D:\WINDOWS\system32\mshta.dll
D:\WINDOWS\system32\mstimewd.dll
D:\WINDOWS\system32\mstimewd.nls
D:\WINDOWS\system32\qxfel.dll
D:\WINDOWS\system32\rasdlgcq.dll
D:\WINDOWS\system32\rasdlgcq.nls
D:\WINDOWS\system32\slbiopfs2.dll
D:\WINDOWS\system32\slbiopfs2.nls
D:\WINDOWS\system32\thermaltinc.dll
D:\WINDOWS\system32\tscfgwmijxsj.dll
D:\WINDOWS\system32\tscfgwmijxsj.nls
D:\WINDOWS\temp\wmsetup.dll
D:\WINDOWS\Update.dll

.
(((((((((((((((((((((((((   Files Created from 2008-08-02 to 2008-09-02  )))))))))))))))))))))))))))))))
.

2008-09-02 16:07 . 2008-09-02 16:07	73,728	-rahs----	D:\WINDOWS\LH2C80O.exe
2008-09-02 16:07 . 2008-09-02 16:07	73,728	-r-hs----	D:\WINDOWS\2XFA7G8.exe
2008-09-02 16:07 . 2008-09-02 16:07	28,672	--a------	D:\WINDOWS\ET6FR1Y1L1.exe
2008-09-02 15:59 . 2008-09-02 15:59	2,448,672	--a------	D:\WINDOWS\system32\towfsjex.dll
2008-09-02 15:59 . 2008-09-02 15:59	288	--a------	D:\WINDOWS\system32\towfsjex.nls
2008-09-02 12:52 . 2008-09-02 12:52	73,728	--a------	D:\WINDOWS\YM39Q.exe
2008-09-02 12:52 . 2008-09-02 12:52	73,728	-rahs----	D:\WINDOWS\LHMLBDDI.exe
2008-09-02 12:52 . 2008-09-02 12:52	73,728	-r-hs----	D:\WINDOWS\I8MR9FF3SWHY.exe
2008-09-02 12:52 . 2008-09-02 12:52	61,440	--a------	D:\WINDOWS\UAYYI.exe
2008-09-02 12:52 . 2008-09-02 12:52	28,672	--a------	D:\WINDOWS\NIODPQ5Y0F.exe
2008-09-02 11:32 . 2004-08-03 23:08	31,616	--a------	D:\WINDOWS\system32\drivers\usbccgp.sys
2008-09-02 11:32 . 2004-08-03 23:08	31,616	--a--c---	D:\WINDOWS\system32\dllcache\usbccgp.sys
2008-09-02 11:32 . 2004-08-03 23:08	26,496	--a--c---	D:\WINDOWS\system32\dllcache\usbstor.sys
2008-09-02 10:48 . 2008-09-02 10:48	<DIR>	d--------	D:\Program Files\Nowy folder
2008-09-02 10:43 . 2008-09-02 10:43	1,059,616	--a------	D:\WINDOWS\system32\ndyhlclq.dll
2008-09-02 10:43 . 2008-09-02 15:59	24,576	--a------	D:\WINDOWS\system32\aotoppt.dll
2008-09-02 10:43 . 2008-09-02 10:43	288	--a------	D:\WINDOWS\system32\ndyhlclq.nls
2008-09-01 21:20 . 2008-09-01 21:20	288	--a------	D:\WINDOWS\system32\onarozrr.nls
2008-09-01 19:59 . 2008-09-02 15:58	2,219,296	--a------	D:\WINDOWS\system32\inetresdxc.dll
2008-09-01 19:59 . 2008-09-02 15:59	1,011,488	--a------	D:\WINDOWS\system32\xolehlpjh.dll
2008-09-01 19:59 . 2008-09-01 19:59	557,856	--a------	D:\WINDOWS\system32\nsvcessp.dll
2008-09-01 19:59 . 2008-09-01 19:59	288	--a------	D:\WINDOWS\system32\xolehlpjh.nls
2008-09-01 19:59 . 2008-09-01 19:59	288	--a------	D:\WINDOWS\system32\nsvcessp.nls
2008-09-01 19:59 . 2008-09-01 19:59	288	--a------	D:\WINDOWS\system32\inetresdxc.nls
2008-09-01 17:37 . 2008-09-01 17:37	<DIR>	d--------	D:\Program Files\Microsoft.NET
2008-09-01 17:37 . 2008-09-01 17:39	<DIR>	d--------	D:\Program Files\Common Files\Merge Modules
2008-09-01 17:37 . 2008-09-01 17:39	<DIR>	d--------	D:\Microsoft Visual Studio 8
2008-09-01 17:37 . 2008-09-01 18:12	<DIR>	d--------	D:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-09-01 17:15 . 2008-09-01 17:15	<DIR>	d--------	D:\Program Files\DAEMON Tools Lite
2008-09-01 17:13 . 2008-09-01 17:13	<DIR>	d--------	D:\Documents and Settings\MUZYKA\Dane aplikacji\DAEMON Tools
2008-09-01 17:13 . 2008-09-01 17:13	716,272	--a------	D:\WINDOWS\system32\drivers\sptd.sys
2008-09-01 17:07 . 2008-09-01 17:07	13,646	--a------	D:\WINDOWS\system32\wpa.bak
2008-09-01 17:04 . 2008-09-01 17:04	0	--a------	D:\WINDOWS\nsreg.dat

