Skocz do zawartości


Zdjęcie

Logi - Profilaktyczna kontrola


  • Zamknięty Temat jest zamknięty
1 odpowiedź w tym temacie

#1 Dodo_14

Dodo_14

    Początkujący

  • 146 postów

Napisano 25 07 2008 - 09:06

ComboFix 08-07-23.5 - Dominik 2008-07-25 9:02:44.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.606 [GMT 2:00]
Running from: C:\Documents and Settings\Dominik\Pulpit\Dobre Program\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED Dołączona grafika
.

((((((((((((((((((((((((( Files Created from 2008-06-25 to 2008-07-25 )))))))))))))))))))))))))))))))
.

2008-07-24 18:17 . 2008-07-24 19:14 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-07-24 18:17 . 2008-07-24 19:14 <DIR> d-------- C:\Documents and Settings\Dominik\Dane aplikacji\Spyware Terminator
2008-07-24 18:17 . 2008-07-24 18:27 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spyware Terminator
2008-07-24 18:17 . 2008-07-24 18:17 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-07-20 18:45 . 2008-07-20 18:45 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-07-14 15:59 . 2008-07-14 15:59 <DIR> d---s---- C:\Documents and Settings\Dominik\UserData
2008-07-04 14:38 . 2008-07-24 17:25 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-07-02 17:27 . 2008-07-02 17:27 <DIR> d-------- C:\Documents and Settings\Dominik\Dane aplikacji\Tibia

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-25 07:02 --------- d-----w C:\Program Files\Neostrada TP
2008-07-25 06:00 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-24 17:57 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Symantec
2008-07-21 07:22 --------- d-----w C:\Documents and Settings\Dominik\Dane aplikacji\Nokia Multimedia Player
2008-07-20 16:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 18:01 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-06 16:19 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-05-06 15:44 73,216 -c--a-w C:\WINDOWS\ST6UNST.EXE
2008-05-06 15:44 249,856 -c----w C:\WINDOWS\Setup1.exe
.

((((((((((((((((((((((((((((( snapshot@2008-07-24_17.54.35.98 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-24 14:06:56 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-07-25 05:57:27 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-07-24 14:06:56 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat
+ 2008-07-25 05:57:27 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat
- 2008-07-24 14:06:56 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-07-25 05:57:27 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-07-24 14:06:56 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat
+ 2008-07-25 05:57:27 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gainward"="C:\Program Files\VDOTool\TBPanel.exe" [2007-10-02 12:19 2165272]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-05 07:37 8491008]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-05 07:37 81920]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-03-15 19:05 84640]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-03-15 18:23 26248]
"WooCnxMon"="C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [2003-10-16 18:07 24576]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 18:07 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 18:07 53248]
"InstantAccess"="C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE" [1998-07-07 16:04 37376]
"RegisterDropHandler"="C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE" [1998-07-07 16:20 22528]
"WinampAgent"="D:\Program Files\Winamp\winampa.exe" [2008-04-01 20:49 36352]
"PCSuiteTrayApplication"="D:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20 227328]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 11:21 16270848 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2007-10-05 07:37 1626112 C:\WINDOWS\system32\nwiz.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"RegisterDropHandler"="C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE" [1998-07-07 16:20 22528]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"Nokia.PCSync"="D:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 21:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2008-03-15 18:25]
S3 pmxscan;USB Flatbed Scanner Driver;C:\WINDOWS\system32\DRIVERS\usbscan.sys [1999-10-13 09:19]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-07-11 18:13:56 C:\WINDOWS\Tasks\Norton Internet Security - Uruchom pełne skanowanie systemu - Dominik.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exef/TASK:
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.neostrada.pl
O9 -: { - C:\Program Files\Messenger\msmsgs.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-25 09:03:47
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-25 9:04:24
ComboFix-quarantined-files.txt 2008-07-25 07:04:21
ComboFix2.txt 2008-07-24 16:00:19
ComboFix3.txt 2008-07-24 15:54:49

Pre-Run: 66,658,807,808 bajtów wolnych
Post-Run: 66,651,070,464 bajtów wolnych

113 --- E O F --- 2008-07-09 07:40:59

  • 0

#2 ordynat

ordynat

    Zaawansowany użytkownik

  • 804 postów

Napisano 25 07 2008 - 13:30

Ale w logu nie widzę żadnej infekcji!

Może użyj SmitfraudFix?
>http://www.bezpieczenstwosystemow.pl/index.php?topic=3191.0

ordynat

  • 0




Użytkownicy przeglądający ten temat: 1

0 użytkowników, 1 gości, 0 anonimowych