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-01 16:02	---------	d-----w	D:\Program Files\Microsoft Visual Studio .NET 2003
2008-09-01 16:00	1,032,992	----a-w	D:\WINDOWS\system32\ytsfdojf.dll
2008-09-01 14:54	---------	d-----w	D:\Program Files\InstallShield Installation Information
2008-09-01 14:53	---------	d-----w	D:\Program Files\VIAudioi
2008-09-01 14:52	---------	d-----w	D:\Program Files\VIA
2008-09-01 14:52	---------	d-----w	D:\Program Files\Common Files\InstallShield
2008-09-01 14:32	---------	d-----w	D:\Program Files\microsoft frontpage
2008-09-01 14:28	---------	d-----w	D:\Program Files\Usługi online
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-02-14 01:09 486856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDeck"="D:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2006-09-05 18:28 540672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}"= "D:\WINDOWS\system32\inetresdxc.dll" [2008-09-02 15:58 2219296]
"{F0930A2F-D971-4828-8209-B7DFD266ED44}"= "D:\WINDOWS\system32\xolehlpjh.dll" [2008-09-02 15:59 1011488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"inetresdxc.dll"= {BB4E3499-0132-4d3f-849A-2BE1B26D84E1} - D:\WINDOWS\system32\inetresdxc.dll [2008-09-02 15:58 2219296]
"xolehlpjh.dll"= {F0930A2F-D971-4828-8209-B7DFD266ED44} - D:\WINDOWS\system32\xolehlpjh.dll [2008-09-02 15:59 1011488]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

S3 5ALJTCK;2YR0ZJKHZEM5;D:\WINDOWS\9IDGQ1HH.txt [2008-09-02 16:23]
S3 V85JYU8;4HO0JIU;D:\WINDOWS\DINLYVMV.txt [2008-09-02 12:55]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f6728d0-78d2-11dd-9613-000d8779ecd4}]
\shell\explore\Command - I:\boot.exe
\shell\open\Command - I:\boot.exe
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC} - D:\WINDOWS\system32\rasdlgcq.dll
SSODL-rasdlgcq.dll-{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC} - D:\WINDOWS\system32\rasdlgcq.dll



**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-02 16:45:34
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 


D:\WINDOWS\system32\drivers\nvmini.sys 17152 bytes executable
D:\WINDOWS\linkinfo.dll 46592 bytes executable
D:\WINDOWS\system32\linkinfo.dll 18944 bytes executable

scan completed successfully
hidden files: 3

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nvmini]
"ImagePath"="system32\DRIVERS\nvmini.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\5ALJTCK]
"ImagePath"="\??\D:\WINDOWS\9IDGQ1HH.txt"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\V85JYU8]
"ImagePath"="\??\D:\WINDOWS\DINLYVMV.txt"
.
------------------------ Other Running Processes ------------------------
.
D:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-09-02 16:47:35 - machine was rebooted
ComboFix-quarantined-files.txt  2008-09-02 14:47:31

Pre-Run: 16,873,889,792 bajtów wolnych
Post-Run: 16,852,635,648 bajt˘w wolnych

152

  • 0

#10 wncvirus

wncvirus

    Leń !

  • 851 postów

Napisano 02 09 2008 - 17:06

Wklej do notatnika

Files::

 D:\WINDOWS\LH2C80O.exe
  D:\WINDOWS\2XFA7G8.exe
  D:\WINDOWS\ET6FR1Y1L1.exe
   D:\WINDOWS\system32\towfsjex.dll
   D:\WINDOWS\system32\towfsjex.nls
	D:\WINDOWS\YM39Q.exe
   D:\WINDOWS\LHMLBDDI.exe
  D:\WINDOWS\I8MR9FF3SWHY.exe
	D:\WINDOWS\UAYYI.exe
  D:\WINDOWS\NIODPQ5Y0F.exe

D:\WINDOWS\system32\nsvcessp.dll
	D:\WINDOWS\system32\xolehlpjh.nls
   D:\WINDOWS\system32\nsvcessp.nls
   D:\WINDOWS\system32\inetresdxc.nls
D:\WINDOWS\system32\ytsfdojf.dll
D:\WINDOWS\system32\rasdlgcq.dll
D:\WINDOWS\system32\rasdlgcq.dll

Registry::

hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}"=-
"{F0930A2F-D971-4828-8209-B7DFD266ED44}"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"inetresdxc.dll"=-
"xolehlpjh.dll"= -

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f6728d0-78d2-11dd-9613-000d8779ecd4}]




>>Plik>>Zapisz jako... >>> CFScript (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe)
Przeciągnij i upuść plik CFScript.txt na plik ComboFix.exe (czyli ikonkę CFScript.txt na ikonkę ComboFix.exe)
– podobnie jak na tym obrazku -->Dołączona grafika
(jeśli pojawi się pytanie "1 or 2" - to wpisz 1 i naciśnij ENTER) Ma się rozpocząć usuwanie. (i powstanie log)
Po restarcie usuń ręcznie folder C: \Qoobox.

Oczywiście nowy log po wykonaniu tego.
  • 0

#11 Pawel_pl

Pawel_pl

    Początkujący

  • 15 postów

Napisano 02 09 2008 - 17:20

No i kolejny:
ComboFix 08-08-31.01 - MUZYKA 2008-09-02 17:11:51.5 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1250.1.1045.18.110 [GMT 2:00]
Running from: D:\Documents and Settings\MUZYKA\Pulpit\ComboFix.exe
Command switches used :: D:\Documents and Settings\MUZYKA\Pulpit\CFScript.txt

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED [img]http://www.forum.tweaks.pl/public/style_emoticons/default/excl.gif[/img][/b][/color]
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Program Files\Messenger\msgmr.dll
D:\WINDOWS\Fonts\Framdee.ttf
D:\WINDOWS\temp\wmsetup.dll

.
(((((((((((((((((((((((((   Files Created from 2008-08-02 to 2008-09-02  )))))))))))))))))))))))))))))))
.

2008-09-02 17:04 . 2008-09-02 17:04	73,728	-r-hs----	D:\WINDOWS\V0G3M.exe
2008-09-02 17:04 . 2008-09-02 17:04	73,728	-rahs----	D:\WINDOWS\57YIXNHZM.exe
2008-09-02 17:04 . 2008-09-02 17:04	28,672	--a------	D:\WINDOWS\2FLHT3FS.exe
2008-09-02 17:03 . 2008-09-02 17:03	73,728	-r-hs----	D:\WINDOWS\SVWJT5GOUW9F.exe
2008-09-02 17:03 . 2008-09-02 17:03	73,728	-rahs----	D:\WINDOWS\41C6ZFYR.exe
2008-09-02 17:03 . 2008-09-02 17:03	28,672	--a------	D:\WINDOWS\K3THGR.exe
2008-09-02 16:07 . 2008-09-02 16:07	73,728	-rahs----	D:\WINDOWS\LH2C80O.exe
2008-09-02 16:07 . 2008-09-02 16:07	73,728	-r-hs----	D:\WINDOWS\2XFA7G8.exe
2008-09-02 16:07 . 2008-09-02 16:07	28,672	--a------	D:\WINDOWS\ET6FR1Y1L1.exe
2008-09-02 15:59 . 2008-09-02 15:59	2,448,672	--a------	D:\WINDOWS\system32\towfsjex.dll
2008-09-02 15:59 . 2008-09-02 15:59	288	--a------	D:\WINDOWS\system32\towfsjex.nls
2008-09-02 12:52 . 2008-09-02 12:52	73,728	--a------	D:\WINDOWS\YM39Q.exe
2008-09-02 12:52 . 2008-09-02 12:52	73,728	-rahs----	D:\WINDOWS\LHMLBDDI.exe
2008-09-02 12:52 . 2008-09-02 12:52	73,728	-r-hs----	D:\WINDOWS\I8MR9FF3SWHY.exe
2008-09-02 12:52 . 2008-09-02 12:52	61,440	--a------	D:\WINDOWS\UAYYI.exe
2008-09-02 12:52 . 2008-09-02 12:52	28,672	--a------	D:\WINDOWS\NIODPQ5Y0F.exe
2008-09-02 11:32 . 2004-08-03 23:08	31,616	--a------	D:\WINDOWS\system32\drivers\usbccgp.sys
2008-09-02 11:32 . 2004-08-03 23:08	31,616	--a--c---	D:\WINDOWS\system32\dllcache\usbccgp.sys
2008-09-02 11:32 . 2004-08-03 23:08	26,496	--a--c---	D:\WINDOWS\system32\dllcache\usbstor.sys
2008-09-02 10:48 . 2008-09-02 10:48	<DIR>	d--------	D:\Program Files\Nowy folder
2008-09-02 10:43 . 2008-09-02 10:43	1,059,616	--a------	D:\WINDOWS\system32\ndyhlclq.dll
2008-09-02 10:43 . 2008-09-02 15:59	24,576	--a------	D:\WINDOWS\system32\aotoppt.dll
2008-09-02 10:43 . 2008-09-02 10:43	288	--a------	D:\WINDOWS\system32\ndyhlclq.nls
2008-09-01 21:20 . 2008-09-01 21:20	288	--a------	D:\WINDOWS\system32\onarozrr.nls
2008-09-01 19:59 . 2008-09-02 15:58	2,219,296	--a------	D:\WINDOWS\system32\inetresdxc.dll
2008-09-01 19:59 . 2008-09-02 15:59	1,011,488	--a------	D:\WINDOWS\system32\xolehlpjh.dll
2008-09-01 19:59 . 2008-09-01 19:59	557,856	--a------	D:\WINDOWS\system32\nsvcessp.dll
2008-09-01 19:59 . 2008-09-01 19:59	288	--a------	D:\WINDOWS\system32\xolehlpjh.nls
2008-09-01 19:59 . 2008-09-01 19:59	288	--a------	D:\WINDOWS\system32\nsvcessp.nls
2008-09-01 19:59 . 2008-09-01 19:59	288	--a------	D:\WINDOWS\system32\inetresdxc.nls
2008-09-01 17:37 . 2008-09-01 17:37	<DIR>	d--------	D:\Program Files\Microsoft.NET
2008-09-01 17:37 . 2008-09-01 17:39	<DIR>	d--------	D:\Program Files\Common Files\Merge Modules
2008-09-01 17:37 . 2008-09-01 17:39	<DIR>	d--------	D:\Microsoft Visual Studio 8
2008-09-01 17:37 . 2008-09-01 18:12	<DIR>	d--------	D:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2008-09-01 17:15 . 2008-09-01 17:15	<DIR>	d--------	D:\Program Files\DAEMON Tools Lite
2008-09-01 17:13 . 2008-09-01 17:13	<DIR>	d--------	D:\Documents and Settings\MUZYKA\Dane aplikacji\DAEMON Tools
2008-09-01 17:13 . 2008-09-01 17:13	716,272	--a------	D:\WINDOWS\system32\drivers\sptd.sys
2008-09-01 17:07 . 2008-09-01 17:07	13,646	--a------	D:\WINDOWS\system32\wpa.bak
2008-09-01 17:04 . 2008-09-01 17:04	0	--a------	D:\WINDOWS\nsreg.dat

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-01 16:02	---------	d-----w	D:\Program Files\Microsoft Visual Studio .NET 2003
2008-09-01 16:00	1,032,992	----a-w	D:\WINDOWS\system32\ytsfdojf.dll
2008-09-01 14:54	---------	d-----w	D:\Program Files\InstallShield Installation Information
2008-09-01 14:53	---------	d-----w	D:\Program Files\VIAudioi
2008-09-01 14:52	---------	d-----w	D:\Program Files\VIA
2008-09-01 14:52	---------	d-----w	D:\Program Files\Common Files\InstallShield
2008-09-01 14:32	---------	d-----w	D:\Program Files\microsoft frontpage
2008-09-01 14:28	---------	d-----w	D:\Program Files\Usługi online
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-02-14 01:09 486856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDeck"="D:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2006-09-05 18:28 540672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}"= "D:\WINDOWS\system32\inetresdxc.dll" [2008-09-02 15:58 2219296]
"{F0930A2F-D971-4828-8209-B7DFD266ED44}"= "D:\WINDOWS\system32\xolehlpjh.dll" [2008-09-02 15:59 1011488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"inetresdxc.dll"= {BB4E3499-0132-4d3f-849A-2BE1B26D84E1} - D:\WINDOWS\system32\inetresdxc.dll [2008-09-02 15:58 2219296]
"xolehlpjh.dll"= {F0930A2F-D971-4828-8209-B7DFD266ED44} - D:\WINDOWS\system32\xolehlpjh.dll [2008-09-02 15:59 1011488]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

S3 5ALJTCK;2YR0ZJKHZEM5;D:\WINDOWS\9IDGQ1HH.txt [2008-09-02 16:23]
S3 V85JYU8;4HO0JIU;D:\WINDOWS\DINLYVMV.txt [2008-09-02 12:55]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f6728d0-78d2-11dd-9613-000d8779ecd4}]
\shell\explore\Command - I:\boot.exe
\shell\open\Command - I:\boot.exe
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-02 17:14:23
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 


D:\WINDOWS\linkinfo.dll 46592 bytes executable
D:\WINDOWS\system32\drivers\nvmini.sys 17152 bytes executable
D:\WINDOWS\system32\linkinfo.dll 18944 bytes executable

scan completed successfully
hidden files: 3

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nvmini]
"ImagePath"="system32\DRIVERS\nvmini.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\5ALJTCK]
"ImagePath"="\??\D:\WINDOWS\9IDGQ1HH.txt"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\V85JYU8]
"ImagePath"="\??\D:\WINDOWS\DINLYVMV.txt"
.
------------------------ Other Running Processes ------------------------
.
D:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-09-02 17:17:19 - machine was rebooted
ComboFix-quarantined-files.txt  2008-09-02 15:17:14
ComboFix2.txt  2008-09-02 14:47:36

Pre-Run: 16,863,113,216 bajtów wolnych
Post-Run: 16,858,628,096 bajt˘w wolnych

122


  • 0

#12 karolkuich

karolkuich

    Początkujący

  • 141 postów

Napisano 02 09 2008 - 21:23

Niestety prawie nic się nie usunęło. Powtórzymy skrypt :

File::
D:\WINDOWS\V0G3M.exe
D:\WINDOWS\57YIXNHZM.exe
D:\WINDOWS\2FLHT3FS.exe
D:\WINDOWS\SVWJT5GOUW9F.exe
D:\WINDOWS\41C6ZFYR.exe
D:\WINDOWS\K3THGR.exe
D:\WINDOWS\LH2C80O.exe
D:\WINDOWS\2XFA7G8.exe
D:\WINDOWS\ET6FR1Y1L1.exe
D:\WINDOWS\system32\towfsjex.dll
D:\WINDOWS\system32\towfsjex.nls
D:\WINDOWS\YM39Q.exe
D:\WINDOWS\LHMLBDDI.exe
D:\WINDOWS\I8MR9FF3SWHY.exe
D:\WINDOWS\UAYYI.exe
D:\WINDOWS\NIODPQ5Y0F.exe
D:\WINDOWS\system32\ndyhlclq.dll
D:\WINDOWS\system32\aotoppt.dll
D:\WINDOWS\system32\ndyhlclq.nls
D:\WINDOWS\system32\onarozrr.nls
D:\WINDOWS\system32\inetresdxc.dll
D:\WINDOWS\system32\xolehlpjh.dll
D:\WINDOWS\system32\nsvcessp.dll
D:\WINDOWS\system32\xolehlpjh.nls
D:\WINDOWS\system32\nsvcessp.nls
D:\WINDOWS\system32\inetresdxc.nls
D:\WINDOWS\system32\ytsfdojf.dll

Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}"=-
"{F0930A2F-D971-4828-8209-B7DFD266ED44}"=- 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"inetresdxc.dll"=-
"xolehlpjh.dll"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f6728d0-78d2-11dd-9613-000d8779ecd4}]

Driver::
5ALJTCK
V85JYU8
nvmini

Plik zapisz jako CFScript.txt , przeciągnij i upuść na ikonkę ComboFixa.

Jeśli wszystko pójdzie dobrze to usuń ręcznie folder C:\Qoobox

Wyłącz także na chwilę przywracanie systemu na wszystkich dyskach.

  • 0

#13 Pawel_pl

Pawel_pl

    Początkujący

  • 15 postów

Napisano 03 09 2008 - 15:44

ComboFix 08-08-31.01 - MUZYKA 2008-09-03 15:30:22.6 - NTFSx86

Microsoft Windows XP Professional  5.1.2600.2.1250.1.1045.18.100 [GMT 2:00]

Running from: D:\Documents and Settings\MUZYKA\Pulpit\ComboFix.exe

Command switches used :: D:\Documents and Settings\MUZYKA\Pulpit\CFScript.txt

 * Created a new restore point



[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED [img]http://www.forum.tweaks.pl/public/style_emoticons/default/excl.gif[/img][/b][/color]



FILE ::

D:\WINDOWS\2FLHT3FS.exe

D:\WINDOWS\2XFA7G8.exe

D:\WINDOWS\41C6ZFYR.exe

D:\WINDOWS\57YIXNHZM.exe

D:\WINDOWS\ET6FR1Y1L1.exe

D:\WINDOWS\I8MR9FF3SWHY.exe

D:\WINDOWS\K3THGR.exe

D:\WINDOWS\LH2C80O.exe

D:\WINDOWS\LHMLBDDI.exe

D:\WINDOWS\NIODPQ5Y0F.exe

D:\WINDOWS\SVWJT5GOUW9F.exe

D:\WINDOWS\system32\aotoppt.dll

D:\WINDOWS\system32\inetresdxc.dll

D:\WINDOWS\system32\inetresdxc.nls

D:\WINDOWS\system32\ndyhlclq.dll

D:\WINDOWS\system32\ndyhlclq.nls

D:\WINDOWS\system32\nsvcessp.dll

D:\WINDOWS\system32\nsvcessp.nls

D:\WINDOWS\system32\onarozrr.nls

D:\WINDOWS\system32\towfsjex.dll

D:\WINDOWS\system32\towfsjex.nls

D:\WINDOWS\system32\xolehlpjh.dll

D:\WINDOWS\system32\xolehlpjh.nls

D:\WINDOWS\system32\ytsfdojf.dll

D:\WINDOWS\UAYYI.exe

D:\WINDOWS\V0G3M.exe

D:\WINDOWS\YM39Q.exe

.



(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.



D:\Program Files\Messenger\msgmr.dll

D:\WINDOWS\2FLHT3FS.exe

D:\WINDOWS\2XFA7G8.exe

D:\WINDOWS\41C6ZFYR.exe

D:\WINDOWS\57YIXNHZM.exe

D:\WINDOWS\AppPatch\AcSpecf.sdb

D:\WINDOWS\AppPatch\AcXtrnel.sdb

D:\WINDOWS\ET6FR1Y1L1.exe

D:\WINDOWS\Fonts\Framdee.ttf

D:\WINDOWS\I8MR9FF3SWHY.exe

D:\WINDOWS\K3THGR.exe

D:\WINDOWS\LH2C80O.exe

D:\WINDOWS\LHMLBDDI.exe

D:\WINDOWS\NIODPQ5Y0F.exe

D:\WINDOWS\SVWJT5GOUW9F.exe

D:\WINDOWS\sysocmgr.dll

D:\WINDOWS\system32\adsntzt.dll

D:\WINDOWS\system32\adsntzt.nls

D:\WINDOWS\system32\aotoppt.dll

D:\WINDOWS\system32\avicapwm.dll

D:\WINDOWS\system32\avicapwm.nls

D:\WINDOWS\system32\bootvidgj.dll

D:\WINDOWS\system32\bootvidgj.nls

D:\WINDOWS\system32\certmgrkd.dll

D:\WINDOWS\system32\certmgrkd.nls

D:\WINDOWS\system32\cliconfgzx.dll

D:\WINDOWS\system32\cliconfgzx.nls

D:\WINDOWS\system32\cupops.dll

D:\WINDOWS\system32\cupopsk.exe

D:\WINDOWS\system32\dispexcb.dll

D:\WINDOWS\system32\dispexcb.nls

D:\WINDOWS\system32\dpvvoxmh.dll

D:\WINDOWS\system32\dpvvoxmh.nls

D:\WINDOWS\system32\imgutilhx2.dll

D:\WINDOWS\system32\imgutilhx2.nls

D:\WINDOWS\system32\inetresdxc.dll

D:\WINDOWS\system32\inetresdxc.nls

D:\WINDOWS\system32\johandy.dll

D:\WINDOWS\system32\lweurqhx.dll

D:\WINDOWS\system32\lweurqhx.nls

D:\WINDOWS\system32\mshta.dll

D:\WINDOWS\system32\mstimewd.dll

D:\WINDOWS\system32\mstimewd.nls

D:\WINDOWS\system32\ndyhlclq.dll

D:\WINDOWS\system32\ndyhlclq.nls

D:\WINDOWS\system32\nsvcessp.dll

D:\WINDOWS\system32\nsvcessp.nls

D:\WINDOWS\system32\onarozrr.nls

D:\WINDOWS\system32\qxfel.dll

D:\WINDOWS\system32\qxfelk.exe

D:\WINDOWS\system32\rasdlgcq.dll

D:\WINDOWS\system32\rasdlgcq.nls

D:\WINDOWS\system32\slbiopfs2.dll

D:\WINDOWS\system32\slbiopfs2.nls

D:\WINDOWS\system32\thermaltinc.dll

D:\WINDOWS\system32\towfsjex.dll

D:\WINDOWS\system32\towfsjex.nls

D:\WINDOWS\system32\tscfgwmijxsj.dll

D:\WINDOWS\system32\tscfgwmijxsj.nls

D:\WINDOWS\system32\xolehlpjh.dll

D:\WINDOWS\system32\xolehlpjh.nls

D:\WINDOWS\system32\ytsfdojf.dll

D:\WINDOWS\temp\wmsetup.dll

D:\WINDOWS\UAYYI.exe

D:\WINDOWS\Update.dll

D:\WINDOWS\V0G3M.exe

D:\WINDOWS\YM39Q.exe



.

(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))

.



-------\Legacy_5ALJTCK

-------\Legacy_NVMINI

-------\Legacy_V85JYU8

-------\Service_5ALJTCK

-------\Service_V85JYU8





(((((((((((((((((((((((((   Files Created from 2008-08-03 to 2008-09-03  )))))))))))))))))))))))))))))))

.



2008-09-02 17:29 . 2008-09-02 17:29	2,388,628	--a------	D:\WINDOWS\system32\twainyy.dll

2008-09-02 17:29 . 2008-09-02 17:29	148	--a------	D:\WINDOWS\system32\twainyy.nls

2008-09-02 17:27 . 2008-09-02 17:27	2,411,808	--a------	D:\WINDOWS\system32\qqwlpxio.dll

2008-09-02 17:27 . 2008-09-02 17:27	288	--a------	D:\WINDOWS\system32\qqwlpxio.nls

2008-09-02 11:32 . 2004-08-03 23:08	31,616	--a------	D:\WINDOWS\system32\drivers\usbccgp.sys

2008-09-02 11:32 . 2004-08-03 23:08	31,616	--a--c---	D:\WINDOWS\system32\dllcache\usbccgp.sys

2008-09-02 11:32 . 2004-08-03 23:08	26,496	--a--c---	D:\WINDOWS\system32\dllcache\usbstor.sys

2008-09-02 10:48 . 2008-09-02 10:48	<DIR>	d--------	D:\Program Files\Nowy folder

2008-09-01 17:37 . 2008-09-01 17:37	<DIR>	d--------	D:\Program Files\Microsoft.NET

2008-09-01 17:37 . 2008-09-01 17:39	<DIR>	d--------	D:\Program Files\Common Files\Merge Modules

2008-09-01 17:37 . 2008-09-01 17:39	<DIR>	d--------	D:\Microsoft Visual Studio 8

2008-09-01 17:37 . 2008-09-01 18:12	<DIR>	d--------	D:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help

2008-09-01 17:15 . 2008-09-01 17:15	<DIR>	d--------	D:\Program Files\DAEMON Tools Lite

2008-09-01 17:13 . 2008-09-01 17:13	<DIR>	d--------	D:\Documents and Settings\MUZYKA\Dane aplikacji\DAEMON Tools

2008-09-01 17:13 . 2008-09-01 17:13	716,272	--a------	D:\WINDOWS\system32\drivers\sptd.sys

2008-09-01 17:07 . 2008-09-01 17:07	13,646	--a------	D:\WINDOWS\system32\wpa.bak

2008-09-01 17:04 . 2008-09-01 17:04	0	--a------	D:\WINDOWS\nsreg.dat



.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-09-01 16:02	---------	d-----w	D:\Program Files\Microsoft Visual Studio .NET 2003

2008-09-01 14:54	---------	d-----w	D:\Program Files\InstallShield Installation Information

2008-09-01 14:53	---------	d-----w	D:\Program Files\VIAudioi

2008-09-01 14:52	---------	d-----w	D:\Program Files\VIA

2008-09-01 14:52	---------	d-----w	D:\Program Files\Common Files\InstallShield

2008-09-01 14:32	---------	d-----w	D:\Program Files\microsoft frontpage

2008-09-01 14:28	---------	d-----w	D:\Program Files\Usługi online

.



(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4



[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

"DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-02-14 01:09 486856]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AudioDeck"="D:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2006-09-05 18:28 540672]



[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]



[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}"= "D:\WINDOWS\system32\twainyy.dll" [2008-09-02 17:29 2388628]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

"twainyy.dll"= {434FA69C-5F0A-42e1-82B8-10AF2C8E53C6} - D:\WINDOWS\system32\twainyy.dll [2008-09-02 17:29 2388628]



[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=





*Newly Created Service* - NVMINI

.

- - - - ORPHANS REMOVED - - - -



ShellExecuteHooks-{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC} - D:\WINDOWS\system32\rasdlgcq.dll

SSODL-rasdlgcq.dll-{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC} - D:\WINDOWS\system32\rasdlgcq.dll







**************************************************************************



catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-09-03 15:33:23

Windows 5.1.2600 Dodatek Service Pack 2 NTFS



scanning hidden processes ... 



scanning hidden autostart entries ...



scanning hidden files ... 





D:\WINDOWS\linkinfo.dll 46592 bytes executable

D:\WINDOWS\system32\drivers\nvmini.sys 17152 bytes executable

D:\WINDOWS\system32\linkinfo.dll 18944 bytes executable



scan completed successfully

hidden files: 3



**************************************************************************



[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nvmini]

"ImagePath"="system32\DRIVERS\nvmini.sys"

.

------------------------ Other Running Processes ------------------------

.

D:\WINDOWS\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2008-09-03 15:36:16 - machine was rebooted

ComboFix-quarantined-files.txt  2008-09-03 13:36:10



Pre-Run: 16,866,426,880 bajtów wolnych

Post-Run: 16,839,168,000 bajt˘w wolnych



191

  • 0

#14 wncvirus

wncvirus

    Leń !

  • 851 postów

Napisano 03 09 2008 - 19:47

Wklej do notatnika
Files::

	D:\WINDOWS\system32\twainyy.dll
	D:\WINDOWS\system32\twainyy.nls
	D:\WINDOWS\system32\qqwlpxio.dll

 Registry::

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}"=-


>>Plik>>Zapisz jako... >>> CFScript (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe)
Przeciągnij i upuść plik CFScript.txt na plik ComboFix.exe (czyli ikonkę CFScript.txt na ikonkę ComboFix.exe)
– podobnie jak na tym obrazku -->Dołączona grafika
(jeśli pojawi się pytanie "1 or 2" - to wpisz 1 i naciśnij ENTER) Ma się rozpocząć usuwanie. (i powstanie log)
Po restarcie usuń ręcznie folder C: \Qoobox.

Po wykonaniu daj nowego loga.
  • 0

#15 Pawel_pl

Pawel_pl

    Początkujący

  • 15 postów

Napisano 03 09 2008 - 20:34

ComboFix 08-08-31.01 - MUZYKA 2008-09-03 20:24:51.7 - NTFSx86

Microsoft Windows XP Professional  5.1.2600.2.1250.1.1045.18.97 [GMT 2:00]

Running from: D:\Documents and Settings\MUZYKA\Pulpit\ComboFix.exe

Command switches used :: D:\Documents and Settings\MUZYKA\Pulpit\CFScript.txt



[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED [img]http://www.forum.tweaks.pl/public/style_emoticons/default/excl.gif[/img][/b][/color]

.



(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

.



D:\Program Files\Messenger\msgmr.dll

D:\WINDOWS\AppPatch\AcSpecf.sdb

D:\WINDOWS\Fonts\Framdee.ttf

D:\WINDOWS\sysocmgr.dll

D:\WINDOWS\system32\adsntzt.dll

D:\WINDOWS\system32\adsntzt.nls

D:\WINDOWS\system32\avicapwm.dll

D:\WINDOWS\system32\avicapwm.nls

D:\WINDOWS\system32\bootvidgj.dll

D:\WINDOWS\system32\bootvidgj.nls

D:\WINDOWS\system32\certmgrkd.dll

D:\WINDOWS\system32\certmgrkd.nls

D:\WINDOWS\system32\cliconfgzx.dll

D:\WINDOWS\system32\cliconfgzx.nls

D:\WINDOWS\system32\cupops.dll

D:\WINDOWS\system32\dispexcb.dll

D:\WINDOWS\system32\dispexcb.nls

D:\WINDOWS\system32\dpvvoxmh.dll

D:\WINDOWS\system32\dpvvoxmh.nls

D:\WINDOWS\system32\imgutilhx2.dll

D:\WINDOWS\system32\imgutilhx2.nls

D:\WINDOWS\system32\johandy.dll

D:\WINDOWS\system32\lweurqhx.dll

D:\WINDOWS\system32\lweurqhx.nls

D:\WINDOWS\system32\mshta.dll

D:\WINDOWS\system32\mstimewd.dll

D:\WINDOWS\system32\mstimewd.nls

D:\WINDOWS\system32\qxfel.dll

D:\WINDOWS\system32\qxfelk.exe

D:\WINDOWS\system32\slbiopfs2.dll

D:\WINDOWS\system32\slbiopfs2.nls

D:\WINDOWS\system32\thermaltinc.dll

D:\WINDOWS\system32\tscfgwmijxsj.dll

D:\WINDOWS\system32\tscfgwmijxsj.nls

D:\WINDOWS\Update.dll



.

(((((((((((((((((((((((((   Files Created from 2008-08-03 to 2008-09-03  )))))))))))))))))))))))))))))))

.



2008-09-03 16:29 . 2008-09-03 16:29	73,728	--a------	D:\WINDOWS\W6L65FQ.exe

2008-09-03 16:21 . 2008-09-03 16:21	0	--a------	D:\WINDOWS\ativpsrm.bin

2008-09-03 16:07 . 2008-07-31 21:05	593,920	---------	D:\WINDOWS\system32\ati2sgag.exe

2008-09-03 15:56 . 2008-09-03 15:56	<DIR>	d--------	D:\ATI

2008-09-03 15:53 . 2008-09-03 15:53	683,808	--a------	D:\WINDOWS\system32\xolehlpjh.dll

2008-09-03 15:53 . 2008-09-03 15:53	288	--a------	D:\WINDOWS\system32\xolehlpjh.nls

2008-09-03 15:52 . 2008-09-03 15:52	2,580,768	--a------	D:\WINDOWS\system32\nkujwonr.dll

2008-09-03 15:52 . 2008-09-03 15:52	24,576	--a------	D:\WINDOWS\system32\aotoppt.dll

2008-09-03 15:52 . 2008-09-03 15:52	288	--a------	D:\WINDOWS\system32\nkujwonr.nls

2008-09-03 15:51 . 2008-09-03 15:51	2,593,056	--a------	D:\WINDOWS\system32\inetresdxc.dll

2008-09-03 15:51 . 2008-09-03 15:51	288	--a------	D:\WINDOWS\system32\inetresdxc.nls

2008-09-03 15:44 . 2008-09-03 15:44	61,440	-rahs----	D:\WINDOWS\YYLMOF.exe

2008-09-03 15:44 . 2008-09-03 15:44	61,440	-r-hs----	D:\WINDOWS\81BYWD16D.exe

2008-09-03 15:44 . 2008-09-03 15:44	28,672	--a------	D:\WINDOWS\SJLFQIH.exe

2008-09-02 17:29 . 2008-09-03 15:53	2,197,140	--a------	D:\WINDOWS\system32\twainyy.dll

2008-09-02 17:29 . 2008-09-02 17:29	148	--a------	D:\WINDOWS\system32\twainyy.nls

2008-09-02 17:27 . 2008-09-02 17:27	2,411,808	--a------	D:\WINDOWS\system32\qqwlpxio.dll

2008-09-02 17:27 . 2008-09-02 17:27	288	--a------	D:\WINDOWS\system32\qqwlpxio.nls

2008-09-02 11:32 . 2004-08-03 23:08	31,616	--a------	D:\WINDOWS\system32\drivers\usbccgp.sys

2008-09-02 11:32 . 2004-08-03 23:08	31,616	--a--c---	D:\WINDOWS\system32\dllcache\usbccgp.sys

2008-09-02 11:32 . 2004-08-03 23:08	26,496	--a--c---	D:\WINDOWS\system32\dllcache\usbstor.sys

2008-09-02 10:48 . 2008-09-02 10:48	<DIR>	d--------	D:\Program Files\Nowy folder

2008-09-01 17:37 . 2008-09-01 17:37	<DIR>	d--------	D:\Program Files\Microsoft.NET

2008-09-01 17:37 . 2008-09-01 17:39	<DIR>	d--------	D:\Program Files\Common Files\Merge Modules

2008-09-01 17:37 . 2008-09-01 17:39	<DIR>	d--------	D:\Microsoft Visual Studio 8

2008-09-01 17:37 . 2008-09-01 18:12	<DIR>	d--------	D:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help

2008-09-01 17:15 . 2008-09-01 17:15	<DIR>	d--------	D:\Program Files\DAEMON Tools Lite

2008-09-01 17:13 . 2008-09-01 17:13	<DIR>	d--------	D:\Documents and Settings\MUZYKA\Dane aplikacji\DAEMON Tools

2008-09-01 17:13 . 2008-09-01 17:13	716,272	--a------	D:\WINDOWS\system32\drivers\sptd.sys

2008-09-01 17:07 . 2008-09-01 17:07	13,646	--a------	D:\WINDOWS\system32\wpa.bak

2008-09-01 17:04 . 2008-09-01 17:04	0	--a------	D:\WINDOWS\nsreg.dat



.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-09-03 13:57	---------	d--h--w	D:\Program Files\InstallShield Installation Information

2008-09-03 13:56	---------	d-----w	D:\Program Files\Common Files\InstallShield

2008-09-01 16:02	---------	d-----w	D:\Program Files\Microsoft Visual Studio .NET 2003

2008-09-01 14:53	---------	d-----w	D:\Program Files\VIAudioi

2008-09-01 14:52	---------	d-----w	D:\Program Files\VIA

2008-09-01 14:32	---------	d-----w	D:\Program Files\microsoft frontpage

2008-09-01 14:28	---------	d-----w	D:\Program Files\Usługi online

2008-08-01 06:38	3,266,560	----a-w	D:\WINDOWS\system32\drivers\ati2mtag.sys

2008-08-01 05:40	9,928,704	----a-w	D:\WINDOWS\system32\atioglxx.dll

2008-08-01 04:58	253,952	----a-w	D:\WINDOWS\system32\atiok3x2.dll

2008-08-01 04:33	425,984	----a-w	D:\WINDOWS\system32\ATIDEMGX.dll

2008-08-01 04:32	311,296	----a-w	D:\WINDOWS\system32\ati2dvag.dll

2008-08-01 04:23	184,320	----a-w	D:\WINDOWS\system32\atipdlxx.dll

2008-08-01 04:23	143,360	----a-w	D:\WINDOWS\system32\Oemdspif.dll

2008-08-01 04:22	43,520	----a-w	D:\WINDOWS\system32\ati2edxx.dll

2008-08-01 04:22	26,112	----a-w	D:\WINDOWS\system32\Ati2mdxx.exe

2008-08-01 04:22	143,360	----a-w	D:\WINDOWS\system32\ati2evxx.dll

2008-08-01 04:21	573,440	----a-w	D:\WINDOWS\system32\ati2evxx.exe

2008-08-01 04:19	53,248	----a-w	D:\WINDOWS\system32\ATIDDC.DLL

2008-08-01 04:10	3,917,568	----a-w	D:\WINDOWS\system32\ati3duag.dll

2008-08-01 03:59	2,183,552	----a-w	D:\WINDOWS\system32\ativvaxx.dll

2008-08-01 03:46	48,640	----a-w	D:\WINDOWS\system32\amdpcom32.dll

2008-08-01 03:42	376,832	----a-w	D:\WINDOWS\system32\atikvmag.dll

2008-08-01 03:40	35,328	----a-w	D:\WINDOWS\system32\atiadlxx.dll

2008-08-01 03:40	17,408	----a-w	D:\WINDOWS\system32\atitvo32.dll

2008-08-01 03:39	53,248	----a-w	D:\WINDOWS\system32\drivers\ati2erec.dll

2008-08-01 03:39	307,200	----a-w	D:\WINDOWS\system32\atiiiexx.dll

2008-08-01 03:34	561,152	----a-w	D:\WINDOWS\system32\ati2cqag.dll

.



(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4



[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

"DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-02-14 01:09 486856]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AudioDeck"="D:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2006-09-05 18:28 540672]



[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]



[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}"= "D:\WINDOWS\system32\inetresdxc.dll" [2008-09-03 15:51 2593056]

"{F0930A2F-D971-4828-8209-B7DFD266ED44}"= "D:\WINDOWS\system32\xolehlpjh.dll" [2008-09-03 15:53 683808]

"{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}"= "D:\WINDOWS\system32\twainyy.dll" [2008-09-03 15:53 2197140]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

"twainyy.dll"= {434FA69C-5F0A-42e1-82B8-10AF2C8E53C6} - D:\WINDOWS\system32\twainyy.dll [2008-09-03 15:53 2197140]

"inetresdxc.dll"= {BB4E3499-0132-4d3f-849A-2BE1B26D84E1} - D:\WINDOWS\system32\inetresdxc.dll [2008-09-03 15:51 2593056]

"xolehlpjh.dll"= {F0930A2F-D971-4828-8209-B7DFD266ED44} - D:\WINDOWS\system32\xolehlpjh.dll [2008-09-03 15:53 683808]



[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=



.



**************************************************************************



catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-09-03 20:28:02

Windows 5.1.2600 Dodatek Service Pack 2 NTFS



scanning hidden processes ... 



scanning hidden autostart entries ...



scanning hidden files ... 





D:\WINDOWS\system32\drivers\nvmini.sys 17152 bytes executable

D:\WINDOWS\linkinfo.dll 46592 bytes executable

D:\WINDOWS\system32\linkinfo.dll 18944 bytes executable



scan completed successfully

hidden files: 3



**************************************************************************



[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nvmini]

"ImagePath"="system32\DRIVERS\nvmini.sys"

.

--------------------- DLLs Loaded Under Running Processes ---------------------



PROCESS: D:\WINDOWS\Explorer.EXE

-> D:\WINDOWS\system32\inetresdxc.dll

-> D:\WINDOWS\system32\xolehlpjh.dll

-> D:\WINDOWS\system32\twainyy.dll

.

------------------------ Other Running Processes ------------------------

.

D:\WINDOWS\system32\ati2evxx.exe

D:\WINDOWS\system32\ati2evxx.exe

D:\WINDOWS\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2008-09-03 20:31:19 - machine was rebooted

ComboFix-quarantined-files.txt  2008-09-03 18:31:14

ComboFix2.txt  2008-09-03 13:36:17



Pre-Run: 16,786,587,648 bajtów wolnych

Post-Run: 16,764,211,200 bajt˘w wolnych



167

  • 0

#16 karolkuich

karolkuich

    Początkujący

  • 141 postów

Napisano 03 09 2008 - 22:33

Niestety formatowanie jednego dysku nie miało sensu. Infekcja się rozrasta. Sam Combo nie da rady.

Wklej do notatnika :

File::
D:\WINDOWS\W6L65FQ.exe
D:\WINDOWS\system32\xolehlpjh.dll
D:\WINDOWS\system32\xolehlpjh.nls
D:\WINDOWS\system32\nkujwonr.dll
D:\WINDOWS\system32\aotoppt.dll
D:\WINDOWS\system32\nkujwonr.nls
D:\WINDOWS\system32\inetresdxc.dll
D:\WINDOWS\system32\inetresdxc.nls
D:\WINDOWS\YYLMOF.exe
D:\WINDOWS\81BYWD16D.exe
D:\WINDOWS\SJLFQIH.exe
D:\WINDOWS\system32\twainyy.dll
D:\WINDOWS\system32\twainyy.nls
D:\WINDOWS\system32\qqwlpxio.dll
D:\WINDOWS\system32\qqwlpxio.nls

Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}"=- 
"{F0930A2F-D971-4828-8209-B7DFD266ED44}"=-
"{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"twainyy.dll"=-
"inetresdxc.dll"=-
"xolehlpjh.dll"=-

Plik zapisz jako CFScript.txt , przeciągnij i upuść na ikonkę ComboFixa.

Nie wklejaj loga.

Zrobisz skanowanie :

Kaspersky Virus Removal Tool
Dr. Web CureIt!
Malwarebytes' Anti-Malware

Logi ze skanowań wklej razem z logiem ComboFix, który wykonasz na końcu.
  • 0

#17 Pawel_pl

Pawel_pl

    Początkujący

  • 15 postów

Napisano 07 09 2008 - 10:25

Problem rozwiązany ,skończyło się na pełnym formacie :rolleyes: .
Dzięki wszystkim za pomoc.

  • 0




Użytkownicy przeglądający ten temat: 0

0 użytkowników, 0 gości, 0 anonimowych